File: //usr/local/apache/error_log
[Tue Jul 21 07:18:36.939138 2026] [lsapi:notice] [pid 131539:tid 131539] mod_lsapi: version 1.1-92
[Tue Jul 21 07:18:36.953002 2026] [:notice] [pid 229238:tid 229238] [host root@br1102.hostgator.com.br] mod_lsapi: Selfstarter 229238 started
[Tue Jul 21 07:18:36.968117 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: oppbrazil.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:36.969801 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: locadoracmd.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:36.975301 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: accjbc.bcaccj.org:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:36.986411 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: accjbr.com.bcaccj.org:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.000187 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: metodoatracaoconsciente.com.vanderleiasilva.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.002809 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sofiagheller1782846626000.argentajoias.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.003230 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sofiagheller1782846537000.argentajoias.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.008631 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: getveltrixhealth.com.shopmelhorcompraonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.010698 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: adloop.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.011229 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: contafic.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.011762 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: climadek.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.012155 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lojacasacosta.com.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.012687 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: voztricolor.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.013059 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: arenaalphaville.com.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.013440 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rioclaroimovel.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.013806 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marketingderua.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.014352 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: tabelionatoportoalegre.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.014911 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: learningsociety.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.015311 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: clubmarketplace.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.015824 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: arenaalphaville.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.016189 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: app.itqmogiguacu.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.016554 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lp.meuendocrinoonline.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.017084 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: blog.meuendocrinoonline.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.017586 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: blog.meupsiquiatraonline.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.017954 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: empresas.meuendocrinoonline.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.018334 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: dizi.segurosrd.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.019035 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rdgoseguros.segurosrd.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.019419 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: diziseguros.segurosrd.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.024384 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rilicitacoes.raphaelicarolicitacoes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.024874 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rilicitacoes.com.br.raphaelicarolicitacoes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.025400 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: espaconeuroascensao.raphaelicarolicitacoes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.025925 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: espaconeuroascensao.com.br.raphaelicarolicitacoes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.029482 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sscoenper.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.029857 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: ssvistorias.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.030205 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rastreamentobh.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.030678 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: locamotobh.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.031083 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: companhiatop.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.031611 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: acheservicos.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.031959 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aluguelmotobh.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.032315 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aluguelcarrobh.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.038650 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: patihipopressivo.com.patyhipopressivo.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.039052 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: patihipopressivo.com.br.patyhipopressivo.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.042857 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyer.com.br.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.043368 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyerapp.com.br.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.043749 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyersuplementos.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.044101 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vespnutricao.com.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.044615 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyersuplementos.com.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.044994 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyersuplementos.com.br.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.058469 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lojinhadoprofessor.lojinhadaprofessora.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.063100 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: leonardodossantoshen1782739753000.metropollitano.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.065416 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: unoperformancedigital.com.br.karenvieiramarketing.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.065923 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: jbms.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.066295 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: benti.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.066640 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: yuribenassi.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.067007 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: wbapoiocontabil.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.067361 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: movimenti.com.br.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.075782 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sigescala.com.sigescala.meusitehostgator.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.088879 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vivenciarempauta.vivenciarempauta.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.095190 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: 3d-surgery.3d-surgery.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.095709 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vivafinanceiras.com.br.vivafinanceira.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.100731 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: academycont.com.goldentrips40.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.103720 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: trendsol.com.br.fusoesaquisicoes.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.105919 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: libertysolutions.figempreendimentos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.108212 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: naturofarma.com.br.farmaciafarmula.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.108746 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: farmacianaturofarma.com.br.farmaciafarmula.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.109784 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: meuamordevoltaa.estriasnuncamaiss.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.110893 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atividadessprontas.online.estriasnuncamaiss.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.117266 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: esidiomass.com.br.eslanguageschool.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.117608 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: porondeeuestive.com.br.eslanguageschool.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.127856 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: deniltoncostasilva1748033966000.samanenergia.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.131936 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: santotchay.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.132314 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: santotchay.com.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.132803 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: osantotchay.com.br.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.133279 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: oinglesdescomplicado.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.133613 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: brasilmotoeletrica.com.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.140891 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: thenexbr.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.156045 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: c5liberdades.store.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.156373 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: produtoswendell.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.156696 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: produtosnapromo.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.157682 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: c5liberdades.com.br.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.165334 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: produtosnapromo.com.br.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.170346 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: weddinglarissaefelipe.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.172967 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: produtoswendellcarvalho.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.173978 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: exclusivepromotiontoday.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.179789 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: pandie.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.180189 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: guarushop.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.180554 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: guarushop2.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.180906 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: olhobionico.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.181243 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: pandoradango.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.181578 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: guiadeoferta.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.181915 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fofoqueironews.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.182262 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: reidocouro.com.br.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.182628 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: bloquetebrasil.com.br.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.182986 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: protetordegraxa.com.br.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.186237 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atom-growth.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.186731 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atom-growth.com.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.187239 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: confiancedigital.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.187590 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: buddyclub.com.br.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.188066 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: gotavitaoriginal.com.br.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.188550 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: motoboyjaguariuna.com.br.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.189391 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: jandiraemdestaque.com.br.jornaldagrandesp.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.205945 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: accjbc.com.bcaccj.org:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.211715 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fit4me.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.213370 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sociooculto.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.213996 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: exnova.tech.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.214986 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fit4me.store.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.215371 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marlonbarreto.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.215706 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fit4me.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.216051 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atilafagundes.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.216393 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: suaconsulta.fun.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.217373 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: escolhasaudavel.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.218022 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vinicius-schneider.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.218483 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sociooculto.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.218835 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: olimposolar.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.219197 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nextfitjourney.com.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.219685 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: themaisonhommes.com.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.220036 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: tamojuntomidias.com.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.220379 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: gustvoferraritrader.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.220734 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marlonbarreto.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.221092 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: escolhasaudavel.shop.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.221450 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atilafagundes.online.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.221772 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vinicius-schneider.com.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.222266 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mariabonfim1762105378000.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.222608 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: gustvoferraritrader.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.223782 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: flowwshop.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.224296 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: agmiz.com.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.224797 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: comecx.online.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.225163 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: flowwshop.com.br.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.226163 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: blog.findcomp.com.br.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.226678 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: importeicomponentes.com.br.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.230534 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aede.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.231059 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: suora.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.231583 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: condmidia.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.232069 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: recowmenda.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.232538 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: valeuefalou.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.233040 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: trilhasdafe.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.233574 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: bergsantana.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.234084 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: shyoftherock.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.234576 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: pegueaestrada.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.235078 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nocaminhodafe.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.235578 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: arielson.com.br.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.235929 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: amareloturquesa.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.236310 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: terraluna.com.br.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.236639 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: zooparquevet.com.br.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.236966 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nosnaestrada.com.br.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.356392 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fusoesaquisicoes.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.388508 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conairmfg.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.393193 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.425048 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: revistareflexopolitico.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.425922 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: ethanslowell.com.infoalert.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.428022 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: evolvaa.online.evolia.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.430215 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: bracks.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.434911 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: raimundol.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.438281 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conhecaonordeste.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.438637 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: overkotz.onfieldcomunicacao.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.438993 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lucaskotovicz.onfieldcomunicacao.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.439358 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: kotovicz.onfieldcomunicacao.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.442510 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: agendazap.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.443716 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: ebookswl.com.wendelleite.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.445752 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: empacta.volyo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.446770 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: inovaeditorial.volyo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.447432 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: volyoaudiobooks.com.volyo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.450974 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: slapingles.com.teacheraleff.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.451295 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: speakinglikeapro.teacheraleff.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.451628 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: brasilcertdigital.tavarescont.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.455201 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: wenith.com.br.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.455745 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: taliafernandavidi1783665345000.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.456319 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: taliafernandavidi1783664968000.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.456881 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: taliafernandavidi1783664932000.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.457296 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: taliafernandavidi1783569474000.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.463485 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: solarisimplementos.com.solarisimplementos.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.465628 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: madmoholding.saojorgesiderurgia.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.469462 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: evolvaa.com.evolia.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.471339 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sulmov.com.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.471677 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: expovilhena.com.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.472049 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: tinybooks.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.472401 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: planamoveis.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.472716 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: paulakaoana.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.473046 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: expovilhena.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.473373 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: muskintranet.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.473698 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: infonetelecom.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.474027 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: agendamasutti.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.474357 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: politicabrasil.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.474672 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: acerteaquestao.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.474987 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mavieloeducacao.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.475312 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: noticiasrondonia.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.475638 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: jornalbrasileiro.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.476001 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mavieloperformance.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.476354 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: ceramicasantoaugusto.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.478138 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mrragrorepresentacoes.com.mrragrorepresentacoesltda.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.485402 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aprendizadosemlimites.store.peticoesvencedorasofc.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.492338 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: gabivet24h.fluxomarketing.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.493014 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: blessoriginal.com.br.fluxomarketing.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.493848 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marmorariasolare.com.br.fluxomarketing.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.534439 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: institutonwa.nwalouwacom.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.534971 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: deniansantos.com.nwalouwacom.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.535310 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fitconecta.academiausina.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.536016 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vinculampe.com.br.academiausina.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.540891 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: camilajung.mktcouple.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.541693 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mixpedido.mixpdv.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.542055 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: guianordestino.mixpdv.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.546784 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sulprimesc.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.547751 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: zyveria.com.br.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.548569 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: multicarsc.com.br.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.548920 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marquemarketing360.com.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.549430 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: pontodooleomecanica.com.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.549756 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: capitalautocentermecanica.com.br.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.554173 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conquisteemcasa.lylow.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.554675 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conquisteemcasa.store.lylow.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.555033 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conquisteemcasa.online.lylow.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.580537 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rcv.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.580871 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rtdi.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.581200 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rego.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.581518 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: forte.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.581882 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: claret.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.582229 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: portali.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.582565 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mcstilo.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.582924 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: joaorocha.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.583277 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: emonteiro.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.583633 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: robertinho.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.583996 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: parqueprado.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.584330 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: asrealestate.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.584635 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lopeslascasas.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.584973 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rstlimoveis.com.br.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.585309 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: residencialvilaliviero.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.592319 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aengenhariadolucro.com.br.infoalert.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.626071 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: beautyline2.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.626798 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: thejapanway.com.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.627591 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: shopbestdaily.com.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.628944 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: oferta.roncostop.com.br.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.629317 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: artix.locaiestetica.com.br.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.629691 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: camillasandrini1772124780000.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.639409 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: potencialilimitado.com.br.alzirarhein.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.645153 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: volyo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.650666 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: triviaodontologi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.696384 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mastercatu.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.703942 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lylow.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.796168 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.816865 2026] [qos:notice] [pid 131539:tid 131539] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Tue Jul 21 07:18:38.158005 2026] [http2:info] [pid 131539:tid 131539] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.69.0), initializing...
[Tue Jul 21 07:18:38.165263 2026] [mpm_event:notice] [pid 131539:tid 131539] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Tue Jul 21 07:18:38.165274 2026] [core:notice] [pid 131539:tid 131539] AH00094: Command line: '/usr/sbin/httpd'
[Tue Jul 21 07:18:39.242454 2026] [http2:info] [pid 229246:tid 229246] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 07:18:39.263214 2026] [security2:error] [pid 229246:tid 229377] [client 20.206.105.145:36078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/file5.php"] [unique_id "al9HfyBMYeh5YLVG45xS4AAAAhU"]
[Tue Jul 21 07:18:39.263286 2026] [security2:error] [pid 229246:tid 229376] [client 20.151.10.161:21440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/hur.php"] [unique_id "al9HfyBMYeh5YLVG45xS3wAAAhQ"]
[Tue Jul 21 07:18:39.264101 2026] [security2:error] [pid 229246:tid 229382] [client 4.204.201.85:35425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/file31.php"] [unique_id "al9HfyBMYeh5YLVG45xS4gAAAho"]
[Tue Jul 21 07:18:39.264230 2026] [security2:error] [pid 229246:tid 229388] [client 184.75.221.3:41796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xS5AAAAiA"]
[Tue Jul 21 07:18:39.264297 2026] [security2:error] [pid 229246:tid 229388] [client 184.75.221.3:41796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xS5AAAAiA"]
[Tue Jul 21 07:18:39.264362 2026] [security2:error] [pid 229246:tid 229385] [client 20.151.10.161:46032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/fpwch.php"] [unique_id "al9HfyBMYeh5YLVG45xS4wAAAh0"]
[Tue Jul 21 07:18:39.265414 2026] [security2:error] [pid 229246:tid 229394] [client 20.197.192.193:23497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9HfyBMYeh5YLVG45xS5gAAAiY"]
[Tue Jul 21 07:18:39.265496 2026] [security2:error] [pid 229246:tid 229397] [client 20.226.60.151:54542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/w3llscc.php"] [unique_id "al9HfyBMYeh5YLVG45xS5wAAAik"]
[Tue Jul 21 07:18:39.266891 2026] [security2:error] [pid 229246:tid 229391] [client 134.19.179.187:54518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xS5QAAAiM"]
[Tue Jul 21 07:18:39.267007 2026] [security2:error] [pid 229246:tid 229391] [client 134.19.179.187:54518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xS5QAAAiM"]
[Tue Jul 21 07:18:39.269217 2026] [security2:error] [pid 229246:tid 229400] [client 134.19.179.187:54534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xS6QAAAiw"]
[Tue Jul 21 07:18:39.269294 2026] [security2:error] [pid 229246:tid 229400] [client 134.19.179.187:54534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xS6QAAAiw"]
[Tue Jul 21 07:18:39.270864 2026] [security2:error] [pid 229246:tid 229409] [client 68.235.38.2:47492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xS7QAAAjU"]
[Tue Jul 21 07:18:39.270974 2026] [security2:error] [pid 229246:tid 229409] [client 68.235.38.2:47492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xS7QAAAjU"]
[Tue Jul 21 07:18:39.272940 2026] [security2:error] [pid 229246:tid 229383] [client 20.197.192.193:8330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patihipopressivo.com.br"] [uri "/dragonshell.php"] [unique_id "al9HfyBMYeh5YLVG45xS7gAAAhs"]
[Tue Jul 21 07:18:39.292516 2026] [security2:error] [pid 229246:tid 229454] [client 20.197.192.193:23520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HfyBMYeh5YLVG45xS8AAAAmI"]
[Tue Jul 21 07:18:39.330131 2026] [security2:error] [pid 229246:tid 229463] [client 20.197.192.193:24464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/dp.php"] [unique_id "al9HfyBMYeh5YLVG45xS-QAAAms"]
[Tue Jul 21 07:18:39.380111 2026] [security2:error] [pid 229246:tid 229470] [client 20.220.225.223:47860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/kq1.php"] [unique_id "al9HfyBMYeh5YLVG45xS_gAAAnI"]
[Tue Jul 21 07:18:39.384806 2026] [security2:error] [pid 229246:tid 229471] [client 20.197.192.193:24451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/old.php"] [unique_id "al9HfyBMYeh5YLVG45xS_wAAAnM"]
[Tue Jul 21 07:18:39.395779 2026] [security2:error] [pid 229246:tid 229259] [remote 85.208.96.208:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hauptmann.com.br"] [uri "/robots.txt"] [unique_id "al9HfyBMYeh5YLVG45xTBgACNgw"]
[Tue Jul 21 07:18:39.395959 2026] [security2:error] [pid 229246:tid 229410] [client 85.208.96.208:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "hauptmann.com.br"] [uri "/robots.txt"] [unique_id "al9HfyBMYeh5YLVG45xTBgACNgw"]
[Tue Jul 21 07:18:39.399434 2026] [security2:error] [pid 229246:tid 229262] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTCgACOg8"]
[Tue Jul 21 07:18:39.399608 2026] [security2:error] [pid 229246:tid 229414] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTCgACOg8"]
[Tue Jul 21 07:18:39.413828 2026] [security2:error] [pid 229246:tid 229392] [client 173.252.95.25:59344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9HfyBMYeh5YLVG45xTHgAAAiQ"]
[Tue Jul 21 07:18:39.415947 2026] [security2:error] [pid 229246:tid 229482] [client 74.7.175.160:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "senhordostelhados.site"] [uri "/cgi-sys/404.html"] [unique_id "al9HfyBMYeh5YLVG45xTHQAAAn4"]
[Tue Jul 21 07:18:39.418169 2026] [security2:error] [pid 229246:tid 229428] [client 74.7.175.160:36210] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "senhordostelhados.site"] [uri "/robots.txt"] [unique_id "al9HfyBMYeh5YLVG45xTCAACSA0"]
[Tue Jul 21 07:18:39.423966 2026] [security2:error] [pid 229246:tid 229280] [remote 195.26.244.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amandamorau.adv.br"] [uri "/wp-login.php"] [unique_id "al9HfyBMYeh5YLVG45xTJAACQiE"]
[Tue Jul 21 07:18:39.439131 2026] [core:alert] [pid 229246:tid 229495] [client 57.141.18.120:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:18:39.439205 2026] [security2:error] [pid 229246:tid 229496] [client 20.197.192.193:23493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/ms-new.php"] [unique_id "al9HfyBMYeh5YLVG45xTLAAAAow"]
[Tue Jul 21 07:18:39.474777 2026] [security2:error] [pid 229246:tid 229501] [client 20.197.192.193:23498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/track.php"] [unique_id "al9HfyBMYeh5YLVG45xTLwAAApE"]
[Tue Jul 21 07:18:39.506006 2026] [security2:error] [pid 229246:tid 229400] [client 20.197.192.193:24461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/2352356666.php"] [unique_id "al9HfyBMYeh5YLVG45xTMgAAAiw"]
[Tue Jul 21 07:18:39.518208 2026] [security2:error] [pid 229246:tid 229464] [client 209.141.34.121:64398] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "kettlebellevolution.com.br"] [uri "/"] [unique_id "al9HfyBMYeh5YLVG45xTMwAAAmw"]
[Tue Jul 21 07:18:39.534179 2026] [security2:error] [pid 229246:tid 229455] [client 20.197.192.193:23514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/pn.php"] [unique_id "al9HfyBMYeh5YLVG45xTNAAAAmM"]
[Tue Jul 21 07:18:39.550868 2026] [security2:error] [pid 229246:tid 229284] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTNQACTCU"]
[Tue Jul 21 07:18:39.551078 2026] [security2:error] [pid 229246:tid 229432] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTNQACTCU"]
[Tue Jul 21 07:18:39.563012 2026] [security2:error] [pid 229246:tid 229263] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTCwACQRA"]
[Tue Jul 21 07:18:39.563263 2026] [security2:error] [pid 229246:tid 229421] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTCwACQRA"]
[Tue Jul 21 07:18:39.568796 2026] [security2:error] [pid 229246:tid 229285] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTNgACNyY"]
[Tue Jul 21 07:18:39.568994 2026] [security2:error] [pid 229246:tid 229411] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTNgACNyY"]
[Tue Jul 21 07:18:39.573683 2026] [security2:error] [pid 229246:tid 229286] [remote 69.165.67.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.67.165.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "produto-express.com"] [uri "/index.php"] [unique_id "al9HfyBMYeh5YLVG45xTNwACLSc"], referer: https://produto-express.com
[Tue Jul 21 07:18:39.574656 2026] [security2:error] [pid 229246:tid 229384] [client 20.197.192.193:24021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wp-wpbak.php"] [unique_id "al9HfyBMYeh5YLVG45xTOAAAAhw"]
[Tue Jul 21 07:18:39.595698 2026] [security2:error] [pid 229246:tid 229408] [client 20.197.192.193:23538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/dr.php"] [unique_id "al9HfyBMYeh5YLVG45xTOgAAAjQ"]
[Tue Jul 21 07:18:39.599219 2026] [security2:error] [pid 229246:tid 229287] [remote 162.19.246.208:53218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTOQACbSg"]
[Tue Jul 21 07:18:39.599427 2026] [security2:error] [pid 229246:tid 229465] [client 162.19.246.208:53218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTOQACbSg"]
[Tue Jul 21 07:18:39.619979 2026] [security2:error] [pid 229246:tid 229470] [client 20.197.192.193:23499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/2x.php"] [unique_id "al9HfyBMYeh5YLVG45xTPAAAAnI"]
[Tue Jul 21 07:18:39.631186 2026] [security2:error] [pid 229246:tid 229474] [client 20.151.10.161:45972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/w2025.php"] [unique_id "al9HfyBMYeh5YLVG45xTPQAAAnY"]
[Tue Jul 21 07:18:39.644986 2026] [security2:error] [pid 229246:tid 229395] [client 20.197.192.193:23491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/kq1.php"] [unique_id "al9HfyBMYeh5YLVG45xTPwAAAic"]
[Tue Jul 21 07:18:39.672428 2026] [security2:error] [pid 229246:tid 229392] [client 20.197.192.193:24469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/zzz.php"] [unique_id "al9HfyBMYeh5YLVG45xTRAAAAiQ"]
[Tue Jul 21 07:18:39.672585 2026] [security2:error] [pid 229246:tid 229381] [client 35.205.139.29:58524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.sistedu-mec.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9HfyBMYeh5YLVG45xTQwAAAhk"]
[Tue Jul 21 07:18:39.699692 2026] [security2:error] [pid 229246:tid 229476] [client 20.197.192.193:24456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wicked.php"] [unique_id "al9HfyBMYeh5YLVG45xTRQAAAng"]
[Tue Jul 21 07:18:39.726833 2026] [security2:error] [pid 229246:tid 229491] [client 20.197.192.193:24462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/edit.php"] [unique_id "al9HfyBMYeh5YLVG45xTSQAAAoc"]
[Tue Jul 21 07:18:39.742181 2026] [security2:error] [pid 229246:tid 229494] [client 20.197.192.193:23504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/kua.php"] [unique_id "al9HfyBMYeh5YLVG45xTSgAAAoo"]
[Tue Jul 21 07:18:39.767032 2026] [security2:error] [pid 229246:tid 229496] [client 20.197.192.193:23502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/ez.php"] [unique_id "al9HfyBMYeh5YLVG45xTSwAAAow"]
[Tue Jul 21 07:18:39.788940 2026] [security2:error] [pid 229246:tid 229486] [client 20.197.192.193:24455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/fz.php"] [unique_id "al9HfyBMYeh5YLVG45xTTAAAAoI"]
[Tue Jul 21 07:18:39.817657 2026] [security2:error] [pid 229246:tid 229444] [client 20.197.192.193:24466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/la.php"] [unique_id "al9HfyBMYeh5YLVG45xTTQAAAlg"]
[Tue Jul 21 07:18:39.875456 2026] [security2:error] [pid 229246:tid 229382] [client 20.197.192.193:23532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/nhvoanpl.php"] [unique_id "al9HfyBMYeh5YLVG45xTUgAAAho"]
[Tue Jul 21 07:18:39.895824 2026] [security2:error] [pid 229246:tid 229391] [client 20.197.192.193:23537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/inso.php"] [unique_id "al9HfyBMYeh5YLVG45xTUwAAAiM"]
[Tue Jul 21 07:18:39.919973 2026] [security2:error] [pid 229246:tid 229502] [client 20.197.192.193:23495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wpx.php"] [unique_id "al9HfyBMYeh5YLVG45xTVQAAApI"]
[Tue Jul 21 07:18:39.921822 2026] [security2:error] [pid 229246:tid 229420] [client 14.139.42.196:6849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTVAAAAkA"]
[Tue Jul 21 07:18:39.922032 2026] [security2:error] [pid 229246:tid 229420] [client 14.139.42.196:6849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTVAAAAkA"]
[Tue Jul 21 07:18:39.946023 2026] [security2:error] [pid 229246:tid 229400] [client 20.197.192.193:23535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/berlin.php"] [unique_id "al9HfyBMYeh5YLVG45xTWQAAAiw"]
[Tue Jul 21 07:18:39.949316 2026] [security2:error] [pid 229246:tid 229407] [client 139.135.44.145:54399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTWgAAAjM"]
[Tue Jul 21 07:18:39.949477 2026] [security2:error] [pid 229246:tid 229407] [client 139.135.44.145:54399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTWgAAAjM"]
[Tue Jul 21 07:18:39.968727 2026] [security2:error] [pid 229246:tid 229403] [client 20.197.192.193:24458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/billur.php"] [unique_id "al9HfyBMYeh5YLVG45xTWwAAAi8"]
[Tue Jul 21 07:18:39.986727 2026] [security2:error] [pid 229246:tid 229443] [client 175.45.70.82:61400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTXAAAAlc"]
[Tue Jul 21 07:18:39.986973 2026] [security2:error] [pid 229246:tid 229443] [client 175.45.70.82:61400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTXAAAAlc"]
[Tue Jul 21 07:18:39.990184 2026] [security2:error] [pid 229246:tid 229464] [client 20.197.192.193:24013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/mimpi.php"] [unique_id "al9HfyBMYeh5YLVG45xTXgAAAmw"]
[Tue Jul 21 07:18:39.992882 2026] [security2:error] [pid 229246:tid 229406] [client 20.151.10.161:21454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/zoro.php"] [unique_id "al9HfyBMYeh5YLVG45xTXwAAAjI"]
[Tue Jul 21 07:18:39.993061 2026] [security2:error] [pid 229246:tid 229431] [client 45.251.232.145:56995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTYAAAAks"]
[Tue Jul 21 07:18:39.993197 2026] [security2:error] [pid 229246:tid 229431] [client 45.251.232.145:56995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTYAAAAks"]
[Tue Jul 21 07:18:40.005091 2026] [security2:error] [pid 229246:tid 229438] [client 20.197.192.193:23547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/dp.php"] [unique_id "al9HgCBMYeh5YLVG45xTYgAAAlI"]
[Tue Jul 21 07:18:40.018911 2026] [security2:error] [pid 229246:tid 229429] [client 20.197.192.193:23519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/bootstrap.php"] [unique_id "al9HgCBMYeh5YLVG45xTZAAAAkk"]
[Tue Jul 21 07:18:40.032493 2026] [security2:error] [pid 229246:tid 229441] [client 209.141.34.121:64487] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "kettlebellevolution.com.br"] [uri "/"] [unique_id "al9HgCBMYeh5YLVG45xTZQAAAlU"]
[Tue Jul 21 07:18:40.038998 2026] [security2:error] [pid 229246:tid 229416] [client 74.244.195.153:6198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.195.244.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9HgCBMYeh5YLVG45xTZgAAAjw"]
[Tue Jul 21 07:18:40.043287 2026] [security2:error] [pid 229246:tid 229416] [client 74.244.195.153:6198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9HgCBMYeh5YLVG45xTZgAAAjw"]
[Tue Jul 21 07:18:40.052410 2026] [security2:error] [pid 229246:tid 229458] [client 20.197.192.193:23528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wp-editor.php"] [unique_id "al9HgCBMYeh5YLVG45xTZwAAAmY"]
[Tue Jul 21 07:18:40.068583 2026] [security2:error] [pid 229246:tid 229421] [client 20.197.192.193:24488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/cro.php"] [unique_id "al9HgCBMYeh5YLVG45xTaAAAAkE"]
[Tue Jul 21 07:18:40.088235 2026] [security2:error] [pid 229246:tid 229411] [client 20.197.192.193:23540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/cron-tab.php"] [unique_id "al9HgCBMYeh5YLVG45xTagAAAjc"]
[Tue Jul 21 07:18:40.122968 2026] [security2:error] [pid 229246:tid 229384] [client 20.197.192.193:23524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/koiy.php"] [unique_id "al9HgCBMYeh5YLVG45xTawAAAhw"]
[Tue Jul 21 07:18:40.154067 2026] [security2:error] [pid 229246:tid 229408] [client 20.197.192.193:24450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/hp2.php"] [unique_id "al9HgCBMYeh5YLVG45xTbAAAAjQ"]
[Tue Jul 21 07:18:40.169235 2026] [security2:error] [pid 229246:tid 229440] [client 20.151.10.161:45965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/scxy.php"] [unique_id "al9HgCBMYeh5YLVG45xTbQAAAlQ"]
[Tue Jul 21 07:18:40.183073 2026] [security2:error] [pid 229246:tid 229483] [client 20.197.192.193:23546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/hp3.php"] [unique_id "al9HgCBMYeh5YLVG45xTcAAAAn8"]
[Tue Jul 21 07:18:40.237589 2026] [security2:error] [pid 229246:tid 229299] [remote 85.208.96.208:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hauptmann.com.br"] [uri "/home-default/"] [unique_id "al9HgCBMYeh5YLVG45xTcwACLTQ"]
[Tue Jul 21 07:18:40.237826 2026] [security2:error] [pid 229246:tid 229401] [client 85.208.96.208:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "hauptmann.com.br"] [uri "/home-default/"] [unique_id "al9HgCBMYeh5YLVG45xTcwACLTQ"]
[Tue Jul 21 07:18:40.240878 2026] [security2:error] [pid 229246:tid 229471] [client 20.197.192.193:24468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/aa1.php"] [unique_id "al9HgCBMYeh5YLVG45xTdAAAAnM"]
[Tue Jul 21 07:18:40.288010 2026] [security2:error] [pid 229246:tid 229381] [client 20.197.192.193:24470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/acew67.php"] [unique_id "al9HgCBMYeh5YLVG45xTdQAAAhk"]
[Tue Jul 21 07:18:40.328161 2026] [security2:error] [pid 229246:tid 229481] [client 20.197.192.193:23543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/bscclapb.php"] [unique_id "al9HgCBMYeh5YLVG45xTdwAAAn0"]
[Tue Jul 21 07:18:40.356142 2026] [security2:error] [pid 229246:tid 229475] [client 20.197.192.193:24453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/else1.php"] [unique_id "al9HgCBMYeh5YLVG45xTeAAAAnc"]
[Tue Jul 21 07:18:40.383765 2026] [security2:error] [pid 229246:tid 229444] [client 20.197.192.193:24452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/tkikikoko.php"] [unique_id "al9HgCBMYeh5YLVG45xTewAAAlg"]
[Tue Jul 21 07:18:40.408928 2026] [security2:error] [pid 229246:tid 229503] [client 20.197.192.193:23506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wp-Blogs.php"] [unique_id "al9HgCBMYeh5YLVG45xTfQAAApM"]
[Tue Jul 21 07:18:40.421698 2026] [security2:error] [pid 229246:tid 229500] [client 20.197.192.193:23549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wp-css.php"] [unique_id "al9HgCBMYeh5YLVG45xTfwAAApA"]
[Tue Jul 21 07:18:40.436306 2026] [security2:error] [pid 229246:tid 229391] [client 20.197.192.193:24511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wp-explorer.php"] [unique_id "al9HgCBMYeh5YLVG45xTgwAAAiM"]
[Tue Jul 21 07:18:40.450454 2026] [security2:error] [pid 229246:tid 229502] [client 20.197.192.193:23529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/akismet.php"] [unique_id "al9HgCBMYeh5YLVG45xThAAAApI"]
[Tue Jul 21 07:18:40.469311 2026] [security2:error] [pid 229246:tid 229448] [client 20.197.192.193:24041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/ace2.php"] [unique_id "al9HgCBMYeh5YLVG45xTiAAAAlw"]
[Tue Jul 21 07:18:40.508737 2026] [security2:error] [pid 229246:tid 229464] [client 20.197.192.193:23513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/ms.php"] [unique_id "al9HgCBMYeh5YLVG45xTjgAAAmw"]
[Tue Jul 21 07:18:40.612824 2026] [security2:error] [pid 229246:tid 229429] [client 20.220.225.223:47840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/zzz.php"] [unique_id "al9HgCBMYeh5YLVG45xTngAAAkk"]
[Tue Jul 21 07:18:40.668945 2026] [security2:error] [pid 229246:tid 229290] [remote 65.111.15.124:38003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.15.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9HfyBMYeh5YLVG45xTQgACgSs"]
[Tue Jul 21 07:18:40.748067 2026] [security2:error] [pid 229246:tid 229468] [client 20.151.10.161:46073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/FWAZ.php"] [unique_id "al9HgCBMYeh5YLVG45xTrwAAAnA"]
[Tue Jul 21 07:18:40.825268 2026] [security2:error] [pid 229246:tid 229419] [client 120.61.173.56:49584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HgCBMYeh5YLVG45xTuAAAAj8"]
[Tue Jul 21 07:18:40.825444 2026] [security2:error] [pid 229246:tid 229419] [client 120.61.173.56:49584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HgCBMYeh5YLVG45xTuAAAAj8"]
[Tue Jul 21 07:18:40.854224 2026] [security2:error] [pid 229246:tid 229400] [client 35.205.139.29:51216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.sistedu-mec.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9HgCBMYeh5YLVG45xTvgAAAiw"]
[Tue Jul 21 07:18:40.891795 2026] [security2:error] [pid 229246:tid 229392] [client 92.119.178.3:59412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9HgCBMYeh5YLVG45xTxQAAAiQ"]
[Tue Jul 21 07:18:40.891876 2026] [security2:error] [pid 229246:tid 229392] [client 92.119.178.3:59412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9HgCBMYeh5YLVG45xTxQAAAiQ"]
[Tue Jul 21 07:18:40.933758 2026] [security2:error] [pid 229246:tid 229363] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HgCBMYeh5YLVG45xTygACdXQ"]
[Tue Jul 21 07:18:40.933927 2026] [security2:error] [pid 229246:tid 229473] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HgCBMYeh5YLVG45xTygACdXQ"]
[Tue Jul 21 07:18:41.243449 2026] [security2:error] [pid 229246:tid 229282] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HgSBMYeh5YLVG45xT5QACgyM"]
[Tue Jul 21 07:18:41.243581 2026] [security2:error] [pid 229246:tid 229487] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HgSBMYeh5YLVG45xT5QACgyM"]
[Tue Jul 21 07:18:41.255996 2026] [security2:error] [pid 229246:tid 229456] [client 4.204.201.85:35378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/file6.php"] [unique_id "al9HgSBMYeh5YLVG45xT5gAAAmQ"]
[Tue Jul 21 07:18:41.268330 2026] [security2:error] [pid 229246:tid 229488] [client 20.206.105.145:36019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9HgSBMYeh5YLVG45xT5wAAAoQ"]
[Tue Jul 21 07:18:41.327009 2026] [security2:error] [pid 229246:tid 229417] [client 20.151.10.161:21377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/coffexium.php"] [unique_id "al9HgSBMYeh5YLVG45xT6wAAAj0"]
[Tue Jul 21 07:18:41.470508 2026] [security2:error] [pid 229246:tid 229443] [client 20.151.10.161:46040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/qterm.php"] [unique_id "al9HgSBMYeh5YLVG45xT8gAAAlc"]
[Tue Jul 21 07:18:41.496530 2026] [security2:error] [pid 229246:tid 229379] [client 20.197.192.193:27161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9HgSBMYeh5YLVG45xT9AAAAhc"]
[Tue Jul 21 07:18:41.584842 2026] [security2:error] [pid 229246:tid 229404] [client 136.144.33.97:54957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9HgSBMYeh5YLVG45xT9wAAAjA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:18:41.607116 2026] [autoindex:error] [pid 229246:tid 229284] [remote 104.253.36.208:37951] AH01276: Cannot serve directory /home2/ric83751/sanovitta.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:18:41.666495 2026] [security2:error] [pid 229246:tid 229429] [client 20.197.192.193:27153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/dr.php"] [unique_id "al9HgSBMYeh5YLVG45xT-gAAAkk"]
[Tue Jul 21 07:18:41.711198 2026] [security2:error] [pid 229246:tid 229416] [client 20.206.105.145:36172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/file.php"] [unique_id "al9HgSBMYeh5YLVG45xT_AAAAjw"]
[Tue Jul 21 07:18:41.807365 2026] [security2:error] [pid 229246:tid 229286] [remote 173.252.95.37:35160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9HgSBMYeh5YLVG45xUBQACXSc"]
[Tue Jul 21 07:18:41.825457 2026] [security2:error] [pid 229246:tid 229407] [client 35.205.139.29:62471] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.sistedu-mec.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9HgSBMYeh5YLVG45xUBgAAAjM"]
[Tue Jul 21 07:18:42.008158 2026] [security2:error] [pid 229246:tid 229419] [client 4.204.201.85:26584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9HgiBMYeh5YLVG45xUCwAAAj8"]
[Tue Jul 21 07:18:42.089183 2026] [security2:error] [pid 229246:tid 229392] [client 92.119.178.3:59426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9HgiBMYeh5YLVG45xUEQAAAiQ"]
[Tue Jul 21 07:18:42.089270 2026] [security2:error] [pid 229246:tid 229392] [client 92.119.178.3:59426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9HgiBMYeh5YLVG45xUEQAAAiQ"]
[Tue Jul 21 07:18:42.237805 2026] [security2:error] [pid 229246:tid 229409] [client 173.252.95.28:48462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9HgCBMYeh5YLVG45xTaQAAAjU"]
[Tue Jul 21 07:18:42.267120 2026] [security2:error] [pid 229246:tid 229496] [client 20.151.10.161:46065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/blurbs.php"] [unique_id "al9HgiBMYeh5YLVG45xUGAAAAow"]
[Tue Jul 21 07:18:42.518525 2026] [security2:error] [pid 229246:tid 229376] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9HgiBMYeh5YLVG45xUIgAAAhQ"]
[Tue Jul 21 07:18:42.539626 2026] [security2:error] [pid 229246:tid 229297] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HgiBMYeh5YLVG45xUIwACkTI"]
[Tue Jul 21 07:18:42.539779 2026] [security2:error] [pid 229246:tid 229501] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HgiBMYeh5YLVG45xUIwACkTI"]
[Tue Jul 21 07:18:42.618977 2026] [security2:error] [pid 229246:tid 229488] [client 4.204.201.85:26605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HgiBMYeh5YLVG45xUJAAAAoQ"]
[Tue Jul 21 07:18:42.700321 2026] [security2:error] [pid 229246:tid 229397] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9HgiBMYeh5YLVG45xUKAAAAik"]
[Tue Jul 21 07:18:42.875485 2026] [security2:error] [pid 229246:tid 229454] [client 20.151.10.161:46053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/v543.php"] [unique_id "al9HgiBMYeh5YLVG45xUMQAAAmI"]
[Tue Jul 21 07:18:42.875501 2026] [security2:error] [pid 229246:tid 229404] [client 20.206.105.145:36049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/cfile.php"] [unique_id "al9HgiBMYeh5YLVG45xUMAAAAjA"]
[Tue Jul 21 07:18:42.883881 2026] [security2:error] [pid 229246:tid 229464] [client 20.226.60.151:54580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wpx.php"] [unique_id "al9HgiBMYeh5YLVG45xUMgAAAmw"]
[Tue Jul 21 07:18:42.950296 2026] [security2:error] [pid 229246:tid 229445] [client 143.244.57.121:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HgiBMYeh5YLVG45xUMwAAAlk"]
[Tue Jul 21 07:18:43.029045 2026] [security2:error] [pid 229246:tid 229456] [client 35.205.139.29:51641] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.sistedu-mec.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9HgyBMYeh5YLVG45xUNgAAAmQ"]
[Tue Jul 21 07:18:43.034321 2026] [security2:error] [pid 229246:tid 229416] [client 143.244.57.118:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HgyBMYeh5YLVG45xUNwAAAjw"]
[Tue Jul 21 07:18:43.039771 2026] [security2:error] [pid 229246:tid 229458] [client 4.204.201.85:26608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/media.php"] [unique_id "al9HgyBMYeh5YLVG45xUOAAAAmY"]
[Tue Jul 21 07:18:43.114317 2026] [security2:error] [pid 229246:tid 229411] [client 68.235.38.2:60542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9HgyBMYeh5YLVG45xUOQAAAjc"]
[Tue Jul 21 07:18:43.114419 2026] [security2:error] [pid 229246:tid 229411] [client 68.235.38.2:60542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9HgyBMYeh5YLVG45xUOQAAAjc"]
[Tue Jul 21 07:18:43.387400 2026] [security2:error] [pid 229246:tid 229434] [client 20.206.105.145:36166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/class-wp.php"] [unique_id "al9HgyBMYeh5YLVG45xUSwAAAk4"]
[Tue Jul 21 07:18:43.388682 2026] [security2:error] [pid 229246:tid 229477] [client 20.151.10.161:21448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/app.php"] [unique_id "al9HgyBMYeh5YLVG45xUTAAAAnk"]
[Tue Jul 21 07:18:43.483455 2026] [security2:error] [pid 229246:tid 229486] [client 4.204.201.85:26583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/images.php"] [unique_id "al9HgyBMYeh5YLVG45xUUgAAAoI"]
[Tue Jul 21 07:18:43.497139 2026] [security2:error] [pid 229246:tid 229413] [client 173.252.95.32:53258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9HgyBMYeh5YLVG45xUUwAAAjk"]
[Tue Jul 21 07:18:43.531604 2026] [security2:error] [pid 229246:tid 229467] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9HgyBMYeh5YLVG45xUVQAAAm8"]
[Tue Jul 21 07:18:43.535258 2026] [security2:error] [pid 229246:tid 229462] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9HgyBMYeh5YLVG45xUVgAAAmo"]
[Tue Jul 21 07:18:43.656088 2026] [security2:error] [pid 229246:tid 229432] [client 103.162.129.114:54962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9HgyBMYeh5YLVG45xUWAAAAkw"]
[Tue Jul 21 07:18:43.656263 2026] [security2:error] [pid 229246:tid 229432] [client 103.162.129.114:54962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9HgyBMYeh5YLVG45xUWAAAAkw"]
[Tue Jul 21 07:18:43.668910 2026] [security2:error] [pid 229246:tid 229487] [client 20.206.105.145:35980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/admin.php"] [unique_id "al9HgyBMYeh5YLVG45xUWQAAAoM"]
[Tue Jul 21 07:18:43.683348 2026] [security2:error] [pid 229246:tid 229426] [client 134.19.179.187:46464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9HgyBMYeh5YLVG45xUWgAAAkY"]
[Tue Jul 21 07:18:43.683453 2026] [security2:error] [pid 229246:tid 229426] [client 134.19.179.187:46464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9HgyBMYeh5YLVG45xUWgAAAkY"]
[Tue Jul 21 07:18:43.837341 2026] [security2:error] [pid 229246:tid 229417] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9HgyBMYeh5YLVG45xUXwAAAj0"]
[Tue Jul 21 07:18:43.888379 2026] [security2:error] [pid 229246:tid 229466] [client 103.121.156.110:58085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HgyBMYeh5YLVG45xUYAAAAm4"]
[Tue Jul 21 07:18:43.888529 2026] [security2:error] [pid 229246:tid 229466] [client 103.121.156.110:58085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HgyBMYeh5YLVG45xUYAAAAm4"]
[Tue Jul 21 07:18:43.889318 2026] [security2:error] [pid 229246:tid 229490] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9HgyBMYeh5YLVG45xUYQAAAoY"]
[Tue Jul 21 07:18:43.940262 2026] [security2:error] [pid 229246:tid 229311] [remote 104.207.56.171:34595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.56.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9HgyBMYeh5YLVG45xUYgACgEA"]
[Tue Jul 21 07:18:43.944268 2026] [security2:error] [pid 229246:tid 229499] [client 35.205.139.29:53154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.sistedu-mec.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9HgyBMYeh5YLVG45xUYwAAAo8"]
[Tue Jul 21 07:18:44.137039 2026] [security2:error] [pid 229246:tid 229454] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9HhCBMYeh5YLVG45xUawAAAmI"]
[Tue Jul 21 07:18:44.177630 2026] [security2:error] [pid 229246:tid 229455] [client 20.206.105.145:35973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/aa2.php"] [unique_id "al9HhCBMYeh5YLVG45xUbAAAAmM"]
[Tue Jul 21 07:18:44.273633 2026] [security2:error] [pid 229246:tid 229452] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9HhCBMYeh5YLVG45xUdAAAAmA"]
[Tue Jul 21 07:18:44.434294 2026] [security2:error] [pid 229246:tid 229453] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9HhCBMYeh5YLVG45xUewAAAmE"]
[Tue Jul 21 07:18:44.447315 2026] [security2:error] [pid 229246:tid 229320] [remote 192.249.127.213:49172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.127.249.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rqracademy.com"] [uri "/wp-login.php"] [unique_id "al9HhCBMYeh5YLVG45xUfQACk0k"]
[Tue Jul 21 07:18:44.554154 2026] [security2:error] [pid 229246:tid 229410] [client 20.206.105.145:36216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/ccou.php"] [unique_id "al9HhCBMYeh5YLVG45xUfwAAAjY"]
[Tue Jul 21 07:18:44.559633 2026] [security2:error] [pid 229246:tid 229476] [client 20.151.10.161:21486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/core.php"] [unique_id "al9HhCBMYeh5YLVG45xUgAAAAng"]
[Tue Jul 21 07:18:44.642767 2026] [security2:error] [pid 229246:tid 229413] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9HhCBMYeh5YLVG45xUggAAAjk"]
[Tue Jul 21 07:18:44.736266 2026] [security2:error] [pid 229246:tid 229475] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9HhCBMYeh5YLVG45xUhQAAAnc"]
[Tue Jul 21 07:18:44.766652 2026] [security2:error] [pid 229246:tid 229376] [client 4.204.201.85:26562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/gecko.php"] [unique_id "al9HhCBMYeh5YLVG45xUhgAAAhQ"]
[Tue Jul 21 07:18:44.841097 2026] [security2:error] [pid 229246:tid 229481] [client 20.197.192.193:51612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9HhCBMYeh5YLVG45xUiAAAAn0"]
[Tue Jul 21 07:18:44.862602 2026] [security2:error] [pid 229246:tid 229502] [client 20.197.192.193:51588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HhCBMYeh5YLVG45xUiwAAApI"]
[Tue Jul 21 07:18:44.889840 2026] [security2:error] [pid 229246:tid 229455] [client 20.197.192.193:64072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/dp.php"] [unique_id "al9HhCBMYeh5YLVG45xUjQAAAmM"]
[Tue Jul 21 07:18:44.927076 2026] [security2:error] [pid 229246:tid 229379] [client 20.197.192.193:58732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/old.php"] [unique_id "al9HhCBMYeh5YLVG45xUkAAAAhc"]
[Tue Jul 21 07:18:44.936959 2026] [security2:error] [pid 229246:tid 229470] [client 35.205.139.29:54580] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.sistedu-mec.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9HhCBMYeh5YLVG45xUkgAAAnI"]
[Tue Jul 21 07:18:45.021922 2026] [security2:error] [pid 229246:tid 229395] [client 20.197.192.193:51643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/ms-new.php"] [unique_id "al9HhSBMYeh5YLVG45xUkwAAAic"]
[Tue Jul 21 07:18:45.026680 2026] [security2:error] [pid 229246:tid 229445] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9HhSBMYeh5YLVG45xUlAAAAlk"]
[Tue Jul 21 07:18:45.034113 2026] [security2:error] [pid 229246:tid 229460] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9HhSBMYeh5YLVG45xUlgAAAmg"]
[Tue Jul 21 07:18:45.047033 2026] [security2:error] [pid 229246:tid 229433] [client 14.139.42.196:12129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HhSBMYeh5YLVG45xUmAAAAk0"]
[Tue Jul 21 07:18:45.047121 2026] [security2:error] [pid 229246:tid 229433] [client 14.139.42.196:12129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HhSBMYeh5YLVG45xUmAAAAk0"]
[Tue Jul 21 07:18:45.050735 2026] [security2:error] [pid 229246:tid 229479] [client 20.197.192.193:58711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/track.php"] [unique_id "al9HhSBMYeh5YLVG45xUmQAAAns"]
[Tue Jul 21 07:18:45.070358 2026] [security2:error] [pid 229246:tid 229496] [client 20.197.192.193:64106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/2352356666.php"] [unique_id "al9HhSBMYeh5YLVG45xUmgAAAow"]
[Tue Jul 21 07:18:45.102128 2026] [security2:error] [pid 229246:tid 229441] [client 20.197.192.193:51608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/pn.php"] [unique_id "al9HhSBMYeh5YLVG45xUmwAAAlU"]
[Tue Jul 21 07:18:45.118782 2026] [security2:error] [pid 229246:tid 229449] [client 20.151.10.161:46042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/w3lls.php"] [unique_id "al9HhSBMYeh5YLVG45xUnAAAAl0"]
[Tue Jul 21 07:18:45.128908 2026] [security2:error] [pid 229246:tid 229384] [client 20.197.192.193:58739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9HhSBMYeh5YLVG45xUnQAAAhw"]
[Tue Jul 21 07:18:45.136565 2026] [security2:error] [pid 229246:tid 229440] [client 4.204.201.85:26609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/82.php"] [unique_id "al9HhSBMYeh5YLVG45xUngAAAlQ"]
[Tue Jul 21 07:18:45.194733 2026] [security2:error] [pid 229246:tid 229453] [client 20.197.192.193:51590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/dr.php"] [unique_id "al9HhSBMYeh5YLVG45xUoQAAAmE"]
[Tue Jul 21 07:18:45.260995 2026] [security2:error] [pid 229246:tid 229430] [client 20.197.192.193:51637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/2x.php"] [unique_id "al9HhSBMYeh5YLVG45xUogAAAko"]
[Tue Jul 21 07:18:45.290156 2026] [security2:error] [pid 229246:tid 229410] [client 20.197.192.193:60590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/kq1.php"] [unique_id "al9HhSBMYeh5YLVG45xUpQAAAjY"]
[Tue Jul 21 07:18:45.312626 2026] [security2:error] [pid 229246:tid 229489] [client 20.197.192.193:60555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/zzz.php"] [unique_id "al9HhSBMYeh5YLVG45xUpgAAAoU"]
[Tue Jul 21 07:18:45.331733 2026] [security2:error] [pid 229246:tid 229419] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9HhSBMYeh5YLVG45xUpwAAAj8"]
[Tue Jul 21 07:18:45.337827 2026] [security2:error] [pid 229246:tid 229486] [client 20.197.192.193:51626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/wicked.php"] [unique_id "al9HhSBMYeh5YLVG45xUqAAAAoI"]
[Tue Jul 21 07:18:45.355381 2026] [security2:error] [pid 229246:tid 229467] [client 20.197.192.193:51640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/edit.php"] [unique_id "al9HhSBMYeh5YLVG45xUqwAAAm8"]
[Tue Jul 21 07:18:45.375784 2026] [security2:error] [pid 229246:tid 229432] [client 20.197.192.193:58745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/kua.php"] [unique_id "al9HhSBMYeh5YLVG45xUrgAAAkw"]
[Tue Jul 21 07:18:45.404810 2026] [security2:error] [pid 229246:tid 229444] [client 20.197.192.193:64104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/ez.php"] [unique_id "al9HhSBMYeh5YLVG45xUsAAAAlg"]
[Tue Jul 21 07:18:45.422781 2026] [security2:error] [pid 229246:tid 229381] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9HhSBMYeh5YLVG45xUswAAAhk"]
[Tue Jul 21 07:18:45.444143 2026] [security2:error] [pid 229246:tid 229488] [client 20.197.192.193:58733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/fz.php"] [unique_id "al9HhSBMYeh5YLVG45xUtQAAAoQ"]
[Tue Jul 21 07:18:45.463235 2026] [security2:error] [pid 229246:tid 229466] [client 20.197.192.193:60599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/la.php"] [unique_id "al9HhSBMYeh5YLVG45xUtgAAAm4"]
[Tue Jul 21 07:18:45.484546 2026] [security2:error] [pid 229246:tid 229402] [client 20.197.192.193:58723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9HhSBMYeh5YLVG45xUtwAAAi4"]
[Tue Jul 21 07:18:45.513362 2026] [security2:error] [pid 229246:tid 229406] [client 20.197.192.193:60563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/inso.php"] [unique_id "al9HhSBMYeh5YLVG45xUuAAAAjI"]
[Tue Jul 21 07:18:45.530305 2026] [security2:error] [pid 229246:tid 229450] [client 20.151.10.161:50361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/main.php"] [unique_id "al9HhSBMYeh5YLVG45xUuQAAAl4"]
[Tue Jul 21 07:18:45.581886 2026] [security2:error] [pid 229246:tid 229464] [client 20.197.192.193:58718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/wpx.php"] [unique_id "al9HhSBMYeh5YLVG45xUugAAAmw"]
[Tue Jul 21 07:18:45.620182 2026] [security2:error] [pid 229246:tid 229455] [client 20.197.192.193:51632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/berlin.php"] [unique_id "al9HhSBMYeh5YLVG45xUvAAAAmM"]
[Tue Jul 21 07:18:45.629346 2026] [security2:error] [pid 229246:tid 229379] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9HhSBMYeh5YLVG45xUvQAAAhc"]
[Tue Jul 21 07:18:45.639062 2026] [security2:error] [pid 229246:tid 229456] [client 92.119.178.3:52992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HhSBMYeh5YLVG45xUvgAAAmQ"]
[Tue Jul 21 07:18:45.639186 2026] [security2:error] [pid 229246:tid 229456] [client 92.119.178.3:52992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HhSBMYeh5YLVG45xUvgAAAmQ"]
[Tue Jul 21 07:18:45.662008 2026] [security2:error] [pid 229246:tid 229389] [client 20.197.192.193:51614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/billur.php"] [unique_id "al9HhSBMYeh5YLVG45xUvwAAAiE"]
[Tue Jul 21 07:18:45.685192 2026] [security2:error] [pid 229246:tid 229416] [client 20.197.192.193:64082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/mimpi.php"] [unique_id "al9HhSBMYeh5YLVG45xUwAAAAjw"]
[Tue Jul 21 07:18:45.715527 2026] [security2:error] [pid 229246:tid 229491] [client 20.197.192.193:58690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/dp.php"] [unique_id "al9HhSBMYeh5YLVG45xUwgAAAoc"]
[Tue Jul 21 07:18:45.739507 2026] [security2:error] [pid 229246:tid 229460] [client 4.204.201.85:26607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/admin.php"] [unique_id "al9HhSBMYeh5YLVG45xUwwAAAmg"]
[Tue Jul 21 07:18:45.742562 2026] [security2:error] [pid 229246:tid 229433] [client 20.197.192.193:64097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/bootstrap.php"] [unique_id "al9HhSBMYeh5YLVG45xUxAAAAk0"]
[Tue Jul 21 07:18:45.761565 2026] [security2:error] [pid 229246:tid 229421] [client 20.197.192.193:60593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/wp-editor.php"] [unique_id "al9HhSBMYeh5YLVG45xUxQAAAkE"]
[Tue Jul 21 07:18:45.772926 2026] [security2:error] [pid 229246:tid 229494] [client 20.197.192.193:64071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/cro.php"] [unique_id "al9HhSBMYeh5YLVG45xUxgAAAoo"]
[Tue Jul 21 07:18:45.784253 2026] [security2:error] [pid 229246:tid 229435] [client 20.197.192.193:58702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/cron-tab.php"] [unique_id "al9HhSBMYeh5YLVG45xUxwAAAk8"]
[Tue Jul 21 07:18:45.802701 2026] [security2:error] [pid 229246:tid 229441] [client 20.197.192.193:64112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/koiy.php"] [unique_id "al9HhSBMYeh5YLVG45xUyQAAAlU"]
[Tue Jul 21 07:18:45.815753 2026] [security2:error] [pid 229246:tid 229449] [client 20.197.192.193:51617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/hp2.php"] [unique_id "al9HhSBMYeh5YLVG45xUygAAAl0"]
[Tue Jul 21 07:18:45.824977 2026] [security2:error] [pid 229246:tid 229429] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9HhSBMYeh5YLVG45xUywAAAkk"]
[Tue Jul 21 07:18:45.882772 2026] [security2:error] [pid 229246:tid 229440] [client 20.197.192.193:60553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/hp3.php"] [unique_id "al9HhSBMYeh5YLVG45xUzQAAAlQ"]
[Tue Jul 21 07:18:45.930723 2026] [security2:error] [pid 229246:tid 229492] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9HhSBMYeh5YLVG45xU1QAAAog"]
[Tue Jul 21 07:18:45.932900 2026] [security2:error] [pid 229246:tid 229424] [client 136.144.33.110:20999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9HhSBMYeh5YLVG45xU1gAAAkQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:18:45.959598 2026] [security2:error] [pid 229246:tid 229420] [client 35.205.139.29:57112] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.sistedu-mec.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9HhSBMYeh5YLVG45xU1wAAAkA"]
[Tue Jul 21 07:18:45.965915 2026] [security2:error] [pid 229246:tid 229335] [remote 51.195.39.149:57519] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "equoterapiaprosseguir.com"] [uri "/"] [unique_id "al9HhSBMYeh5YLVG45xU2AACZ1g"]
[Tue Jul 21 07:18:45.991349 2026] [security2:error] [pid 229246:tid 229414] [client 20.197.192.193:58728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/aa1.php"] [unique_id "al9HhSBMYeh5YLVG45xU2QAAAjo"]
[Tue Jul 21 07:18:46.007448 2026] [security2:error] [pid 229246:tid 229489] [client 20.220.225.223:43034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/wicked.php"] [unique_id "al9HhiBMYeh5YLVG45xU2gAAAoU"]
[Tue Jul 21 07:18:46.082827 2026] [security2:error] [pid 229246:tid 229477] [client 20.197.192.193:58735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/acew67.php"] [unique_id "al9HhiBMYeh5YLVG45xU3QAAAnk"]
[Tue Jul 21 07:18:46.104057 2026] [security2:error] [pid 229246:tid 229413] [client 20.197.192.193:51644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/bscclapb.php"] [unique_id "al9HhiBMYeh5YLVG45xU4AAAAjk"]
[Tue Jul 21 07:18:46.139799 2026] [security2:error] [pid 229246:tid 229387] [client 20.197.192.193:60603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/else1.php"] [unique_id "al9HhiBMYeh5YLVG45xU4QAAAh8"]
[Tue Jul 21 07:18:46.167690 2026] [security2:error] [pid 229246:tid 229392] [client 20.197.192.193:60606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/tkikikoko.php"] [unique_id "al9HhiBMYeh5YLVG45xU4wAAAiQ"]
[Tue Jul 21 07:18:46.211375 2026] [security2:error] [pid 229246:tid 229475] [client 20.197.192.193:49752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9HhiBMYeh5YLVG45xU5AAAAnc"]
[Tue Jul 21 07:18:46.233118 2026] [security2:error] [pid 229246:tid 229376] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9HhiBMYeh5YLVG45xU5wAAAhQ"]
[Tue Jul 21 07:18:46.241369 2026] [security2:error] [pid 229246:tid 229481] [client 20.197.192.193:60562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/wp-css.php"] [unique_id "al9HhiBMYeh5YLVG45xU6QAAAn0"]
[Tue Jul 21 07:18:46.244519 2026] [security2:error] [pid 229246:tid 229402] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9HhiBMYeh5YLVG45xU6wAAAi4"]
[Tue Jul 21 07:18:46.266177 2026] [security2:error] [pid 229246:tid 229404] [client 4.204.201.85:26387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/adminner.php"] [unique_id "al9HhiBMYeh5YLVG45xU7AAAAjA"]
[Tue Jul 21 07:18:46.293042 2026] [security2:error] [pid 229246:tid 229464] [client 20.197.192.193:64105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/wp-explorer.php"] [unique_id "al9HhiBMYeh5YLVG45xU7QAAAmw"]
[Tue Jul 21 07:18:46.320501 2026] [security2:error] [pid 229246:tid 229399] [client 20.197.192.193:60596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/akismet.php"] [unique_id "al9HhiBMYeh5YLVG45xU7gAAAis"]
[Tue Jul 21 07:18:46.367472 2026] [security2:error] [pid 229246:tid 229445] [client 20.197.192.193:60546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/ace2.php"] [unique_id "al9HhiBMYeh5YLVG45xU7wAAAlk"]
[Tue Jul 21 07:18:46.418155 2026] [security2:error] [pid 229246:tid 229491] [client 20.197.192.193:64085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/ms.php"] [unique_id "al9HhiBMYeh5YLVG45xU9AAAAoc"]
[Tue Jul 21 07:18:46.444737 2026] [security2:error] [pid 229246:tid 229433] [client 20.197.192.193:8350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patihipopressivo.com.br"] [uri "/wp-mt.php"] [unique_id "al9HhiBMYeh5YLVG45xU9wAAAk0"]
[Tue Jul 21 07:18:46.453470 2026] [security2:error] [pid 229246:tid 229421] [client 20.151.10.161:21471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/init.php"] [unique_id "al9HhiBMYeh5YLVG45xU-AAAAkE"]
[Tue Jul 21 07:18:46.532525 2026] [security2:error] [pid 229246:tid 229407] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9HhiBMYeh5YLVG45xU_wAAAjM"]
[Tue Jul 21 07:18:46.611405 2026] [security2:error] [pid 229246:tid 229436] [client 20.206.105.145:36189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/dr.php"] [unique_id "al9HhiBMYeh5YLVG45xVAQAAAlA"]
[Tue Jul 21 07:18:46.613520 2026] [security2:error] [pid 229246:tid 229453] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9HhiBMYeh5YLVG45xVAgAAAmE"]
[Tue Jul 21 07:18:46.682080 2026] [security2:error] [pid 229246:tid 229348] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HhiBMYeh5YLVG45xVAwACHGU"]
[Tue Jul 21 07:18:46.682266 2026] [security2:error] [pid 229246:tid 229384] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HhiBMYeh5YLVG45xVAwACHGU"]
[Tue Jul 21 07:18:46.738719 2026] [autoindex:error] [pid 229246:tid 229470] [client 4.204.201.85:35408] AH01276: Cannot serve directory /home3/seaport/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:18:46.780983 2026] [security2:error] [pid 229246:tid 229350] [remote 154.61.75.100:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vanderleiasilva.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HhiBMYeh5YLVG45xVBwACgGc"]
[Tue Jul 21 07:18:46.781123 2026] [security2:error] [pid 229246:tid 229484] [client 154.61.75.100:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vanderleiasilva.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HhiBMYeh5YLVG45xVBwACgGc"]
[Tue Jul 21 07:18:46.798577 2026] [security2:error] [pid 229246:tid 229352] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HhiBMYeh5YLVG45xVCAACjWk"]
[Tue Jul 21 07:18:46.798721 2026] [security2:error] [pid 229246:tid 229497] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HhiBMYeh5YLVG45xVCAACjWk"]
[Tue Jul 21 07:18:46.808011 2026] [security2:error] [pid 229246:tid 229489] [client 4.204.201.85:26565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/admin.php"] [unique_id "al9HhiBMYeh5YLVG45xVCgAAAoU"]
[Tue Jul 21 07:18:46.836337 2026] [security2:error] [pid 229246:tid 229474] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9HhiBMYeh5YLVG45xVCwAAAnY"]
[Tue Jul 21 07:18:46.968373 2026] [security2:error] [pid 229246:tid 229429] [client 35.205.139.29:51623] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.sistedu-mec.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9HhiBMYeh5YLVG45xVEgAAAkk"]
[Tue Jul 21 07:18:47.025112 2026] [security2:error] [pid 229246:tid 229419] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9HhyBMYeh5YLVG45xVGAAAAj8"]
[Tue Jul 21 07:18:47.032620 2026] [security2:error] [pid 229246:tid 229408] [client 20.151.10.161:50329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/prekel.php"] [unique_id "al9HhyBMYeh5YLVG45xVGgAAAjQ"]
[Tue Jul 21 07:18:47.043929 2026] [security2:error] [pid 229246:tid 229393] [client 4.204.201.85:35420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/adminfuns.php"] [unique_id "al9HhyBMYeh5YLVG45xVHAAAAiU"]
[Tue Jul 21 07:18:47.129455 2026] [access_compat:error] [pid 229246:tid 229404] [client 162.241.63.68:24582] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:18:47.154469 2026] [security2:error] [pid 229246:tid 229385] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9HhyBMYeh5YLVG45xVIgAAAh0"]
[Tue Jul 21 07:18:47.322419 2026] [security2:error] [pid 229246:tid 229438] [client 4.204.201.85:26368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/k.php"] [unique_id "al9HhyBMYeh5YLVG45xVJwAAAlI"]
[Tue Jul 21 07:18:47.359218 2026] [security2:error] [pid 229246:tid 229491] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9HhyBMYeh5YLVG45xVKAAAAoc"]
[Tue Jul 21 07:18:47.406731 2026] [security2:error] [pid 229246:tid 229492] [client 139.135.44.145:53547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HhyBMYeh5YLVG45xVKQAAAog"]
[Tue Jul 21 07:18:47.407323 2026] [security2:error] [pid 229246:tid 229492] [client 139.135.44.145:53547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HhyBMYeh5YLVG45xVKQAAAog"]
[Tue Jul 21 07:18:47.463322 2026] [security2:error] [pid 229246:tid 229494] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9HhyBMYeh5YLVG45xVLQAAAoo"]
[Tue Jul 21 07:18:47.528295 2026] [security2:error] [pid 229246:tid 229477] [client 122.183.40.231:33021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.40.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "psiqueflix.online"] [uri "/xmlrpc.php"] [unique_id "al9HhyBMYeh5YLVG45xVLgAAAnk"]
[Tue Jul 21 07:18:47.528429 2026] [security2:error] [pid 229246:tid 229477] [client 122.183.40.231:33021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "psiqueflix.online"] [uri "/xmlrpc.php"] [unique_id "al9HhyBMYeh5YLVG45xVLgAAAnk"]
[Tue Jul 21 07:18:47.673512 2026] [security2:error] [pid 229246:tid 229471] [client 4.204.201.85:26621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/blurbs.php"] [unique_id "al9HhyBMYeh5YLVG45xVMgAAAnM"]
[Tue Jul 21 07:18:47.731575 2026] [security2:error] [pid 229246:tid 229409] [client 4.204.201.85:35369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/goods.php"] [unique_id "al9HhyBMYeh5YLVG45xVNgAAAjU"]
[Tue Jul 21 07:18:47.747661 2026] [security2:error] [pid 229246:tid 229424] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9HhyBMYeh5YLVG45xVNwAAAkQ"]
[Tue Jul 21 07:18:47.795171 2026] [security2:error] [pid 229246:tid 229446] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9HhyBMYeh5YLVG45xVOQAAAlo"]
[Tue Jul 21 07:18:47.801959 2026] [security2:error] [pid 229246:tid 229420] [client 20.206.105.145:36050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/xamp.php"] [unique_id "al9HhyBMYeh5YLVG45xVOgAAAkA"]
[Tue Jul 21 07:18:47.823186 2026] [security2:error] [pid 229246:tid 229481] [client 74.244.195.153:42852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.195.244.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9HhyBMYeh5YLVG45xVOwAAAn0"]
[Tue Jul 21 07:18:47.823292 2026] [security2:error] [pid 229246:tid 229481] [client 74.244.195.153:42852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9HhyBMYeh5YLVG45xVOwAAAn0"]
[Tue Jul 21 07:18:47.929824 2026] [security2:error] [pid 229246:tid 229400] [client 35.205.139.29:65245] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.sistedu-mec.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9HhyBMYeh5YLVG45xVQAAAAiw"]
[Tue Jul 21 07:18:48.042743 2026] [security2:error] [pid 229246:tid 229382] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9HiCBMYeh5YLVG45xVRAAAAho"]
[Tue Jul 21 07:18:48.044325 2026] [security2:error] [pid 229246:tid 229493] [client 4.204.201.85:26582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/bajah.php"] [unique_id "al9HiCBMYeh5YLVG45xVRQAAAok"]
[Tue Jul 21 07:18:48.055524 2026] [security2:error] [pid 229246:tid 229370] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HiCBMYeh5YLVG45xVRgACFXs"]
[Tue Jul 21 07:18:48.055668 2026] [security2:error] [pid 229246:tid 229377] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HiCBMYeh5YLVG45xVRgACFXs"]
[Tue Jul 21 07:18:48.102437 2026] [security2:error] [pid 229246:tid 229478] [client 4.204.201.85:35423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/100.php"] [unique_id "al9HiCBMYeh5YLVG45xVRwAAAno"]
[Tue Jul 21 07:18:48.153525 2026] [security2:error] [pid 229246:tid 229402] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9HiCBMYeh5YLVG45xVSgAAAi4"]
[Tue Jul 21 07:18:48.183173 2026] [security2:error] [pid 229246:tid 229454] [client 20.151.10.161:46063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-ws68.php"] [unique_id "al9HiCBMYeh5YLVG45xVSwAAAmI"]
[Tue Jul 21 07:18:48.267990 2026] [security2:error] [pid 229246:tid 229388] [client 20.151.10.161:21455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/0.php"] [unique_id "al9HiCBMYeh5YLVG45xVUAAAAiA"]
[Tue Jul 21 07:18:48.291560 2026] [security2:error] [pid 229246:tid 229445] [client 20.226.60.151:54566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-css.php"] [unique_id "al9HiCBMYeh5YLVG45xVUgAAAlk"]
[Tue Jul 21 07:18:48.469626 2026] [security2:error] [pid 229246:tid 229482] [client 4.204.201.85:26574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/a.php"] [unique_id "al9HiCBMYeh5YLVG45xVVgAAAn4"]
[Tue Jul 21 07:18:48.490349 2026] [security2:error] [pid 229246:tid 229491] [client 20.197.192.193:9454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patihipopressivo.com.br"] [uri "/ww.php"] [unique_id "al9HiCBMYeh5YLVG45xVWgAAAoc"]
[Tue Jul 21 07:18:48.513906 2026] [security2:error] [pid 229246:tid 229421] [client 4.204.201.85:35411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/about.php"] [unique_id "al9HiCBMYeh5YLVG45xVWwAAAkE"]
[Tue Jul 21 07:18:48.557976 2026] [security2:error] [pid 229246:tid 229259] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HiCBMYeh5YLVG45xVXQACZAw"]
[Tue Jul 21 07:18:48.558134 2026] [security2:error] [pid 229246:tid 229456] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HiCBMYeh5YLVG45xVXQACZAw"]
[Tue Jul 21 07:18:48.688426 2026] [security2:error] [pid 229246:tid 229458] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9HiCBMYeh5YLVG45xVXgAAAmY"]
[Tue Jul 21 07:18:48.695210 2026] [security2:error] [pid 229246:tid 229429] [client 45.251.232.145:57510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HiCBMYeh5YLVG45xVXwAAAkk"]
[Tue Jul 21 07:18:48.695356 2026] [security2:error] [pid 229246:tid 229429] [client 45.251.232.145:57510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HiCBMYeh5YLVG45xVXwAAAkk"]
[Tue Jul 21 07:18:48.796229 2026] [security2:error] [pid 229246:tid 229441] [client 4.204.201.85:26612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/edit.php"] [unique_id "al9HiCBMYeh5YLVG45xVZAAAAlU"]
[Tue Jul 21 07:18:48.902113 2026] [security2:error] [pid 229246:tid 229435] [client 4.204.201.85:35449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/about.php"] [unique_id "al9HiCBMYeh5YLVG45xVZwAAAk8"]
[Tue Jul 21 07:18:49.033877 2026] [security2:error] [pid 229246:tid 229383] [client 35.205.139.29:61015] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.sistedu-mec.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9HiSBMYeh5YLVG45xVbAAAAhs"]
[Tue Jul 21 07:18:49.086981 2026] [security2:error] [pid 229246:tid 229468] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9HiSBMYeh5YLVG45xVbQAAAnA"]
[Tue Jul 21 07:18:49.118536 2026] [security2:error] [pid 229246:tid 229481] [client 4.204.201.85:26597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/hosty.php"] [unique_id "al9HiSBMYeh5YLVG45xVbgAAAn0"]
[Tue Jul 21 07:18:49.162806 2026] [security2:error] [pid 229246:tid 229392] [client 20.151.10.161:21387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/BDKR28.php"] [unique_id "al9HiSBMYeh5YLVG45xVbwAAAiQ"]
[Tue Jul 21 07:18:49.181343 2026] [security2:error] [pid 229246:tid 229459] [client 173.252.95.6:53802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9HiSBMYeh5YLVG45xVcAAAAmc"]
[Tue Jul 21 07:18:49.195461 2026] [security2:error] [pid 229246:tid 229469] [client 20.220.225.223:52758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/edit.php"] [unique_id "al9HiSBMYeh5YLVG45xVcQAAAnE"]
[Tue Jul 21 07:18:49.338666 2026] [security2:error] [pid 229246:tid 229487] [client 4.204.201.85:35438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/admin.php"] [unique_id "al9HiSBMYeh5YLVG45xVdQAAAoM"]
[Tue Jul 21 07:18:49.398600 2026] [security2:error] [pid 229246:tid 229475] [client 136.144.33.99:37073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9HiSBMYeh5YLVG45xVeAAAAnc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:18:49.409893 2026] [security2:error] [pid 229246:tid 229377] [client 20.206.105.145:36015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/bless.php"] [unique_id "al9HiSBMYeh5YLVG45xVeQAAAhU"]
[Tue Jul 21 07:18:49.460359 2026] [security2:error] [pid 229246:tid 229376] [client 4.204.201.85:26566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/k.php"] [unique_id "al9HiSBMYeh5YLVG45xVewAAAhQ"]
[Tue Jul 21 07:18:49.465136 2026] [security2:error] [pid 229246:tid 229483] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9HiSBMYeh5YLVG45xVfAAAAn8"]
[Tue Jul 21 07:18:49.630388 2026] [security2:error] [pid 229246:tid 229381] [client 20.197.192.193:9426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patihipopressivo.com.br"] [uri "/cron.php"] [unique_id "al9HiSBMYeh5YLVG45xVgwAAAhk"]
[Tue Jul 21 07:18:49.837474 2026] [security2:error] [pid 229246:tid 229452] [client 4.204.201.85:26614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/aaa.php"] [unique_id "al9HiSBMYeh5YLVG45xVigAAAmA"]
[Tue Jul 21 07:18:49.846314 2026] [security2:error] [pid 229246:tid 229482] [client 20.151.10.161:21446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/f35.update.php"] [unique_id "al9HiSBMYeh5YLVG45xViwAAAn4"]
[Tue Jul 21 07:18:50.055526 2026] [security2:error] [pid 229246:tid 229479] [client 4.204.201.85:35454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/admin.php"] [unique_id "al9HiiBMYeh5YLVG45xVjwAAAns"]
[Tue Jul 21 07:18:50.295719 2026] [security2:error] [pid 229246:tid 229411] [client 4.204.201.85:26586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/file5.php"] [unique_id "al9HiiBMYeh5YLVG45xVlQAAAjc"]
[Tue Jul 21 07:18:50.414104 2026] [security2:error] [pid 229246:tid 229416] [client 175.45.70.82:61895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HiiBMYeh5YLVG45xVmgAAAjw"]
[Tue Jul 21 07:18:50.414242 2026] [security2:error] [pid 229246:tid 229416] [client 175.45.70.82:61895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HiiBMYeh5YLVG45xVmgAAAjw"]
[Tue Jul 21 07:18:50.625350 2026] [security2:error] [pid 229246:tid 229378] [client 20.226.60.151:54545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/ho.php"] [unique_id "al9HiiBMYeh5YLVG45xVqAAAAhY"]
[Tue Jul 21 07:18:50.757583 2026] [security2:error] [pid 229246:tid 229481] [client 4.204.201.85:35328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/themes.php"] [unique_id "al9HiiBMYeh5YLVG45xVqgAAAn0"]
[Tue Jul 21 07:18:50.890009 2026] [security2:error] [pid 229246:tid 229414] [client 4.204.201.85:26376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/222.php"] [unique_id "al9HiiBMYeh5YLVG45xVrAAAAjo"]
[Tue Jul 21 07:18:51.075662 2026] [security2:error] [pid 229246:tid 229451] [client 20.151.10.161:46060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xyn.php"] [unique_id "al9HiyBMYeh5YLVG45xVswAAAl8"]
[Tue Jul 21 07:18:51.126718 2026] [autoindex:error] [pid 229246:tid 229444] [client 170.106.35.153:58240] AH01276: Cannot serve directory /home2/rebe1126/rebecavivone.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:18:51.234335 2026] [security2:error] [pid 229246:tid 229493] [client 20.151.10.161:50324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/f900.php"] [unique_id "al9HiyBMYeh5YLVG45xVtQAAAok"]
[Tue Jul 21 07:18:51.299787 2026] [security2:error] [pid 229246:tid 229488] [client 4.204.201.85:26369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/test.php"] [unique_id "al9HiyBMYeh5YLVG45xVtgAAAoQ"]
[Tue Jul 21 07:18:51.416230 2026] [security2:error] [pid 229246:tid 229392] [client 120.61.173.56:50094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HiyBMYeh5YLVG45xVuQAAAiQ"]
[Tue Jul 21 07:18:51.416339 2026] [security2:error] [pid 229246:tid 229392] [client 120.61.173.56:50094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HiyBMYeh5YLVG45xVuQAAAiQ"]
[Tue Jul 21 07:18:51.457832 2026] [autoindex:error] [pid 229246:tid 229499] [client 4.204.201.85:35408] AH01276: Cannot serve directory /home3/seaport/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:18:51.498247 2026] [security2:error] [pid 229246:tid 229300] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HiyBMYeh5YLVG45xVvgACITU"]
[Tue Jul 21 07:18:51.498405 2026] [security2:error] [pid 229246:tid 229389] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HiyBMYeh5YLVG45xVvgACITU"]
[Tue Jul 21 07:18:51.757657 2026] [security2:error] [pid 229246:tid 229308] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HiyBMYeh5YLVG45xVyQACID0"]
[Tue Jul 21 07:18:51.757867 2026] [security2:error] [pid 229246:tid 229388] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HiyBMYeh5YLVG45xVyQACID0"]
[Tue Jul 21 07:18:51.783231 2026] [security2:error] [pid 229246:tid 229492] [client 20.220.225.223:47850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/kua.php"] [unique_id "al9HiyBMYeh5YLVG45xVygAAAog"]
[Tue Jul 21 07:18:51.862605 2026] [security2:error] [pid 229246:tid 229411] [client 4.204.201.85:26385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/aaa.php"] [unique_id "al9HiyBMYeh5YLVG45xV0AAAAjc"]
[Tue Jul 21 07:18:51.921108 2026] [security2:error] [pid 229246:tid 229471] [client 20.206.105.145:36181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/file46.php"] [unique_id "al9HiyBMYeh5YLVG45xV0gAAAnM"]
[Tue Jul 21 07:18:51.996871 2026] [security2:error] [pid 229246:tid 229436] [client 20.206.105.145:35849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/eee.php"] [unique_id "al9HiyBMYeh5YLVG45xV0wAAAlA"]
[Tue Jul 21 07:18:52.075062 2026] [security2:error] [pid 229246:tid 229378] [client 4.204.201.85:35431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/.well-known/about.php"] [unique_id "al9HjCBMYeh5YLVG45xV2AAAAhY"]
[Tue Jul 21 07:18:52.121171 2026] [security2:error] [pid 229246:tid 229497] [client 20.206.105.145:36184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/file25.php"] [unique_id "al9HjCBMYeh5YLVG45xV3AAAAo0"]
[Tue Jul 21 07:18:52.274926 2026] [security2:error] [pid 229246:tid 229457] [client 20.206.105.145:36214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/file48.php"] [unique_id "al9HjCBMYeh5YLVG45xV3wAAAmU"]
[Tue Jul 21 07:18:52.346820 2026] [security2:error] [pid 229246:tid 229487] [client 4.204.201.85:26390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/11.php"] [unique_id "al9HjCBMYeh5YLVG45xV4QAAAoM"]
[Tue Jul 21 07:18:52.417497 2026] [security2:error] [pid 229246:tid 229474] [client 20.151.10.161:21390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/xmrl.php"] [unique_id "al9HjCBMYeh5YLVG45xV6AAAAnY"]
[Tue Jul 21 07:18:52.419331 2026] [security2:error] [pid 229246:tid 229304] [remote 188.138.102.156:50012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "girassollimpeza.com.br"] [uri "/wp-login.php"] [unique_id "al9HjCBMYeh5YLVG45xV6QACSTk"]
[Tue Jul 21 07:18:52.617183 2026] [security2:error] [pid 229246:tid 229417] [client 20.151.10.161:46018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/green3.php"] [unique_id "al9HjCBMYeh5YLVG45xV9AAAAj0"]
[Tue Jul 21 07:18:52.710554 2026] [security2:error] [pid 229246:tid 229450] [client 4.204.201.85:35407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9HjCBMYeh5YLVG45xV9gAAAl4"]
[Tue Jul 21 07:18:52.829766 2026] [security2:error] [pid 229246:tid 229501] [client 20.197.192.193:8338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patihipopressivo.com.br"] [uri "/xxx.php"] [unique_id "al9HjCBMYeh5YLVG45xV-AAAApE"]
[Tue Jul 21 07:18:52.855837 2026] [security2:error] [pid 229246:tid 229458] [client 20.197.192.193:17607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9HjCBMYeh5YLVG45xV-QAAAmY"]
[Tue Jul 21 07:18:53.009890 2026] [security2:error] [pid 229246:tid 229395] [client 20.197.192.193:22828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HjSBMYeh5YLVG45xV_QAAAic"]
[Tue Jul 21 07:18:53.058636 2026] [security2:error] [pid 229246:tid 229477] [client 4.204.201.85:26599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/mac.php"] [unique_id "al9HjSBMYeh5YLVG45xV_wAAAnk"]
[Tue Jul 21 07:18:53.099709 2026] [security2:error] [pid 229246:tid 229470] [client 20.197.192.193:17615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/dp.php"] [unique_id "al9HjSBMYeh5YLVG45xWAQAAAnI"]
[Tue Jul 21 07:18:53.105599 2026] [security2:error] [pid 229246:tid 229323] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HjSBMYeh5YLVG45xWAgACc0w"]
[Tue Jul 21 07:18:53.105739 2026] [security2:error] [pid 229246:tid 229471] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HjSBMYeh5YLVG45xWAgACc0w"]
[Tue Jul 21 07:18:53.155335 2026] [security2:error] [pid 229246:tid 229378] [client 20.197.192.193:22838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/old.php"] [unique_id "al9HjSBMYeh5YLVG45xWAwAAAhY"]
[Tue Jul 21 07:18:53.179781 2026] [security2:error] [pid 229246:tid 229401] [client 20.197.192.193:17633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/ms-new.php"] [unique_id "al9HjSBMYeh5YLVG45xWBwAAAi0"]
[Tue Jul 21 07:18:53.208083 2026] [security2:error] [pid 229246:tid 229462] [client 20.197.192.193:22789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/track.php"] [unique_id "al9HjSBMYeh5YLVG45xWCQAAAmo"]
[Tue Jul 21 07:18:53.256089 2026] [security2:error] [pid 229246:tid 229449] [client 20.197.192.193:22835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/2352356666.php"] [unique_id "al9HjSBMYeh5YLVG45xWDgAAAl0"]
[Tue Jul 21 07:18:53.400886 2026] [security2:error] [pid 229246:tid 229414] [client 4.204.201.85:35403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wefile.php"] [unique_id "al9HjSBMYeh5YLVG45xWFAAAAjo"]
[Tue Jul 21 07:18:53.513112 2026] [security2:error] [pid 229246:tid 229419] [client 20.197.192.193:17640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/pn.php"] [unique_id "al9HjSBMYeh5YLVG45xWGAAAAj8"]
[Tue Jul 21 07:18:53.554923 2026] [security2:error] [pid 229246:tid 229381] [client 20.197.192.193:22836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/wp-wpbak.php"] [unique_id "al9HjSBMYeh5YLVG45xWGgAAAhk"]
[Tue Jul 21 07:18:53.582715 2026] [security2:error] [pid 229246:tid 229500] [client 4.204.201.85:26379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/chosen.php"] [unique_id "al9HjSBMYeh5YLVG45xWGwAAApA"]
[Tue Jul 21 07:18:53.584580 2026] [security2:error] [pid 229246:tid 229435] [client 136.144.33.54:33043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9HjSBMYeh5YLVG45xWFgAAAk8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:18:53.602450 2026] [security2:error] [pid 229246:tid 229417] [client 20.197.192.193:22812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/dr.php"] [unique_id "al9HjSBMYeh5YLVG45xWHwAAAj0"]
[Tue Jul 21 07:18:53.625739 2026] [security2:error] [pid 229246:tid 229490] [client 20.151.10.161:50356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/memberfuns.php"] [unique_id "al9HjSBMYeh5YLVG45xWIAAAAoY"]
[Tue Jul 21 07:18:53.684689 2026] [security2:error] [pid 229246:tid 229456] [client 20.197.192.193:22804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/2x.php"] [unique_id "al9HjSBMYeh5YLVG45xWIQAAAmQ"]
[Tue Jul 21 07:18:53.775205 2026] [security2:error] [pid 229246:tid 229501] [client 20.206.105.145:36187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/file6.php"] [unique_id "al9HjSBMYeh5YLVG45xWJQAAApE"]
[Tue Jul 21 07:18:53.901878 2026] [security2:error] [pid 229246:tid 229460] [client 20.197.192.193:22805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/kq1.php"] [unique_id "al9HjSBMYeh5YLVG45xWKwAAAmg"]
[Tue Jul 21 07:18:53.944911 2026] [security2:error] [pid 229246:tid 229446] [client 4.204.201.85:35441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9HjSBMYeh5YLVG45xWLQAAAlo"]
[Tue Jul 21 07:18:54.017401 2026] [security2:error] [pid 229246:tid 229409] [client 20.197.192.193:22785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/zzz.php"] [unique_id "al9HjiBMYeh5YLVG45xWMwAAAjU"]
[Tue Jul 21 07:18:54.049126 2026] [security2:error] [pid 229246:tid 229377] [client 20.197.192.193:17638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/wicked.php"] [unique_id "al9HjiBMYeh5YLVG45xWNQAAAhU"]
[Tue Jul 21 07:18:54.108445 2026] [security2:error] [pid 229246:tid 229418] [client 20.226.60.151:54559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/xy.php"] [unique_id "al9HjiBMYeh5YLVG45xWNgAAAj4"]
[Tue Jul 21 07:18:54.114131 2026] [security2:error] [pid 229246:tid 229444] [client 4.204.201.85:26587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/cream1.php"] [unique_id "al9HjiBMYeh5YLVG45xWNwAAAlg"]
[Tue Jul 21 07:18:54.149295 2026] [security2:error] [pid 229246:tid 229488] [client 20.197.192.193:17602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/edit.php"] [unique_id "al9HjiBMYeh5YLVG45xWOwAAAoQ"]
[Tue Jul 21 07:18:54.205565 2026] [security2:error] [pid 229246:tid 229390] [client 103.162.129.114:55452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9HjiBMYeh5YLVG45xWPAAAAiI"]
[Tue Jul 21 07:18:54.205723 2026] [security2:error] [pid 229246:tid 229390] [client 103.162.129.114:55452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9HjiBMYeh5YLVG45xWPAAAAiI"]
[Tue Jul 21 07:18:54.332556 2026] [security2:error] [pid 229246:tid 229381] [client 20.197.192.193:17644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/kua.php"] [unique_id "al9HjiBMYeh5YLVG45xWQQAAAhk"]
[Tue Jul 21 07:18:54.340004 2026] [security2:error] [pid 229246:tid 229451] [client 92.119.178.3:33922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9HjiBMYeh5YLVG45xWQgAAAl8"]
[Tue Jul 21 07:18:54.340108 2026] [security2:error] [pid 229246:tid 229451] [client 92.119.178.3:33922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9HjiBMYeh5YLVG45xWQgAAAl8"]
[Tue Jul 21 07:18:54.395515 2026] [security2:error] [pid 229246:tid 229500] [client 20.197.192.193:22843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/ez.php"] [unique_id "al9HjiBMYeh5YLVG45xWRAAAApA"]
[Tue Jul 21 07:18:54.440042 2026] [security2:error] [pid 229246:tid 229403] [client 20.197.192.193:17642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/fz.php"] [unique_id "al9HjiBMYeh5YLVG45xWRQAAAi8"]
[Tue Jul 21 07:18:54.498641 2026] [security2:error] [pid 229246:tid 229447] [client 103.121.156.110:58412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HjiBMYeh5YLVG45xWSAAAAls"]
[Tue Jul 21 07:18:54.498768 2026] [security2:error] [pid 229246:tid 229447] [client 103.121.156.110:58412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HjiBMYeh5YLVG45xWSAAAAls"]
[Tue Jul 21 07:18:54.514567 2026] [security2:error] [pid 229246:tid 229452] [client 20.197.192.193:22847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/la.php"] [unique_id "al9HjiBMYeh5YLVG45xWSQAAAmA"]
[Tue Jul 21 07:18:54.526519 2026] [security2:error] [pid 229246:tid 229486] [client 20.151.10.161:21490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/ms.php"] [unique_id "al9HjiBMYeh5YLVG45xWSwAAAoI"]
[Tue Jul 21 07:18:54.542208 2026] [security2:error] [pid 229246:tid 229433] [client 20.197.192.193:22839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/nhvoanpl.php"] [unique_id "al9HjiBMYeh5YLVG45xWTwAAAk0"]
[Tue Jul 21 07:18:54.560380 2026] [security2:error] [pid 229246:tid 229421] [client 20.197.192.193:17663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/inso.php"] [unique_id "al9HjiBMYeh5YLVG45xWUAAAAkE"]
[Tue Jul 21 07:18:54.604559 2026] [security2:error] [pid 229246:tid 229389] [client 20.197.192.193:17641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/wpx.php"] [unique_id "al9HjiBMYeh5YLVG45xWUwAAAiE"]
[Tue Jul 21 07:18:54.619358 2026] [autoindex:error] [pid 229246:tid 229501] [client 4.204.201.85:35408] AH01276: Cannot serve directory /home3/seaport/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:18:54.674982 2026] [security2:error] [pid 229246:tid 229496] [client 20.197.192.193:22840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/berlin.php"] [unique_id "al9HjiBMYeh5YLVG45xWVwAAAow"]
[Tue Jul 21 07:18:54.740899 2026] [security2:error] [pid 229246:tid 229477] [client 4.204.201.85:26617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/dr.php"] [unique_id "al9HjiBMYeh5YLVG45xWXAAAAnk"]
[Tue Jul 21 07:18:54.764838 2026] [security2:error] [pid 229246:tid 229441] [client 20.197.192.193:22790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/billur.php"] [unique_id "al9HjiBMYeh5YLVG45xWXgAAAlU"]
[Tue Jul 21 07:18:54.866482 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:46041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ccs.php"] [unique_id "al9HjiBMYeh5YLVG45xWXwAAAlo"]
[Tue Jul 21 07:18:54.949764 2026] [autoindex:error] [pid 229246:tid 229464] [client 4.204.201.85:35408] AH01276: Cannot serve directory /home3/seaport/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:18:54.966087 2026] [security2:error] [pid 229246:tid 229377] [client 20.197.192.193:22793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/mimpi.php"] [unique_id "al9HjiBMYeh5YLVG45xWYQAAAhU"]
[Tue Jul 21 07:18:55.109903 2026] [security2:error] [pid 229246:tid 229459] [client 4.204.201.85:35346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9HjyBMYeh5YLVG45xWZwAAAmc"]
[Tue Jul 21 07:18:55.157908 2026] [security2:error] [pid 229246:tid 229475] [client 20.197.192.193:22803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/dp.php"] [unique_id "al9HjyBMYeh5YLVG45xWaQAAAnc"]
[Tue Jul 21 07:18:55.251207 2026] [security2:error] [pid 229246:tid 229448] [client 4.204.201.85:26383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/x.php"] [unique_id "al9HjyBMYeh5YLVG45xWcgAAAlw"]
[Tue Jul 21 07:18:55.276354 2026] [security2:error] [pid 229246:tid 229487] [client 20.197.192.193:22820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/bootstrap.php"] [unique_id "al9HjyBMYeh5YLVG45xWcwAAAoM"]
[Tue Jul 21 07:18:55.320945 2026] [security2:error] [pid 229246:tid 229419] [client 20.206.105.145:36061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/a2.php"] [unique_id "al9HjyBMYeh5YLVG45xWdAAAAj8"]
[Tue Jul 21 07:18:55.323899 2026] [security2:error] [pid 229246:tid 229381] [client 20.197.192.193:22832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/wp-editor.php"] [unique_id "al9HjyBMYeh5YLVG45xWdQAAAhk"]
[Tue Jul 21 07:18:55.355970 2026] [security2:error] [pid 229246:tid 229417] [client 20.197.192.193:17654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/cro.php"] [unique_id "al9HjyBMYeh5YLVG45xWdgAAAj0"]
[Tue Jul 21 07:18:55.413775 2026] [security2:error] [pid 229246:tid 229455] [client 20.197.192.193:22819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/cron-tab.php"] [unique_id "al9HjyBMYeh5YLVG45xWdwAAAmM"]
[Tue Jul 21 07:18:55.483546 2026] [security2:error] [pid 229246:tid 229450] [client 20.197.192.193:17652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/koiy.php"] [unique_id "al9HjyBMYeh5YLVG45xWegAAAl4"]
[Tue Jul 21 07:18:55.559918 2026] [security2:error] [pid 229246:tid 229490] [client 20.197.192.193:17435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/hp2.php"] [unique_id "al9HjyBMYeh5YLVG45xWewAAAoY"]
[Tue Jul 21 07:18:55.581671 2026] [security2:error] [pid 229246:tid 229492] [client 4.204.201.85:26595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/155.php"] [unique_id "al9HjyBMYeh5YLVG45xWfQAAAog"]
[Tue Jul 21 07:18:55.660975 2026] [security2:error] [pid 229246:tid 229493] [client 20.197.192.193:22796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/hp3.php"] [unique_id "al9HjyBMYeh5YLVG45xWgQAAAok"]
[Tue Jul 21 07:18:55.739881 2026] [security2:error] [pid 229246:tid 229458] [client 20.197.192.193:17610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/aa1.php"] [unique_id "al9HjyBMYeh5YLVG45xWhQAAAmY"]
[Tue Jul 21 07:18:55.743598 2026] [security2:error] [pid 229246:tid 229451] [client 14.139.42.196:31759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HjyBMYeh5YLVG45xWhgAAAl8"]
[Tue Jul 21 07:18:55.743706 2026] [security2:error] [pid 229246:tid 229451] [client 14.139.42.196:31759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HjyBMYeh5YLVG45xWhgAAAl8"]
[Tue Jul 21 07:18:55.835764 2026] [security2:error] [pid 229246:tid 229491] [client 4.204.201.85:35381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/8.php"] [unique_id "al9HjyBMYeh5YLVG45xWjAAAAoc"]
[Tue Jul 21 07:18:55.873143 2026] [security2:error] [pid 229246:tid 229456] [client 20.197.192.193:17600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/acew67.php"] [unique_id "al9HjyBMYeh5YLVG45xWjQAAAmQ"]
[Tue Jul 21 07:18:56.009254 2026] [security2:error] [pid 229246:tid 229401] [client 20.197.192.193:17627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/bscclapb.php"] [unique_id "al9HkCBMYeh5YLVG45xWjgAAAi0"]
[Tue Jul 21 07:18:56.034686 2026] [security2:error] [pid 229246:tid 229378] [client 4.204.201.85:26571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/ops.php"] [unique_id "al9HkCBMYeh5YLVG45xWjwAAAhY"]
[Tue Jul 21 07:18:56.071881 2026] [security2:error] [pid 229246:tid 229377] [client 20.220.225.223:39539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/ez.php"] [unique_id "al9HkCBMYeh5YLVG45xWkAAAAhU"]
[Tue Jul 21 07:18:56.417506 2026] [security2:error] [pid 229246:tid 229390] [client 4.204.201.85:26373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/file31.php"] [unique_id "al9HkCBMYeh5YLVG45xWnAAAAiI"]
[Tue Jul 21 07:18:56.459858 2026] [security2:error] [pid 229246:tid 229476] [client 20.197.192.193:17613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/else1.php"] [unique_id "al9HkCBMYeh5YLVG45xWoAAAAng"]
[Tue Jul 21 07:18:56.749510 2026] [security2:error] [pid 229246:tid 229452] [client 4.204.201.85:26613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/file6.php"] [unique_id "al9HkCBMYeh5YLVG45xWpQAAAmA"]
[Tue Jul 21 07:18:56.912876 2026] [security2:error] [pid 229246:tid 229454] [client 20.197.192.193:17601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/tkikikoko.php"] [unique_id "al9HkCBMYeh5YLVG45xWqgAAAmI"]
[Tue Jul 21 07:18:56.961882 2026] [security2:error] [pid 229246:tid 229431] [client 20.151.10.161:45981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ccc.php"] [unique_id "al9HkCBMYeh5YLVG45xWrAAAAks"]
[Tue Jul 21 07:18:57.193085 2026] [security2:error] [pid 229246:tid 229399] [client 4.204.201.85:26380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/adminfuns.php"] [unique_id "al9HkSBMYeh5YLVG45xWswAAAis"]
[Tue Jul 21 07:18:57.216594 2026] [security2:error] [pid 229246:tid 229248] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HkSBMYeh5YLVG45xWtQACaAE"]
[Tue Jul 21 07:18:57.216730 2026] [security2:error] [pid 229246:tid 229460] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HkSBMYeh5YLVG45xWtQACaAE"]
[Tue Jul 21 07:18:57.235668 2026] [security2:error] [pid 229246:tid 229409] [client 193.36.225.60:23887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9HkSBMYeh5YLVG45xWtgAAAjU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:18:57.237060 2026] [security2:error] [pid 229246:tid 229456] [client 20.197.192.193:17650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/wp-Blogs.php"] [unique_id "al9HkSBMYeh5YLVG45xWtwAAAmQ"]
[Tue Jul 21 07:18:57.240625 2026] [security2:error] [pid 229246:tid 229482] [client 20.151.10.161:21458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/zz.php"] [unique_id "al9HkSBMYeh5YLVG45xWuQAAAn4"]
[Tue Jul 21 07:18:57.282157 2026] [security2:error] [pid 229246:tid 229497] [client 68.235.38.2:48738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9HkSBMYeh5YLVG45xWvQAAAo0"]
[Tue Jul 21 07:18:57.282251 2026] [security2:error] [pid 229246:tid 229497] [client 68.235.38.2:48738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9HkSBMYeh5YLVG45xWvQAAAo0"]
[Tue Jul 21 07:18:57.359505 2026] [security2:error] [pid 229246:tid 229481] [client 20.197.192.193:17439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/wp-css.php"] [unique_id "al9HkSBMYeh5YLVG45xWvwAAAn0"]
[Tue Jul 21 07:18:57.417101 2026] [security2:error] [pid 229246:tid 229469] [client 20.197.192.193:22786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/wp-explorer.php"] [unique_id "al9HkSBMYeh5YLVG45xWwwAAAnE"]
[Tue Jul 21 07:18:57.471648 2026] [security2:error] [pid 229246:tid 229402] [client 20.197.192.193:22798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/akismet.php"] [unique_id "al9HkSBMYeh5YLVG45xWxgAAAi4"]
[Tue Jul 21 07:18:57.497558 2026] [security2:error] [pid 229246:tid 229284] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HkSBMYeh5YLVG45xWyAACWiU"]
[Tue Jul 21 07:18:57.497696 2026] [security2:error] [pid 229246:tid 229446] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HkSBMYeh5YLVG45xWyAACWiU"]
[Tue Jul 21 07:18:57.507343 2026] [security2:error] [pid 229246:tid 229466] [client 20.197.192.193:22807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/ace2.php"] [unique_id "al9HkSBMYeh5YLVG45xWyQAAAm4"]
[Tue Jul 21 07:18:57.517403 2026] [security2:error] [pid 229246:tid 229403] [client 4.204.201.85:26569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/goods.php"] [unique_id "al9HkSBMYeh5YLVG45xWygAAAi8"]
[Tue Jul 21 07:18:57.551455 2026] [security2:error] [pid 229246:tid 229382] [client 20.197.192.193:22826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/ms.php"] [unique_id "al9HkSBMYeh5YLVG45xWzAAAAho"]
[Tue Jul 21 07:18:57.828707 2026] [security2:error] [pid 229246:tid 229474] [client 4.204.201.85:26412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/100.php"] [unique_id "al9HkSBMYeh5YLVG45xWzwAAAnY"]
[Tue Jul 21 07:18:57.944893 2026] [security2:error] [pid 229246:tid 229379] [client 20.206.105.145:36161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/file15.php"] [unique_id "al9HkSBMYeh5YLVG45xW1QAAAhc"]
[Tue Jul 21 07:18:58.070024 2026] [security2:error] [pid 229246:tid 229458] [client 20.220.225.223:52771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/fz.php"] [unique_id "al9HkiBMYeh5YLVG45xW1gAAAmY"]
[Tue Jul 21 07:18:58.093871 2026] [security2:error] [pid 229246:tid 229496] [client 4.204.201.85:35363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9HkiBMYeh5YLVG45xW1wAAAow"]
[Tue Jul 21 07:18:58.213140 2026] [security2:error] [pid 229246:tid 229395] [client 4.204.201.85:26375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/about.php"] [unique_id "al9HkiBMYeh5YLVG45xW2wAAAic"]
[Tue Jul 21 07:18:58.273507 2026] [security2:error] [pid 229246:tid 229452] [client 139.135.44.145:54632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HkiBMYeh5YLVG45xW3AAAAmA"]
[Tue Jul 21 07:18:58.273627 2026] [security2:error] [pid 229246:tid 229452] [client 139.135.44.145:54632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HkiBMYeh5YLVG45xW3AAAAmA"]
[Tue Jul 21 07:18:58.431424 2026] [security2:error] [pid 229246:tid 229418] [client 20.206.105.145:36082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/jp.php"] [unique_id "al9HkiBMYeh5YLVG45xW3gAAAj4"]
[Tue Jul 21 07:18:58.505876 2026] [security2:error] [pid 229246:tid 229463] [client 20.151.10.161:21502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/for.php"] [unique_id "al9HkiBMYeh5YLVG45xW5gAAAms"]
[Tue Jul 21 07:18:58.579456 2026] [security2:error] [pid 229246:tid 229490] [client 74.244.195.153:47569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.195.244.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9HkiBMYeh5YLVG45xW6AAAAoY"]
[Tue Jul 21 07:18:58.586604 2026] [security2:error] [pid 229246:tid 229490] [client 74.244.195.153:47569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9HkiBMYeh5YLVG45xW6AAAAoY"]
[Tue Jul 21 07:18:58.663406 2026] [security2:error] [pid 229246:tid 229467] [client 20.151.10.161:53578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9HkiBMYeh5YLVG45xW6gAAAm8"]
[Tue Jul 21 07:18:58.681115 2026] [security2:error] [pid 229246:tid 229294] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9HkiBMYeh5YLVG45xW6wACcS8"]
[Tue Jul 21 07:18:58.695695 2026] [security2:error] [pid 229246:tid 229266] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HkiBMYeh5YLVG45xW7AACVBM"]
[Tue Jul 21 07:18:58.698697 2026] [security2:error] [pid 229246:tid 229501] [client 4.204.201.85:26590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/about.php"] [unique_id "al9HkiBMYeh5YLVG45xW7QAAApE"]
[Tue Jul 21 07:18:58.772518 2026] [security2:error] [pid 229246:tid 229291] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/xyn.php"] [unique_id "al9HkiBMYeh5YLVG45xW8gACNiw"]
[Tue Jul 21 07:18:58.779788 2026] [security2:error] [pid 229246:tid 229296] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HkiBMYeh5YLVG45xW8wACQzE"]
[Tue Jul 21 07:18:58.779925 2026] [security2:error] [pid 229246:tid 229423] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HkiBMYeh5YLVG45xW8wACQzE"]
[Tue Jul 21 07:18:58.822530 2026] [security2:error] [pid 229246:tid 229308] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/patie.php"] [unique_id "al9HkiBMYeh5YLVG45xW9AAChT0"]
[Tue Jul 21 07:18:59.116074 2026] [proxy:error] [pid 229246:tid 229419] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:18:59.116120 2026] [proxy_http:error] [pid 229246:tid 229419] [client 146.190.25.162:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:18:59.116722 2026] [proxy:error] [pid 229246:tid 229419] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:18:59.116742 2026] [proxy_http:error] [pid 229246:tid 229419] [client 146.190.25.162:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:18:59.118964 2026] [security2:error] [pid 229246:tid 229493] [client 20.151.10.161:53631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HkyBMYeh5YLVG45xW_wAAAok"]
[Tue Jul 21 07:18:59.147119 2026] [security2:error] [pid 229246:tid 229413] [client 20.151.10.161:46064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/get.php"] [unique_id "al9HkyBMYeh5YLVG45xXAQAAAjk"]
[Tue Jul 21 07:18:59.147522 2026] [security2:error] [pid 229246:tid 229431] [client 4.204.201.85:26406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/admin.php"] [unique_id "al9HkyBMYeh5YLVG45xXAgAAAks"]
[Tue Jul 21 07:18:59.182197 2026] [security2:error] [pid 229246:tid 229468] [client 45.251.232.145:58028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HkyBMYeh5YLVG45xXAwAAAnA"]
[Tue Jul 21 07:18:59.182315 2026] [security2:error] [pid 229246:tid 229468] [client 45.251.232.145:58028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HkyBMYeh5YLVG45xXAwAAAnA"]
[Tue Jul 21 07:18:59.324345 2026] [security2:error] [pid 229246:tid 229307] [remote 68.178.160.25:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9HkyBMYeh5YLVG45xXBgACHTw"]
[Tue Jul 21 07:18:59.332790 2026] [security2:error] [pid 229246:tid 229313] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HkyBMYeh5YLVG45xXBwACIEI"]
[Tue Jul 21 07:18:59.332984 2026] [security2:error] [pid 229246:tid 229388] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HkyBMYeh5YLVG45xXBwACIEI"]
[Tue Jul 21 07:18:59.416010 2026] [proxy:error] [pid 229246:tid 229453] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:18:59.416073 2026] [proxy_http:error] [pid 229246:tid 229453] [client 146.190.25.162:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.brunopacolla1749139258240.0721679.meusitehostgator.com.br/
[Tue Jul 21 07:18:59.416762 2026] [proxy:error] [pid 229246:tid 229453] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:18:59.416787 2026] [proxy_http:error] [pid 229246:tid 229453] [client 146.190.25.162:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.brunopacolla1749139258240.0721679.meusitehostgator.com.br/
[Tue Jul 21 07:18:59.587221 2026] [security2:error] [pid 229246:tid 229462] [client 4.204.201.85:26377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/admin.php"] [unique_id "al9HkyBMYeh5YLVG45xXGAAAAmo"]
[Tue Jul 21 07:18:59.621904 2026] [security2:error] [pid 229246:tid 229475] [client 20.151.10.161:55253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/x.php"] [unique_id "al9HkyBMYeh5YLVG45xXGgAAAnc"]
[Tue Jul 21 07:18:59.674414 2026] [security2:error] [pid 229246:tid 229464] [client 74.7.230.14:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cristianepbbegosso1748480777915.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9HkyBMYeh5YLVG45xXHAACbEk"]
[Tue Jul 21 07:18:59.899726 2026] [security2:error] [pid 229246:tid 229470] [client 20.226.60.151:54468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/loader.php"] [unique_id "al9HkyBMYeh5YLVG45xXHwAAAnI"]
[Tue Jul 21 07:18:59.984903 2026] [security2:error] [pid 229246:tid 229429] [client 4.204.201.85:35344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/f6.php"] [unique_id "al9HkyBMYeh5YLVG45xXIwAAAkk"]
[Tue Jul 21 07:19:00.070762 2026] [security2:error] [pid 229246:tid 229419] [client 4.204.201.85:26604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/themes.php"] [unique_id "al9HlCBMYeh5YLVG45xXKQAAAj8"]
[Tue Jul 21 07:19:00.109335 2026] [security2:error] [pid 229246:tid 229414] [client 20.220.225.223:52775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/la.php"] [unique_id "al9HlCBMYeh5YLVG45xXLAAAAjo"]
[Tue Jul 21 07:19:00.155780 2026] [security2:error] [pid 229246:tid 229389] [client 20.151.10.161:55253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/j260624_13.php"] [unique_id "al9HlCBMYeh5YLVG45xXLQAAAiE"]
[Tue Jul 21 07:19:00.158222 2026] [security2:error] [pid 229246:tid 229474] [client 20.151.10.161:21378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/yup.php"] [unique_id "al9HlCBMYeh5YLVG45xXLgAAAnY"]
[Tue Jul 21 07:19:00.200683 2026] [security2:error] [pid 229246:tid 229379] [client 68.235.38.2:38400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9HlCBMYeh5YLVG45xXLwAAAhc"]
[Tue Jul 21 07:19:00.200789 2026] [security2:error] [pid 229246:tid 229379] [client 68.235.38.2:38400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9HlCBMYeh5YLVG45xXLwAAAhc"]
[Tue Jul 21 07:19:00.339033 2026] [security2:error] [pid 229246:tid 229458] [client 20.206.105.145:35851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/f35.php"] [unique_id "al9HlCBMYeh5YLVG45xXMgAAAmY"]
[Tue Jul 21 07:19:00.727606 2026] [security2:error] [pid 229246:tid 229490] [client 20.151.10.161:53585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/d62.php"] [unique_id "al9HlCBMYeh5YLVG45xXQAAAAoY"]
[Tue Jul 21 07:19:00.929041 2026] [security2:error] [pid 229246:tid 229463] [client 4.204.201.85:26618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/.well-known/about.php"] [unique_id "al9HlCBMYeh5YLVG45xXRQAAAms"]
[Tue Jul 21 07:19:00.963466 2026] [security2:error] [pid 229246:tid 229406] [client 20.206.105.145:35971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/wp-load.php"] [unique_id "al9HlCBMYeh5YLVG45xXRwAAAjI"]
[Tue Jul 21 07:19:00.969033 2026] [security2:error] [pid 229246:tid 229423] [client 20.151.10.161:45969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/images.php"] [unique_id "al9HlCBMYeh5YLVG45xXSAAAAkM"]
[Tue Jul 21 07:19:00.992991 2026] [security2:error] [pid 229246:tid 229341] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/aa.php"] [unique_id "al9HlCBMYeh5YLVG45xXSQACPF4"]
[Tue Jul 21 07:19:01.022383 2026] [security2:error] [pid 229246:tid 229345] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/xwpg.php"] [unique_id "al9HlSBMYeh5YLVG45xXSwACcmI"]
[Tue Jul 21 07:19:01.039186 2026] [security2:error] [pid 229246:tid 229346] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/ops.php"] [unique_id "al9HlSBMYeh5YLVG45xXTAACg2M"]
[Tue Jul 21 07:19:01.054166 2026] [security2:error] [pid 229246:tid 229344] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/mac.php"] [unique_id "al9HlSBMYeh5YLVG45xXTQACgmE"]
[Tue Jul 21 07:19:01.068323 2026] [security2:error] [pid 229246:tid 229335] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/mg.php"] [unique_id "al9HlSBMYeh5YLVG45xXTgACSVg"]
[Tue Jul 21 07:19:01.081859 2026] [security2:error] [pid 229246:tid 229494] [client 175.45.70.82:62386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HlSBMYeh5YLVG45xXTwAAAoo"]
[Tue Jul 21 07:19:01.081998 2026] [security2:error] [pid 229246:tid 229494] [client 175.45.70.82:62386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HlSBMYeh5YLVG45xXTwAAAoo"]
[Tue Jul 21 07:19:01.082173 2026] [security2:error] [pid 229246:tid 229348] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-post-data.php"] [unique_id "al9HlSBMYeh5YLVG45xXUAACL2U"]
[Tue Jul 21 07:19:01.103473 2026] [security2:error] [pid 229246:tid 229338] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/pucci.php"] [unique_id "al9HlSBMYeh5YLVG45xXVwACTVs"]
[Tue Jul 21 07:19:01.116302 2026] [security2:error] [pid 229246:tid 229467] [client 193.36.225.57:50793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9HlCBMYeh5YLVG45xXRgAAAm8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:01.118080 2026] [security2:error] [pid 229246:tid 229352] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/black.php"] [unique_id "al9HlSBMYeh5YLVG45xXWAACdmk"]
[Tue Jul 21 07:19:01.149308 2026] [security2:error] [pid 229246:tid 229340] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/zlece.php"] [unique_id "al9HlSBMYeh5YLVG45xXWQACRl0"]
[Tue Jul 21 07:19:01.195591 2026] [security2:error] [pid 229246:tid 229349] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/vssrs.php"] [unique_id "al9HlSBMYeh5YLVG45xXWgACHGY"]
[Tue Jul 21 07:19:01.245493 2026] [security2:error] [pid 229246:tid 229347] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wicked.php"] [unique_id "al9HlSBMYeh5YLVG45xXXAACGGQ"]
[Tue Jul 21 07:19:01.259524 2026] [security2:error] [pid 229246:tid 229343] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/24.php"] [unique_id "al9HlSBMYeh5YLVG45xXXgACPWA"]
[Tue Jul 21 07:19:01.274955 2026] [security2:error] [pid 229246:tid 229350] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/xacs.php"] [unique_id "al9HlSBMYeh5YLVG45xXYAACLGc"]
[Tue Jul 21 07:19:01.290296 2026] [security2:error] [pid 229246:tid 229357] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/zildan.php"] [unique_id "al9HlSBMYeh5YLVG45xXYwACaW4"]
[Tue Jul 21 07:19:01.294016 2026] [security2:error] [pid 229246:tid 229396] [client 4.204.201.85:26598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9HlSBMYeh5YLVG45xXZAAAAig"]
[Tue Jul 21 07:19:01.305054 2026] [security2:error] [pid 229246:tid 229363] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/csa.php"] [unique_id "al9HlSBMYeh5YLVG45xXZQACe3Q"]
[Tue Jul 21 07:19:01.354849 2026] [security2:error] [pid 229246:tid 229378] [client 20.151.10.161:45996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/alls.php"] [unique_id "al9HlSBMYeh5YLVG45xXaAAAAhY"]
[Tue Jul 21 07:19:01.391456 2026] [security2:error] [pid 229246:tid 229497] [client 20.206.105.145:36060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/xwpg.php"] [unique_id "al9HlSBMYeh5YLVG45xXagAAAo0"]
[Tue Jul 21 07:19:01.452882 2026] [security2:error] [pid 229246:tid 229409] [client 20.151.10.161:53630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ups.php"] [unique_id "al9HlSBMYeh5YLVG45xXawAAAjU"]
[Tue Jul 21 07:19:01.640314 2026] [security2:error] [pid 229246:tid 229457] [client 4.204.201.85:26588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/wefile.php"] [unique_id "al9HlSBMYeh5YLVG45xXcwAAAmU"]
[Tue Jul 21 07:19:01.645586 2026] [security2:error] [pid 229246:tid 229371] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/w3llscc.php"] [unique_id "al9HlSBMYeh5YLVG45xXdAACVXw"]
[Tue Jul 21 07:19:01.670884 2026] [security2:error] [pid 229246:tid 229365] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wpx.php"] [unique_id "al9HlSBMYeh5YLVG45xXdQACcXY"]
[Tue Jul 21 07:19:01.711384 2026] [security2:error] [pid 229246:tid 229250] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-css.php"] [unique_id "al9HlSBMYeh5YLVG45xXeAACXAM"]
[Tue Jul 21 07:19:01.743517 2026] [security2:error] [pid 229246:tid 229262] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/ho.php"] [unique_id "al9HlSBMYeh5YLVG45xXegAChQ8"]
[Tue Jul 21 07:19:01.875949 2026] [security2:error] [pid 229246:tid 229429] [client 184.75.221.3:46292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9HlSBMYeh5YLVG45xXewAAAkk"]
[Tue Jul 21 07:19:01.876046 2026] [security2:error] [pid 229246:tid 229429] [client 184.75.221.3:46292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9HlSBMYeh5YLVG45xXewAAAkk"]
[Tue Jul 21 07:19:01.917295 2026] [security2:error] [pid 229246:tid 229466] [client 20.151.10.161:53609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/k.php"] [unique_id "al9HlSBMYeh5YLVG45xXfQAAAm4"]
[Tue Jul 21 07:19:02.059053 2026] [security2:error] [pid 229246:tid 229454] [client 4.204.201.85:26611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9HliBMYeh5YLVG45xXgAAAAmI"]
[Tue Jul 21 07:19:02.060340 2026] [security2:error] [pid 229246:tid 229280] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HliBMYeh5YLVG45xXgQACLyE"]
[Tue Jul 21 07:19:02.060504 2026] [security2:error] [pid 229246:tid 229403] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HliBMYeh5YLVG45xXgQACLyE"]
[Tue Jul 21 07:19:02.083494 2026] [security2:error] [pid 229246:tid 229452] [client 120.61.173.56:50594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HliBMYeh5YLVG45xXgwAAAmA"]
[Tue Jul 21 07:19:02.083647 2026] [security2:error] [pid 229246:tid 229452] [client 120.61.173.56:50594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HliBMYeh5YLVG45xXgwAAAmA"]
[Tue Jul 21 07:19:02.097766 2026] [security2:error] [pid 229246:tid 229419] [client 4.204.201.85:35400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/inputs.php"] [unique_id "al9HliBMYeh5YLVG45xXhAAAAj8"]
[Tue Jul 21 07:19:02.277348 2026] [security2:error] [pid 229246:tid 229257] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HliBMYeh5YLVG45xXjQACIAo"]
[Tue Jul 21 07:19:02.277522 2026] [security2:error] [pid 229246:tid 229388] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HliBMYeh5YLVG45xXjQACIAo"]
[Tue Jul 21 07:19:02.293378 2026] [security2:error] [pid 229246:tid 229396] [client 20.206.105.145:36162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/waf.php"] [unique_id "al9HliBMYeh5YLVG45xXjgAAAig"]
[Tue Jul 21 07:19:02.348294 2026] [security2:error] [pid 229246:tid 229479] [client 20.151.10.161:46036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/yyu.php"] [unique_id "al9HliBMYeh5YLVG45xXkAAAAns"]
[Tue Jul 21 07:19:02.390665 2026] [security2:error] [pid 229246:tid 229436] [client 20.151.10.161:53620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/k2.php"] [unique_id "al9HliBMYeh5YLVG45xXkgAAAlA"]
[Tue Jul 21 07:19:02.438267 2026] [security2:error] [pid 229246:tid 229476] [client 20.206.105.145:35984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/xstelth.php"] [unique_id "al9HliBMYeh5YLVG45xXlAAAAng"]
[Tue Jul 21 07:19:02.478873 2026] [security2:error] [pid 229246:tid 229482] [client 20.206.105.145:35884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/wp-links.php"] [unique_id "al9HliBMYeh5YLVG45xXlQAAAn4"]
[Tue Jul 21 07:19:02.503856 2026] [security2:error] [pid 229246:tid 229484] [client 20.206.105.145:36195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9HliBMYeh5YLVG45xXlwAAAoA"]
[Tue Jul 21 07:19:02.536687 2026] [security2:error] [pid 229246:tid 229462] [client 20.206.105.145:36165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/aaa.php"] [unique_id "al9HliBMYeh5YLVG45xXmQAAAmo"]
[Tue Jul 21 07:19:02.637234 2026] [security2:error] [pid 229246:tid 229278] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/xy.php"] [unique_id "al9HliBMYeh5YLVG45xXoAACfR8"]
[Tue Jul 21 07:19:02.638917 2026] [security2:error] [pid 229246:tid 229457] [client 4.204.201.85:26006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9HliBMYeh5YLVG45xXoQAAAmU"]
[Tue Jul 21 07:19:02.801649 2026] [security2:error] [pid 229246:tid 229448] [client 20.220.225.223:43033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9HliBMYeh5YLVG45xXowAAAlw"]
[Tue Jul 21 07:19:02.855949 2026] [security2:error] [pid 229246:tid 229401] [client 114.119.130.33:57485] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "carrosselbuique.com.br"] [uri "/wp-content/uploads/2017/07/CONTE%C3%9ADOS-PARA-RECUPERA%C3%87%C3%83O-I-SEMESTRE.docx"] [unique_id "al9HliBMYeh5YLVG45xXpQAAAi0"], referer: https://carrosselbuique.com.br/wp-content/uploads/2017/07/CONTE%C3%9ADOS-PARA-RECUPERA%C3%87%C3%83O-I-SEMESTRE.docx
[Tue Jul 21 07:19:02.923225 2026] [security2:error] [pid 229246:tid 229501] [client 4.204.201.85:26620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/8.php"] [unique_id "al9HliBMYeh5YLVG45xXpgAAApE"]
[Tue Jul 21 07:19:02.960326 2026] [security2:error] [pid 229246:tid 229410] [client 20.151.10.161:21312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/wpxml.php"] [unique_id "al9HliBMYeh5YLVG45xXqAAAAjY"]
[Tue Jul 21 07:19:03.097808 2026] [security2:error] [pid 229246:tid 229377] [client 20.151.10.161:53590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/k3.php"] [unique_id "al9HlyBMYeh5YLVG45xXqgAAAhU"]
[Tue Jul 21 07:19:03.256526 2026] [security2:error] [pid 229246:tid 229419] [client 20.151.10.161:46046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/by.php"] [unique_id "al9HlyBMYeh5YLVG45xXsAAAAj8"]
[Tue Jul 21 07:19:03.269610 2026] [security2:error] [pid 229246:tid 229431] [client 4.204.201.85:26391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9HlyBMYeh5YLVG45xXsQAAAks"]
[Tue Jul 21 07:19:03.448923 2026] [autoindex:error] [pid 229246:tid 229384] [client 147.185.132.231:58302] AH01276: Cannot serve directory /home4/dralul00/idufinance.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:03.648714 2026] [security2:error] [pid 229246:tid 229390] [client 4.204.201.85:26044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/f6.php"] [unique_id "al9HlyBMYeh5YLVG45xXugAAAiI"]
[Tue Jul 21 07:19:03.651058 2026] [security2:error] [pid 229246:tid 229264] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HlyBMYeh5YLVG45xXuwACHxE"]
[Tue Jul 21 07:19:03.651173 2026] [security2:error] [pid 229246:tid 229387] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HlyBMYeh5YLVG45xXuwACHxE"]
[Tue Jul 21 07:19:03.750554 2026] [security2:error] [pid 229246:tid 229491] [client 20.10.88.227:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "arthromdcanada.online"] [uri "/index.php"] [unique_id "al9HlyBMYeh5YLVG45xXwwAAAoc"]
[Tue Jul 21 07:19:03.751809 2026] [security2:error] [pid 229246:tid 229499] [client 20.10.88.227:2371] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "arthromdcanada.online"] [uri "/robots.txt"] [unique_id "al9HlyBMYeh5YLVG45xXwAAAAo8"]
[Tue Jul 21 07:19:03.968059 2026] [security2:error] [pid 229246:tid 229490] [client 4.204.201.85:26602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/inputs.php"] [unique_id "al9HlyBMYeh5YLVG45xXxgAAAoY"]
[Tue Jul 21 07:19:04.247401 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:45921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/FAQ.php"] [unique_id "al9HmCBMYeh5YLVG45xXzQAAAlo"]
[Tue Jul 21 07:19:04.275939 2026] [security2:error] [pid 229246:tid 229470] [client 4.204.201.85:26429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/inputs.php"] [unique_id "al9HmCBMYeh5YLVG45xXzgAAAnI"]
[Tue Jul 21 07:19:04.409880 2026] [security2:error] [pid 229246:tid 229265] [remote 47.128.44.67:29658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gradiente.com.br"] [uri "/soundbar-1000w-woofer-5-2-3d-arc-optica-bth-usb-gst107---gradiente-bivolt/p"] [unique_id "al9HmCBMYeh5YLVG45xX0wACbhI"]
[Tue Jul 21 07:19:04.708546 2026] [security2:error] [pid 229246:tid 229417] [client 4.204.201.85:26603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/classwithtostring.php"] [unique_id "al9HmCBMYeh5YLVG45xX2gAAAj0"]
[Tue Jul 21 07:19:04.857841 2026] [security2:error] [pid 229246:tid 229378] [client 193.36.225.55:47165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9HmCBMYeh5YLVG45xX3wAAAhY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:04.878780 2026] [security2:error] [pid 229246:tid 229301] [remote 182.77.62.24:55128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-login.php"] [unique_id "al9HmCBMYeh5YLVG45xX4AACKTY"]
[Tue Jul 21 07:19:04.913604 2026] [security2:error] [pid 229246:tid 229489] [client 103.162.129.114:55951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9HmCBMYeh5YLVG45xX4QAAAoU"]
[Tue Jul 21 07:19:04.913773 2026] [security2:error] [pid 229246:tid 229489] [client 103.162.129.114:55951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9HmCBMYeh5YLVG45xX4QAAAoU"]
[Tue Jul 21 07:19:04.917533 2026] [security2:error] [pid 229246:tid 229390] [client 20.151.10.161:46054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/coffexium.php"] [unique_id "al9HmCBMYeh5YLVG45xX4gAAAiI"]
[Tue Jul 21 07:19:04.918863 2026] [security2:error] [pid 229246:tid 229482] [client 20.226.60.151:54518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/spadex.php"] [unique_id "al9HmCBMYeh5YLVG45xX4wAAAn4"]
[Tue Jul 21 07:19:05.131223 2026] [security2:error] [pid 229246:tid 229414] [client 103.121.156.110:58746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HmSBMYeh5YLVG45xX5QAAAjo"]
[Tue Jul 21 07:19:05.131357 2026] [security2:error] [pid 229246:tid 229414] [client 103.121.156.110:58746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HmSBMYeh5YLVG45xX5QAAAjo"]
[Tue Jul 21 07:19:05.220949 2026] [security2:error] [pid 229246:tid 229483] [client 4.204.201.85:26382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9HmSBMYeh5YLVG45xX6QAAAn8"]
[Tue Jul 21 07:19:05.255746 2026] [security2:error] [pid 229246:tid 229434] [client 20.206.67.15:61300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9HmSBMYeh5YLVG45xX7QAAAk4"]
[Tue Jul 21 07:19:05.283090 2026] [security2:error] [pid 229246:tid 229481] [client 20.206.67.15:61268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HmSBMYeh5YLVG45xX7wAAAn0"]
[Tue Jul 21 07:19:05.321984 2026] [security2:error] [pid 229246:tid 229469] [client 20.206.67.15:61243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/sql.php"] [unique_id "al9HmSBMYeh5YLVG45xX8AAAAnE"]
[Tue Jul 21 07:19:05.372113 2026] [security2:error] [pid 229246:tid 229448] [client 20.151.10.161:53615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/k4.php"] [unique_id "al9HmSBMYeh5YLVG45xX8gAAAlw"]
[Tue Jul 21 07:19:05.380700 2026] [security2:error] [pid 229246:tid 229501] [client 20.206.67.15:61219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/1index.php"] [unique_id "al9HmSBMYeh5YLVG45xX8wAAApE"]
[Tue Jul 21 07:19:05.381786 2026] [security2:error] [pid 229246:tid 229451] [client 20.151.10.161:46044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/red.php"] [unique_id "al9HmSBMYeh5YLVG45xX9AAAAl8"]
[Tue Jul 21 07:19:05.411956 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:51404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/fffm.php"] [unique_id "al9HmSBMYeh5YLVG45xX9gAAAlo"]
[Tue Jul 21 07:19:05.457529 2026] [security2:error] [pid 229246:tid 229377] [client 20.206.67.15:61273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/reop1.php"] [unique_id "al9HmSBMYeh5YLVG45xX9wAAAhU"]
[Tue Jul 21 07:19:05.517650 2026] [security2:error] [pid 229246:tid 229454] [client 20.206.67.15:61283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/trusj18.php"] [unique_id "al9HmSBMYeh5YLVG45xX-QAAAmI"]
[Tue Jul 21 07:19:05.526738 2026] [security2:error] [pid 229246:tid 229423] [client 20.197.192.193:8365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patihipopressivo.com.br"] [uri "/hunter.php"] [unique_id "al9HmSBMYeh5YLVG45xX-gAAAkM"]
[Tue Jul 21 07:19:05.620155 2026] [security2:error] [pid 229246:tid 229496] [client 20.206.67.15:61206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/trusj15.php"] [unique_id "al9HmSBMYeh5YLVG45xX_wAAAow"]
[Tue Jul 21 07:19:05.655434 2026] [security2:error] [pid 229246:tid 229380] [client 20.206.67.15:61184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/rft8.php"] [unique_id "al9HmSBMYeh5YLVG45xYAQAAAhg"]
[Tue Jul 21 07:19:05.691853 2026] [security2:error] [pid 229246:tid 229436] [client 4.204.201.85:35388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/inputs.php"] [unique_id "al9HmSBMYeh5YLVG45xYAgAAAlA"]
[Tue Jul 21 07:19:05.730656 2026] [security2:error] [pid 229246:tid 229378] [client 4.204.201.85:26386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/wp-blog.php"] [unique_id "al9HmSBMYeh5YLVG45xYAwAAAhY"]
[Tue Jul 21 07:19:05.758616 2026] [security2:error] [pid 229246:tid 229497] [client 20.206.67.15:61274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/ai.php"] [unique_id "al9HmSBMYeh5YLVG45xYBAAAAo0"]
[Tue Jul 21 07:19:05.914110 2026] [security2:error] [pid 229246:tid 229384] [client 20.206.67.15:61245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/fx.php"] [unique_id "al9HmSBMYeh5YLVG45xYCwAAAhw"]
[Tue Jul 21 07:19:06.095082 2026] [security2:error] [pid 229246:tid 229459] [client 20.151.10.161:45958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9HmiBMYeh5YLVG45xYDwAAAmc"]
[Tue Jul 21 07:19:06.110452 2026] [security2:error] [pid 229246:tid 229392] [client 20.151.10.161:55250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/k5.php"] [unique_id "al9HmiBMYeh5YLVG45xYEAAAAiQ"]
[Tue Jul 21 07:19:06.162840 2026] [security2:error] [pid 229246:tid 229434] [client 20.206.67.15:61199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/xxx.php"] [unique_id "al9HmiBMYeh5YLVG45xYFQAAAk4"]
[Tue Jul 21 07:19:06.232829 2026] [security2:error] [pid 229246:tid 229395] [client 20.206.67.15:61204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/dropdown.php"] [unique_id "al9HmiBMYeh5YLVG45xYGgAAAic"]
[Tue Jul 21 07:19:06.238849 2026] [autoindex:error] [pid 229246:tid 229424] [client 66.132.172.205:26998] AH01276: Cannot serve directory /home4/ciclod61/homemsedutoronline.store/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:06.260124 2026] [security2:error] [pid 229246:tid 229418] [client 20.220.225.223:39523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/inso.php"] [unique_id "al9HmiBMYeh5YLVG45xYGwAAAj4"]
[Tue Jul 21 07:19:06.261765 2026] [security2:error] [pid 229246:tid 229478] [client 20.206.67.15:61185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/file11.php"] [unique_id "al9HmiBMYeh5YLVG45xYHAAAAno"]
[Tue Jul 21 07:19:06.343027 2026] [security2:error] [pid 229246:tid 229487] [client 20.206.67.15:61217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/png.php"] [unique_id "al9HmiBMYeh5YLVG45xYIQAAAoM"]
[Tue Jul 21 07:19:06.380741 2026] [security2:error] [pid 229246:tid 229445] [client 20.206.67.15:61257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-slss.php"] [unique_id "al9HmiBMYeh5YLVG45xYIgAAAlk"]
[Tue Jul 21 07:19:06.457159 2026] [security2:error] [pid 229246:tid 229426] [client 14.139.42.196:14272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HmiBMYeh5YLVG45xYJAAAAkY"]
[Tue Jul 21 07:19:06.457268 2026] [security2:error] [pid 229246:tid 229426] [client 14.139.42.196:14272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HmiBMYeh5YLVG45xYJAAAAkY"]
[Tue Jul 21 07:19:06.514589 2026] [security2:error] [pid 229246:tid 229393] [client 20.206.67.15:61235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/ah25.php"] [unique_id "al9HmiBMYeh5YLVG45xYJQAAAiU"]
[Tue Jul 21 07:19:06.540005 2026] [security2:error] [pid 229246:tid 229329] [remote 173.252.95.25:56340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9HmiBMYeh5YLVG45xYJgACblI"]
[Tue Jul 21 07:19:06.553362 2026] [security2:error] [pid 229246:tid 229417] [client 4.204.201.85:26573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9HmiBMYeh5YLVG45xYKAAAAj0"]
[Tue Jul 21 07:19:06.560869 2026] [security2:error] [pid 229246:tid 229474] [client 20.151.10.161:50355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/gecko.php"] [unique_id "al9HmiBMYeh5YLVG45xYKQAAAnY"]
[Tue Jul 21 07:19:06.713240 2026] [security2:error] [pid 229246:tid 229396] [client 20.206.67.15:61303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/ccou.php"] [unique_id "al9HmiBMYeh5YLVG45xYLAAAAig"]
[Tue Jul 21 07:19:06.762333 2026] [security2:error] [pid 229246:tid 229476] [client 20.206.67.15:59648] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/1.php"] [unique_id "al9HmiBMYeh5YLVG45xYLQAAAng"]
[Tue Jul 21 07:19:06.762439 2026] [security2:error] [pid 229246:tid 229476] [client 20.206.67.15:59648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/1.php"] [unique_id "al9HmiBMYeh5YLVG45xYLQAAAng"]
[Tue Jul 21 07:19:06.779618 2026] [security2:error] [pid 229246:tid 229463] [client 20.206.67.15:61226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/900.php"] [unique_id "al9HmiBMYeh5YLVG45xYLgAAAms"]
[Tue Jul 21 07:19:06.795195 2026] [security2:error] [pid 229246:tid 229400] [client 20.197.192.193:9410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patihipopressivo.com.br"] [uri "/we.php"] [unique_id "al9HmiBMYeh5YLVG45xYLwAAAiw"]
[Tue Jul 21 07:19:06.838995 2026] [security2:error] [pid 229246:tid 229462] [client 20.206.67.15:61246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/file59.php"] [unique_id "al9HmiBMYeh5YLVG45xYMwAAAmo"]
[Tue Jul 21 07:19:06.911141 2026] [security2:error] [pid 229246:tid 229483] [client 4.204.201.85:35334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/classwithtostring.php"] [unique_id "al9HmiBMYeh5YLVG45xYNwAAAn8"]
[Tue Jul 21 07:19:06.932737 2026] [security2:error] [pid 229246:tid 229424] [client 20.206.67.15:59673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/amxloxxr.php"] [unique_id "al9HmiBMYeh5YLVG45xYOAAAAkQ"]
[Tue Jul 21 07:19:06.965029 2026] [security2:error] [pid 229246:tid 229441] [client 20.206.67.15:61279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/aboutc.php"] [unique_id "al9HmiBMYeh5YLVG45xYOQAAAlU"]
[Tue Jul 21 07:19:07.007591 2026] [security2:error] [pid 229246:tid 229418] [client 20.206.67.15:61308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/bless18.php"] [unique_id "al9HmyBMYeh5YLVG45xYOgAAAj4"]
[Tue Jul 21 07:19:07.018669 2026] [security2:error] [pid 229246:tid 229326] [remote 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/wp-admin/install.php"] [unique_id "al9HmyBMYeh5YLVG45xYOwACj08"]
[Tue Jul 21 07:19:07.047448 2026] [security2:error] [pid 229246:tid 229501] [client 4.204.201.85:26596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/ms-edit.php"] [unique_id "al9HmyBMYeh5YLVG45xYPQAAApE"]
[Tue Jul 21 07:19:07.104681 2026] [security2:error] [pid 229246:tid 229446] [client 20.206.67.15:61215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/crgio.php"] [unique_id "al9HmyBMYeh5YLVG45xYQQAAAlo"]
[Tue Jul 21 07:19:07.169883 2026] [security2:error] [pid 229246:tid 229488] [client 20.151.10.161:53617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/w.php"] [unique_id "al9HmyBMYeh5YLVG45xYRgAAAoQ"]
[Tue Jul 21 07:19:07.182003 2026] [security2:error] [pid 229246:tid 229290] [remote 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9HmyBMYeh5YLVG45xYRwACcCs"]
[Tue Jul 21 07:19:07.332099 2026] [security2:error] [pid 229246:tid 229445] [client 173.252.95.25:56352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9HmyBMYeh5YLVG45xYSwAAAlk"]
[Tue Jul 21 07:19:07.349070 2026] [security2:error] [pid 229246:tid 229426] [client 20.151.10.161:46021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/footer.php"] [unique_id "al9HmyBMYeh5YLVG45xYTgAAAkY"]
[Tue Jul 21 07:19:07.404953 2026] [security2:error] [pid 229246:tid 229461] [client 20.151.10.161:21410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/a1.php"] [unique_id "al9HmyBMYeh5YLVG45xYUQAAAmk"]
[Tue Jul 21 07:19:07.671270 2026] [security2:error] [pid 229246:tid 229400] [client 20.206.67.15:61262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-act.php"] [unique_id "al9HmyBMYeh5YLVG45xYVwAAAiw"]
[Tue Jul 21 07:19:07.706480 2026] [security2:error] [pid 229246:tid 229414] [client 20.197.192.193:27140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/kq1.php"] [unique_id "al9HmyBMYeh5YLVG45xYWAAAAjo"]
[Tue Jul 21 07:19:07.710364 2026] [security2:error] [pid 229246:tid 229404] [client 185.198.240.10:26801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mbarcondicionados.com.br"] [uri "/wp-login.php"] [unique_id "al9HmiBMYeh5YLVG45xYKwAAAjA"]
[Tue Jul 21 07:19:07.728655 2026] [security2:error] [pid 229246:tid 229345] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HmyBMYeh5YLVG45xYWQACImI"]
[Tue Jul 21 07:19:07.728807 2026] [security2:error] [pid 229246:tid 229390] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HmyBMYeh5YLVG45xYWQACImI"]
[Tue Jul 21 07:19:07.832696 2026] [security2:error] [pid 229246:tid 229440] [client 20.206.67.15:61194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/new4.php"] [unique_id "al9HmyBMYeh5YLVG45xYXQAAAlQ"]
[Tue Jul 21 07:19:07.893875 2026] [security2:error] [pid 229246:tid 229410] [client 4.204.201.85:35269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9HmyBMYeh5YLVG45xYYgAAAjY"]
[Tue Jul 21 07:19:07.913648 2026] [security2:error] [pid 229246:tid 229435] [client 173.252.95.42:51826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9HmyBMYeh5YLVG45xYYwAAAk8"]
[Tue Jul 21 07:19:07.940712 2026] [security2:error] [pid 229246:tid 229488] [client 20.197.192.193:16842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9HmyBMYeh5YLVG45xYZQAAAoQ"]
[Tue Jul 21 07:19:07.996004 2026] [security2:error] [pid 229246:tid 229472] [client 4.204.201.85:26420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9HmyBMYeh5YLVG45xYbAAAAnQ"]
[Tue Jul 21 07:19:08.065092 2026] [security2:error] [pid 229246:tid 229403] [client 20.206.67.15:61309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-the.php"] [unique_id "al9HnCBMYeh5YLVG45xYbQAAAi8"]
[Tue Jul 21 07:19:08.065738 2026] [security2:error] [pid 229246:tid 229466] [client 20.151.10.161:51392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/k2.php"] [unique_id "al9HnCBMYeh5YLVG45xYbgAAAm4"]
[Tue Jul 21 07:19:08.231616 2026] [security2:error] [pid 229246:tid 229457] [client 20.206.67.15:59595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/atkno.php"] [unique_id "al9HnCBMYeh5YLVG45xYbwAAAmU"]
[Tue Jul 21 07:19:08.254489 2026] [security2:error] [pid 229246:tid 229489] [client 20.206.67.15:61203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/mass.php"] [unique_id "al9HnCBMYeh5YLVG45xYcwAAAoU"]
[Tue Jul 21 07:19:08.299617 2026] [security2:error] [pid 229246:tid 229400] [client 20.206.67.15:59589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wefile.php"] [unique_id "al9HnCBMYeh5YLVG45xYdQAAAiw"]
[Tue Jul 21 07:19:08.318914 2026] [security2:error] [pid 229246:tid 229414] [client 20.151.10.161:53597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/fpwch.php"] [unique_id "al9HnCBMYeh5YLVG45xYdgAAAjo"]
[Tue Jul 21 07:19:08.405983 2026] [security2:error] [pid 229246:tid 229447] [client 20.206.67.15:61291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/min.php"] [unique_id "al9HnCBMYeh5YLVG45xYegAAAls"]
[Tue Jul 21 07:19:08.466894 2026] [security2:error] [pid 229246:tid 229478] [client 4.204.201.85:35399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wp-blog.php"] [unique_id "al9HnCBMYeh5YLVG45xYfQAAAno"]
[Tue Jul 21 07:19:08.546070 2026] [security2:error] [pid 229246:tid 229479] [client 20.206.67.15:61286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/sid3.php"] [unique_id "al9HnCBMYeh5YLVG45xYgAAAAns"]
[Tue Jul 21 07:19:08.595398 2026] [security2:error] [pid 229246:tid 229347] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HnCBMYeh5YLVG45xYggACfmQ"]
[Tue Jul 21 07:19:08.595548 2026] [security2:error] [pid 229246:tid 229482] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HnCBMYeh5YLVG45xYggACfmQ"]
[Tue Jul 21 07:19:08.627829 2026] [security2:error] [pid 229246:tid 229343] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/loader.php"] [unique_id "al9HnCBMYeh5YLVG45xYgwACLWA"]
[Tue Jul 21 07:19:08.642548 2026] [security2:error] [pid 229246:tid 229350] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/spadex.php"] [unique_id "al9HnCBMYeh5YLVG45xYhAACNmc"]
[Tue Jul 21 07:19:08.643509 2026] [security2:error] [pid 229246:tid 229435] [client 4.204.201.85:26576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9HnCBMYeh5YLVG45xYhQAAAk8"]
[Tue Jul 21 07:19:08.656946 2026] [security2:error] [pid 229246:tid 229356] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/2x.php"] [unique_id "al9HnCBMYeh5YLVG45xYhwAChm0"]
[Tue Jul 21 07:19:08.671106 2026] [security2:error] [pid 229246:tid 229363] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/ctex1.php"] [unique_id "al9HnCBMYeh5YLVG45xYiAACgnQ"]
[Tue Jul 21 07:19:08.686835 2026] [security2:error] [pid 229246:tid 229370] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/edorxrr.php"] [unique_id "al9HnCBMYeh5YLVG45xYiQACGns"]
[Tue Jul 21 07:19:08.687280 2026] [security2:error] [pid 229246:tid 229477] [client 20.197.192.193:16855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HnCBMYeh5YLVG45xYigAAAnk"]
[Tue Jul 21 07:19:08.701966 2026] [security2:error] [pid 229246:tid 229354] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/miru1.php"] [unique_id "al9HnCBMYeh5YLVG45xYiwACTms"]
[Tue Jul 21 07:19:08.704582 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:46076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-content/index.php"] [unique_id "al9HnCBMYeh5YLVG45xYjAAAAlo"]
[Tue Jul 21 07:19:08.716372 2026] [security2:error] [pid 229246:tid 229333] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/sump1.php"] [unique_id "al9HnCBMYeh5YLVG45xYjgACPFY"]
[Tue Jul 21 07:19:08.755368 2026] [security2:error] [pid 229246:tid 229367] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/file5.php"] [unique_id "al9HnCBMYeh5YLVG45xYkAACing"]
[Tue Jul 21 07:19:08.765680 2026] [security2:error] [pid 229246:tid 229445] [client 20.206.67.15:61239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/fileas.php"] [unique_id "al9HnCBMYeh5YLVG45xYkQAAAlk"]
[Tue Jul 21 07:19:08.767113 2026] [security2:error] [pid 229246:tid 229481] [client 20.197.192.193:9425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patihipopressivo.com.br"] [uri "/phpinfo.php1"] [unique_id "al9HnCBMYeh5YLVG45xYkgAAAn0"]
[Tue Jul 21 07:19:08.807635 2026] [security2:error] [pid 229246:tid 229373] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/0xD.php"] [unique_id "al9HnCBMYeh5YLVG45xYlAACbn4"]
[Tue Jul 21 07:19:08.825047 2026] [security2:error] [pid 229246:tid 229371] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/fnstall.php"] [unique_id "al9HnCBMYeh5YLVG45xYlgACQ3w"]
[Tue Jul 21 07:19:08.861521 2026] [security2:error] [pid 229246:tid 229365] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/acp.php"] [unique_id "al9HnCBMYeh5YLVG45xYmQACTXY"]
[Tue Jul 21 07:19:08.912028 2026] [security2:error] [pid 229246:tid 229358] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/mosty.php"] [unique_id "al9HnCBMYeh5YLVG45xYoAACeG8"]
[Tue Jul 21 07:19:08.926095 2026] [security2:error] [pid 229246:tid 229256] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/6.php"] [unique_id "al9HnCBMYeh5YLVG45xYoQACawk"]
[Tue Jul 21 07:19:08.958678 2026] [security2:error] [pid 229246:tid 229280] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9HnCBMYeh5YLVG45xYogACKyE"]
[Tue Jul 21 07:19:09.008987 2026] [security2:error] [pid 229246:tid 229453] [client 20.206.67.15:61207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/bless24.php"] [unique_id "al9HnSBMYeh5YLVG45xYpwAAAmE"]
[Tue Jul 21 07:19:09.010945 2026] [security2:error] [pid 229246:tid 229253] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/qqqa.php"] [unique_id "al9HnSBMYeh5YLVG45xYqAACZwY"]
[Tue Jul 21 07:19:09.058042 2026] [security2:error] [pid 229246:tid 229282] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/aunmc.php"] [unique_id "al9HnSBMYeh5YLVG45xYqQACeiM"]
[Tue Jul 21 07:19:09.095964 2026] [security2:error] [pid 229246:tid 229257] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/uoocf.php"] [unique_id "al9HnSBMYeh5YLVG45xYqwACJwo"]
[Tue Jul 21 07:19:09.137494 2026] [security2:error] [pid 229246:tid 229261] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/iywwi.php"] [unique_id "al9HnSBMYeh5YLVG45xYrAACjw4"]
[Tue Jul 21 07:19:09.168088 2026] [security2:error] [pid 229246:tid 229404] [client 20.206.67.15:61238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/fun.php"] [unique_id "al9HnSBMYeh5YLVG45xYrgAAAjA"]
[Tue Jul 21 07:19:09.188439 2026] [security2:error] [pid 229246:tid 229372] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/gqgsa.php"] [unique_id "al9HnSBMYeh5YLVG45xYsQACNn0"]
[Tue Jul 21 07:19:09.205030 2026] [security2:error] [pid 229246:tid 229435] [client 20.151.10.161:53602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/w2025.php"] [unique_id "al9HnSBMYeh5YLVG45xYsgAAAk8"]
[Tue Jul 21 07:19:09.229526 2026] [security2:error] [pid 229246:tid 229255] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/elbzl.php"] [unique_id "al9HnSBMYeh5YLVG45xYtAAChgg"]
[Tue Jul 21 07:19:09.251172 2026] [security2:error] [pid 229246:tid 229409] [client 136.144.33.97:36295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9HnSBMYeh5YLVG45xYtgAAAjU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:09.274774 2026] [security2:error] [pid 229246:tid 229446] [client 20.206.67.15:59667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/drykl.php"] [unique_id "al9HnSBMYeh5YLVG45xYuAAAAlo"]
[Tue Jul 21 07:19:09.280268 2026] [security2:error] [pid 229246:tid 229284] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/adjig.php"] [unique_id "al9HnSBMYeh5YLVG45xYuQACPCU"]
[Tue Jul 21 07:19:09.300536 2026] [security2:error] [pid 229246:tid 229488] [client 20.197.192.193:16872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/dp.php"] [unique_id "al9HnSBMYeh5YLVG45xYugAAAoQ"]
[Tue Jul 21 07:19:09.318416 2026] [security2:error] [pid 229246:tid 229267] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/byp.php"] [unique_id "al9HnSBMYeh5YLVG45xYuwACLhQ"]
[Tue Jul 21 07:19:09.334179 2026] [security2:error] [pid 229246:tid 229429] [client 20.151.10.161:21457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/82.php"] [unique_id "al9HnSBMYeh5YLVG45xYvAAAAkk"]
[Tue Jul 21 07:19:09.347297 2026] [security2:error] [pid 229246:tid 229288] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9HnSBMYeh5YLVG45xYvQACYCk"]
[Tue Jul 21 07:19:09.365570 2026] [security2:error] [pid 229246:tid 229445] [client 20.206.67.15:59670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "al9HnSBMYeh5YLVG45xYvgAAAlk"]
[Tue Jul 21 07:19:09.391784 2026] [security2:error] [pid 229246:tid 229419] [client 20.206.67.15:61202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/mifta.php"] [unique_id "al9HnSBMYeh5YLVG45xYvwAAAj8"]
[Tue Jul 21 07:19:09.398342 2026] [security2:error] [pid 229246:tid 229368] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/classwithtostring.php"] [unique_id "al9HnSBMYeh5YLVG45xYwAACIXk"]
[Tue Jul 21 07:19:09.412706 2026] [security2:error] [pid 229246:tid 229283] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/root.php"] [unique_id "al9HnSBMYeh5YLVG45xYwQACbiQ"]
[Tue Jul 21 07:19:09.426878 2026] [security2:error] [pid 229246:tid 229286] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/sym403.php"] [unique_id "al9HnSBMYeh5YLVG45xYwgACJSc"]
[Tue Jul 21 07:19:09.441347 2026] [security2:error] [pid 229246:tid 229264] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/v543.php"] [unique_id "al9HnSBMYeh5YLVG45xYxQACIBE"]
[Tue Jul 21 07:19:09.455282 2026] [security2:error] [pid 229246:tid 229297] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/sixxis.php"] [unique_id "al9HnSBMYeh5YLVG45xYxwACSzI"]
[Tue Jul 21 07:19:09.469957 2026] [security2:error] [pid 229246:tid 229293] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/ip.php"] [unique_id "al9HnSBMYeh5YLVG45xYyAACdi4"]
[Tue Jul 21 07:19:09.483884 2026] [security2:error] [pid 229246:tid 229289] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/kq1.php"] [unique_id "al9HnSBMYeh5YLVG45xYyQACeCo"]
[Tue Jul 21 07:19:09.498252 2026] [security2:error] [pid 229246:tid 229300] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9HnSBMYeh5YLVG45xYywACHzU"]
[Tue Jul 21 07:19:09.499323 2026] [security2:error] [pid 229246:tid 229406] [client 20.206.67.15:59586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/class-t.api.php"] [unique_id "al9HnSBMYeh5YLVG45xYzAAAAjI"]
[Tue Jul 21 07:19:09.511789 2026] [security2:error] [pid 229246:tid 229366] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/h02ugyh.php"] [unique_id "al9HnSBMYeh5YLVG45xYzQACHXc"]
[Tue Jul 21 07:19:09.515672 2026] [security2:error] [pid 229246:tid 229400] [client 20.206.67.15:61290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/vgtyu.php"] [unique_id "al9HnSBMYeh5YLVG45xYzgAAAiw"]
[Tue Jul 21 07:19:09.539584 2026] [security2:error] [pid 229246:tid 229497] [client 20.206.67.15:61254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/atomlib.php"] [unique_id "al9HnSBMYeh5YLVG45xYzwAAAo0"]
[Tue Jul 21 07:19:09.541524 2026] [security2:error] [pid 229246:tid 229265] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-temp.php"] [unique_id "al9HnSBMYeh5YLVG45xY0AACcxI"]
[Tue Jul 21 07:19:09.569889 2026] [security2:error] [pid 229246:tid 229266] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9HnSBMYeh5YLVG45xY0QACZxM"]
[Tue Jul 21 07:19:09.591209 2026] [security2:error] [pid 229246:tid 229428] [client 20.206.67.15:61210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-access.php"] [unique_id "al9HnSBMYeh5YLVG45xY0wAAAkg"]
[Tue Jul 21 07:19:09.613683 2026] [security2:error] [pid 229246:tid 229378] [client 139.135.44.145:53635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HnSBMYeh5YLVG45xY1QAAAhY"]
[Tue Jul 21 07:19:09.613800 2026] [security2:error] [pid 229246:tid 229378] [client 139.135.44.145:53635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HnSBMYeh5YLVG45xY1QAAAhY"]
[Tue Jul 21 07:19:09.617603 2026] [security2:error] [pid 229246:tid 229489] [client 45.251.232.145:58539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HnSBMYeh5YLVG45xY1gAAAoU"]
[Tue Jul 21 07:19:09.617705 2026] [security2:error] [pid 229246:tid 229489] [client 45.251.232.145:58539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HnSBMYeh5YLVG45xY1gAAAoU"]
[Tue Jul 21 07:19:09.637476 2026] [security2:error] [pid 229246:tid 229440] [client 20.206.67.15:61221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-update.php"] [unique_id "al9HnSBMYeh5YLVG45xY1wAAAlQ"]
[Tue Jul 21 07:19:09.667180 2026] [security2:error] [pid 229246:tid 229478] [client 20.206.67.15:61241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/erty.php"] [unique_id "al9HnSBMYeh5YLVG45xY2QAAAno"]
[Tue Jul 21 07:19:09.670282 2026] [security2:error] [pid 229246:tid 229392] [client 68.235.38.2:34998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9HnSBMYeh5YLVG45xY2gAAAiQ"]
[Tue Jul 21 07:19:09.670380 2026] [security2:error] [pid 229246:tid 229392] [client 68.235.38.2:34998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9HnSBMYeh5YLVG45xY2gAAAiQ"]
[Tue Jul 21 07:19:09.677717 2026] [security2:error] [pid 229246:tid 229395] [client 20.226.60.151:54532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/2x.php"] [unique_id "al9HnSBMYeh5YLVG45xY2wAAAic"]
[Tue Jul 21 07:19:09.706072 2026] [security2:error] [pid 229246:tid 229499] [client 20.206.67.15:61255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "al9HnSBMYeh5YLVG45xY3gAAAo8"]
[Tue Jul 21 07:19:09.732063 2026] [security2:error] [pid 229246:tid 229435] [client 20.206.67.15:61289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/like.php"] [unique_id "al9HnSBMYeh5YLVG45xY3wAAAk8"]
[Tue Jul 21 07:19:09.789778 2026] [security2:error] [pid 229246:tid 229409] [client 4.204.201.85:26610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/abcd.php"] [unique_id "al9HnSBMYeh5YLVG45xY4QAAAjU"]
[Tue Jul 21 07:19:09.797661 2026] [security2:error] [pid 229246:tid 229475] [client 20.206.67.15:61296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/bless5.php"] [unique_id "al9HnSBMYeh5YLVG45xY4gAAAnc"]
[Tue Jul 21 07:19:09.804040 2026] [security2:error] [pid 229246:tid 229434] [client 20.197.192.193:16833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/old.php"] [unique_id "al9HnSBMYeh5YLVG45xY5AAAAk4"]
[Tue Jul 21 07:19:09.812649 2026] [autoindex:error] [pid 229246:tid 229469] [client 4.204.201.85:35400] AH01276: Cannot serve directory /home3/seaport/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:09.864537 2026] [security2:error] [pid 229246:tid 229488] [client 20.151.10.161:46022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/zoro.php"] [unique_id "al9HnSBMYeh5YLVG45xY5QAAAoQ"]
[Tue Jul 21 07:19:09.923673 2026] [security2:error] [pid 229246:tid 229451] [client 74.244.195.153:33829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.195.244.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9HnSBMYeh5YLVG45xY5wAAAl8"]
[Tue Jul 21 07:19:09.927234 2026] [security2:error] [pid 229246:tid 229451] [client 74.244.195.153:33829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9HnSBMYeh5YLVG45xY5wAAAl8"]
[Tue Jul 21 07:19:09.964633 2026] [security2:error] [pid 229246:tid 229481] [client 20.151.10.161:55239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/scxy.php"] [unique_id "al9HnSBMYeh5YLVG45xY6QAAAn0"]
[Tue Jul 21 07:19:10.021071 2026] [security2:error] [pid 229246:tid 229417] [client 20.197.192.193:11145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/ms-new.php"] [unique_id "al9HniBMYeh5YLVG45xY8AAAAj0"]
[Tue Jul 21 07:19:10.110515 2026] [security2:error] [pid 229246:tid 229406] [client 4.204.201.85:35272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9HniBMYeh5YLVG45xY8wAAAjI"]
[Tue Jul 21 07:19:10.132374 2026] [security2:error] [pid 229246:tid 229311] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HniBMYeh5YLVG45xY9AACPkA"]
[Tue Jul 21 07:19:10.132492 2026] [security2:error] [pid 229246:tid 229418] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HniBMYeh5YLVG45xY9AACPkA"]
[Tue Jul 21 07:19:10.142617 2026] [security2:error] [pid 229246:tid 229314] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HniBMYeh5YLVG45xY9QACGEM"]
[Tue Jul 21 07:19:10.142715 2026] [security2:error] [pid 229246:tid 229380] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HniBMYeh5YLVG45xY9QACGEM"]
[Tue Jul 21 07:19:10.173340 2026] [security2:error] [pid 229246:tid 229400] [client 20.206.67.15:59631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/t.php"] [unique_id "al9HniBMYeh5YLVG45xY-QAAAiw"]
[Tue Jul 21 07:19:10.214777 2026] [security2:error] [pid 229246:tid 229428] [client 20.197.192.193:11238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/track.php"] [unique_id "al9HniBMYeh5YLVG45xY_AAAAkg"]
[Tue Jul 21 07:19:10.256025 2026] [security2:error] [pid 229246:tid 229447] [client 4.204.201.85:26014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/file15.php"] [unique_id "al9HniBMYeh5YLVG45xY_gAAAls"]
[Tue Jul 21 07:19:10.350377 2026] [security2:error] [pid 229246:tid 229491] [client 173.252.95.59:48284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9HnSBMYeh5YLVG45xYsAAAAoc"]
[Tue Jul 21 07:19:10.394750 2026] [security2:error] [pid 229246:tid 229501] [client 20.206.67.15:61198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/xoot.php"] [unique_id "al9HniBMYeh5YLVG45xZAQAAApE"]
[Tue Jul 21 07:19:10.396379 2026] [security2:error] [pid 229246:tid 229404] [client 20.151.10.161:21490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/config.json.php"] [unique_id "al9HniBMYeh5YLVG45xZAgAAAjA"]
[Tue Jul 21 07:19:10.496976 2026] [security2:error] [pid 229246:tid 229467] [client 20.151.10.161:53587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/FWAZ.php"] [unique_id "al9HniBMYeh5YLVG45xZBAAAAm8"]
[Tue Jul 21 07:19:10.498162 2026] [security2:error] [pid 229246:tid 229484] [client 4.204.201.85:35352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/ms-edit.php"] [unique_id "al9HniBMYeh5YLVG45xZBQAAAoA"]
[Tue Jul 21 07:19:10.578328 2026] [security2:error] [pid 229246:tid 229402] [client 20.206.67.15:61237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/xqq.php"] [unique_id "al9HniBMYeh5YLVG45xZCgAAAi4"]
[Tue Jul 21 07:19:10.620158 2026] [security2:error] [pid 229246:tid 229393] [client 20.220.225.223:40857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/wpx.php"] [unique_id "al9HniBMYeh5YLVG45xZCwAAAiU"]
[Tue Jul 21 07:19:10.623799 2026] [security2:error] [pid 229246:tid 229472] [client 20.206.67.15:61201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-load.php"] [unique_id "al9HniBMYeh5YLVG45xZDAAAAnQ"]
[Tue Jul 21 07:19:10.667075 2026] [security2:error] [pid 229246:tid 229423] [client 20.206.67.15:59688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/x.php"] [unique_id "al9HniBMYeh5YLVG45xZDQAAAkM"]
[Tue Jul 21 07:19:10.694474 2026] [security2:error] [pid 229246:tid 229431] [client 20.151.10.161:45962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/admin.php"] [unique_id "al9HniBMYeh5YLVG45xZDgAAAks"]
[Tue Jul 21 07:19:10.706676 2026] [security2:error] [pid 229246:tid 229396] [client 20.206.67.15:61236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/i.php"] [unique_id "al9HniBMYeh5YLVG45xZDwAAAig"]
[Tue Jul 21 07:19:10.765453 2026] [security2:error] [pid 229246:tid 229418] [client 20.206.67.15:61195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/ms-edit.php"] [unique_id "al9HniBMYeh5YLVG45xZEQAAAj4"]
[Tue Jul 21 07:19:10.808354 2026] [security2:error] [pid 229246:tid 229476] [client 20.151.10.161:55294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/qterm.php"] [unique_id "al9HniBMYeh5YLVG45xZEgAAAng"]
[Tue Jul 21 07:19:10.820338 2026] [security2:error] [pid 229246:tid 229463] [client 20.206.67.15:61281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/v2.php"] [unique_id "al9HniBMYeh5YLVG45xZEwAAAms"]
[Tue Jul 21 07:19:10.854800 2026] [security2:error] [pid 229246:tid 229399] [client 20.206.67.15:61285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/new.php"] [unique_id "al9HniBMYeh5YLVG45xZFQAAAis"]
[Tue Jul 21 07:19:10.915905 2026] [security2:error] [pid 229246:tid 229424] [client 20.206.67.15:59692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-admin/network/edit.php"] [unique_id "al9HniBMYeh5YLVG45xZFwAAAkQ"]
[Tue Jul 21 07:19:10.932502 2026] [security2:error] [pid 229246:tid 229482] [client 4.204.201.85:35445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9HniBMYeh5YLVG45xZGAAAAn4"]
[Tue Jul 21 07:19:10.935470 2026] [security2:error] [pid 229246:tid 229445] [client 20.206.67.15:59592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/pouhg.php"] [unique_id "al9HniBMYeh5YLVG45xZGQAAAlk"]
[Tue Jul 21 07:19:10.950533 2026] [security2:error] [pid 229246:tid 229489] [client 20.206.67.15:61197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/cilus.php"] [unique_id "al9HniBMYeh5YLVG45xZGgAAAoU"]
[Tue Jul 21 07:19:10.974404 2026] [security2:error] [pid 229246:tid 229478] [client 20.206.67.15:61232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/file4.php"] [unique_id "al9HniBMYeh5YLVG45xZHAAAAno"]
[Tue Jul 21 07:19:11.011473 2026] [security2:error] [pid 229246:tid 229435] [client 20.206.67.15:61191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/samll.php"] [unique_id "al9HnyBMYeh5YLVG45xZJAAAAk8"]
[Tue Jul 21 07:19:11.027374 2026] [security2:error] [pid 229246:tid 229475] [client 20.206.67.15:61280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/Okxob.php"] [unique_id "al9HnyBMYeh5YLVG45xZJwAAAnc"]
[Tue Jul 21 07:19:11.038745 2026] [security2:error] [pid 229246:tid 229409] [client 4.204.201.85:26563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/jp.php"] [unique_id "al9HnyBMYeh5YLVG45xZKAAAAjU"]
[Tue Jul 21 07:19:11.066758 2026] [security2:error] [pid 229246:tid 229382] [client 20.206.67.15:61213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/ok.php"] [unique_id "al9HnyBMYeh5YLVG45xZLAAAAho"]
[Tue Jul 21 07:19:11.191458 2026] [security2:error] [pid 229246:tid 229418] [client 20.151.10.161:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/blurbs.php"] [unique_id "al9HnyBMYeh5YLVG45xZNAAAAj4"]
[Tue Jul 21 07:19:11.194700 2026] [security2:error] [pid 229246:tid 229380] [client 20.206.67.15:61276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wuasr.php"] [unique_id "al9HnyBMYeh5YLVG45xZNQAAAhg"]
[Tue Jul 21 07:19:11.218122 2026] [security2:error] [pid 229246:tid 229477] [client 20.206.67.15:61188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/bless11.php"] [unique_id "al9HnyBMYeh5YLVG45xZNgAAAnk"]
[Tue Jul 21 07:19:11.223290 2026] [security2:error] [pid 229246:tid 229385] [client 20.151.10.161:46037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/greap.php"] [unique_id "al9HnyBMYeh5YLVG45xZNwAAAh0"]
[Tue Jul 21 07:19:11.237047 2026] [security2:error] [pid 229246:tid 229466] [client 20.206.67.15:61227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-block.php"] [unique_id "al9HnyBMYeh5YLVG45xZOAAAAm4"]
[Tue Jul 21 07:19:11.281668 2026] [security2:error] [pid 229246:tid 229482] [client 20.206.67.15:61250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/aevly.php"] [unique_id "al9HnyBMYeh5YLVG45xZOwAAAn4"]
[Tue Jul 21 07:19:11.324530 2026] [security2:error] [pid 229246:tid 229489] [client 20.206.67.15:59601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/hello.php"] [unique_id "al9HnyBMYeh5YLVG45xZPwAAAoU"]
[Tue Jul 21 07:19:11.360834 2026] [security2:error] [pid 229246:tid 229392] [client 20.206.67.15:59605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-links-opml.php"] [unique_id "al9HnyBMYeh5YLVG45xZQgAAAiQ"]
[Tue Jul 21 07:19:11.404765 2026] [security2:error] [pid 229246:tid 229426] [client 20.206.67.15:61212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/forbidals.php"] [unique_id "al9HnyBMYeh5YLVG45xZQwAAAkY"]
[Tue Jul 21 07:19:11.413555 2026] [security2:error] [pid 229246:tid 229491] [client 20.151.10.161:51415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/fpwch.php"] [unique_id "al9HnyBMYeh5YLVG45xZRAAAAoc"]
[Tue Jul 21 07:19:11.495011 2026] [security2:error] [pid 229246:tid 229403] [client 20.206.67.15:59674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/file30.php"] [unique_id "al9HnyBMYeh5YLVG45xZRQAAAi8"]
[Tue Jul 21 07:19:11.542749 2026] [security2:error] [pid 229246:tid 229467] [client 20.151.10.161:53622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/v543.php"] [unique_id "al9HnyBMYeh5YLVG45xZRwAAAm8"]
[Tue Jul 21 07:19:11.578485 2026] [security2:error] [pid 229246:tid 229484] [client 20.206.67.15:61284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/xda.php"] [unique_id "al9HnyBMYeh5YLVG45xZSgAAAoA"]
[Tue Jul 21 07:19:11.633274 2026] [security2:error] [pid 229246:tid 229416] [client 20.206.67.15:61244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/z.php"] [unique_id "al9HnyBMYeh5YLVG45xZTAAAAjw"]
[Tue Jul 21 07:19:11.669377 2026] [security2:error] [pid 229246:tid 229402] [client 20.206.67.15:59695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/b.php"] [unique_id "al9HnyBMYeh5YLVG45xZTQAAAi4"]
[Tue Jul 21 07:19:11.671006 2026] [security2:error] [pid 229246:tid 229429] [client 4.204.201.85:26371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/f35.php"] [unique_id "al9HnyBMYeh5YLVG45xZTgAAAkk"]
[Tue Jul 21 07:19:11.700801 2026] [security2:error] [pid 229246:tid 229393] [client 20.151.10.161:45953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/177.php"] [unique_id "al9HnyBMYeh5YLVG45xZTwAAAiU"]
[Tue Jul 21 07:19:11.705102 2026] [security2:error] [pid 229246:tid 229486] [client 20.206.67.15:61277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/edit.php"] [unique_id "al9HnyBMYeh5YLVG45xZUAAAAoI"]
[Tue Jul 21 07:19:11.718266 2026] [security2:error] [pid 229246:tid 229304] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9HnyBMYeh5YLVG45xZUQACcjk"]
[Tue Jul 21 07:19:11.721885 2026] [security2:error] [pid 229246:tid 229462] [client 20.206.67.15:59671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/app.php"] [unique_id "al9HnyBMYeh5YLVG45xZUgAAAmo"]
[Tue Jul 21 07:19:11.725983 2026] [security2:error] [pid 229246:tid 229446] [client 175.45.70.82:62887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HnyBMYeh5YLVG45xZUwAAAlo"]
[Tue Jul 21 07:19:11.726063 2026] [security2:error] [pid 229246:tid 229446] [client 175.45.70.82:62887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HnyBMYeh5YLVG45xZUwAAAlo"]
[Tue Jul 21 07:19:11.732068 2026] [security2:error] [pid 229246:tid 229290] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/jj.php"] [unique_id "al9HnyBMYeh5YLVG45xZVAACFSs"]
[Tue Jul 21 07:19:11.758239 2026] [security2:error] [pid 229246:tid 229423] [client 20.206.67.15:59685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-png.php"] [unique_id "al9HnyBMYeh5YLVG45xZVQAAAkM"]
[Tue Jul 21 07:19:11.783510 2026] [security2:error] [pid 229246:tid 229337] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9HnyBMYeh5YLVG45xZVgACbFo"]
[Tue Jul 21 07:19:11.790870 2026] [security2:error] [pid 229246:tid 229479] [client 20.206.67.15:59660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/lib.php"] [unique_id "al9HnyBMYeh5YLVG45xZVwAAAns"]
[Tue Jul 21 07:19:11.816006 2026] [security2:error] [pid 229246:tid 229330] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/txets.php"] [unique_id "al9HnyBMYeh5YLVG45xZWgACPlM"]
[Tue Jul 21 07:19:11.825015 2026] [security2:error] [pid 229246:tid 229476] [client 20.151.10.161:53588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/w3lls.php"] [unique_id "al9HnyBMYeh5YLVG45xZWwAAAng"]
[Tue Jul 21 07:19:11.834562 2026] [security2:error] [pid 229246:tid 229463] [client 20.206.67.15:59686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/sys.php"] [unique_id "al9HnyBMYeh5YLVG45xZXAAAAms"]
[Tue Jul 21 07:19:11.847492 2026] [security2:error] [pid 229246:tid 229345] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/dex.php"] [unique_id "al9HnyBMYeh5YLVG45xZXgACc2I"]
[Tue Jul 21 07:19:11.859107 2026] [security2:error] [pid 229246:tid 229414] [client 20.206.67.15:59653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/la.php"] [unique_id "al9HnyBMYeh5YLVG45xZXwAAAjo"]
[Tue Jul 21 07:19:11.871592 2026] [security2:error] [pid 229246:tid 229339] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/xpwer1.php"] [unique_id "al9HnyBMYeh5YLVG45xZYQACblw"]
[Tue Jul 21 07:19:11.883965 2026] [security2:error] [pid 229246:tid 229459] [client 20.206.67.15:61297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/tires.php"] [unique_id "al9HnyBMYeh5YLVG45xZYwAAAmc"]
[Tue Jul 21 07:19:11.885835 2026] [security2:error] [pid 229246:tid 229331] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/flox.php"] [unique_id "al9HnyBMYeh5YLVG45xZZAACYVQ"]
[Tue Jul 21 07:19:11.908709 2026] [security2:error] [pid 229246:tid 229445] [client 20.206.67.15:59608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/lv.php"] [unique_id "al9HnyBMYeh5YLVG45xZZQAAAlk"]
[Tue Jul 21 07:19:11.915523 2026] [security2:error] [pid 229246:tid 229328] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/popo.php"] [unique_id "al9HnyBMYeh5YLVG45xZZgAChVE"]
[Tue Jul 21 07:19:11.929958 2026] [security2:error] [pid 229246:tid 229478] [client 20.206.67.15:61233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/myfile.php"] [unique_id "al9HnyBMYeh5YLVG45xZaAAAAno"]
[Tue Jul 21 07:19:11.954046 2026] [security2:error] [pid 229246:tid 229335] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/yas.php"] [unique_id "al9HnyBMYeh5YLVG45xZawACJ1g"]
[Tue Jul 21 07:19:11.960468 2026] [security2:error] [pid 229246:tid 229488] [client 20.206.67.15:59662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/06.php"] [unique_id "al9HnyBMYeh5YLVG45xZbQAAAoQ"]
[Tue Jul 21 07:19:11.968009 2026] [security2:error] [pid 229246:tid 229332] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/file61.php"] [unique_id "al9HnyBMYeh5YLVG45xZbgACh1U"]
[Tue Jul 21 07:19:11.981798 2026] [security2:error] [pid 229246:tid 229338] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/water.php"] [unique_id "al9HnyBMYeh5YLVG45xZcQACL1s"]
[Tue Jul 21 07:19:11.987357 2026] [security2:error] [pid 229246:tid 229468] [client 20.206.67.15:59658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/fs.php"] [unique_id "al9HnyBMYeh5YLVG45xZcgAAAnA"]
[Tue Jul 21 07:19:11.995601 2026] [security2:error] [pid 229246:tid 229352] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/nano.php"] [unique_id "al9HnyBMYeh5YLVG45xZcwACb2k"]
[Tue Jul 21 07:19:12.009585 2026] [security2:error] [pid 229246:tid 229347] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/moon.php"] [unique_id "al9HoCBMYeh5YLVG45xZdAAChmQ"]
[Tue Jul 21 07:19:12.010181 2026] [security2:error] [pid 229246:tid 229484] [client 20.206.67.15:59584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/asasx.php"] [unique_id "al9HoCBMYeh5YLVG45xZdQAAAoA"]
[Tue Jul 21 07:19:12.037607 2026] [security2:error] [pid 229246:tid 229435] [client 20.206.67.15:61222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-kd4xalrg7m.php"] [unique_id "al9HoCBMYeh5YLVG45xZewAAAk8"]
[Tue Jul 21 07:19:12.051284 2026] [security2:error] [pid 229246:tid 229416] [client 20.197.192.193:11163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/2352356666.php"] [unique_id "al9HoCBMYeh5YLVG45xZfAAAAjw"]
[Tue Jul 21 07:19:12.065377 2026] [security2:error] [pid 229246:tid 229429] [client 20.206.67.15:59707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-good.php"] [unique_id "al9HoCBMYeh5YLVG45xZfQAAAkk"]
[Tue Jul 21 07:19:12.076918 2026] [security2:error] [pid 229246:tid 229486] [client 20.206.67.15:61295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/scxy.php"] [unique_id "al9HoCBMYeh5YLVG45xZfwAAAoI"]
[Tue Jul 21 07:19:12.085774 2026] [autoindex:error] [pid 229246:tid 229481] [client 4.204.201.85:35400] AH01276: Cannot serve directory /home3/seaport/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:12.119424 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:53624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-ws68.php"] [unique_id "al9HoCBMYeh5YLVG45xZgQAAAlo"]
[Tue Jul 21 07:19:12.121041 2026] [security2:error] [pid 229246:tid 229377] [client 20.206.67.15:59640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wmore1.php"] [unique_id "al9HoCBMYeh5YLVG45xZggAAAhU"]
[Tue Jul 21 07:19:12.158728 2026] [security2:error] [pid 229246:tid 229396] [client 20.206.67.15:61306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/like.php"] [unique_id "al9HoCBMYeh5YLVG45xZhgAAAig"]
[Tue Jul 21 07:19:12.196648 2026] [security2:error] [pid 229246:tid 229471] [client 20.206.67.15:59617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/x.php"] [unique_id "al9HoCBMYeh5YLVG45xZiAAAAnM"]
[Tue Jul 21 07:19:12.229500 2026] [security2:error] [pid 229246:tid 229466] [client 4.204.201.85:35409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9HoCBMYeh5YLVG45xZigAAAm4"]
[Tue Jul 21 07:19:12.350300 2026] [security2:error] [pid 229246:tid 229445] [client 20.206.67.15:61224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/xa.php"] [unique_id "al9HoCBMYeh5YLVG45xZjAAAAlk"]
[Tue Jul 21 07:19:12.455874 2026] [security2:error] [pid 229246:tid 229488] [client 20.151.10.161:46050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/199.php"] [unique_id "al9HoCBMYeh5YLVG45xZkAAAAoQ"]
[Tue Jul 21 07:19:12.466285 2026] [security2:error] [pid 229246:tid 229491] [client 4.204.201.85:26423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/wp-load.php"] [unique_id "al9HoCBMYeh5YLVG45xZkgAAAoc"]
[Tue Jul 21 07:19:12.510629 2026] [security2:error] [pid 229246:tid 229403] [client 20.206.67.15:61261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/kolda.php"] [unique_id "al9HoCBMYeh5YLVG45xZkwAAAi8"]
[Tue Jul 21 07:19:12.527657 2026] [security2:error] [pid 229246:tid 229467] [client 20.151.10.161:53574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xyn.php"] [unique_id "al9HoCBMYeh5YLVG45xZlgAAAm8"]
[Tue Jul 21 07:19:12.532218 2026] [security2:error] [pid 229246:tid 229457] [client 103.187.68.227:62017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.68.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.vivaconcierge.com.br"] [uri "/wp-login.php"] [unique_id "al9HoCBMYeh5YLVG45xZlAAAAmU"], referer: https://www.google.com/
[Tue Jul 21 07:19:12.650767 2026] [security2:error] [pid 229246:tid 229409] [client 20.206.67.15:59703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-aothait.php"] [unique_id "al9HoCBMYeh5YLVG45xZmwAAAjU"]
[Tue Jul 21 07:19:12.652519 2026] [security2:error] [pid 229246:tid 229371] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HoCBMYeh5YLVG45xZnAACLnw"]
[Tue Jul 21 07:19:12.652673 2026] [security2:error] [pid 229246:tid 229402] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HoCBMYeh5YLVG45xZnAACLnw"]
[Tue Jul 21 07:19:12.723966 2026] [security2:error] [pid 229246:tid 229481] [client 20.206.67.15:61292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/ftde.php"] [unique_id "al9HoCBMYeh5YLVG45xZnwAAAn0"]
[Tue Jul 21 07:19:12.773161 2026] [autoindex:error] [pid 229246:tid 229423] [client 4.204.201.85:35400] AH01276: Cannot serve directory /home3/seaport/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:12.776121 2026] [security2:error] [pid 229246:tid 229454] [client 20.197.192.193:11194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/pn.php"] [unique_id "al9HoCBMYeh5YLVG45xZoQAAAmI"]
[Tue Jul 21 07:19:12.798293 2026] [security2:error] [pid 229246:tid 229365] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HoCBMYeh5YLVG45xZowACinY"]
[Tue Jul 21 07:19:12.798449 2026] [security2:error] [pid 229246:tid 229494] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HoCBMYeh5YLVG45xZowACinY"]
[Tue Jul 21 07:19:12.802168 2026] [security2:error] [pid 229246:tid 229433] [client 120.61.173.56:51104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HoCBMYeh5YLVG45xZpAAAAk0"]
[Tue Jul 21 07:19:12.802244 2026] [security2:error] [pid 229246:tid 229433] [client 120.61.173.56:51104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HoCBMYeh5YLVG45xZpAAAAk0"]
[Tue Jul 21 07:19:12.937187 2026] [security2:error] [pid 229246:tid 229250] [remote 8.217.108.67:48962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "revistareflexopolitico.com.br"] [uri "/wp-login.php"] [unique_id "al9HoCBMYeh5YLVG45xZqAACegM"]
[Tue Jul 21 07:19:12.988179 2026] [security2:error] [pid 229246:tid 229459] [client 20.151.10.161:53591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/green3.php"] [unique_id "al9HoCBMYeh5YLVG45xZqQAAAmc"]
[Tue Jul 21 07:19:13.044601 2026] [security2:error] [pid 229246:tid 229424] [client 20.206.67.15:59657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/vx.php"] [unique_id "al9HoSBMYeh5YLVG45xZrAAAAkQ"]
[Tue Jul 21 07:19:13.077342 2026] [autoindex:error] [pid 229246:tid 229497] [client 4.204.201.85:35400] AH01276: Cannot serve directory /home3/seaport/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:13.094181 2026] [security2:error] [pid 229246:tid 229448] [client 20.197.192.193:11215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9HoSBMYeh5YLVG45xZsQAAAlw"]
[Tue Jul 21 07:19:13.141644 2026] [security2:error] [pid 229246:tid 229251] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-info.php"] [unique_id "al9HoSBMYeh5YLVG45xZsgACLwQ"]
[Tue Jul 21 07:19:13.156261 2026] [security2:error] [pid 229246:tid 229253] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/2000.php"] [unique_id "al9HoSBMYeh5YLVG45xZtQACZQY"]
[Tue Jul 21 07:19:13.178411 2026] [security2:error] [pid 229246:tid 229501] [client 20.206.67.15:59628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/a5.php"] [unique_id "al9HoSBMYeh5YLVG45xZtwAAApE"]
[Tue Jul 21 07:19:13.193061 2026] [security2:error] [pid 229246:tid 229257] [remote 185.115.217.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.217.115.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "annaguimaraes.com.br"] [uri "/wp-login.php"] [unique_id "al9HoSBMYeh5YLVG45xZuQACYQo"]
[Tue Jul 21 07:19:13.207692 2026] [security2:error] [pid 229246:tid 229261] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/122.php"] [unique_id "al9HoSBMYeh5YLVG45xZugACIg4"]
[Tue Jul 21 07:19:13.230748 2026] [security2:error] [pid 229246:tid 229486] [client 4.204.201.85:35296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/abcd.php"] [unique_id "al9HoSBMYeh5YLVG45xZvQAAAoI"]
[Tue Jul 21 07:19:13.241468 2026] [security2:error] [pid 229246:tid 229255] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/mds.php"] [unique_id "al9HoSBMYeh5YLVG45xZvwACdAg"]
[Tue Jul 21 07:19:13.256681 2026] [security2:error] [pid 229246:tid 229435] [client 20.206.67.15:59661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-sing.php"] [unique_id "al9HoSBMYeh5YLVG45xZwAAAAk8"]
[Tue Jul 21 07:19:13.258172 2026] [security2:error] [pid 229246:tid 229470] [client 4.204.201.85:26397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/xyn.php"] [unique_id "al9HoSBMYeh5YLVG45xZwQAAAnI"]
[Tue Jul 21 07:19:13.270683 2026] [security2:error] [pid 229246:tid 229284] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-blink.php"] [unique_id "al9HoSBMYeh5YLVG45xZwgACWiU"]
[Tue Jul 21 07:19:13.290988 2026] [http2:info] [pid 230252:tid 230252] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 07:19:13.311344 2026] [security2:error] [pid 229246:tid 229479] [client 20.151.10.161:46002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file52.php"] [unique_id "al9HoSBMYeh5YLVG45xZxgAAAns"]
[Tue Jul 21 07:19:13.342114 2026] [security2:error] [pid 229246:tid 229490] [client 20.197.192.193:16874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/dr.php"] [unique_id "al9HoSBMYeh5YLVG45xZxwAAAoY"]
[Tue Jul 21 07:19:13.446431 2026] [security2:error] [pid 229246:tid 229397] [client 20.151.10.161:53601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ccs.php"] [unique_id "al9HoSBMYeh5YLVG45xZzQAAAik"]
[Tue Jul 21 07:19:13.461681 2026] [security2:error] [pid 230252:tid 230386] [client 20.206.67.15:59696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/database.php"] [unique_id "al9HoU0Dwhk5-Z44Xro1GgAAAps"]
[Tue Jul 21 07:19:13.469753 2026] [security2:error] [pid 229246:tid 229483] [client 193.36.225.58:33553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9HoSBMYeh5YLVG45xZxQAAAn8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:13.555289 2026] [security2:error] [pid 229246:tid 229418] [client 209.141.34.121:53052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "odontoclinicms.com.br"] [uri "/"] [unique_id "al9HoSBMYeh5YLVG45xZzgAAAj4"]
[Tue Jul 21 07:19:13.563158 2026] [security2:error] [pid 230252:tid 230389] [client 4.204.201.85:35358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/file15.php"] [unique_id "al9HoU0Dwhk5-Z44Xro1HAAAAp4"]
[Tue Jul 21 07:19:13.572625 2026] [security2:error] [pid 229246:tid 229388] [client 20.206.67.15:61214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/explorer/index_.php"] [unique_id "al9HoSBMYeh5YLVG45xZ0AAAAiA"]
[Tue Jul 21 07:19:13.628259 2026] [security2:error] [pid 230252:tid 230390] [client 20.206.67.15:61311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-at.php"] [unique_id "al9HoU0Dwhk5-Z44Xro1HQAAAp8"]
[Tue Jul 21 07:19:13.659603 2026] [security2:error] [pid 230252:tid 230392] [client 20.206.67.15:61229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-wz.php"] [unique_id "al9HoU0Dwhk5-Z44Xro1HgAAAqE"]
[Tue Jul 21 07:19:13.726370 2026] [security2:error] [pid 229246:tid 229448] [client 20.206.67.15:59655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-ver.php"] [unique_id "al9HoSBMYeh5YLVG45xZ0wAAAlw"]
[Tue Jul 21 07:19:13.742884 2026] [security2:error] [pid 230252:tid 230397] [client 20.197.192.193:11146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/2x.php"] [unique_id "al9HoU0Dwhk5-Z44Xro1IAAAAqY"]
[Tue Jul 21 07:19:13.751647 2026] [security2:error] [pid 229246:tid 229457] [client 20.206.67.15:61230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp5.php"] [unique_id "al9HoSBMYeh5YLVG45xZ1gAAAmU"]
[Tue Jul 21 07:19:13.757123 2026] [security2:error] [pid 230252:tid 230384] [client 103.187.68.225:65518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.68.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.vivaconcierge.com.br"] [uri "/wp-login.php"] [unique_id "al9HoU0Dwhk5-Z44Xro1IgAAApk"], referer: https://www.vivaconcierge.com.br/wp-admin/
[Tue Jul 21 07:19:13.794196 2026] [security2:error] [pid 229246:tid 229468] [client 20.206.67.15:61218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-pp.php"] [unique_id "al9HoSBMYeh5YLVG45xZ2AAAAnA"]
[Tue Jul 21 07:19:13.797603 2026] [security2:error] [pid 230252:tid 230400] [client 20.197.192.193:11148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/kq1.php"] [unique_id "al9HoU0Dwhk5-Z44Xro1IwAAAqk"]
[Tue Jul 21 07:19:13.823120 2026] [security2:error] [pid 229246:tid 229429] [client 20.197.192.193:11199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/zzz.php"] [unique_id "al9HoSBMYeh5YLVG45xZ2QAAAkk"]
[Tue Jul 21 07:19:13.837047 2026] [security2:error] [pid 229246:tid 229390] [client 20.206.67.15:59678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/w3lls.php"] [unique_id "al9HoSBMYeh5YLVG45xZ2gAAAiI"]
[Tue Jul 21 07:19:13.842028 2026] [security2:error] [pid 230252:tid 230402] [client 20.151.10.161:55252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ccc.php"] [unique_id "al9HoU0Dwhk5-Z44Xro1JAAAAqs"]
[Tue Jul 21 07:19:13.902819 2026] [security2:error] [pid 229246:tid 229479] [client 20.206.67.15:61293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/sbhu.php"] [unique_id "al9HoSBMYeh5YLVG45xZ3QAAAns"]
[Tue Jul 21 07:19:13.909535 2026] [security2:error] [pid 229246:tid 229490] [client 20.197.192.193:16860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/wicked.php"] [unique_id "al9HoSBMYeh5YLVG45xZ3gAAAoY"]
[Tue Jul 21 07:19:13.926473 2026] [security2:error] [pid 229246:tid 229476] [client 20.206.67.15:59694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-content/uploads/admin.php"] [unique_id "al9HoSBMYeh5YLVG45xZ3wAAAng"]
[Tue Jul 21 07:19:13.947259 2026] [security2:error] [pid 230252:tid 230404] [client 4.204.201.85:35332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/jp.php"] [unique_id "al9HoU0Dwhk5-Z44Xro1JQAAAq0"]
[Tue Jul 21 07:19:13.971754 2026] [security2:error] [pid 229246:tid 229496] [client 20.197.192.193:11152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/edit.php"] [unique_id "al9HoSBMYeh5YLVG45xZ4AAAAow"]
[Tue Jul 21 07:19:14.043458 2026] [security2:error] [pid 229246:tid 229475] [client 20.206.67.15:61299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/favicon.php"] [unique_id "al9HoiBMYeh5YLVG45xZ4wAAAnc"]
[Tue Jul 21 07:19:14.077764 2026] [security2:error] [pid 230252:tid 230403] [client 209.141.34.121:53117] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "odontoclinicms.com.br"] [uri "/"] [unique_id "al9Hok0Dwhk5-Z44Xro1KgAAAqw"]
[Tue Jul 21 07:19:14.121806 2026] [autoindex:error] [pid 229246:tid 229366] [remote 104.253.36.208:52277] AH01276: Cannot serve directory /home2/ric83751/sanovitta.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:14.139615 2026] [security2:error] [pid 229246:tid 229451] [client 20.151.10.161:53573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/get.php"] [unique_id "al9HoiBMYeh5YLVG45xZ5gAAAl8"]
[Tue Jul 21 07:19:14.179856 2026] [security2:error] [pid 229246:tid 229477] [client 20.151.10.161:46025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/122.php"] [unique_id "al9HoiBMYeh5YLVG45xZ6AAAAnk"]
[Tue Jul 21 07:19:14.213792 2026] [security2:error] [pid 229246:tid 229385] [client 20.206.67.15:59585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/txets.php"] [unique_id "al9HoiBMYeh5YLVG45xZ6QAAAh0"]
[Tue Jul 21 07:19:14.236537 2026] [security2:error] [pid 229246:tid 229459] [client 20.197.192.193:16878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/kua.php"] [unique_id "al9HoiBMYeh5YLVG45xZ6wAAAmc"]
[Tue Jul 21 07:19:14.275226 2026] [security2:error] [pid 229246:tid 229266] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HoiBMYeh5YLVG45xZ7gACOhM"]
[Tue Jul 21 07:19:14.275377 2026] [security2:error] [pid 229246:tid 229414] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HoiBMYeh5YLVG45xZ7gACOhM"]
[Tue Jul 21 07:19:14.304044 2026] [security2:error] [pid 229246:tid 229448] [client 20.206.67.15:61267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-su.php"] [unique_id "al9HoiBMYeh5YLVG45xZ7wAAAlw"]
[Tue Jul 21 07:19:14.376329 2026] [security2:error] [pid 229246:tid 229404] [client 20.206.67.15:61278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/ff.php"] [unique_id "al9HoiBMYeh5YLVG45xZ8AAAAjA"]
[Tue Jul 21 07:19:14.393453 2026] [security2:error] [pid 230252:tid 230414] [client 20.206.67.15:61253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/reze.php"] [unique_id "al9Hok0Dwhk5-Z44Xro1KwAAArc"]
[Tue Jul 21 07:19:14.501207 2026] [security2:error] [pid 230252:tid 230417] [client 20.206.67.15:59711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/666.php"] [unique_id "al9Hok0Dwhk5-Z44Xro1LAAAAro"]
[Tue Jul 21 07:19:14.519090 2026] [security2:error] [pid 230252:tid 230418] [client 20.151.10.161:53577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/images.php"] [unique_id "al9Hok0Dwhk5-Z44Xro1LQAAArs"]
[Tue Jul 21 07:19:14.550909 2026] [security2:error] [pid 230252:tid 230420] [client 20.197.192.193:11137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/ez.php"] [unique_id "al9Hok0Dwhk5-Z44Xro1LwAAAr0"]
[Tue Jul 21 07:19:14.625247 2026] [security2:error] [pid 229246:tid 229435] [client 20.206.67.15:59704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wehrman.php"] [unique_id "al9HoiBMYeh5YLVG45xZ-AAAAk8"]
[Tue Jul 21 07:19:14.686287 2026] [security2:error] [pid 230252:tid 230427] [client 4.204.201.85:35345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/f35.php"] [unique_id "al9Hok0Dwhk5-Z44Xro1MQAAAsQ"]
[Tue Jul 21 07:19:14.696893 2026] [security2:error] [pid 229246:tid 229423] [client 20.206.67.15:59706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-conflg.php"] [unique_id "al9HoiBMYeh5YLVG45xZ-gAAAkM"]
[Tue Jul 21 07:19:14.747374 2026] [security2:error] [pid 229246:tid 229301] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/zc-208.php"] [unique_id "al9HoiBMYeh5YLVG45xZ_AACazY"]
[Tue Jul 21 07:19:14.758343 2026] [security2:error] [pid 229246:tid 229433] [client 20.206.67.15:59675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/ff1.php"] [unique_id "al9HoiBMYeh5YLVG45xZ_QAAAk0"]
[Tue Jul 21 07:19:14.790685 2026] [security2:error] [pid 229246:tid 229307] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/sid4.php"] [unique_id "al9HoiBMYeh5YLVG45xZ_gACWzw"]
[Tue Jul 21 07:19:14.805225 2026] [security2:error] [pid 229246:tid 229499] [client 20.206.67.15:61192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/fff.php"] [unique_id "al9HoiBMYeh5YLVG45xZ_wAAAo8"]
[Tue Jul 21 07:19:14.830968 2026] [autoindex:error] [pid 229246:tid 229279] [remote 20.226.60.151:0] AH01276: Cannot serve directory /home4/wende360/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:14.838954 2026] [security2:error] [pid 229246:tid 229496] [client 20.206.67.15:59623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/amax.php"] [unique_id "al9HoiBMYeh5YLVG45xaAgAAAow"]
[Tue Jul 21 07:19:14.876339 2026] [security2:error] [pid 229246:tid 229314] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wmore1.php"] [unique_id "al9HoiBMYeh5YLVG45xaBAACd0M"]
[Tue Jul 21 07:19:14.911870 2026] [security2:error] [pid 230252:tid 230442] [client 20.206.67.15:59634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-firewall.php"] [unique_id "al9Hok0Dwhk5-Z44Xro1NwAAAtM"]
[Tue Jul 21 07:19:14.916267 2026] [security2:error] [pid 229246:tid 229281] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/solo1.php"] [unique_id "al9HoiBMYeh5YLVG45xaCAACbCI"]
[Tue Jul 21 07:19:14.950470 2026] [security2:error] [pid 230252:tid 230446] [client 20.206.67.15:59645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/appt.php"] [unique_id "al9Hok0Dwhk5-Z44Xro1OQAAAtc"]
[Tue Jul 21 07:19:14.974451 2026] [security2:error] [pid 230252:tid 230448] [client 20.206.67.15:59604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-thi.php"] [unique_id "al9Hok0Dwhk5-Z44Xro1OgAAAtk"]
[Tue Jul 21 07:19:14.980733 2026] [security2:error] [pid 230252:tid 230450] [client 20.151.10.161:53596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/alls.php"] [unique_id "al9Hok0Dwhk5-Z44Xro1OwAAAts"]
[Tue Jul 21 07:19:14.998172 2026] [autoindex:error] [pid 229246:tid 229316] [remote 20.226.60.151:0] AH01276: Cannot serve directory /home4/wende360/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:15.003043 2026] [security2:error] [pid 229246:tid 229418] [client 20.206.67.15:61216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/jj.php"] [unique_id "al9HoyBMYeh5YLVG45xaDAAAAj4"]
[Tue Jul 21 07:19:15.046751 2026] [security2:error] [pid 230252:tid 230451] [client 4.204.201.85:26388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/ccc.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1PAAAAtw"]
[Tue Jul 21 07:19:15.053239 2026] [security2:error] [pid 229246:tid 229303] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/cong.php"] [unique_id "al9HoyBMYeh5YLVG45xaDwACHTg"]
[Tue Jul 21 07:19:15.062629 2026] [security2:error] [pid 229246:tid 229466] [client 20.206.67.15:61231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/333.php"] [unique_id "al9HoyBMYeh5YLVG45xaEQAAAm4"]
[Tue Jul 21 07:19:15.087340 2026] [autoindex:error] [pid 229246:tid 229317] [remote 20.226.60.151:0] AH01276: Cannot serve directory /home4/wende360/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:15.092471 2026] [security2:error] [pid 230252:tid 230452] [client 20.206.67.15:61234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/albin.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1PQAAAt0"]
[Tue Jul 21 07:19:15.123476 2026] [security2:error] [pid 230252:tid 230455] [client 20.206.67.15:61187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/66.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1PgAAAuA"]
[Tue Jul 21 07:19:15.124518 2026] [security2:error] [pid 230252:tid 230456] [client 4.204.201.85:35451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wp-load.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1PwAAAuE"]
[Tue Jul 21 07:19:15.134847 2026] [security2:error] [pid 229246:tid 229319] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/public/css.php"] [unique_id "al9HoyBMYeh5YLVG45xaEwACWUg"]
[Tue Jul 21 07:19:15.158391 2026] [security2:error] [pid 230252:tid 230458] [client 20.206.67.15:59656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/motu.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1QAAAAuM"]
[Tue Jul 21 07:19:15.177448 2026] [security2:error] [pid 229246:tid 229327] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/output.php"] [unique_id "al9HoyBMYeh5YLVG45xaFAACOlA"]
[Tue Jul 21 07:19:15.211288 2026] [security2:error] [pid 229246:tid 229296] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-file-120.php"] [unique_id "al9HoyBMYeh5YLVG45xaFQACKTE"]
[Tue Jul 21 07:19:15.225868 2026] [security2:error] [pid 229246:tid 229323] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/special.php"] [unique_id "al9HoyBMYeh5YLVG45xaFgACjUw"]
[Tue Jul 21 07:19:15.239708 2026] [security2:error] [pid 229246:tid 229326] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/as.php"] [unique_id "al9HoyBMYeh5YLVG45xaGAAChE8"]
[Tue Jul 21 07:19:15.253748 2026] [security2:error] [pid 229246:tid 229321] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9HoyBMYeh5YLVG45xaGgACMEo"]
[Tue Jul 21 07:19:15.290109 2026] [security2:error] [pid 229246:tid 229304] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/w1px.php"] [unique_id "al9HoyBMYeh5YLVG45xaGwACkTk"]
[Tue Jul 21 07:19:15.303810 2026] [security2:error] [pid 229246:tid 229290] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/yawa.php"] [unique_id "al9HoyBMYeh5YLVG45xaHAACLis"]
[Tue Jul 21 07:19:15.317960 2026] [security2:error] [pid 229246:tid 229337] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/js.php"] [unique_id "al9HoyBMYeh5YLVG45xaHQACSVo"]
[Tue Jul 21 07:19:15.321335 2026] [security2:error] [pid 230252:tid 230466] [client 20.206.67.15:61307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/kj.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1QgAAAus"]
[Tue Jul 21 07:19:15.322294 2026] [security2:error] [pid 230252:tid 230467] [client 20.151.10.161:55246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/yyu.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1QwAAAuw"]
[Tue Jul 21 07:19:15.370300 2026] [security2:error] [pid 229246:tid 229330] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/core.php"] [unique_id "al9HoyBMYeh5YLVG45xaHgACYVM"]
[Tue Jul 21 07:19:15.392659 2026] [security2:error] [pid 229246:tid 229467] [client 20.206.67.15:57740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp4.php"] [unique_id "al9HoyBMYeh5YLVG45xaHwAAAm8"]
[Tue Jul 21 07:19:15.420220 2026] [security2:error] [pid 229246:tid 229345] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/19.php"] [unique_id "al9HoyBMYeh5YLVG45xaIAACcmI"]
[Tue Jul 21 07:19:15.429007 2026] [security2:error] [pid 229246:tid 229417] [client 20.197.192.193:11175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/fz.php"] [unique_id "al9HoyBMYeh5YLVG45xaIQAAAj0"]
[Tue Jul 21 07:19:15.459864 2026] [security2:error] [pid 229246:tid 229339] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/inc.php"] [unique_id "al9HoyBMYeh5YLVG45xaIwACL1w"]
[Tue Jul 21 07:19:15.464628 2026] [security2:error] [pid 229246:tid 229401] [client 20.206.67.15:59587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/file61.php"] [unique_id "al9HoyBMYeh5YLVG45xaJAAAAi0"]
[Tue Jul 21 07:19:15.482436 2026] [security2:error] [pid 229246:tid 229331] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9HoyBMYeh5YLVG45xaJQACe1Q"]
[Tue Jul 21 07:19:15.496381 2026] [security2:error] [pid 229246:tid 229320] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9HoyBMYeh5YLVG45xaJwACdEk"]
[Tue Jul 21 07:19:15.506618 2026] [security2:error] [pid 229246:tid 229461] [client 4.204.201.85:35402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/xyn.php"] [unique_id "al9HoyBMYeh5YLVG45xaKAAAAmk"]
[Tue Jul 21 07:19:15.510725 2026] [security2:error] [pid 229246:tid 229328] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/ss.php"] [unique_id "al9HoyBMYeh5YLVG45xaKQACilE"]
[Tue Jul 21 07:19:15.516649 2026] [security2:error] [pid 229246:tid 229476] [client 4.204.201.85:26606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/w.php"] [unique_id "al9HoyBMYeh5YLVG45xaKgAAAng"]
[Tue Jul 21 07:19:15.526171 2026] [security2:error] [pid 229246:tid 229463] [client 20.206.67.15:59708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp.php"] [unique_id "al9HoyBMYeh5YLVG45xaKwAAAms"]
[Tue Jul 21 07:19:15.538288 2026] [security2:error] [pid 229246:tid 229346] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/min.php"] [unique_id "al9HoyBMYeh5YLVG45xaLAACSGM"]
[Tue Jul 21 07:19:15.553036 2026] [security2:error] [pid 229246:tid 229335] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9HoyBMYeh5YLVG45xaLQACW1g"]
[Tue Jul 21 07:19:15.566001 2026] [security2:error] [pid 229246:tid 229338] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9HoyBMYeh5YLVG45xaLwACRls"]
[Tue Jul 21 07:19:15.579846 2026] [security2:error] [pid 230252:tid 230471] [client 20.206.67.15:61196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-trackback.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1RAAAAvA"]
[Tue Jul 21 07:19:15.580363 2026] [security2:error] [pid 230252:tid 230443] [client 103.162.129.114:56452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1RQAAAtQ"]
[Tue Jul 21 07:19:15.580449 2026] [security2:error] [pid 230252:tid 230443] [client 103.162.129.114:56452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1RQAAAtQ"]
[Tue Jul 21 07:19:15.590176 2026] [security2:error] [pid 229246:tid 229352] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9HoyBMYeh5YLVG45xaMAACcGk"]
[Tue Jul 21 07:19:15.614517 2026] [security2:error] [pid 229246:tid 229347] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9HoyBMYeh5YLVG45xaMQACNmQ"]
[Tue Jul 21 07:19:15.632946 2026] [security2:error] [pid 229246:tid 229356] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/albin.php"] [unique_id "al9HoyBMYeh5YLVG45xaMgACcW0"]
[Tue Jul 21 07:19:15.667351 2026] [security2:error] [pid 230252:tid 230473] [client 20.151.10.161:53605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/by.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1RgAAAvI"]
[Tue Jul 21 07:19:15.673066 2026] [security2:error] [pid 229246:tid 229341] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/cilus.php"] [unique_id "al9HoyBMYeh5YLVG45xaMwACf14"]
[Tue Jul 21 07:19:15.697911 2026] [security2:error] [pid 229246:tid 229354] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/gptsh.php"] [unique_id "al9HoyBMYeh5YLVG45xaNQACh2s"]
[Tue Jul 21 07:19:15.736006 2026] [security2:error] [pid 229246:tid 229357] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/rithin.php"] [unique_id "al9HoyBMYeh5YLVG45xaNgACeW4"]
[Tue Jul 21 07:19:15.750289 2026] [security2:error] [pid 229246:tid 229489] [client 103.121.156.110:59075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HoyBMYeh5YLVG45xaNwAAAoU"]
[Tue Jul 21 07:19:15.750419 2026] [security2:error] [pid 229246:tid 229489] [client 103.121.156.110:59075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HoyBMYeh5YLVG45xaNwAAAoU"]
[Tue Jul 21 07:19:15.761691 2026] [security2:error] [pid 229246:tid 229490] [client 20.206.67.15:59588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/db.php"] [unique_id "al9HoyBMYeh5YLVG45xaOAAAAoY"]
[Tue Jul 21 07:19:15.765519 2026] [security2:error] [pid 229246:tid 229371] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/fffm.php"] [unique_id "al9HoyBMYeh5YLVG45xaOQACIHw"]
[Tue Jul 21 07:19:15.812746 2026] [security2:error] [pid 229246:tid 229367] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/dfre.php"] [unique_id "al9HoyBMYeh5YLVG45xaPAACMng"]
[Tue Jul 21 07:19:15.838503 2026] [security2:error] [pid 230252:tid 230482] [client 20.206.67.15:59602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/NewFile.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1SgAAAvs"]
[Tue Jul 21 07:19:15.859469 2026] [security2:error] [pid 229246:tid 229365] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-happy.php"] [unique_id "al9HoyBMYeh5YLVG45xaPQACbnY"]
[Tue Jul 21 07:19:15.862333 2026] [security2:error] [pid 229246:tid 229459] [client 20.151.10.161:46045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/green1.php"] [unique_id "al9HoyBMYeh5YLVG45xaPgAAAmc"]
[Tue Jul 21 07:19:15.887535 2026] [security2:error] [pid 229246:tid 229333] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/fpr4.php"] [unique_id "al9HoyBMYeh5YLVG45xaQAACS1Y"]
[Tue Jul 21 07:19:15.897071 2026] [security2:error] [pid 230252:tid 230486] [client 20.206.67.15:61301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/xxx.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1SwAAAv8"]
[Tue Jul 21 07:19:15.914478 2026] [security2:error] [pid 229246:tid 229343] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/file88.php"] [unique_id "al9HoyBMYeh5YLVG45xaQQACWWA"]
[Tue Jul 21 07:19:15.946985 2026] [security2:error] [pid 230252:tid 230491] [client 20.206.67.15:59684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/ms.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1TAAAAwQ"]
[Tue Jul 21 07:19:15.971027 2026] [security2:error] [pid 229246:tid 229250] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/ccc.php"] [unique_id "al9HoyBMYeh5YLVG45xaQgACOgM"]
[Tue Jul 21 07:19:15.988035 2026] [security2:error] [pid 229246:tid 229397] [client 20.206.67.15:59689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/mini.php"] [unique_id "al9HoyBMYeh5YLVG45xaQwAAAik"]
[Tue Jul 21 07:19:16.031255 2026] [security2:error] [pid 229246:tid 229353] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/777.php"] [unique_id "al9HpCBMYeh5YLVG45xaRQACkmo"]
[Tue Jul 21 07:19:16.055735 2026] [security2:error] [pid 229246:tid 229251] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/for.php"] [unique_id "al9HpCBMYeh5YLVG45xaRgACTgQ"]
[Tue Jul 21 07:19:16.066909 2026] [autoindex:error] [pid 229246:tid 229448] [client 4.204.201.85:35400] AH01276: Cannot serve directory /home3/seaport/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:16.087801 2026] [security2:error] [pid 229246:tid 229253] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/ssla.php"] [unique_id "al9HpCBMYeh5YLVG45xaSAACNQY"]
[Tue Jul 21 07:19:16.095462 2026] [security2:error] [pid 230252:tid 230493] [client 20.206.67.15:57670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/first.php"] [unique_id "al9HpE0Dwhk5-Z44Xro1TgAAAwY"]
[Tue Jul 21 07:19:16.111074 2026] [security2:error] [pid 230252:tid 230495] [client 20.151.10.161:53569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/FAQ.php"] [unique_id "al9HpE0Dwhk5-Z44Xro1TwAAAwg"]
[Tue Jul 21 07:19:16.112844 2026] [security2:error] [pid 229246:tid 229280] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/zc-131.php"] [unique_id "al9HpCBMYeh5YLVG45xaSQACIiE"]
[Tue Jul 21 07:19:16.161501 2026] [security2:error] [pid 230252:tid 230496] [client 4.204.201.85:26561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9HpE0Dwhk5-Z44Xro1UAAAAwk"]
[Tue Jul 21 07:19:16.176417 2026] [security2:error] [pid 230252:tid 230498] [client 184.75.221.3:38896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9HpE0Dwhk5-Z44Xro1UgAAAws"]
[Tue Jul 21 07:19:16.176509 2026] [security2:error] [pid 230252:tid 230498] [client 184.75.221.3:38896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9HpE0Dwhk5-Z44Xro1UgAAAws"]
[Tue Jul 21 07:19:16.233920 2026] [security2:error] [pid 229246:tid 229435] [client 20.206.67.15:57778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/0okj.php"] [unique_id "al9HpCBMYeh5YLVG45xaTQAAAk8"]
[Tue Jul 21 07:19:16.286404 2026] [security2:error] [pid 229246:tid 229401] [client 20.206.67.15:61294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/grsiuk.php"] [unique_id "al9HpCBMYeh5YLVG45xaTwAAAi0"]
[Tue Jul 21 07:19:16.338089 2026] [security2:error] [pid 230252:tid 230502] [client 20.206.67.15:61205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/shell20211028.php"] [unique_id "al9HpE0Dwhk5-Z44Xro1UwAAAw8"]
[Tue Jul 21 07:19:16.412025 2026] [autoindex:error] [pid 229246:tid 229396] [client 4.204.201.85:35400] AH01276: Cannot serve directory /home3/seaport/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:16.477090 2026] [security2:error] [pid 229246:tid 229496] [client 20.206.67.15:59650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/revealability.php"] [unique_id "al9HpCBMYeh5YLVG45xaVwAAAow"]
[Tue Jul 21 07:19:16.553252 2026] [security2:error] [pid 229246:tid 229387] [client 4.204.201.85:35455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/ccc.php"] [unique_id "al9HpCBMYeh5YLVG45xaWAAAAh8"]
[Tue Jul 21 07:19:16.608109 2026] [security2:error] [pid 229246:tid 229483] [client 20.206.67.15:61252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/btx25.php"] [unique_id "al9HpCBMYeh5YLVG45xaWgAAAn8"]
[Tue Jul 21 07:19:16.627054 2026] [security2:error] [pid 229246:tid 229471] [client 20.197.192.193:11171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/la.php"] [unique_id "al9HpCBMYeh5YLVG45xaWwAAAnM"]
[Tue Jul 21 07:19:16.641027 2026] [security2:error] [pid 230252:tid 230507] [client 20.206.67.15:59654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/bthil.php"] [unique_id "al9HpE0Dwhk5-Z44Xro1VAAAAxQ"]
[Tue Jul 21 07:19:16.674608 2026] [security2:error] [pid 230252:tid 230509] [client 20.206.67.15:59591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/hplfuns.php"] [unique_id "al9HpE0Dwhk5-Z44Xro1VQAAAxY"]
[Tue Jul 21 07:19:16.682711 2026] [security2:error] [pid 230252:tid 230499] [client 103.187.68.224:57975] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "www.vivaconcierge.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HpE0Dwhk5-Z44Xro1VgAAAww"], referer: https://www.google.com/
[Tue Jul 21 07:19:16.683047 2026] [security2:error] [pid 230252:tid 230499] [client 103.187.68.224:57975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "www.vivaconcierge.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HpE0Dwhk5-Z44Xro1VgAAAww"], referer: https://www.google.com/
[Tue Jul 21 07:19:16.707071 2026] [security2:error] [pid 229246:tid 229377] [client 20.206.67.15:59607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/error.php"] [unique_id "al9HpCBMYeh5YLVG45xaXAAAAhU"]
[Tue Jul 21 07:19:16.788253 2026] [security2:error] [pid 229246:tid 229478] [client 20.206.67.15:59702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/edit.php"] [unique_id "al9HpCBMYeh5YLVG45xaXQAAAno"]
[Tue Jul 21 07:19:16.880558 2026] [security2:error] [pid 229246:tid 229459] [client 4.204.201.85:35410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/w.php"] [unique_id "al9HpCBMYeh5YLVG45xaYQAAAmc"]
[Tue Jul 21 07:19:16.894596 2026] [security2:error] [pid 229246:tid 229424] [client 20.197.192.193:16893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9HpCBMYeh5YLVG45xaYgAAAkQ"]
[Tue Jul 21 07:19:16.908893 2026] [security2:error] [pid 229246:tid 229431] [client 20.206.67.15:61270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/pass4.php"] [unique_id "al9HpCBMYeh5YLVG45xaYwAAAks"]
[Tue Jul 21 07:19:16.914141 2026] [security2:error] [pid 229246:tid 229445] [client 4.204.201.85:26405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/FWAZ.php"] [unique_id "al9HpCBMYeh5YLVG45xaZAAAAlk"]
[Tue Jul 21 07:19:16.946788 2026] [security2:error] [pid 229246:tid 229399] [client 92.119.178.3:33464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9HpCBMYeh5YLVG45xaZgAAAis"]
[Tue Jul 21 07:19:16.946911 2026] [security2:error] [pid 229246:tid 229399] [client 92.119.178.3:33464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9HpCBMYeh5YLVG45xaZgAAAis"]
[Tue Jul 21 07:19:17.066560 2026] [security2:error] [pid 229246:tid 229288] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpSBMYeh5YLVG45xaZwAChik"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:17.067498 2026] [security2:error] [pid 229246:tid 229278] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpSBMYeh5YLVG45xaaAACIB8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:17.075280 2026] [security2:error] [pid 229246:tid 229368] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpSBMYeh5YLVG45xaaQACj3k"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:17.107673 2026] [security2:error] [pid 229246:tid 229488] [client 20.197.192.193:11156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/inso.php"] [unique_id "al9HpSBMYeh5YLVG45xaagAAAoQ"]
[Tue Jul 21 07:19:17.183033 2026] [security2:error] [pid 229246:tid 229385] [client 14.139.42.196:12901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HpSBMYeh5YLVG45xabAAAAh0"]
[Tue Jul 21 07:19:17.183656 2026] [security2:error] [pid 229246:tid 229385] [client 14.139.42.196:12901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HpSBMYeh5YLVG45xabAAAAh0"]
[Tue Jul 21 07:19:17.231769 2026] [security2:error] [pid 229246:tid 229451] [client 20.151.10.161:53580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/coffexium.php"] [unique_id "al9HpSBMYeh5YLVG45xabwAAAl8"]
[Tue Jul 21 07:19:17.264105 2026] [security2:error] [pid 229246:tid 229435] [client 4.204.201.85:35340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9HpSBMYeh5YLVG45xacAAAAk8"]
[Tue Jul 21 07:19:17.277369 2026] [security2:error] [pid 229246:tid 229470] [client 20.197.192.193:11158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/wpx.php"] [unique_id "al9HpSBMYeh5YLVG45xacQAAAnI"]
[Tue Jul 21 07:19:17.355792 2026] [security2:error] [pid 229246:tid 229400] [client 20.151.10.161:45971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/biufile.php"] [unique_id "al9HpSBMYeh5YLVG45xacgAAAiw"]
[Tue Jul 21 07:19:17.421520 2026] [security2:error] [pid 229246:tid 229293] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpSBMYeh5YLVG45xadgACii4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:17.428100 2026] [security2:error] [pid 229246:tid 229297] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpSBMYeh5YLVG45xadwACazI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:17.463154 2026] [security2:error] [pid 229246:tid 229358] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpSBMYeh5YLVG45xaeAACQ28"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:17.510447 2026] [security2:error] [pid 229246:tid 229468] [client 20.197.192.193:11159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/berlin.php"] [unique_id "al9HpSBMYeh5YLVG45xaegAAAnA"]
[Tue Jul 21 07:19:17.554004 2026] [security2:error] [pid 229246:tid 229366] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpSBMYeh5YLVG45xafAACanc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:17.586557 2026] [security2:error] [pid 229246:tid 229483] [client 4.204.201.85:25990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/miru1.php"] [unique_id "al9HpSBMYeh5YLVG45xafQAAAn8"]
[Tue Jul 21 07:19:17.643669 2026] [security2:error] [pid 229246:tid 229477] [client 4.204.201.85:35342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/FWAZ.php"] [unique_id "al9HpSBMYeh5YLVG45xafwAAAnk"]
[Tue Jul 21 07:19:17.646910 2026] [security2:error] [pid 229246:tid 229476] [client 20.197.192.193:11186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/billur.php"] [unique_id "al9HpSBMYeh5YLVG45xagAAAAng"]
[Tue Jul 21 07:19:17.735066 2026] [security2:error] [pid 229246:tid 229478] [client 20.151.10.161:55244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/red.php"] [unique_id "al9HpSBMYeh5YLVG45xagQAAAno"]
[Tue Jul 21 07:19:17.780118 2026] [security2:error] [pid 229246:tid 229266] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpSBMYeh5YLVG45xahAACMhM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:17.781904 2026] [security2:error] [pid 229246:tid 229300] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpSBMYeh5YLVG45xahQACbjU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:17.865685 2026] [security2:error] [pid 229246:tid 229283] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpSBMYeh5YLVG45xahwACOiQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:17.874287 2026] [security2:error] [pid 229246:tid 229397] [client 20.197.192.193:11218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/mimpi.php"] [unique_id "al9HpSBMYeh5YLVG45xaiAAAAik"]
[Tue Jul 21 07:19:17.927115 2026] [security2:error] [pid 229246:tid 229488] [client 184.75.221.3:38900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9HpSBMYeh5YLVG45xajAAAAoQ"]
[Tue Jul 21 07:19:17.927206 2026] [security2:error] [pid 229246:tid 229488] [client 184.75.221.3:38900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9HpSBMYeh5YLVG45xajAAAAoQ"]
[Tue Jul 21 07:19:18.017756 2026] [security2:error] [pid 229246:tid 229435] [client 4.204.201.85:35390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/miru1.php"] [unique_id "al9HpiBMYeh5YLVG45xajQAAAk8"]
[Tue Jul 21 07:19:18.053334 2026] [security2:error] [pid 229246:tid 229401] [client 20.197.192.193:16851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/dp.php"] [unique_id "al9HpiBMYeh5YLVG45xakQAAAi0"]
[Tue Jul 21 07:19:18.131758 2026] [security2:error] [pid 229246:tid 229301] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpiBMYeh5YLVG45xalAACdDY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:18.135860 2026] [security2:error] [pid 229246:tid 229307] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpiBMYeh5YLVG45xalQACezw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:18.159584 2026] [security2:error] [pid 229246:tid 229501] [client 136.144.33.241:33449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9HpiBMYeh5YLVG45xalgAAApE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:18.233650 2026] [security2:error] [pid 229246:tid 229311] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpiBMYeh5YLVG45xamQACSEA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:18.235329 2026] [security2:error] [pid 229246:tid 229279] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HpiBMYeh5YLVG45xamAACaSA"]
[Tue Jul 21 07:19:18.235464 2026] [security2:error] [pid 229246:tid 229461] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HpiBMYeh5YLVG45xamAACaSA"]
[Tue Jul 21 07:19:18.260189 2026] [security2:error] [pid 229246:tid 229416] [client 20.151.10.161:55248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9HpiBMYeh5YLVG45xamgAAAjw"]
[Tue Jul 21 07:19:18.431773 2026] [security2:error] [pid 229246:tid 229409] [client 4.204.201.85:26430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/aa.php"] [unique_id "al9HpiBMYeh5YLVG45xaogAAAjU"]
[Tue Jul 21 07:19:18.435115 2026] [security2:error] [pid 229246:tid 229316] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpiBMYeh5YLVG45xaowAChUU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:18.490403 2026] [security2:error] [pid 229246:tid 229303] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpiBMYeh5YLVG45xapQACfjg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:18.493517 2026] [security2:error] [pid 229246:tid 229317] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpiBMYeh5YLVG45xapgACMkY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:18.509268 2026] [security2:error] [pid 229246:tid 229466] [client 20.197.192.193:16839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/bootstrap.php"] [unique_id "al9HpiBMYeh5YLVG45xapwAAAm4"]
[Tue Jul 21 07:19:18.523032 2026] [security2:error] [pid 229246:tid 229459] [client 4.204.201.85:35351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/aa.php"] [unique_id "al9HpiBMYeh5YLVG45xaqAAAAmc"]
[Tue Jul 21 07:19:18.594626 2026] [security2:error] [pid 229246:tid 229327] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpiBMYeh5YLVG45xaqgACK1A"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:18.711235 2026] [security2:error] [pid 229246:tid 229448] [client 20.197.192.193:11255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/wp-editor.php"] [unique_id "al9HpiBMYeh5YLVG45xarAAAAlw"]
[Tue Jul 21 07:19:18.810251 2026] [security2:error] [pid 229246:tid 229402] [client 20.197.192.193:16832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/cro.php"] [unique_id "al9HpiBMYeh5YLVG45xarwAAAi4"]
[Tue Jul 21 07:19:18.860778 2026] [security2:error] [pid 229246:tid 229321] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpiBMYeh5YLVG45xasgACSko"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:18.862928 2026] [autoindex:error] [pid 229246:tid 229404] [client 147.185.132.204:62000] AH01276: Cannot serve directory /home2/reser379/megaroteiros.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:18.893412 2026] [security2:error] [pid 229246:tid 229390] [client 20.151.10.161:55240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/footer.php"] [unique_id "al9HpiBMYeh5YLVG45xatAAAAiI"]
[Tue Jul 21 07:19:18.922622 2026] [security2:error] [pid 229246:tid 229304] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpiBMYeh5YLVG45xatgACPTk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:18.997997 2026] [security2:error] [pid 229246:tid 229470] [client 4.204.201.85:35336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/122.php"] [unique_id "al9HpiBMYeh5YLVG45xatwAAAnI"]
[Tue Jul 21 07:19:19.073677 2026] [security2:error] [pid 229246:tid 229401] [client 20.197.192.193:16869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/cron-tab.php"] [unique_id "al9HpyBMYeh5YLVG45xauAAAAi0"]
[Tue Jul 21 07:19:19.176237 2026] [security2:error] [pid 230252:tid 230392] [client 4.204.201.85:26585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/122.php"] [unique_id "al9Hp00Dwhk5-Z44Xro1WAAAAqE"]
[Tue Jul 21 07:19:19.350347 2026] [security2:error] [pid 229246:tid 229330] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HpyBMYeh5YLVG45xauwACLFM"]
[Tue Jul 21 07:19:19.350510 2026] [security2:error] [pid 229246:tid 229400] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HpyBMYeh5YLVG45xauwACLFM"]
[Tue Jul 21 07:19:19.404680 2026] [security2:error] [pid 229246:tid 229462] [client 4.204.201.85:35374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/get.php"] [unique_id "al9HpyBMYeh5YLVG45xavQAAAmo"]
[Tue Jul 21 07:19:19.408319 2026] [security2:error] [pid 230252:tid 230393] [client 20.151.10.161:53614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-content/index.php"] [unique_id "al9Hp00Dwhk5-Z44Xro1WgAAAqI"]
[Tue Jul 21 07:19:19.510105 2026] [security2:error] [pid 229246:tid 229339] [remote 45.146.55.205:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.55.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mecanicanogueira.com.br"] [uri "/wp-login.php"] [unique_id "al9HpyBMYeh5YLVG45xawAACRlw"]
[Tue Jul 21 07:19:19.602657 2026] [security2:error] [pid 230252:tid 230401] [client 4.204.201.85:25869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/get.php"] [unique_id "al9Hp00Dwhk5-Z44Xro1XQAAAqo"]
[Tue Jul 21 07:19:19.708729 2026] [security2:error] [pid 229246:tid 229466] [client 20.151.10.161:55290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/zoro.php"] [unique_id "al9HpyBMYeh5YLVG45xawgAAAm4"]
[Tue Jul 21 07:19:19.748807 2026] [security2:error] [pid 230252:tid 230405] [client 20.197.192.193:16849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/koiy.php"] [unique_id "al9Hp00Dwhk5-Z44Xro1XgAAAq4"]
[Tue Jul 21 07:19:19.797248 2026] [security2:error] [pid 230252:tid 230410] [client 4.204.201.85:35347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/as.php"] [unique_id "al9Hp00Dwhk5-Z44Xro1XwAAArM"]
[Tue Jul 21 07:19:19.875327 2026] [security2:error] [pid 230252:tid 230416] [client 20.197.192.193:11155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/hp2.php"] [unique_id "al9Hp00Dwhk5-Z44Xro1YwAAArk"]
[Tue Jul 21 07:19:19.952696 2026] [security2:error] [pid 230252:tid 230418] [client 20.197.192.193:11157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/hp3.php"] [unique_id "al9Hp00Dwhk5-Z44Xro1ZAAAArs"]
[Tue Jul 21 07:19:20.001378 2026] [security2:error] [pid 230252:tid 230425] [client 20.151.10.161:53616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/admin.php"] [unique_id "al9HqE0Dwhk5-Z44Xro1ZwAAAsI"]
[Tue Jul 21 07:19:20.008777 2026] [security2:error] [pid 230252:tid 230426] [client 4.204.201.85:26589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/as.php"] [unique_id "al9HqE0Dwhk5-Z44Xro1aAAAAsM"]
[Tue Jul 21 07:19:20.161708 2026] [security2:error] [pid 230252:tid 230431] [client 4.204.201.85:35330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/ccou.php"] [unique_id "al9HqE0Dwhk5-Z44Xro1aQAAAsg"]
[Tue Jul 21 07:19:20.172564 2026] [security2:error] [pid 229246:tid 229477] [client 45.251.232.145:59062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HqCBMYeh5YLVG45xaxgAAAnk"]
[Tue Jul 21 07:19:20.172689 2026] [security2:error] [pid 229246:tid 229477] [client 45.251.232.145:59062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HqCBMYeh5YLVG45xaxgAAAnk"]
[Tue Jul 21 07:19:20.180083 2026] [security2:error] [pid 229246:tid 229424] [client 20.197.192.193:11177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/aa1.php"] [unique_id "al9HqCBMYeh5YLVG45xaxwAAAkQ"]
[Tue Jul 21 07:19:20.255030 2026] [security2:error] [pid 230252:tid 230400] [client 139.135.44.145:54558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HqE0Dwhk5-Z44Xro1agAAAqk"]
[Tue Jul 21 07:19:20.255206 2026] [security2:error] [pid 230252:tid 230400] [client 139.135.44.145:54558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HqE0Dwhk5-Z44Xro1agAAAqk"]
[Tue Jul 21 07:19:20.387169 2026] [security2:error] [pid 230252:tid 230409] [client 20.151.10.161:55234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/greap.php"] [unique_id "al9HqE0Dwhk5-Z44Xro1bAAAArI"]
[Tue Jul 21 07:19:20.397397 2026] [security2:error] [pid 230252:tid 230436] [client 20.197.192.193:11164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/acew67.php"] [unique_id "al9HqE0Dwhk5-Z44Xro1bQAAAs0"]
[Tue Jul 21 07:19:20.442602 2026] [security2:error] [pid 230252:tid 230439] [client 20.151.10.161:45955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wpconf.php"] [unique_id "al9HqE0Dwhk5-Z44Xro1bwAAAtA"]
[Tue Jul 21 07:19:20.460702 2026] [security2:error] [pid 229246:tid 229388] [client 4.204.201.85:35418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/w3lls.php"] [unique_id "al9HqCBMYeh5YLVG45xaywAAAiA"]
[Tue Jul 21 07:19:20.502462 2026] [security2:error] [pid 229246:tid 229429] [client 4.204.201.85:26579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/ccou.php"] [unique_id "al9HqCBMYeh5YLVG45xa0QAAAkk"]
[Tue Jul 21 07:19:20.571347 2026] [security2:error] [pid 229246:tid 229390] [client 134.19.179.187:60274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HqCBMYeh5YLVG45xa1AAAAiI"]
[Tue Jul 21 07:19:20.571441 2026] [security2:error] [pid 229246:tid 229390] [client 134.19.179.187:60274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HqCBMYeh5YLVG45xa1AAAAiI"]
[Tue Jul 21 07:19:20.668949 2026] [security2:error] [pid 230252:tid 230450] [client 20.197.192.193:11212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/bscclapb.php"] [unique_id "al9HqE0Dwhk5-Z44Xro1dQAAAts"]
[Tue Jul 21 07:19:20.811160 2026] [security2:error] [pid 230252:tid 230452] [client 20.151.10.161:53575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/177.php"] [unique_id "al9HqE0Dwhk5-Z44Xro1dwAAAt0"]
[Tue Jul 21 07:19:20.917745 2026] [security2:error] [pid 229246:tid 229357] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HqCBMYeh5YLVG45xa2gACcm4"]
[Tue Jul 21 07:19:20.918033 2026] [security2:error] [pid 229246:tid 229470] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HqCBMYeh5YLVG45xa2gACcm4"]
[Tue Jul 21 07:19:21.020642 2026] [security2:error] [pid 229246:tid 229446] [client 173.252.95.37:45770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9HqSBMYeh5YLVG45xa3gAAAlo"]
[Tue Jul 21 07:19:21.126518 2026] [security2:error] [pid 229246:tid 229426] [client 4.204.201.85:35365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/test1.php"] [unique_id "al9HqSBMYeh5YLVG45xa4QAAAkY"]
[Tue Jul 21 07:19:21.158471 2026] [security2:error] [pid 229246:tid 229483] [client 20.151.10.161:55282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/199.php"] [unique_id "al9HqSBMYeh5YLVG45xa4gAAAn8"]
[Tue Jul 21 07:19:21.177584 2026] [security2:error] [pid 230252:tid 230408] [client 74.244.195.153:8808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.195.244.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9HqU0Dwhk5-Z44Xro1eAAAArE"]
[Tue Jul 21 07:19:21.177740 2026] [security2:error] [pid 230252:tid 230408] [client 74.244.195.153:8808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9HqU0Dwhk5-Z44Xro1eAAAArE"]
[Tue Jul 21 07:19:21.226931 2026] [security2:error] [pid 230252:tid 230456] [client 4.204.201.85:26402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/w3lls.php"] [unique_id "al9HqU0Dwhk5-Z44Xro1eQAAAuE"]
[Tue Jul 21 07:19:21.427657 2026] [security2:error] [pid 229246:tid 229424] [client 92.119.178.3:37840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HqSBMYeh5YLVG45xa5gAAAkQ"]
[Tue Jul 21 07:19:21.427751 2026] [security2:error] [pid 229246:tid 229424] [client 92.119.178.3:37840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HqSBMYeh5YLVG45xa5gAAAkQ"]
[Tue Jul 21 07:19:21.563180 2026] [security2:error] [pid 230252:tid 230467] [client 4.204.201.85:35389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/database.php"] [unique_id "al9HqU0Dwhk5-Z44Xro1fAAAAuw"]
[Tue Jul 21 07:19:21.570560 2026] [security2:error] [pid 229246:tid 229477] [client 173.252.95.40:40956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9HqSBMYeh5YLVG45xa6wAAAnk"]
[Tue Jul 21 07:19:21.580576 2026] [security2:error] [pid 230252:tid 230469] [client 20.151.10.161:55255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file52.php"] [unique_id "al9HqU0Dwhk5-Z44Xro1fQAAAu4"]
[Tue Jul 21 07:19:21.835174 2026] [security2:error] [pid 230252:tid 230264] [remote 20.153.140.50:55854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9HqU0Dwhk5-Z44Xro1hQAC4go"]
[Tue Jul 21 07:19:21.835353 2026] [security2:error] [pid 230252:tid 230457] [client 20.153.140.50:55854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9HqU0Dwhk5-Z44Xro1hQAC4go"]
[Tue Jul 21 07:19:21.938040 2026] [security2:error] [pid 229246:tid 229401] [client 4.204.201.85:26026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/test1.php"] [unique_id "al9HqSBMYeh5YLVG45xa8QAAAi0"]
[Tue Jul 21 07:19:22.050706 2026] [security2:error] [pid 229246:tid 229479] [client 20.151.10.161:53571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/122.php"] [unique_id "al9HqiBMYeh5YLVG45xa9QAAAns"]
[Tue Jul 21 07:19:22.053588 2026] [security2:error] [pid 230252:tid 230482] [client 4.204.201.85:35349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/file.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1hwAAAvs"]
[Tue Jul 21 07:19:22.084117 2026] [security2:error] [pid 230252:tid 230483] [client 20.197.192.193:11162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/else1.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1iAAAAvw"]
[Tue Jul 21 07:19:22.320153 2026] [security2:error] [pid 230252:tid 230492] [client 134.19.179.187:60288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1iQAAAwU"]
[Tue Jul 21 07:19:22.320265 2026] [security2:error] [pid 230252:tid 230492] [client 134.19.179.187:60288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1iQAAAwU"]
[Tue Jul 21 07:19:22.417248 2026] [security2:error] [pid 230252:tid 230473] [client 175.45.70.82:63355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1igAAAvI"]
[Tue Jul 21 07:19:22.417407 2026] [security2:error] [pid 230252:tid 230473] [client 175.45.70.82:63355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1igAAAvI"]
[Tue Jul 21 07:19:22.432049 2026] [security2:error] [pid 230252:tid 230496] [client 20.151.10.161:53629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/green1.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1iwAAAwk"]
[Tue Jul 21 07:19:22.490981 2026] [security2:error] [pid 229246:tid 229471] [client 4.204.201.85:26427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/database.php"] [unique_id "al9HqiBMYeh5YLVG45xa-wAAAnM"]
[Tue Jul 21 07:19:22.552444 2026] [security2:error] [pid 230252:tid 230265] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1jAADBws"]
[Tue Jul 21 07:19:22.552635 2026] [security2:error] [pid 230252:tid 230494] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1jAADBws"]
[Tue Jul 21 07:19:22.666243 2026] [security2:error] [pid 229246:tid 229483] [client 4.204.201.85:35379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/file.php"] [unique_id "al9HqiBMYeh5YLVG45xbAgAAAn8"]
[Tue Jul 21 07:19:22.749691 2026] [security2:error] [pid 230252:tid 230389] [client 20.197.192.193:11166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/tkikikoko.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1lgAAAp4"]
[Tue Jul 21 07:19:22.752806 2026] [security2:error] [pid 229246:tid 229467] [client 193.36.225.73:25867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9HqiBMYeh5YLVG45xa_QAAAm8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:22.869484 2026] [security2:error] [pid 230252:tid 230396] [client 4.204.201.85:25998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/file.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1mAAAAqU"]
[Tue Jul 21 07:19:22.905688 2026] [security2:error] [pid 230252:tid 230397] [client 20.197.192.193:16880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1mQAAAqY"]
[Tue Jul 21 07:19:22.934470 2026] [security2:error] [pid 230252:tid 230453] [client 103.187.68.224:63068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.68.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.vivaconcierge.com.br"] [uri "/administrator/index.php"] [unique_id "al9HqU0Dwhk5-Z44Xro1ggAAAt4"], referer: https://www.google.com/
[Tue Jul 21 07:19:22.955339 2026] [security2:error] [pid 229246:tid 229486] [client 20.197.192.193:16846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/wp-css.php"] [unique_id "al9HqiBMYeh5YLVG45xbCAAAAoI"]
[Tue Jul 21 07:19:23.022166 2026] [security2:error] [pid 229246:tid 229397] [client 4.204.201.85:35319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/777.php"] [unique_id "al9HqyBMYeh5YLVG45xbCQAAAik"]
[Tue Jul 21 07:19:23.080599 2026] [security2:error] [pid 229246:tid 229496] [client 20.197.192.193:11191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/wp-explorer.php"] [unique_id "al9HqyBMYeh5YLVG45xbCgAAAow"]
[Tue Jul 21 07:19:23.139179 2026] [security2:error] [pid 229246:tid 229429] [client 20.197.192.193:16838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/akismet.php"] [unique_id "al9HqyBMYeh5YLVG45xbDgAAAkk"]
[Tue Jul 21 07:19:23.198888 2026] [security2:error] [pid 229246:tid 229385] [client 20.151.10.161:53583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/biufile.php"] [unique_id "al9HqyBMYeh5YLVG45xbDwAAAh0"]
[Tue Jul 21 07:19:23.200957 2026] [security2:error] [pid 230252:tid 230266] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hq00Dwhk5-Z44Xro1nQACqgw"]
[Tue Jul 21 07:19:23.201122 2026] [security2:error] [pid 230252:tid 230401] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hq00Dwhk5-Z44Xro1nQACqgw"]
[Tue Jul 21 07:19:23.241116 2026] [security2:error] [pid 230252:tid 230411] [client 4.204.201.85:26409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/file.php"] [unique_id "al9Hq00Dwhk5-Z44Xro1nwAAArQ"]
[Tue Jul 21 07:19:23.272924 2026] [security2:error] [pid 230252:tid 230414] [client 20.220.225.223:47868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/berlin.php"] [unique_id "al9Hq00Dwhk5-Z44Xro1oAAAArc"]
[Tue Jul 21 07:19:23.283276 2026] [security2:error] [pid 229246:tid 229481] [client 20.197.192.193:11181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/ace2.php"] [unique_id "al9HqyBMYeh5YLVG45xbEAAAAn0"]
[Tue Jul 21 07:19:23.296267 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296359 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296466 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296507 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296542 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296649 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296721 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296759 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296810 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296865 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296901 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296938 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296973 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297008 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297044 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297080 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297115 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297158 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297194 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297229 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297266 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297301 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297336 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297372 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297408 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297444 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297480 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297515 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297600 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297636 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297672 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297707 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297743 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297778 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297820 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297857 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297892 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297929 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297981 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298016 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298067 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298109 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298153 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298207 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298249 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298285 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298320 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298355 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298404 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298442 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298477 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298513 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298548 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298585 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298620 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298657 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298694 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298730 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298767 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298803 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298849 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298884 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298920 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298969 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299006 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299042 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299086 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299123 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299163 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299202 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299243 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299281 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299323 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299359 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299393 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299430 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299465 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299501 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299536 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299573 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299609 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299644 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299680 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299715 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299751 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299786 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299838 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299875 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299911 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299946 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299986 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.300023 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.300069 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.300107 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.300156 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.329935 2026] [security2:error] [pid 229246:tid 229257] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HqyBMYeh5YLVG45xbEQACIAo"]
[Tue Jul 21 07:19:23.330045 2026] [security2:error] [pid 229246:tid 229388] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HqyBMYeh5YLVG45xbEQACIAo"]
[Tue Jul 21 07:19:23.346085 2026] [security2:error] [pid 230252:tid 230420] [client 20.197.192.193:11256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/ms.php"] [unique_id "al9Hq00Dwhk5-Z44Xro1ogAAAr0"]
[Tue Jul 21 07:19:23.514979 2026] [security2:error] [pid 229246:tid 229466] [client 120.61.173.56:51611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HqyBMYeh5YLVG45xbFgAAAm4"]
[Tue Jul 21 07:19:23.515126 2026] [security2:error] [pid 229246:tid 229466] [client 120.61.173.56:51611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HqyBMYeh5YLVG45xbFgAAAm4"]
[Tue Jul 21 07:19:23.589714 2026] [security2:error] [pid 230252:tid 230399] [client 4.204.201.85:35448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/ssixta.php"] [unique_id "al9Hq00Dwhk5-Z44Xro1owAAAqg"]
[Tue Jul 21 07:19:23.674490 2026] [security2:error] [pid 230252:tid 230415] [client 4.204.201.85:26398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/777.php"] [unique_id "al9Hq00Dwhk5-Z44Xro1pQAAArg"]
[Tue Jul 21 07:19:23.935613 2026] [security2:error] [pid 230252:tid 230428] [client 20.206.67.15:61275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/sadcut1.php"] [unique_id "al9Hq00Dwhk5-Z44Xro1pwAAAsU"]
[Tue Jul 21 07:19:23.968658 2026] [security2:error] [pid 230252:tid 230434] [client 20.206.67.15:57694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/bgymj.php"] [unique_id "al9Hq00Dwhk5-Z44Xro1qAAAAss"]
[Tue Jul 21 07:19:24.037527 2026] [security2:error] [pid 229246:tid 229476] [client 20.151.10.161:53572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wpconf.php"] [unique_id "al9HrCBMYeh5YLVG45xbLwAAAng"]
[Tue Jul 21 07:19:24.050185 2026] [security2:error] [pid 229246:tid 229433] [client 20.206.67.15:59681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/yas.php"] [unique_id "al9HrCBMYeh5YLVG45xbMAAAAk0"]
[Tue Jul 21 07:19:24.055592 2026] [security2:error] [pid 229246:tid 229488] [client 184.154.139.40:34782] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.alperembalagens.com.br"] [uri "/eventos.php"] [unique_id "al9HqiBMYeh5YLVG45xbBgAAAoQ"]
[Tue Jul 21 07:19:24.067236 2026] [security2:error] [pid 229246:tid 229406] [client 20.206.67.15:59666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/dx.php"] [unique_id "al9HrCBMYeh5YLVG45xbMQAAAjI"]
[Tue Jul 21 07:19:24.097218 2026] [security2:error] [pid 230252:tid 230437] [client 20.206.67.15:59637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/yellow.php"] [unique_id "al9HrE0Dwhk5-Z44Xro1qgAAAs4"]
[Tue Jul 21 07:19:24.126868 2026] [security2:error] [pid 229246:tid 229482] [client 20.206.67.15:57771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-der.php"] [unique_id "al9HrCBMYeh5YLVG45xbNQAAAn4"]
[Tue Jul 21 07:19:24.181531 2026] [security2:error] [pid 230252:tid 230440] [client 20.206.67.15:61256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/lala.php"] [unique_id "al9HrE0Dwhk5-Z44Xro1rQAAAtE"]
[Tue Jul 21 07:19:24.189120 2026] [security2:error] [pid 230252:tid 230450] [client 4.204.201.85:26591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/ssixta.php"] [unique_id "al9HrE0Dwhk5-Z44Xro1rgAAAts"]
[Tue Jul 21 07:19:24.213854 2026] [security2:error] [pid 230252:tid 230452] [client 20.206.67.15:57688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/aa.php"] [unique_id "al9HrE0Dwhk5-Z44Xro1rwAAAt0"]
[Tue Jul 21 07:19:24.237678 2026] [security2:error] [pid 229246:tid 229429] [client 4.204.201.85:35387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/1c.php"] [unique_id "al9HrCBMYeh5YLVG45xbOwAAAkk"]
[Tue Jul 21 07:19:24.327775 2026] [security2:error] [pid 230252:tid 230449] [client 20.151.10.161:46068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/mosty.php"] [unique_id "al9HrE0Dwhk5-Z44Xro1sAAAAto"]
[Tue Jul 21 07:19:24.658666 2026] [security2:error] [pid 229246:tid 229417] [client 4.204.201.85:25865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/1c.php"] [unique_id "al9HrCBMYeh5YLVG45xbRQAAAj0"]
[Tue Jul 21 07:19:24.726974 2026] [security2:error] [pid 230252:tid 230460] [client 4.204.201.85:35368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/test2.php"] [unique_id "al9HrE0Dwhk5-Z44Xro1swAAAuU"]
[Tue Jul 21 07:19:24.802559 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:55241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/mosty.php"] [unique_id "al9HrCBMYeh5YLVG45xbSgAAAlo"]
[Tue Jul 21 07:19:24.817310 2026] [security2:error] [pid 230252:tid 230270] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HrE0Dwhk5-Z44Xro1tAAC5BA"]
[Tue Jul 21 07:19:24.817494 2026] [security2:error] [pid 230252:tid 230459] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HrE0Dwhk5-Z44Xro1tAAC5BA"]
[Tue Jul 21 07:19:24.898239 2026] [security2:error] [pid 229246:tid 229387] [client 34.74.242.206:1638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "northcomm.com.br"] [uri "/robots.txt"] [unique_id "al9HrCBMYeh5YLVG45xbTQAAAh8"]
[Tue Jul 21 07:19:24.898361 2026] [security2:error] [pid 229246:tid 229387] [client 34.74.242.206:1638] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "northcomm.com.br"] [uri "/robots.txt"] [unique_id "al9HrCBMYeh5YLVG45xbTQAAAh8"]
[Tue Jul 21 07:19:24.996476 2026] [security2:error] [pid 230252:tid 230435] [client 209.141.34.121:54510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "dorathiotoadvogados.com.br"] [uri "/"] [unique_id "al9HrE0Dwhk5-Z44Xro1ugAAAsw"]
[Tue Jul 21 07:19:25.024960 2026] [security2:error] [pid 230252:tid 230444] [client 4.204.201.85:26040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/test2.php"] [unique_id "al9HrU0Dwhk5-Z44Xro1uwAAAtU"]
[Tue Jul 21 07:19:25.058244 2026] [security2:error] [pid 229246:tid 229378] [client 4.204.201.85:35443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/buy.php"] [unique_id "al9HrSBMYeh5YLVG45xbUgAAAhY"]
[Tue Jul 21 07:19:25.122725 2026] [security2:error] [pid 230252:tid 230445] [client 127.0.0.1:31652] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al9HrU0Dwhk5-Z44Xro1vQAAAtY"]
[Tue Jul 21 07:19:25.122767 2026] [security2:error] [pid 229246:tid 229400] [client 127.0.0.1:31640] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.conquisteemcasa.com.br"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al9HrSBMYeh5YLVG45xbUwAAAiw"]
[Tue Jul 21 07:19:25.122860 2026] [security2:error] [pid 230252:tid 230471] [client 74.7.175.170:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.conquisteemcasa.com.br"] [uri "/robots.txt"] [unique_id "al9HrU0Dwhk5-Z44Xro1vAAC8BE"]
[Tue Jul 21 07:19:25.136164 2026] [security2:error] [pid 230252:tid 230477] [client 34.74.242.206:1661] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "northcomm.com.br"] [uri "/"] [unique_id "al9HrU0Dwhk5-Z44Xro1vgAAAvY"]
[Tue Jul 21 07:19:25.136268 2026] [security2:error] [pid 230252:tid 230477] [client 34.74.242.206:1661] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "northcomm.com.br"] [uri "/"] [unique_id "al9HrU0Dwhk5-Z44Xro1vgAAAvY"]
[Tue Jul 21 07:19:25.419032 2026] [security2:error] [pid 229246:tid 229486] [client 4.204.201.85:26594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/buy.php"] [unique_id "al9HrSBMYeh5YLVG45xbWwAAAoI"]
[Tue Jul 21 07:19:25.511393 2026] [security2:error] [pid 229246:tid 229482] [client 209.141.34.121:54568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "dorathiotoadvogados.com.br"] [uri "/"] [unique_id "al9HrSBMYeh5YLVG45xbXQAAAn4"]
[Tue Jul 21 07:19:25.562917 2026] [security2:error] [pid 230252:tid 230490] [client 4.204.201.85:35337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/ssend.php"] [unique_id "al9HrU0Dwhk5-Z44Xro1wQAAAwM"]
[Tue Jul 21 07:19:25.977807 2026] [security2:error] [pid 230252:tid 230509] [client 4.204.201.85:35376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/item.php"] [unique_id "al9HrU0Dwhk5-Z44Xro1yAAAAxY"]
[Tue Jul 21 07:19:26.000113 2026] [security2:error] [pid 229246:tid 229453] [client 4.204.201.85:26404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/ssend.php"] [unique_id "al9HrSBMYeh5YLVG45xbYAAAAmE"]
[Tue Jul 21 07:19:26.062853 2026] [security2:error] [pid 230252:tid 230386] [client 20.151.10.161:55277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/dejavu.php"] [unique_id "al9Hrk0Dwhk5-Z44Xro1yQAAAps"]
[Tue Jul 21 07:19:26.218630 2026] [security2:error] [pid 229246:tid 229435] [client 20.151.10.161:46075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/dejavu.php"] [unique_id "al9HriBMYeh5YLVG45xbYwAAAk8"]
[Tue Jul 21 07:19:26.331283 2026] [security2:error] [pid 230252:tid 230491] [client 103.162.129.114:56947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Hrk0Dwhk5-Z44Xro1zQAAAwQ"]
[Tue Jul 21 07:19:26.331401 2026] [security2:error] [pid 230252:tid 230491] [client 103.162.129.114:56947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Hrk0Dwhk5-Z44Xro1zQAAAwQ"]
[Tue Jul 21 07:19:26.337417 2026] [security2:error] [pid 230252:tid 230395] [client 4.204.201.85:26417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/item.php"] [unique_id "al9Hrk0Dwhk5-Z44Xro1zgAAAqQ"]
[Tue Jul 21 07:19:26.390075 2026] [security2:error] [pid 229246:tid 229388] [client 4.204.201.85:35315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/ss.php"] [unique_id "al9HriBMYeh5YLVG45xbZgAAAiA"]
[Tue Jul 21 07:19:26.391614 2026] [security2:error] [pid 230252:tid 230496] [client 103.121.156.110:59494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Hrk0Dwhk5-Z44Xro10AAAAwk"]
[Tue Jul 21 07:19:26.391713 2026] [security2:error] [pid 230252:tid 230496] [client 103.121.156.110:59494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Hrk0Dwhk5-Z44Xro10AAAAwk"]
[Tue Jul 21 07:19:26.540622 2026] [security2:error] [pid 230252:tid 230398] [client 173.252.95.32:43800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Hrk0Dwhk5-Z44Xro10QAAAqc"]
[Tue Jul 21 07:19:26.748045 2026] [security2:error] [pid 230252:tid 230401] [client 4.204.201.85:26622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/ss.php"] [unique_id "al9Hrk0Dwhk5-Z44Xro10gAAAqo"]
[Tue Jul 21 07:19:26.972331 2026] [security2:error] [pid 229246:tid 229446] [client 4.204.201.85:35316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/hypo.php"] [unique_id "al9HriBMYeh5YLVG45xbbQAAAlo"]
[Tue Jul 21 07:19:27.095808 2026] [security2:error] [pid 230252:tid 230399] [client 20.197.192.193:27098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/wicked.php"] [unique_id "al9Hr00Dwhk5-Z44Xro12gAAAqg"]
[Tue Jul 21 07:19:27.366840 2026] [security2:error] [pid 230252:tid 230427] [client 4.204.201.85:35361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/users.php"] [unique_id "al9Hr00Dwhk5-Z44Xro13AAAAsQ"]
[Tue Jul 21 07:19:27.422977 2026] [security2:error] [pid 230252:tid 230430] [client 20.226.60.151:54514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/ctex1.php"] [unique_id "al9Hr00Dwhk5-Z44Xro13QAAAsc"]
[Tue Jul 21 07:19:27.780667 2026] [security2:error] [pid 229246:tid 229496] [client 193.36.225.54:30205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9HryBMYeh5YLVG45xbdwAAAow"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:27.888114 2026] [security2:error] [pid 230252:tid 230452] [client 4.204.201.85:35355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/177.php"] [unique_id "al9Hr00Dwhk5-Z44Xro14gAAAt0"]
[Tue Jul 21 07:19:28.050845 2026] [security2:error] [pid 229246:tid 229463] [client 14.139.42.196:6546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HsCBMYeh5YLVG45xbfAAAAms"]
[Tue Jul 21 07:19:28.051004 2026] [security2:error] [pid 229246:tid 229463] [client 14.139.42.196:6546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HsCBMYeh5YLVG45xbfAAAAms"]
[Tue Jul 21 07:19:28.087937 2026] [security2:error] [pid 230252:tid 230459] [client 20.151.10.161:53613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/aaf.php"] [unique_id "al9HsE0Dwhk5-Z44Xro15gAAAuQ"]
[Tue Jul 21 07:19:28.151353 2026] [security2:error] [pid 230252:tid 230462] [client 20.151.10.161:46072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/aaf.php"] [unique_id "al9HsE0Dwhk5-Z44Xro16gAAAuc"]
[Tue Jul 21 07:19:28.312507 2026] [security2:error] [pid 230252:tid 230457] [client 4.204.201.85:35274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/config.php"] [unique_id "al9HsE0Dwhk5-Z44Xro17QAAAuI"]
[Tue Jul 21 07:19:28.650647 2026] [security2:error] [pid 230252:tid 230489] [client 4.204.201.85:35290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/gettest.php"] [unique_id "al9HsE0Dwhk5-Z44Xro18QAAAwI"]
[Tue Jul 21 07:19:28.746346 2026] [security2:error] [pid 229246:tid 229350] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HsCBMYeh5YLVG45xbgQACImc"]
[Tue Jul 21 07:19:28.746505 2026] [security2:error] [pid 229246:tid 229390] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HsCBMYeh5YLVG45xbgQACImc"]
[Tue Jul 21 07:19:28.754562 2026] [security2:error] [pid 230252:tid 230480] [client 4.204.201.85:3314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/hypo.php"] [unique_id "al9HsE0Dwhk5-Z44Xro18gAAAvk"]
[Tue Jul 21 07:19:28.931696 2026] [security2:error] [pid 230252:tid 230500] [client 184.154.139.40:37340] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.alperembalagens.com.br"] [uri "/produtos-higiene.php"] [unique_id "al9HsE0Dwhk5-Z44Xro19QAAAw0"]
[Tue Jul 21 07:19:29.010122 2026] [security2:error] [pid 229246:tid 229459] [client 4.204.201.85:35329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/min.php"] [unique_id "al9HsSBMYeh5YLVG45xbhAAAAmc"]
[Tue Jul 21 07:19:29.051597 2026] [security2:error] [pid 230252:tid 230508] [client 74.249.245.134:43887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9HsU0Dwhk5-Z44Xro19wAAAxU"]
[Tue Jul 21 07:19:29.324987 2026] [security2:error] [pid 229246:tid 229417] [client 92.119.178.3:54152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9HsSBMYeh5YLVG45xbhwAAAj0"]
[Tue Jul 21 07:19:29.325098 2026] [security2:error] [pid 229246:tid 229417] [client 92.119.178.3:54152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9HsSBMYeh5YLVG45xbhwAAAj0"]
[Tue Jul 21 07:19:29.334751 2026] [security2:error] [pid 230252:tid 230386] [client 4.204.201.85:35359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/dvjul.php"] [unique_id "al9HsU0Dwhk5-Z44Xro1-AAAAps"]
[Tue Jul 21 07:19:29.599833 2026] [security2:error] [pid 230252:tid 230394] [client 20.151.10.161:55237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/term.php"] [unique_id "al9HsU0Dwhk5-Z44Xro1_AAAAqM"]
[Tue Jul 21 07:19:29.639860 2026] [security2:error] [pid 229246:tid 229428] [client 4.204.201.85:35294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/biufile.php"] [unique_id "al9HsSBMYeh5YLVG45xbiwAAAkg"]
[Tue Jul 21 07:19:29.765442 2026] [autoindex:error] [pid 230252:tid 230511] [client 167.94.146.48:51728] AH01276: Cannot serve directory /home4/dralul00/idufinance.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:29.785872 2026] [security2:error] [pid 229246:tid 229468] [client 134.19.179.187:36028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9HsSBMYeh5YLVG45xbjwAAAnA"]
[Tue Jul 21 07:19:29.785960 2026] [security2:error] [pid 229246:tid 229468] [client 134.19.179.187:36028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9HsSBMYeh5YLVG45xbjwAAAnA"]
[Tue Jul 21 07:19:29.989911 2026] [security2:error] [pid 229246:tid 229471] [client 4.204.201.85:35270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/av.php"] [unique_id "al9HsSBMYeh5YLVG45xbkAAAAnM"]
[Tue Jul 21 07:19:30.190075 2026] [security2:error] [pid 229246:tid 229267] [remote 192.249.127.213:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.127.249.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tavarescont.com.br"] [uri "/wp-login.php"] [unique_id "al9HsiBMYeh5YLVG45xblAACFRQ"]
[Tue Jul 21 07:19:30.205357 2026] [security2:error] [pid 230252:tid 230285] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Hsk0Dwhk5-Z44Xro2AgACpB8"]
[Tue Jul 21 07:19:30.205474 2026] [security2:error] [pid 230252:tid 230395] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Hsk0Dwhk5-Z44Xro2AgACpB8"]
[Tue Jul 21 07:19:30.579574 2026] [security2:error] [pid 230252:tid 230417] [client 4.204.201.85:35386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/coffexium.php"] [unique_id "al9Hsk0Dwhk5-Z44Xro2BAAAAro"]
[Tue Jul 21 07:19:30.643604 2026] [security2:error] [pid 230252:tid 230397] [client 45.251.232.145:59581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hsk0Dwhk5-Z44Xro2BgAAAqY"]
[Tue Jul 21 07:19:30.643733 2026] [security2:error] [pid 230252:tid 230397] [client 45.251.232.145:59581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hsk0Dwhk5-Z44Xro2BgAAAqY"]
[Tue Jul 21 07:19:30.743340 2026] [security2:error] [pid 230252:tid 230287] [remote 72.167.132.114:60188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Hsk0Dwhk5-Z44Xro2BwACuSE"]
[Tue Jul 21 07:19:30.763387 2026] [security2:error] [pid 230252:tid 230427] [client 20.151.10.161:12050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ha.php"] [unique_id "al9Hsk0Dwhk5-Z44Xro2CAAAAsQ"]
[Tue Jul 21 07:19:30.822723 2026] [security2:error] [pid 229246:tid 229440] [client 20.151.10.161:46029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/term.php"] [unique_id "al9HsiBMYeh5YLVG45xbmgAAAlQ"]
[Tue Jul 21 07:19:30.927300 2026] [security2:error] [pid 229246:tid 229486] [client 4.204.201.85:35377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/core.php"] [unique_id "al9HsiBMYeh5YLVG45xbnAAAAoI"]
[Tue Jul 21 07:19:31.180621 2026] [security2:error] [pid 229246:tid 229457] [client 4.204.201.85:3270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/users.php"] [unique_id "al9HsyBMYeh5YLVG45xboAAAAmU"]
[Tue Jul 21 07:19:31.239287 2026] [security2:error] [pid 229246:tid 229410] [client 4.204.201.85:35383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/als.php"] [unique_id "al9HsyBMYeh5YLVG45xboQAAAjY"]
[Tue Jul 21 07:19:31.327901 2026] [security2:error] [pid 230252:tid 230424] [client 139.135.44.145:53537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Hs00Dwhk5-Z44Xro2CgAAAsE"]
[Tue Jul 21 07:19:31.328808 2026] [security2:error] [pid 230252:tid 230424] [client 139.135.44.145:53537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Hs00Dwhk5-Z44Xro2CgAAAsE"]
[Tue Jul 21 07:19:31.598098 2026] [security2:error] [pid 229246:tid 229409] [client 4.204.201.85:35286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/simple.php"] [unique_id "al9HsyBMYeh5YLVG45xbpAAAAjU"]
[Tue Jul 21 07:19:31.626345 2026] [security2:error] [pid 230252:tid 230288] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Hs00Dwhk5-Z44Xro2CwAC1yI"]
[Tue Jul 21 07:19:31.626492 2026] [security2:error] [pid 230252:tid 230446] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Hs00Dwhk5-Z44Xro2CwAC1yI"]
[Tue Jul 21 07:19:31.639522 2026] [security2:error] [pid 230252:tid 230418] [client 193.36.225.73:37243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Hs00Dwhk5-Z44Xro2DAAAArs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:31.776688 2026] [security2:error] [pid 229246:tid 229417] [client 20.226.60.151:54575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/edorxrr.php"] [unique_id "al9HsyBMYeh5YLVG45xbqgAAAj0"]
[Tue Jul 21 07:19:31.919816 2026] [security2:error] [pid 230252:tid 230437] [client 74.244.195.153:55708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.195.244.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Hs00Dwhk5-Z44Xro2DwAAAs4"]
[Tue Jul 21 07:19:31.923548 2026] [security2:error] [pid 230252:tid 230437] [client 74.244.195.153:55708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Hs00Dwhk5-Z44Xro2DwAAAs4"]
[Tue Jul 21 07:19:31.958573 2026] [security2:error] [pid 230252:tid 230456] [client 4.204.201.85:35228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/init.php"] [unique_id "al9Hs00Dwhk5-Z44Xro2EAAAAuE"]
[Tue Jul 21 07:19:32.061731 2026] [security2:error] [pid 230252:tid 230289] [remote 182.77.62.24:56052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ellosemijoias.com.br"] [uri "/wp-login.php"] [unique_id "al9HtE0Dwhk5-Z44Xro2EgAC3iM"]
[Tue Jul 21 07:19:32.091157 2026] [security2:error] [pid 229246:tid 229401] [client 74.249.245.134:21870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HtCBMYeh5YLVG45xbrgAAAi0"]
[Tue Jul 21 07:19:32.238112 2026] [security2:error] [pid 229246:tid 229466] [client 74.7.175.163:38062] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.properketo.tryhealth.shop"] [uri "/index.php"] [unique_id "al9HtCBMYeh5YLVG45xbrQACbkA"]
[Tue Jul 21 07:19:32.287457 2026] [security2:error] [pid 230252:tid 230474] [client 4.204.201.85:35292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/fpwch.php"] [unique_id "al9HtE0Dwhk5-Z44Xro2FwAAAvM"]
[Tue Jul 21 07:19:32.643620 2026] [security2:error] [pid 230252:tid 230483] [client 4.204.201.85:35384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/domvf.php"] [unique_id "al9HtE0Dwhk5-Z44Xro2HgAAAvw"]
[Tue Jul 21 07:19:32.649979 2026] [core:alert] [pid 230252:tid 230486] [client 66.249.66.74:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:19:32.920922 2026] [security2:error] [pid 230252:tid 230471] [client 74.7.175.163:38070] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "properketo.tryhealth.shop"] [uri "/index.php"] [unique_id "al9HtE0Dwhk5-Z44Xro2IgAC8CY"], referer: https://www.properketo.tryhealth.shop/robots.txt
[Tue Jul 21 07:19:33.006333 2026] [security2:error] [pid 229246:tid 229467] [client 74.7.228.22:58790] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "properketo.tryhealth.shop"] [uri "/index.php"] [unique_id "al9HtCBMYeh5YLVG45xbvQACb1I"]
[Tue Jul 21 07:19:33.018960 2026] [security2:error] [pid 230252:tid 230508] [client 4.204.201.85:35277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wp.php"] [unique_id "al9HtU0Dwhk5-Z44Xro2JQAAAxU"]
[Tue Jul 21 07:19:33.119712 2026] [security2:error] [pid 230252:tid 230509] [client 68.235.38.2:52062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9HtU0Dwhk5-Z44Xro2JgAAAxY"]
[Tue Jul 21 07:19:33.119843 2026] [security2:error] [pid 230252:tid 230509] [client 68.235.38.2:52062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9HtU0Dwhk5-Z44Xro2JgAAAxY"]
[Tue Jul 21 07:19:33.145758 2026] [security2:error] [pid 230252:tid 230386] [client 4.204.201.85:3284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/177.php"] [unique_id "al9HtU0Dwhk5-Z44Xro2JwAAAps"]
[Tue Jul 21 07:19:33.187982 2026] [security2:error] [pid 229246:tid 229426] [client 175.45.70.82:63824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HtSBMYeh5YLVG45xbvwAAAkY"]
[Tue Jul 21 07:19:33.188107 2026] [security2:error] [pid 229246:tid 229426] [client 175.45.70.82:63824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HtSBMYeh5YLVG45xbvwAAAkY"]
[Tue Jul 21 07:19:33.206185 2026] [security2:error] [pid 229246:tid 229486] [client 20.151.10.161:55272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/hur.php"] [unique_id "al9HtSBMYeh5YLVG45xbwQAAAoI"]
[Tue Jul 21 07:19:33.232360 2026] [security2:error] [pid 229246:tid 229337] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HtSBMYeh5YLVG45xbxAAChVo"]
[Tue Jul 21 07:19:33.232498 2026] [security2:error] [pid 229246:tid 229489] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HtSBMYeh5YLVG45xbxAAChVo"]
[Tue Jul 21 07:19:33.463944 2026] [security2:error] [pid 230252:tid 230396] [client 4.204.201.85:35298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/class.php"] [unique_id "al9HtU0Dwhk5-Z44Xro2KwAAAqU"]
[Tue Jul 21 07:19:33.644894 2026] [security2:error] [pid 230252:tid 230295] [remote 4.205.168.44:33884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/wp-login.php"] [unique_id "al9HtU0Dwhk5-Z44Xro2LgADECk"]
[Tue Jul 21 07:19:33.680252 2026] [security2:error] [pid 230252:tid 230388] [client 74.249.245.134:21863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp.php"] [unique_id "al9HtU0Dwhk5-Z44Xro2LwAAAp0"]
[Tue Jul 21 07:19:33.728056 2026] [security2:error] [pid 229246:tid 229303] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HtSBMYeh5YLVG45xbxgACjzg"]
[Tue Jul 21 07:19:33.728241 2026] [security2:error] [pid 229246:tid 229499] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HtSBMYeh5YLVG45xbxgACjzg"]
[Tue Jul 21 07:19:33.822979 2026] [security2:error] [pid 229246:tid 229399] [client 4.204.201.85:35338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/echkm.php"] [unique_id "al9HtSBMYeh5YLVG45xbygAAAis"]
[Tue Jul 21 07:19:33.846116 2026] [security2:error] [pid 230252:tid 230296] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HtU0Dwhk5-Z44Xro2MQACrio"]
[Tue Jul 21 07:19:33.846327 2026] [security2:error] [pid 230252:tid 230405] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HtU0Dwhk5-Z44Xro2MQACrio"]
[Tue Jul 21 07:19:33.918856 2026] [security2:error] [pid 229246:tid 229494] [client 20.226.60.151:54470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/miru1.php"] [unique_id "al9HtSBMYeh5YLVG45xbywAAAoo"]
[Tue Jul 21 07:19:34.078757 2026] [security2:error] [pid 230252:tid 230299] [remote 64.225.121.94:47712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedrocromo.com.br"] [uri "/wp-login.php"] [unique_id "al9Htk0Dwhk5-Z44Xro2NAACsy0"]
[Tue Jul 21 07:19:34.093997 2026] [security2:error] [pid 230252:tid 230506] [client 173.252.95.24:54314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9HtE0Dwhk5-Z44Xro2JAAAAxM"]
[Tue Jul 21 07:19:34.151083 2026] [security2:error] [pid 229246:tid 229457] [client 120.61.173.56:52115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HtiBMYeh5YLVG45xb0QAAAmU"]
[Tue Jul 21 07:19:34.151191 2026] [security2:error] [pid 229246:tid 229457] [client 120.61.173.56:52115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HtiBMYeh5YLVG45xb0QAAAmU"]
[Tue Jul 21 07:19:34.196830 2026] [security2:error] [pid 229246:tid 229428] [client 4.204.201.85:35411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/lib.php"] [unique_id "al9HtiBMYeh5YLVG45xb0gAAAkg"]
[Tue Jul 21 07:19:34.412804 2026] [security2:error] [pid 230252:tid 230407] [client 4.204.201.85:3208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/config.php"] [unique_id "al9Htk0Dwhk5-Z44Xro2OgAAArA"]
[Tue Jul 21 07:19:34.536657 2026] [security2:error] [pid 230252:tid 230423] [client 4.204.201.85:35366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/login.php"] [unique_id "al9Htk0Dwhk5-Z44Xro2OwAAAsA"]
[Tue Jul 21 07:19:34.588197 2026] [security2:error] [pid 230252:tid 230449] [client 74.249.245.134:56117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/new.php"] [unique_id "al9Htk0Dwhk5-Z44Xro2PQAAAto"]
[Tue Jul 21 07:19:34.830564 2026] [security2:error] [pid 229246:tid 229467] [client 4.204.201.85:35309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/a2.php"] [unique_id "al9HtiBMYeh5YLVG45xb4QAAAm8"]
[Tue Jul 21 07:19:34.861136 2026] [security2:error] [pid 230252:tid 230464] [client 20.197.192.193:27149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/edit.php"] [unique_id "al9Htk0Dwhk5-Z44Xro2RgAAAuk"]
[Tue Jul 21 07:19:34.996126 2026] [security2:error] [pid 229246:tid 229396] [client 4.204.201.85:3215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/gettest.php"] [unique_id "al9HtiBMYeh5YLVG45xb5AAAAig"]
[Tue Jul 21 07:19:35.028900 2026] [security2:error] [pid 230252:tid 230477] [client 4.204.201.85:44016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Ht00Dwhk5-Z44Xro2SQAAAvY"]
[Tue Jul 21 07:19:35.125176 2026] [security2:error] [pid 230252:tid 230486] [client 4.204.201.85:35241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/d61.php"] [unique_id "al9Ht00Dwhk5-Z44Xro2SwAAAv8"]
[Tue Jul 21 07:19:35.375371 2026] [security2:error] [pid 230252:tid 230492] [client 4.204.201.85:3222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/min.php"] [unique_id "al9Ht00Dwhk5-Z44Xro2TQAAAwU"]
[Tue Jul 21 07:19:35.437469 2026] [security2:error] [pid 229246:tid 229402] [client 4.204.201.85:35213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/info.php"] [unique_id "al9HtyBMYeh5YLVG45xb6wAAAi4"]
[Tue Jul 21 07:19:35.440413 2026] [security2:error] [pid 229246:tid 229399] [client 4.204.201.85:43985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HtyBMYeh5YLVG45xb7AAAAis"]
[Tue Jul 21 07:19:35.457618 2026] [security2:error] [pid 229246:tid 229332] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HtyBMYeh5YLVG45xb7QACNlU"]
[Tue Jul 21 07:19:35.457802 2026] [security2:error] [pid 229246:tid 229410] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HtyBMYeh5YLVG45xb7QACNlU"]
[Tue Jul 21 07:19:35.648371 2026] [security2:error] [pid 229246:tid 229441] [client 20.151.10.161:46003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ha.php"] [unique_id "al9HtyBMYeh5YLVG45xb7wAAAlU"]
[Tue Jul 21 07:19:35.674418 2026] [security2:error] [pid 229246:tid 229457] [client 20.151.10.161:12042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/h02ugyh.php"] [unique_id "al9HtyBMYeh5YLVG45xb8AAAAmU"]
[Tue Jul 21 07:19:35.762211 2026] [security2:error] [pid 230252:tid 230389] [client 4.204.201.85:35301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/11.php"] [unique_id "al9Ht00Dwhk5-Z44Xro2TgAAAp4"]
[Tue Jul 21 07:19:35.833869 2026] [security2:error] [pid 230252:tid 230387] [client 4.204.201.85:3313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/dvjul.php"] [unique_id "al9Ht00Dwhk5-Z44Xro2TwAAApw"]
[Tue Jul 21 07:19:36.139615 2026] [security2:error] [pid 229246:tid 229388] [client 4.204.201.85:43971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/media.php"] [unique_id "al9HuCBMYeh5YLVG45xb_AAAAiA"]
[Tue Jul 21 07:19:36.149206 2026] [security2:error] [pid 230252:tid 230406] [client 4.204.201.85:3210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/biufile.php"] [unique_id "al9HuE0Dwhk5-Z44Xro2VwAAAq8"]
[Tue Jul 21 07:19:36.193317 2026] [security2:error] [pid 229246:tid 229462] [client 4.204.201.85:35437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/v2.php"] [unique_id "al9HuCBMYeh5YLVG45xb_QAAAmo"]
[Tue Jul 21 07:19:36.394458 2026] [security2:error] [pid 229246:tid 229406] [client 35.221.17.130:54436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gruposafiramt.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9HuCBMYeh5YLVG45xcAgAAAjI"]
[Tue Jul 21 07:19:36.550486 2026] [security2:error] [pid 229246:tid 229396] [client 74.249.245.134:60802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/class-t.api.php"] [unique_id "al9HuCBMYeh5YLVG45xcBgAAAig"]
[Tue Jul 21 07:19:36.642256 2026] [security2:error] [pid 230252:tid 230419] [client 4.204.201.85:35333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/panel.php"] [unique_id "al9HuE0Dwhk5-Z44Xro2XAAAArw"]
[Tue Jul 21 07:19:36.645502 2026] [security2:error] [pid 229246:tid 229440] [client 4.204.201.85:43997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/images.php"] [unique_id "al9HuCBMYeh5YLVG45xcCAAAAlQ"]
[Tue Jul 21 07:19:36.656889 2026] [security2:error] [pid 230252:tid 230421] [client 35.221.17.130:61545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.17.221.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HuE0Dwhk5-Z44Xro2XQAAAr4"]
[Tue Jul 21 07:19:36.679288 2026] [security2:error] [pid 229246:tid 229404] [client 4.204.201.85:3316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/av.php"] [unique_id "al9HuCBMYeh5YLVG45xcCQAAAjA"]
[Tue Jul 21 07:19:36.742976 2026] [security2:error] [pid 230252:tid 230409] [client 136.144.33.103:48213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9HuE0Dwhk5-Z44Xro2WwAAArI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:37.019068 2026] [security2:error] [pid 230252:tid 230388] [client 103.121.156.110:59902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2YwAAAp0"]
[Tue Jul 21 07:19:37.019213 2026] [security2:error] [pid 230252:tid 230388] [client 103.121.156.110:59902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2YwAAAp0"]
[Tue Jul 21 07:19:37.085037 2026] [security2:error] [pid 230252:tid 230426] [client 4.204.201.85:3212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/coffexium.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2ZAAAAsM"]
[Tue Jul 21 07:19:37.087863 2026] [security2:error] [pid 230252:tid 230407] [client 4.204.201.85:35283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/dex.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2ZQAAArA"]
[Tue Jul 21 07:19:37.101807 2026] [security2:error] [pid 230252:tid 230395] [client 103.162.129.114:57449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2ZgAAAqQ"]
[Tue Jul 21 07:19:37.101937 2026] [security2:error] [pid 230252:tid 230395] [client 103.162.129.114:57449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2ZgAAAqQ"]
[Tue Jul 21 07:19:37.275626 2026] [security2:error] [pid 230252:tid 230461] [client 20.151.10.161:53593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/seiso.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2bQAAAuY"]
[Tue Jul 21 07:19:37.305416 2026] [security2:error] [pid 230252:tid 230462] [client 4.204.201.85:43915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/gecko.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2bwAAAuc"]
[Tue Jul 21 07:19:37.550007 2026] [security2:error] [pid 230252:tid 230310] [remote 5.252.52.249:55428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2eAACzTg"]
[Tue Jul 21 07:19:37.567575 2026] [security2:error] [pid 230252:tid 230311] [remote 45.79.123.44:38418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/wp-login.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2eQACwDk"]
[Tue Jul 21 07:19:37.597265 2026] [security2:error] [pid 229246:tid 229408] [client 4.204.201.85:3213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/core.php"] [unique_id "al9HuSBMYeh5YLVG45xcSQAAAjQ"]
[Tue Jul 21 07:19:37.746325 2026] [security2:error] [pid 229246:tid 229483] [client 4.204.201.85:35304] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "seaportservicos.com.br"] [uri "/1.php"] [unique_id "al9HuSBMYeh5YLVG45xcUAAAAn8"]
[Tue Jul 21 07:19:37.746430 2026] [security2:error] [pid 229246:tid 229483] [client 4.204.201.85:35304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/1.php"] [unique_id "al9HuSBMYeh5YLVG45xcUAAAAn8"]
[Tue Jul 21 07:19:37.796042 2026] [autoindex:error] [pid 229246:tid 229489] [client 101.33.80.42:46630] AH01276: Cannot serve directory /home2/sarare11/milhasexpresso.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:37.803221 2026] [security2:error] [pid 230252:tid 230490] [client 20.220.225.223:52763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/billur.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2ewAAAwM"]
[Tue Jul 21 07:19:37.843403 2026] [security2:error] [pid 229246:tid 229486] [client 35.221.17.130:60572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.17.221.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HuSBMYeh5YLVG45xcUwAAAoI"]
[Tue Jul 21 07:19:37.843501 2026] [security2:error] [pid 229246:tid 229486] [client 35.221.17.130:60572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gruposafiramt.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HuSBMYeh5YLVG45xcUwAAAoI"]
[Tue Jul 21 07:19:37.940425 2026] [core:error] [pid 230252:tid 230445] [client 66.249.66.67:63967] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:19:37.940443 2026] [core:error] [pid 230252:tid 230445] [client 66.249.66.67:63967] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:19:37.968180 2026] [security2:error] [pid 229246:tid 229390] [client 20.197.192.193:27162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/kua.php"] [unique_id "al9HuSBMYeh5YLVG45xcWQAAAiI"]
[Tue Jul 21 07:19:37.992839 2026] [security2:error] [pid 230252:tid 230500] [client 4.204.201.85:3315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/als.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2fQAAAw0"]
[Tue Jul 21 07:19:38.117099 2026] [security2:error] [pid 230252:tid 230391] [client 4.204.201.85:43973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/82.php"] [unique_id "al9Huk0Dwhk5-Z44Xro2gAAAAqA"]
[Tue Jul 21 07:19:38.165719 2026] [security2:error] [pid 229246:tid 229446] [client 4.204.201.85:35252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/ms.php"] [unique_id "al9HuiBMYeh5YLVG45xcbAAAAlo"]
[Tue Jul 21 07:19:38.314458 2026] [security2:error] [pid 230252:tid 230412] [client 74.249.245.134:61158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/plugins.php"] [unique_id "al9Huk0Dwhk5-Z44Xro2iQAAArU"]
[Tue Jul 21 07:19:38.325901 2026] [security2:error] [pid 230252:tid 230384] [client 4.204.201.85:3268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/simple.php"] [unique_id "al9Huk0Dwhk5-Z44Xro2igAAApk"]
[Tue Jul 21 07:19:38.599800 2026] [security2:error] [pid 230252:tid 230443] [client 4.204.201.85:44027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/admin.php"] [unique_id "al9Huk0Dwhk5-Z44Xro2kgAAAtQ"]
[Tue Jul 21 07:19:38.603735 2026] [security2:error] [pid 230252:tid 230405] [client 14.139.42.196:13751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Huk0Dwhk5-Z44Xro2kwAAAq4"]
[Tue Jul 21 07:19:38.603857 2026] [security2:error] [pid 230252:tid 230405] [client 14.139.42.196:13751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Huk0Dwhk5-Z44Xro2kwAAAq4"]
[Tue Jul 21 07:19:38.751620 2026] [security2:error] [pid 230252:tid 230459] [client 4.204.201.85:3301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/init.php"] [unique_id "al9Huk0Dwhk5-Z44Xro2mQAAAuQ"]
[Tue Jul 21 07:19:38.870308 2026] [security2:error] [pid 230252:tid 230476] [client 20.151.10.161:45960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/hur.php"] [unique_id "al9Huk0Dwhk5-Z44Xro2mwAAAvU"]
[Tue Jul 21 07:19:39.071191 2026] [security2:error] [pid 230252:tid 230482] [client 4.204.201.85:44021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/adminner.php"] [unique_id "al9Hu00Dwhk5-Z44Xro2oAAAAvs"]
[Tue Jul 21 07:19:39.109770 2026] [security2:error] [pid 229246:tid 229499] [client 20.151.10.161:55260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/155.php"] [unique_id "al9HuyBMYeh5YLVG45xcjAAAAo8"]
[Tue Jul 21 07:19:39.161542 2026] [security2:error] [pid 230252:tid 230445] [client 68.235.38.2:37160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Hu00Dwhk5-Z44Xro2owAAAtY"]
[Tue Jul 21 07:19:39.161641 2026] [security2:error] [pid 230252:tid 230445] [client 68.235.38.2:37160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Hu00Dwhk5-Z44Xro2owAAAtY"]
[Tue Jul 21 07:19:39.168935 2026] [security2:error] [pid 230252:tid 230494] [client 4.204.201.85:3218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/fpwch.php"] [unique_id "al9Hu00Dwhk5-Z44Xro2pAAAAwc"]
[Tue Jul 21 07:19:39.276507 2026] [autoindex:error] [pid 230252:tid 230436] [client 4.204.201.85:35426] AH01276: Cannot serve directory /home3/seaport/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:39.333909 2026] [security2:error] [pid 230252:tid 230329] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Hu00Dwhk5-Z44Xro2qAADD0o"]
[Tue Jul 21 07:19:39.334048 2026] [security2:error] [pid 230252:tid 230502] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Hu00Dwhk5-Z44Xro2qAADD0o"]
[Tue Jul 21 07:19:39.571149 2026] [security2:error] [pid 230252:tid 230492] [client 4.204.201.85:3211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/domvf.php"] [unique_id "al9Hu00Dwhk5-Z44Xro2qQAAAwU"]
[Tue Jul 21 07:19:39.705738 2026] [core:error] [pid 230252:tid 230401] [client 66.249.66.67:37483] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:19:39.705760 2026] [core:error] [pid 230252:tid 230401] [client 66.249.66.67:37483] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:19:39.746710 2026] [security2:error] [pid 230252:tid 230507] [client 4.204.201.85:35422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/memberfuns.php"] [unique_id "al9Hu00Dwhk5-Z44Xro2rAAAAxQ"]
[Tue Jul 21 07:19:39.898357 2026] [security2:error] [pid 230252:tid 230412] [client 4.204.201.85:43917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/admin.php"] [unique_id "al9Hu00Dwhk5-Z44Xro2rQAAArU"]
[Tue Jul 21 07:19:39.985396 2026] [security2:error] [pid 230252:tid 230392] [client 4.204.201.85:3231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/wp.php"] [unique_id "al9Hu00Dwhk5-Z44Xro2rgAAAqE"]
[Tue Jul 21 07:19:40.085305 2026] [security2:error] [pid 230252:tid 230400] [client 20.151.10.161:53611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ppp.php"] [unique_id "al9HvE0Dwhk5-Z44Xro2tAAAAqk"]
[Tue Jul 21 07:19:40.306750 2026] [security2:error] [pid 230252:tid 230418] [client 74.249.245.134:21907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/jp.php"] [unique_id "al9HvE0Dwhk5-Z44Xro2ugAAArs"]
[Tue Jul 21 07:19:40.337867 2026] [security2:error] [pid 229246:tid 229385] [client 4.204.201.85:43984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/k.php"] [unique_id "al9HvCBMYeh5YLVG45xcmAAAAh0"]
[Tue Jul 21 07:19:40.407708 2026] [security2:error] [pid 230252:tid 230459] [client 4.204.201.85:3214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/class.php"] [unique_id "al9HvE0Dwhk5-Z44Xro2vgAAAuQ"]
[Tue Jul 21 07:19:40.441438 2026] [security2:error] [pid 230252:tid 230433] [client 4.204.201.85:35287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/0.php"] [unique_id "al9HvE0Dwhk5-Z44Xro2vwAAAso"]
[Tue Jul 21 07:19:40.638755 2026] [security2:error] [pid 230252:tid 230388] [client 20.220.225.223:36815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/mimpi.php"] [unique_id "al9HvE0Dwhk5-Z44Xro2wgAAAp0"]
[Tue Jul 21 07:19:40.651914 2026] [security2:error] [pid 229246:tid 229501] [client 4.204.201.85:43977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/blurbs.php"] [unique_id "al9HvCBMYeh5YLVG45xcnQAAApE"]
[Tue Jul 21 07:19:40.760641 2026] [security2:error] [pid 230252:tid 230499] [client 136.144.33.241:25037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9HvE0Dwhk5-Z44Xro2xQAAAww"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:40.787830 2026] [security2:error] [pid 229246:tid 229478] [client 20.151.10.161:55260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/201.php"] [unique_id "al9HvCBMYeh5YLVG45xcogAAAno"]
[Tue Jul 21 07:19:40.801056 2026] [security2:error] [pid 230252:tid 230422] [client 20.226.60.151:54568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/sump1.php"] [unique_id "al9HvE0Dwhk5-Z44Xro2yAAAAr8"]
[Tue Jul 21 07:19:40.920306 2026] [security2:error] [pid 229246:tid 229483] [client 4.204.201.85:3202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/echkm.php"] [unique_id "al9HvCBMYeh5YLVG45xcpwAAAn8"]
[Tue Jul 21 07:19:40.946393 2026] [security2:error] [pid 230252:tid 230497] [client 4.204.201.85:35222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/BDKR28.php"] [unique_id "al9HvE0Dwhk5-Z44Xro2yQAAAwo"]
[Tue Jul 21 07:19:41.004591 2026] [security2:error] [pid 230252:tid 230337] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HvU0Dwhk5-Z44Xro2ywADAlI"]
[Tue Jul 21 07:19:41.004820 2026] [security2:error] [pid 230252:tid 230489] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HvU0Dwhk5-Z44Xro2ywADAlI"]
[Tue Jul 21 07:19:41.114778 2026] [security2:error] [pid 230252:tid 230426] [client 45.251.232.145:60107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HvU0Dwhk5-Z44Xro2zAAAAsM"]
[Tue Jul 21 07:19:41.114947 2026] [security2:error] [pid 230252:tid 230426] [client 45.251.232.145:60107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HvU0Dwhk5-Z44Xro2zAAAAsM"]
[Tue Jul 21 07:19:41.149130 2026] [security2:error] [pid 229246:tid 229430] [client 4.204.201.85:43983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/bajah.php"] [unique_id "al9HvSBMYeh5YLVG45xcqQAAAko"]
[Tue Jul 21 07:19:41.374567 2026] [security2:error] [pid 230252:tid 230491] [client 4.204.201.85:26578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/lib.php"] [unique_id "al9HvU0Dwhk5-Z44Xro21wAAAwQ"]
[Tue Jul 21 07:19:41.466285 2026] [security2:error] [pid 230252:tid 230404] [client 20.197.192.193:27142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/ez.php"] [unique_id "al9HvU0Dwhk5-Z44Xro22AAAAq0"]
[Tue Jul 21 07:19:41.566204 2026] [security2:error] [pid 230252:tid 230469] [client 4.204.201.85:43978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/a.php"] [unique_id "al9HvU0Dwhk5-Z44Xro22QAAAu4"]
[Tue Jul 21 07:19:41.629476 2026] [security2:error] [pid 229246:tid 229440] [client 20.151.10.161:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ops.php"] [unique_id "al9HvSBMYeh5YLVG45xcswAAAlQ"]
[Tue Jul 21 07:19:41.639510 2026] [security2:error] [pid 229246:tid 229457] [client 92.119.178.3:37244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9HvSBMYeh5YLVG45xctAAAAmU"]
[Tue Jul 21 07:19:41.639629 2026] [security2:error] [pid 229246:tid 229457] [client 92.119.178.3:37244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9HvSBMYeh5YLVG45xctAAAAmU"]
[Tue Jul 21 07:19:41.904387 2026] [security2:error] [pid 229246:tid 229402] [client 4.204.201.85:35227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/green1.php"] [unique_id "al9HvSBMYeh5YLVG45xcuwAAAi4"]
[Tue Jul 21 07:19:41.923404 2026] [security2:error] [pid 230252:tid 230416] [client 4.204.201.85:43851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/edit.php"] [unique_id "al9HvU0Dwhk5-Z44Xro23AAAArk"]
[Tue Jul 21 07:19:41.935862 2026] [security2:error] [pid 230252:tid 230341] [remote 37.139.53.11:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "37.139.53.11" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "cromobelo.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9HvU0Dwhk5-Z44Xro23QACyVY"], referer: https://cromobelo.com.br/2020/08/06/metalizacao-em-cromo/?unapproved=6547&moderation-hash=39b53877f6b6894645ed3235b1178b4c
[Tue Jul 21 07:19:41.936047 2026] [security2:error] [pid 230252:tid 230432] [client 37.139.53.11:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "cromobelo.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9HvU0Dwhk5-Z44Xro23QACyVY"], referer: https://cromobelo.com.br/2020/08/06/metalizacao-em-cromo/?unapproved=6547&moderation-hash=39b53877f6b6894645ed3235b1178b4c
[Tue Jul 21 07:19:41.939422 2026] [security2:error] [pid 230252:tid 230415] [client 4.204.201.85:3269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/login.php"] [unique_id "al9HvU0Dwhk5-Z44Xro23gAAArg"]
[Tue Jul 21 07:19:42.002297 2026] [security2:error] [pid 230252:tid 230412] [client 20.197.192.193:6876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Hvk0Dwhk5-Z44Xro23wAAArU"]
[Tue Jul 21 07:19:42.121099 2026] [security2:error] [pid 230252:tid 230406] [client 20.151.10.161:45979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/h02ugyh.php"] [unique_id "al9Hvk0Dwhk5-Z44Xro24AAAAq8"]
[Tue Jul 21 07:19:42.258282 2026] [security2:error] [pid 229246:tid 229468] [client 139.135.44.145:54418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HviBMYeh5YLVG45xcwAAAAnA"]
[Tue Jul 21 07:19:42.258953 2026] [security2:error] [pid 229246:tid 229468] [client 139.135.44.145:54418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HviBMYeh5YLVG45xcwAAAAnA"]
[Tue Jul 21 07:19:42.307578 2026] [security2:error] [pid 230252:tid 230418] [client 4.204.201.85:43909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/hosty.php"] [unique_id "al9Hvk0Dwhk5-Z44Xro25wAAArs"]
[Tue Jul 21 07:19:42.434932 2026] [security2:error] [pid 230252:tid 230342] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Hvk0Dwhk5-Z44Xro26AACy1c"]
[Tue Jul 21 07:19:42.435128 2026] [security2:error] [pid 230252:tid 230434] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Hvk0Dwhk5-Z44Xro26AACy1c"]
[Tue Jul 21 07:19:42.526760 2026] [security2:error] [pid 230252:tid 230443] [client 4.204.201.85:3296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/a2.php"] [unique_id "al9Hvk0Dwhk5-Z44Xro27AAAAtQ"]
[Tue Jul 21 07:19:42.715500 2026] [security2:error] [pid 230252:tid 230423] [client 4.204.201.85:43905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/k.php"] [unique_id "al9Hvk0Dwhk5-Z44Xro28gAAAsA"]
[Tue Jul 21 07:19:42.848806 2026] [security2:error] [pid 230252:tid 230480] [client 20.220.225.223:43045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/dp.php"] [unique_id "al9Hvk0Dwhk5-Z44Xro29QAAAvk"]
[Tue Jul 21 07:19:43.069897 2026] [security2:error] [pid 230252:tid 230489] [client 4.204.201.85:35356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/nc4.php"] [unique_id "al9Hv00Dwhk5-Z44Xro29gAAAwI"]
[Tue Jul 21 07:19:43.081596 2026] [security2:error] [pid 229246:tid 229392] [client 4.204.201.85:3283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/d61.php"] [unique_id "al9HvyBMYeh5YLVG45xcygAAAiQ"]
[Tue Jul 21 07:19:43.185396 2026] [security2:error] [pid 230252:tid 230426] [client 20.151.10.161:55285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ingfo.php"] [unique_id "al9Hv00Dwhk5-Z44Xro2-QAAAsM"]
[Tue Jul 21 07:19:43.251731 2026] [security2:error] [pid 230252:tid 230462] [client 74.244.195.153:21999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.195.244.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Hv00Dwhk5-Z44Xro2-gAAAuc"]
[Tue Jul 21 07:19:43.259480 2026] [security2:error] [pid 230252:tid 230462] [client 74.244.195.153:21999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Hv00Dwhk5-Z44Xro2-gAAAuc"]
[Tue Jul 21 07:19:43.261792 2026] [security2:error] [pid 229246:tid 229499] [client 4.204.201.85:43914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/aaa.php"] [unique_id "al9HvyBMYeh5YLVG45xc0AAAAo8"]
[Tue Jul 21 07:19:43.724752 2026] [security2:error] [pid 230252:tid 230507] [client 4.204.201.85:44031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/file5.php"] [unique_id "al9Hv00Dwhk5-Z44Xro2_gAAAxQ"]
[Tue Jul 21 07:19:43.903877 2026] [security2:error] [pid 229246:tid 229463] [client 175.45.70.82:64292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HvyBMYeh5YLVG45xc1wAAAms"]
[Tue Jul 21 07:19:43.903993 2026] [security2:error] [pid 229246:tid 229463] [client 175.45.70.82:64292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HvyBMYeh5YLVG45xc1wAAAms"]
[Tue Jul 21 07:19:43.931647 2026] [security2:error] [pid 229246:tid 229448] [client 4.204.201.85:3228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/info.php"] [unique_id "al9HvyBMYeh5YLVG45xc2AAAAlw"]
[Tue Jul 21 07:19:43.951562 2026] [security2:error] [pid 230252:tid 230406] [client 4.204.201.85:35391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/a1.php"] [unique_id "al9Hv00Dwhk5-Z44Xro3BgAAAq8"]
[Tue Jul 21 07:19:43.953879 2026] [security2:error] [pid 229246:tid 229470] [client 74.249.245.134:61471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/error.php"] [unique_id "al9HvyBMYeh5YLVG45xc2QAAAnI"]
[Tue Jul 21 07:19:44.166158 2026] [security2:error] [pid 230252:tid 230418] [client 20.197.192.193:6344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3GgAAArs"]
[Tue Jul 21 07:19:44.277232 2026] [security2:error] [pid 230252:tid 230376] [remote 152.53.111.131:40644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3IAAC83k"]
[Tue Jul 21 07:19:44.288498 2026] [security2:error] [pid 230252:tid 230377] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3IQAC2no"]
[Tue Jul 21 07:19:44.288660 2026] [security2:error] [pid 230252:tid 230449] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3IQAC2no"]
[Tue Jul 21 07:19:44.339132 2026] [security2:error] [pid 230252:tid 230476] [client 4.204.201.85:44030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/222.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3VAAAAvU"]
[Tue Jul 21 07:19:44.346375 2026] [security2:error] [pid 230252:tid 230499] [client 20.151.10.161:45966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/seiso.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3VQAAAww"]
[Tue Jul 21 07:19:44.370762 2026] [security2:error] [pid 230252:tid 230318] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3VwAC20A"]
[Tue Jul 21 07:19:44.370863 2026] [security2:error] [pid 230252:tid 230450] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3VwAC20A"]
[Tue Jul 21 07:19:44.550158 2026] [security2:error] [pid 230252:tid 230323] [remote 156.59.198.135:59870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "politicaemdebate.org"] [uri "/wp-content/uploads/2023/03/Joias-ilegaiss-de-michelle.png"] [unique_id "al9HwE0Dwhk5-Z44Xro3XQAC50U"], referer: https://politicaemdebate.org/2023/03/04/joias-trazidas-ilegalmente-para-michelle-bolsonaro/
[Tue Jul 21 07:19:44.691961 2026] [security2:error] [pid 230252:tid 230391] [client 4.204.201.85:3299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/11.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3ZAAAAqA"]
[Tue Jul 21 07:19:44.784555 2026] [security2:error] [pid 230252:tid 230397] [client 120.61.173.56:52612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3bAAAAqY"]
[Tue Jul 21 07:19:44.784684 2026] [security2:error] [pid 230252:tid 230397] [client 120.61.173.56:52612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3bAAAAqY"]
[Tue Jul 21 07:19:44.893389 2026] [security2:error] [pid 230252:tid 230401] [client 4.204.201.85:44003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/test.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3bwAAAqo"]
[Tue Jul 21 07:19:44.894237 2026] [security2:error] [pid 230252:tid 230507] [client 134.19.179.187:34148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3cAAAAxQ"]
[Tue Jul 21 07:19:44.894378 2026] [security2:error] [pid 230252:tid 230507] [client 134.19.179.187:34148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3cAAAAxQ"]
[Tue Jul 21 07:19:44.923731 2026] [security2:error] [pid 229246:tid 229293] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HwCBMYeh5YLVG45xc5AAChS4"]
[Tue Jul 21 07:19:44.923875 2026] [security2:error] [pid 229246:tid 229489] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HwCBMYeh5YLVG45xc5AAChS4"]
[Tue Jul 21 07:19:45.046307 2026] [security2:error] [pid 230252:tid 230458] [client 20.197.192.193:6857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/dp.php"] [unique_id "al9HwU0Dwhk5-Z44Xro3cQAAAuM"]
[Tue Jul 21 07:19:45.304043 2026] [security2:error] [pid 230252:tid 230460] [client 20.220.225.223:59468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/bootstrap.php"] [unique_id "al9HwU0Dwhk5-Z44Xro3cgAAAuU"]
[Tue Jul 21 07:19:45.323171 2026] [security2:error] [pid 230252:tid 230406] [client 20.197.192.193:27073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/fz.php"] [unique_id "al9HwU0Dwhk5-Z44Xro3cwAAAq8"]
[Tue Jul 21 07:19:45.363420 2026] [security2:error] [pid 229246:tid 229453] [client 4.204.201.85:44001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/aaa.php"] [unique_id "al9HwSBMYeh5YLVG45xc6gAAAmE"]
[Tue Jul 21 07:19:45.483175 2026] [security2:error] [pid 229246:tid 229280] [remote 52.128.31.170:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "cromobelo.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9HvyBMYeh5YLVG45xczAACKyE"], referer: https://cromobelo.com.br/2020/08/06/metalizacao-em-cromo/?unapproved=6547&moderation-hash=39b53877f6b6894645ed3235b1178b4c
[Tue Jul 21 07:19:45.567255 2026] [security2:error] [pid 230252:tid 230453] [client 20.151.10.161:53579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/error_log.php"] [unique_id "al9HwU0Dwhk5-Z44Xro3fQAAAt4"]
[Tue Jul 21 07:19:45.681172 2026] [security2:error] [pid 230252:tid 230495] [client 136.144.33.109:57791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9HwU0Dwhk5-Z44Xro3fgAAAwg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:45.860406 2026] [security2:error] [pid 230252:tid 230449] [client 4.204.201.85:3324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/v2.php"] [unique_id "al9HwU0Dwhk5-Z44Xro3gQAAAto"]
[Tue Jul 21 07:19:45.872728 2026] [security2:error] [pid 230252:tid 230499] [client 4.204.201.85:43990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/11.php"] [unique_id "al9HwU0Dwhk5-Z44Xro3ggAAAww"]
[Tue Jul 21 07:19:45.940032 2026] [security2:error] [pid 229246:tid 229486] [client 4.204.201.85:35266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/eee.php"] [unique_id "al9HwSBMYeh5YLVG45xc7wAAAoI"]
[Tue Jul 21 07:19:45.959298 2026] [security2:error] [pid 229246:tid 229494] [client 20.151.10.161:45940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/155.php"] [unique_id "al9HwSBMYeh5YLVG45xc8AAAAoo"]
[Tue Jul 21 07:19:46.000605 2026] [core:alert] [pid 229246:tid 229502] [client 57.141.18.67:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:19:46.087706 2026] [security2:error] [pid 230252:tid 230343] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Hwk0Dwhk5-Z44Xro3hgACv1g"]
[Tue Jul 21 07:19:46.087931 2026] [security2:error] [pid 230252:tid 230422] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Hwk0Dwhk5-Z44Xro3hgACv1g"]
[Tue Jul 21 07:19:46.234636 2026] [security2:error] [pid 229246:tid 229399] [client 52.128.31.170:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "cromobelo.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9HvyBMYeh5YLVG45xczAACKyE"], referer: https://cromobelo.com.br/2020/08/06/metalizacao-em-cromo/?unapproved=6547&moderation-hash=39b53877f6b6894645ed3235b1178b4c
[Tue Jul 21 07:19:46.741527 2026] [security2:error] [pid 230252:tid 230472] [client 74.249.245.134:50998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/classwithtostring.php"] [unique_id "al9Hwk0Dwhk5-Z44Xro3jwAAAvE"]
[Tue Jul 21 07:19:46.823575 2026] [security2:error] [pid 229246:tid 229435] [client 4.204.201.85:35323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wp-aothait.php"] [unique_id "al9HwiBMYeh5YLVG45xc_AAAAk8"]
[Tue Jul 21 07:19:46.889730 2026] [security2:error] [pid 230252:tid 230361] [remote 154.61.75.100:56562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Hwk0Dwhk5-Z44Xro3kAADA2o"]
[Tue Jul 21 07:19:46.952231 2026] [security2:error] [pid 230252:tid 230507] [client 20.151.10.161:46006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ppp.php"] [unique_id "al9Hwk0Dwhk5-Z44Xro3lAAAAxQ"]
[Tue Jul 21 07:19:47.010473 2026] [security2:error] [pid 230252:tid 230477] [client 4.204.201.85:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/mac.php"] [unique_id "al9Hw00Dwhk5-Z44Xro3lQAAAvY"]
[Tue Jul 21 07:19:47.067173 2026] [security2:error] [pid 230252:tid 230357] [remote 103.112.62.59:50094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.62.112.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/wp-login.php"] [unique_id "al9Hw00Dwhk5-Z44Xro3lgADBWY"]
[Tue Jul 21 07:19:47.254333 2026] [security2:error] [pid 230252:tid 230358] [remote 182.77.62.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.hauptmann.com.br"] [uri "/wp-login.php"] [unique_id "al9Hw00Dwhk5-Z44Xro3mgACqmc"]
[Tue Jul 21 07:19:47.273108 2026] [security2:error] [pid 230252:tid 230423] [client 4.204.201.85:35276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/config.json.php"] [unique_id "al9Hw00Dwhk5-Z44Xro3nAAAAsA"]
[Tue Jul 21 07:19:47.329711 2026] [security2:error] [pid 230252:tid 230483] [client 20.226.60.151:54494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/file5.php"] [unique_id "al9Hw00Dwhk5-Z44Xro3nQAAAvw"]
[Tue Jul 21 07:19:47.400476 2026] [access_compat:error] [pid 229246:tid 229388] [client 162.241.63.68:32882] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:19:47.704929 2026] [security2:error] [pid 229246:tid 229377] [client 103.121.156.110:60267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HwyBMYeh5YLVG45xdAwAAAhU"]
[Tue Jul 21 07:19:47.705066 2026] [security2:error] [pid 229246:tid 229377] [client 103.121.156.110:60267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HwyBMYeh5YLVG45xdAwAAAhU"]
[Tue Jul 21 07:19:47.781779 2026] [security2:error] [pid 230252:tid 230481] [client 20.151.10.161:45902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/201.php"] [unique_id "al9Hw00Dwhk5-Z44Xro3qwAAAvo"]
[Tue Jul 21 07:19:47.805058 2026] [security2:error] [pid 230252:tid 230417] [client 103.162.129.114:57950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Hw00Dwhk5-Z44Xro3rAAAAro"]
[Tue Jul 21 07:19:47.805184 2026] [security2:error] [pid 230252:tid 230417] [client 103.162.129.114:57950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Hw00Dwhk5-Z44Xro3rAAAAro"]
[Tue Jul 21 07:19:47.892986 2026] [security2:error] [pid 229246:tid 229397] [client 20.197.192.193:6344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/old.php"] [unique_id "al9HwyBMYeh5YLVG45xdBAAAAik"]
[Tue Jul 21 07:19:47.917422 2026] [security2:error] [pid 230252:tid 230487] [client 4.204.201.85:3233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/panel.php"] [unique_id "al9Hw00Dwhk5-Z44Xro3rQAAAwA"]
[Tue Jul 21 07:19:48.015912 2026] [security2:error] [pid 229246:tid 229441] [client 4.204.201.85:44028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/chosen.php"] [unique_id "al9HxCBMYeh5YLVG45xdCQAAAlU"]
[Tue Jul 21 07:19:48.195742 2026] [security2:error] [pid 230252:tid 230424] [client 4.204.201.85:35307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9HxE0Dwhk5-Z44Xro3tgAAAsE"]
[Tue Jul 21 07:19:48.439078 2026] [security2:error] [pid 230252:tid 230442] [client 20.151.10.161:46069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ops.php"] [unique_id "al9HxE0Dwhk5-Z44Xro3uwAAAtM"]
[Tue Jul 21 07:19:48.790332 2026] [security2:error] [pid 229246:tid 229486] [client 20.10.88.227:9799] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gnxinox.com.br"] [uri "/index.php"] [unique_id "al9HxCBMYeh5YLVG45xdEAAAAoI"]
[Tue Jul 21 07:19:48.906034 2026] [security2:error] [pid 230252:tid 230467] [client 20.151.10.161:46024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ingfo.php"] [unique_id "al9HxE0Dwhk5-Z44Xro3vAAAAuw"]
[Tue Jul 21 07:19:48.920118 2026] [security2:error] [pid 229246:tid 229402] [client 4.204.201.85:44007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/cream1.php"] [unique_id "al9HxCBMYeh5YLVG45xdEwAAAi4"]
[Tue Jul 21 07:19:49.149340 2026] [security2:error] [pid 229246:tid 229497] [client 14.139.42.196:20251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HxSBMYeh5YLVG45xdHAAAAo0"]
[Tue Jul 21 07:19:49.149438 2026] [security2:error] [pid 229246:tid 229497] [client 14.139.42.196:20251] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HxSBMYeh5YLVG45xdHAAAAo0"]
[Tue Jul 21 07:19:49.279162 2026] [security2:error] [pid 229246:tid 229496] [client 20.151.10.161:12036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xenon1337.php"] [unique_id "al9HxSBMYeh5YLVG45xdHQAAAow"]
[Tue Jul 21 07:19:49.510475 2026] [security2:error] [pid 229246:tid 229388] [client 4.204.201.85:3271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/dex.php"] [unique_id "al9HxSBMYeh5YLVG45xdHwAAAiA"]
[Tue Jul 21 07:19:49.722873 2026] [security2:error] [pid 229246:tid 229478] [client 20.151.10.161:45998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/error_log.php"] [unique_id "al9HxSBMYeh5YLVG45xdJgAAAno"]
[Tue Jul 21 07:19:49.759084 2026] [security2:error] [pid 230252:tid 230351] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HxU0Dwhk5-Z44Xro3yAAC52A"]
[Tue Jul 21 07:19:49.759220 2026] [security2:error] [pid 230252:tid 230462] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HxU0Dwhk5-Z44Xro3yAAC52A"]
[Tue Jul 21 07:19:49.807402 2026] [security2:error] [pid 229246:tid 229457] [client 172.245.102.44:56031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9HxSBMYeh5YLVG45xdIwAAAmU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:49.853207 2026] [security2:error] [pid 229246:tid 229314] [remote 132.148.72.88:42372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nocaminhodafe.com.br"] [uri "/wp-login.php"] [unique_id "al9HxSBMYeh5YLVG45xdJwACQ0M"]
[Tue Jul 21 07:19:49.880127 2026] [security2:error] [pid 230252:tid 230482] [client 157.90.156.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9HxU0Dwhk5-Z44Xro3ygAC-3Q"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:19:50.101370 2026] [security2:error] [pid 230252:tid 230416] [client 4.204.201.85:3291] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "conectarpessoas.com.br"] [uri "/1.php"] [unique_id "al9Hxk0Dwhk5-Z44Xro30QAAArk"]
[Tue Jul 21 07:19:50.101483 2026] [security2:error] [pid 230252:tid 230416] [client 4.204.201.85:3291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/1.php"] [unique_id "al9Hxk0Dwhk5-Z44Xro30QAAArk"]
[Tue Jul 21 07:19:50.107472 2026] [security2:error] [pid 230252:tid 230495] [client 157.90.156.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9Hxk0Dwhk5-Z44Xro30gADCHY"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:19:50.155475 2026] [security2:error] [pid 230252:tid 230464] [client 20.151.10.161:45963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xenon1337.php"] [unique_id "al9Hxk0Dwhk5-Z44Xro31QAAAuk"]
[Tue Jul 21 07:19:50.352918 2026] [security2:error] [pid 229246:tid 229393] [client 4.204.201.85:35271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/k2.php"] [unique_id "al9HxiBMYeh5YLVG45xdLwAAAiU"]
[Tue Jul 21 07:19:50.622632 2026] [security2:error] [pid 229246:tid 229463] [client 20.151.10.161:45951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/test11.php"] [unique_id "al9HxiBMYeh5YLVG45xdNAAAAms"]
[Tue Jul 21 07:19:50.635852 2026] [autoindex:error] [pid 229246:tid 229448] [client 205.210.31.180:59630] AH01276: Cannot serve directory /home1/denerd44/dpatrick.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:50.786906 2026] [security2:error] [pid 229246:tid 229468] [client 4.204.201.85:3209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/ms.php"] [unique_id "al9HxiBMYeh5YLVG45xdNwAAAnA"]
[Tue Jul 21 07:19:50.889133 2026] [security2:error] [pid 230252:tid 230405] [client 4.204.201.85:35310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9Hxk0Dwhk5-Z44Xro34QAAAq4"]
[Tue Jul 21 07:19:50.983388 2026] [security2:error] [pid 230252:tid 230433] [client 74.249.245.134:50952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/bless.php"] [unique_id "al9Hxk0Dwhk5-Z44Xro35AAAAso"]
[Tue Jul 21 07:19:51.068626 2026] [security2:error] [pid 229246:tid 229431] [client 20.151.10.161:46061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/koala.php"] [unique_id "al9HxyBMYeh5YLVG45xdOgAAAks"]
[Tue Jul 21 07:19:51.291632 2026] [security2:error] [pid 230252:tid 230502] [client 20.197.192.193:6372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/ms-new.php"] [unique_id "al9Hx00Dwhk5-Z44Xro35gAAAw8"]
[Tue Jul 21 07:19:51.442551 2026] [security2:error] [pid 230252:tid 230395] [client 4.204.201.85:35218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9Hx00Dwhk5-Z44Xro36AAAAqQ"]
[Tue Jul 21 07:19:51.468762 2026] [security2:error] [pid 230252:tid 230507] [client 4.204.201.85:26572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/memberfuns.php"] [unique_id "al9Hx00Dwhk5-Z44Xro36QAAAxQ"]
[Tue Jul 21 07:19:51.618555 2026] [security2:error] [pid 230252:tid 230393] [client 45.251.232.145:60618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hx00Dwhk5-Z44Xro37QAAAqI"]
[Tue Jul 21 07:19:51.618659 2026] [security2:error] [pid 230252:tid 230393] [client 45.251.232.145:60618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hx00Dwhk5-Z44Xro37QAAAqI"]
[Tue Jul 21 07:19:51.798383 2026] [security2:error] [pid 230252:tid 230290] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Hx00Dwhk5-Z44Xro38wAC7iQ"]
[Tue Jul 21 07:19:51.798573 2026] [security2:error] [pid 230252:tid 230469] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Hx00Dwhk5-Z44Xro38wAC7iQ"]
[Tue Jul 21 07:19:51.843137 2026] [security2:error] [pid 229246:tid 229401] [client 20.151.10.161:46007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/mac.php"] [unique_id "al9HxyBMYeh5YLVG45xdQQAAAi0"]
[Tue Jul 21 07:19:51.942137 2026] [security2:error] [pid 230252:tid 230399] [client 4.204.201.85:3318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/0.php"] [unique_id "al9Hx00Dwhk5-Z44Xro39AAAAqg"]
[Tue Jul 21 07:19:52.196907 2026] [security2:error] [pid 229246:tid 229410] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9HyCBMYeh5YLVG45xdRAAAAjY"]
[Tue Jul 21 07:19:52.279156 2026] [security2:error] [pid 229246:tid 229453] [client 4.204.201.85:35285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9HyCBMYeh5YLVG45xdRgAAAmE"]
[Tue Jul 21 07:19:52.420798 2026] [security2:error] [pid 230252:tid 230406] [client 20.151.10.161:46034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9HyE0Dwhk5-Z44Xro3_gAAAq8"]
[Tue Jul 21 07:19:52.620230 2026] [security2:error] [pid 229246:tid 229481] [client 4.204.201.85:3216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/BDKR28.php"] [unique_id "al9HyCBMYeh5YLVG45xdSQAAAn0"]
[Tue Jul 21 07:19:52.940104 2026] [security2:error] [pid 230252:tid 230445] [client 20.151.10.161:45900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wefile.php"] [unique_id "al9HyE0Dwhk5-Z44Xro4AwAAAtY"]
[Tue Jul 21 07:19:52.977888 2026] [security2:error] [pid 230252:tid 230497] [client 4.204.201.85:44019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/dr.php"] [unique_id "al9HyE0Dwhk5-Z44Xro4BQAAAwo"]
[Tue Jul 21 07:19:53.169679 2026] [security2:error] [pid 230252:tid 230433] [client 134.19.179.187:43314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4CwAAAso"]
[Tue Jul 21 07:19:53.169833 2026] [security2:error] [pid 230252:tid 230433] [client 134.19.179.187:43314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4CwAAAso"]
[Tue Jul 21 07:19:53.208287 2026] [security2:error] [pid 230252:tid 230459] [client 4.204.201.85:3282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/green1.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4DAAAAuQ"]
[Tue Jul 21 07:19:53.210775 2026] [security2:error] [pid 230252:tid 230264] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4DQACrgo"]
[Tue Jul 21 07:19:53.210978 2026] [security2:error] [pid 230252:tid 230405] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4DQACrgo"]
[Tue Jul 21 07:19:53.309270 2026] [security2:error] [pid 230252:tid 230387] [client 4.204.201.85:35205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/for.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4EAAAApw"]
[Tue Jul 21 07:19:53.479858 2026] [autoindex:error] [pid 230252:tid 230447] [client 198.235.24.47:63782] AH01276: Cannot serve directory /home4/ciclod61/ciclododinheiro.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:53.610104 2026] [security2:error] [pid 230252:tid 230423] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4EwAAAsA"]
[Tue Jul 21 07:19:53.710821 2026] [security2:error] [pid 230252:tid 230483] [client 134.19.179.187:60740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4FgAAAvw"]
[Tue Jul 21 07:19:53.710924 2026] [security2:error] [pid 230252:tid 230483] [client 134.19.179.187:60740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4FgAAAvw"]
[Tue Jul 21 07:19:53.732174 2026] [security2:error] [pid 230252:tid 230428] [client 4.204.201.85:43998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/x.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4FwAAAsU"]
[Tue Jul 21 07:19:53.778415 2026] [security2:error] [pid 230252:tid 230390] [client 194.147.58.101:44780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/localhost.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4GwAAAp8"]
[Tue Jul 21 07:19:53.778555 2026] [security2:error] [pid 230252:tid 230434] [client 194.147.58.101:44674] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/db_backup.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4GgAAAss"]
[Tue Jul 21 07:19:53.778619 2026] [security2:error] [pid 229246:tid 229494] [client 194.147.58.101:44704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/br1102.hostgator.com.br.sql"] [unique_id "al9HySBMYeh5YLVG45xdWAAAAoo"]
[Tue Jul 21 07:19:53.779939 2026] [security2:error] [pid 230252:tid 230395] [client 194.147.58.101:44680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/dbdump.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4HAAAAqQ"]
[Tue Jul 21 07:19:53.780047 2026] [security2:error] [pid 229246:tid 229496] [client 194.147.58.101:44690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/db.sql"] [unique_id "al9HySBMYeh5YLVG45xdWQAAAow"]
[Tue Jul 21 07:19:53.780279 2026] [security2:error] [pid 229246:tid 229433] [client 194.147.58.101:44684] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/br1102.hostgator.com.br_db.sql"] [unique_id "al9HySBMYeh5YLVG45xdWgAAAk0"]
[Tue Jul 21 07:19:53.780705 2026] [security2:error] [pid 230252:tid 230414] [client 194.147.58.101:44720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/mysqldump.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4HQAAArc"]
[Tue Jul 21 07:19:53.781194 2026] [security2:error] [pid 229246:tid 229468] [client 194.147.58.101:44730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/mysql.sql"] [unique_id "al9HySBMYeh5YLVG45xdWwAAAnA"]
[Tue Jul 21 07:19:53.781239 2026] [security2:error] [pid 230252:tid 230507] [client 194.147.58.101:44712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/backup.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4HgAAAxQ"]
[Tue Jul 21 07:19:53.781424 2026] [security2:error] [pid 230252:tid 230491] [client 194.147.58.101:44790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/wp-content/uploads/dump.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4HwAAAwQ"]
[Tue Jul 21 07:19:53.781538 2026] [security2:error] [pid 230252:tid 230393] [client 194.147.58.101:44764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/translate.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4IAAAAqI"]
[Tue Jul 21 07:19:53.781581 2026] [security2:error] [pid 229246:tid 229462] [client 194.147.58.101:44810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/wp-content/mysql.sql"] [unique_id "al9HySBMYeh5YLVG45xdXAAAAmo"]
[Tue Jul 21 07:19:53.782508 2026] [security2:error] [pid 230252:tid 230401] [client 194.147.58.101:44826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/sql.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4IQAAAqo"]
[Tue Jul 21 07:19:53.783273 2026] [security2:error] [pid 230252:tid 230458] [client 194.147.58.101:44734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/www.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4IgAAAuM"]
[Tue Jul 21 07:19:53.783456 2026] [security2:error] [pid 230252:tid 230503] [client 194.147.58.101:44816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/site.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4IwAAAxA"]
[Tue Jul 21 07:19:53.783686 2026] [security2:error] [pid 230252:tid 230477] [client 194.147.58.101:44804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/dump.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4JAAAAvY"]
[Tue Jul 21 07:19:53.784011 2026] [security2:error] [pid 230252:tid 230425] [client 194.147.58.101:44856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/data.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4JQAAAsI"]
[Tue Jul 21 07:19:53.784095 2026] [security2:error] [pid 229246:tid 229414] [client 194.147.58.101:44746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/1.sql"] [unique_id "al9HySBMYeh5YLVG45xdXQAAAjo"]
[Tue Jul 21 07:19:53.785463 2026] [security2:error] [pid 230252:tid 230432] [client 194.147.58.101:44842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/users.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4JgAAAsk"]
[Tue Jul 21 07:19:53.785685 2026] [security2:error] [pid 230252:tid 230475] [client 194.147.58.101:44748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/temp.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4JwAAAvQ"]
[Tue Jul 21 07:19:53.787315 2026] [security2:error] [pid 230252:tid 230470] [client 194.147.58.101:44688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/database.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4KAAAAu8"]
[Tue Jul 21 07:19:53.884762 2026] [security2:error] [pid 230252:tid 230495] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/xyn.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4LAAAAwg"]
[Tue Jul 21 07:19:53.962827 2026] [security2:error] [pid 230252:tid 230415] [client 4.204.201.85:26418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/nc4.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4LQAAArg"]
[Tue Jul 21 07:19:53.986078 2026] [security2:error] [pid 230252:tid 230422] [client 8.228.118.177:61230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rlvgestaoempresarial.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9HyU0Dwhk5-Z44Xro4LgAAAr8"]
[Tue Jul 21 07:19:54.158442 2026] [security2:error] [pid 230252:tid 230466] [client 20.151.10.161:45896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4MQAAAus"]
[Tue Jul 21 07:19:54.219563 2026] [security2:error] [pid 230252:tid 230465] [client 74.249.245.134:34473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/storage/index.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4MwAAAuo"]
[Tue Jul 21 07:19:54.331952 2026] [security2:error] [pid 230252:tid 230442] [client 20.226.60.151:61074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/0xD.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4NgAAAtM"]
[Tue Jul 21 07:19:54.376273 2026] [security2:error] [pid 230252:tid 230481] [client 136.144.33.99:57737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4OAAAAvo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:54.476527 2026] [security2:error] [pid 230252:tid 230399] [client 74.244.195.153:31557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.195.244.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4PgAAAqg"]
[Tue Jul 21 07:19:54.484264 2026] [security2:error] [pid 230252:tid 230399] [client 74.244.195.153:31557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4PgAAAqg"]
[Tue Jul 21 07:19:54.581197 2026] [security2:error] [pid 229246:tid 229471] [client 175.45.70.82:64764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HyiBMYeh5YLVG45xdaQAAAnM"]
[Tue Jul 21 07:19:54.581375 2026] [security2:error] [pid 229246:tid 229471] [client 175.45.70.82:64764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HyiBMYeh5YLVG45xdaQAAAnM"]
[Tue Jul 21 07:19:54.643696 2026] [security2:error] [pid 230252:tid 230423] [client 4.204.201.85:44010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/155.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4QQAAAsA"]
[Tue Jul 21 07:19:54.768516 2026] [security2:error] [pid 229246:tid 229463] [client 20.151.10.161:46077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/2P.php"] [unique_id "al9HyiBMYeh5YLVG45xdbwAAAms"]
[Tue Jul 21 07:19:54.813300 2026] [security2:error] [pid 230252:tid 230395] [client 4.204.201.85:3207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/a1.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4RQAAAqQ"]
[Tue Jul 21 07:19:54.859753 2026] [security2:error] [pid 230252:tid 230288] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4RgADDyI"]
[Tue Jul 21 07:19:54.859977 2026] [security2:error] [pid 230252:tid 230502] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4RgADDyI"]
[Tue Jul 21 07:19:54.907252 2026] [security2:error] [pid 230252:tid 230393] [client 4.204.201.85:35396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/raw.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4RwAAAqI"]
[Tue Jul 21 07:19:54.968248 2026] [security2:error] [pid 230252:tid 230304] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4SAACyzI"]
[Tue Jul 21 07:19:54.968447 2026] [security2:error] [pid 230252:tid 230434] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4SAACyzI"]
[Tue Jul 21 07:19:55.075841 2026] [security2:error] [pid 229246:tid 229388] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/patie.php"] [unique_id "al9HyyBMYeh5YLVG45xdcQAAAiA"]
[Tue Jul 21 07:19:55.181176 2026] [security2:error] [pid 230252:tid 230436] [client 4.204.201.85:43970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/ops.php"] [unique_id "al9Hy00Dwhk5-Z44Xro4SQAAAs0"]
[Tue Jul 21 07:19:55.347801 2026] [security2:error] [pid 230252:tid 230426] [client 4.204.201.85:3309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/eee.php"] [unique_id "al9Hy00Dwhk5-Z44Xro4SwAAAsM"]
[Tue Jul 21 07:19:55.350918 2026] [security2:error] [pid 229246:tid 229401] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/aa.php"] [unique_id "al9HyyBMYeh5YLVG45xdewAAAi0"]
[Tue Jul 21 07:19:55.456187 2026] [security2:error] [pid 230252:tid 230400] [client 120.61.173.56:53119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hy00Dwhk5-Z44Xro4TAAAAqk"]
[Tue Jul 21 07:19:55.456357 2026] [security2:error] [pid 230252:tid 230400] [client 120.61.173.56:53119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hy00Dwhk5-Z44Xro4TAAAAqk"]
[Tue Jul 21 07:19:55.486651 2026] [security2:error] [pid 230252:tid 230472] [client 117.222.76.61:55285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.76.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gradiente.com"] [uri "/xmlrpc.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4EQAAAvE"]
[Tue Jul 21 07:19:55.486887 2026] [security2:error] [pid 230252:tid 230472] [client 117.222.76.61:55285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gradiente.com"] [uri "/xmlrpc.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4EQAAAvE"]
[Tue Jul 21 07:19:55.489397 2026] [security2:error] [pid 230252:tid 230511] [client 20.151.10.161:45924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/.well-known/about.php"] [unique_id "al9Hy00Dwhk5-Z44Xro4TQAAAxg"]
[Tue Jul 21 07:19:55.671317 2026] [security2:error] [pid 230252:tid 230464] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/xwpg.php"] [unique_id "al9Hy00Dwhk5-Z44Xro4TgAAAuk"]
[Tue Jul 21 07:19:55.732069 2026] [security2:error] [pid 229246:tid 229441] [client 159.69.158.189:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9HyyBMYeh5YLVG45xdfgACVXk"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:19:55.910370 2026] [security2:error] [pid 230252:tid 230504] [client 4.204.201.85:43921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/file31.php"] [unique_id "al9Hy00Dwhk5-Z44Xro4UgAAAxE"]
[Tue Jul 21 07:19:55.948243 2026] [security2:error] [pid 230252:tid 230474] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/ops.php"] [unique_id "al9Hy00Dwhk5-Z44Xro4UwAAAvM"]
[Tue Jul 21 07:19:55.992875 2026] [security2:error] [pid 229246:tid 229430] [client 4.204.201.85:3263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/wp-aothait.php"] [unique_id "al9HyyBMYeh5YLVG45xdhAAAAko"]
[Tue Jul 21 07:19:56.223029 2026] [security2:error] [pid 230252:tid 230508] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/mac.php"] [unique_id "al9HzE0Dwhk5-Z44Xro4WQAAAxU"]
[Tue Jul 21 07:19:56.225195 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:45924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9HzE0Dwhk5-Z44Xro4WgAAAwY"]
[Tue Jul 21 07:19:56.252040 2026] [security2:error] [pid 230252:tid 230466] [client 20.151.10.161:55249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/test11.php"] [unique_id "al9HzE0Dwhk5-Z44Xro4WwAAAus"]
[Tue Jul 21 07:19:56.267250 2026] [security2:error] [pid 230252:tid 230445] [client 159.69.158.189:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9HzE0Dwhk5-Z44Xro4XAAC1jo"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:19:56.373759 2026] [security2:error] [pid 229246:tid 229377] [client 4.204.201.85:3286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/config.json.php"] [unique_id "al9HzCBMYeh5YLVG45xdjwAAAhU"]
[Tue Jul 21 07:19:56.392510 2026] [security2:error] [pid 229246:tid 229406] [client 20.197.192.193:6870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/track.php"] [unique_id "al9HzCBMYeh5YLVG45xdkAAAAjI"]
[Tue Jul 21 07:19:56.499514 2026] [security2:error] [pid 230252:tid 230469] [client 4.204.201.85:43912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/file6.php"] [unique_id "al9HzE0Dwhk5-Z44Xro4YwAAAu4"]
[Tue Jul 21 07:19:56.527674 2026] [security2:error] [pid 229246:tid 229403] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/mg.php"] [unique_id "al9HzCBMYeh5YLVG45xdkgAAAi8"]
[Tue Jul 21 07:19:56.616563 2026] [security2:error] [pid 230252:tid 230483] [client 74.249.245.134:58137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/g.php"] [unique_id "al9HzE0Dwhk5-Z44Xro4ZAAAAvw"]
[Tue Jul 21 07:19:56.688764 2026] [security2:error] [pid 230252:tid 230285] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HzE0Dwhk5-Z44Xro4ZgACxx8"]
[Tue Jul 21 07:19:56.688937 2026] [security2:error] [pid 230252:tid 230430] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HzE0Dwhk5-Z44Xro4ZgACxx8"]
[Tue Jul 21 07:19:56.770119 2026] [security2:error] [pid 230252:tid 230440] [client 92.119.178.3:35720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9HzE0Dwhk5-Z44Xro4ZwAAAtE"]
[Tue Jul 21 07:19:56.770227 2026] [security2:error] [pid 230252:tid 230440] [client 92.119.178.3:35720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9HzE0Dwhk5-Z44Xro4ZwAAAtE"]
[Tue Jul 21 07:19:56.822879 2026] [security2:error] [pid 229246:tid 229469] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-post-data.php"] [unique_id "al9HzCBMYeh5YLVG45xdmAAAAnE"]
[Tue Jul 21 07:19:56.885465 2026] [security2:error] [pid 229246:tid 229385] [client 4.204.201.85:3323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9HzCBMYeh5YLVG45xdmQAAAh0"]
[Tue Jul 21 07:19:57.036510 2026] [security2:error] [pid 230252:tid 230491] [client 8.228.118.177:64315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.118.228.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rlvgestaoempresarial.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HzU0Dwhk5-Z44Xro4agAAAwQ"]
[Tue Jul 21 07:19:57.036615 2026] [security2:error] [pid 230252:tid 230491] [client 8.228.118.177:64315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rlvgestaoempresarial.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HzU0Dwhk5-Z44Xro4agAAAwQ"]
[Tue Jul 21 07:19:57.117556 2026] [security2:error] [pid 230252:tid 230307] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HzU0Dwhk5-Z44Xro4awACtzU"]
[Tue Jul 21 07:19:57.117681 2026] [security2:error] [pid 230252:tid 230414] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HzU0Dwhk5-Z44Xro4awACtzU"]
[Tue Jul 21 07:19:57.135362 2026] [security2:error] [pid 229246:tid 229378] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/pucci.php"] [unique_id "al9HzSBMYeh5YLVG45xdnQAAAhY"]
[Tue Jul 21 07:19:57.264790 2026] [security2:error] [pid 229246:tid 229414] [client 20.151.10.161:45916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/bob.php"] [unique_id "al9HzSBMYeh5YLVG45xdoQAAAjo"]
[Tue Jul 21 07:19:57.410332 2026] [security2:error] [pid 229246:tid 229388] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/black.php"] [unique_id "al9HzSBMYeh5YLVG45xdpgAAAiA"]
[Tue Jul 21 07:19:57.534953 2026] [security2:error] [pid 230252:tid 230486] [client 20.197.192.193:27186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/la.php"] [unique_id "al9HzU0Dwhk5-Z44Xro4bQAAAv8"]
[Tue Jul 21 07:19:57.607450 2026] [security2:error] [pid 230252:tid 230495] [client 4.204.201.85:3311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/k2.php"] [unique_id "al9HzU0Dwhk5-Z44Xro4bwAAAwg"]
[Tue Jul 21 07:19:57.689442 2026] [security2:error] [pid 229246:tid 229423] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/zlece.php"] [unique_id "al9HzSBMYeh5YLVG45xdpwAAAkM"]
[Tue Jul 21 07:19:57.721256 2026] [security2:error] [pid 230252:tid 230426] [client 134.19.179.187:43342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HzU0Dwhk5-Z44Xro4cAAAAsM"]
[Tue Jul 21 07:19:57.721368 2026] [security2:error] [pid 230252:tid 230426] [client 134.19.179.187:43342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HzU0Dwhk5-Z44Xro4cAAAAsM"]
[Tue Jul 21 07:19:57.948328 2026] [security2:error] [pid 230252:tid 230404] [client 20.220.225.223:59491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/wp-editor.php"] [unique_id "al9HzU0Dwhk5-Z44Xro4cwAAAq0"]
[Tue Jul 21 07:19:57.970198 2026] [security2:error] [pid 230252:tid 230454] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/vssrs.php"] [unique_id "al9HzU0Dwhk5-Z44Xro4dwAAAt8"]
[Tue Jul 21 07:19:58.034748 2026] [security2:error] [pid 230252:tid 230407] [client 4.204.201.85:26580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9Hzk0Dwhk5-Z44Xro4eAAAArA"]
[Tue Jul 21 07:19:58.093668 2026] [http2:warn] [pid 229246:tid 229386] [client 57.141.18.25:62414] h2_stream(229246-22-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:19:58.273321 2026] [security2:error] [pid 230252:tid 230422] [client 20.151.10.161:46066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/crgio.php"] [unique_id "al9Hzk0Dwhk5-Z44Xro4egAAAr8"]
[Tue Jul 21 07:19:58.279278 2026] [security2:error] [pid 230252:tid 230497] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wicked.php"] [unique_id "al9Hzk0Dwhk5-Z44Xro4ewAAAwo"]
[Tue Jul 21 07:19:58.343583 2026] [security2:error] [pid 230252:tid 230424] [client 103.121.156.110:60613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Hzk0Dwhk5-Z44Xro4fwAAAsE"]
[Tue Jul 21 07:19:58.343722 2026] [security2:error] [pid 230252:tid 230424] [client 103.121.156.110:60613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Hzk0Dwhk5-Z44Xro4fwAAAsE"]
[Tue Jul 21 07:19:58.371664 2026] [security2:error] [pid 230252:tid 230263] [remote 41.76.214.143:37560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Hzk0Dwhk5-Z44Xro4gQACuQk"]
[Tue Jul 21 07:19:58.459130 2026] [security2:error] [pid 230252:tid 230466] [client 4.204.201.85:3275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9Hzk0Dwhk5-Z44Xro4hAAAAus"]
[Tue Jul 21 07:19:58.464285 2026] [security2:error] [pid 229246:tid 229429] [client 103.162.129.114:58491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9HziBMYeh5YLVG45xdsQAAAkk"]
[Tue Jul 21 07:19:58.464426 2026] [security2:error] [pid 229246:tid 229429] [client 103.162.129.114:58491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9HziBMYeh5YLVG45xdsQAAAkk"]
[Tue Jul 21 07:19:58.562607 2026] [security2:error] [pid 230252:tid 230459] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/24.php"] [unique_id "al9Hzk0Dwhk5-Z44Xro4hwAAAuQ"]
[Tue Jul 21 07:19:58.681882 2026] [security2:error] [pid 229246:tid 229446] [client 136.144.33.111:21599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9HziBMYeh5YLVG45xdsgAAAlo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:58.689551 2026] [security2:error] [pid 229246:tid 229401] [client 4.204.201.85:43955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/adminfuns.php"] [unique_id "al9HziBMYeh5YLVG45xdtQAAAi0"]
[Tue Jul 21 07:19:58.794650 2026] [security2:error] [pid 230252:tid 230501] [client 4.204.201.85:3272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9Hzk0Dwhk5-Z44Xro4iQAAAw4"]
[Tue Jul 21 07:19:58.844150 2026] [security2:error] [pid 230252:tid 230469] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/xacs.php"] [unique_id "al9Hzk0Dwhk5-Z44Xro4igAAAu4"]
[Tue Jul 21 07:19:59.022690 2026] [security2:error] [pid 229246:tid 229483] [client 20.220.225.223:52770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/cro.php"] [unique_id "al9HzyBMYeh5YLVG45xduwAAAn8"]
[Tue Jul 21 07:19:59.124784 2026] [security2:error] [pid 229246:tid 229405] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/zildan.php"] [unique_id "al9HzyBMYeh5YLVG45xdvgAAAjE"]
[Tue Jul 21 07:19:59.172372 2026] [security2:error] [pid 230252:tid 230510] [client 4.204.201.85:26005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/for.php"] [unique_id "al9Hz00Dwhk5-Z44Xro4lAAAAxc"]
[Tue Jul 21 07:19:59.406470 2026] [security2:error] [pid 229246:tid 229402] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/csa.php"] [unique_id "al9HzyBMYeh5YLVG45xdwAAAAi4"]
[Tue Jul 21 07:19:59.589073 2026] [security2:error] [pid 230252:tid 230454] [client 4.204.201.85:43910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/goods.php"] [unique_id "al9Hz00Dwhk5-Z44Xro4mQAAAt8"]
[Tue Jul 21 07:19:59.681233 2026] [security2:error] [pid 230252:tid 230384] [client 4.204.201.85:3249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/raw.php"] [unique_id "al9Hz00Dwhk5-Z44Xro4mwAAApk"]
[Tue Jul 21 07:19:59.696890 2026] [security2:error] [pid 230252:tid 230500] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/w3llscc.php"] [unique_id "al9Hz00Dwhk5-Z44Xro4nAAAAw0"]
[Tue Jul 21 07:19:59.968943 2026] [security2:error] [pid 229246:tid 229377] [client 4.204.201.85:43924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/100.php"] [unique_id "al9HzyBMYeh5YLVG45xdzgAAAhU"]
[Tue Jul 21 07:19:59.987808 2026] [security2:error] [pid 230252:tid 230422] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wpx.php"] [unique_id "al9Hz00Dwhk5-Z44Xro4oQAAAr8"]
[Tue Jul 21 07:19:59.989829 2026] [security2:error] [pid 229246:tid 229433] [client 14.139.42.196:19451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HzyBMYeh5YLVG45xdzwAAAk0"]
[Tue Jul 21 07:19:59.989917 2026] [security2:error] [pid 229246:tid 229433] [client 14.139.42.196:19451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HzyBMYeh5YLVG45xdzwAAAk0"]
[Tue Jul 21 07:20:00.017081 2026] [security2:error] [pid 229246:tid 229365] [remote 124.55.178.99:34008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-login.php"] [unique_id "al9H0CBMYeh5YLVG45xd0AACMHY"]
[Tue Jul 21 07:20:00.029898 2026] [security2:error] [pid 229246:tid 229429] [client 20.151.10.161:46008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/pucci.php"] [unique_id "al9H0CBMYeh5YLVG45xd0QAAAkk"]
[Tue Jul 21 07:20:00.222604 2026] [http2:warn] [pid 229246:tid 229480] [client 57.141.18.25:62416] h2_stream(229246-26-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:00.277028 2026] [security2:error] [pid 230252:tid 230300] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9H0E0Dwhk5-Z44Xro4owACtS4"]
[Tue Jul 21 07:20:00.277161 2026] [security2:error] [pid 230252:tid 230412] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9H0E0Dwhk5-Z44Xro4owACtS4"]
[Tue Jul 21 07:20:00.280030 2026] [security2:error] [pid 230252:tid 230466] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-css.php"] [unique_id "al9H0E0Dwhk5-Z44Xro4pAAAAus"]
[Tue Jul 21 07:20:00.330245 2026] [security2:error] [pid 229246:tid 229469] [client 74.249.245.134:59496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/nf.php"] [unique_id "al9H0CBMYeh5YLVG45xd1gAAAnE"]
[Tue Jul 21 07:20:00.477078 2026] [security2:error] [pid 229246:tid 229393] [client 4.204.201.85:43965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/about.php"] [unique_id "al9H0CBMYeh5YLVG45xd2wAAAiU"]
[Tue Jul 21 07:20:00.597627 2026] [security2:error] [pid 229246:tid 229392] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/ho.php"] [unique_id "al9H0CBMYeh5YLVG45xd3wAAAiQ"]
[Tue Jul 21 07:20:00.896439 2026] [security2:error] [pid 229246:tid 229497] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/xy.php"] [unique_id "al9H0CBMYeh5YLVG45xd4AAAAo0"]
[Tue Jul 21 07:20:00.959497 2026] [security2:error] [pid 229246:tid 229423] [client 92.119.178.3:32794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9H0CBMYeh5YLVG45xd4gAAAkM"]
[Tue Jul 21 07:20:00.959605 2026] [security2:error] [pid 229246:tid 229423] [client 92.119.178.3:32794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9H0CBMYeh5YLVG45xd4gAAAkM"]
[Tue Jul 21 07:20:01.167967 2026] [security2:error] [pid 229246:tid 229419] [client 20.197.192.193:27169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9H0SBMYeh5YLVG45xd6AAAAj8"]
[Tue Jul 21 07:20:01.177531 2026] [security2:error] [pid 229246:tid 229406] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/loader.php"] [unique_id "al9H0SBMYeh5YLVG45xd6QAAAjI"]
[Tue Jul 21 07:20:01.452550 2026] [security2:error] [pid 229246:tid 229491] [client 20.220.225.223:47852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/cron-tab.php"] [unique_id "al9H0SBMYeh5YLVG45xd8QAAAoc"]
[Tue Jul 21 07:20:01.460195 2026] [security2:error] [pid 230252:tid 230442] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/spadex.php"] [unique_id "al9H0U0Dwhk5-Z44Xro4qQAAAtM"]
[Tue Jul 21 07:20:01.495638 2026] [security2:error] [pid 230252:tid 230396] [client 68.235.38.2:54420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9H0U0Dwhk5-Z44Xro4qwAAAqU"]
[Tue Jul 21 07:20:01.495756 2026] [security2:error] [pid 230252:tid 230396] [client 68.235.38.2:54420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9H0U0Dwhk5-Z44Xro4qwAAAqU"]
[Tue Jul 21 07:20:01.683260 2026] [security2:error] [pid 230252:tid 230432] [client 92.119.178.3:32804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9H0U0Dwhk5-Z44Xro4sgAAAsk"]
[Tue Jul 21 07:20:01.683415 2026] [security2:error] [pid 230252:tid 230432] [client 92.119.178.3:32804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9H0U0Dwhk5-Z44Xro4sgAAAsk"]
[Tue Jul 21 07:20:01.761951 2026] [security2:error] [pid 230252:tid 230475] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/2x.php"] [unique_id "al9H0U0Dwhk5-Z44Xro4tAAAAvQ"]
[Tue Jul 21 07:20:01.875753 2026] [security2:error] [pid 230252:tid 230436] [client 20.197.192.193:6368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/2352356666.php"] [unique_id "al9H0U0Dwhk5-Z44Xro4tQAAAs0"]
[Tue Jul 21 07:20:01.917677 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.917761 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.917885 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.917925 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.917961 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918067 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918150 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918189 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918243 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918279 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918315 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918350 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918385 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918420 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918454 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918489 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918525 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918559 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918593 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918631 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918665 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918700 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918734 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918770 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918804 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918851 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918887 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918923 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919025 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919083 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919151 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919204 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919259 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919301 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919336 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919372 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919406 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919443 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919497 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919532 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919581 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919624 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919668 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919725 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919764 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919800 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919852 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919886 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919934 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919972 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920024 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920077 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920124 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920167 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920201 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920236 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920272 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920308 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920343 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920377 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920415 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920450 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920485 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920534 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920571 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920607 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920650 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920688 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920723 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920761 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920800 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920853 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920894 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920929 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920965 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921000 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921034 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921070 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921104 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921150 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921183 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921217 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921253 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921288 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921322 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921357 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921392 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921429 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921464 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921499 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921539 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921575 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921620 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921656 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921702 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:02.046682 2026] [security2:error] [pid 230252:tid 230507] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/ctex1.php"] [unique_id "al9H0k0Dwhk5-Z44Xro4twAAAxQ"]
[Tue Jul 21 07:20:02.112352 2026] [security2:error] [pid 230252:tid 230397] [client 45.251.232.145:61134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H0k0Dwhk5-Z44Xro4uAAAAqY"]
[Tue Jul 21 07:20:02.112501 2026] [security2:error] [pid 230252:tid 230397] [client 45.251.232.145:61134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H0k0Dwhk5-Z44Xro4uAAAAqY"]
[Tue Jul 21 07:20:02.223268 2026] [security2:error] [pid 230252:tid 230394] [client 20.197.192.193:6880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/pn.php"] [unique_id "al9H0k0Dwhk5-Z44Xro4uwAAAqM"]
[Tue Jul 21 07:20:02.335280 2026] [security2:error] [pid 230252:tid 230449] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/edorxrr.php"] [unique_id "al9H0k0Dwhk5-Z44Xro4vAAAAto"]
[Tue Jul 21 07:20:02.386937 2026] [security2:error] [pid 230252:tid 230454] [client 68.235.38.2:34236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9H0k0Dwhk5-Z44Xro4vQAAAt8"]
[Tue Jul 21 07:20:02.387080 2026] [security2:error] [pid 230252:tid 230454] [client 68.235.38.2:34236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9H0k0Dwhk5-Z44Xro4vQAAAt8"]
[Tue Jul 21 07:20:02.387331 2026] [security2:error] [pid 229246:tid 229368] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9H0iBMYeh5YLVG45xd_QACSHk"]
[Tue Jul 21 07:20:02.387623 2026] [security2:error] [pid 229246:tid 229428] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9H0iBMYeh5YLVG45xd_QACSHk"]
[Tue Jul 21 07:20:02.494937 2026] [security2:error] [pid 229246:tid 229387] [client 20.151.10.161:45999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-temp.php"] [unique_id "al9H0iBMYeh5YLVG45xd_gAAAh8"]
[Tue Jul 21 07:20:02.526355 2026] [security2:error] [pid 230252:tid 230447] [client 193.36.225.61:34387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9H0k0Dwhk5-Z44Xro4wQAAAtg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:02.615977 2026] [security2:error] [pid 230252:tid 230422] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/miru1.php"] [unique_id "al9H0k0Dwhk5-Z44Xro4wwAAAr8"]
[Tue Jul 21 07:20:02.627067 2026] [security2:error] [pid 230252:tid 230437] [client 74.249.245.134:34451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/xda.php"] [unique_id "al9H0k0Dwhk5-Z44Xro4xAAAAs4"]
[Tue Jul 21 07:20:02.636093 2026] [security2:error] [pid 230252:tid 230424] [client 20.151.10.161:53618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/koala.php"] [unique_id "al9H0k0Dwhk5-Z44Xro4xgAAAsE"]
[Tue Jul 21 07:20:03.016412 2026] [security2:error] [pid 230252:tid 230419] [client 4.204.201.85:43994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/about.php"] [unique_id "al9H000Dwhk5-Z44Xro4ywAAArw"]
[Tue Jul 21 07:20:03.515188 2026] [security2:error] [pid 229246:tid 229381] [client 4.204.201.85:43941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/admin.php"] [unique_id "al9H0yBMYeh5YLVG45xeDQAAAhk"]
[Tue Jul 21 07:20:03.665521 2026] [security2:error] [pid 229246:tid 229404] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/sump1.php"] [unique_id "al9H0yBMYeh5YLVG45xeEAAAAjA"]
[Tue Jul 21 07:20:03.718982 2026] [http2:warn] [pid 229246:tid 229442] [client 57.141.18.103:36488] h2_stream(229246-31-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:03.731975 2026] [autoindex:error] [pid 230252:tid 230502] [client 43.130.32.245:47032] AH01276: Cannot serve directory /home1/leon6484/lumevisual.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:20:03.770416 2026] [security2:error] [pid 230252:tid 230428] [client 20.197.192.193:6862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9H000Dwhk5-Z44Xro40gAAAsU"]
[Tue Jul 21 07:20:03.909832 2026] [security2:error] [pid 229246:tid 229269] [remote 159.223.116.62:60552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.116.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carrosselbuique.com.br"] [uri "/wp-login.php"] [unique_id "al9H0yBMYeh5YLVG45xeFAACVRY"]
[Tue Jul 21 07:20:03.949448 2026] [security2:error] [pid 229246:tid 229392] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/file5.php"] [unique_id "al9H0yBMYeh5YLVG45xeFQAAAiQ"]
[Tue Jul 21 07:20:03.965779 2026] [security2:error] [pid 230252:tid 230349] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9H000Dwhk5-Z44Xro41AAC_F4"]
[Tue Jul 21 07:20:03.965933 2026] [security2:error] [pid 230252:tid 230483] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9H000Dwhk5-Z44Xro41AAC_F4"]
[Tue Jul 21 07:20:04.018403 2026] [security2:error] [pid 230252:tid 230395] [client 4.204.201.85:43932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/admin.php"] [unique_id "al9H1E0Dwhk5-Z44Xro41QAAAqQ"]
[Tue Jul 21 07:20:04.259330 2026] [security2:error] [pid 229246:tid 229385] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/0xD.php"] [unique_id "al9H1CBMYeh5YLVG45xeGgAAAh0"]
[Tue Jul 21 07:20:04.465277 2026] [security2:error] [pid 229246:tid 229415] [client 139.135.44.145:54203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9H1CBMYeh5YLVG45xeGwAAAjs"]
[Tue Jul 21 07:20:04.465428 2026] [security2:error] [pid 229246:tid 229415] [client 139.135.44.145:54203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9H1CBMYeh5YLVG45xeGwAAAjs"]
[Tue Jul 21 07:20:04.521098 2026] [security2:error] [pid 230252:tid 230486] [client 4.204.201.85:43976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/themes.php"] [unique_id "al9H1E0Dwhk5-Z44Xro42AAAAv8"]
[Tue Jul 21 07:20:04.585413 2026] [security2:error] [pid 230252:tid 230473] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/fnstall.php"] [unique_id "al9H1E0Dwhk5-Z44Xro42QAAAvI"]
[Tue Jul 21 07:20:04.652628 2026] [security2:error] [pid 229246:tid 229393] [client 117.222.76.61:62400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.76.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gradiente.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H1CBMYeh5YLVG45xeHgAAAiU"]
[Tue Jul 21 07:20:04.652771 2026] [security2:error] [pid 229246:tid 229393] [client 117.222.76.61:62400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gradiente.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H1CBMYeh5YLVG45xeHgAAAiU"]
[Tue Jul 21 07:20:04.851645 2026] [security2:error] [pid 230252:tid 230394] [client 74.249.245.134:50996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/shell.php"] [unique_id "al9H1E0Dwhk5-Z44Xro43QAAAqM"]
[Tue Jul 21 07:20:04.887279 2026] [security2:error] [pid 230252:tid 230406] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/acp.php"] [unique_id "al9H1E0Dwhk5-Z44Xro43wAAAq8"]
[Tue Jul 21 07:20:05.004395 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:45888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9H1SBMYeh5YLVG45xeJAAAAlo"]
[Tue Jul 21 07:20:05.173064 2026] [security2:error] [pid 229246:tid 229467] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/mosty.php"] [unique_id "al9H1SBMYeh5YLVG45xeKAAAAm8"]
[Tue Jul 21 07:20:05.191395 2026] [security2:error] [pid 230252:tid 230472] [client 184.75.221.3:39206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9H1U0Dwhk5-Z44Xro44AAAAvE"]
[Tue Jul 21 07:20:05.191501 2026] [security2:error] [pid 230252:tid 230472] [client 184.75.221.3:39206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9H1U0Dwhk5-Z44Xro44AAAAvE"]
[Tue Jul 21 07:20:05.322866 2026] [security2:error] [pid 229246:tid 229431] [client 74.244.195.153:36225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.195.244.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9H1SBMYeh5YLVG45xeLAAAAks"]
[Tue Jul 21 07:20:05.323002 2026] [security2:error] [pid 229246:tid 229431] [client 74.244.195.153:36225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9H1SBMYeh5YLVG45xeLAAAAks"]
[Tue Jul 21 07:20:05.329569 2026] [security2:error] [pid 229246:tid 229410] [client 20.197.192.193:6398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/dr.php"] [unique_id "al9H1SBMYeh5YLVG45xeLQAAAjY"]
[Tue Jul 21 07:20:05.361537 2026] [security2:error] [pid 230252:tid 230320] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H1U0Dwhk5-Z44Xro44QAC30I"]
[Tue Jul 21 07:20:05.362029 2026] [security2:error] [pid 230252:tid 230454] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H1U0Dwhk5-Z44Xro44QAC30I"]
[Tue Jul 21 07:20:05.400316 2026] [security2:error] [pid 230252:tid 230471] [client 175.45.70.82:65283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H1U0Dwhk5-Z44Xro44gAAAvA"]
[Tue Jul 21 07:20:05.400439 2026] [security2:error] [pid 230252:tid 230471] [client 175.45.70.82:65283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H1U0Dwhk5-Z44Xro44gAAAvA"]
[Tue Jul 21 07:20:05.447583 2026] [security2:error] [pid 229246:tid 229463] [client 20.226.60.151:54505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/fnstall.php"] [unique_id "al9H1SBMYeh5YLVG45xeMQAAAms"]
[Tue Jul 21 07:20:05.460001 2026] [security2:error] [pid 229246:tid 229399] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/6.php"] [unique_id "al9H1SBMYeh5YLVG45xeMgAAAis"]
[Tue Jul 21 07:20:05.460308 2026] [security2:error] [pid 229246:tid 229405] [client 134.19.179.187:46258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9H1SBMYeh5YLVG45xeMwAAAjE"]
[Tue Jul 21 07:20:05.460376 2026] [security2:error] [pid 229246:tid 229405] [client 134.19.179.187:46258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9H1SBMYeh5YLVG45xeMwAAAjE"]
[Tue Jul 21 07:20:05.501680 2026] [security2:error] [pid 229246:tid 229354] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H1SBMYeh5YLVG45xeNAACVWs"]
[Tue Jul 21 07:20:05.501846 2026] [security2:error] [pid 229246:tid 229441] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H1SBMYeh5YLVG45xeNAACVWs"]
[Tue Jul 21 07:20:05.765902 2026] [security2:error] [pid 229246:tid 229423] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/32e17094cfindex.php"] [unique_id "al9H1SBMYeh5YLVG45xeOgAAAkM"]
[Tue Jul 21 07:20:05.876123 2026] [security2:error] [pid 229246:tid 229477] [client 20.220.225.223:43061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/koiy.php"] [unique_id "al9H1SBMYeh5YLVG45xePQAAAnk"]
[Tue Jul 21 07:20:06.040043 2026] [security2:error] [pid 229246:tid 229419] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/qqqa.php"] [unique_id "al9H1iBMYeh5YLVG45xeQQAAAj8"]
[Tue Jul 21 07:20:06.098041 2026] [security2:error] [pid 229246:tid 229480] [client 120.61.173.56:53619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H1iBMYeh5YLVG45xeQgAAAnw"]
[Tue Jul 21 07:20:06.098223 2026] [security2:error] [pid 229246:tid 229480] [client 120.61.173.56:53619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H1iBMYeh5YLVG45xeQgAAAnw"]
[Tue Jul 21 07:20:06.142605 2026] [security2:error] [pid 229246:tid 229481] [client 20.197.192.193:6892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/2x.php"] [unique_id "al9H1iBMYeh5YLVG45xeRAAAAn0"]
[Tue Jul 21 07:20:06.232466 2026] [security2:error] [pid 229246:tid 229462] [client 20.226.60.151:61056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/acp.php"] [unique_id "al9H1iBMYeh5YLVG45xeRwAAAmo"]
[Tue Jul 21 07:20:06.307295 2026] [security2:error] [pid 230252:tid 230457] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/aunmc.php"] [unique_id "al9H1k0Dwhk5-Z44Xro45QAAAuI"]
[Tue Jul 21 07:20:06.431339 2026] [security2:error] [pid 229246:tid 229380] [client 4.204.201.85:43940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/.well-known/about.php"] [unique_id "al9H1iBMYeh5YLVG45xeTAAAAhg"]
[Tue Jul 21 07:20:06.463270 2026] [security2:error] [pid 229246:tid 229495] [client 20.226.60.151:54489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/mosty.php"] [unique_id "al9H1iBMYeh5YLVG45xeTwAAAos"]
[Tue Jul 21 07:20:06.476330 2026] [http2:warn] [pid 229246:tid 229412] [client 57.141.18.41:21028] h2_stream(229246-57-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:06.574431 2026] [security2:error] [pid 230252:tid 230487] [client 91.92.41.64:53483] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.63.69"] [uri "/.env"] [unique_id "al9H1k0Dwhk5-Z44Xro45wAAAwA"]
[Tue Jul 21 07:20:06.580628 2026] [security2:error] [pid 230252:tid 230412] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/uoocf.php"] [unique_id "al9H1k0Dwhk5-Z44Xro46AAAArU"]
[Tue Jul 21 07:20:06.714797 2026] [security2:error] [pid 230252:tid 230511] [client 74.249.245.134:21639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/3.php"] [unique_id "al9H1k0Dwhk5-Z44Xro46gAAAxg"]
[Tue Jul 21 07:20:06.864525 2026] [security2:error] [pid 230252:tid 230504] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/iywwi.php"] [unique_id "al9H1k0Dwhk5-Z44Xro47AAAAxE"]
[Tue Jul 21 07:20:07.021278 2026] [security2:error] [pid 230252:tid 230439] [client 20.151.10.161:55284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/mac.php"] [unique_id "al9H100Dwhk5-Z44Xro47gAAAtA"]
[Tue Jul 21 07:20:07.139002 2026] [security2:error] [pid 229246:tid 229398] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/gqgsa.php"] [unique_id "al9H1yBMYeh5YLVG45xeVQAAAio"]
[Tue Jul 21 07:20:07.276922 2026] [security2:error] [pid 230252:tid 230501] [client 20.197.192.193:6384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/kq1.php"] [unique_id "al9H100Dwhk5-Z44Xro48AAAAw4"]
[Tue Jul 21 07:20:07.373211 2026] [security2:error] [pid 229246:tid 229250] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9H1yBMYeh5YLVG45xeWQACRwM"]
[Tue Jul 21 07:20:07.373333 2026] [security2:error] [pid 229246:tid 229427] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9H1yBMYeh5YLVG45xeWQACRwM"]
[Tue Jul 21 07:20:07.407123 2026] [security2:error] [pid 229246:tid 229469] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/elbzl.php"] [unique_id "al9H1yBMYeh5YLVG45xeWgAAAnE"]
[Tue Jul 21 07:20:07.412830 2026] [security2:error] [pid 229246:tid 229403] [client 193.36.225.61:35751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9H1iBMYeh5YLVG45xeSAAAAi8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:07.607656 2026] [security2:error] [pid 229246:tid 229439] [client 20.151.10.161:46038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/puc.php"] [unique_id "al9H1yBMYeh5YLVG45xeXQAAAlM"]
[Tue Jul 21 07:20:07.619982 2026] [security2:error] [pid 229246:tid 229377] [client 4.204.201.85:43989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9H1yBMYeh5YLVG45xeXgAAAhU"]
[Tue Jul 21 07:20:07.690753 2026] [security2:error] [pid 229246:tid 229481] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/adjig.php"] [unique_id "al9H1yBMYeh5YLVG45xeYgAAAn0"]
[Tue Jul 21 07:20:07.790361 2026] [security2:error] [pid 229246:tid 229410] [client 20.197.192.193:6868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/zzz.php"] [unique_id "al9H1yBMYeh5YLVG45xeZgAAAjY"]
[Tue Jul 21 07:20:07.977492 2026] [security2:error] [pid 229246:tid 229398] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/byp.php"] [unique_id "al9H1yBMYeh5YLVG45xebwAAAio"]
[Tue Jul 21 07:20:07.991413 2026] [security2:error] [pid 229246:tid 229466] [client 20.220.225.223:39543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/hp2.php"] [unique_id "al9H1yBMYeh5YLVG45xecAAAAm4"]
[Tue Jul 21 07:20:08.124003 2026] [http2:warn] [pid 229246:tid 229437] [client 57.141.18.42:31308] h2_stream(229246-67-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:08.227326 2026] [security2:error] [pid 229246:tid 229435] [client 20.197.192.193:6366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/wicked.php"] [unique_id "al9H2CBMYeh5YLVG45xecwAAAk8"]
[Tue Jul 21 07:20:08.272219 2026] [security2:error] [pid 229246:tid 229256] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9H2CBMYeh5YLVG45xedgACLwk"]
[Tue Jul 21 07:20:08.272343 2026] [security2:error] [pid 229246:tid 229403] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9H2CBMYeh5YLVG45xedgACLwk"]
[Tue Jul 21 07:20:08.286010 2026] [security2:error] [pid 229246:tid 229480] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/ortasekerli1.php"] [unique_id "al9H2CBMYeh5YLVG45xedwAAAnw"]
[Tue Jul 21 07:20:08.375278 2026] [security2:error] [pid 229246:tid 229429] [client 134.19.179.187:44074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9H2CBMYeh5YLVG45xeewAAAkk"]
[Tue Jul 21 07:20:08.375372 2026] [security2:error] [pid 229246:tid 229429] [client 134.19.179.187:44074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9H2CBMYeh5YLVG45xeewAAAkk"]
[Tue Jul 21 07:20:08.570259 2026] [security2:error] [pid 230252:tid 230425] [client 20.220.225.223:34189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9H2E0Dwhk5-Z44Xro4-gAAAsI"]
[Tue Jul 21 07:20:08.579253 2026] [security2:error] [pid 230252:tid 230486] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/classwithtostring.php"] [unique_id "al9H2E0Dwhk5-Z44Xro4-wAAAv8"]
[Tue Jul 21 07:20:08.797865 2026] [security2:error] [pid 230252:tid 230458] [client 74.249.245.134:43448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/mds.php"] [unique_id "al9H2E0Dwhk5-Z44Xro4_QAAAuM"]
[Tue Jul 21 07:20:08.862178 2026] [security2:error] [pid 230252:tid 230433] [client 85.208.96.198:49380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "vivaconcierge.com.br"] [uri "/robots.txt"] [unique_id "al9H2E0Dwhk5-Z44Xro5AQAAAso"]
[Tue Jul 21 07:20:08.862315 2026] [security2:error] [pid 230252:tid 230433] [client 85.208.96.198:49380] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "vivaconcierge.com.br"] [uri "/robots.txt"] [unique_id "al9H2E0Dwhk5-Z44Xro5AQAAAso"]
[Tue Jul 21 07:20:08.870692 2026] [security2:error] [pid 230252:tid 230392] [client 20.151.10.161:53596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9H2E0Dwhk5-Z44Xro5AgAAAqE"]
[Tue Jul 21 07:20:08.889221 2026] [security2:error] [pid 230252:tid 230426] [client 74.7.228.31:40322] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "tainaegiovane.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9H2E0Dwhk5-Z44Xro5AwACw04"]
[Tue Jul 21 07:20:08.901082 2026] [security2:error] [pid 230252:tid 230409] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/root.php"] [unique_id "al9H2E0Dwhk5-Z44Xro5BAAAArI"]
[Tue Jul 21 07:20:08.955781 2026] [security2:error] [pid 230252:tid 230394] [client 4.204.201.85:43848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/wefile.php"] [unique_id "al9H2E0Dwhk5-Z44Xro5BQAAAqM"]
[Tue Jul 21 07:20:09.009910 2026] [security2:error] [pid 230252:tid 230503] [client 103.121.156.110:60938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9H2U0Dwhk5-Z44Xro5BwAAAxA"]
[Tue Jul 21 07:20:09.010032 2026] [security2:error] [pid 230252:tid 230503] [client 103.121.156.110:60938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9H2U0Dwhk5-Z44Xro5BwAAAxA"]
[Tue Jul 21 07:20:09.064054 2026] [security2:error] [pid 230252:tid 230432] [client 103.162.129.114:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9H2U0Dwhk5-Z44Xro5CAAAAsk"]
[Tue Jul 21 07:20:09.064253 2026] [security2:error] [pid 230252:tid 230432] [client 103.162.129.114:59060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9H2U0Dwhk5-Z44Xro5CAAAAsk"]
[Tue Jul 21 07:20:09.095908 2026] [security2:error] [pid 230252:tid 230407] [client 20.197.192.193:6393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/edit.php"] [unique_id "al9H2U0Dwhk5-Z44Xro5CQAAArA"]
[Tue Jul 21 07:20:09.210628 2026] [security2:error] [pid 229246:tid 229466] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/sym403.php"] [unique_id "al9H2SBMYeh5YLVG45xehgAAAm4"]
[Tue Jul 21 07:20:09.424634 2026] [security2:error] [pid 229246:tid 229424] [client 185.191.171.5:15098] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "vivaconcierge.com.br"] [uri "/_detalhes/lavanderia/page/2/"] [unique_id "al9H2SBMYeh5YLVG45xeiwAAAkQ"]
[Tue Jul 21 07:20:09.424741 2026] [security2:error] [pid 229246:tid 229424] [client 185.191.171.5:15098] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "vivaconcierge.com.br"] [uri "/_detalhes/lavanderia/page/2/"] [unique_id "al9H2SBMYeh5YLVG45xeiwAAAkQ"]
[Tue Jul 21 07:20:09.516256 2026] [security2:error] [pid 230252:tid 230437] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/v543.php"] [unique_id "al9H2U0Dwhk5-Z44Xro5DgAAAs4"]
[Tue Jul 21 07:20:09.808978 2026] [security2:error] [pid 229246:tid 229390] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/sixxis.php"] [unique_id "al9H2SBMYeh5YLVG45xejgAAAiI"]
[Tue Jul 21 07:20:10.125917 2026] [security2:error] [pid 230252:tid 230399] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/ip.php"] [unique_id "al9H2k0Dwhk5-Z44Xro5EwAAAqg"]
[Tue Jul 21 07:20:10.140973 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:45994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/themes.php"] [unique_id "al9H2k0Dwhk5-Z44Xro5FAAAAwY"]
[Tue Jul 21 07:20:10.181368 2026] [core:error] [pid 229246:tid 229277] [remote 198.235.24.183:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:10.181397 2026] [core:error] [pid 229246:tid 229277] [remote 198.235.24.183:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:10.273765 2026] [security2:error] [pid 230252:tid 230439] [client 20.220.225.223:34274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9H2k0Dwhk5-Z44Xro5FQAAAtA"]
[Tue Jul 21 07:20:10.419434 2026] [security2:error] [pid 230252:tid 230501] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/kq1.php"] [unique_id "al9H2k0Dwhk5-Z44Xro5FwAAAw4"]
[Tue Jul 21 07:20:10.517538 2026] [security2:error] [pid 230252:tid 230461] [client 20.151.10.161:55251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wefile.php"] [unique_id "al9H2k0Dwhk5-Z44Xro5GQAAAuY"]
[Tue Jul 21 07:20:10.715722 2026] [security2:error] [pid 229246:tid 229478] [client 14.139.42.196:3048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H2iBMYeh5YLVG45xenQAAAno"]
[Tue Jul 21 07:20:10.715846 2026] [security2:error] [pid 229246:tid 229478] [client 14.139.42.196:3048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H2iBMYeh5YLVG45xenQAAAno"]
[Tue Jul 21 07:20:10.716768 2026] [security2:error] [pid 230252:tid 230428] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/fw/faiyy.php"] [unique_id "al9H2k0Dwhk5-Z44Xro5GgAAAsU"]
[Tue Jul 21 07:20:10.749503 2026] [security2:error] [pid 230252:tid 230334] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9H2k0Dwhk5-Z44Xro5GwACx08"]
[Tue Jul 21 07:20:10.749643 2026] [security2:error] [pid 230252:tid 230430] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9H2k0Dwhk5-Z44Xro5GwACx08"]
[Tue Jul 21 07:20:11.016547 2026] [security2:error] [pid 229246:tid 229495] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/h02ugyh.php"] [unique_id "al9H2yBMYeh5YLVG45xeowAAAos"]
[Tue Jul 21 07:20:11.028564 2026] [security2:error] [pid 229246:tid 229503] [client 74.249.245.134:56111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/archive.php"] [unique_id "al9H2yBMYeh5YLVG45xepAAAApM"]
[Tue Jul 21 07:20:11.204954 2026] [security2:error] [pid 229246:tid 229406] [client 20.197.192.193:6897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/kua.php"] [unique_id "al9H2yBMYeh5YLVG45xeqQAAAjI"]
[Tue Jul 21 07:20:11.208666 2026] [security2:error] [pid 230252:tid 230510] [client 4.204.201.85:44020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9H200Dwhk5-Z44Xro5HgAAAxc"]
[Tue Jul 21 07:20:11.298929 2026] [security2:error] [pid 230252:tid 230410] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-temp.php"] [unique_id "al9H200Dwhk5-Z44Xro5HwAAArM"]
[Tue Jul 21 07:20:11.513866 2026] [security2:error] [pid 229246:tid 229344] [remote 45.79.123.44:56894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "murilomattos.com"] [uri "/wp-login.php"] [unique_id "al9H2yBMYeh5YLVG45xergACHWE"]
[Tue Jul 21 07:20:11.580423 2026] [security2:error] [pid 230252:tid 230397] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-content/cong.php"] [unique_id "al9H200Dwhk5-Z44Xro5IwAAAqY"]
[Tue Jul 21 07:20:11.609315 2026] [security2:error] [pid 229246:tid 229354] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelalves1781880029279.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H2yBMYeh5YLVG45xesQACe2s"]
[Tue Jul 21 07:20:11.659634 2026] [security2:error] [pid 230252:tid 230507] [client 20.151.10.161:53603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9H200Dwhk5-Z44Xro5JQAAAxQ"]
[Tue Jul 21 07:20:11.832246 2026] [security2:error] [pid 230252:tid 230508] [client 193.36.225.65:61021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9H200Dwhk5-Z44Xro5JwAAAxU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:12.095765 2026] [security2:error] [pid 230252:tid 230503] [client 20.197.192.193:6885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/ez.php"] [unique_id "al9H3E0Dwhk5-Z44Xro5KwAAAxA"]
[Tue Jul 21 07:20:12.198743 2026] [security2:error] [pid 230252:tid 230407] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelalves1781880029279.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H3E0Dwhk5-Z44Xro5LAAAArA"]
[Tue Jul 21 07:20:12.384888 2026] [security2:error] [pid 230252:tid 230347] [remote 57.141.18.26:27804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemaph.xml"] [unique_id "al9H3E0Dwhk5-Z44Xro5LQAC11w"]
[Tue Jul 21 07:20:12.592517 2026] [security2:error] [pid 230252:tid 230426] [client 45.251.232.145:61649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H3E0Dwhk5-Z44Xro5MgAAAsM"]
[Tue Jul 21 07:20:12.592636 2026] [security2:error] [pid 230252:tid 230426] [client 45.251.232.145:61649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H3E0Dwhk5-Z44Xro5MgAAAsM"]
[Tue Jul 21 07:20:12.601898 2026] [qos:error] [pid 230252:tid 230330] [remote 74.7.227.54:57656] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=74.7.227.54, id=al9H3E0Dwhk5-Z44Xro5MwACzks, referer: https://arielson.com.br/coursos/?duration=extraLong%2Cmedium&filter_course-category=397&filter_course-tag=134%2C455%2C454%2C249%2C130&filtering=1&orderby=newest_first&price_type=paid&rating_filter=5
[Tue Jul 21 07:20:12.946747 2026] [security2:error] [pid 230252:tid 230354] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9H3E0Dwhk5-Z44Xro5NgADCmM"]
[Tue Jul 21 07:20:12.946936 2026] [security2:error] [pid 230252:tid 230497] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9H3E0Dwhk5-Z44Xro5NgADCmM"]
[Tue Jul 21 07:20:12.952343 2026] [security2:error] [pid 229246:tid 229356] [remote 165.227.132.137:37770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.132.227.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "caminhoneiro.giovanoniadv.com.br"] [uri "/wp-login.php"] [unique_id "al9H3CBMYeh5YLVG45xevgACTG0"]
[Tue Jul 21 07:20:13.026988 2026] [security2:error] [pid 230252:tid 230465] [client 20.151.10.161:46001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/dx.php"] [unique_id "al9H3U0Dwhk5-Z44Xro5OAAAAuo"]
[Tue Jul 21 07:20:13.138990 2026] [security2:error] [pid 230252:tid 230399] [client 74.249.245.134:61472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/amax.php"] [unique_id "al9H3U0Dwhk5-Z44Xro5PQAAAqg"]
[Tue Jul 21 07:20:13.207431 2026] [security2:error] [pid 230252:tid 230391] [client 20.151.10.161:53570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/2P.php"] [unique_id "al9H3U0Dwhk5-Z44Xro5PwAAAqA"]
[Tue Jul 21 07:20:13.523835 2026] [security2:error] [pid 229246:tid 229310] [remote 45.150.79.142:55472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/wp-login.php"] [unique_id "al9H3SBMYeh5YLVG45xeyQACST8"]
[Tue Jul 21 07:20:14.192128 2026] [security2:error] [pid 230252:tid 230352] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelalves1781880029279.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H3k0Dwhk5-Z44Xro5RgACs2E"]
[Tue Jul 21 07:20:14.606807 2026] [security2:error] [pid 230252:tid 230397] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelalves1781880029279.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H3k0Dwhk5-Z44Xro5TAAAAqY"]
[Tue Jul 21 07:20:14.738918 2026] [security2:error] [pid 230252:tid 230366] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9H3k0Dwhk5-Z44Xro5TgACzW8"]
[Tue Jul 21 07:20:14.739075 2026] [security2:error] [pid 230252:tid 230436] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9H3k0Dwhk5-Z44Xro5TgACzW8"]
[Tue Jul 21 07:20:14.794987 2026] [security2:error] [pid 230252:tid 230464] [client 134.19.179.187:53014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9H3k0Dwhk5-Z44Xro5UQAAAuk"]
[Tue Jul 21 07:20:14.795064 2026] [security2:error] [pid 230252:tid 230464] [client 134.19.179.187:53014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9H3k0Dwhk5-Z44Xro5UQAAAuk"]
[Tue Jul 21 07:20:15.017636 2026] [security2:error] [pid 230252:tid 230411] [client 20.226.60.151:54553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/6.php"] [unique_id "al9H300Dwhk5-Z44Xro5VAAAArQ"]
[Tue Jul 21 07:20:15.028622 2026] [security2:error] [pid 230252:tid 230369] [remote 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sbbarrosadvocacia.com.br"] [uri "/wp-admin/install.php"] [unique_id "al9H300Dwhk5-Z44Xro5VQADCHI"]
[Tue Jul 21 07:20:15.032642 2026] [http2:warn] [pid 229246:tid 229394] [client 57.141.18.97:24286] h2_stream(229246-97-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:15.065549 2026] [security2:error] [pid 229246:tid 229441] [client 139.135.44.145:53168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9H3yBMYeh5YLVG45xe2QAAAlU"]
[Tue Jul 21 07:20:15.065656 2026] [security2:error] [pid 229246:tid 229441] [client 139.135.44.145:53168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9H3yBMYeh5YLVG45xe2QAAAlU"]
[Tue Jul 21 07:20:15.089415 2026] [security2:error] [pid 230252:tid 230418] [client 4.204.201.85:43996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9H300Dwhk5-Z44Xro5VgAAArs"]
[Tue Jul 21 07:20:15.181702 2026] [security2:error] [pid 229246:tid 229424] [client 20.151.10.161:12035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/.well-known/about.php"] [unique_id "al9H3yBMYeh5YLVG45xe3AAAAkQ"]
[Tue Jul 21 07:20:15.224221 2026] [security2:error] [pid 230252:tid 230351] [remote 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sbbarrosadvocacia.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9H300Dwhk5-Z44Xro5WgAC9WA"]
[Tue Jul 21 07:20:15.530317 2026] [security2:error] [pid 230252:tid 230497] [client 20.151.10.161:46004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/p.php"] [unique_id "al9H300Dwhk5-Z44Xro5XQAAAwo"]
[Tue Jul 21 07:20:15.823196 2026] [security2:error] [pid 230252:tid 230429] [client 20.151.10.161:53582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9H300Dwhk5-Z44Xro5YQAAAsY"]
[Tue Jul 21 07:20:15.917190 2026] [security2:error] [pid 230252:tid 230371] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H300Dwhk5-Z44Xro5YgACtXQ"]
[Tue Jul 21 07:20:15.917312 2026] [security2:error] [pid 230252:tid 230412] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H300Dwhk5-Z44Xro5YgACtXQ"]
[Tue Jul 21 07:20:16.059034 2026] [security2:error] [pid 230252:tid 230447] [client 175.45.70.82:49385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H4E0Dwhk5-Z44Xro5ZAAAAtg"]
[Tue Jul 21 07:20:16.059171 2026] [security2:error] [pid 230252:tid 230447] [client 175.45.70.82:49385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H4E0Dwhk5-Z44Xro5ZAAAAtg"]
[Tue Jul 21 07:20:16.074862 2026] [security2:error] [pid 229246:tid 229435] [client 92.119.178.3:58902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9H4CBMYeh5YLVG45xe5gAAAk8"]
[Tue Jul 21 07:20:16.074959 2026] [security2:error] [pid 229246:tid 229435] [client 92.119.178.3:58902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9H4CBMYeh5YLVG45xe5gAAAk8"]
[Tue Jul 21 07:20:16.087491 2026] [security2:error] [pid 230252:tid 230373] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H4E0Dwhk5-Z44Xro5ZgACqHY"]
[Tue Jul 21 07:20:16.087612 2026] [security2:error] [pid 230252:tid 230399] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H4E0Dwhk5-Z44Xro5ZgACqHY"]
[Tue Jul 21 07:20:16.124257 2026] [security2:error] [pid 230252:tid 230462] [client 74.244.195.153:17850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.195.244.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9H4E0Dwhk5-Z44Xro5ZwAAAuc"]
[Tue Jul 21 07:20:16.129176 2026] [security2:error] [pid 230252:tid 230462] [client 74.244.195.153:17850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9H4E0Dwhk5-Z44Xro5ZwAAAuc"]
[Tue Jul 21 07:20:16.177118 2026] [http2:warn] [pid 229246:tid 229376] [client 57.141.18.0:35978] h2_stream(229246-101-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:16.357771 2026] [security2:error] [pid 229246:tid 229407] [client 172.245.102.42:49889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9H4CBMYeh5YLVG45xe6AAAAjM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:16.473827 2026] [security2:error] [pid 229246:tid 229397] [client 20.151.10.161:55247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/bob.php"] [unique_id "al9H4CBMYeh5YLVG45xe6gAAAik"]
[Tue Jul 21 07:20:16.575041 2026] [security2:error] [pid 229246:tid 229463] [client 4.204.201.85:43844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/8.php"] [unique_id "al9H4CBMYeh5YLVG45xe7AAAAms"]
[Tue Jul 21 07:20:16.602464 2026] [security2:error] [pid 230252:tid 230486] [client 20.197.192.193:6872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/fz.php"] [unique_id "al9H4E0Dwhk5-Z44Xro5bgAAAv8"]
[Tue Jul 21 07:20:16.622335 2026] [security2:error] [pid 230252:tid 230491] [client 91.92.41.64:58914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.63.69"] [uri "/.env"] [unique_id "al9H4E0Dwhk5-Z44Xro5bwAAAwQ"]
[Tue Jul 21 07:20:16.694810 2026] [security2:error] [pid 229246:tid 229438] [client 74.249.245.134:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/moon.php"] [unique_id "al9H4CBMYeh5YLVG45xe7wAAAlI"]
[Tue Jul 21 07:20:16.812965 2026] [security2:error] [pid 229246:tid 229462] [client 120.61.173.56:54123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H4CBMYeh5YLVG45xe8QAAAmo"]
[Tue Jul 21 07:20:16.813101 2026] [security2:error] [pid 229246:tid 229462] [client 120.61.173.56:54123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H4CBMYeh5YLVG45xe8QAAAmo"]
[Tue Jul 21 07:20:17.134789 2026] [http2:warn] [pid 229246:tid 229485] [client 57.141.18.3:20152] h2_stream(229246-108-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:17.173287 2026] [http2:warn] [pid 229246:tid 229473] [client 57.141.18.98:33432] h2_stream(229246-110-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:17.192009 2026] [security2:error] [pid 230252:tid 230449] [client 20.220.225.223:47827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9H4U0Dwhk5-Z44Xro5dgAAAto"]
[Tue Jul 21 07:20:17.218323 2026] [security2:error] [pid 229246:tid 229432] [client 20.151.10.161:46057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/bthil.php"] [unique_id "al9H4SBMYeh5YLVG45xe-QAAAkw"]
[Tue Jul 21 07:20:17.501522 2026] [security2:error] [pid 230252:tid 230372] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782090694588.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H4U0Dwhk5-Z44Xro5fQADDXU"]
[Tue Jul 21 07:20:17.510344 2026] [security2:error] [pid 230252:tid 230294] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091656000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H4U0Dwhk5-Z44Xro5fgADAig"]
[Tue Jul 21 07:20:17.512737 2026] [security2:error] [pid 230252:tid 230268] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091746000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H4U0Dwhk5-Z44Xro5fwACvw4"]
[Tue Jul 21 07:20:17.534863 2026] [security2:error] [pid 230252:tid 230457] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091746000.samuelgoncalvesdesou1782090694588.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H4U0Dwhk5-Z44Xro5gQAAAuI"]
[Tue Jul 21 07:20:17.554746 2026] [security2:error] [pid 230252:tid 230473] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091656000.samuelgoncalvesdesou1782090694588.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H4U0Dwhk5-Z44Xro5ggAAAvI"]
[Tue Jul 21 07:20:17.631223 2026] [security2:error] [pid 230252:tid 230400] [client 134.19.179.187:44108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9H4U0Dwhk5-Z44Xro5hQAAAqk"]
[Tue Jul 21 07:20:17.631326 2026] [security2:error] [pid 230252:tid 230400] [client 134.19.179.187:44108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9H4U0Dwhk5-Z44Xro5hQAAAqk"]
[Tue Jul 21 07:20:17.638590 2026] [core:error] [pid 230252:tid 230274] [remote 40.77.167.49:64096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:17.638604 2026] [core:error] [pid 230252:tid 230274] [remote 40.77.167.49:64096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:17.701621 2026] [security2:error] [pid 230252:tid 230429] [client 4.204.201.85:44014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9H4U0Dwhk5-Z44Xro5hwAAAsY"]
[Tue Jul 21 07:20:17.757584 2026] [security2:error] [pid 230252:tid 230439] [client 20.151.10.161:55287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/crgio.php"] [unique_id "al9H4U0Dwhk5-Z44Xro5iAAAAtA"]
[Tue Jul 21 07:20:17.761637 2026] [core:error] [pid 230252:tid 230282] [remote 40.77.167.49:64096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:17.761654 2026] [core:error] [pid 230252:tid 230282] [remote 40.77.167.49:64096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:17.821935 2026] [security2:error] [pid 230252:tid 230467] [client 34.86.210.0:55487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.210.86.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H4U0Dwhk5-Z44Xro5jQAAAuw"]
[Tue Jul 21 07:20:17.822012 2026] [security2:error] [pid 230252:tid 230467] [client 34.86.210.0:55487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H4U0Dwhk5-Z44Xro5jQAAAuw"]
[Tue Jul 21 07:20:17.884732 2026] [core:error] [pid 230252:tid 230376] [remote 40.77.167.49:64096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:17.884753 2026] [core:error] [pid 230252:tid 230376] [remote 40.77.167.49:64096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:17.956904 2026] [security2:error] [pid 230252:tid 230264] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9H4U0Dwhk5-Z44Xro5kQADBgo"]
[Tue Jul 21 07:20:17.957026 2026] [security2:error] [pid 230252:tid 230493] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9H4U0Dwhk5-Z44Xro5kQADBgo"]
[Tue Jul 21 07:20:18.003998 2026] [security2:error] [pid 230252:tid 230414] [client 20.197.192.193:6851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/la.php"] [unique_id "al9H4k0Dwhk5-Z44Xro5kgAAArc"]
[Tue Jul 21 07:20:18.014072 2026] [core:error] [pid 230252:tid 230275] [remote 40.77.167.49:64096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:18.014090 2026] [core:error] [pid 230252:tid 230275] [remote 40.77.167.49:64096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:18.136406 2026] [security2:error] [pid 230252:tid 230425] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782090694588.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H4k0Dwhk5-Z44Xro5lAAAAsI"]
[Tue Jul 21 07:20:18.142443 2026] [security2:error] [pid 229246:tid 229479] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091656000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H4iBMYeh5YLVG45xfAwAAAns"]
[Tue Jul 21 07:20:18.143289 2026] [security2:error] [pid 230252:tid 230434] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091746000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H4k0Dwhk5-Z44Xro5lQAAAss"]
[Tue Jul 21 07:20:18.222646 2026] [security2:error] [pid 230252:tid 230458] [client 4.204.201.85:44013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/f6.php"] [unique_id "al9H4k0Dwhk5-Z44Xro5lwAAAuM"]
[Tue Jul 21 07:20:18.319479 2026] [core:error] [pid 230252:tid 230288] [remote 40.77.167.49:64096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:18.319499 2026] [core:error] [pid 230252:tid 230288] [remote 40.77.167.49:64096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:18.458065 2026] [security2:error] [pid 229246:tid 229441] [client 136.144.42.184:36115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.42.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9H4iBMYeh5YLVG45xfBwAAAlU"]
[Tue Jul 21 07:20:18.476700 2026] [security2:error] [pid 229246:tid 229437] [client 20.151.10.161:55280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/pucci.php"] [unique_id "al9H4iBMYeh5YLVG45xfCQAAAlE"]
[Tue Jul 21 07:20:18.618030 2026] [security2:error] [pid 230252:tid 230508] [client 136.144.42.186:37295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.42.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9H4k0Dwhk5-Z44Xro5nwAAAxU"]
[Tue Jul 21 07:20:18.708149 2026] [http2:warn] [pid 229246:tid 229411] [client 57.141.18.13:24102] h2_stream(229246-116-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:18.867934 2026] [security2:error] [pid 229246:tid 229296] [remote 119.195.102.159:35976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9H4iBMYeh5YLVG45xfGAACTzE"]
[Tue Jul 21 07:20:18.979499 2026] [security2:error] [pid 229246:tid 229394] [client 4.204.201.85:44022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/inputs.php"] [unique_id "al9H4iBMYeh5YLVG45xfGwAAAiY"]
[Tue Jul 21 07:20:19.010473 2026] [security2:error] [pid 229246:tid 229422] [client 20.151.10.161:45894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/7.php"] [unique_id "al9H4yBMYeh5YLVG45xfHAAAAkI"]
[Tue Jul 21 07:20:19.069185 2026] [security2:error] [pid 230252:tid 230400] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091656000.samuelgoncalvesdesou1782090694588.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H400Dwhk5-Z44Xro5owAAAqk"]
[Tue Jul 21 07:20:19.090764 2026] [security2:error] [pid 230252:tid 230416] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091746000.samuelgoncalvesdesou1782090694588.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H400Dwhk5-Z44Xro5pAAAArk"]
[Tue Jul 21 07:20:19.119556 2026] [security2:error] [pid 229246:tid 229470] [client 20.151.10.161:55236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-temp.php"] [unique_id "al9H4yBMYeh5YLVG45xfHgAAAnI"]
[Tue Jul 21 07:20:19.402960 2026] [security2:error] [pid 229246:tid 229454] [client 20.197.192.193:6338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9H4yBMYeh5YLVG45xfJQAAAmI"]
[Tue Jul 21 07:20:19.455088 2026] [security2:error] [pid 229246:tid 229412] [client 185.251.19.66:23079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9H4iBMYeh5YLVG45xfCAAAAjg"]
[Tue Jul 21 07:20:19.464997 2026] [security2:error] [pid 230252:tid 230465] [client 4.204.201.85:43980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/inputs.php"] [unique_id "al9H400Dwhk5-Z44Xro5pQAAAuo"]
[Tue Jul 21 07:20:19.670036 2026] [security2:error] [pid 229246:tid 229398] [client 103.121.156.110:61262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9H4yBMYeh5YLVG45xfKAAAAio"]
[Tue Jul 21 07:20:19.670205 2026] [security2:error] [pid 229246:tid 229398] [client 103.121.156.110:61262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9H4yBMYeh5YLVG45xfKAAAAio"]
[Tue Jul 21 07:20:19.751810 2026] [security2:error] [pid 229246:tid 229319] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9H4yBMYeh5YLVG45xfKQACVUg"]
[Tue Jul 21 07:20:19.751990 2026] [security2:error] [pid 229246:tid 229441] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9H4yBMYeh5YLVG45xfKQACVUg"]
[Tue Jul 21 07:20:19.770121 2026] [core:error] [pid 230252:tid 230406] [client 47.252.16.44:42048] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Tue Jul 21 07:20:19.825682 2026] [security2:error] [pid 230252:tid 230481] [client 20.151.10.161:55268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9H400Dwhk5-Z44Xro5qQAAAvo"]
[Tue Jul 21 07:20:19.900867 2026] [security2:error] [pid 229246:tid 229503] [client 4.204.201.85:43982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/classwithtostring.php"] [unique_id "al9H4yBMYeh5YLVG45xfMwAAApM"]
[Tue Jul 21 07:20:20.098763 2026] [security2:error] [pid 230252:tid 230310] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091746000.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H5E0Dwhk5-Z44Xro5qgADDzg"]
[Tue Jul 21 07:20:20.169996 2026] [security2:error] [pid 229246:tid 229381] [client 103.162.129.114:59562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9H5CBMYeh5YLVG45xfNwAAAhk"]
[Tue Jul 21 07:20:20.170116 2026] [security2:error] [pid 229246:tid 229381] [client 103.162.129.114:59562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9H5CBMYeh5YLVG45xfNwAAAhk"]
[Tue Jul 21 07:20:20.198228 2026] [security2:error] [pid 229246:tid 229364] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091656000.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H5CBMYeh5YLVG45xfOgACRHU"]
[Tue Jul 21 07:20:20.199170 2026] [security2:error] [pid 229246:tid 229380] [client 114.119.157.43:64877] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "madeireirapiske.com.br"] [uri "/catalogo/p9"] [unique_id "al9H5CBMYeh5YLVG45xfOwAAAhg"], referer: https://madeireirapiske.com.br/catalogo/p9
[Tue Jul 21 07:20:20.263751 2026] [security2:error] [pid 230252:tid 230254] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782090694588.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H5E0Dwhk5-Z44Xro5qwACrQA"]
[Tue Jul 21 07:20:20.351274 2026] [http2:warn] [pid 229246:tid 229421] [client 57.141.18.111:48642] h2_stream(229246-121-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:20.351666 2026] [security2:error] [pid 229246:tid 229480] [client 20.151.10.161:53598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/puc.php"] [unique_id "al9H5CBMYeh5YLVG45xfPQAAAnw"]
[Tue Jul 21 07:20:20.506428 2026] [security2:error] [pid 230252:tid 230486] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091746000.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H5E0Dwhk5-Z44Xro5rgAAAv8"]
[Tue Jul 21 07:20:20.663803 2026] [security2:error] [pid 230252:tid 230425] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-includes/css/index.php"] [unique_id "al9H5E0Dwhk5-Z44Xro5rwAAAsI"]
[Tue Jul 21 07:20:20.672882 2026] [security2:error] [pid 229246:tid 229441] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091656000.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H5CBMYeh5YLVG45xfRwAAAlU"]
[Tue Jul 21 07:20:20.703748 2026] [security2:error] [pid 230252:tid 230434] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782090694588.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H5E0Dwhk5-Z44Xro5sAAAAss"]
[Tue Jul 21 07:20:20.841521 2026] [http2:warn] [pid 229246:tid 229383] [client 57.141.18.103:43206] h2_stream(229246-124-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:20.890349 2026] [security2:error] [pid 229246:tid 229388] [client 20.197.192.193:27135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/wpx.php"] [unique_id "al9H5CBMYeh5YLVG45xfSQAAAiA"]
[Tue Jul 21 07:20:20.918494 2026] [security2:error] [pid 229246:tid 229392] [client 193.36.225.65:28591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9H5CBMYeh5YLVG45xfSgAAAiQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:20.943972 2026] [security2:error] [pid 229246:tid 229415] [client 4.204.201.85:43913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9H5CBMYeh5YLVG45xfTQAAAjs"]
[Tue Jul 21 07:20:20.950441 2026] [security2:error] [pid 229246:tid 229496] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/jj.php"] [unique_id "al9H5CBMYeh5YLVG45xfTwAAAow"]
[Tue Jul 21 07:20:21.125195 2026] [security2:error] [pid 229246:tid 229411] [client 20.197.192.193:6896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/inso.php"] [unique_id "al9H5SBMYeh5YLVG45xfUQAAAjc"]
[Tue Jul 21 07:20:21.264050 2026] [security2:error] [pid 230252:tid 230389] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/class-walker-footer-dev.php"] [unique_id "al9H5U0Dwhk5-Z44Xro5twAAAp4"]
[Tue Jul 21 07:20:21.324463 2026] [security2:error] [pid 229246:tid 229365] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9H5SBMYeh5YLVG45xfWQACWnY"]
[Tue Jul 21 07:20:21.324506 2026] [security2:error] [pid 230252:tid 230508] [client 35.219.104.147:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "al9H5U0Dwhk5-Z44Xro5uQAAAxU"]
[Tue Jul 21 07:20:21.324616 2026] [security2:error] [pid 229246:tid 229446] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9H5SBMYeh5YLVG45xfWQACWnY"]
[Tue Jul 21 07:20:21.335202 2026] [security2:error] [pid 229246:tid 229426] [client 35.219.104.147:45330] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/"] [unique_id "al9H5SBMYeh5YLVG45xfVgAAAkY"]
[Tue Jul 21 07:20:21.523557 2026] [security2:error] [pid 229246:tid 229414] [client 4.204.201.85:43988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/wp-blog.php"] [unique_id "al9H5SBMYeh5YLVG45xfYQAAAjo"]
[Tue Jul 21 07:20:21.569877 2026] [security2:error] [pid 230252:tid 230466] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/txets.php"] [unique_id "al9H5U0Dwhk5-Z44Xro5vwAAAus"]
[Tue Jul 21 07:20:21.638342 2026] [security2:error] [pid 230252:tid 230497] [client 20.151.10.161:12081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/themes.php"] [unique_id "al9H5U0Dwhk5-Z44Xro5wQAAAwo"]
[Tue Jul 21 07:20:21.688792 2026] [security2:error] [pid 230252:tid 230406] [client 35.219.104.147:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "al9H5U0Dwhk5-Z44Xro5xAAAAq8"]
[Tue Jul 21 07:20:21.689282 2026] [security2:error] [pid 230252:tid 230451] [client 35.219.104.147:45334] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/"] [unique_id "al9H5U0Dwhk5-Z44Xro5wgAAAtw"]
[Tue Jul 21 07:20:21.717591 2026] [security2:error] [pid 230252:tid 230454] [client 14.139.42.196:22082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H5U0Dwhk5-Z44Xro5xQAAAt8"]
[Tue Jul 21 07:20:21.717685 2026] [security2:error] [pid 230252:tid 230454] [client 14.139.42.196:22082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H5U0Dwhk5-Z44Xro5xQAAAt8"]
[Tue Jul 21 07:20:21.851967 2026] [security2:error] [pid 229246:tid 229432] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/dex.php"] [unique_id "al9H5SBMYeh5YLVG45xfZAAAAkw"]
[Tue Jul 21 07:20:21.950899 2026] [security2:error] [pid 229246:tid 229410] [client 20.197.192.193:6392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/wpx.php"] [unique_id "al9H5SBMYeh5YLVG45xfZQAAAjY"]
[Tue Jul 21 07:20:22.133659 2026] [security2:error] [pid 230252:tid 230428] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/xpwer1.php"] [unique_id "al9H5k0Dwhk5-Z44Xro5yQAAAsU"]
[Tue Jul 21 07:20:22.275266 2026] [security2:error] [pid 230252:tid 230510] [client 20.151.10.161:45892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/8.php"] [unique_id "al9H5k0Dwhk5-Z44Xro5ywAAAxc"]
[Tue Jul 21 07:20:22.429200 2026] [security2:error] [pid 229246:tid 229405] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/flox.php"] [unique_id "al9H5iBMYeh5YLVG45xfbAAAAjE"]
[Tue Jul 21 07:20:22.433820 2026] [http2:warn] [pid 229246:tid 229455] [client 57.141.18.87:45288] h2_stream(229246-131-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:22.720050 2026] [security2:error] [pid 230252:tid 230395] [client 20.220.225.223:59511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9H5k0Dwhk5-Z44Xro5zwAAAqQ"]
[Tue Jul 21 07:20:22.720933 2026] [security2:error] [pid 229246:tid 229477] [client 4.204.201.85:43987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9H5iBMYeh5YLVG45xfcgAAAnk"]
[Tue Jul 21 07:20:22.721659 2026] [security2:error] [pid 230252:tid 230486] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/popo.php"] [unique_id "al9H5k0Dwhk5-Z44Xro50AAAAv8"]
[Tue Jul 21 07:20:22.928074 2026] [http2:warn] [pid 229246:tid 229449] [client 57.141.18.13:21514] h2_stream(229246-132-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:23.035712 2026] [security2:error] [pid 230252:tid 230401] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/yas.php"] [unique_id "al9H500Dwhk5-Z44Xro50gAAAqo"]
[Tue Jul 21 07:20:23.056944 2026] [security2:error] [pid 230252:tid 230440] [client 20.151.10.161:55238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/dx.php"] [unique_id "al9H500Dwhk5-Z44Xro50wAAAtE"]
[Tue Jul 21 07:20:23.060547 2026] [security2:error] [pid 229246:tid 229388] [client 45.251.232.145:62173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H5yBMYeh5YLVG45xfdQAAAiA"]
[Tue Jul 21 07:20:23.060660 2026] [security2:error] [pid 229246:tid 229388] [client 45.251.232.145:62173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H5yBMYeh5YLVG45xfdQAAAiA"]
[Tue Jul 21 07:20:23.268615 2026] [http2:warn] [pid 229246:tid 229456] [client 57.141.18.96:32164] h2_stream(229246-134-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:23.318165 2026] [security2:error] [pid 230252:tid 230407] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/file61.php"] [unique_id "al9H500Dwhk5-Z44Xro51gAAArA"]
[Tue Jul 21 07:20:23.331240 2026] [security2:error] [pid 230252:tid 230508] [client 4.204.201.85:43845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/ms-edit.php"] [unique_id "al9H500Dwhk5-Z44Xro51wAAAxU"]
[Tue Jul 21 07:20:23.336059 2026] [security2:error] [pid 230252:tid 230500] [client 20.197.192.193:27097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/berlin.php"] [unique_id "al9H500Dwhk5-Z44Xro52AAAAw0"]
[Tue Jul 21 07:20:23.408475 2026] [security2:error] [pid 229246:tid 229381] [client 20.197.192.193:6395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/berlin.php"] [unique_id "al9H5yBMYeh5YLVG45xfeQAAAhk"]
[Tue Jul 21 07:20:23.470524 2026] [security2:error] [pid 230252:tid 230255] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9H500Dwhk5-Z44Xro53AACsgE"]
[Tue Jul 21 07:20:23.470648 2026] [security2:error] [pid 230252:tid 230409] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9H500Dwhk5-Z44Xro53AACsgE"]
[Tue Jul 21 07:20:23.591965 2026] [security2:error] [pid 230252:tid 230497] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/water.php"] [unique_id "al9H500Dwhk5-Z44Xro53QAAAwo"]
[Tue Jul 21 07:20:23.610982 2026] [security2:error] [pid 230252:tid 230437] [client 20.151.10.161:55269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/p.php"] [unique_id "al9H500Dwhk5-Z44Xro54AAAAs4"]
[Tue Jul 21 07:20:23.673508 2026] [security2:error] [pid 230252:tid 230451] [client 4.204.201.85:43916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9H500Dwhk5-Z44Xro54QAAAtw"]
[Tue Jul 21 07:20:23.891516 2026] [security2:error] [pid 230252:tid 230461] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/nano.php"] [unique_id "al9H500Dwhk5-Z44Xro55QAAAuY"]
[Tue Jul 21 07:20:23.970541 2026] [security2:error] [pid 230252:tid 230430] [client 20.220.225.223:34298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/dp.php"] [unique_id "al9H500Dwhk5-Z44Xro55gAAAsc"]
[Tue Jul 21 07:20:24.184205 2026] [security2:error] [pid 230252:tid 230422] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/moon.php"] [unique_id "al9H6E0Dwhk5-Z44Xro56gAAAr8"]
[Tue Jul 21 07:20:24.329767 2026] [security2:error] [pid 229246:tid 229424] [client 114.119.144.38:45201] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.tempex.com.br"] [uri "/category/dicas"] [unique_id "al9H6CBMYeh5YLVG45xfhAAAAkQ"], referer: https://www.tempex.com.br/blog
[Tue Jul 21 07:20:24.371236 2026] [security2:error] [pid 230252:tid 230434] [client 184.75.221.3:56966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9H6E0Dwhk5-Z44Xro57AAAAss"]
[Tue Jul 21 07:20:24.371364 2026] [security2:error] [pid 230252:tid 230434] [client 184.75.221.3:56966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9H6E0Dwhk5-Z44Xro57AAAAss"]
[Tue Jul 21 07:20:24.452199 2026] [security2:error] [pid 230252:tid 230464] [client 4.204.201.85:44012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9H6E0Dwhk5-Z44Xro58AAAAuk"]
[Tue Jul 21 07:20:24.465912 2026] [security2:error] [pid 230252:tid 230504] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-info.php"] [unique_id "al9H6E0Dwhk5-Z44Xro58QAAAxE"]
[Tue Jul 21 07:20:24.686688 2026] [security2:error] [pid 230252:tid 230458] [client 173.252.95.13:52814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9H6E0Dwhk5-Z44Xro58gAAAuM"]
[Tue Jul 21 07:20:24.751645 2026] [http2:warn] [pid 229246:tid 229500] [client 57.141.18.17:25310] h2_stream(229246-147-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:24.754224 2026] [security2:error] [pid 230252:tid 230384] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/2000.php"] [unique_id "al9H6E0Dwhk5-Z44Xro59gAAApk"]
[Tue Jul 21 07:20:24.989620 2026] [security2:error] [pid 230252:tid 230400] [client 20.151.10.161:55270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/bthil.php"] [unique_id "al9H6E0Dwhk5-Z44Xro5-QAAAqk"]
[Tue Jul 21 07:20:25.049039 2026] [security2:error] [pid 229246:tid 229431] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/122.php"] [unique_id "al9H6SBMYeh5YLVG45xfigAAAks"]
[Tue Jul 21 07:20:25.072564 2026] [security2:error] [pid 230252:tid 230466] [client 20.151.10.161:45997] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "prospecta.agendaclique.com.br"] [uri "/1.php"] [unique_id "al9H6U0Dwhk5-Z44Xro5_AAAAus"]
[Tue Jul 21 07:20:25.072677 2026] [security2:error] [pid 230252:tid 230466] [client 20.151.10.161:45997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/1.php"] [unique_id "al9H6U0Dwhk5-Z44Xro5_AAAAus"]
[Tue Jul 21 07:20:25.329267 2026] [security2:error] [pid 229246:tid 229407] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/mds.php"] [unique_id "al9H6SBMYeh5YLVG45xfkAAAAjM"]
[Tue Jul 21 07:20:25.381591 2026] [security2:error] [pid 229246:tid 229455] [client 68.235.38.2:56568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9H6SBMYeh5YLVG45xfkgAAAmM"]
[Tue Jul 21 07:20:25.381671 2026] [security2:error] [pid 229246:tid 229455] [client 68.235.38.2:56568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9H6SBMYeh5YLVG45xfkgAAAmM"]
[Tue Jul 21 07:20:25.405827 2026] [security2:error] [pid 230252:tid 230451] [client 20.197.192.193:6346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/billur.php"] [unique_id "al9H6U0Dwhk5-Z44Xro6BAAAAtw"]
[Tue Jul 21 07:20:25.448391 2026] [security2:error] [pid 230252:tid 230462] [client 4.204.201.85:43928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/abcd.php"] [unique_id "al9H6U0Dwhk5-Z44Xro6BgAAAuc"]
[Tue Jul 21 07:20:25.494129 2026] [security2:error] [pid 229246:tid 229289] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9H6SBMYeh5YLVG45xflAACZyo"]
[Tue Jul 21 07:20:25.494289 2026] [security2:error] [pid 229246:tid 229459] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9H6SBMYeh5YLVG45xflAACZyo"]
[Tue Jul 21 07:20:25.515718 2026] [security2:error] [pid 230252:tid 230452] [client 193.36.225.64:61645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9H6U0Dwhk5-Z44Xro6BwAAAt0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:25.612050 2026] [security2:error] [pid 230252:tid 230430] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-blink.php"] [unique_id "al9H6U0Dwhk5-Z44Xro6CAAAAsc"]
[Tue Jul 21 07:20:25.622801 2026] [core:error] [pid 229246:tid 229267] [remote 40.77.167.14:50307] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:25.622839 2026] [core:error] [pid 229246:tid 229267] [remote 40.77.167.14:50307] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:25.726592 2026] [security2:error] [pid 230252:tid 230493] [client 20.226.60.151:54495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9H6U0Dwhk5-Z44Xro6DAAAAwY"]
[Tue Jul 21 07:20:25.750589 2026] [core:error] [pid 229246:tid 229334] [remote 40.77.167.14:50307] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:25.750608 2026] [core:error] [pid 229246:tid 229334] [remote 40.77.167.14:50307] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:25.836708 2026] [security2:error] [pid 230252:tid 230289] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelsilva1755793355195.0711679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H6U0Dwhk5-Z44Xro6DgAC0yM"]
[Tue Jul 21 07:20:25.877268 2026] [core:error] [pid 229246:tid 229358] [remote 40.77.167.14:50307] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:25.877287 2026] [core:error] [pid 229246:tid 229358] [remote 40.77.167.14:50307] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:25.895487 2026] [security2:error] [pid 230252:tid 230425] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/zc-208.php"] [unique_id "al9H6U0Dwhk5-Z44Xro6DwAAAsI"]
[Tue Jul 21 07:20:25.962921 2026] [http2:warn] [pid 229246:tid 229492] [client 57.141.18.16:35796] h2_stream(229246-154-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:26.054996 2026] [security2:error] [pid 229246:tid 229446] [client 4.204.201.85:43859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/file15.php"] [unique_id "al9H6iBMYeh5YLVG45xfmwAAAlo"]
[Tue Jul 21 07:20:26.136421 2026] [security2:error] [pid 229246:tid 229470] [client 20.197.192.193:6371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/mimpi.php"] [unique_id "al9H6iBMYeh5YLVG45xfnAAAAnI"]
[Tue Jul 21 07:20:26.192024 2026] [security2:error] [pid 229246:tid 229424] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/sid4.php"] [unique_id "al9H6iBMYeh5YLVG45xfngAAAkQ"]
[Tue Jul 21 07:20:26.262929 2026] [security2:error] [pid 230252:tid 230404] [client 139.135.44.145:53940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9H6k0Dwhk5-Z44Xro6FgAAAq0"]
[Tue Jul 21 07:20:26.263029 2026] [security2:error] [pid 230252:tid 230404] [client 139.135.44.145:53940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9H6k0Dwhk5-Z44Xro6FgAAAq0"]
[Tue Jul 21 07:20:26.407620 2026] [security2:error] [pid 229246:tid 229404] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelsilva1755793355195.0711679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H6iBMYeh5YLVG45xfowAAAjA"]
[Tue Jul 21 07:20:26.417212 2026] [security2:error] [pid 229246:tid 229296] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H6iBMYeh5YLVG45xfpAACjTE"]
[Tue Jul 21 07:20:26.417389 2026] [security2:error] [pid 229246:tid 229497] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H6iBMYeh5YLVG45xfpAACjTE"]
[Tue Jul 21 07:20:26.436699 2026] [security2:error] [pid 229246:tid 229478] [client 74.249.245.134:48075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/ws83.php"] [unique_id "al9H6iBMYeh5YLVG45xfpQAAAno"]
[Tue Jul 21 07:20:26.664740 2026] [security2:error] [pid 229246:tid 229276] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H6iBMYeh5YLVG45xfqAACVR0"]
[Tue Jul 21 07:20:26.664912 2026] [security2:error] [pid 229246:tid 229441] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H6iBMYeh5YLVG45xfqAACVR0"]
[Tue Jul 21 07:20:26.678745 2026] [security2:error] [pid 229246:tid 229491] [client 20.197.192.193:6382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/dp.php"] [unique_id "al9H6iBMYeh5YLVG45xfqQAAAoc"]
[Tue Jul 21 07:20:26.751205 2026] [security2:error] [pid 230252:tid 230401] [client 175.45.70.82:49887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H6k0Dwhk5-Z44Xro6GgAAAqo"]
[Tue Jul 21 07:20:26.751329 2026] [security2:error] [pid 230252:tid 230401] [client 175.45.70.82:49887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H6k0Dwhk5-Z44Xro6GgAAAqo"]
[Tue Jul 21 07:20:26.830258 2026] [security2:error] [pid 229246:tid 229428] [client 74.244.195.153:59523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.195.244.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9H6iBMYeh5YLVG45xfrAAAAkg"]
[Tue Jul 21 07:20:26.840591 2026] [security2:error] [pid 229246:tid 229428] [client 74.244.195.153:59523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9H6iBMYeh5YLVG45xfrAAAAkg"]
[Tue Jul 21 07:20:26.974106 2026] [http2:warn] [pid 229246:tid 229413] [client 57.141.18.32:36788] h2_stream(229246-158-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:26.989945 2026] [security2:error] [pid 229246:tid 229462] [client 20.151.10.161:53586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/7.php"] [unique_id "al9H6iBMYeh5YLVG45xfrQAAAmo"]
[Tue Jul 21 07:20:27.057625 2026] [http2:warn] [pid 229246:tid 229379] [client 57.141.18.79:38222] h2_stream(229246-160-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:27.059490 2026] [security2:error] [pid 229246:tid 229479] [client 20.151.10.161:45956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/100.php"] [unique_id "al9H6yBMYeh5YLVG45xfrgAAAns"]
[Tue Jul 21 07:20:27.297376 2026] [security2:error] [pid 230252:tid 230510] [client 20.197.192.193:6391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/bootstrap.php"] [unique_id "al9H600Dwhk5-Z44Xro6JQAAAxc"]
[Tue Jul 21 07:20:27.355676 2026] [security2:error] [pid 230252:tid 230494] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wmore1.php"] [unique_id "al9H600Dwhk5-Z44Xro6JwAAAwc"]
[Tue Jul 21 07:20:27.413925 2026] [security2:error] [pid 230252:tid 230473] [client 120.61.173.56:54618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H600Dwhk5-Z44Xro6KAAAAvI"]
[Tue Jul 21 07:20:27.414097 2026] [security2:error] [pid 230252:tid 230473] [client 120.61.173.56:54618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H600Dwhk5-Z44Xro6KAAAAvI"]
[Tue Jul 21 07:20:27.625104 2026] [security2:error] [pid 229246:tid 229380] [client 20.220.225.223:36840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/dp.php"] [unique_id "al9H6yBMYeh5YLVG45xftQAAAhg"]
[Tue Jul 21 07:20:27.637757 2026] [security2:error] [pid 230252:tid 230442] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/solo1.php"] [unique_id "al9H600Dwhk5-Z44Xro6KQAAAtM"]
[Tue Jul 21 07:20:27.694794 2026] [security2:error] [pid 230252:tid 230412] [client 74.249.245.134:44585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/CDX1.php"] [unique_id "al9H600Dwhk5-Z44Xro6KgAAArU"]
[Tue Jul 21 07:20:27.700032 2026] [security2:error] [pid 230252:tid 230491] [client 4.204.201.85:43963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/jp.php"] [unique_id "al9H600Dwhk5-Z44Xro6KwAAAwQ"]
[Tue Jul 21 07:20:27.856506 2026] [security2:error] [pid 230252:tid 230428] [client 173.252.95.18:57226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9H6U0Dwhk5-Z44Xro6CgAAAsU"]
[Tue Jul 21 07:20:28.198684 2026] [security2:error] [pid 230252:tid 230401] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/cong.php"] [unique_id "al9H7E0Dwhk5-Z44Xro6NAAAAqo"]
[Tue Jul 21 07:20:28.201652 2026] [security2:error] [pid 229246:tid 229364] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelsilva1755793355195.0711679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H7CBMYeh5YLVG45xfvwACYnU"]
[Tue Jul 21 07:20:28.416156 2026] [http2:warn] [pid 229246:tid 229458] [client 57.141.18.35:61098] h2_stream(229246-166-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:28.562624 2026] [security2:error] [pid 230252:tid 230464] [client 173.252.95.17:44336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9H7E0Dwhk5-Z44Xro6OwAAAuk"]
[Tue Jul 21 07:20:28.646093 2026] [security2:error] [pid 229246:tid 229478] [client 20.151.10.161:12047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/8.php"] [unique_id "al9H7CBMYeh5YLVG45xfwwAAAno"]
[Tue Jul 21 07:20:28.694281 2026] [security2:error] [pid 230252:tid 230335] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9H7E0Dwhk5-Z44Xro6PgACxlA"]
[Tue Jul 21 07:20:28.694468 2026] [security2:error] [pid 230252:tid 230429] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9H7E0Dwhk5-Z44Xro6PgACxlA"]
[Tue Jul 21 07:20:28.767205 2026] [security2:error] [pid 230252:tid 230462] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/public/css.php"] [unique_id "al9H7E0Dwhk5-Z44Xro6PwAAAuc"]
[Tue Jul 21 07:20:28.773235 2026] [security2:error] [pid 230252:tid 230406] [client 20.151.10.161:46058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/about.php"] [unique_id "al9H7E0Dwhk5-Z44Xro6QAAAAq8"]
[Tue Jul 21 07:20:28.914598 2026] [security2:error] [pid 230252:tid 230461] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelsilva1755793355195.0711679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H7E0Dwhk5-Z44Xro6QQAAAuY"]
[Tue Jul 21 07:20:29.051314 2026] [security2:error] [pid 229246:tid 229496] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/output.php"] [unique_id "al9H7SBMYeh5YLVG45xfyQAAAow"]
[Tue Jul 21 07:20:29.223032 2026] [http2:warn] [pid 229246:tid 229493] [client 57.141.18.120:26156] h2_stream(229246-168-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:29.327574 2026] [security2:error] [pid 230252:tid 230502] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-file-120.php"] [unique_id "al9H7U0Dwhk5-Z44Xro6QgAAAw8"]
[Tue Jul 21 07:20:29.331682 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:12069] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.jandel.com.br"] [uri "/1.php"] [unique_id "al9H7U0Dwhk5-Z44Xro6QwAAAwY"]
[Tue Jul 21 07:20:29.331772 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:12069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/1.php"] [unique_id "al9H7U0Dwhk5-Z44Xro6QwAAAwY"]
[Tue Jul 21 07:20:29.386803 2026] [security2:error] [pid 230252:tid 230511] [client 4.204.201.85:43992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/f35.php"] [unique_id "al9H7U0Dwhk5-Z44Xro6RAAAAxg"]
[Tue Jul 21 07:20:29.463151 2026] [security2:error] [pid 230252:tid 230486] [client 92.119.178.3:44230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9H7U0Dwhk5-Z44Xro6RwAAAv8"]
[Tue Jul 21 07:20:29.463234 2026] [security2:error] [pid 230252:tid 230486] [client 92.119.178.3:44230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9H7U0Dwhk5-Z44Xro6RwAAAv8"]
[Tue Jul 21 07:20:29.532226 2026] [http2:warn] [pid 229246:tid 229450] [client 57.141.18.71:28578] h2_stream(229246-169-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:29.616801 2026] [security2:error] [pid 230252:tid 230440] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/special.php"] [unique_id "al9H7U0Dwhk5-Z44Xro6TAAAAtE"]
[Tue Jul 21 07:20:29.734717 2026] [core:error] [pid 229246:tid 229362] [remote 40.77.167.49:64068] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:29.734744 2026] [core:error] [pid 229246:tid 229362] [remote 40.77.167.49:64068] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:29.932552 2026] [http2:warn] [pid 230252:tid 230496] [client 45.80.104.96:51773] h2_stream(230252-4-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:30.003752 2026] [security2:error] [pid 230252:tid 230389] [client 184.75.221.3:53916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6UQAAAp4"]
[Tue Jul 21 07:20:30.003858 2026] [security2:error] [pid 230252:tid 230389] [client 184.75.221.3:53916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6UQAAAp4"]
[Tue Jul 21 07:20:30.007375 2026] [security2:error] [pid 230252:tid 230495] [client 20.151.10.161:55273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/100.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6UgAAAwg"]
[Tue Jul 21 07:20:30.143188 2026] [security2:error] [pid 230252:tid 230387] [client 4.204.201.85:43956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/wp-load.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6VAAAApw"]
[Tue Jul 21 07:20:30.163144 2026] [security2:error] [pid 229246:tid 229498] [client 20.197.192.193:6902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/wp-editor.php"] [unique_id "al9H7iBMYeh5YLVG45xf1AAAAo4"]
[Tue Jul 21 07:20:30.298423 2026] [security2:error] [pid 230252:tid 230470] [client 103.162.129.114:60007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6WQAAAu8"]
[Tue Jul 21 07:20:30.298559 2026] [security2:error] [pid 230252:tid 230470] [client 103.162.129.114:60007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6WQAAAu8"]
[Tue Jul 21 07:20:30.340724 2026] [security2:error] [pid 230252:tid 230498] [client 103.121.156.110:61585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6WgAAAws"]
[Tue Jul 21 07:20:30.340890 2026] [security2:error] [pid 230252:tid 230498] [client 103.121.156.110:61585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6WgAAAws"]
[Tue Jul 21 07:20:30.414257 2026] [security2:error] [pid 229246:tid 229302] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9H7iBMYeh5YLVG45xf2AACGTc"]
[Tue Jul 21 07:20:30.414395 2026] [security2:error] [pid 229246:tid 229381] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9H7iBMYeh5YLVG45xf2AACGTc"]
[Tue Jul 21 07:20:30.468213 2026] [security2:error] [pid 230252:tid 230445] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/as.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6XAAAAtY"]
[Tue Jul 21 07:20:30.749514 2026] [security2:error] [pid 230252:tid 230451] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/cgi-bin/index.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6XwAAAtw"]
[Tue Jul 21 07:20:30.767457 2026] [security2:error] [pid 230252:tid 230429] [client 20.151.10.161:55235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/about.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6YAAAAsY"]
[Tue Jul 21 07:20:30.889772 2026] [security2:error] [pid 230252:tid 230424] [client 92.119.178.3:44238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6YQAAAsE"]
[Tue Jul 21 07:20:30.889898 2026] [security2:error] [pid 230252:tid 230424] [client 92.119.178.3:44238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6YQAAAsE"]
[Tue Jul 21 07:20:30.945280 2026] [http2:warn] [pid 229246:tid 229460] [client 57.141.18.95:49382] h2_stream(229246-175-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:31.051393 2026] [security2:error] [pid 230252:tid 230447] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/w1px.php"] [unique_id "al9H700Dwhk5-Z44Xro6YwAAAtg"]
[Tue Jul 21 07:20:31.162466 2026] [security2:error] [pid 230252:tid 230476] [client 37.140.223.69:35105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9H7U0Dwhk5-Z44Xro6UAAAAvU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:31.202155 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:53589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/admin.php"] [unique_id "al9H700Dwhk5-Z44Xro6ZgAAAwY"]
[Tue Jul 21 07:20:31.325318 2026] [security2:error] [pid 230252:tid 230494] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/yawa.php"] [unique_id "al9H700Dwhk5-Z44Xro6aAAAAwc"]
[Tue Jul 21 07:20:31.489608 2026] [security2:error] [pid 230252:tid 230434] [client 20.104.96.117:59160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9H700Dwhk5-Z44Xro6aQAAAss"]
[Tue Jul 21 07:20:31.535388 2026] [security2:error] [pid 229246:tid 229478] [client 4.204.201.85:43934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/xyn.php"] [unique_id "al9H7yBMYeh5YLVG45xf6AAAAno"]
[Tue Jul 21 07:20:31.572658 2026] [security2:error] [pid 229246:tid 229473] [client 20.151.10.161:46043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/admin.php"] [unique_id "al9H7yBMYeh5YLVG45xf6QAAAnU"]
[Tue Jul 21 07:20:31.614471 2026] [security2:error] [pid 229246:tid 229392] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/js.php"] [unique_id "al9H7yBMYeh5YLVG45xf6gAAAiQ"]
[Tue Jul 21 07:20:31.858773 2026] [security2:error] [pid 230252:tid 230428] [client 20.151.10.161:55242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/edit.php"] [unique_id "al9H700Dwhk5-Z44Xro6bgAAAsU"]
[Tue Jul 21 07:20:31.932552 2026] [security2:error] [pid 230252:tid 230389] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/core.php"] [unique_id "al9H700Dwhk5-Z44Xro6bwAAAp4"]
[Tue Jul 21 07:20:31.954737 2026] [security2:error] [pid 229246:tid 229273] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9H7yBMYeh5YLVG45xf7QACjBo"]
[Tue Jul 21 07:20:31.954865 2026] [security2:error] [pid 229246:tid 229496] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9H7yBMYeh5YLVG45xf7QACjBo"]
[Tue Jul 21 07:20:31.991752 2026] [http2:warn] [pid 229246:tid 229487] [client 57.141.18.121:26834] h2_stream(229246-182-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:32.116167 2026] [security2:error] [pid 229246:tid 229388] [client 107.189.6.149:57908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "contafic.com.br"] [uri "/"] [unique_id "al9H8CBMYeh5YLVG45xf7wAAAiA"]
[Tue Jul 21 07:20:32.210914 2026] [security2:error] [pid 230252:tid 230487] [client 20.226.60.151:61072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/qqqa.php"] [unique_id "al9H8E0Dwhk5-Z44Xro6dgAAAwA"]
[Tue Jul 21 07:20:32.234072 2026] [security2:error] [pid 230252:tid 230498] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/19.php"] [unique_id "al9H8E0Dwhk5-Z44Xro6dwAAAws"]
[Tue Jul 21 07:20:32.291457 2026] [security2:error] [pid 230252:tid 230445] [client 20.151.10.161:53594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9H8E0Dwhk5-Z44Xro6eQAAAtY"]
[Tue Jul 21 07:20:32.309315 2026] [security2:error] [pid 230252:tid 230472] [client 107.189.6.149:57907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "contafic.com.br"] [uri "/"] [unique_id "al9H8E0Dwhk5-Z44Xro6egAAAvE"]
[Tue Jul 21 07:20:32.344037 2026] [security2:error] [pid 230252:tid 230407] [client 14.139.42.196:12847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H8E0Dwhk5-Z44Xro6ewAAArA"]
[Tue Jul 21 07:20:32.344171 2026] [security2:error] [pid 230252:tid 230407] [client 14.139.42.196:12847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H8E0Dwhk5-Z44Xro6ewAAArA"]
[Tue Jul 21 07:20:32.452337 2026] [security2:error] [pid 230252:tid 230419] [client 20.104.96.117:59710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9H8E0Dwhk5-Z44Xro6fQAAArw"]
[Tue Jul 21 07:20:32.515151 2026] [security2:error] [pid 229246:tid 229398] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/inc.php"] [unique_id "al9H8CBMYeh5YLVG45xf8gAAAio"]
[Tue Jul 21 07:20:32.516750 2026] [security2:error] [pid 230252:tid 230409] [client 107.189.6.149:57957] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "contafic.com.br"] [uri "/"] [unique_id "al9H8E0Dwhk5-Z44Xro6fgAAArI"]
[Tue Jul 21 07:20:32.639083 2026] [security2:error] [pid 229246:tid 229438] [client 20.151.10.161:12077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/f6.php"] [unique_id "al9H8CBMYeh5YLVG45xf9QAAAlI"]
[Tue Jul 21 07:20:32.755714 2026] [security2:error] [pid 229246:tid 229471] [client 20.151.10.161:45909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/edit.php"] [unique_id "al9H8CBMYeh5YLVG45xf9gAAAnM"]
[Tue Jul 21 07:20:32.796484 2026] [security2:error] [pid 230252:tid 230452] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-ppoxua4.php"] [unique_id "al9H8E0Dwhk5-Z44Xro6gAAAAt0"]
[Tue Jul 21 07:20:32.867733 2026] [security2:error] [pid 230252:tid 230390] [client 114.119.135.35:40111] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "startonesite.com.br"] [uri "/9618ejodhl3-ffcbo1018686"] [unique_id "al9H8E0Dwhk5-Z44Xro6gQAAAp8"], referer: https://startonesite.com.br/9618ejodhl3-ffcbo1018686
[Tue Jul 21 07:20:32.905690 2026] [security2:error] [pid 229246:tid 229498] [client 107.189.6.149:57979] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "contafic.com.br"] [uri "/"] [unique_id "al9H8CBMYeh5YLVG45xf-QAAAo4"]
[Tue Jul 21 07:20:33.172792 2026] [http2:warn] [pid 229246:tid 229384] [client 57.141.18.24:56438] h2_stream(229246-188-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:33.185718 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:45985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9H8SBMYeh5YLVG45xf_AAAAlo"]
[Tue Jul 21 07:20:33.250398 2026] [security2:error] [pid 230252:tid 230423] [client 20.151.10.161:12041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/inputs.php"] [unique_id "al9H8U0Dwhk5-Z44Xro6hQAAAsA"]
[Tue Jul 21 07:20:33.363349 2026] [security2:error] [pid 230252:tid 230430] [client 20.104.96.117:59194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/xyn.php"] [unique_id "al9H8U0Dwhk5-Z44Xro6hwAAAsc"]
[Tue Jul 21 07:20:33.515252 2026] [security2:error] [pid 229246:tid 229495] [client 45.251.232.145:62693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H8SBMYeh5YLVG45xf_wAAAos"]
[Tue Jul 21 07:20:33.515411 2026] [security2:error] [pid 229246:tid 229495] [client 45.251.232.145:62693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H8SBMYeh5YLVG45xf_wAAAos"]
[Tue Jul 21 07:20:33.627474 2026] [http2:warn] [pid 229246:tid 229436] [client 57.141.18.107:52722] h2_stream(229246-193-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:33.639049 2026] [security2:error] [pid 229246:tid 229479] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-u3nxbvx.php"] [unique_id "al9H8SBMYeh5YLVG45xgAgAAAns"]
[Tue Jul 21 07:20:33.834581 2026] [security2:error] [pid 230252:tid 230427] [client 4.204.201.85:43927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/ccc.php"] [unique_id "al9H8U0Dwhk5-Z44Xro6jAAAAsQ"]
[Tue Jul 21 07:20:33.879916 2026] [security2:error] [pid 229246:tid 229466] [client 20.151.10.161:12032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/av.php"] [unique_id "al9H8SBMYeh5YLVG45xgBAAAAm4"]
[Tue Jul 21 07:20:33.946964 2026] [security2:error] [pid 229246:tid 229403] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/ss.php"] [unique_id "al9H8SBMYeh5YLVG45xgBwAAAi8"]
[Tue Jul 21 07:20:33.964962 2026] [security2:error] [pid 229246:tid 229299] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9H8SBMYeh5YLVG45xgCAACXjQ"]
[Tue Jul 21 07:20:33.965100 2026] [security2:error] [pid 229246:tid 229450] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9H8SBMYeh5YLVG45xgCAACXjQ"]
[Tue Jul 21 07:20:34.231550 2026] [security2:error] [pid 229246:tid 229473] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/min.php"] [unique_id "al9H8iBMYeh5YLVG45xgDwAAAnU"]
[Tue Jul 21 07:20:34.233563 2026] [security2:error] [pid 229246:tid 229460] [client 20.151.10.161:45977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/f6.php"] [unique_id "al9H8iBMYeh5YLVG45xgEAAAAmg"]
[Tue Jul 21 07:20:34.282746 2026] [security2:error] [pid 229246:tid 229421] [client 4.204.201.85:43936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/w.php"] [unique_id "al9H8iBMYeh5YLVG45xgEQAAAkE"]
[Tue Jul 21 07:20:34.513164 2026] [security2:error] [pid 229246:tid 229444] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9H8iBMYeh5YLVG45xgEwAAAlg"]
[Tue Jul 21 07:20:34.542097 2026] [security2:error] [pid 230252:tid 230487] [client 20.220.225.223:39535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/aa1.php"] [unique_id "al9H8k0Dwhk5-Z44Xro6kwAAAwA"]
[Tue Jul 21 07:20:34.737566 2026] [security2:error] [pid 230252:tid 230465] [client 4.204.201.85:43919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9H8k0Dwhk5-Z44Xro6swAAAuo"]
[Tue Jul 21 07:20:34.799953 2026] [security2:error] [pid 230252:tid 230481] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/autoload_classmap.php"] [unique_id "al9H8k0Dwhk5-Z44Xro6tAAAAvo"]
[Tue Jul 21 07:20:34.830488 2026] [http2:warn] [pid 229246:tid 229452] [client 57.141.18.89:25240] h2_stream(229246-196-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:34.903623 2026] [http2:warn] [pid 229246:tid 229474] [client 57.141.18.82:49256] h2_stream(229246-199-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:34.928640 2026] [security2:error] [pid 230252:tid 230458] [client 20.151.10.161:46019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/inputs.php"] [unique_id "al9H8k0Dwhk5-Z44Xro6tQAAAuM"]
[Tue Jul 21 07:20:34.940249 2026] [security2:error] [pid 230252:tid 230409] [client 20.197.192.193:6877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/cro.php"] [unique_id "al9H8k0Dwhk5-Z44Xro6tgAAArI"]
[Tue Jul 21 07:20:34.968409 2026] [security2:error] [pid 229246:tid 229388] [client 20.151.10.161:55232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/classwithtostring.php"] [unique_id "al9H8iBMYeh5YLVG45xgGAAAAiA"]
[Tue Jul 21 07:20:35.080557 2026] [security2:error] [pid 230252:tid 230452] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-link-zorm.php"] [unique_id "al9H800Dwhk5-Z44Xro6ugAAAt0"]
[Tue Jul 21 07:20:35.181729 2026] [security2:error] [pid 229246:tid 229393] [client 4.204.201.85:44009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/FWAZ.php"] [unique_id "al9H8yBMYeh5YLVG45xgHQAAAiU"]
[Tue Jul 21 07:20:35.334369 2026] [security2:error] [pid 229246:tid 229498] [client 114.119.143.158:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.imobiliariasobrado.com.br"] [uri "/index.php/imovel/sobrado-geminado-3-quartos-com-garagem-9494m2-venda-floresta-joinville-sc-v06183"] [unique_id "al9H8yBMYeh5YLVG45xgIgAAAo4"], referer: https://www.imobiliariasobrado.com.br/index.php
[Tue Jul 21 07:20:35.377879 2026] [security2:error] [pid 229246:tid 229411] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-link-szoppm.php"] [unique_id "al9H8yBMYeh5YLVG45xgIwAAAjc"]
[Tue Jul 21 07:20:35.461033 2026] [autoindex:error] [pid 229246:tid 229442] [client 43.163.112.239:36622] AH01276: Cannot serve directory /home1/joaor255/meupetpaixao.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:20:35.625928 2026] [security2:error] [pid 229246:tid 229406] [client 20.151.10.161:45967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/av.php"] [unique_id "al9H8yBMYeh5YLVG45xgJwAAAjI"]
[Tue Jul 21 07:20:35.675160 2026] [security2:error] [pid 229246:tid 229479] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/albin.php"] [unique_id "al9H8yBMYeh5YLVG45xgKAAAAns"]
[Tue Jul 21 07:20:35.784246 2026] [security2:error] [pid 229246:tid 229403] [client 20.104.96.117:59664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/patie.php"] [unique_id "al9H8yBMYeh5YLVG45xgLAAAAi8"]
[Tue Jul 21 07:20:35.850960 2026] [security2:error] [pid 230252:tid 230471] [client 136.144.33.215:55705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9H800Dwhk5-Z44Xro6vAAAAvA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:35.957875 2026] [security2:error] [pid 230252:tid 230473] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/cilus.php"] [unique_id "al9H800Dwhk5-Z44Xro6vQAAAvI"]
[Tue Jul 21 07:20:36.105023 2026] [security2:error] [pid 230252:tid 230510] [client 4.204.201.85:44000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/miru1.php"] [unique_id "al9H9E0Dwhk5-Z44Xro6vgAAAxc"]
[Tue Jul 21 07:20:36.221841 2026] [security2:error] [pid 229246:tid 229276] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9H9CBMYeh5YLVG45xgMwACJB0"]
[Tue Jul 21 07:20:36.222004 2026] [security2:error] [pid 229246:tid 229392] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9H9CBMYeh5YLVG45xgMwACJB0"]
[Tue Jul 21 07:20:36.237547 2026] [security2:error] [pid 230252:tid 230440] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/gptsh.php"] [unique_id "al9H9E0Dwhk5-Z44Xro6wgAAAtE"]
[Tue Jul 21 07:20:36.275568 2026] [security2:error] [pid 229246:tid 229441] [client 20.151.10.161:55286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9H9CBMYeh5YLVG45xgNgAAAlU"]
[Tue Jul 21 07:20:36.433985 2026] [security2:error] [pid 229246:tid 229400] [client 20.151.10.161:45978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/classwithtostring.php"] [unique_id "al9H9CBMYeh5YLVG45xgNwAAAiw"]
[Tue Jul 21 07:20:36.512249 2026] [security2:error] [pid 230252:tid 230457] [client 20.197.192.193:6859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/cron-tab.php"] [unique_id "al9H9E0Dwhk5-Z44Xro6xQAAAuI"]
[Tue Jul 21 07:20:36.512448 2026] [security2:error] [pid 230252:tid 230401] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/rithin.php"] [unique_id "al9H9E0Dwhk5-Z44Xro6xgAAAqo"]
[Tue Jul 21 07:20:36.654761 2026] [security2:error] [pid 230252:tid 230389] [client 114.119.145.137:43081] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "northcomm.com.br"] [uri "/wp-includes/css/wp-embed-template-ie.css"] [unique_id "al9H9E0Dwhk5-Z44Xro6xwAAAp4"], referer: https://northcomm.com.br/wp-includes/css/?MD
[Tue Jul 21 07:20:36.755376 2026] [http2:warn] [pid 229246:tid 229389] [client 57.141.18.57:54776] h2_stream(229246-202-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:36.821619 2026] [security2:error] [pid 230252:tid 230495] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/fffm.php"] [unique_id "al9H9E0Dwhk5-Z44Xro6yAAAAwg"]
[Tue Jul 21 07:20:36.859245 2026] [security2:error] [pid 230252:tid 230498] [client 20.151.10.161:11740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-blog.php"] [unique_id "al9H9E0Dwhk5-Z44Xro6zAAAAws"]
[Tue Jul 21 07:20:36.929341 2026] [http2:warn] [pid 229246:tid 229382] [client 57.141.18.19:44984] h2_stream(229246-204-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:36.968687 2026] [security2:error] [pid 229246:tid 229304] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H9CBMYeh5YLVG45xgQAACUzk"]
[Tue Jul 21 07:20:36.968872 2026] [security2:error] [pid 229246:tid 229439] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H9CBMYeh5YLVG45xgQAACUzk"]
[Tue Jul 21 07:20:36.982171 2026] [security2:error] [pid 229246:tid 229387] [client 74.249.245.134:60509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/inputs.php"] [unique_id "al9H9CBMYeh5YLVG45xgQQAAAh8"]
[Tue Jul 21 07:20:37.119288 2026] [security2:error] [pid 230252:tid 230497] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/dfre.php"] [unique_id "al9H9U0Dwhk5-Z44Xro6zgAAAwo"]
[Tue Jul 21 07:20:37.128304 2026] [security2:error] [pid 230252:tid 230384] [client 139.135.44.145:54798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9H9U0Dwhk5-Z44Xro6zwAAApk"]
[Tue Jul 21 07:20:37.128458 2026] [security2:error] [pid 230252:tid 230384] [client 139.135.44.145:54798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9H9U0Dwhk5-Z44Xro6zwAAApk"]
[Tue Jul 21 07:20:37.169699 2026] [security2:error] [pid 230252:tid 230464] [client 20.151.10.161:45950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9H9U0Dwhk5-Z44Xro60AAAAuk"]
[Tue Jul 21 07:20:37.275719 2026] [security2:error] [pid 230252:tid 230263] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H9U0Dwhk5-Z44Xro60gAC3Qk"]
[Tue Jul 21 07:20:37.275922 2026] [security2:error] [pid 230252:tid 230452] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H9U0Dwhk5-Z44Xro60gAC3Qk"]
[Tue Jul 21 07:20:37.385382 2026] [security2:error] [pid 230252:tid 230511] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-happy.php"] [unique_id "al9H9U0Dwhk5-Z44Xro61AAAAxg"]
[Tue Jul 21 07:20:37.477433 2026] [security2:error] [pid 230252:tid 230466] [client 175.45.70.82:50624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H9U0Dwhk5-Z44Xro61QAAAus"]
[Tue Jul 21 07:20:37.477562 2026] [security2:error] [pid 230252:tid 230466] [client 175.45.70.82:50624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H9U0Dwhk5-Z44Xro61QAAAus"]
[Tue Jul 21 07:20:37.604586 2026] [security2:error] [pid 230252:tid 230425] [client 20.197.192.193:6358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/koiy.php"] [unique_id "al9H9U0Dwhk5-Z44Xro63AAAAsI"]
[Tue Jul 21 07:20:37.651111 2026] [security2:error] [pid 230252:tid 230440] [client 4.204.201.85:17891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/aa.php"] [unique_id "al9H9U0Dwhk5-Z44Xro63QAAAtE"]
[Tue Jul 21 07:20:37.659219 2026] [security2:error] [pid 230252:tid 230396] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/fpr4.php"] [unique_id "al9H9U0Dwhk5-Z44Xro63gAAAqU"]
[Tue Jul 21 07:20:37.835865 2026] [security2:error] [pid 229246:tid 229414] [client 20.226.60.151:54486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/aunmc.php"] [unique_id "al9H9SBMYeh5YLVG45xgSQAAAjo"]
[Tue Jul 21 07:20:37.932963 2026] [security2:error] [pid 229246:tid 229403] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/file88.php"] [unique_id "al9H9SBMYeh5YLVG45xgTQAAAi8"]
[Tue Jul 21 07:20:38.007958 2026] [security2:error] [pid 229246:tid 229455] [client 20.151.10.161:46056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-blog.php"] [unique_id "al9H9iBMYeh5YLVG45xgTgAAAmM"]
[Tue Jul 21 07:20:38.028509 2026] [core:alert] [pid 230252:tid 230416] [client 49.51.38.193:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:20:38.044773 2026] [security2:error] [pid 230252:tid 230476] [client 120.61.173.56:55118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H9k0Dwhk5-Z44Xro64wAAAvU"]
[Tue Jul 21 07:20:38.044968 2026] [security2:error] [pid 230252:tid 230476] [client 120.61.173.56:55118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H9k0Dwhk5-Z44Xro64wAAAvU"]
[Tue Jul 21 07:20:38.222078 2026] [security2:error] [pid 230252:tid 230389] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/ccc.php"] [unique_id "al9H9k0Dwhk5-Z44Xro65AAAAp4"]
[Tue Jul 21 07:20:38.227356 2026] [http2:warn] [pid 230252:tid 230385] [client 57.141.18.113:37894] h2_stream(230252-0-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:38.363833 2026] [security2:error] [pid 230252:tid 230489] [client 20.104.96.117:59707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/aa.php"] [unique_id "al9H9k0Dwhk5-Z44Xro65QAAAwI"]
[Tue Jul 21 07:20:38.386641 2026] [security2:error] [pid 230252:tid 230397] [client 20.197.192.193:7004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/hp2.php"] [unique_id "al9H9k0Dwhk5-Z44Xro65gAAAqY"]
[Tue Jul 21 07:20:38.412692 2026] [security2:error] [pid 229246:tid 229404] [client 20.151.10.161:55258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9H9iBMYeh5YLVG45xgUgAAAjA"]
[Tue Jul 21 07:20:38.505860 2026] [security2:error] [pid 230252:tid 230497] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/777.php"] [unique_id "al9H9k0Dwhk5-Z44Xro66wAAAwo"]
[Tue Jul 21 07:20:38.825158 2026] [security2:error] [pid 229246:tid 229460] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/for.php"] [unique_id "al9H9iBMYeh5YLVG45xgVAAAAmg"]
[Tue Jul 21 07:20:38.894602 2026] [security2:error] [pid 230252:tid 230464] [client 20.151.10.161:46023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9H9k0Dwhk5-Z44Xro67QAAAuk"]
[Tue Jul 21 07:20:38.896836 2026] [core:error] [pid 229246:tid 229335] [remote 40.77.167.14:50367] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:38.896851 2026] [core:error] [pid 229246:tid 229335] [remote 40.77.167.14:50367] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:38.989891 2026] [security2:error] [pid 230252:tid 230429] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9H9k0Dwhk5-Z44Xro67wAAAsY"]
[Tue Jul 21 07:20:39.002087 2026] [security2:error] [pid 230252:tid 230406] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9H900Dwhk5-Z44Xro68QAAAq8"]
[Tue Jul 21 07:20:39.015628 2026] [security2:error] [pid 229246:tid 229444] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/sql.php"] [unique_id "al9H9yBMYeh5YLVG45xgWQAAAlg"]
[Tue Jul 21 07:20:39.038275 2026] [security2:error] [pid 229246:tid 229441] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/1index.php"] [unique_id "al9H9yBMYeh5YLVG45xgWgAAAlU"]
[Tue Jul 21 07:20:39.062324 2026] [security2:error] [pid 229246:tid 229332] [remote 5.39.1.238:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "hauptmann.com.br"] [uri "/grid-full-width-2-cols/page/3/"] [unique_id "al9H9yBMYeh5YLVG45xgWwACdlU"]
[Tue Jul 21 07:20:39.062476 2026] [security2:error] [pid 229246:tid 229474] [client 5.39.1.238:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "hauptmann.com.br"] [uri "/grid-full-width-2-cols/page/3/"] [unique_id "al9H9yBMYeh5YLVG45xgWwACdlU"]
[Tue Jul 21 07:20:39.076600 2026] [security2:error] [pid 229246:tid 229497] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/reop1.php"] [unique_id "al9H9yBMYeh5YLVG45xgXAAAAo0"]
[Tue Jul 21 07:20:39.101819 2026] [security2:error] [pid 230252:tid 230399] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/trusj18.php"] [unique_id "al9H900Dwhk5-Z44Xro68gAAAqg"]
[Tue Jul 21 07:20:39.107310 2026] [security2:error] [pid 229246:tid 229399] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/ssla.php"] [unique_id "al9H9yBMYeh5YLVG45xgXQAAAis"]
[Tue Jul 21 07:20:39.116040 2026] [security2:error] [pid 229246:tid 229410] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/trusj15.php"] [unique_id "al9H9yBMYeh5YLVG45xgXgAAAjY"]
[Tue Jul 21 07:20:39.128590 2026] [security2:error] [pid 230252:tid 230390] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/rft8.php"] [unique_id "al9H900Dwhk5-Z44Xro68wAAAp8"]
[Tue Jul 21 07:20:39.139924 2026] [security2:error] [pid 230252:tid 230423] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/ai.php"] [unique_id "al9H900Dwhk5-Z44Xro69AAAAsA"]
[Tue Jul 21 07:20:39.151394 2026] [security2:error] [pid 230252:tid 230447] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/fx.php"] [unique_id "al9H900Dwhk5-Z44Xro69QAAAtg"]
[Tue Jul 21 07:20:39.163292 2026] [security2:error] [pid 230252:tid 230410] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/xxx.php"] [unique_id "al9H900Dwhk5-Z44Xro69gAAArM"]
[Tue Jul 21 07:20:39.174561 2026] [security2:error] [pid 230252:tid 230395] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/dropdown.php"] [unique_id "al9H900Dwhk5-Z44Xro69wAAAqQ"]
[Tue Jul 21 07:20:39.185325 2026] [security2:error] [pid 230252:tid 230287] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9H900Dwhk5-Z44Xro6-AADBiE"]
[Tue Jul 21 07:20:39.185480 2026] [security2:error] [pid 230252:tid 230493] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9H900Dwhk5-Z44Xro6-AADBiE"]
[Tue Jul 21 07:20:39.187948 2026] [security2:error] [pid 230252:tid 230502] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/file11.php"] [unique_id "al9H900Dwhk5-Z44Xro6-QAAAw8"]
[Tue Jul 21 07:20:39.198686 2026] [security2:error] [pid 230252:tid 230510] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/png.php"] [unique_id "al9H900Dwhk5-Z44Xro6-gAAAxc"]
[Tue Jul 21 07:20:39.209563 2026] [security2:error] [pid 230252:tid 230396] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-slss.php"] [unique_id "al9H900Dwhk5-Z44Xro6-wAAAqU"]
[Tue Jul 21 07:20:39.220673 2026] [security2:error] [pid 230252:tid 230392] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/ah25.php"] [unique_id "al9H900Dwhk5-Z44Xro6_QAAAqE"]
[Tue Jul 21 07:20:39.232037 2026] [security2:error] [pid 230252:tid 230300] [remote 41.76.214.143:51010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9H900Dwhk5-Z44Xro6_wACvC4"]
[Tue Jul 21 07:20:39.232182 2026] [security2:error] [pid 230252:tid 230457] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/ccou.php"] [unique_id "al9H900Dwhk5-Z44Xro6_gAAAuI"]
[Tue Jul 21 07:20:39.237446 2026] [http2:warn] [pid 230252:tid 230413] [client 57.141.18.109:28454] h2_stream(230252-2-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:39.244072 2026] [security2:error] [pid 230252:tid 230426] [client 20.206.67.15:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/1.php"] [unique_id "al9H900Dwhk5-Z44Xro7AAAAAsM"]
[Tue Jul 21 07:20:39.244187 2026] [security2:error] [pid 230252:tid 230426] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/1.php"] [unique_id "al9H900Dwhk5-Z44Xro7AAAAAsM"]
[Tue Jul 21 07:20:39.258600 2026] [security2:error] [pid 230252:tid 230387] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/900.php"] [unique_id "al9H900Dwhk5-Z44Xro7AQAAApw"]
[Tue Jul 21 07:20:39.266236 2026] [security2:error] [pid 230252:tid 230389] [client 20.197.192.193:6861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/hp3.php"] [unique_id "al9H900Dwhk5-Z44Xro7AgAAAp4"]
[Tue Jul 21 07:20:39.278178 2026] [security2:error] [pid 230252:tid 230507] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/file59.php"] [unique_id "al9H900Dwhk5-Z44Xro7AwAAAxQ"]
[Tue Jul 21 07:20:39.290479 2026] [security2:error] [pid 229246:tid 229493] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/amxloxxr.php"] [unique_id "al9H9yBMYeh5YLVG45xgYAAAAok"]
[Tue Jul 21 07:20:39.303630 2026] [security2:error] [pid 229246:tid 229407] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/aboutc.php"] [unique_id "al9H9yBMYeh5YLVG45xgYQAAAjM"]
[Tue Jul 21 07:20:39.307532 2026] [security2:error] [pid 229246:tid 229393] [client 20.197.192.193:6374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/aa1.php"] [unique_id "al9H9yBMYeh5YLVG45xgYgAAAiU"]
[Tue Jul 21 07:20:39.317943 2026] [security2:error] [pid 230252:tid 230397] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/bless18.php"] [unique_id "al9H900Dwhk5-Z44Xro7BAAAAqY"]
[Tue Jul 21 07:20:39.333565 2026] [security2:error] [pid 230252:tid 230436] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/crgio.php"] [unique_id "al9H900Dwhk5-Z44Xro7BQAAAs0"]
[Tue Jul 21 07:20:39.346866 2026] [security2:error] [pid 230252:tid 230445] [client 20.197.192.193:6850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/acew67.php"] [unique_id "al9H900Dwhk5-Z44Xro7BgAAAtY"]
[Tue Jul 21 07:20:39.350622 2026] [security2:error] [pid 230252:tid 230497] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-act.php"] [unique_id "al9H900Dwhk5-Z44Xro7BwAAAwo"]
[Tue Jul 21 07:20:39.369311 2026] [security2:error] [pid 230252:tid 230464] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/new4.php"] [unique_id "al9H900Dwhk5-Z44Xro7CQAAAuk"]
[Tue Jul 21 07:20:39.377847 2026] [security2:error] [pid 230252:tid 230501] [client 20.197.192.193:6899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/bscclapb.php"] [unique_id "al9H900Dwhk5-Z44Xro7CgAAAw4"]
[Tue Jul 21 07:20:39.380350 2026] [security2:error] [pid 230252:tid 230406] [client 20.151.10.161:12049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/adminfuns.php"] [unique_id "al9H900Dwhk5-Z44Xro7CwAAAq8"]
[Tue Jul 21 07:20:39.381736 2026] [security2:error] [pid 230252:tid 230500] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-the.php"] [unique_id "al9H900Dwhk5-Z44Xro7DAAAAw0"]
[Tue Jul 21 07:20:39.388700 2026] [security2:error] [pid 230252:tid 230409] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/zc-131.php"] [unique_id "al9H900Dwhk5-Z44Xro7DQAAArI"]
[Tue Jul 21 07:20:39.398740 2026] [security2:error] [pid 230252:tid 230461] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/atkno.php"] [unique_id "al9H900Dwhk5-Z44Xro7DgAAAuY"]
[Tue Jul 21 07:20:39.406939 2026] [security2:error] [pid 230252:tid 230511] [client 20.197.192.193:6340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/else1.php"] [unique_id "al9H900Dwhk5-Z44Xro7DwAAAxg"]
[Tue Jul 21 07:20:39.412214 2026] [security2:error] [pid 230252:tid 230390] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/mass.php"] [unique_id "al9H900Dwhk5-Z44Xro7EAAAAp8"]
[Tue Jul 21 07:20:39.429031 2026] [security2:error] [pid 230252:tid 230466] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wefile.php"] [unique_id "al9H900Dwhk5-Z44Xro7EQAAAus"]
[Tue Jul 21 07:20:39.432487 2026] [security2:error] [pid 230252:tid 230430] [client 20.197.192.193:6354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/tkikikoko.php"] [unique_id "al9H900Dwhk5-Z44Xro7EgAAAsc"]
[Tue Jul 21 07:20:39.445359 2026] [security2:error] [pid 229246:tid 229438] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/min.php"] [unique_id "al9H9yBMYeh5YLVG45xgYwAAAlI"]
[Tue Jul 21 07:20:39.461211 2026] [security2:error] [pid 229246:tid 229381] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/sid3.php"] [unique_id "al9H9yBMYeh5YLVG45xgZAAAAhk"]
[Tue Jul 21 07:20:39.478624 2026] [security2:error] [pid 229246:tid 229459] [client 20.197.192.193:6370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9H9yBMYeh5YLVG45xgZQAAAmc"]
[Tue Jul 21 07:20:39.479214 2026] [security2:error] [pid 230252:tid 230395] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/fileas.php"] [unique_id "al9H900Dwhk5-Z44Xro7FAAAAqQ"]
[Tue Jul 21 07:20:39.491047 2026] [security2:error] [pid 229246:tid 229428] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/bless24.php"] [unique_id "al9H9yBMYeh5YLVG45xgZgAAAkg"]
[Tue Jul 21 07:20:39.503100 2026] [security2:error] [pid 230252:tid 230493] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/fun.php"] [unique_id "al9H900Dwhk5-Z44Xro7FgAAAwY"]
[Tue Jul 21 07:20:39.526100 2026] [security2:error] [pid 229246:tid 229391] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/drykl.php"] [unique_id "al9H9yBMYeh5YLVG45xgagAAAiM"]
[Tue Jul 21 07:20:39.528552 2026] [security2:error] [pid 230252:tid 230504] [client 20.197.192.193:7016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/wp-css.php"] [unique_id "al9H900Dwhk5-Z44Xro7FwAAAxE"]
[Tue Jul 21 07:20:39.540094 2026] [security2:error] [pid 229246:tid 229384] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "al9H9yBMYeh5YLVG45xgawAAAhw"]
[Tue Jul 21 07:20:39.541731 2026] [security2:error] [pid 229246:tid 229401] [client 20.151.10.161:45893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/adminfuns.php"] [unique_id "al9H9yBMYeh5YLVG45xgbAAAAi0"]
[Tue Jul 21 07:20:39.551148 2026] [security2:error] [pid 229246:tid 229495] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/mifta.php"] [unique_id "al9H9yBMYeh5YLVG45xgbQAAAos"]
[Tue Jul 21 07:20:39.569089 2026] [security2:error] [pid 229246:tid 229394] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/class-t.api.php"] [unique_id "al9H9yBMYeh5YLVG45xgbgAAAiY"]
[Tue Jul 21 07:20:39.571860 2026] [security2:error] [pid 230252:tid 230265] [remote 182.77.62.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/wp-login.php"] [unique_id "al9H900Dwhk5-Z44Xro7GQAC9Qs"]
[Tue Jul 21 07:20:39.585863 2026] [security2:error] [pid 229246:tid 229380] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/vgtyu.php"] [unique_id "al9H9yBMYeh5YLVG45xgbwAAAhg"]
[Tue Jul 21 07:20:39.609239 2026] [security2:error] [pid 229246:tid 229379] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/atomlib.php"] [unique_id "al9H9yBMYeh5YLVG45xgcAAAAhc"]
[Tue Jul 21 07:20:39.625049 2026] [security2:error] [pid 230252:tid 230400] [client 193.36.225.73:20495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9H900Dwhk5-Z44Xro7GgAAAqk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:39.628239 2026] [security2:error] [pid 229246:tid 229389] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-access.php"] [unique_id "al9H9yBMYeh5YLVG45xgcQAAAiE"]
[Tue Jul 21 07:20:39.644763 2026] [security2:error] [pid 229246:tid 229429] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-update.php"] [unique_id "al9H9yBMYeh5YLVG45xgcgAAAkk"]
[Tue Jul 21 07:20:39.663989 2026] [security2:error] [pid 229246:tid 229403] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/erty.php"] [unique_id "al9H9yBMYeh5YLVG45xgdAAAAi8"]
[Tue Jul 21 07:20:39.688875 2026] [security2:error] [pid 230252:tid 230428] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "al9H900Dwhk5-Z44Xro7GwAAAsU"]
[Tue Jul 21 07:20:39.700672 2026] [security2:error] [pid 230252:tid 230457] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/like.php"] [unique_id "al9H900Dwhk5-Z44Xro7HAAAAuI"]
[Tue Jul 21 07:20:39.713628 2026] [security2:error] [pid 230252:tid 230426] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/bless5.php"] [unique_id "al9H900Dwhk5-Z44Xro7HQAAAsM"]
[Tue Jul 21 07:20:39.724649 2026] [security2:error] [pid 230252:tid 230387] [client 4.204.201.85:17806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/122.php"] [unique_id "al9H900Dwhk5-Z44Xro7HgAAApw"]
[Tue Jul 21 07:20:39.724971 2026] [security2:error] [pid 230252:tid 230401] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/t.php"] [unique_id "al9H900Dwhk5-Z44Xro7HwAAAqo"]
[Tue Jul 21 07:20:39.737015 2026] [security2:error] [pid 229246:tid 229466] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/xoot.php"] [unique_id "al9H9yBMYeh5YLVG45xgdgAAAm4"]
[Tue Jul 21 07:20:39.748403 2026] [security2:error] [pid 229246:tid 229404] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/xqq.php"] [unique_id "al9H9yBMYeh5YLVG45xgdwAAAjA"]
[Tue Jul 21 07:20:39.760846 2026] [security2:error] [pid 229246:tid 229478] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-load.php"] [unique_id "al9H9yBMYeh5YLVG45xgeAAAAno"]
[Tue Jul 21 07:20:39.772939 2026] [security2:error] [pid 229246:tid 229484] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/x.php"] [unique_id "al9H9yBMYeh5YLVG45xgeQAAAoA"]
[Tue Jul 21 07:20:39.798940 2026] [security2:error] [pid 229246:tid 229460] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/i.php"] [unique_id "al9H9yBMYeh5YLVG45xgegAAAmg"]
[Tue Jul 21 07:20:39.807908 2026] [http2:warn] [pid 229246:tid 229395] [client 57.141.18.21:25248] h2_stream(229246-221-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:39.812785 2026] [security2:error] [pid 229246:tid 229421] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/ms-edit.php"] [unique_id "al9H9yBMYeh5YLVG45xgewAAAkE"]
[Tue Jul 21 07:20:39.816319 2026] [security2:error] [pid 230252:tid 230397] [client 20.197.192.193:6873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/wp-explorer.php"] [unique_id "al9H900Dwhk5-Z44Xro7IAAAAqY"]
[Tue Jul 21 07:20:39.824337 2026] [security2:error] [pid 229246:tid 229392] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/v2.php"] [unique_id "al9H9yBMYeh5YLVG45xgfAAAAiQ"]
[Tue Jul 21 07:20:39.836964 2026] [security2:error] [pid 229246:tid 229481] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/new.php"] [unique_id "al9H9yBMYeh5YLVG45xgfQAAAn0"]
[Tue Jul 21 07:20:39.844021 2026] [security2:error] [pid 229246:tid 229480] [client 20.151.10.161:12043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/goods.php"] [unique_id "al9H9yBMYeh5YLVG45xgfgAAAnw"]
[Tue Jul 21 07:20:39.850745 2026] [security2:error] [pid 229246:tid 229441] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-admin/network/edit.php"] [unique_id "al9H9yBMYeh5YLVG45xgfwAAAlU"]
[Tue Jul 21 07:20:39.870624 2026] [security2:error] [pid 229246:tid 229474] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/pouhg.php"] [unique_id "al9H9yBMYeh5YLVG45xggAAAAnY"]
[Tue Jul 21 07:20:39.883187 2026] [security2:error] [pid 229246:tid 229496] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/cilus.php"] [unique_id "al9H9yBMYeh5YLVG45xggQAAAow"]
[Tue Jul 21 07:20:39.897357 2026] [security2:error] [pid 230252:tid 230497] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/file4.php"] [unique_id "al9H900Dwhk5-Z44Xro7IQAAAwo"]
[Tue Jul 21 07:20:39.912750 2026] [security2:error] [pid 230252:tid 230472] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/samll.php"] [unique_id "al9H900Dwhk5-Z44Xro7IgAAAvE"]
[Tue Jul 21 07:20:39.927480 2026] [security2:error] [pid 230252:tid 230464] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/Okxob.php"] [unique_id "al9H900Dwhk5-Z44Xro7IwAAAuk"]
[Tue Jul 21 07:20:39.939156 2026] [security2:error] [pid 230252:tid 230501] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/ok.php"] [unique_id "al9H900Dwhk5-Z44Xro7JAAAAw4"]
[Tue Jul 21 07:20:39.951444 2026] [security2:error] [pid 229246:tid 229410] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wuasr.php"] [unique_id "al9H9yBMYeh5YLVG45xgggAAAjY"]
[Tue Jul 21 07:20:39.962935 2026] [security2:error] [pid 229246:tid 229491] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/bless11.php"] [unique_id "al9H9yBMYeh5YLVG45xggwAAAoc"]
[Tue Jul 21 07:20:39.976850 2026] [security2:error] [pid 229246:tid 229398] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-block.php"] [unique_id "al9H9yBMYeh5YLVG45xghAAAAio"]
[Tue Jul 21 07:20:39.988926 2026] [security2:error] [pid 229246:tid 229503] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/aevly.php"] [unique_id "al9H9yBMYeh5YLVG45xghQAAApM"]
[Tue Jul 21 07:20:40.002198 2026] [security2:error] [pid 230252:tid 230452] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/hello.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7JQAAAt0"]
[Tue Jul 21 07:20:40.015990 2026] [security2:error] [pid 229246:tid 229452] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-links-opml.php"] [unique_id "al9H-CBMYeh5YLVG45xghgAAAmA"]
[Tue Jul 21 07:20:40.028792 2026] [security2:error] [pid 230252:tid 230461] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/forbidals.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7JwAAAuY"]
[Tue Jul 21 07:20:40.045415 2026] [security2:error] [pid 230252:tid 230424] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/file30.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7KQAAAsE"]
[Tue Jul 21 07:20:40.056808 2026] [security2:error] [pid 229246:tid 229438] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/xda.php"] [unique_id "al9H-CBMYeh5YLVG45xgiQAAAlI"]
[Tue Jul 21 07:20:40.070550 2026] [security2:error] [pid 229246:tid 229477] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/z.php"] [unique_id "al9H-CBMYeh5YLVG45xgigAAAnk"]
[Tue Jul 21 07:20:40.085427 2026] [security2:error] [pid 229246:tid 229413] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/b.php"] [unique_id "al9H-CBMYeh5YLVG45xgjAAAAjk"]
[Tue Jul 21 07:20:40.101407 2026] [security2:error] [pid 229246:tid 229388] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/edit.php"] [unique_id "al9H-CBMYeh5YLVG45xgjQAAAiA"]
[Tue Jul 21 07:20:40.113033 2026] [security2:error] [pid 229246:tid 229439] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/app.php"] [unique_id "al9H-CBMYeh5YLVG45xgjgAAAlM"]
[Tue Jul 21 07:20:40.130961 2026] [security2:error] [pid 229246:tid 229463] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-png.php"] [unique_id "al9H-CBMYeh5YLVG45xgjwAAAms"]
[Tue Jul 21 07:20:40.132104 2026] [security2:error] [pid 230252:tid 230410] [client 20.104.96.117:59181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/xwpg.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7LQAAArM"]
[Tue Jul 21 07:20:40.144208 2026] [security2:error] [pid 229246:tid 229501] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/lib.php"] [unique_id "al9H-CBMYeh5YLVG45xgkAAAApE"]
[Tue Jul 21 07:20:40.152444 2026] [security2:error] [pid 230252:tid 230465] [client 20.151.10.161:45905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/goods.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7LgAAAuo"]
[Tue Jul 21 07:20:40.159473 2026] [security2:error] [pid 229246:tid 229470] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/sys.php"] [unique_id "al9H-CBMYeh5YLVG45xgkQAAAnI"]
[Tue Jul 21 07:20:40.173825 2026] [security2:error] [pid 230252:tid 230395] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/la.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7LwAAAqQ"]
[Tue Jul 21 07:20:40.186617 2026] [security2:error] [pid 230252:tid 230493] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/tires.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7MAAAAwY"]
[Tue Jul 21 07:20:40.198950 2026] [security2:error] [pid 230252:tid 230425] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/lv.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7MQAAAsI"]
[Tue Jul 21 07:20:40.211681 2026] [security2:error] [pid 230252:tid 230440] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/myfile.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7MgAAAtE"]
[Tue Jul 21 07:20:40.235709 2026] [security2:error] [pid 229246:tid 229401] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/06.php"] [unique_id "al9H-CBMYeh5YLVG45xgkgAAAi0"]
[Tue Jul 21 07:20:40.243764 2026] [security2:error] [pid 230252:tid 230434] [client 20.151.10.161:55291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ms-edit.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7MwAAAss"]
[Tue Jul 21 07:20:40.250505 2026] [security2:error] [pid 229246:tid 229456] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/fs.php"] [unique_id "al9H-CBMYeh5YLVG45xgkwAAAmQ"]
[Tue Jul 21 07:20:40.265396 2026] [security2:error] [pid 229246:tid 229394] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/asasx.php"] [unique_id "al9H-CBMYeh5YLVG45xglQAAAiY"]
[Tue Jul 21 07:20:40.284037 2026] [security2:error] [pid 230252:tid 230400] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-kd4xalrg7m.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7NAAAAqk"]
[Tue Jul 21 07:20:40.296606 2026] [security2:error] [pid 230252:tid 230419] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-good.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7NQAAArw"]
[Tue Jul 21 07:20:40.313924 2026] [security2:error] [pid 229246:tid 229380] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/scxy.php"] [unique_id "al9H-CBMYeh5YLVG45xglgAAAhg"]
[Tue Jul 21 07:20:40.329719 2026] [security2:error] [pid 230252:tid 230426] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wmore1.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7NwAAAsM"]
[Tue Jul 21 07:20:40.340984 2026] [security2:error] [pid 230252:tid 230387] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/like.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7OAAAApw"]
[Tue Jul 21 07:20:40.376074 2026] [security2:error] [pid 230252:tid 230389] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/x.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7OQAAAp4"]
[Tue Jul 21 07:20:40.391871 2026] [security2:error] [pid 230252:tid 230489] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/xa.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7OgAAAwI"]
[Tue Jul 21 07:20:40.408761 2026] [security2:error] [pid 230252:tid 230498] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/kolda.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7OwAAAws"]
[Tue Jul 21 07:20:40.427321 2026] [security2:error] [pid 230252:tid 230407] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-aothait.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7PAAAArA"]
[Tue Jul 21 07:20:40.455555 2026] [security2:error] [pid 230252:tid 230481] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/ftde.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7PgAAAvo"]
[Tue Jul 21 07:20:40.471347 2026] [security2:error] [pid 230252:tid 230406] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/vx.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7QAAAAq8"]
[Tue Jul 21 07:20:40.489631 2026] [security2:error] [pid 230252:tid 230452] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/a5.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7QQAAAt0"]
[Tue Jul 21 07:20:40.505103 2026] [security2:error] [pid 230252:tid 230495] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-sing.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7QgAAAwg"]
[Tue Jul 21 07:20:40.518492 2026] [security2:error] [pid 230252:tid 230399] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/database.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7QwAAAqg"]
[Tue Jul 21 07:20:40.531521 2026] [security2:error] [pid 230252:tid 230390] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/explorer/index_.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7RAAAAp8"]
[Tue Jul 21 07:20:40.548538 2026] [security2:error] [pid 230252:tid 230385] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-at.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7RwAAApo"]
[Tue Jul 21 07:20:40.560826 2026] [security2:error] [pid 230252:tid 230473] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-wz.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7SQAAAvI"]
[Tue Jul 21 07:20:40.580077 2026] [security2:error] [pid 230252:tid 230440] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-ver.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7SgAAAtE"]
[Tue Jul 21 07:20:40.600999 2026] [security2:error] [pid 230252:tid 230434] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp5.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7SwAAAss"]
[Tue Jul 21 07:20:40.603233 2026] [security2:error] [pid 229246:tid 229429] [client 20.151.10.161:55274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/222.php"] [unique_id "al9H-CBMYeh5YLVG45xgmgAAAkk"]
[Tue Jul 21 07:20:40.617581 2026] [security2:error] [pid 230252:tid 230476] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-pp.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7TAAAAvU"]
[Tue Jul 21 07:20:40.632760 2026] [security2:error] [pid 230252:tid 230428] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/w3lls.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7TQAAAsU"]
[Tue Jul 21 07:20:40.648340 2026] [security2:error] [pid 230252:tid 230457] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/sbhu.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7TgAAAuI"]
[Tue Jul 21 07:20:40.662312 2026] [security2:error] [pid 230252:tid 230412] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-content/uploads/admin.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7TwAAArU"]
[Tue Jul 21 07:20:40.674592 2026] [security2:error] [pid 230252:tid 230401] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/favicon.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7UAAAAqo"]
[Tue Jul 21 07:20:40.686303 2026] [security2:error] [pid 230252:tid 230454] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/txets.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7UQAAAt8"]
[Tue Jul 21 07:20:40.698313 2026] [security2:error] [pid 229246:tid 229492] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-su.php"] [unique_id "al9H-CBMYeh5YLVG45xgnAAAAog"]
[Tue Jul 21 07:20:40.710533 2026] [security2:error] [pid 229246:tid 229455] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/ff.php"] [unique_id "al9H-CBMYeh5YLVG45xgnQAAAmM"]
[Tue Jul 21 07:20:40.716845 2026] [http2:warn] [pid 230252:tid 230485] [client 57.141.18.116:26954] h2_stream(230252-5-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:40.723273 2026] [security2:error] [pid 230252:tid 230389] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/reze.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7UgAAAp4"]
[Tue Jul 21 07:20:40.739567 2026] [security2:error] [pid 230252:tid 230489] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/666.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7VAAAAwI"]
[Tue Jul 21 07:20:40.758914 2026] [security2:error] [pid 229246:tid 229431] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wehrman.php"] [unique_id "al9H-CBMYeh5YLVG45xgoAAAAks"]
[Tue Jul 21 07:20:40.786360 2026] [security2:error] [pid 229246:tid 229412] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-conflg.php"] [unique_id "al9H-CBMYeh5YLVG45xgoQAAAjg"]
[Tue Jul 21 07:20:40.805220 2026] [security2:error] [pid 229246:tid 229473] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/ff1.php"] [unique_id "al9H-CBMYeh5YLVG45xgogAAAnU"]
[Tue Jul 21 07:20:40.825363 2026] [security2:error] [pid 229246:tid 229449] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/fff.php"] [unique_id "al9H-CBMYeh5YLVG45xgowAAAl0"]
[Tue Jul 21 07:20:40.857529 2026] [security2:error] [pid 229246:tid 229383] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/amax.php"] [unique_id "al9H-CBMYeh5YLVG45xgpAAAAhs"]
[Tue Jul 21 07:20:40.869501 2026] [security2:error] [pid 230252:tid 230498] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-firewall.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7VQAAAws"]
[Tue Jul 21 07:20:40.880477 2026] [security2:error] [pid 230252:tid 230407] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/appt.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7VgAAArA"]
[Tue Jul 21 07:20:40.897855 2026] [security2:error] [pid 230252:tid 230472] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-thi.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7VwAAAvE"]
[Tue Jul 21 07:20:40.909390 2026] [security2:error] [pid 230252:tid 230406] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/jj.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7WAAAAq8"]
[Tue Jul 21 07:20:40.920697 2026] [security2:error] [pid 230252:tid 230501] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/333.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7WQAAAw4"]
[Tue Jul 21 07:20:40.922556 2026] [security2:error] [pid 230252:tid 230504] [client 103.121.156.110:61911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7WgAAAxE"]
[Tue Jul 21 07:20:40.922634 2026] [security2:error] [pid 230252:tid 230504] [client 103.121.156.110:61911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7WgAAAxE"]
[Tue Jul 21 07:20:40.928535 2026] [security2:error] [pid 230252:tid 230452] [client 20.151.10.161:46078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ms-edit.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7WwAAAt0"]
[Tue Jul 21 07:20:40.931754 2026] [security2:error] [pid 230252:tid 230461] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/albin.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7XQAAAuY"]
[Tue Jul 21 07:20:40.942949 2026] [security2:error] [pid 229246:tid 229474] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/66.php"] [unique_id "al9H-CBMYeh5YLVG45xgpwAAAnY"]
[Tue Jul 21 07:20:40.955056 2026] [security2:error] [pid 229246:tid 229496] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/motu.php"] [unique_id "al9H-CBMYeh5YLVG45xgqAAAAow"]
[Tue Jul 21 07:20:40.976103 2026] [security2:error] [pid 229246:tid 229410] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/kj.php"] [unique_id "al9H-CBMYeh5YLVG45xgqQAAAjY"]
[Tue Jul 21 07:20:40.996848 2026] [security2:error] [pid 229246:tid 229491] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp4.php"] [unique_id "al9H-CBMYeh5YLVG45xgqgAAAoc"]
[Tue Jul 21 07:20:41.011292 2026] [security2:error] [pid 229246:tid 229398] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/file61.php"] [unique_id "al9H-SBMYeh5YLVG45xgqwAAAio"]
[Tue Jul 21 07:20:41.023940 2026] [security2:error] [pid 229246:tid 229435] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp.php"] [unique_id "al9H-SBMYeh5YLVG45xgrAAAAk8"]
[Tue Jul 21 07:20:41.036345 2026] [security2:error] [pid 229246:tid 229407] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-trackback.php"] [unique_id "al9H-SBMYeh5YLVG45xgrQAAAjM"]
[Tue Jul 21 07:20:41.067722 2026] [security2:error] [pid 230252:tid 230385] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/db.php"] [unique_id "al9H-U0Dwhk5-Z44Xro7ZAAAApo"]
[Tue Jul 21 07:20:41.070346 2026] [security2:error] [pid 229246:tid 229393] [client 20.151.10.161:12071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9H-SBMYeh5YLVG45xgrgAAAiU"]
[Tue Jul 21 07:20:41.080705 2026] [security2:error] [pid 230252:tid 230465] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/NewFile.php"] [unique_id "al9H-U0Dwhk5-Z44Xro7ZQAAAuo"]
[Tue Jul 21 07:20:41.097031 2026] [security2:error] [pid 229246:tid 229381] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/xxx.php"] [unique_id "al9H-SBMYeh5YLVG45xgsgAAAhk"]
[Tue Jul 21 07:20:41.131013 2026] [security2:error] [pid 229246:tid 229428] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/ms.php"] [unique_id "al9H-SBMYeh5YLVG45xgswAAAkg"]
[Tue Jul 21 07:20:41.142888 2026] [security2:error] [pid 229246:tid 229471] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/mini.php"] [unique_id "al9H-SBMYeh5YLVG45xgtAAAAnM"]
[Tue Jul 21 07:20:41.154252 2026] [security2:error] [pid 229246:tid 229386] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/first.php"] [unique_id "al9H-SBMYeh5YLVG45xgtQAAAh4"]
[Tue Jul 21 07:20:41.174922 2026] [security2:error] [pid 229246:tid 229387] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/0okj.php"] [unique_id "al9H-SBMYeh5YLVG45xgtgAAAh8"]
[Tue Jul 21 07:20:41.202120 2026] [security2:error] [pid 229246:tid 229391] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/grsiuk.php"] [unique_id "al9H-SBMYeh5YLVG45xgtwAAAiM"]
[Tue Jul 21 07:20:41.220660 2026] [security2:error] [pid 229246:tid 229384] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/shell20211028.php"] [unique_id "al9H-SBMYeh5YLVG45xguAAAAhw"]
[Tue Jul 21 07:20:41.237254 2026] [security2:error] [pid 229246:tid 229495] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/revealability.php"] [unique_id "al9H-SBMYeh5YLVG45xguQAAAos"]
[Tue Jul 21 07:20:41.255406 2026] [security2:error] [pid 229246:tid 229422] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/btx25.php"] [unique_id "al9H-SBMYeh5YLVG45xguwAAAkI"]
[Tue Jul 21 07:20:41.274772 2026] [security2:error] [pid 230252:tid 230423] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/bthil.php"] [unique_id "al9H-U0Dwhk5-Z44Xro7ZwAAAsA"]
[Tue Jul 21 07:20:41.293441 2026] [security2:error] [pid 230252:tid 230510] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/hplfuns.php"] [unique_id "al9H-U0Dwhk5-Z44Xro7aAAAAxc"]
[Tue Jul 21 07:20:41.310844 2026] [security2:error] [pid 230252:tid 230396] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/error.php"] [unique_id "al9H-U0Dwhk5-Z44Xro7aQAAAqU"]
[Tue Jul 21 07:20:41.328334 2026] [security2:error] [pid 229246:tid 229406] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/edit.php"] [unique_id "al9H-SBMYeh5YLVG45xgvgAAAjI"]
[Tue Jul 21 07:20:41.344731 2026] [security2:error] [pid 229246:tid 229414] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/pass4.php"] [unique_id "al9H-SBMYeh5YLVG45xgvwAAAjo"]
[Tue Jul 21 07:20:41.361628 2026] [security2:error] [pid 229246:tid 229482] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/sadcut1.php"] [unique_id "al9H-SBMYeh5YLVG45xgwQAAAn4"]
[Tue Jul 21 07:20:41.378735 2026] [security2:error] [pid 229246:tid 229485] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/bgymj.php"] [unique_id "al9H-SBMYeh5YLVG45xgwgAAAoE"]
[Tue Jul 21 07:20:41.392363 2026] [security2:error] [pid 229246:tid 229455] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/yas.php"] [unique_id "al9H-SBMYeh5YLVG45xgwwAAAmM"]
[Tue Jul 21 07:20:41.406847 2026] [security2:error] [pid 229246:tid 229466] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/dx.php"] [unique_id "al9H-SBMYeh5YLVG45xgxAAAAm4"]
[Tue Jul 21 07:20:41.412796 2026] [security2:error] [pid 229246:tid 229404] [client 4.204.201.85:17872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/get.php"] [unique_id "al9H-SBMYeh5YLVG45xgxQAAAjA"]
[Tue Jul 21 07:20:41.420114 2026] [security2:error] [pid 230252:tid 230447] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/yellow.php"] [unique_id "al9H-U0Dwhk5-Z44Xro7awAAAtg"]
[Tue Jul 21 07:20:41.432037 2026] [security2:error] [pid 229246:tid 229478] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-der.php"] [unique_id "al9H-SBMYeh5YLVG45xgxgAAAno"]
[Tue Jul 21 07:20:41.443961 2026] [security2:error] [pid 229246:tid 229382] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/lala.php"] [unique_id "al9H-SBMYeh5YLVG45xgxwAAAho"]
[Tue Jul 21 07:20:41.451291 2026] [security2:error] [pid 229246:tid 229430] [client 114.119.128.132:55045] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.rtdi.com.br"] [uri "/imoveis/sao-paulo/cidade-moncoes"] [unique_id "al9H-SBMYeh5YLVG45xgyAAAAko"], referer: https://www.rtdi.com.br/imoveis/para-alugar/apartamento%2Bcasa/vila-andrade/sao-paulo?quartos=3%2B&suites=1%2B&caracteristicas=-em-condominio-fechado
[Tue Jul 21 07:20:41.455001 2026] [security2:error] [pid 229246:tid 229484] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/aa.php"] [unique_id "al9H-SBMYeh5YLVG45xgyQAAAoA"]
[Tue Jul 21 07:20:41.481521 2026] [security2:error] [pid 229246:tid 229460] [client 114.119.129.97:29525] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.vivermaishospital.com.br"] [uri "/agendamento-online/"] [unique_id "al9H-SBMYeh5YLVG45xgygAAAmg"], referer: http://www.vivermaishospital.com.br/fale-conosco/
[Tue Jul 21 07:20:41.566291 2026] [security2:error] [pid 230252:tid 230445] [client 103.162.129.114:60464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9H-U0Dwhk5-Z44Xro7bAAAAtY"]
[Tue Jul 21 07:20:41.566409 2026] [security2:error] [pid 230252:tid 230445] [client 103.162.129.114:60464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9H-U0Dwhk5-Z44Xro7bAAAAtY"]
[Tue Jul 21 07:20:41.648443 2026] [security2:error] [pid 229246:tid 229444] [client 20.151.10.161:55264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9H-SBMYeh5YLVG45xgzwAAAlg"]
[Tue Jul 21 07:20:41.947382 2026] [http2:warn] [pid 229246:tid 229434] [client 57.141.18.76:64566] h2_stream(229246-226-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:41.956193 2026] [security2:error] [pid 230252:tid 230332] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9H-U0Dwhk5-Z44Xro7cQADFE0"]
[Tue Jul 21 07:20:41.956374 2026] [security2:error] [pid 230252:tid 230507] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9H-U0Dwhk5-Z44Xro7cQADFE0"]
[Tue Jul 21 07:20:41.976165 2026] [security2:error] [pid 230252:tid 230486] [client 160.30.136.8:52031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9H-U0Dwhk5-Z44Xro7cgAAAv8"]
[Tue Jul 21 07:20:42.009060 2026] [security2:error] [pid 230252:tid 230470] [client 20.151.10.161:45845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/222.php"] [unique_id "al9H-k0Dwhk5-Z44Xro7cwAAAu8"]
[Tue Jul 21 07:20:42.252204 2026] [security2:error] [pid 229246:tid 229439] [client 20.220.225.223:43066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/old.php"] [unique_id "al9H-iBMYeh5YLVG45xg2QAAAlM"]
[Tue Jul 21 07:20:42.308361 2026] [security2:error] [pid 230252:tid 230472] [client 20.104.96.117:59184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/ops.php"] [unique_id "al9H-k0Dwhk5-Z44Xro7dQAAAvE"]
[Tue Jul 21 07:20:42.369991 2026] [qos:error] [pid 230252:tid 230337] [remote 57.141.18.24:65348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.24, id=al9H-k0Dwhk5-Z44Xro7dgAC6VI
[Tue Jul 21 07:20:42.472234 2026] [security2:error] [pid 230252:tid 230336] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9H-k0Dwhk5-Z44Xro7dwAC-lE"]
[Tue Jul 21 07:20:42.472367 2026] [security2:error] [pid 230252:tid 230481] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9H-k0Dwhk5-Z44Xro7dwAC-lE"]
[Tue Jul 21 07:20:42.503569 2026] [http2:warn] [pid 229246:tid 229475] [client 57.141.18.14:62686] h2_stream(229246-228-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:42.542419 2026] [qos:error] [pid 229246:tid 229273] [remote 57.141.18.102:23364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.102, id=al9H-iBMYeh5YLVG45xg3AACHxo
[Tue Jul 21 07:20:42.656330 2026] [security2:error] [pid 229246:tid 229401] [client 20.151.10.161:12055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp.php"] [unique_id "al9H-iBMYeh5YLVG45xg3gAAAi0"]
[Tue Jul 21 07:20:42.683233 2026] [security2:error] [pid 229246:tid 229422] [client 160.30.136.8:56253] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bestdealsvalmir.com"] [uri "/"] [unique_id "al9H-iBMYeh5YLVG45xg4AAAAkI"]
[Tue Jul 21 07:20:42.708333 2026] [autoindex:error] [pid 230252:tid 230452] [client 205.210.31.167:61250] AH01276: Cannot serve directory /home2/setpoi24/public_html/setpointgeradores.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:20:42.877951 2026] [security2:error] [pid 230252:tid 230413] [client 20.220.225.223:52755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/acew67.php"] [unique_id "al9H-k0Dwhk5-Z44Xro7egAAArY"]
[Tue Jul 21 07:20:42.903008 2026] [core:error] [pid 230252:tid 230378] [remote 40.77.167.79:45085] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:42.903026 2026] [core:error] [pid 230252:tid 230378] [remote 40.77.167.79:45085] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:42.942024 2026] [security2:error] [pid 229246:tid 229405] [client 74.249.245.134:54550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/ms-edit.php"] [unique_id "al9H-iBMYeh5YLVG45xg5AAAAjE"]
[Tue Jul 21 07:20:42.998365 2026] [security2:error] [pid 229246:tid 229389] [client 20.151.10.161:12048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/abcd.php"] [unique_id "al9H-iBMYeh5YLVG45xg5QAAAiE"]
[Tue Jul 21 07:20:43.371453 2026] [security2:error] [pid 229246:tid 229404] [client 4.204.201.85:17864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/as.php"] [unique_id "al9H-yBMYeh5YLVG45xg6QAAAjA"]
[Tue Jul 21 07:20:43.387553 2026] [security2:error] [pid 229246:tid 229429] [client 160.30.136.8:63143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9H-yBMYeh5YLVG45xg6gAAAkk"]
[Tue Jul 21 07:20:43.469321 2026] [security2:error] [pid 230252:tid 230440] [client 20.197.192.193:26887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/mimpi.php"] [unique_id "al9H-00Dwhk5-Z44Xro7fwAAAtE"]
[Tue Jul 21 07:20:43.541999 2026] [http2:warn] [pid 229246:tid 229490] [client 57.141.18.25:33736] h2_stream(229246-233-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:43.545655 2026] [security2:error] [pid 230252:tid 230400] [client 20.151.10.161:55267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/a1.php"] [unique_id "al9H-00Dwhk5-Z44Xro7gAAAAqk"]
[Tue Jul 21 07:20:43.715870 2026] [proxy:error] [pid 229246:tid 229392] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:20:43.715930 2026] [proxy_http:error] [pid 229246:tid 229392] [client 205.210.31.51:60862] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:20:43.716523 2026] [proxy:error] [pid 229246:tid 229392] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:20:43.716564 2026] [proxy_http:error] [pid 229246:tid 229392] [client 205.210.31.51:60862] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:20:43.749424 2026] [security2:error] [pid 229246:tid 229474] [client 20.151.10.161:46012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9H-yBMYeh5YLVG45xg8wAAAnY"]
[Tue Jul 21 07:20:43.818674 2026] [security2:error] [pid 230252:tid 230428] [client 209.141.34.121:64405] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "amandatorresestetica.com.br"] [uri "/"] [unique_id "al9H-00Dwhk5-Z44Xro7gwAAAsU"]
[Tue Jul 21 07:20:43.858191 2026] [security2:error] [pid 229246:tid 229497] [client 20.197.192.193:6848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/akismet.php"] [unique_id "al9H-yBMYeh5YLVG45xg9QAAAo0"]
[Tue Jul 21 07:20:43.978790 2026] [security2:error] [pid 229246:tid 229431] [client 45.251.232.145:63216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H-yBMYeh5YLVG45xg9wAAAks"]
[Tue Jul 21 07:20:43.978916 2026] [security2:error] [pid 229246:tid 229431] [client 45.251.232.145:63216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H-yBMYeh5YLVG45xg9wAAAks"]
[Tue Jul 21 07:20:43.996391 2026] [security2:error] [pid 230252:tid 230454] [client 20.151.10.161:55262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9H-00Dwhk5-Z44Xro7hwAAAt8"]
[Tue Jul 21 07:20:44.096066 2026] [security2:error] [pid 230252:tid 230426] [client 160.30.136.8:59663] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bestdealsvalmir.com"] [uri "/"] [unique_id "al9H_E0Dwhk5-Z44Xro7iQAAAsM"]
[Tue Jul 21 07:20:44.193167 2026] [security2:error] [pid 230252:tid 230486] [client 4.204.201.85:17883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/ccou.php"] [unique_id "al9H_E0Dwhk5-Z44Xro7jQAAAv8"]
[Tue Jul 21 07:20:44.242410 2026] [security2:error] [pid 230252:tid 230384] [client 37.140.223.69:29189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9H_E0Dwhk5-Z44Xro7kAAAApk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:44.333946 2026] [security2:error] [pid 230252:tid 230466] [client 209.141.34.121:64475] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "amandatorresestetica.com.br"] [uri "/"] [unique_id "al9H_E0Dwhk5-Z44Xro7kgAAAus"]
[Tue Jul 21 07:20:44.436255 2026] [security2:error] [pid 230252:tid 230461] [client 20.104.96.117:59679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/mac.php"] [unique_id "al9H_E0Dwhk5-Z44Xro7mQAAAuY"]
[Tue Jul 21 07:20:44.509443 2026] [security2:error] [pid 230252:tid 230385] [client 20.151.10.161:46015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9H_E0Dwhk5-Z44Xro7mgAAApo"]
[Tue Jul 21 07:20:44.510600 2026] [security2:error] [pid 229246:tid 229286] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9H_CBMYeh5YLVG45xhAAACiSc"]
[Tue Jul 21 07:20:44.510766 2026] [security2:error] [pid 229246:tid 229493] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9H_CBMYeh5YLVG45xhAAACiSc"]
[Tue Jul 21 07:20:44.540655 2026] [security2:error] [pid 229246:tid 229460] [client 14.139.42.196:4212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H_CBMYeh5YLVG45xhAQAAAmg"]
[Tue Jul 21 07:20:44.540750 2026] [security2:error] [pid 229246:tid 229460] [client 14.139.42.196:4212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H_CBMYeh5YLVG45xhAQAAAmg"]
[Tue Jul 21 07:20:44.806156 2026] [security2:error] [pid 230252:tid 230404] [client 134.19.179.187:54424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9H_E0Dwhk5-Z44Xro7mwAAAq0"]
[Tue Jul 21 07:20:44.806264 2026] [security2:error] [pid 230252:tid 230404] [client 134.19.179.187:54424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9H_E0Dwhk5-Z44Xro7mwAAAq0"]
[Tue Jul 21 07:20:44.812210 2026] [security2:error] [pid 229246:tid 229401] [client 160.30.136.8:60430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9H_CBMYeh5YLVG45xhCQAAAi0"]
[Tue Jul 21 07:20:44.872081 2026] [security2:error] [pid 229246:tid 229446] [client 4.204.201.85:17807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/w3lls.php"] [unique_id "al9H_CBMYeh5YLVG45xhCgAAAlo"]
[Tue Jul 21 07:20:44.917571 2026] [security2:error] [pid 229246:tid 229495] [client 20.151.10.161:11729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9H_CBMYeh5YLVG45xhCwAAAos"]
[Tue Jul 21 07:20:44.992939 2026] [security2:error] [pid 230252:tid 230440] [client 184.75.221.3:47452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9H_E0Dwhk5-Z44Xro7nQAAAtE"]
[Tue Jul 21 07:20:44.993099 2026] [security2:error] [pid 230252:tid 230440] [client 184.75.221.3:47452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9H_E0Dwhk5-Z44Xro7nQAAAtE"]
[Tue Jul 21 07:20:45.088645 2026] [security2:error] [pid 230252:tid 230360] [remote 42.200.84.61:33100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "prissedermatologia.com.br"] [uri "/wp-login.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7owADCGk"]
[Tue Jul 21 07:20:45.091963 2026] [security2:error] [pid 230252:tid 230342] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7pAAC8Fc"]
[Tue Jul 21 07:20:45.108766 2026] [security2:error] [pid 230252:tid 230344] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7pQACvFk"]
[Tue Jul 21 07:20:45.127748 2026] [security2:error] [pid 230252:tid 230353] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/dp.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7pgACxWI"]
[Tue Jul 21 07:20:45.158486 2026] [security2:error] [pid 230252:tid 230355] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/old.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7pwACx2Q"]
[Tue Jul 21 07:20:45.178823 2026] [security2:error] [pid 230252:tid 230380] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/ms-new.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7qAACqn0"]
[Tue Jul 21 07:20:45.188268 2026] [qos:error] [pid 230252:tid 230368] [remote 57.141.18.74:37864] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.74, id=al9H_U0Dwhk5-Z44Xro7qgAC2HE
[Tue Jul 21 07:20:45.203658 2026] [security2:error] [pid 230252:tid 230372] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/track.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7qwAC0HU"]
[Tue Jul 21 07:20:45.211014 2026] [http2:warn] [pid 229246:tid 229445] [client 57.141.18.2:30472] h2_stream(229246-238-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:45.223636 2026] [security2:error] [pid 230252:tid 230369] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/2352356666.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7rAACtXI"]
[Tue Jul 21 07:20:45.243952 2026] [security2:error] [pid 230252:tid 230371] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/pn.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7rQACw3Q"]
[Tue Jul 21 07:20:45.248947 2026] [security2:error] [pid 230252:tid 230489] [client 20.151.10.161:11724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/gettest.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7rgAAAwI"]
[Tue Jul 21 07:20:45.266004 2026] [security2:error] [pid 230252:tid 230374] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/wp-wpbak.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7sAAC53c"]
[Tue Jul 21 07:20:45.288894 2026] [security2:error] [pid 230252:tid 230276] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/dr.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7sQACtxY"]
[Tue Jul 21 07:20:45.308430 2026] [security2:error] [pid 230252:tid 230367] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/2x.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7sgADC3A"]
[Tue Jul 21 07:20:45.328595 2026] [security2:error] [pid 230252:tid 230283] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/kq1.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7swACzR0"]
[Tue Jul 21 07:20:45.346199 2026] [security2:error] [pid 230252:tid 230296] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/zzz.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7tAADCio"]
[Tue Jul 21 07:20:45.367759 2026] [security2:error] [pid 230252:tid 230373] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/wicked.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7tQAC8XY"]
[Tue Jul 21 07:20:45.383840 2026] [security2:error] [pid 230252:tid 230370] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/edit.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7tgADFHM"]
[Tue Jul 21 07:20:45.404044 2026] [security2:error] [pid 230252:tid 230376] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/kua.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7twAC6Xk"]
[Tue Jul 21 07:20:45.419331 2026] [security2:error] [pid 230252:tid 230451] [client 4.204.201.85:17813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/test1.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7uAAAAtw"]
[Tue Jul 21 07:20:45.420537 2026] [security2:error] [pid 230252:tid 230294] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/ez.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7uQAC6yg"]
[Tue Jul 21 07:20:45.438764 2026] [security2:error] [pid 230252:tid 230264] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/fz.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7ugAC-go"]
[Tue Jul 21 07:20:45.459112 2026] [security2:error] [pid 230252:tid 230366] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/la.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7uwADDW8"]
[Tue Jul 21 07:20:45.471082 2026] [security2:error] [pid 229246:tid 229403] [client 20.226.60.151:54537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/uoocf.php"] [unique_id "al9H_SBMYeh5YLVG45xhEQAAAi8"]
[Tue Jul 21 07:20:45.477031 2026] [http2:warn] [pid 230252:tid 230448] [client 57.141.18.69:34688] h2_stream(230252-8-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:45.479806 2026] [security2:error] [pid 230252:tid 230282] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/nhvoanpl.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7vAACxhw"]
[Tue Jul 21 07:20:45.501759 2026] [security2:error] [pid 230252:tid 230274] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/inso.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7vQAC5hQ"]
[Tue Jul 21 07:20:45.519293 2026] [security2:error] [pid 230252:tid 230304] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/wpx.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7vgACqDI"]
[Tue Jul 21 07:20:45.521599 2026] [security2:error] [pid 229246:tid 229492] [client 160.30.136.8:64579] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bestdealsvalmir.com"] [uri "/"] [unique_id "al9H_SBMYeh5YLVG45xhEwAAAog"]
[Tue Jul 21 07:20:45.538928 2026] [security2:error] [pid 230252:tid 230268] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/berlin.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7vwAC_g4"]
[Tue Jul 21 07:20:45.559196 2026] [security2:error] [pid 230252:tid 230312] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/billur.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7wAACtjo"]
[Tue Jul 21 07:20:45.580238 2026] [security2:error] [pid 230252:tid 230311] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/mimpi.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7wQACmjk"]
[Tue Jul 21 07:20:45.598011 2026] [security2:error] [pid 230252:tid 230260] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/dp.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7wgAC6gY"]
[Tue Jul 21 07:20:45.618074 2026] [security2:error] [pid 230252:tid 230310] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/bootstrap.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7wwACrTg"]
[Tue Jul 21 07:20:45.636536 2026] [security2:error] [pid 230252:tid 230306] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/wp-editor.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7xAADGDQ"]
[Tue Jul 21 07:20:45.654501 2026] [security2:error] [pid 230252:tid 230288] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/cro.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7xQADBiI"]
[Tue Jul 21 07:20:45.672363 2026] [security2:error] [pid 230252:tid 230357] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/cron-tab.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7xgAC0WY"]
[Tue Jul 21 07:20:45.688747 2026] [security2:error] [pid 230252:tid 230254] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/koiy.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7xwACoQA"]
[Tue Jul 21 07:20:45.704720 2026] [security2:error] [pid 230252:tid 230275] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/hp2.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7yAACqRU"]
[Tue Jul 21 07:20:45.726980 2026] [security2:error] [pid 230252:tid 230285] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/hp3.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7yQADCR8"]
[Tue Jul 21 07:20:45.745373 2026] [security2:error] [pid 230252:tid 230314] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/aa1.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7ygADCDw"]
[Tue Jul 21 07:20:45.766035 2026] [security2:error] [pid 230252:tid 230290] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/acew67.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7ywAC1iQ"]
[Tue Jul 21 07:20:45.783637 2026] [security2:error] [pid 230252:tid 230263] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/bscclapb.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7zQACxQk"]
[Tue Jul 21 07:20:45.806493 2026] [security2:error] [pid 230252:tid 230315] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/else1.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7zgACxz0"]
[Tue Jul 21 07:20:45.823037 2026] [security2:error] [pid 230252:tid 230316] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/tkikikoko.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7zwACnD4"]
[Tue Jul 21 07:20:45.846434 2026] [security2:error] [pid 230252:tid 230273] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/wp-Blogs.php"] [unique_id "al9H_U0Dwhk5-Z44Xro70AACqhM"]
[Tue Jul 21 07:20:45.863437 2026] [security2:error] [pid 230252:tid 230287] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/wp-css.php"] [unique_id "al9H_U0Dwhk5-Z44Xro70QAC0CE"]
[Tue Jul 21 07:20:45.886428 2026] [security2:error] [pid 230252:tid 230300] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/wp-explorer.php"] [unique_id "al9H_U0Dwhk5-Z44Xro70wACwy4"]
[Tue Jul 21 07:20:45.905192 2026] [security2:error] [pid 230252:tid 230298] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/akismet.php"] [unique_id "al9H_U0Dwhk5-Z44Xro71AAC5yw"]
[Tue Jul 21 07:20:45.922311 2026] [security2:error] [pid 230252:tid 230271] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/ace2.php"] [unique_id "al9H_U0Dwhk5-Z44Xro71QAC9RE"]
[Tue Jul 21 07:20:45.939221 2026] [security2:error] [pid 230252:tid 230265] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/ms.php"] [unique_id "al9H_U0Dwhk5-Z44Xro71gAC_ws"]
[Tue Jul 21 07:20:45.988713 2026] [security2:error] [pid 230252:tid 230498] [client 20.151.10.161:12070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/simple.php"] [unique_id "al9H_U0Dwhk5-Z44Xro71wAAAws"]
[Tue Jul 21 07:20:46.075114 2026] [security2:error] [pid 230252:tid 230255] [remote 51.195.39.149:60374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mgdcondominial.com.br"] [uri "/"] [unique_id "al9H_k0Dwhk5-Z44Xro72gAC3wE"]
[Tue Jul 21 07:20:46.178614 2026] [security2:error] [pid 230252:tid 230461] [client 20.151.10.161:45930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp.php"] [unique_id "al9H_k0Dwhk5-Z44Xro74AAAAuY"]
[Tue Jul 21 07:20:46.193900 2026] [http2:warn] [pid 229246:tid 229416] [client 57.141.18.25:38266] h2_stream(229246-241-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:46.252429 2026] [security2:error] [pid 229246:tid 229421] [client 160.30.136.8:54467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9H_iBMYeh5YLVG45xhHAAAAkE"]
[Tue Jul 21 07:20:46.282707 2026] [security2:error] [pid 229246:tid 229478] [client 20.151.10.161:53607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xxx.php"] [unique_id "al9H_iBMYeh5YLVG45xhHwAAAno"]
[Tue Jul 21 07:20:46.525959 2026] [security2:error] [pid 229246:tid 229267] [remote 47.251.82.1:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.82.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-login.php"] [unique_id "al9H_SBMYeh5YLVG45xhEgACMhQ"]
[Tue Jul 21 07:20:46.617592 2026] [security2:error] [pid 229246:tid 229395] [client 20.104.96.117:59140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/mg.php"] [unique_id "al9H_iBMYeh5YLVG45xhJgAAAic"]
[Tue Jul 21 07:20:46.671434 2026] [security2:error] [pid 230252:tid 230511] [client 68.235.38.2:49014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9H_k0Dwhk5-Z44Xro74wAAAxg"]
[Tue Jul 21 07:20:46.671565 2026] [security2:error] [pid 230252:tid 230511] [client 68.235.38.2:49014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9H_k0Dwhk5-Z44Xro74wAAAxg"]
[Tue Jul 21 07:20:46.710517 2026] [security2:error] [pid 230252:tid 230416] [client 4.204.201.85:17809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/database.php"] [unique_id "al9H_k0Dwhk5-Z44Xro75AAAArk"]
[Tue Jul 21 07:20:46.729480 2026] [security2:error] [pid 230252:tid 230392] [client 20.220.225.223:34258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/ms-new.php"] [unique_id "al9H_k0Dwhk5-Z44Xro75gAAAqE"]
[Tue Jul 21 07:20:46.730343 2026] [security2:error] [pid 230252:tid 230400] [client 20.197.192.193:6359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/ace2.php"] [unique_id "al9H_k0Dwhk5-Z44Xro75wAAAqk"]
[Tue Jul 21 07:20:46.740477 2026] [security2:error] [pid 230252:tid 230471] [client 20.151.10.161:55266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/hypo.php"] [unique_id "al9H_k0Dwhk5-Z44Xro76AAAAvA"]
[Tue Jul 21 07:20:46.806925 2026] [security2:error] [pid 230252:tid 230445] [client 92.119.178.3:58512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9H_k0Dwhk5-Z44Xro76QAAAtY"]
[Tue Jul 21 07:20:46.807110 2026] [security2:error] [pid 230252:tid 230445] [client 92.119.178.3:58512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9H_k0Dwhk5-Z44Xro76QAAAtY"]
[Tue Jul 21 07:20:46.817939 2026] [security2:error] [pid 230252:tid 230428] [client 20.151.10.161:45973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/abcd.php"] [unique_id "al9H_k0Dwhk5-Z44Xro76wAAAsU"]
[Tue Jul 21 07:20:46.930921 2026] [security2:error] [pid 230252:tid 230486] [client 74.249.245.134:55778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/simple.php"] [unique_id "al9H_k0Dwhk5-Z44Xro77wAAAv8"]
[Tue Jul 21 07:20:46.959623 2026] [security2:error] [pid 230252:tid 230498] [client 160.30.136.8:59751] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bestdealsvalmir.com"] [uri "/"] [unique_id "al9H_k0Dwhk5-Z44Xro78AAAAws"]
[Tue Jul 21 07:20:46.963498 2026] [security2:error] [pid 230252:tid 230305] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9H_k0Dwhk5-Z44Xro78QADBjM"]
[Tue Jul 21 07:20:46.963731 2026] [security2:error] [pid 230252:tid 230493] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9H_k0Dwhk5-Z44Xro78QADBjM"]
[Tue Jul 21 07:20:47.052963 2026] [security2:error] [pid 230252:tid 230497] [client 20.220.225.223:59483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/bscclapb.php"] [unique_id "al9H_00Dwhk5-Z44Xro78gAAAwo"]
[Tue Jul 21 07:20:47.137237 2026] [security2:error] [pid 230252:tid 230504] [client 20.197.192.193:27175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/dp.php"] [unique_id "al9H_00Dwhk5-Z44Xro79AAAAxE"]
[Tue Jul 21 07:20:47.233617 2026] [security2:error] [pid 230252:tid 230354] [remote 173.252.87.115:55370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9H_00Dwhk5-Z44Xro8NwAC6WM"]
[Tue Jul 21 07:20:47.254479 2026] [security2:error] [pid 230252:tid 230429] [client 20.151.10.161:12076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/chosen.php"] [unique_id "al9H_00Dwhk5-Z44Xro8OAAAAsY"]
[Tue Jul 21 07:20:47.276684 2026] [security2:error] [pid 230252:tid 230409] [client 20.151.10.161:45901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/a1.php"] [unique_id "al9H_00Dwhk5-Z44Xro8OQAAArI"]
[Tue Jul 21 07:20:47.286805 2026] [http2:warn] [pid 229246:tid 229464] [client 57.141.18.50:26728] h2_stream(229246-242-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:47.487119 2026] [security2:error] [pid 230252:tid 230259] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H_00Dwhk5-Z44Xro8RAAC0QU"]
[Tue Jul 21 07:20:47.487269 2026] [security2:error] [pid 230252:tid 230440] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H_00Dwhk5-Z44Xro8RAAC0QU"]
[Tue Jul 21 07:20:47.621115 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:45889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9H_yBMYeh5YLVG45xhMwAAAlo"]
[Tue Jul 21 07:20:47.732718 2026] [access_compat:error] [pid 229246:tid 229479] [client 162.241.63.68:58392] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:20:47.744254 2026] [security2:error] [pid 229246:tid 229386] [client 20.220.225.223:47819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/else1.php"] [unique_id "al9H_yBMYeh5YLVG45xhNwAAAh4"]
[Tue Jul 21 07:20:47.779491 2026] [security2:error] [pid 229246:tid 229470] [client 194.147.58.101:57192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/db_backup.bak"] [unique_id "al9H_yBMYeh5YLVG45xhOAAAAnI"]
[Tue Jul 21 07:20:47.779638 2026] [security2:error] [pid 229246:tid 229442] [client 194.147.58.101:57156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/wwwroot.bak"] [unique_id "al9H_yBMYeh5YLVG45xhOQAAAlY"]
[Tue Jul 21 07:20:47.780349 2026] [security2:error] [pid 230252:tid 230495] [client 194.147.58.101:57180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/db.bak"] [unique_id "al9H_00Dwhk5-Z44Xro8TQAAAwg"]
[Tue Jul 21 07:20:47.780351 2026] [security2:error] [pid 230252:tid 230496] [client 194.147.58.101:57152] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/sa.bak"] [unique_id "al9H_00Dwhk5-Z44Xro8SwAAAwk"]
[Tue Jul 21 07:20:47.780556 2026] [security2:error] [pid 229246:tid 229387] [client 194.147.58.101:57202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/dbdump.bak"] [unique_id "al9H_yBMYeh5YLVG45xhOgAAAh8"]
[Tue Jul 21 07:20:47.780615 2026] [security2:error] [pid 230252:tid 230471] [client 194.147.58.101:57162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/dump.bak"] [unique_id "al9H_00Dwhk5-Z44Xro8TAAAAvA"]
[Tue Jul 21 07:20:47.781056 2026] [security2:error] [pid 230252:tid 230445] [client 194.147.58.101:57178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/data.bak"] [unique_id "al9H_00Dwhk5-Z44Xro8TgAAAtY"]
[Tue Jul 21 07:20:47.782205 2026] [security2:error] [pid 230252:tid 230419] [client 194.147.58.101:57214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/backup.bak"] [unique_id "al9H_00Dwhk5-Z44Xro8TwAAArw"]
[Tue Jul 21 07:20:47.783749 2026] [security2:error] [pid 229246:tid 229428] [client 194.147.58.101:57226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/database.bak"] [unique_id "al9H_yBMYeh5YLVG45xhOwAAAkg"]
[Tue Jul 21 07:20:47.804674 2026] [security2:error] [pid 230252:tid 230451] [client 139.135.44.145:53656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9H_00Dwhk5-Z44Xro8UAAAAtw"]
[Tue Jul 21 07:20:47.804853 2026] [security2:error] [pid 230252:tid 230451] [client 139.135.44.145:53656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9H_00Dwhk5-Z44Xro8UAAAAtw"]
[Tue Jul 21 07:20:47.831196 2026] [security2:error] [pid 230252:tid 230426] [client 20.151.10.161:55288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/als.php"] [unique_id "al9H_00Dwhk5-Z44Xro8UQAAAsM"]
[Tue Jul 21 07:20:47.862858 2026] [security2:error] [pid 229246:tid 229342] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H_yBMYeh5YLVG45xhPgACd18"]
[Tue Jul 21 07:20:47.863075 2026] [security2:error] [pid 229246:tid 229475] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H_yBMYeh5YLVG45xhPgACd18"]
[Tue Jul 21 07:20:47.936292 2026] [http2:warn] [pid 230252:tid 230402] [client 57.141.18.15:35936] h2_stream(230252-13-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:48.036186 2026] [qos:error] [pid 229246:tid 229370] [remote 57.141.18.115:65350] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.115, id=al9IACBMYeh5YLVG45xhQgACY3s
[Tue Jul 21 07:20:48.071205 2026] [security2:error] [pid 229246:tid 229497] [client 4.204.201.85:17917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/file.php"] [unique_id "al9IACBMYeh5YLVG45xhRAAAAo0"]
[Tue Jul 21 07:20:48.139168 2026] [security2:error] [pid 229246:tid 229439] [client 175.45.70.82:51305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IACBMYeh5YLVG45xhRgAAAlM"]
[Tue Jul 21 07:20:48.139328 2026] [security2:error] [pid 229246:tid 229439] [client 175.45.70.82:51305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IACBMYeh5YLVG45xhRgAAAlM"]
[Tue Jul 21 07:20:48.146319 2026] [security2:error] [pid 230252:tid 230507] [client 20.220.225.223:34284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/track.php"] [unique_id "al9IAE0Dwhk5-Z44Xro8UwAAAxQ"]
[Tue Jul 21 07:20:48.240487 2026] [security2:error] [pid 230252:tid 230401] [client 136.144.33.215:56797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IAE0Dwhk5-Z44Xro8VAAAAqo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:48.326192 2026] [security2:error] [pid 229246:tid 229398] [client 20.151.10.161:12072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/pol.php"] [unique_id "al9IACBMYeh5YLVG45xhSgAAAio"]
[Tue Jul 21 07:20:48.347747 2026] [security2:error] [pid 229246:tid 229406] [client 20.220.225.223:52752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/ms-new.php"] [unique_id "al9IACBMYeh5YLVG45xhSwAAAjI"]
[Tue Jul 21 07:20:48.638225 2026] [security2:error] [pid 229246:tid 229479] [client 20.151.10.161:55275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file5.php"] [unique_id "al9IACBMYeh5YLVG45xhVQAAAns"]
[Tue Jul 21 07:20:48.711639 2026] [security2:error] [pid 229246:tid 229456] [client 20.104.96.117:59683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-post-data.php"] [unique_id "al9IACBMYeh5YLVG45xhVgAAAmQ"]
[Tue Jul 21 07:20:48.722964 2026] [security2:error] [pid 229246:tid 229496] [client 120.61.173.56:55626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IACBMYeh5YLVG45xhVwAAAow"]
[Tue Jul 21 07:20:48.723688 2026] [security2:error] [pid 229246:tid 229496] [client 120.61.173.56:55626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IACBMYeh5YLVG45xhVwAAAow"]
[Tue Jul 21 07:20:48.780131 2026] [security2:error] [pid 229246:tid 229391] [client 194.147.58.101:57244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/br1102.hostgator.com.br.bak"] [unique_id "al9IACBMYeh5YLVG45xhWQAAAiM"]
[Tue Jul 21 07:20:48.782019 2026] [security2:error] [pid 229246:tid 229388] [client 194.147.58.101:57318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/www.bak"] [unique_id "al9IACBMYeh5YLVG45xhWgAAAiA"]
[Tue Jul 21 07:20:48.782176 2026] [security2:error] [pid 229246:tid 229401] [client 194.147.58.101:57324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/translate.bak"] [unique_id "al9IACBMYeh5YLVG45xhXAAAAi0"]
[Tue Jul 21 07:20:48.782247 2026] [security2:error] [pid 230252:tid 230501] [client 194.147.58.101:57284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/mysqldump.bak"] [unique_id "al9IAE0Dwhk5-Z44Xro8WAAAAw4"]
[Tue Jul 21 07:20:48.782292 2026] [security2:error] [pid 229246:tid 229384] [client 194.147.58.101:57344] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/sql.bak"] [unique_id "al9IACBMYeh5YLVG45xhWwAAAhw"]
[Tue Jul 21 07:20:48.782296 2026] [security2:error] [pid 230252:tid 230429] [client 194.147.58.101:57274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/wp-content/uploads/dump.bak"] [unique_id "al9IAE0Dwhk5-Z44Xro8VwAAAsY"]
[Tue Jul 21 07:20:48.784639 2026] [security2:error] [pid 229246:tid 229377] [client 194.147.58.101:57270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/wp-content/mysql.bak"] [unique_id "al9IACBMYeh5YLVG45xhXQAAAhU"]
[Tue Jul 21 07:20:48.784758 2026] [security2:error] [pid 230252:tid 230409] [client 194.147.58.101:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/localhost.bak"] [unique_id "al9IAE0Dwhk5-Z44Xro8WQAAArI"]
[Tue Jul 21 07:20:48.787268 2026] [security2:error] [pid 230252:tid 230461] [client 194.147.58.101:57286] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/users.bak"] [unique_id "al9IAE0Dwhk5-Z44Xro8WgAAAuY"]
[Tue Jul 21 07:20:48.787719 2026] [security2:error] [pid 229246:tid 229446] [client 194.147.58.101:57328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/site.bak"] [unique_id "al9IACBMYeh5YLVG45xhXgAAAlo"]
[Tue Jul 21 07:20:48.787784 2026] [security2:error] [pid 230252:tid 230399] [client 194.147.58.101:57256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/br1102.hostgator.com.br_db.bak"] [unique_id "al9IAE0Dwhk5-Z44Xro8WwAAAqg"]
[Tue Jul 21 07:20:48.791184 2026] [security2:error] [pid 230252:tid 230413] [client 194.147.58.101:57306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/mysql.bak"] [unique_id "al9IAE0Dwhk5-Z44Xro8XAAAArY"]
[Tue Jul 21 07:20:48.791201 2026] [security2:error] [pid 229246:tid 229493] [client 194.147.58.101:57300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/temp.bak"] [unique_id "al9IACBMYeh5YLVG45xhXwAAAok"]
[Tue Jul 21 07:20:48.864704 2026] [security2:error] [pid 229246:tid 229428] [client 20.151.10.161:45933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9IACBMYeh5YLVG45xhYAAAAkg"]
[Tue Jul 21 07:20:48.928397 2026] [security2:error] [pid 230252:tid 230502] [client 114.119.151.63:61733] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "oticapersona.com.br"] [uri "/produto/oculos-speedo-sp3037"] [unique_id "al9IAE0Dwhk5-Z44Xro8XQAAAw8"], referer: https://oticapersona.com.br/categoria-produto/speedo
[Tue Jul 21 07:20:48.985062 2026] [security2:error] [pid 229246:tid 229429] [client 20.151.10.161:55233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9IACBMYeh5YLVG45xhYwAAAkk"]
[Tue Jul 21 07:20:49.242002 2026] [security2:error] [pid 229246:tid 229439] [client 4.204.201.85:17880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/file.php"] [unique_id "al9IASBMYeh5YLVG45xhaAAAAlM"]
[Tue Jul 21 07:20:49.347202 2026] [http2:warn] [pid 230252:tid 230408] [client 57.141.18.33:39370] h2_stream(230252-17-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:49.411679 2026] [security2:error] [pid 230252:tid 230439] [client 20.151.10.161:12083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file.php"] [unique_id "al9IAU0Dwhk5-Z44Xro8XgAAAtA"]
[Tue Jul 21 07:20:49.483991 2026] [security2:error] [pid 230252:tid 230495] [client 20.197.192.193:6363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/ms.php"] [unique_id "al9IAU0Dwhk5-Z44Xro8XwAAAwg"]
[Tue Jul 21 07:20:49.641214 2026] [security2:error] [pid 229246:tid 229452] [client 20.220.225.223:36845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/track.php"] [unique_id "al9IASBMYeh5YLVG45xhgAAAAmA"]
[Tue Jul 21 07:20:49.776119 2026] [security2:error] [pid 229246:tid 229435] [client 20.151.10.161:45974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/gettest.php"] [unique_id "al9IASBMYeh5YLVG45xhgwAAAk8"]
[Tue Jul 21 07:20:49.827071 2026] [security2:error] [pid 229246:tid 229371] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IASBMYeh5YLVG45xhhQACJXw"]
[Tue Jul 21 07:20:49.827209 2026] [security2:error] [pid 229246:tid 229393] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IASBMYeh5YLVG45xhhQACJXw"]
[Tue Jul 21 07:20:49.851365 2026] [security2:error] [pid 229246:tid 229392] [client 20.151.10.161:55245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/cfile.php"] [unique_id "al9IASBMYeh5YLVG45xhhgAAAiQ"]
[Tue Jul 21 07:20:49.887181 2026] [http2:warn] [pid 230252:tid 230479] [client 57.141.18.109:26718] h2_stream(230252-20-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:50.022912 2026] [security2:error] [pid 229246:tid 229503] [client 4.204.201.85:17881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/777.php"] [unique_id "al9IAiBMYeh5YLVG45xhkAAAApM"]
[Tue Jul 21 07:20:50.050698 2026] [security2:error] [pid 230252:tid 230410] [client 20.220.225.223:47817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/tkikikoko.php"] [unique_id "al9IAk0Dwhk5-Z44Xro8YwAAArM"]
[Tue Jul 21 07:20:50.051651 2026] [qos:error] [pid 229246:tid 229395] [client 162.241.63.68:34672] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9IAiBMYeh5YLVG45xhkwAAAic
[Tue Jul 21 07:20:50.116790 2026] [http2:warn] [pid 229246:tid 229476] [client 57.141.18.12:49452] h2_stream(229246-252-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:50.329957 2026] [security2:error] [pid 229246:tid 229444] [client 20.151.10.161:55263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/class-wp.php"] [unique_id "al9IAiBMYeh5YLVG45xhmgAAAlg"]
[Tue Jul 21 07:20:50.437567 2026] [security2:error] [pid 229246:tid 229453] [client 20.220.225.223:40875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/2352356666.php"] [unique_id "al9IAiBMYeh5YLVG45xhnQAAAmE"]
[Tue Jul 21 07:20:50.444990 2026] [security2:error] [pid 229246:tid 229450] [client 20.104.96.117:59693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/pucci.php"] [unique_id "al9IAiBMYeh5YLVG45xhngAAAl4"]
[Tue Jul 21 07:20:50.507717 2026] [security2:error] [pid 229246:tid 229382] [client 20.151.10.161:46049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/simple.php"] [unique_id "al9IAiBMYeh5YLVG45xhowAAAho"]
[Tue Jul 21 07:20:50.614719 2026] [security2:error] [pid 230252:tid 230462] [client 4.204.201.85:17904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/ssixta.php"] [unique_id "al9IAk0Dwhk5-Z44Xro8ZAAAAuc"]
[Tue Jul 21 07:20:50.634509 2026] [security2:error] [pid 230252:tid 230458] [client 68.235.38.2:35902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9IAk0Dwhk5-Z44Xro8ZgAAAuM"]
[Tue Jul 21 07:20:50.634604 2026] [security2:error] [pid 230252:tid 230458] [client 68.235.38.2:35902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9IAk0Dwhk5-Z44Xro8ZgAAAuM"]
[Tue Jul 21 07:20:50.732060 2026] [security2:error] [pid 230252:tid 230414] [client 20.151.10.161:12080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/admin.php"] [unique_id "al9IAk0Dwhk5-Z44Xro8ZwAAArc"]
[Tue Jul 21 07:20:50.774510 2026] [security2:error] [pid 229246:tid 229497] [client 92.119.178.3:44372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9IAiBMYeh5YLVG45xhqgAAAo0"]
[Tue Jul 21 07:20:50.774615 2026] [security2:error] [pid 229246:tid 229497] [client 92.119.178.3:44372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9IAiBMYeh5YLVG45xhqgAAAo0"]
[Tue Jul 21 07:20:50.907732 2026] [security2:error] [pid 230252:tid 230510] [client 20.151.10.161:46070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xxx.php"] [unique_id "al9IAk0Dwhk5-Z44Xro8aAAAAxc"]
[Tue Jul 21 07:20:51.151587 2026] [security2:error] [pid 229246:tid 229274] [remote 156.59.198.136:29550] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "powerflats.com.br"] [uri "/wp-content/uploads/2025/08/photo30-1-592x444.webp"] [unique_id "al9IAyBMYeh5YLVG45xhtwACexs"], referer: https://powerflats.com.br/condominio/nex-one-pinheiros/
[Tue Jul 21 07:20:51.322065 2026] [security2:error] [pid 230252:tid 230481] [client 20.151.10.161:46028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/hypo.php"] [unique_id "al9IA00Dwhk5-Z44Xro8aQAAAvo"]
[Tue Jul 21 07:20:51.368038 2026] [security2:error] [pid 229246:tid 229435] [client 173.252.95.36:64606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9IAyBMYeh5YLVG45xhuQAAAk8"]
[Tue Jul 21 07:20:51.459988 2026] [security2:error] [pid 229246:tid 229470] [client 4.204.201.85:17895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/1c.php"] [unique_id "al9IAyBMYeh5YLVG45xhwQAAAnI"]
[Tue Jul 21 07:20:51.680375 2026] [security2:error] [pid 229246:tid 229434] [client 103.121.156.110:62245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IAyBMYeh5YLVG45xhxAAAAk4"]
[Tue Jul 21 07:20:51.680514 2026] [security2:error] [pid 229246:tid 229434] [client 103.121.156.110:62245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IAyBMYeh5YLVG45xhxAAAAk4"]
[Tue Jul 21 07:20:51.680692 2026] [security2:error] [pid 229246:tid 229480] [client 103.162.129.114:61170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IAyBMYeh5YLVG45xhxQAAAnw"]
[Tue Jul 21 07:20:51.680800 2026] [security2:error] [pid 229246:tid 229480] [client 103.162.129.114:61170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IAyBMYeh5YLVG45xhxQAAAnw"]
[Tue Jul 21 07:20:51.791228 2026] [security2:error] [pid 229246:tid 229453] [client 20.151.10.161:53595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/aa2.php"] [unique_id "al9IAyBMYeh5YLVG45xhxwAAAmE"]
[Tue Jul 21 07:20:51.828903 2026] [http2:warn] [pid 230252:tid 230420] [client 57.141.18.80:23700] h2_stream(230252-25-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:51.875191 2026] [security2:error] [pid 229246:tid 229450] [client 20.220.225.223:47869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9IAyBMYeh5YLVG45xhyAAAAl4"]
[Tue Jul 21 07:20:51.959670 2026] [security2:error] [pid 230252:tid 230485] [client 20.104.96.117:59164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/black.php"] [unique_id "al9IA00Dwhk5-Z44Xro8bQAAAv4"]
[Tue Jul 21 07:20:51.994632 2026] [security2:error] [pid 230252:tid 230501] [client 114.119.136.64:49323] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.vivaconcierge.com.br"] [uri "/wp-content/uploads/2018/09/04-23-142-1170x738.jpg"] [unique_id "al9IA00Dwhk5-Z44Xro8bwAAAw4"], referer: https://www.vivaconcierge.com.br/wp-content/uploads/2018/09/04-23-142-1170x738.jpg
[Tue Jul 21 07:20:52.002404 2026] [security2:error] [pid 230252:tid 230473] [client 20.151.10.161:45897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/chosen.php"] [unique_id "al9IBE0Dwhk5-Z44Xro8cAAAAvI"]
[Tue Jul 21 07:20:52.027065 2026] [security2:error] [pid 230252:tid 230465] [client 134.19.179.187:53484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9IBE0Dwhk5-Z44Xro8cQAAAuo"]
[Tue Jul 21 07:20:52.027191 2026] [security2:error] [pid 230252:tid 230465] [client 134.19.179.187:53484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9IBE0Dwhk5-Z44Xro8cQAAAuo"]
[Tue Jul 21 07:20:52.143536 2026] [security2:error] [pid 229246:tid 229439] [client 136.144.33.104:49553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IBCBMYeh5YLVG45xhygAAAlM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:52.199059 2026] [security2:error] [pid 229246:tid 229449] [client 105.96.79.38:60876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.79.96.105.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giovanaviana.online"] [uri "/xmlrpc.php"] [unique_id "al9IAyBMYeh5YLVG45xhuAAAAl0"]
[Tue Jul 21 07:20:52.199275 2026] [security2:error] [pid 229246:tid 229449] [client 105.96.79.38:60876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giovanaviana.online"] [uri "/xmlrpc.php"] [unique_id "al9IAyBMYeh5YLVG45xhuAAAAl0"]
[Tue Jul 21 07:20:52.297977 2026] [security2:error] [pid 230252:tid 230428] [client 20.151.10.161:12068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ccou.php"] [unique_id "al9IBE0Dwhk5-Z44Xro8dAAAAsU"]
[Tue Jul 21 07:20:52.307913 2026] [http2:warn] [pid 230252:tid 230431] [client 57.141.18.49:20468] h2_stream(230252-26-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:52.342515 2026] [security2:error] [pid 230252:tid 230412] [client 74.249.245.134:49971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/404.php"] [unique_id "al9IBE0Dwhk5-Z44Xro8dQAAArU"]
[Tue Jul 21 07:20:52.564648 2026] [security2:error] [pid 230252:tid 230378] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IBE0Dwhk5-Z44Xro8dgAC0Hs"]
[Tue Jul 21 07:20:52.564843 2026] [security2:error] [pid 230252:tid 230439] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IBE0Dwhk5-Z44Xro8dgAC0Hs"]
[Tue Jul 21 07:20:52.683742 2026] [security2:error] [pid 229246:tid 229466] [client 20.151.10.161:45982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/als.php"] [unique_id "al9IBCBMYeh5YLVG45xh0QAAAm4"]
[Tue Jul 21 07:20:52.897292 2026] [http2:warn] [pid 230252:tid 230441] [client 57.141.18.14:55194] h2_stream(230252-27-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:52.929669 2026] [security2:error] [pid 229246:tid 229436] [client 20.104.96.117:59651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/zlece.php"] [unique_id "al9IBCBMYeh5YLVG45xh1QAAAlA"]
[Tue Jul 21 07:20:52.977061 2026] [security2:error] [pid 230252:tid 230486] [client 68.235.38.2:35918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9IBE0Dwhk5-Z44Xro8eAAAAv8"]
[Tue Jul 21 07:20:52.977177 2026] [security2:error] [pid 230252:tid 230486] [client 68.235.38.2:35918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9IBE0Dwhk5-Z44Xro8eAAAAv8"]
[Tue Jul 21 07:20:52.996997 2026] [security2:error] [pid 230252:tid 230458] [client 4.204.201.85:17911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/test2.php"] [unique_id "al9IBE0Dwhk5-Z44Xro8eQAAAuM"]
[Tue Jul 21 07:20:53.099423 2026] [security2:error] [pid 230252:tid 230342] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IBU0Dwhk5-Z44Xro8ewAC9Vc"]
[Tue Jul 21 07:20:53.099620 2026] [security2:error] [pid 230252:tid 230476] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IBU0Dwhk5-Z44Xro8ewAC9Vc"]
[Tue Jul 21 07:20:53.103667 2026] [security2:error] [pid 230252:tid 230426] [client 114.119.137.28:35199] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jandel.com.br"] [uri "/ldwy6t6/waterford-crystal-made-in-germany"] [unique_id "al9IBU0Dwhk5-Z44Xro8fAAAAsM"], referer: https://jandel.com.br/ldwy6t6/waterford-crystal-made-in-germany
[Tue Jul 21 07:20:53.231927 2026] [core:alert] [pid 229246:tid 229381] [client 57.141.18.25:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:20:53.514029 2026] [http2:warn] [pid 230252:tid 230488] [client 57.141.18.55:53226] h2_stream(230252-30-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:53.531236 2026] [security2:error] [pid 229246:tid 229503] [client 20.151.10.161:45984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/pol.php"] [unique_id "al9IBSBMYeh5YLVG45xh3gAAApM"]
[Tue Jul 21 07:20:53.753235 2026] [security2:error] [pid 229246:tid 229495] [client 14.139.42.196:13493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IBSBMYeh5YLVG45xh4gAAAos"]
[Tue Jul 21 07:20:53.753393 2026] [security2:error] [pid 229246:tid 229495] [client 14.139.42.196:13493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IBSBMYeh5YLVG45xh4gAAAos"]
[Tue Jul 21 07:20:54.016238 2026] [security2:error] [pid 229246:tid 229387] [client 20.220.225.223:43041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/wp-css.php"] [unique_id "al9IBiBMYeh5YLVG45xh5gAAAh8"]
[Tue Jul 21 07:20:54.144828 2026] [security2:error] [pid 229246:tid 229348] [remote 152.53.111.131:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/wp-login.php"] [unique_id "al9IBiBMYeh5YLVG45xh5wACWGU"]
[Tue Jul 21 07:20:54.199890 2026] [security2:error] [pid 230252:tid 230465] [client 20.151.10.161:45968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file5.php"] [unique_id "al9IBk0Dwhk5-Z44Xro8igAAAuo"]
[Tue Jul 21 07:20:54.253008 2026] [security2:error] [pid 230252:tid 230511] [client 20.104.96.117:59650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/vssrs.php"] [unique_id "al9IBk0Dwhk5-Z44Xro8iwAAAxg"]
[Tue Jul 21 07:20:54.348992 2026] [security2:error] [pid 229246:tid 229403] [client 4.204.201.85:44009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/buy.php"] [unique_id "al9IBiBMYeh5YLVG45xh7QAAAi8"]
[Tue Jul 21 07:20:54.455577 2026] [security2:error] [pid 230252:tid 230430] [client 20.151.10.161:53621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/dr.php"] [unique_id "al9IBk0Dwhk5-Z44Xro8jQAAAsc"]
[Tue Jul 21 07:20:54.496577 2026] [security2:error] [pid 230252:tid 230501] [client 45.251.232.145:63733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IBk0Dwhk5-Z44Xro8kAAAAw4"]
[Tue Jul 21 07:20:54.496719 2026] [security2:error] [pid 230252:tid 230501] [client 45.251.232.145:63733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IBk0Dwhk5-Z44Xro8kAAAAw4"]
[Tue Jul 21 07:20:54.634881 2026] [security2:error] [pid 230252:tid 230496] [client 20.151.10.161:45891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9IBk0Dwhk5-Z44Xro8kQAAAwk"]
[Tue Jul 21 07:20:54.881271 2026] [http2:warn] [pid 230252:tid 230398] [client 57.141.18.44:24762] h2_stream(230252-32-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:54.882162 2026] [security2:error] [pid 230252:tid 230489] [client 20.220.225.223:34207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/2352356666.php"] [unique_id "al9IBk0Dwhk5-Z44Xro8kgAAAwI"]
[Tue Jul 21 07:20:54.979631 2026] [security2:error] [pid 229246:tid 229391] [client 92.119.178.3:44374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9IBiBMYeh5YLVG45xh9gAAAiM"]
[Tue Jul 21 07:20:54.979745 2026] [security2:error] [pid 229246:tid 229391] [client 92.119.178.3:44374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9IBiBMYeh5YLVG45xh9gAAAiM"]
[Tue Jul 21 07:20:55.012914 2026] [security2:error] [pid 230252:tid 230353] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IB00Dwhk5-Z44Xro8kwAC0GI"]
[Tue Jul 21 07:20:55.013100 2026] [security2:error] [pid 230252:tid 230439] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IB00Dwhk5-Z44Xro8kwAC0GI"]
[Tue Jul 21 07:20:55.032737 2026] [security2:error] [pid 230252:tid 230486] [client 4.204.201.85:17823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/ssend.php"] [unique_id "al9IB00Dwhk5-Z44Xro8lAAAAv8"]
[Tue Jul 21 07:20:55.148307 2026] [security2:error] [pid 230252:tid 230426] [client 20.151.10.161:46027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file.php"] [unique_id "al9IB00Dwhk5-Z44Xro8lgAAAsM"]
[Tue Jul 21 07:20:55.275151 2026] [http2:warn] [pid 229246:tid 229488] [client 57.141.18.102:37838] h2_stream(229246-260-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:55.304582 2026] [security2:error] [pid 229246:tid 229497] [client 20.220.225.223:43050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/wp-explorer.php"] [unique_id "al9IByBMYeh5YLVG45xh-wAAAo0"]
[Tue Jul 21 07:20:55.514188 2026] [security2:error] [pid 230252:tid 230424] [client 20.151.10.161:45976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/cfile.php"] [unique_id "al9IB00Dwhk5-Z44Xro8nwAAAsE"]
[Tue Jul 21 07:20:55.661870 2026] [security2:error] [pid 230252:tid 230464] [client 4.204.201.85:17812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/item.php"] [unique_id "al9IB00Dwhk5-Z44Xro8oAAAAuk"]
[Tue Jul 21 07:20:55.808419 2026] [security2:error] [pid 229246:tid 229392] [client 20.104.96.117:59158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wicked.php"] [unique_id "al9IByBMYeh5YLVG45xiBQAAAiQ"]
[Tue Jul 21 07:20:55.830331 2026] [security2:error] [pid 229246:tid 229484] [client 34.86.210.0:52702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.210.86.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "unigein.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IByBMYeh5YLVG45xiBgAAAoA"]
[Tue Jul 21 07:20:55.830419 2026] [security2:error] [pid 229246:tid 229484] [client 34.86.210.0:52702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "unigein.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IByBMYeh5YLVG45xiBgAAAoA"]
[Tue Jul 21 07:20:55.874960 2026] [security2:error] [pid 230252:tid 230440] [client 20.151.10.161:46079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/class-wp.php"] [unique_id "al9IB00Dwhk5-Z44Xro8ogAAAtE"]
[Tue Jul 21 07:20:55.938464 2026] [security2:error] [pid 230252:tid 230430] [client 20.206.105.145:30669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9IB00Dwhk5-Z44Xro8owAAAsc"]
[Tue Jul 21 07:20:55.975869 2026] [security2:error] [pid 230252:tid 230428] [client 74.7.230.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.agrocibus.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "al9IB00Dwhk5-Z44Xro8pAAAAsU"]
[Tue Jul 21 07:20:56.093279 2026] [security2:error] [pid 229246:tid 229335] [remote 178.18.124.148:36070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.124.18.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9ICCBMYeh5YLVG45xiDQACkVg"]
[Tue Jul 21 07:20:56.292451 2026] [security2:error] [pid 230252:tid 230496] [client 20.151.10.161:45890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/admin.php"] [unique_id "al9ICE0Dwhk5-Z44Xro8pwAAAwk"]
[Tue Jul 21 07:20:56.372238 2026] [security2:error] [pid 230252:tid 230471] [client 4.204.201.85:17874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/ss.php"] [unique_id "al9ICE0Dwhk5-Z44Xro8qAAAAvA"]
[Tue Jul 21 07:20:56.410397 2026] [security2:error] [pid 230252:tid 230410] [client 136.144.33.99:32859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9ICE0Dwhk5-Z44Xro8pgAAArM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:56.418269 2026] [security2:error] [pid 230252:tid 230419] [client 20.151.10.161:55283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xamp.php"] [unique_id "al9ICE0Dwhk5-Z44Xro8vgAAArw"]
[Tue Jul 21 07:20:56.749473 2026] [http2:warn] [pid 229246:tid 229451] [client 57.141.18.64:53814] h2_stream(229246-262-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:56.876109 2026] [security2:error] [pid 230252:tid 230476] [client 114.119.158.18:56025] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gradiente.com"] [uri "/site/produtos/view.asp"] [unique_id "al9ICE0Dwhk5-Z44Xro8wgAAAvU"], referer: https://www.bernabauer.com/gradiente-gf930/
[Tue Jul 21 07:20:57.020677 2026] [security2:error] [pid 230252:tid 230401] [client 20.151.10.161:45853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/aa2.php"] [unique_id "al9ICU0Dwhk5-Z44Xro8xgAAAqo"]
[Tue Jul 21 07:20:57.156097 2026] [security2:error] [pid 229246:tid 229404] [client 20.220.225.223:52793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/pn.php"] [unique_id "al9ICSBMYeh5YLVG45xiFwAAAjA"]
[Tue Jul 21 07:20:57.159017 2026] [security2:error] [pid 230252:tid 230510] [client 4.204.201.85:17913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/hypo.php"] [unique_id "al9ICU0Dwhk5-Z44Xro8ygAAAxc"]
[Tue Jul 21 07:20:57.346493 2026] [http2:warn] [pid 230252:tid 230478] [client 57.141.18.97:23062] h2_stream(230252-40-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:57.497596 2026] [security2:error] [pid 230252:tid 230424] [client 20.206.105.145:30661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9ICU0Dwhk5-Z44Xro8zgAAAsE"]
[Tue Jul 21 07:20:57.703064 2026] [security2:error] [pid 230252:tid 230283] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9ICU0Dwhk5-Z44Xro80gACrx0"]
[Tue Jul 21 07:20:57.703238 2026] [security2:error] [pid 230252:tid 230406] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9ICU0Dwhk5-Z44Xro80gACrx0"]
[Tue Jul 21 07:20:57.768076 2026] [security2:error] [pid 230252:tid 230408] [client 20.220.225.223:59496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/akismet.php"] [unique_id "al9ICU0Dwhk5-Z44Xro80wAAArE"]
[Tue Jul 21 07:20:57.962947 2026] [security2:error] [pid 230252:tid 230464] [client 20.104.96.117:59180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/24.php"] [unique_id "al9ICU0Dwhk5-Z44Xro81AAAAuk"]
[Tue Jul 21 07:20:57.977452 2026] [security2:error] [pid 230252:tid 230452] [client 4.204.201.85:17873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/users.php"] [unique_id "al9ICU0Dwhk5-Z44Xro81QAAAt0"]
[Tue Jul 21 07:20:58.065625 2026] [security2:error] [pid 230252:tid 230312] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ICk0Dwhk5-Z44Xro82AACtzo"]
[Tue Jul 21 07:20:58.065775 2026] [security2:error] [pid 230252:tid 230414] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ICk0Dwhk5-Z44Xro82AACtzo"]
[Tue Jul 21 07:20:58.174327 2026] [security2:error] [pid 230252:tid 230457] [client 20.151.10.161:45919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ccou.php"] [unique_id "al9ICk0Dwhk5-Z44Xro83AAAAuI"]
[Tue Jul 21 07:20:58.176147 2026] [security2:error] [pid 229246:tid 229487] [client 20.151.10.161:12059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/bless.php"] [unique_id "al9ICiBMYeh5YLVG45xiIwAAAoM"]
[Tue Jul 21 07:20:58.397893 2026] [security2:error] [pid 230252:tid 230357] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ICk0Dwhk5-Z44Xro85AACnGY"]
[Tue Jul 21 07:20:58.398014 2026] [security2:error] [pid 230252:tid 230387] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ICk0Dwhk5-Z44Xro85AACnGY"]
[Tue Jul 21 07:20:58.599308 2026] [http2:warn] [pid 230252:tid 230403] [client 57.141.18.31:38182] h2_stream(230252-46-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:58.625472 2026] [security2:error] [pid 229246:tid 229481] [client 139.135.44.145:54494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ICiBMYeh5YLVG45xiKAAAAn0"]
[Tue Jul 21 07:20:58.625627 2026] [security2:error] [pid 229246:tid 229481] [client 139.135.44.145:54494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ICiBMYeh5YLVG45xiKAAAAn0"]
[Tue Jul 21 07:20:58.669562 2026] [security2:error] [pid 230252:tid 230439] [client 4.204.201.85:17834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/177.php"] [unique_id "al9ICk0Dwhk5-Z44Xro88AAAAtA"]
[Tue Jul 21 07:20:58.782975 2026] [security2:error] [pid 230252:tid 230441] [client 20.197.192.193:27189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/bootstrap.php"] [unique_id "al9ICk0Dwhk5-Z44Xro88QAAAtI"]
[Tue Jul 21 07:20:58.886406 2026] [security2:error] [pid 230252:tid 230428] [client 175.45.70.82:51813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ICk0Dwhk5-Z44Xro88wAAAsU"]
[Tue Jul 21 07:20:58.886567 2026] [security2:error] [pid 230252:tid 230428] [client 175.45.70.82:51813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ICk0Dwhk5-Z44Xro88wAAAsU"]
[Tue Jul 21 07:20:58.951083 2026] [security2:error] [pid 229246:tid 229503] [client 20.197.192.193:27081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/wp-editor.php"] [unique_id "al9ICiBMYeh5YLVG45xiLAAAApM"]
[Tue Jul 21 07:20:58.965514 2026] [security2:error] [pid 230252:tid 230497] [client 20.206.105.145:30692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/media.php"] [unique_id "al9ICk0Dwhk5-Z44Xro89AAAAwo"]
[Tue Jul 21 07:20:59.090553 2026] [security2:error] [pid 230252:tid 230504] [client 20.220.225.223:47831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9IC00Dwhk5-Z44Xro8-AAAAxE"]
[Tue Jul 21 07:20:59.384687 2026] [security2:error] [pid 229246:tid 229452] [client 120.61.173.56:56127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ICyBMYeh5YLVG45xiMAAAAmA"]
[Tue Jul 21 07:20:59.384890 2026] [security2:error] [pid 229246:tid 229452] [client 120.61.173.56:56127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ICyBMYeh5YLVG45xiMAAAAmA"]
[Tue Jul 21 07:20:59.395085 2026] [security2:error] [pid 230252:tid 230485] [client 92.119.178.3:59610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9IC00Dwhk5-Z44Xro9AgAAAv4"]
[Tue Jul 21 07:20:59.395227 2026] [security2:error] [pid 230252:tid 230485] [client 92.119.178.3:59610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9IC00Dwhk5-Z44Xro9AgAAAv4"]
[Tue Jul 21 07:20:59.428414 2026] [security2:error] [pid 229246:tid 229410] [client 20.226.60.151:54479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/iywwi.php"] [unique_id "al9ICyBMYeh5YLVG45xiMQAAAjY"]
[Tue Jul 21 07:20:59.491103 2026] [http2:warn] [pid 230252:tid 230455] [client 57.141.18.75:31802] h2_stream(230252-50-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:59.518332 2026] [security2:error] [pid 229246:tid 229401] [client 114.119.136.139:54203] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "transitoaberto.com.br"] [uri "/pat-disponibiliza-635-vagas-de-emprego-em-varias-areas-em-sao-jose/"] [unique_id "al9ICyBMYeh5YLVG45xiMgAAAi0"], referer: https://transitoaberto.com.br/post-sitemap7.xml
[Tue Jul 21 07:20:59.567534 2026] [security2:error] [pid 230252:tid 230465] [client 4.204.201.85:17868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/config.php"] [unique_id "al9IC00Dwhk5-Z44Xro9BgAAAuo"]
[Tue Jul 21 07:20:59.923326 2026] [security2:error] [pid 230252:tid 230398] [client 20.220.225.223:34270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/pn.php"] [unique_id "al9IC00Dwhk5-Z44Xro9EgAAAqc"]
[Tue Jul 21 07:20:59.979887 2026] [security2:error] [pid 229246:tid 229477] [client 20.104.96.117:59152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/xacs.php"] [unique_id "al9ICyBMYeh5YLVG45xiNgAAAnk"]
[Tue Jul 21 07:21:00.382509 2026] [security2:error] [pid 229246:tid 229284] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IDCBMYeh5YLVG45xiOwACfCU"]
[Tue Jul 21 07:21:00.382641 2026] [security2:error] [pid 229246:tid 229480] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IDCBMYeh5YLVG45xiOwACfCU"]
[Tue Jul 21 07:21:00.504575 2026] [security2:error] [pid 229246:tid 229429] [client 20.206.105.145:30597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/images.php"] [unique_id "al9IDCBMYeh5YLVG45xiPgAAAkk"]
[Tue Jul 21 07:21:00.547243 2026] [security2:error] [pid 230252:tid 230493] [client 20.220.225.223:40859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/ace2.php"] [unique_id "al9IDE0Dwhk5-Z44Xro9JAAAAwY"]
[Tue Jul 21 07:21:00.570457 2026] [http2:warn] [pid 230252:tid 230509] [client 57.141.18.115:47810] h2_stream(230252-51-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:00.775248 2026] [security2:error] [pid 229246:tid 229430] [client 4.204.201.85:44002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/gettest.php"] [unique_id "al9IDCBMYeh5YLVG45xiQQAAAko"]
[Tue Jul 21 07:21:00.873480 2026] [security2:error] [pid 229246:tid 229454] [client 20.151.10.161:12045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file46.php"] [unique_id "al9IDCBMYeh5YLVG45xiRAAAAmI"]
[Tue Jul 21 07:21:00.911922 2026] [security2:error] [pid 230252:tid 230425] [client 20.151.10.161:45964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/dr.php"] [unique_id "al9IDE0Dwhk5-Z44Xro9LQAAAsI"]
[Tue Jul 21 07:21:00.944190 2026] [security2:error] [pid 230252:tid 230481] [client 74.249.245.134:61928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/file3.php"] [unique_id "al9IDE0Dwhk5-Z44Xro9LgAAAvo"]
[Tue Jul 21 07:21:00.956415 2026] [security2:error] [pid 230252:tid 230454] [client 193.36.225.54:62433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IDE0Dwhk5-Z44Xro9LwAAAt8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:01.507823 2026] [http2:warn] [pid 229246:tid 229447] [client 57.141.18.2:26722] h2_stream(229246-275-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:01.526880 2026] [security2:error] [pid 230252:tid 230457] [client 20.206.105.145:30681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/adminner.php"] [unique_id "al9IDU0Dwhk5-Z44Xro9PAAAAuI"]
[Tue Jul 21 07:21:01.587457 2026] [security2:error] [pid 230252:tid 230495] [client 20.104.96.117:59663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/zildan.php"] [unique_id "al9IDU0Dwhk5-Z44Xro9PgAAAwg"]
[Tue Jul 21 07:21:01.616879 2026] [security2:error] [pid 230252:tid 230445] [client 20.197.192.193:27100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/cro.php"] [unique_id "al9IDU0Dwhk5-Z44Xro9QgAAAtY"]
[Tue Jul 21 07:21:01.635784 2026] [security2:error] [pid 229246:tid 229275] [remote 199.189.225.40:50855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/wp-login.php"] [unique_id "al9IDSBMYeh5YLVG45xiSgACjRw"]
[Tue Jul 21 07:21:01.837630 2026] [security2:error] [pid 230252:tid 230486] [client 4.204.201.85:17822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/min.php"] [unique_id "al9IDU0Dwhk5-Z44Xro9TAAAAv8"]
[Tue Jul 21 07:21:02.113022 2026] [security2:error] [pid 229246:tid 229471] [client 20.220.225.223:59495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/dr.php"] [unique_id "al9IDiBMYeh5YLVG45xiUAAAAnM"]
[Tue Jul 21 07:21:02.211368 2026] [http2:warn] [pid 230252:tid 230456] [client 57.141.18.22:61362] h2_stream(230252-56-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:02.352997 2026] [security2:error] [pid 230252:tid 230481] [client 20.206.105.145:30697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/admin.php"] [unique_id "al9IDk0Dwhk5-Z44Xro9WQAAAvo"]
[Tue Jul 21 07:21:02.405054 2026] [security2:error] [pid 230252:tid 230399] [client 103.121.156.110:62572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IDk0Dwhk5-Z44Xro9WwAAAqg"]
[Tue Jul 21 07:21:02.405200 2026] [security2:error] [pid 230252:tid 230399] [client 103.121.156.110:62572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IDk0Dwhk5-Z44Xro9WwAAAqg"]
[Tue Jul 21 07:21:02.426093 2026] [security2:error] [pid 230252:tid 230395] [client 103.162.129.114:61811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IDk0Dwhk5-Z44Xro9XAAAAqQ"]
[Tue Jul 21 07:21:02.426216 2026] [security2:error] [pid 230252:tid 230395] [client 103.162.129.114:61811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IDk0Dwhk5-Z44Xro9XAAAAqQ"]
[Tue Jul 21 07:21:02.479576 2026] [security2:error] [pid 229246:tid 229334] [remote 114.119.143.77:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "androapkmod.com"] [uri "/scavenger-hunt-mod-apk/"] [unique_id "al9IDiBMYeh5YLVG45xiVwACe1c"], referer: https://xn--r1a.website/s/androapkmodoficial/57206
[Tue Jul 21 07:21:02.492964 2026] [security2:error] [pid 229246:tid 229435] [client 20.220.225.223:47837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/ms.php"] [unique_id "al9IDiBMYeh5YLVG45xiWAAAAk8"]
[Tue Jul 21 07:21:02.508009 2026] [security2:error] [pid 230252:tid 230440] [client 20.151.10.161:45945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xamp.php"] [unique_id "al9IDk0Dwhk5-Z44Xro9YQAAAtE"]
[Tue Jul 21 07:21:02.630457 2026] [http2:warn] [pid 229246:tid 229396] [client 57.141.18.11:37344] h2_stream(229246-280-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:02.773254 2026] [security2:error] [pid 230252:tid 230495] [client 4.204.201.85:43842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/dvjul.php"] [unique_id "al9IDk0Dwhk5-Z44Xro9bgAAAwg"]
[Tue Jul 21 07:21:02.938317 2026] [fcgid:warn] [pid 230252:tid 230493] (70014)End of file found: [client 66.132.195.50:41594] mod_fcgid: can't get data from http client
[Tue Jul 21 07:21:03.014330 2026] [security2:error] [pid 230252:tid 230402] [client 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/wp-admin/install.php"] [unique_id "al9ID00Dwhk5-Z44Xro9fwAAAqs"]
[Tue Jul 21 07:21:03.126707 2026] [http2:warn] [pid 230252:tid 230421] [client 57.141.18.61:61818] h2_stream(230252-62-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:03.228094 2026] [security2:error] [pid 229246:tid 229386] [client 20.104.96.117:59146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/csa.php"] [unique_id "al9IDyBMYeh5YLVG45xiXQAAAh4"]
[Tue Jul 21 07:21:03.275093 2026] [security2:error] [pid 230252:tid 230425] [client 20.151.10.161:45975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/bless.php"] [unique_id "al9ID00Dwhk5-Z44Xro9gwAAAsI"]
[Tue Jul 21 07:21:03.300334 2026] [security2:error] [pid 229246:tid 229387] [client 4.204.201.85:17903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/biufile.php"] [unique_id "al9IDyBMYeh5YLVG45xiYAAAAh8"]
[Tue Jul 21 07:21:03.335402 2026] [security2:error] [pid 229246:tid 229380] [client 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9IDyBMYeh5YLVG45xiYgAAAhg"]
[Tue Jul 21 07:21:03.364384 2026] [security2:error] [pid 230252:tid 230267] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ID00Dwhk5-Z44Xro9hwACqg0"]
[Tue Jul 21 07:21:03.364567 2026] [security2:error] [pid 230252:tid 230401] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ID00Dwhk5-Z44Xro9hwACqg0"]
[Tue Jul 21 07:21:03.450142 2026] [security2:error] [pid 230252:tid 230488] [client 20.220.225.223:34178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9ID00Dwhk5-Z44Xro9iAAAAwE"]
[Tue Jul 21 07:21:03.558371 2026] [security2:error] [pid 229246:tid 229450] [client 20.206.105.145:30610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/k.php"] [unique_id "al9IDyBMYeh5YLVG45xiZgAAAl4"]
[Tue Jul 21 07:21:03.571673 2026] [security2:error] [pid 229246:tid 229310] [remote 173.252.70.23:65496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.70.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9IDyBMYeh5YLVG45xiZAACeT8"]
[Tue Jul 21 07:21:03.666959 2026] [security2:error] [pid 230252:tid 230360] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9ID00Dwhk5-Z44Xro9kwACwGk"]
[Tue Jul 21 07:21:03.667170 2026] [security2:error] [pid 230252:tid 230423] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9ID00Dwhk5-Z44Xro9kwACwGk"]
[Tue Jul 21 07:21:03.712261 2026] [security2:error] [pid 229246:tid 229404] [client 20.151.10.161:45970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file46.php"] [unique_id "al9IDyBMYeh5YLVG45xiagAAAjA"]
[Tue Jul 21 07:21:03.950695 2026] [security2:error] [pid 229246:tid 229454] [client 20.220.225.223:36851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/2x.php"] [unique_id "al9IDyBMYeh5YLVG45xibQAAAmI"]
[Tue Jul 21 07:21:04.072493 2026] [security2:error] [pid 229246:tid 229424] [client 20.151.10.161:46010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/eee.php"] [unique_id "al9IECBMYeh5YLVG45xibgAAAkQ"]
[Tue Jul 21 07:21:04.305276 2026] [security2:error] [pid 229246:tid 229460] [client 114.119.130.14:40031] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gfacil.com.br"] [uri "/201-6188336/nic-nucleo-intensivo-de-cursos-ltda/detalhe.html"] [unique_id "al9IECBMYeh5YLVG45xicwAAAmg"], referer: https://www.pages24.com.br/rio-de-janeiro-rj/61717-nic-nucleo-intensivo-de-cursos-ltda
[Tue Jul 21 07:21:04.309691 2026] [security2:error] [pid 230252:tid 230395] [client 20.151.10.161:11719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/eee.php"] [unique_id "al9IEE0Dwhk5-Z44Xro9qAAAAqQ"]
[Tue Jul 21 07:21:04.367023 2026] [security2:error] [pid 230252:tid 230384] [client 20.151.10.161:45961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file25.php"] [unique_id "al9IEE0Dwhk5-Z44Xro9qgAAApk"]
[Tue Jul 21 07:21:04.526307 2026] [security2:error] [pid 230252:tid 230400] [client 14.139.42.196:10431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IEE0Dwhk5-Z44Xro9rgAAAqk"]
[Tue Jul 21 07:21:04.526465 2026] [security2:error] [pid 230252:tid 230400] [client 14.139.42.196:10431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IEE0Dwhk5-Z44Xro9rgAAAqk"]
[Tue Jul 21 07:21:04.590207 2026] [security2:error] [pid 230252:tid 230409] [client 20.206.105.145:30611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/x.php"] [unique_id "al9IEE0Dwhk5-Z44Xro9sgAAArI"]
[Tue Jul 21 07:21:04.741647 2026] [security2:error] [pid 230252:tid 230392] [client 4.204.201.85:17882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/av.php"] [unique_id "al9IEE0Dwhk5-Z44Xro9twAAAqE"]
[Tue Jul 21 07:21:04.777036 2026] [http2:warn] [pid 230252:tid 230435] [client 57.141.18.29:37052] h2_stream(230252-73-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:04.872441 2026] [security2:error] [pid 230252:tid 230398] [client 20.151.10.161:45914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file48.php"] [unique_id "al9IEE0Dwhk5-Z44Xro9uQAAAqc"]
[Tue Jul 21 07:21:04.994885 2026] [security2:error] [pid 229246:tid 229490] [client 45.251.232.145:64248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IECBMYeh5YLVG45xiegAAAoY"]
[Tue Jul 21 07:21:04.995028 2026] [security2:error] [pid 229246:tid 229490] [client 45.251.232.145:64248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IECBMYeh5YLVG45xiegAAAoY"]
[Tue Jul 21 07:21:05.299853 2026] [security2:error] [pid 230252:tid 230420] [client 20.206.105.145:30612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wss.php"] [unique_id "al9IEU0Dwhk5-Z44Xro9yQAAAr0"]
[Tue Jul 21 07:21:05.359998 2026] [security2:error] [pid 229246:tid 229481] [client 20.151.10.161:45987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file6.php"] [unique_id "al9IESBMYeh5YLVG45xifwAAAn0"]
[Tue Jul 21 07:21:05.535348 2026] [security2:error] [pid 229246:tid 229410] [client 74.249.245.134:52446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-mail.php"] [unique_id "al9IESBMYeh5YLVG45xigQAAAjY"]
[Tue Jul 21 07:21:05.560113 2026] [http2:warn] [pid 229246:tid 229408] [client 57.141.18.59:61610] h2_stream(229246-284-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:05.569242 2026] [security2:error] [pid 230252:tid 230306] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IEU0Dwhk5-Z44Xro9ywADCTQ"]
[Tue Jul 21 07:21:05.569421 2026] [security2:error] [pid 230252:tid 230496] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IEU0Dwhk5-Z44Xro9ywADCTQ"]
[Tue Jul 21 07:21:05.837050 2026] [security2:error] [pid 230252:tid 230481] [client 4.204.201.85:17893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/coffexium.php"] [unique_id "al9IEU0Dwhk5-Z44Xro90wAAAvo"]
[Tue Jul 21 07:21:05.846025 2026] [security2:error] [pid 230252:tid 230387] [client 136.144.33.107:42377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IEU0Dwhk5-Z44Xro9zgAAApw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:05.987542 2026] [security2:error] [pid 230252:tid 230440] [client 20.151.10.161:46048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/a2.php"] [unique_id "al9IEU0Dwhk5-Z44Xro91gAAAtE"]
[Tue Jul 21 07:21:06.005408 2026] [security2:error] [pid 230252:tid 230458] [client 20.220.225.223:47849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/kq1.php"] [unique_id "al9IEk0Dwhk5-Z44Xro91wAAAuM"]
[Tue Jul 21 07:21:06.062570 2026] [http2:warn] [pid 230252:tid 230463] [client 57.141.18.7:49678] h2_stream(230252-80-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:06.130529 2026] [security2:error] [pid 230252:tid 230478] [client 20.104.96.117:59191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/w3llscc.php"] [unique_id "al9IEk0Dwhk5-Z44Xro92AAAAvc"]
[Tue Jul 21 07:21:06.515359 2026] [security2:error] [pid 229246:tid 229463] [client 4.204.201.85:17916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/core.php"] [unique_id "al9IEiBMYeh5YLVG45xikgAAAms"]
[Tue Jul 21 07:21:06.555568 2026] [security2:error] [pid 229246:tid 229430] [client 20.151.10.161:45988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file15.php"] [unique_id "al9IEiBMYeh5YLVG45xilAAAAko"]
[Tue Jul 21 07:21:06.559953 2026] [security2:error] [pid 230252:tid 230404] [client 114.119.143.158:30989] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "essenceclinicadesaude.com.br"] [uri "/blog/page/4"] [unique_id "al9IEk0Dwhk5-Z44Xro94QAAAq0"], referer: https://essenceclinicadesaude.com.br/blog
[Tue Jul 21 07:21:06.850367 2026] [security2:error] [pid 229246:tid 229421] [client 20.206.105.145:30659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/ty.php"] [unique_id "al9IEiBMYeh5YLVG45ximgAAAkE"]
[Tue Jul 21 07:21:06.954359 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:53623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file25.php"] [unique_id "al9IEk0Dwhk5-Z44Xro95AAAAwY"]
[Tue Jul 21 07:21:06.965113 2026] [security2:error] [pid 229246:tid 229436] [client 4.204.201.85:17800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/als.php"] [unique_id "al9IEiBMYeh5YLVG45xinQAAAlA"]
[Tue Jul 21 07:21:07.073548 2026] [autoindex:error] [pid 229246:tid 229416] [client 135.225.181.175:1280] AH01276: Cannot serve directory /home1/edua4721/trabalhista.eduardogoesadv.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:21:07.196848 2026] [security2:error] [pid 229246:tid 229400] [client 20.151.10.161:46005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/jp.php"] [unique_id "al9IEyBMYeh5YLVG45xioAAAAiw"]
[Tue Jul 21 07:21:07.317128 2026] [security2:error] [pid 229246:tid 229496] [client 4.204.201.85:17870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/simple.php"] [unique_id "al9IEyBMYeh5YLVG45xiogAAAow"]
[Tue Jul 21 07:21:07.446825 2026] [http2:warn] [pid 230252:tid 230388] [client 57.141.18.106:50708] h2_stream(230252-87-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:07.513882 2026] [security2:error] [pid 229246:tid 229484] [client 20.151.10.161:53625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file48.php"] [unique_id "al9IEyBMYeh5YLVG45xipwAAAoA"]
[Tue Jul 21 07:21:07.545601 2026] [security2:error] [pid 229246:tid 229488] [client 20.206.105.145:30712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/155.php"] [unique_id "al9IEyBMYeh5YLVG45xiqwAAAoQ"]
[Tue Jul 21 07:21:07.549306 2026] [security2:error] [pid 229246:tid 229452] [client 74.249.245.134:21870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/about.php"] [unique_id "al9IEyBMYeh5YLVG45xirAAAAmA"]
[Tue Jul 21 07:21:07.897793 2026] [security2:error] [pid 230252:tid 230403] [client 4.204.201.85:17804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/init.php"] [unique_id "al9IE00Dwhk5-Z44Xro95gAAAqw"]
[Tue Jul 21 07:21:07.943052 2026] [security2:error] [pid 230252:tid 230507] [client 20.151.10.161:46055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/f35.php"] [unique_id "al9IE00Dwhk5-Z44Xro95wAAAxQ"]
[Tue Jul 21 07:21:08.181003 2026] [security2:error] [pid 230252:tid 230455] [client 114.119.143.75:64741] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lojadoclimatizador.com.br"] [uri "/produto-tag/p13/"] [unique_id "al9IFE0Dwhk5-Z44Xro96wAAAuA"], referer: http://lojadoclimatizador.com.br/produto/p13-inovare
[Tue Jul 21 07:21:08.217553 2026] [security2:error] [pid 230252:tid 230458] [client 20.104.96.117:59182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wpx.php"] [unique_id "al9IFE0Dwhk5-Z44Xro97AAAAuM"]
[Tue Jul 21 07:21:08.269587 2026] [security2:error] [pid 230252:tid 230436] [client 20.151.10.161:45991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-load.php"] [unique_id "al9IFE0Dwhk5-Z44Xro97gAAAs0"]
[Tue Jul 21 07:21:08.451123 2026] [security2:error] [pid 230252:tid 230399] [client 114.119.132.122:63763] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.simleite.com.br"] [uri "/album/32"] [unique_id "al9IFE0Dwhk5-Z44Xro98AAAAqg"], referer: https://www.simleite.com.br/album/32
[Tue Jul 21 07:21:08.462222 2026] [security2:error] [pid 230252:tid 230371] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IFE0Dwhk5-Z44Xro98QADCHQ"]
[Tue Jul 21 07:21:08.462389 2026] [security2:error] [pid 230252:tid 230495] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IFE0Dwhk5-Z44Xro98QADCHQ"]
[Tue Jul 21 07:21:08.501963 2026] [security2:error] [pid 229246:tid 229482] [client 20.206.105.145:30690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/ops.php"] [unique_id "al9IFCBMYeh5YLVG45xitwAAAn4"]
[Tue Jul 21 07:21:08.510851 2026] [security2:error] [pid 230252:tid 230511] [client 34.34.16.122:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "vinculampe.com.br"] [uri "/"] [unique_id "al9IFE0Dwhk5-Z44Xro98gAAAxg"]
[Tue Jul 21 07:21:08.510970 2026] [security2:error] [pid 230252:tid 230511] [client 34.34.16.122:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "vinculampe.com.br"] [uri "/"] [unique_id "al9IFE0Dwhk5-Z44Xro98gAAAxg"]
[Tue Jul 21 07:21:08.542786 2026] [security2:error] [pid 230252:tid 230408] [client 20.151.10.161:12058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file6.php"] [unique_id "al9IFE0Dwhk5-Z44Xro99AAAArE"]
[Tue Jul 21 07:21:08.589327 2026] [security2:error] [pid 230252:tid 230283] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IFE0Dwhk5-Z44Xro99gAC9x0"]
[Tue Jul 21 07:21:08.589508 2026] [security2:error] [pid 230252:tid 230478] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IFE0Dwhk5-Z44Xro99gAC9x0"]
[Tue Jul 21 07:21:08.608196 2026] [http2:warn] [pid 230252:tid 230444] [client 57.141.18.16:59356] h2_stream(230252-91-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:09.023402 2026] [security2:error] [pid 230252:tid 230297] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IFU0Dwhk5-Z44Xro9_AAC8Ss"]
[Tue Jul 21 07:21:09.023561 2026] [security2:error] [pid 230252:tid 230472] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IFU0Dwhk5-Z44Xro9_AAC8Ss"]
[Tue Jul 21 07:21:09.078327 2026] [proxy:error] [pid 230252:tid 230421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:09.078366 2026] [proxy_http:error] [pid 230252:tid 230421] [client 205.210.31.38:61000] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:09.078841 2026] [proxy:error] [pid 230252:tid 230421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:09.078875 2026] [proxy_http:error] [pid 230252:tid 230421] [client 205.210.31.38:61000] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:09.127692 2026] [http2:warn] [pid 229246:tid 229472] [client 57.141.18.92:23922] h2_stream(229246-290-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:09.134531 2026] [core:error] [pid 230252:tid 230402] [client 66.249.66.68:48595] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:21:09.134557 2026] [core:error] [pid 230252:tid 230402] [client 66.249.66.68:48595] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:21:09.164759 2026] [security2:error] [pid 230252:tid 230496] [client 114.119.157.37:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.imobiliariasobrado.net.br"] [uri "/imovel/terreno-venda-costa-e-silva-joinville-sc-v09004"] [unique_id "al9IFU0Dwhk5-Z44Xro-AwAAAwk"], referer: https://www.imobiliariasobrado.net.br/
[Tue Jul 21 07:21:09.252736 2026] [security2:error] [pid 230252:tid 230504] [client 20.220.225.223:34245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/dr.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-CAAAAxE"]
[Tue Jul 21 07:21:09.283945 2026] [security2:error] [pid 230252:tid 230455] [client 20.206.105.145:30713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/ingfo.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-CQAAAuA"]
[Tue Jul 21 07:21:09.320664 2026] [security2:error] [pid 230252:tid 230458] [client 4.204.201.85:17897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/fpwch.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-CgAAAuM"]
[Tue Jul 21 07:21:09.368356 2026] [security2:error] [pid 230252:tid 230426] [client 20.151.10.161:45912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xwpg.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-CwAAAsM"]
[Tue Jul 21 07:21:09.519387 2026] [security2:error] [pid 230252:tid 230401] [client 139.135.44.145:53378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-DAAAAqo"]
[Tue Jul 21 07:21:09.519506 2026] [security2:error] [pid 230252:tid 230401] [client 139.135.44.145:53378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-DAAAAqo"]
[Tue Jul 21 07:21:09.595316 2026] [security2:error] [pid 230252:tid 230409] [client 20.151.10.161:53612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/a2.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-DwAAArI"]
[Tue Jul 21 07:21:09.610190 2026] [security2:error] [pid 230252:tid 230435] [client 20.206.105.145:30665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/error_log.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-EAAAAsw"]
[Tue Jul 21 07:21:09.710837 2026] [security2:error] [pid 230252:tid 230497] [client 175.45.70.82:52325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-EQAAAwo"]
[Tue Jul 21 07:21:09.710981 2026] [security2:error] [pid 230252:tid 230497] [client 175.45.70.82:52325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-EQAAAwo"]
[Tue Jul 21 07:21:09.928674 2026] [security2:error] [pid 230252:tid 230282] [remote 132.148.72.88:54844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-EwACpxw"]
[Tue Jul 21 07:21:09.992232 2026] [security2:error] [pid 230252:tid 230484] [client 4.204.201.85:17900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/domvf.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-FAAAAv0"]
[Tue Jul 21 07:21:09.992806 2026] [security2:error] [pid 230252:tid 230486] [client 20.197.192.193:27075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/cron-tab.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-FQAAAv8"]
[Tue Jul 21 07:21:10.067838 2026] [security2:error] [pid 229246:tid 229414] [client 120.61.173.56:56633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IFiBMYeh5YLVG45xixQAAAjo"]
[Tue Jul 21 07:21:10.067965 2026] [security2:error] [pid 229246:tid 229414] [client 120.61.173.56:56633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IFiBMYeh5YLVG45xixQAAAjo"]
[Tue Jul 21 07:21:10.359394 2026] [security2:error] [pid 230252:tid 230509] [client 20.206.105.145:30683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/ok.php"] [unique_id "al9IFk0Dwhk5-Z44Xro-HAAAAxY"]
[Tue Jul 21 07:21:10.385422 2026] [security2:error] [pid 230252:tid 230445] [client 193.36.225.73:58655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IFk0Dwhk5-Z44Xro-HQAAAtY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:10.435250 2026] [security2:error] [pid 229246:tid 229441] [client 4.204.201.85:17861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/wp.php"] [unique_id "al9IFiBMYeh5YLVG45xiyQAAAlU"]
[Tue Jul 21 07:21:10.535461 2026] [http2:warn] [pid 229246:tid 229499] [client 57.141.18.87:56288] h2_stream(229246-292-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:10.555169 2026] [security2:error] [pid 229246:tid 229496] [client 134.19.179.187:37706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IFiBMYeh5YLVG45xiygAAAow"]
[Tue Jul 21 07:21:10.555289 2026] [security2:error] [pid 229246:tid 229496] [client 134.19.179.187:37706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IFiBMYeh5YLVG45xiygAAAow"]
[Tue Jul 21 07:21:10.717453 2026] [security2:error] [pid 229246:tid 229452] [client 20.104.96.117:59654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-css.php"] [unique_id "al9IFiBMYeh5YLVG45xi0AAAAmA"]
[Tue Jul 21 07:21:10.740082 2026] [security2:error] [pid 230252:tid 230403] [client 114.119.128.203:27961] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gradiente.com.br"] [uri "/mini-system/gradiente/Preto/139/Bluetooth/de%20101W%20at%C3%A9%20500W/Bivolt"] [unique_id "al9IFk0Dwhk5-Z44Xro-HwAAAqw"], referer: https://www.gradiente.com.br/mini-system/Preto/139/Bluetooth/de%20101W%20at%C3%A9%20500W/Bivolt?PS=12&map=c%2CspecificationFilter_21%2CproductClusterSearchableIds%2CspecificationFilter_18%2CspecificationFilter_22%2CspecificationFilter_20
[Tue Jul 21 07:21:10.760846 2026] [security2:error] [pid 230252:tid 230416] [client 92.119.178.3:49796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9IFk0Dwhk5-Z44Xro-IAAAArk"]
[Tue Jul 21 07:21:10.760937 2026] [security2:error] [pid 230252:tid 230416] [client 92.119.178.3:49796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9IFk0Dwhk5-Z44Xro-IAAAArk"]
[Tue Jul 21 07:21:10.766923 2026] [security2:error] [pid 229246:tid 229343] [remote 114.119.157.43:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aud-7.com"] [uri "/good.php"] [unique_id "al9IFiBMYeh5YLVG45xi0QACLGA"], referer: https://aud-7.com/good.php?tvvbf/t310000.html
[Tue Jul 21 07:21:10.825029 2026] [security2:error] [pid 229246:tid 229410] [client 4.204.201.85:17796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/class.php"] [unique_id "al9IFiBMYeh5YLVG45xi0gAAAjY"]
[Tue Jul 21 07:21:10.906883 2026] [security2:error] [pid 229246:tid 229476] [client 20.220.225.223:47816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/zzz.php"] [unique_id "al9IFiBMYeh5YLVG45xi1AAAAng"]
[Tue Jul 21 07:21:11.071905 2026] [security2:error] [pid 230252:tid 230354] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IF00Dwhk5-Z44Xro-IQACtmM"]
[Tue Jul 21 07:21:11.072087 2026] [security2:error] [pid 230252:tid 230413] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IF00Dwhk5-Z44Xro-IQACtmM"]
[Tue Jul 21 07:21:11.112502 2026] [http2:warn] [pid 229246:tid 229461] [client 57.141.18.115:63526] h2_stream(229246-294-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:11.173003 2026] [security2:error] [pid 230252:tid 230395] [client 114.119.144.64:42397] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ellosemijoias.com.br"] [uri "/product-category/pulseiras/pulseiras-semi-joia/"] [unique_id "al9IF00Dwhk5-Z44Xro-JAAAAqQ"], referer: https://www.ellosemijoias.com.br/product-category/pulseiras/pulseiras-semi-joia/?orderby=menu_order
[Tue Jul 21 07:21:11.434080 2026] [security2:error] [pid 230252:tid 230384] [client 4.204.201.85:17896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/echkm.php"] [unique_id "al9IF00Dwhk5-Z44Xro-JwAAApk"]
[Tue Jul 21 07:21:11.705691 2026] [security2:error] [pid 229246:tid 229429] [client 20.151.10.161:12046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file15.php"] [unique_id "al9IFyBMYeh5YLVG45xi3QAAAkk"]
[Tue Jul 21 07:21:12.171711 2026] [security2:error] [pid 229246:tid 229453] [client 20.104.96.117:59159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/ho.php"] [unique_id "al9IGCBMYeh5YLVG45xi4AAAAmE"]
[Tue Jul 21 07:21:12.227046 2026] [security2:error] [pid 230252:tid 230410] [client 20.206.105.145:30709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/mac.php"] [unique_id "al9IGE0Dwhk5-Z44Xro-MAAAArM"]
[Tue Jul 21 07:21:12.300649 2026] [security2:error] [pid 230252:tid 230445] [client 4.204.201.85:17902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/lib.php"] [unique_id "al9IGE0Dwhk5-Z44Xro-OAAAAtY"]
[Tue Jul 21 07:21:12.302737 2026] [security2:error] [pid 229246:tid 229403] [client 74.249.245.134:51019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/adminfuns.php"] [unique_id "al9IGCBMYeh5YLVG45xi4gAAAi8"]
[Tue Jul 21 07:21:12.319168 2026] [autoindex:error] [pid 229246:tid 229463] [client 205.210.31.49:58176] AH01276: Cannot serve directory /home2/tiago878/public_html/hostserv/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:21:12.427222 2026] [security2:error] [pid 230252:tid 230435] [client 47.128.37.143:13046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "drapatriciavarella.com.br"] [uri "/robots.txt"] [unique_id "al9IGE0Dwhk5-Z44Xro-OgAAAsw"]
[Tue Jul 21 07:21:12.504991 2026] [security2:error] [pid 230252:tid 230400] [client 20.226.60.151:54585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/gqgsa.php"] [unique_id "al9IGE0Dwhk5-Z44Xro-PAAAAqk"]
[Tue Jul 21 07:21:12.563580 2026] [security2:error] [pid 230252:tid 230416] [client 20.197.192.193:27101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/koiy.php"] [unique_id "al9IGE0Dwhk5-Z44Xro-PQAAArk"]
[Tue Jul 21 07:21:12.741118 2026] [http2:warn] [pid 230252:tid 230499] [client 57.141.18.82:56708] h2_stream(230252-113-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:12.823121 2026] [http2:warn] [pid 230252:tid 230450] [client 57.141.18.89:60890] h2_stream(230252-114-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:12.897006 2026] [security2:error] [pid 230252:tid 230485] [client 20.151.10.161:46000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/waf.php"] [unique_id "al9IGE0Dwhk5-Z44Xro-QgAAAv4"]
[Tue Jul 21 07:21:12.963046 2026] [security2:error] [pid 230252:tid 230426] [client 4.204.201.85:17792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/login.php"] [unique_id "al9IGE0Dwhk5-Z44Xro-QwAAAsM"]
[Tue Jul 21 07:21:13.098180 2026] [security2:error] [pid 230252:tid 230481] [client 103.121.156.110:62898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IGU0Dwhk5-Z44Xro-RgAAAvo"]
[Tue Jul 21 07:21:13.098318 2026] [security2:error] [pid 230252:tid 230481] [client 103.121.156.110:62898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IGU0Dwhk5-Z44Xro-RgAAAvo"]
[Tue Jul 21 07:21:13.250641 2026] [security2:error] [pid 229246:tid 229394] [client 103.162.129.114:62264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IGSBMYeh5YLVG45xi7wAAAiY"]
[Tue Jul 21 07:21:13.250748 2026] [security2:error] [pid 229246:tid 229394] [client 103.162.129.114:62264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IGSBMYeh5YLVG45xi7wAAAiY"]
[Tue Jul 21 07:21:13.369581 2026] [security2:error] [pid 229246:tid 229381] [client 20.220.225.223:47826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/wicked.php"] [unique_id "al9IGSBMYeh5YLVG45xi8QAAAhk"]
[Tue Jul 21 07:21:13.435819 2026] [security2:error] [pid 230252:tid 230385] [client 34.148.166.21:56900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.166.148.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/cgi-sys/suspendedpage.cgi/xmlrpc.php"] [unique_id "al9IGE0Dwhk5-Z44Xro-OwAAApo"]
[Tue Jul 21 07:21:13.440861 2026] [security2:error] [pid 229246:tid 229383] [client 20.104.96.117:59143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/xy.php"] [unique_id "al9IGSBMYeh5YLVG45xi9QAAAhs"]
[Tue Jul 21 07:21:13.532218 2026] [security2:error] [pid 229246:tid 229454] [client 4.204.201.85:17814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/a2.php"] [unique_id "al9IGSBMYeh5YLVG45xi9wAAAmI"]
[Tue Jul 21 07:21:13.676062 2026] [security2:error] [pid 230252:tid 230495] [client 34.148.166.21:57253] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "look.dealspark.com.br"] [uri "/cgi-sys/suspendedpage.cgi/web/wp-includes/wlwmanifest.xml"] [unique_id "al9IGU0Dwhk5-Z44Xro-RwAAAwg"]
[Tue Jul 21 07:21:13.760572 2026] [security2:error] [pid 229246:tid 229493] [client 20.197.192.193:27124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/hp2.php"] [unique_id "al9IGSBMYeh5YLVG45xi-gAAAok"]
[Tue Jul 21 07:21:13.902050 2026] [security2:error] [pid 230252:tid 230478] [client 20.206.105.145:30718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wefile.php"] [unique_id "al9IGU0Dwhk5-Z44Xro-SwAAAvc"]
[Tue Jul 21 07:21:13.949904 2026] [security2:error] [pid 230252:tid 230452] [client 34.148.166.21:51185] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "look.dealspark.com.br"] [uri "/cgi-sys/suspendedpage.cgi/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9IGU0Dwhk5-Z44Xro-TAAAAt0"]
[Tue Jul 21 07:21:14.059996 2026] [security2:error] [pid 229246:tid 229387] [client 4.204.201.85:17899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/d61.php"] [unique_id "al9IGiBMYeh5YLVG45xi_QAAAh8"]
[Tue Jul 21 07:21:14.178438 2026] [http2:warn] [pid 230252:tid 230386] [client 57.141.18.31:41848] h2_stream(230252-116-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:14.221345 2026] [security2:error] [pid 229246:tid 229464] [client 34.148.166.21:64274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "look.dealspark.com.br"] [uri "/cgi-sys/suspendedpage.cgi/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9IGiBMYeh5YLVG45xi_wAAAmw"]
[Tue Jul 21 07:21:14.222750 2026] [security2:error] [pid 229246:tid 229313] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IGiBMYeh5YLVG45xjAAACekI"]
[Tue Jul 21 07:21:14.222958 2026] [security2:error] [pid 229246:tid 229478] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IGiBMYeh5YLVG45xjAAACekI"]
[Tue Jul 21 07:21:14.277118 2026] [security2:error] [pid 229246:tid 229503] [client 114.119.134.106:52933] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bcsenepol.com.br"] [uri "/home/sem-titulo-2/"] [unique_id "al9IGiBMYeh5YLVG45xjBAAAApM"], referer: https://bcsenepol.com.br/home/sem-titulo-2/
[Tue Jul 21 07:21:14.283014 2026] [security2:error] [pid 230252:tid 230327] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IGk0Dwhk5-Z44Xro-TwACs0g"]
[Tue Jul 21 07:21:14.283183 2026] [security2:error] [pid 230252:tid 230410] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IGk0Dwhk5-Z44Xro-TwACs0g"]
[Tue Jul 21 07:21:14.483131 2026] [security2:error] [pid 229246:tid 229414] [client 193.36.225.61:58863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IGiBMYeh5YLVG45xjBgAAAjo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:14.484768 2026] [security2:error] [pid 229246:tid 229429] [client 34.148.166.21:50429] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "look.dealspark.com.br"] [uri "/cgi-sys/suspendedpage.cgi/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9IGiBMYeh5YLVG45xjBwAAAkk"]
[Tue Jul 21 07:21:14.664330 2026] [security2:error] [pid 229246:tid 229403] [client 20.206.105.145:30604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9IGiBMYeh5YLVG45xjCQAAAi8"]
[Tue Jul 21 07:21:14.731419 2026] [security2:error] [pid 230252:tid 230420] [client 34.148.166.21:64680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "look.dealspark.com.br"] [uri "/cgi-sys/suspendedpage.cgi/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9IGk0Dwhk5-Z44Xro-UAAAAr0"]
[Tue Jul 21 07:21:14.787477 2026] [http2:warn] [pid 229246:tid 229489] [client 57.141.18.51:39434] h2_stream(229246-298-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:14.810218 2026] [security2:error] [pid 230252:tid 230398] [client 4.204.201.85:17914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/info.php"] [unique_id "al9IGk0Dwhk5-Z44Xro-UQAAAqc"]
[Tue Jul 21 07:21:14.946650 2026] [http2:warn] [pid 229246:tid 229440] [client 57.141.18.5:49164] h2_stream(229246-300-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:14.987099 2026] [security2:error] [pid 230252:tid 230400] [client 34.148.166.21:57053] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "look.dealspark.com.br"] [uri "/cgi-sys/suspendedpage.cgi/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9IGk0Dwhk5-Z44Xro-VgAAAqk"]
[Tue Jul 21 07:21:15.037493 2026] [security2:error] [pid 230252:tid 230389] [client 20.104.96.117:59680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/loader.php"] [unique_id "al9IG00Dwhk5-Z44Xro-WAAAAp4"]
[Tue Jul 21 07:21:15.101691 2026] [security2:error] [pid 229246:tid 229459] [client 20.220.225.223:34208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/2x.php"] [unique_id "al9IGyBMYeh5YLVG45xjDwAAAmc"]
[Tue Jul 21 07:21:15.131382 2026] [security2:error] [pid 230252:tid 230430] [client 20.220.225.223:59465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/edit.php"] [unique_id "al9IG00Dwhk5-Z44Xro-WgAAAsc"]
[Tue Jul 21 07:21:15.235475 2026] [security2:error] [pid 230252:tid 230501] [client 14.139.42.196:1816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IG00Dwhk5-Z44Xro-XAAAAw4"]
[Tue Jul 21 07:21:15.235582 2026] [security2:error] [pid 230252:tid 230501] [client 14.139.42.196:1816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IG00Dwhk5-Z44Xro-XAAAAw4"]
[Tue Jul 21 07:21:15.257705 2026] [security2:error] [pid 230252:tid 230440] [client 34.148.166.21:60358] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "look.dealspark.com.br"] [uri "/cgi-sys/suspendedpage.cgi/test/wp-includes/wlwmanifest.xml"] [unique_id "al9IG00Dwhk5-Z44Xro-XQAAAtE"]
[Tue Jul 21 07:21:15.407069 2026] [security2:error] [pid 230252:tid 230395] [client 20.197.192.193:27173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/hp3.php"] [unique_id "al9IG00Dwhk5-Z44Xro-XwAAAqQ"]
[Tue Jul 21 07:21:15.463452 2026] [security2:error] [pid 229246:tid 229391] [client 45.251.232.145:64771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IGyBMYeh5YLVG45xjFwAAAiM"]
[Tue Jul 21 07:21:15.463947 2026] [security2:error] [pid 229246:tid 229391] [client 45.251.232.145:64771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IGyBMYeh5YLVG45xjFwAAAiM"]
[Tue Jul 21 07:21:15.541703 2026] [security2:error] [pid 229246:tid 229441] [client 34.148.166.21:54746] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "look.dealspark.com.br"] [uri "/cgi-sys/suspendedpage.cgi/site/wp-includes/wlwmanifest.xml"] [unique_id "al9IGyBMYeh5YLVG45xjGQAAAlU"]
[Tue Jul 21 07:21:15.585733 2026] [security2:error] [pid 229246:tid 229496] [client 4.204.201.85:44006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/11.php"] [unique_id "al9IGyBMYeh5YLVG45xjGwAAAow"]
[Tue Jul 21 07:21:16.004018 2026] [security2:error] [pid 230252:tid 230392] [client 20.197.192.193:27094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/aa1.php"] [unique_id "al9IHE0Dwhk5-Z44Xro-aAAAAqE"]
[Tue Jul 21 07:21:16.014747 2026] [security2:error] [pid 229246:tid 229501] [client 114.119.138.178:51841] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.dharmanet.com.br"] [uri "/honganji"] [unique_id "al9IHCBMYeh5YLVG45xjIQAAApE"], referer: http://www.buddhanet.info/wbd/region.php?id=7900&offset=5325
[Tue Jul 21 07:21:16.132548 2026] [security2:error] [pid 230252:tid 230465] [client 20.104.96.117:59183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/spadex.php"] [unique_id "al9IHE0Dwhk5-Z44Xro-aQAAAuo"]
[Tue Jul 21 07:21:16.165386 2026] [security2:error] [pid 229246:tid 229355] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IHCBMYeh5YLVG45xjIgACG2w"]
[Tue Jul 21 07:21:16.165519 2026] [security2:error] [pid 229246:tid 229383] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IHCBMYeh5YLVG45xjIgACG2w"]
[Tue Jul 21 07:21:16.246477 2026] [security2:error] [pid 230252:tid 230428] [client 4.204.201.85:17797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/v2.php"] [unique_id "al9IHE0Dwhk5-Z44Xro-agAAAsU"]
[Tue Jul 21 07:21:16.376432 2026] [security2:error] [pid 230252:tid 230510] [client 173.252.95.57:34208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9IG00Dwhk5-Z44Xro-WwAAAxc"]
[Tue Jul 21 07:21:16.473172 2026] [http2:warn] [pid 230252:tid 230492] [client 57.141.18.95:54948] h2_stream(230252-125-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:16.701256 2026] [security2:error] [pid 229246:tid 229431] [client 20.206.105.145:30694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9IHCBMYeh5YLVG45xjLAAAAks"]
[Tue Jul 21 07:21:16.888439 2026] [security2:error] [pid 230252:tid 230389] [client 4.204.201.85:17816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/panel.php"] [unique_id "al9IHE0Dwhk5-Z44Xro-cwAAAp4"]
[Tue Jul 21 07:21:17.342001 2026] [security2:error] [pid 230252:tid 230412] [client 20.104.96.117:59138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/2x.php"] [unique_id "al9IHU0Dwhk5-Z44Xro-dQAAArU"]
[Tue Jul 21 07:21:17.438213 2026] [security2:error] [pid 229246:tid 229403] [client 20.151.10.161:11762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/jp.php"] [unique_id "al9IHSBMYeh5YLVG45xjNAAAAi8"]
[Tue Jul 21 07:21:17.581767 2026] [security2:error] [pid 230252:tid 230496] [client 20.206.105.145:30644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/like.php"] [unique_id "al9IHU0Dwhk5-Z44Xro-eQAAAwk"]
[Tue Jul 21 07:21:17.581957 2026] [http2:warn] [pid 230252:tid 230453] [client 57.141.18.75:31792] h2_stream(230252-129-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:17.644007 2026] [security2:error] [pid 229246:tid 229430] [client 74.249.245.134:62296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/php8.php"] [unique_id "al9IHSBMYeh5YLVG45xjOQAAAko"]
[Tue Jul 21 07:21:17.649901 2026] [proxy:error] [pid 230252:tid 230395] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:17.649969 2026] [proxy_http:error] [pid 230252:tid 230395] [client 161.35.142.61:58978] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:17.650558 2026] [proxy:error] [pid 230252:tid 230395] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:17.650586 2026] [proxy_http:error] [pid 230252:tid 230395] [client 161.35.142.61:58978] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:17.728333 2026] [security2:error] [pid 229246:tid 229432] [client 8.228.118.177:54822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9IHSBMYeh5YLVG45xjOgAAAkw"]
[Tue Jul 21 07:21:17.745587 2026] [security2:error] [pid 229246:tid 229404] [client 20.197.192.193:27156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/acew67.php"] [unique_id "al9IHSBMYeh5YLVG45xjOwAAAjA"]
[Tue Jul 21 07:21:17.883019 2026] [proxy:error] [pid 230252:tid 230385] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:17.883094 2026] [proxy_http:error] [pid 230252:tid 230385] [client 161.35.142.61:58982] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.dpatrick.com.br/
[Tue Jul 21 07:21:17.883746 2026] [proxy:error] [pid 230252:tid 230385] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:17.883780 2026] [proxy_http:error] [pid 230252:tid 230385] [client 161.35.142.61:58982] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.dpatrick.com.br/
[Tue Jul 21 07:21:17.975759 2026] [security2:error] [pid 230252:tid 230384] [client 8.228.118.177:54753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.118.228.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IHU0Dwhk5-Z44Xro-fQAAApk"]
[Tue Jul 21 07:21:18.016197 2026] [security2:error] [pid 230252:tid 230409] [client 20.104.96.117:59655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/ctex1.php"] [unique_id "al9IHk0Dwhk5-Z44Xro-fwAAArI"]
[Tue Jul 21 07:21:18.063116 2026] [security2:error] [pid 229246:tid 229391] [client 20.220.225.223:36831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/kua.php"] [unique_id "al9IHiBMYeh5YLVG45xjQAAAAiM"]
[Tue Jul 21 07:21:18.227876 2026] [security2:error] [pid 229246:tid 229408] [client 8.228.118.177:65447] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9IHiBMYeh5YLVG45xjQgAAAjQ"]
[Tue Jul 21 07:21:18.346530 2026] [proxy:error] [pid 229246:tid 229472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:18.346568 2026] [proxy_http:error] [pid 229246:tid 229472] [client 161.35.142.61:47716] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:18.347319 2026] [proxy:error] [pid 229246:tid 229472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:18.347358 2026] [proxy_http:error] [pid 229246:tid 229472] [client 161.35.142.61:47716] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:18.389525 2026] [security2:error] [pid 230252:tid 230399] [client 20.226.60.151:54497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/elbzl.php"] [unique_id "al9IHk0Dwhk5-Z44Xro-ggAAAqg"]
[Tue Jul 21 07:21:18.442657 2026] [security2:error] [pid 230252:tid 230478] [client 114.119.141.152:43445] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ssvistorias.com.br"] [uri "/zgkb.php"] [unique_id "al9IHk0Dwhk5-Z44Xro-gwAAAvc"], referer: http://www.ssvistorias.com.br/zgkb.php?mall/-gdq/21/tg_22276/
[Tue Jul 21 07:21:18.478501 2026] [security2:error] [pid 230252:tid 230484] [client 8.228.118.177:55272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9IHk0Dwhk5-Z44Xro-hQAAAv0"]
[Tue Jul 21 07:21:18.616156 2026] [http2:warn] [pid 230252:tid 230506] [client 57.141.18.72:43702] h2_stream(230252-131-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:18.655502 2026] [security2:error] [pid 230252:tid 230454] [client 193.36.225.65:53047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IHk0Dwhk5-Z44Xro-hAAAAt8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:18.711644 2026] [security2:error] [pid 230252:tid 230441] [client 20.197.192.193:27103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/bscclapb.php"] [unique_id "al9IHk0Dwhk5-Z44Xro-igAAAtI"]
[Tue Jul 21 07:21:18.726312 2026] [security2:error] [pid 230252:tid 230510] [client 8.228.118.177:64088] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9IHk0Dwhk5-Z44Xro-iwAAAxc"]
[Tue Jul 21 07:21:18.974305 2026] [security2:error] [pid 230252:tid 230421] [client 8.228.118.177:63134] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9IHk0Dwhk5-Z44Xro-jQAAAr4"]
[Tue Jul 21 07:21:19.059317 2026] [security2:error] [pid 229246:tid 229453] [client 74.7.241.190:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "printcom.com.br"] [uri "/index.php"] [unique_id "al9IHSBMYeh5YLVG45xjNwACYRI"], referer: http://printcom.com.br/robots.txt
[Tue Jul 21 07:21:19.100501 2026] [security2:error] [pid 230252:tid 230435] [client 114.119.158.106:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sobradoimoveis.com.br"] [uri "/imovel/casa-3-quartos-com-garagem-13405m2-venda-atiradores-joinville-sc-kr444"] [unique_id "al9IH00Dwhk5-Z44Xro-kAAAAsw"], referer: https://www.sobradoimoveis.com.br/imovel/casa-3-quartos-com-garagem-13405m2-venda-atiradores-joinville-sc-kr444?opcao=KR444&cd_empresa=4
[Tue Jul 21 07:21:19.107416 2026] [security2:error] [pid 229246:tid 229452] [client 4.204.201.85:17795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/dex.php"] [unique_id "al9IHyBMYeh5YLVG45xjUwAAAmA"]
[Tue Jul 21 07:21:19.111636 2026] [security2:error] [pid 230252:tid 230332] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IH00Dwhk5-Z44Xro-kQACp00"]
[Tue Jul 21 07:21:19.111770 2026] [security2:error] [pid 230252:tid 230398] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IH00Dwhk5-Z44Xro-kQACp00"]
[Tue Jul 21 07:21:19.121530 2026] [security2:error] [pid 230252:tid 230326] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IH00Dwhk5-Z44Xro-kgAC8Uc"]
[Tue Jul 21 07:21:19.121701 2026] [security2:error] [pid 230252:tid 230472] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IH00Dwhk5-Z44Xro-kgAC8Uc"]
[Tue Jul 21 07:21:19.170584 2026] [http2:warn] [pid 230252:tid 230405] [client 57.141.18.59:53316] h2_stream(230252-135-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:19.226340 2026] [security2:error] [pid 230252:tid 230430] [client 8.228.118.177:63471] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9IH00Dwhk5-Z44Xro-kwAAAsc"]
[Tue Jul 21 07:21:19.286024 2026] [security2:error] [pid 230252:tid 230426] [client 20.104.96.117:59657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/edorxrr.php"] [unique_id "al9IH00Dwhk5-Z44Xro-lQAAAsM"]
[Tue Jul 21 07:21:19.292939 2026] [security2:error] [pid 229246:tid 229476] [client 114.119.140.169:46165] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tragaseushow.com.br"] [uri "/projeto/monica-tomasi"] [unique_id "al9IHyBMYeh5YLVG45xjVAAAAng"], referer: http://tragaseushow.com.br/projeto/monica-tomasi
[Tue Jul 21 07:21:19.339211 2026] [security2:error] [pid 230252:tid 230496] [client 20.220.225.223:52782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/ez.php"] [unique_id "al9IH00Dwhk5-Z44Xro-lwAAAwk"]
[Tue Jul 21 07:21:19.403187 2026] [security2:error] [pid 230252:tid 230385] [client 20.206.105.145:30685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/.well-known/about.php"] [unique_id "al9IH00Dwhk5-Z44Xro-mAAAApo"]
[Tue Jul 21 07:21:19.477494 2026] [security2:error] [pid 230252:tid 230409] [client 8.228.118.177:58720] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9IH00Dwhk5-Z44Xro-nAAAArI"]
[Tue Jul 21 07:21:19.526934 2026] [security2:error] [pid 230252:tid 230509] [client 20.226.60.151:54473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/adjig.php"] [unique_id "al9IH00Dwhk5-Z44Xro-nQAAAxY"]
[Tue Jul 21 07:21:19.655943 2026] [security2:error] [pid 230252:tid 230267] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IH00Dwhk5-Z44Xro-ogACzQ0"]
[Tue Jul 21 07:21:19.656099 2026] [security2:error] [pid 230252:tid 230436] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IH00Dwhk5-Z44Xro-ogACzQ0"]
[Tue Jul 21 07:21:19.721238 2026] [security2:error] [pid 230252:tid 230510] [client 8.228.118.177:50452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9IH00Dwhk5-Z44Xro-pAAAAxc"]
[Tue Jul 21 07:21:19.965651 2026] [security2:error] [pid 229246:tid 229431] [client 8.228.118.177:50973] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9IHyBMYeh5YLVG45xjWAAAAks"]
[Tue Jul 21 07:21:20.064961 2026] [security2:error] [pid 229246:tid 229434] [client 20.151.10.161:45942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xstelth.php"] [unique_id "al9IICBMYeh5YLVG45xjWQAAAk4"]
[Tue Jul 21 07:21:20.150167 2026] [http2:warn] [pid 229246:tid 229457] [client 57.141.18.69:31978] h2_stream(229246-306-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:20.195592 2026] [security2:error] [pid 230252:tid 230451] [client 114.119.143.104:30469] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "inonebrasil.com.br"] [uri "/nyqlf/k110524.html"] [unique_id "al9IIE0Dwhk5-Z44Xro-pwAAAtw"], referer: https://inonebrasil.com.br/nyqlf/k110524.html
[Tue Jul 21 07:21:20.216503 2026] [security2:error] [pid 230252:tid 230403] [client 8.228.118.177:59449] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9IIE0Dwhk5-Z44Xro-qQAAAqw"]
[Tue Jul 21 07:21:20.317206 2026] [security2:error] [pid 230252:tid 230269] [remote 45.79.123.44:52574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9IIE0Dwhk5-Z44Xro-qgAC4g8"]
[Tue Jul 21 07:21:20.348361 2026] [security2:error] [pid 230252:tid 230416] [client 20.104.96.117:59703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/miru1.php"] [unique_id "al9IIE0Dwhk5-Z44Xro-qwAAArk"]
[Tue Jul 21 07:21:20.365288 2026] [http2:warn] [pid 229246:tid 229409] [client 57.141.18.50:23848] h2_stream(229246-307-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:20.416109 2026] [security2:error] [pid 230252:tid 230465] [client 175.45.70.82:52825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IIE0Dwhk5-Z44Xro-rAAAAuo"]
[Tue Jul 21 07:21:20.416261 2026] [security2:error] [pid 230252:tid 230465] [client 175.45.70.82:52825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IIE0Dwhk5-Z44Xro-rAAAAuo"]
[Tue Jul 21 07:21:20.472483 2026] [security2:error] [pid 230252:tid 230485] [client 8.228.118.177:58224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9IIE0Dwhk5-Z44Xro-rwAAAv4"]
[Tue Jul 21 07:21:20.508803 2026] [security2:error] [pid 230252:tid 230450] [client 20.151.10.161:12063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/f35.php"] [unique_id "al9IIE0Dwhk5-Z44Xro-sQAAAts"]
[Tue Jul 21 07:21:20.567604 2026] [security2:error] [pid 229246:tid 229478] [client 139.135.44.145:54184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IICBMYeh5YLVG45xjXgAAAno"]
[Tue Jul 21 07:21:20.567739 2026] [security2:error] [pid 229246:tid 229478] [client 139.135.44.145:54184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IICBMYeh5YLVG45xjXgAAAno"]
[Tue Jul 21 07:21:20.648529 2026] [security2:error] [pid 229246:tid 229418] [client 20.220.225.223:36825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/fz.php"] [unique_id "al9IICBMYeh5YLVG45xjYAAAAj4"]
[Tue Jul 21 07:21:20.665447 2026] [security2:error] [pid 229246:tid 229401] [client 120.61.173.56:56906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IICBMYeh5YLVG45xjYwAAAi0"]
[Tue Jul 21 07:21:20.665546 2026] [security2:error] [pid 229246:tid 229401] [client 120.61.173.56:56906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IICBMYeh5YLVG45xjYwAAAi0"]
[Tue Jul 21 07:21:20.708886 2026] [security2:error] [pid 230252:tid 230455] [client 4.204.201.85:17879] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "beezar.com.br"] [uri "/1.php"] [unique_id "al9IIE0Dwhk5-Z44Xro-sgAAAuA"]
[Tue Jul 21 07:21:20.708994 2026] [security2:error] [pid 230252:tid 230455] [client 4.204.201.85:17879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/1.php"] [unique_id "al9IIE0Dwhk5-Z44Xro-sgAAAuA"]
[Tue Jul 21 07:21:20.727824 2026] [security2:error] [pid 230252:tid 230425] [client 8.228.118.177:58567] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9IIE0Dwhk5-Z44Xro-swAAAsI"]
[Tue Jul 21 07:21:20.803123 2026] [security2:error] [pid 230252:tid 230442] [client 54.39.89.168:37822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "porondeeuestive.com.br"] [uri "/robots.txt"] [unique_id "al9IIE0Dwhk5-Z44Xro-tAAAAtM"]
[Tue Jul 21 07:21:20.803228 2026] [security2:error] [pid 230252:tid 230442] [client 54.39.89.168:37822] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "porondeeuestive.com.br"] [uri "/robots.txt"] [unique_id "al9IIE0Dwhk5-Z44Xro-tAAAAtM"]
[Tue Jul 21 07:21:20.816515 2026] [security2:error] [pid 230252:tid 230384] [client 20.206.105.145:30710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9IIE0Dwhk5-Z44Xro-tQAAApk"]
[Tue Jul 21 07:21:20.870311 2026] [security2:error] [pid 230252:tid 230439] [client 20.104.96.117:59172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/sump1.php"] [unique_id "al9IIE0Dwhk5-Z44Xro-tgAAAtA"]
[Tue Jul 21 07:21:20.940229 2026] [security2:error] [pid 229246:tid 229404] [client 74.249.245.134:52462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/info.php"] [unique_id "al9IICBMYeh5YLVG45xjZwAAAjA"]
[Tue Jul 21 07:21:20.965403 2026] [security2:error] [pid 230252:tid 230499] [client 8.228.118.177:57280] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9IIE0Dwhk5-Z44Xro-twAAAww"]
[Tue Jul 21 07:21:21.093115 2026] [proxy:error] [pid 230252:tid 230409] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:21.093169 2026] [proxy_http:error] [pid 230252:tid 230409] [client 161.35.142.61:47844] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.dpatrick.com.br/
[Tue Jul 21 07:21:21.093753 2026] [proxy:error] [pid 230252:tid 230409] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:21.093773 2026] [proxy_http:error] [pid 230252:tid 230409] [client 161.35.142.61:47844] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.dpatrick.com.br/
[Tue Jul 21 07:21:21.145911 2026] [http2:warn] [pid 229246:tid 229468] [client 57.141.18.115:31648] h2_stream(229246-311-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:21.219505 2026] [security2:error] [pid 230252:tid 230454] [client 8.228.118.177:54507] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9IIU0Dwhk5-Z44Xro-uwAAAt8"]
[Tue Jul 21 07:21:21.242022 2026] [security2:error] [pid 230252:tid 230272] [remote 41.76.214.143:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fidellium.com"] [uri "/wp-login.php"] [unique_id "al9IIU0Dwhk5-Z44Xro-vAADGBI"]
[Tue Jul 21 07:21:21.473480 2026] [security2:error] [pid 230252:tid 230420] [client 8.228.118.177:58569] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9IIU0Dwhk5-Z44Xro-vwAAAr0"]
[Tue Jul 21 07:21:21.485761 2026] [security2:error] [pid 229246:tid 229436] [client 20.104.96.117:61154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/file5.php"] [unique_id "al9IISBMYeh5YLVG45xjbAAAAlA"]
[Tue Jul 21 07:21:21.588410 2026] [security2:error] [pid 230252:tid 230355] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IIU0Dwhk5-Z44Xro-wAACs2Q"]
[Tue Jul 21 07:21:21.588602 2026] [security2:error] [pid 230252:tid 230410] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IIU0Dwhk5-Z44Xro-wAACs2Q"]
[Tue Jul 21 07:21:21.644772 2026] [security2:error] [pid 230252:tid 230435] [client 20.151.10.161:11736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-load.php"] [unique_id "al9IIU0Dwhk5-Z44Xro-wQAAAsw"]
[Tue Jul 21 07:21:21.716899 2026] [security2:error] [pid 230252:tid 230476] [client 8.228.118.177:65395] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9IIU0Dwhk5-Z44Xro-xQAAAvU"]
[Tue Jul 21 07:21:21.724953 2026] [security2:error] [pid 230252:tid 230430] [client 4.204.201.85:43993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/ms.php"] [unique_id "al9IIU0Dwhk5-Z44Xro-xgAAAsc"]
[Tue Jul 21 07:21:21.831390 2026] [security2:error] [pid 229246:tid 229394] [client 20.206.105.145:30705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/pucci.php"] [unique_id "al9IISBMYeh5YLVG45xjcwAAAiY"]
[Tue Jul 21 07:21:21.965297 2026] [security2:error] [pid 230252:tid 230450] [client 8.228.118.177:60437] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9IIU0Dwhk5-Z44Xro-xwAAAts"]
[Tue Jul 21 07:21:22.058857 2026] [security2:error] [pid 229246:tid 229475] [client 20.220.225.223:36837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/la.php"] [unique_id "al9IIiBMYeh5YLVG45xjdAAAAnc"]
[Tue Jul 21 07:21:22.160151 2026] [security2:error] [pid 230252:tid 230395] [client 20.226.60.151:54561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/byp.php"] [unique_id "al9IIk0Dwhk5-Z44Xro-yAAAAqQ"]
[Tue Jul 21 07:21:22.346932 2026] [security2:error] [pid 230252:tid 230439] [client 20.151.10.161:11666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xwpg.php"] [unique_id "al9IIk0Dwhk5-Z44Xro-zwAAAtA"]
[Tue Jul 21 07:21:22.358797 2026] [security2:error] [pid 230252:tid 230423] [client 20.104.96.117:59689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/0xD.php"] [unique_id "al9IIk0Dwhk5-Z44Xro-0AAAAsA"]
[Tue Jul 21 07:21:22.452002 2026] [http2:warn] [pid 229246:tid 229494] [client 57.141.18.18:23752] h2_stream(229246-314-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:22.992836 2026] [security2:error] [pid 229246:tid 229395] [client 114.119.151.93:37479] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.politicabrasil.com.br"] [uri "/post/prefeito-vitor-valim-visita-sede-da-fiec-e-garante-parcerias-na-%C3%A1rea-da-educa%C3%A7%C3%A3o"] [unique_id "al9IIiBMYeh5YLVG45xjggAAAic"], referer: https://www.politicabrasil.com.br/post/chico-buarque-processa-eduardo-bolsonaro-novamente-e-vence
[Tue Jul 21 07:21:23.071646 2026] [security2:error] [pid 229246:tid 229384] [client 20.104.96.117:59141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/fnstall.php"] [unique_id "al9IIyBMYeh5YLVG45xjgwAAAhw"]
[Tue Jul 21 07:21:23.219081 2026] [security2:error] [pid 229246:tid 229431] [client 134.19.179.187:33450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IIyBMYeh5YLVG45xjhQAAAks"]
[Tue Jul 21 07:21:23.219200 2026] [security2:error] [pid 229246:tid 229431] [client 134.19.179.187:33450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IIyBMYeh5YLVG45xjhQAAAks"]
[Tue Jul 21 07:21:23.226609 2026] [security2:error] [pid 230252:tid 230453] [client 20.151.10.161:55278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/waf.php"] [unique_id "al9II00Dwhk5-Z44Xro-3AAAAt4"]
[Tue Jul 21 07:21:23.550887 2026] [security2:error] [pid 230252:tid 230303] [remote 188.138.102.156:50608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "digitaclick.com"] [uri "/wp-login.php"] [unique_id "al9II00Dwhk5-Z44Xro-4AADGDE"]
[Tue Jul 21 07:21:23.666204 2026] [security2:error] [pid 230252:tid 230485] [client 20.206.105.145:30645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-temp.php"] [unique_id "al9II00Dwhk5-Z44Xro-4wAAAv4"]
[Tue Jul 21 07:21:23.668435 2026] [security2:error] [pid 230252:tid 230431] [client 34.74.242.206:1654] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.northcomm.com.br"] [uri "/robots.txt"] [unique_id "al9II00Dwhk5-Z44Xro-5AAAAsg"]
[Tue Jul 21 07:21:23.668526 2026] [security2:error] [pid 230252:tid 230431] [client 34.74.242.206:1654] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.northcomm.com.br"] [uri "/robots.txt"] [unique_id "al9II00Dwhk5-Z44Xro-5AAAAsg"]
[Tue Jul 21 07:21:23.688323 2026] [security2:error] [pid 230252:tid 230426] [client 20.104.96.117:59700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/acp.php"] [unique_id "al9II00Dwhk5-Z44Xro-5QAAAsM"]
[Tue Jul 21 07:21:23.703009 2026] [security2:error] [pid 230252:tid 230412] [client 20.151.10.161:12062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xstelth.php"] [unique_id "al9II00Dwhk5-Z44Xro-5gAAArU"]
[Tue Jul 21 07:21:23.721874 2026] [security2:error] [pid 229246:tid 229387] [client 103.162.129.114:62748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IIyBMYeh5YLVG45xjiwAAAh8"]
[Tue Jul 21 07:21:23.721974 2026] [security2:error] [pid 229246:tid 229387] [client 103.162.129.114:62748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IIyBMYeh5YLVG45xjiwAAAh8"]
[Tue Jul 21 07:21:23.811319 2026] [security2:error] [pid 229246:tid 229380] [client 103.121.156.110:63227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IIyBMYeh5YLVG45xjjgAAAhg"]
[Tue Jul 21 07:21:23.811415 2026] [security2:error] [pid 229246:tid 229380] [client 103.121.156.110:63227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IIyBMYeh5YLVG45xjjgAAAhg"]
[Tue Jul 21 07:21:23.916639 2026] [security2:error] [pid 230252:tid 230442] [client 34.74.242.206:1647] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.northcomm.com.br"] [uri "/"] [unique_id "al9II00Dwhk5-Z44Xro-6gAAAtM"]
[Tue Jul 21 07:21:23.916742 2026] [security2:error] [pid 230252:tid 230442] [client 34.74.242.206:1647] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.northcomm.com.br"] [uri "/"] [unique_id "al9II00Dwhk5-Z44Xro-6gAAAtM"]
[Tue Jul 21 07:21:23.980985 2026] [security2:error] [pid 229246:tid 229382] [client 114.119.146.117:63479] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/index.php/wishlist/index/add/product/54/form_key/Su9aBVdW3rd6fsBm"] [unique_id "al9IIyBMYeh5YLVG45xjkQAAAho"], referer: http://www.ceramicasantoaugusto.com.br/index.php/produtos.html?dir=desc&order=position
[Tue Jul 21 07:21:24.006113 2026] [security2:error] [pid 229246:tid 229495] [client 20.151.10.161:53606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-links.php"] [unique_id "al9IJCBMYeh5YLVG45xjkgAAAos"]
[Tue Jul 21 07:21:24.034194 2026] [http2:warn] [pid 230252:tid 230477] [client 57.141.18.108:24376] h2_stream(230252-148-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:24.095621 2026] [security2:error] [pid 230252:tid 230413] [client 114.119.138.251:52965] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "powerflats.com.br"] [uri "/recurso/sauna"] [unique_id "al9IJE0Dwhk5-Z44Xro-7QAAArY"], referer: https://powerflats.com.br/recurso/sauna
[Tue Jul 21 07:21:24.229105 2026] [security2:error] [pid 230252:tid 230496] [client 20.104.96.117:59151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/mosty.php"] [unique_id "al9IJE0Dwhk5-Z44Xro-7gAAAwk"]
[Tue Jul 21 07:21:24.263264 2026] [security2:error] [pid 230252:tid 230439] [client 4.204.201.85:17876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/memberfuns.php"] [unique_id "al9IJE0Dwhk5-Z44Xro-7wAAAtA"]
[Tue Jul 21 07:21:24.407033 2026] [security2:error] [pid 230252:tid 230408] [client 20.220.225.223:47810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9IJE0Dwhk5-Z44Xro-8AAAArE"]
[Tue Jul 21 07:21:24.529943 2026] [security2:error] [pid 229246:tid 229492] [client 20.151.10.161:12067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9IJCBMYeh5YLVG45xjmAAAAog"]
[Tue Jul 21 07:21:24.663131 2026] [security2:error] [pid 230252:tid 230345] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IJE0Dwhk5-Z44Xro-8wACoVo"]
[Tue Jul 21 07:21:24.663327 2026] [security2:error] [pid 230252:tid 230392] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IJE0Dwhk5-Z44Xro-8wACoVo"]
[Tue Jul 21 07:21:24.712662 2026] [security2:error] [pid 229246:tid 229449] [client 20.104.96.117:59150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/6.php"] [unique_id "al9IJCBMYeh5YLVG45xjmgAAAl0"]
[Tue Jul 21 07:21:24.849320 2026] [security2:error] [pid 229246:tid 229460] [client 20.151.10.161:45827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-links.php"] [unique_id "al9IJCBMYeh5YLVG45xjngAAAmg"]
[Tue Jul 21 07:21:24.854521 2026] [security2:error] [pid 230252:tid 230290] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IJE0Dwhk5-Z44Xro-9QAC0SQ"]
[Tue Jul 21 07:21:24.854639 2026] [security2:error] [pid 230252:tid 230440] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IJE0Dwhk5-Z44Xro-9QAC0SQ"]
[Tue Jul 21 07:21:24.920478 2026] [http2:warn] [pid 230252:tid 230474] [client 57.141.18.74:54378] h2_stream(230252-151-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:25.071769 2026] [http2:warn] [pid 229246:tid 229448] [client 57.141.18.104:33866] h2_stream(229246-321-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:25.128339 2026] [security2:error] [pid 229246:tid 229475] [client 4.204.201.85:17803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/0.php"] [unique_id "al9IJSBMYeh5YLVG45xjoAAAAnc"]
[Tue Jul 21 07:21:25.313052 2026] [security2:error] [pid 229246:tid 229400] [client 20.104.96.117:59186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9IJSBMYeh5YLVG45xjpQAAAiw"]
[Tue Jul 21 07:21:25.432720 2026] [security2:error] [pid 229246:tid 229477] [client 20.206.105.145:30535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/xmu.php"] [unique_id "al9IJSBMYeh5YLVG45xjpwAAAnk"]
[Tue Jul 21 07:21:25.777506 2026] [security2:error] [pid 229246:tid 229484] [client 20.220.225.223:59458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/inso.php"] [unique_id "al9IJSBMYeh5YLVG45xjqgAAAoA"]
[Tue Jul 21 07:21:25.901084 2026] [security2:error] [pid 229246:tid 229454] [client 14.139.42.196:26478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IJSBMYeh5YLVG45xjrwAAAmI"]
[Tue Jul 21 07:21:25.901212 2026] [security2:error] [pid 229246:tid 229454] [client 14.139.42.196:26478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IJSBMYeh5YLVG45xjrwAAAmI"]
[Tue Jul 21 07:21:25.938586 2026] [security2:error] [pid 229246:tid 229406] [client 45.251.232.145:65290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IJSBMYeh5YLVG45xjsAAAAjI"]
[Tue Jul 21 07:21:25.938713 2026] [security2:error] [pid 229246:tid 229406] [client 45.251.232.145:65290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IJSBMYeh5YLVG45xjsAAAAjI"]
[Tue Jul 21 07:21:25.971600 2026] [security2:error] [pid 229246:tid 229440] [client 20.104.96.117:61129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/qqqa.php"] [unique_id "al9IJSBMYeh5YLVG45xjsQAAAlQ"]
[Tue Jul 21 07:21:26.118038 2026] [security2:error] [pid 229246:tid 229438] [client 4.204.201.85:43960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/BDKR28.php"] [unique_id "al9IJiBMYeh5YLVG45xjswAAAlI"]
[Tue Jul 21 07:21:26.360361 2026] [security2:error] [pid 229246:tid 229480] [client 20.151.10.161:53600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/aaa.php"] [unique_id "al9IJiBMYeh5YLVG45xjtAAAAnw"]
[Tue Jul 21 07:21:26.362934 2026] [http2:warn] [pid 230252:tid 230482] [client 57.141.18.0:23330] h2_stream(230252-156-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:26.471460 2026] [security2:error] [pid 230252:tid 230402] [client 20.206.105.145:30592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-admin/js/index.php"] [unique_id "al9IJk0Dwhk5-Z44Xro-_gAAAqs"]
[Tue Jul 21 07:21:26.511000 2026] [security2:error] [pid 229246:tid 229289] [remote 192.241.143.148:38168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9IJiBMYeh5YLVG45xjuQACcyo"]
[Tue Jul 21 07:21:26.615369 2026] [security2:error] [pid 230252:tid 230412] [client 4.204.201.85:17853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/green1.php"] [unique_id "al9IJk0Dwhk5-Z44Xro_AAAAArU"]
[Tue Jul 21 07:21:26.622278 2026] [security2:error] [pid 230252:tid 230501] [client 20.104.96.117:59149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/aunmc.php"] [unique_id "al9IJk0Dwhk5-Z44Xro_AQAAAw4"]
[Tue Jul 21 07:21:26.779754 2026] [security2:error] [pid 230252:tid 230426] [client 136.144.33.98:61071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IJk0Dwhk5-Z44Xro-_wAAAsM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:26.798865 2026] [security2:error] [pid 229246:tid 229461] [client 20.226.60.151:54569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9IJiBMYeh5YLVG45xjvAAAAmk"]
[Tue Jul 21 07:21:26.907449 2026] [security2:error] [pid 229246:tid 229313] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IJiBMYeh5YLVG45xjwAACi0I"]
[Tue Jul 21 07:21:26.907618 2026] [security2:error] [pid 229246:tid 229495] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IJiBMYeh5YLVG45xjwAACi0I"]
[Tue Jul 21 07:21:27.101172 2026] [security2:error] [pid 229246:tid 229315] [remote 20.75.217.64:3569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9IJyBMYeh5YLVG45xjxAACVkQ"]
[Tue Jul 21 07:21:27.184432 2026] [security2:error] [pid 230252:tid 230409] [client 20.220.225.223:59484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/wpx.php"] [unique_id "al9IJ00Dwhk5-Z44Xro_CAAAArI"]
[Tue Jul 21 07:21:27.228919 2026] [security2:error] [pid 229246:tid 229457] [client 20.206.105.145:30633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/puc.php"] [unique_id "al9IJyBMYeh5YLVG45xjxQAAAmU"]
[Tue Jul 21 07:21:27.323482 2026] [security2:error] [pid 229246:tid 229492] [client 20.104.96.117:59157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/uoocf.php"] [unique_id "al9IJyBMYeh5YLVG45xjxgAAAog"]
[Tue Jul 21 07:21:27.374035 2026] [http2:warn] [pid 230252:tid 230443] [client 57.141.18.114:22366] h2_stream(230252-160-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:27.443948 2026] [security2:error] [pid 230252:tid 230454] [client 20.220.225.223:34265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/kq1.php"] [unique_id "al9IJ00Dwhk5-Z44Xro_DQAAAt8"]
[Tue Jul 21 07:21:27.453680 2026] [security2:error] [pid 229246:tid 229491] [client 20.197.192.193:27160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/else1.php"] [unique_id "al9IJyBMYeh5YLVG45xjyAAAAoc"]
[Tue Jul 21 07:21:27.476672 2026] [security2:error] [pid 230252:tid 230428] [client 4.204.201.85:17820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/nc4.php"] [unique_id "al9IJ00Dwhk5-Z44Xro_DgAAAsU"]
[Tue Jul 21 07:21:27.527421 2026] [security2:error] [pid 229246:tid 229408] [client 92.119.178.3:46294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IJyBMYeh5YLVG45xjyQAAAjQ"]
[Tue Jul 21 07:21:27.527554 2026] [security2:error] [pid 229246:tid 229408] [client 92.119.178.3:46294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IJyBMYeh5YLVG45xjyQAAAjQ"]
[Tue Jul 21 07:21:27.692584 2026] [security2:error] [pid 230252:tid 230440] [client 20.206.105.145:30698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/themes.php"] [unique_id "al9IJ00Dwhk5-Z44Xro_EAAAAtE"]
[Tue Jul 21 07:21:27.697808 2026] [security2:error] [pid 229246:tid 229475] [client 74.249.245.134:58640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/edit.php"] [unique_id "al9IJyBMYeh5YLVG45xjzAAAAnc"]
[Tue Jul 21 07:21:27.734199 2026] [http2:warn] [pid 229246:tid 229425] [client 57.141.18.19:39198] h2_stream(229246-326-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:27.891438 2026] [security2:error] [pid 230252:tid 230368] [remote 114.119.157.37:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.naturofarma.com.br"] [uri "/imagem.php"] [unique_id "al9IJ00Dwhk5-Z44Xro_EQACnnE"], referer: https://www.naturofarma.com.br/imagem.php?tipo=8&cod_img=179289
[Tue Jul 21 07:21:28.049737 2026] [security2:error] [pid 229246:tid 229398] [client 20.197.192.193:27167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/tkikikoko.php"] [unique_id "al9IKCBMYeh5YLVG45xj0AAAAio"]
[Tue Jul 21 07:21:28.076253 2026] [security2:error] [pid 229246:tid 229476] [client 20.104.96.117:61125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/iywwi.php"] [unique_id "al9IKCBMYeh5YLVG45xj0QAAAng"]
[Tue Jul 21 07:21:28.121165 2026] [security2:error] [pid 230252:tid 230398] [client 4.204.201.85:43949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/a1.php"] [unique_id "al9IKE0Dwhk5-Z44Xro_EwAAAqc"]
[Tue Jul 21 07:21:28.181080 2026] [security2:error] [pid 230252:tid 230291] [remote 156.59.198.136:35660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "issima.net.br"] [uri "/equestre/assina-vert/assina-vert.pdf"] [unique_id "al9IKE0Dwhk5-Z44Xro_FAAC3iU"]
[Tue Jul 21 07:21:28.536729 2026] [security2:error] [pid 230252:tid 230403] [client 4.204.201.85:17892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/eee.php"] [unique_id "al9IKE0Dwhk5-Z44Xro_FgAAAqw"]
[Tue Jul 21 07:21:28.683651 2026] [http2:warn] [pid 230252:tid 230393] [client 57.141.18.50:48664] h2_stream(230252-161-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:28.815446 2026] [security2:error] [pid 229246:tid 229464] [client 134.19.179.187:36292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IKCBMYeh5YLVG45xj3gAAAmw"]
[Tue Jul 21 07:21:28.815543 2026] [security2:error] [pid 229246:tid 229464] [client 134.19.179.187:36292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IKCBMYeh5YLVG45xj3gAAAmw"]
[Tue Jul 21 07:21:28.827199 2026] [security2:error] [pid 229246:tid 229478] [client 92.222.104.192:62314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "porondeeuestive.com.br"] [uri "/"] [unique_id "al9IKCBMYeh5YLVG45xj3wAAAno"]
[Tue Jul 21 07:21:28.827290 2026] [security2:error] [pid 229246:tid 229478] [client 92.222.104.192:62314] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "porondeeuestive.com.br"] [uri "/"] [unique_id "al9IKCBMYeh5YLVG45xj3wAAAno"]
[Tue Jul 21 07:21:28.881489 2026] [security2:error] [pid 230252:tid 230501] [client 20.104.96.117:59175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/gqgsa.php"] [unique_id "al9IKE0Dwhk5-Z44Xro_GwAAAw4"]
[Tue Jul 21 07:21:28.986975 2026] [security2:error] [pid 229246:tid 229403] [client 20.220.225.223:52745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/berlin.php"] [unique_id "al9IKCBMYeh5YLVG45xj4gAAAi8"]
[Tue Jul 21 07:21:29.575036 2026] [security2:error] [pid 230252:tid 230409] [client 20.226.60.151:54500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/classwithtostring.php"] [unique_id "al9IKU0Dwhk5-Z44Xro_IgAAArI"]
[Tue Jul 21 07:21:29.609768 2026] [http2:warn] [pid 230252:tid 230415] [client 57.141.18.19:30238] h2_stream(230252-165-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:29.623254 2026] [security2:error] [pid 229246:tid 229304] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IKSBMYeh5YLVG45xj9QACUDk"]
[Tue Jul 21 07:21:29.623431 2026] [security2:error] [pid 229246:tid 229436] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IKSBMYeh5YLVG45xj9QACUDk"]
[Tue Jul 21 07:21:29.808041 2026] [security2:error] [pid 230252:tid 230500] [client 4.204.201.85:17793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/wp-aothait.php"] [unique_id "al9IKU0Dwhk5-Z44Xro_IwAAAw0"]
[Tue Jul 21 07:21:29.911226 2026] [security2:error] [pid 229246:tid 229409] [client 20.206.105.145:30717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/8.php"] [unique_id "al9IKSBMYeh5YLVG45xj-QAAAjU"]
[Tue Jul 21 07:21:29.911481 2026] [security2:error] [pid 229246:tid 229351] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IKSBMYeh5YLVG45xj-AACdGg"]
[Tue Jul 21 07:21:29.911603 2026] [security2:error] [pid 229246:tid 229472] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IKSBMYeh5YLVG45xj-AACdGg"]
[Tue Jul 21 07:21:29.990330 2026] [security2:error] [pid 230252:tid 230442] [client 103.174.34.15:63636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IKU0Dwhk5-Z44Xro_JQAAAtM"]
[Tue Jul 21 07:21:29.990489 2026] [security2:error] [pid 230252:tid 230442] [client 103.174.34.15:63636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IKU0Dwhk5-Z44Xro_JQAAAtM"]
[Tue Jul 21 07:21:30.004643 2026] [security2:error] [pid 229246:tid 229383] [client 20.197.192.193:26892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9IKiBMYeh5YLVG45xj-gAAAhs"]
[Tue Jul 21 07:21:30.044915 2026] [security2:error] [pid 230252:tid 230420] [client 20.206.105.145:30614] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/1.php"] [unique_id "al9IKk0Dwhk5-Z44Xro_JwAAAr0"]
[Tue Jul 21 07:21:30.045036 2026] [security2:error] [pid 230252:tid 230420] [client 20.206.105.145:30614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/1.php"] [unique_id "al9IKk0Dwhk5-Z44Xro_JwAAAr0"]
[Tue Jul 21 07:21:30.158288 2026] [security2:error] [pid 230252:tid 230476] [client 184.75.221.3:58332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9IKk0Dwhk5-Z44Xro_MgAAAvU"]
[Tue Jul 21 07:21:30.158383 2026] [security2:error] [pid 230252:tid 230476] [client 184.75.221.3:58332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9IKk0Dwhk5-Z44Xro_MgAAAvU"]
[Tue Jul 21 07:21:30.163913 2026] [security2:error] [pid 230252:tid 230268] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IKk0Dwhk5-Z44Xro_MwAC0Q4"]
[Tue Jul 21 07:21:30.164055 2026] [security2:error] [pid 230252:tid 230440] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IKk0Dwhk5-Z44Xro_MwAC0Q4"]
[Tue Jul 21 07:21:30.253557 2026] [security2:error] [pid 229246:tid 229477] [client 20.206.105.145:30615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/100.php"] [unique_id "al9IKiBMYeh5YLVG45xj_gAAAnk"]
[Tue Jul 21 07:21:30.261737 2026] [security2:error] [pid 230252:tid 230403] [client 4.204.201.85:17815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/config.json.php"] [unique_id "al9IKk0Dwhk5-Z44Xro_NQAAAqw"]
[Tue Jul 21 07:21:30.282298 2026] [security2:error] [pid 230252:tid 230458] [client 20.104.96.117:59669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/elbzl.php"] [unique_id "al9IKk0Dwhk5-Z44Xro_NgAAAuM"]
[Tue Jul 21 07:21:30.408306 2026] [security2:error] [pid 230252:tid 230263] [remote 97.74.87.194:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/wp-login.php"] [unique_id "al9IKk0Dwhk5-Z44Xro_NwAC_wk"]
[Tue Jul 21 07:21:30.721483 2026] [security2:error] [pid 230252:tid 230451] [client 4.204.201.85:17867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9IKk0Dwhk5-Z44Xro_PQAAAtw"]
[Tue Jul 21 07:21:30.727357 2026] [security2:error] [pid 230252:tid 230411] [client 20.220.225.223:60092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/billur.php"] [unique_id "al9IKk0Dwhk5-Z44Xro_PgAAArQ"]
[Tue Jul 21 07:21:30.980432 2026] [security2:error] [pid 229246:tid 229431] [client 20.104.96.117:59668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/adjig.php"] [unique_id "al9IKiBMYeh5YLVG45xkAwAAAks"]
[Tue Jul 21 07:21:31.015914 2026] [http2:warn] [pid 229246:tid 229486] [client 57.141.18.26:27796] h2_stream(229246-338-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:31.073850 2026] [security2:error] [pid 229246:tid 229406] [client 20.206.105.145:30613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/about.php"] [unique_id "al9IKyBMYeh5YLVG45xkBwAAAjI"]
[Tue Jul 21 07:21:31.176395 2026] [security2:error] [pid 230252:tid 230511] [client 175.45.70.82:53327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IK00Dwhk5-Z44Xro_QAAAAxg"]
[Tue Jul 21 07:21:31.176522 2026] [security2:error] [pid 230252:tid 230511] [client 175.45.70.82:53327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IK00Dwhk5-Z44Xro_QAAAAxg"]
[Tue Jul 21 07:21:31.338077 2026] [security2:error] [pid 229246:tid 229447] [client 139.135.44.145:53137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IKyBMYeh5YLVG45xkDQAAAls"]
[Tue Jul 21 07:21:31.338282 2026] [security2:error] [pid 229246:tid 229447] [client 139.135.44.145:53137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IKyBMYeh5YLVG45xkDQAAAls"]
[Tue Jul 21 07:21:31.422906 2026] [http2:warn] [pid 230252:tid 230460] [client 57.141.18.110:55522] h2_stream(230252-167-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:31.463869 2026] [security2:error] [pid 229246:tid 229421] [client 136.144.33.97:21539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IKyBMYeh5YLVG45xkCwAAAkE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:31.516565 2026] [security2:error] [pid 230252:tid 230399] [client 20.197.192.193:26901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/wp-css.php"] [unique_id "al9IK00Dwhk5-Z44Xro_QQAAAqg"]
[Tue Jul 21 07:21:31.576873 2026] [security2:error] [pid 229246:tid 229471] [client 4.204.201.85:43931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/k2.php"] [unique_id "al9IKyBMYeh5YLVG45xkEgAAAnM"]
[Tue Jul 21 07:21:31.883165 2026] [security2:error] [pid 230252:tid 230436] [client 74.249.245.134:58669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/166.php"] [unique_id "al9IK00Dwhk5-Z44Xro_RgAAAs0"]
[Tue Jul 21 07:21:31.960658 2026] [security2:error] [pid 230252:tid 230414] [client 20.151.10.161:45898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9IK00Dwhk5-Z44Xro_RwAAArc"]
[Tue Jul 21 07:21:32.015893 2026] [security2:error] [pid 229246:tid 229495] [client 20.104.96.117:59648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/byp.php"] [unique_id "al9ILCBMYeh5YLVG45xkGAAAAos"]
[Tue Jul 21 07:21:32.100584 2026] [security2:error] [pid 230252:tid 230392] [client 74.7.241.130:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "304"] [hostname "sobradoimoveis.com"] [uri "/robots.txt"] [unique_id "al9ILE0Dwhk5-Z44Xro_SQAAAqE"]
[Tue Jul 21 07:21:32.188410 2026] [security2:error] [pid 230252:tid 230306] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9ILE0Dwhk5-Z44Xro_SgADFzQ"]
[Tue Jul 21 07:21:32.188535 2026] [security2:error] [pid 230252:tid 230510] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9ILE0Dwhk5-Z44Xro_SgADFzQ"]
[Tue Jul 21 07:21:32.239402 2026] [security2:error] [pid 229246:tid 229492] [client 20.220.225.223:34192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/zzz.php"] [unique_id "al9ILCBMYeh5YLVG45xkGwAAAog"]
[Tue Jul 21 07:21:32.241063 2026] [security2:error] [pid 229246:tid 229470] [client 4.204.201.85:17810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9ILCBMYeh5YLVG45xkHAAAAnI"]
[Tue Jul 21 07:21:32.271400 2026] [http2:warn] [pid 229246:tid 229433] [client 57.141.18.57:48542] h2_stream(229246-341-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:32.370304 2026] [security2:error] [pid 230252:tid 230264] [remote 202.51.202.242:34532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9ILE0Dwhk5-Z44Xro_SwACxQo"]
[Tue Jul 21 07:21:32.370493 2026] [security2:error] [pid 230252:tid 230428] [client 202.51.202.242:34532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9ILE0Dwhk5-Z44Xro_SwACxQo"]
[Tue Jul 21 07:21:32.383844 2026] [security2:error] [pid 229246:tid 229436] [client 20.206.105.145:30532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/about.php"] [unique_id "al9ILCBMYeh5YLVG45xkIAAAAlA"]
[Tue Jul 21 07:21:32.736980 2026] [security2:error] [pid 230252:tid 230463] [client 20.104.96.117:59672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9ILE0Dwhk5-Z44Xro_UQAAAug"]
[Tue Jul 21 07:21:33.028452 2026] [security2:error] [pid 230252:tid 230451] [client 4.204.201.85:17919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9ILU0Dwhk5-Z44Xro_WwAAAtw"]
[Tue Jul 21 07:21:33.033803 2026] [security2:error] [pid 230252:tid 230385] [client 54.39.136.109:59344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "formaesplendida.com"] [uri "/robots.txt"] [unique_id "al9ILU0Dwhk5-Z44Xro_XQAAApo"]
[Tue Jul 21 07:21:33.033949 2026] [security2:error] [pid 230252:tid 230385] [client 54.39.136.109:59344] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "formaesplendida.com"] [uri "/robots.txt"] [unique_id "al9ILU0Dwhk5-Z44Xro_XQAAApo"]
[Tue Jul 21 07:21:33.052553 2026] [proxy:error] [pid 230252:tid 230511] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.052610 2026] [proxy_http:error] [pid 230252:tid 230511] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.053040 2026] [proxy:error] [pid 230252:tid 230511] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.053064 2026] [proxy_http:error] [pid 230252:tid 230511] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.086374 2026] [proxy:error] [pid 230252:tid 230389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.086452 2026] [proxy_http:error] [pid 230252:tid 230389] [client 2a03:b0c0:3:d0::1413:d001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.087688 2026] [proxy:error] [pid 230252:tid 230389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.087727 2026] [proxy_http:error] [pid 230252:tid 230389] [client 2a03:b0c0:3:d0::1413:d001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.152525 2026] [proxy:error] [pid 230252:tid 230443] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.152577 2026] [proxy_http:error] [pid 230252:tid 230443] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.153020 2026] [proxy:error] [pid 230252:tid 230443] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.153047 2026] [proxy_http:error] [pid 230252:tid 230443] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.198526 2026] [proxy:error] [pid 230252:tid 230485] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.198582 2026] [proxy_http:error] [pid 230252:tid 230485] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.199185 2026] [proxy:error] [pid 230252:tid 230485] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.199218 2026] [proxy_http:error] [pid 230252:tid 230485] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.202786 2026] [proxy:error] [pid 230252:tid 230499] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.202840 2026] [proxy_http:error] [pid 230252:tid 230499] [client 2a03:b0c0:1:d0::e05:9001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.203275 2026] [proxy:error] [pid 230252:tid 230499] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.203296 2026] [proxy_http:error] [pid 230252:tid 230499] [client 2a03:b0c0:1:d0::e05:9001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.226970 2026] [proxy:error] [pid 229246:tid 229452] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.227014 2026] [proxy_http:error] [pid 229246:tid 229452] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.227473 2026] [proxy:error] [pid 229246:tid 229452] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.227497 2026] [proxy_http:error] [pid 229246:tid 229452] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.262016 2026] [security2:error] [pid 229246:tid 229488] [client 184.75.221.3:58336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9ILSBMYeh5YLVG45xkMwAAAoQ"]
[Tue Jul 21 07:21:33.262110 2026] [security2:error] [pid 229246:tid 229488] [client 184.75.221.3:58336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9ILSBMYeh5YLVG45xkMwAAAoQ"]
[Tue Jul 21 07:21:33.337146 2026] [http2:warn] [pid 230252:tid 230475] [client 57.141.18.25:21576] h2_stream(230252-171-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:33.353488 2026] [security2:error] [pid 229246:tid 229484] [client 20.206.105.145:30719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/admin.php"] [unique_id "al9ILSBMYeh5YLVG45xkOAAAAoA"]
[Tue Jul 21 07:21:33.353990 2026] [proxy:error] [pid 230252:tid 230403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.354062 2026] [proxy_http:error] [pid 230252:tid 230403] [client 2a03:b0c0:3:d0::12f7:9001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.354757 2026] [proxy:error] [pid 230252:tid 230403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.354786 2026] [proxy_http:error] [pid 230252:tid 230403] [client 2a03:b0c0:3:d0::12f7:9001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.455327 2026] [proxy:error] [pid 230252:tid 230447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.455391 2026] [proxy_http:error] [pid 230252:tid 230447] [client 2400:6180:0:d0::1182:2001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.455937 2026] [proxy:error] [pid 230252:tid 230447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.455962 2026] [proxy_http:error] [pid 230252:tid 230447] [client 2400:6180:0:d0::1182:2001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.788705 2026] [security2:error] [pid 230252:tid 230500] [client 4.204.201.85:43902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9ILU0Dwhk5-Z44Xro_iwAAAw0"]
[Tue Jul 21 07:21:33.822585 2026] [security2:error] [pid 230252:tid 230436] [client 20.197.192.193:27177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/wp-explorer.php"] [unique_id "al9ILU0Dwhk5-Z44Xro_jQAAAs0"]
[Tue Jul 21 07:21:33.854512 2026] [security2:error] [pid 230252:tid 230485] [client 114.119.134.165:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sobradoimoveis.com"] [uri "/imovel/terreno-venda-joao-costa-joinville-sc-2519"] [unique_id "al9ILU0Dwhk5-Z44Xro_jgAAAv4"], referer: https://sobradoimoveis.com/
[Tue Jul 21 07:21:33.946071 2026] [security2:error] [pid 230252:tid 230430] [client 20.151.10.161:45835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/aaa.php"] [unique_id "al9ILU0Dwhk5-Z44Xro_jwAAAsc"]
[Tue Jul 21 07:21:34.082223 2026] [proxy:error] [pid 229246:tid 229414] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:34.082292 2026] [proxy_http:error] [pid 229246:tid 229414] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:34.082800 2026] [proxy:error] [pid 229246:tid 229414] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:34.082842 2026] [proxy_http:error] [pid 229246:tid 229414] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:34.095728 2026] [http2:warn] [pid 229246:tid 229483] [client 57.141.18.104:63944] h2_stream(229246-351-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:34.195501 2026] [proxy:error] [pid 230252:tid 230506] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:34.195560 2026] [proxy_http:error] [pid 230252:tid 230506] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:34.196027 2026] [proxy:error] [pid 230252:tid 230506] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:34.196052 2026] [proxy_http:error] [pid 230252:tid 230506] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:34.225810 2026] [proxy:error] [pid 230252:tid 230403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:34.225873 2026] [proxy_http:error] [pid 230252:tid 230403] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:34.226513 2026] [proxy:error] [pid 230252:tid 230403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:34.226538 2026] [proxy_http:error] [pid 230252:tid 230403] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:34.233809 2026] [proxy:error] [pid 230252:tid 230416] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:34.233865 2026] [proxy_http:error] [pid 230252:tid 230416] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:34.234291 2026] [proxy:error] [pid 230252:tid 230416] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:34.234313 2026] [proxy_http:error] [pid 230252:tid 230416] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:34.258031 2026] [security2:error] [pid 230252:tid 230442] [client 20.104.96.117:61165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/classwithtostring.php"] [unique_id "al9ILk0Dwhk5-Z44Xro_nQAAAtM"]
[Tue Jul 21 07:21:34.335140 2026] [security2:error] [pid 230252:tid 230414] [client 4.204.201.85:17910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/for.php"] [unique_id "al9ILk0Dwhk5-Z44Xro_oQAAArc"]
[Tue Jul 21 07:21:34.350943 2026] [security2:error] [pid 230252:tid 230456] [client 103.162.129.114:63232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9ILk0Dwhk5-Z44Xro_ogAAAuE"]
[Tue Jul 21 07:21:34.351048 2026] [security2:error] [pid 230252:tid 230456] [client 103.162.129.114:63232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9ILk0Dwhk5-Z44Xro_ogAAAuE"]
[Tue Jul 21 07:21:34.445319 2026] [security2:error] [pid 230252:tid 230479] [client 15.235.27.226:15964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "formaesplendida.com"] [uri "/"] [unique_id "al9ILk0Dwhk5-Z44Xro_owAAAvg"]
[Tue Jul 21 07:21:34.445439 2026] [security2:error] [pid 230252:tid 230479] [client 15.235.27.226:15964] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "formaesplendida.com"] [uri "/"] [unique_id "al9ILk0Dwhk5-Z44Xro_owAAAvg"]
[Tue Jul 21 07:21:34.499854 2026] [security2:error] [pid 230252:tid 230484] [client 103.121.156.110:63555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9ILk0Dwhk5-Z44Xro_pwAAAv0"]
[Tue Jul 21 07:21:34.500036 2026] [security2:error] [pid 230252:tid 230484] [client 103.121.156.110:63555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9ILk0Dwhk5-Z44Xro_pwAAAv0"]
[Tue Jul 21 07:21:34.885008 2026] [http2:warn] [pid 229246:tid 229402] [client 57.141.18.100:55070] h2_stream(229246-354-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:35.062662 2026] [proxy:error] [pid 230252:tid 230415] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:35.062736 2026] [proxy_http:error] [pid 230252:tid 230415] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:35.063560 2026] [proxy:error] [pid 230252:tid 230415] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:35.063595 2026] [proxy_http:error] [pid 230252:tid 230415] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:35.181485 2026] [proxy:error] [pid 229246:tid 229488] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:35.181542 2026] [proxy_http:error] [pid 229246:tid 229488] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:35.182146 2026] [proxy:error] [pid 229246:tid 229488] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:35.182182 2026] [proxy_http:error] [pid 229246:tid 229488] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:35.203014 2026] [security2:error] [pid 229246:tid 229381] [client 20.206.105.145:30682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/admin.php"] [unique_id "al9ILyBMYeh5YLVG45xkYwAAAhk"]
[Tue Jul 21 07:21:35.204228 2026] [proxy:error] [pid 230252:tid 230421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:35.204276 2026] [proxy_http:error] [pid 230252:tid 230421] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:35.204837 2026] [proxy:error] [pid 230252:tid 230421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:35.204861 2026] [proxy_http:error] [pid 230252:tid 230421] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:35.208139 2026] [security2:error] [pid 230252:tid 230340] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IL00Dwhk5-Z44Xro_0gAC_VU"]
[Tue Jul 21 07:21:35.208244 2026] [security2:error] [pid 230252:tid 230484] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IL00Dwhk5-Z44Xro_0gAC_VU"]
[Tue Jul 21 07:21:35.222932 2026] [proxy:error] [pid 230252:tid 230441] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:35.222979 2026] [proxy_http:error] [pid 230252:tid 230441] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:35.223464 2026] [proxy:error] [pid 230252:tid 230441] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:35.223486 2026] [proxy_http:error] [pid 230252:tid 230441] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:35.285974 2026] [security2:error] [pid 229246:tid 229478] [client 4.204.201.85:17798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/raw.php"] [unique_id "al9ILyBMYeh5YLVG45xkZwAAAno"]
[Tue Jul 21 07:21:35.455998 2026] [security2:error] [pid 230252:tid 230255] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IL00Dwhk5-Z44Xro_4AADFwE"]
[Tue Jul 21 07:21:35.456142 2026] [security2:error] [pid 230252:tid 230510] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IL00Dwhk5-Z44Xro_4AADFwE"]
[Tue Jul 21 07:21:35.710768 2026] [security2:error] [pid 230252:tid 230442] [client 20.220.225.223:34237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/wicked.php"] [unique_id "al9IL00Dwhk5-Z44Xro_5wAAAtM"]
[Tue Jul 21 07:21:35.912302 2026] [http2:warn] [pid 230252:tid 230483] [client 57.141.18.110:36590] h2_stream(230252-178-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:35.947350 2026] [security2:error] [pid 230252:tid 230485] [client 206.189.19.19:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webdisk.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/server-status"] [unique_id "al9IL00Dwhk5-Z44Xro_8QAAAv4"]
[Tue Jul 21 07:21:36.066958 2026] [security2:error] [pid 230252:tid 230472] [client 136.144.33.111:32969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IME0Dwhk5-Z44Xro_9wAAAvE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:36.068959 2026] [security2:error] [pid 229246:tid 229384] [client 64.23.218.208:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webmail.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/server-status"] [unique_id "al9IMCBMYeh5YLVG45xkgAAAAhw"]
[Tue Jul 21 07:21:36.088865 2026] [security2:error] [pid 229246:tid 229494] [client 157.230.19.140:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webdisk.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/server-status"] [unique_id "al9IMCBMYeh5YLVG45xkgQAAAoo"]
[Tue Jul 21 07:21:36.094384 2026] [security2:error] [pid 229246:tid 229416] [client 143.110.217.244:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpanel.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/server-status"] [unique_id "al9IMCBMYeh5YLVG45xkgwAAAjw"]
[Tue Jul 21 07:21:36.101881 2026] [security2:error] [pid 230252:tid 230443] [client 134.209.25.199:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcontacts.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/server-status"] [unique_id "al9IME0Dwhk5-Z44Xro_-QAAAtQ"]
[Tue Jul 21 07:21:36.164630 2026] [security2:error] [pid 230252:tid 230399] [client 139.59.136.184:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpanel.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/server-status"] [unique_id "al9IME0Dwhk5-Z44Xro_-gAAAqg"]
[Tue Jul 21 07:21:36.171693 2026] [security2:error] [pid 230252:tid 230411] [client 64.226.65.160:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcalendars.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/server-status"] [unique_id "al9IME0Dwhk5-Z44Xro__AAAArQ"]
[Tue Jul 21 07:21:36.171975 2026] [access_compat:error] [pid 229246:tid 229337] [remote 167.172.232.142:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:36.212208 2026] [access_compat:error] [pid 230252:tid 230463] [client 147.182.200.94:0] AH01797: client denied by server configuration: proxy:http://127.0.0.1/cgi-sys/autodiscover.cgi
[Tue Jul 21 07:21:36.233193 2026] [security2:error] [pid 229246:tid 229451] [client 46.101.1.225:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcalendars.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/server-status"] [unique_id "al9IMCBMYeh5YLVG45xkhwAAAl8"]
[Tue Jul 21 07:21:36.279770 2026] [security2:error] [pid 229246:tid 229476] [client 64.23.218.208:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webmail.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/server-status"] [unique_id "al9IMCBMYeh5YLVG45xkiAAAAng"]
[Tue Jul 21 07:21:36.288714 2026] [http2:warn] [pid 229246:tid 229423] [client 57.141.18.39:62468] h2_stream(229246-361-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:36.319709 2026] [security2:error] [pid 230252:tid 230506] [client 139.59.132.8:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcontacts.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/server-status"] [unique_id "al9IME0Dwhk5-Z44XrpAAQAAAxM"]
[Tue Jul 21 07:21:36.366435 2026] [access_compat:error] [pid 229246:tid 229400] [client 143.110.213.72:0] AH01797: client denied by server configuration: proxy:http://127.0.0.1/cgi-sys/autodiscover.cgi
[Tue Jul 21 07:21:36.366983 2026] [security2:error] [pid 230252:tid 230404] [client 107.172.140.193:36904] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "gpcom.com.br"] [uri "/"] [unique_id "al9IME0Dwhk5-Z44XrpABAAAAq0"]
[Tue Jul 21 07:21:36.426414 2026] [security2:error] [pid 229246:tid 229414] [client 45.251.232.145:49423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IMCBMYeh5YLVG45xkjAAAAjo"]
[Tue Jul 21 07:21:36.426522 2026] [security2:error] [pid 229246:tid 229414] [client 45.251.232.145:49423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IMCBMYeh5YLVG45xkjAAAAjo"]
[Tue Jul 21 07:21:36.482303 2026] [security2:error] [pid 230252:tid 230410] [client 20.104.96.117:61140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/root.php"] [unique_id "al9IME0Dwhk5-Z44XrpACgAAArM"]
[Tue Jul 21 07:21:36.513088 2026] [access_compat:error] [pid 230252:tid 230458] [client 165.22.235.3:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:36.590357 2026] [access_compat:error] [pid 230252:tid 230403] [client 167.71.175.236:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:36.593364 2026] [access_compat:error] [pid 230252:tid 230509] [client 207.154.197.113:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:36.661119 2026] [security2:error] [pid 230252:tid 230500] [client 14.139.42.196:15932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IME0Dwhk5-Z44XrpAEQAAAw0"]
[Tue Jul 21 07:21:36.661241 2026] [security2:error] [pid 230252:tid 230500] [client 14.139.42.196:15932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IME0Dwhk5-Z44XrpAEQAAAw0"]
[Tue Jul 21 07:21:36.681411 2026] [access_compat:error] [pid 230252:tid 230395] [client 206.189.233.36:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:36.692181 2026] [security2:error] [pid 230252:tid 230442] [client 20.197.192.193:27157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/akismet.php"] [unique_id "al9IME0Dwhk5-Z44XrpAEgAAAtM"]
[Tue Jul 21 07:21:36.698906 2026] [access_compat:error] [pid 230252:tid 230465] [client 146.190.63.248:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:36.849866 2026] [security2:error] [pid 230252:tid 230455] [client 20.206.105.145:30538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/edit.php"] [unique_id "al9IME0Dwhk5-Z44XrpAFQAAAuA"]
[Tue Jul 21 07:21:36.855714 2026] [access_compat:error] [pid 230252:tid 230511] [client 165.227.84.14:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:36.895377 2026] [access_compat:error] [pid 229246:tid 229460] [client 167.71.175.236:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:37.029067 2026] [access_compat:error] [pid 229246:tid 229312] [remote 138.197.191.87:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:37.032291 2026] [security2:error] [pid 230252:tid 230439] [client 114.119.150.95:34871] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "acaiofficial.com.br"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/"] [unique_id "al9IMU0Dwhk5-Z44XrpAGAAAAtA"], referer: https://acaiofficial.com.br/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/
[Tue Jul 21 07:21:37.045784 2026] [http2:warn] [pid 230252:tid 230432] [client 57.141.18.109:63044] h2_stream(230252-182-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:37.093129 2026] [access_compat:error] [pid 230252:tid 230415] [client 138.68.144.227:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:37.098586 2026] [access_compat:error] [pid 229246:tid 229473] [client 68.183.180.73:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:37.169591 2026] [security2:error] [pid 230252:tid 230304] [remote 114.34.90.9:41450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.90.34.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9IMU0Dwhk5-Z44XrpAHgAC4jI"]
[Tue Jul 21 07:21:37.527997 2026] [security2:error] [pid 230252:tid 230416] [client 20.206.105.145:30706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-content/admin.php"] [unique_id "al9IMU0Dwhk5-Z44XrpAIwAAArk"]
[Tue Jul 21 07:21:37.576608 2026] [security2:error] [pid 230252:tid 230379] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IMU0Dwhk5-Z44XrpAJwACvXw"]
[Tue Jul 21 07:21:37.576791 2026] [security2:error] [pid 230252:tid 230420] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IMU0Dwhk5-Z44XrpAJwACvXw"]
[Tue Jul 21 07:21:37.825882 2026] [security2:error] [pid 230252:tid 230440] [client 20.104.96.117:59189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/sym403.php"] [unique_id "al9IMU0Dwhk5-Z44XrpAKwAAAtE"]
[Tue Jul 21 07:21:37.835663 2026] [security2:error] [pid 230252:tid 230451] [client 68.235.38.2:52860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IMU0Dwhk5-Z44XrpALAAAAtw"]
[Tue Jul 21 07:21:37.835743 2026] [security2:error] [pid 230252:tid 230451] [client 68.235.38.2:52860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IMU0Dwhk5-Z44XrpALAAAAtw"]
[Tue Jul 21 07:21:37.959976 2026] [http2:warn] [pid 229246:tid 229390] [client 57.141.18.17:59336] h2_stream(229246-365-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:38.056800 2026] [proxy:error] [pid 230252:tid 230456] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:38.056879 2026] [proxy_http:error] [pid 230252:tid 230456] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:38.057585 2026] [proxy:error] [pid 230252:tid 230456] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:38.057610 2026] [proxy_http:error] [pid 230252:tid 230456] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:38.071686 2026] [access_compat:error] [pid 230252:tid 230403] [client 142.93.143.8:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:38.185624 2026] [proxy:error] [pid 230252:tid 230421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:38.185693 2026] [proxy_http:error] [pid 230252:tid 230421] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:38.186335 2026] [proxy:error] [pid 230252:tid 230421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:38.186371 2026] [proxy_http:error] [pid 230252:tid 230421] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:38.230518 2026] [proxy:error] [pid 230252:tid 230457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:38.230570 2026] [proxy_http:error] [pid 230252:tid 230457] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:38.231033 2026] [proxy:error] [pid 230252:tid 230457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:38.231059 2026] [proxy_http:error] [pid 230252:tid 230457] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:38.232300 2026] [security2:error] [pid 230252:tid 230409] [client 20.206.105.145:30536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/f6.php"] [unique_id "al9IMk0Dwhk5-Z44XrpAOgAAArI"]
[Tue Jul 21 07:21:38.276433 2026] [proxy:error] [pid 230252:tid 230454] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:38.276509 2026] [proxy_http:error] [pid 230252:tid 230454] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:38.277256 2026] [proxy:error] [pid 230252:tid 230454] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:38.277301 2026] [proxy_http:error] [pid 230252:tid 230454] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:38.323538 2026] [security2:error] [pid 230252:tid 230476] [client 20.226.60.151:54560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/root.php"] [unique_id "al9IMk0Dwhk5-Z44XrpAQAAAAvU"]
[Tue Jul 21 07:21:38.455097 2026] [security2:error] [pid 229246:tid 229382] [client 74.249.245.134:61557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/8.php"] [unique_id "al9IMiBMYeh5YLVG45xkqQAAAho"]
[Tue Jul 21 07:21:38.613560 2026] [security2:error] [pid 229246:tid 229486] [client 20.104.96.117:59666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/v543.php"] [unique_id "al9IMiBMYeh5YLVG45xkrgAAAoI"]
[Tue Jul 21 07:21:38.750872 2026] [security2:error] [pid 229246:tid 229380] [client 20.206.105.145:30696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/inputs.php"] [unique_id "al9IMiBMYeh5YLVG45xksgAAAhg"]
[Tue Jul 21 07:21:38.752641 2026] [security2:error] [pid 229246:tid 229461] [client 20.220.225.223:52792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/mimpi.php"] [unique_id "al9IMiBMYeh5YLVG45xkswAAAmk"]
[Tue Jul 21 07:21:38.978930 2026] [security2:error] [pid 230252:tid 230510] [client 139.59.99.58:59321] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.vivaconcierge.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9IMk0Dwhk5-Z44XrpATQAAAxc"]
[Tue Jul 21 07:21:39.043530 2026] [proxy:error] [pid 230252:tid 230402] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:39.043615 2026] [proxy_http:error] [pid 230252:tid 230402] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:39.044671 2026] [proxy:error] [pid 230252:tid 230402] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:39.044729 2026] [proxy_http:error] [pid 230252:tid 230402] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:39.057413 2026] [proxy:error] [pid 229246:tid 229389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:39.057469 2026] [proxy_http:error] [pid 229246:tid 229389] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:39.057938 2026] [proxy:error] [pid 229246:tid 229389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:39.057965 2026] [proxy_http:error] [pid 229246:tid 229389] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:39.071321 2026] [security2:error] [pid 230252:tid 230415] [client 20.206.105.145:30638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/inputs.php"] [unique_id "al9IM00Dwhk5-Z44XrpAUAAAArg"]
[Tue Jul 21 07:21:39.202199 2026] [proxy:error] [pid 230252:tid 230447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:39.202267 2026] [proxy_http:error] [pid 230252:tid 230447] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:39.202855 2026] [proxy:error] [pid 230252:tid 230447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:39.202884 2026] [proxy_http:error] [pid 230252:tid 230447] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:39.271024 2026] [proxy:error] [pid 230252:tid 230436] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:39.271110 2026] [proxy_http:error] [pid 230252:tid 230436] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:39.271795 2026] [proxy:error] [pid 230252:tid 230436] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:39.271909 2026] [proxy_http:error] [pid 230252:tid 230436] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:39.381634 2026] [security2:error] [pid 230252:tid 230500] [client 20.220.225.223:34199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/edit.php"] [unique_id "al9IM00Dwhk5-Z44XrpAWwAAAw0"]
[Tue Jul 21 07:21:39.396603 2026] [security2:error] [pid 230252:tid 230492] [client 20.206.105.145:30678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/av.php"] [unique_id "al9IM00Dwhk5-Z44XrpAXAAAAwU"]
[Tue Jul 21 07:21:39.534660 2026] [security2:error] [pid 229246:tid 229499] [client 103.174.34.15:64265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IMyBMYeh5YLVG45xkwwAAAo8"]
[Tue Jul 21 07:21:39.534767 2026] [security2:error] [pid 229246:tid 229499] [client 103.174.34.15:64265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IMyBMYeh5YLVG45xkwwAAAo8"]
[Tue Jul 21 07:21:39.715948 2026] [http2:warn] [pid 230252:tid 230394] [client 57.141.18.11:41980] h2_stream(230252-197-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:39.912119 2026] [security2:error] [pid 230252:tid 230462] [client 20.206.105.145:30629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/classwithtostring.php"] [unique_id "al9IM00Dwhk5-Z44XrpAZQAAAuc"]
[Tue Jul 21 07:21:39.925152 2026] [http2:warn] [pid 230252:tid 230446] [client 57.141.18.113:40528] h2_stream(230252-199-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:40.077846 2026] [proxy:error] [pid 229246:tid 229403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.077919 2026] [proxy_http:error] [pid 229246:tid 229403] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.078631 2026] [proxy:error] [pid 229246:tid 229403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.078672 2026] [proxy_http:error] [pid 229246:tid 229403] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.177182 2026] [security2:error] [pid 230252:tid 230365] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9INE0Dwhk5-Z44XrpAbwACzW4"]
[Tue Jul 21 07:21:40.177356 2026] [security2:error] [pid 230252:tid 230436] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9INE0Dwhk5-Z44XrpAbwACzW4"]
[Tue Jul 21 07:21:40.180085 2026] [proxy:error] [pid 230252:tid 230445] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.180149 2026] [proxy_http:error] [pid 230252:tid 230445] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.180613 2026] [proxy:error] [pid 230252:tid 230445] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.180634 2026] [proxy_http:error] [pid 230252:tid 230445] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.195743 2026] [proxy:error] [pid 230252:tid 230386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.195809 2026] [proxy_http:error] [pid 230252:tid 230386] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.196511 2026] [proxy:error] [pid 230252:tid 230386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.196546 2026] [proxy_http:error] [pid 230252:tid 230386] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.277053 2026] [security2:error] [pid 229246:tid 229442] [client 20.206.105.145:30660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9INCBMYeh5YLVG45xk4AAAAlY"]
[Tue Jul 21 07:21:40.282849 2026] [proxy:error] [pid 230252:tid 230412] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.282901 2026] [proxy_http:error] [pid 230252:tid 230412] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.283499 2026] [proxy:error] [pid 230252:tid 230412] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.283522 2026] [proxy_http:error] [pid 230252:tid 230412] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.356766 2026] [security2:error] [pid 230252:tid 230408] [client 20.220.225.223:34255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/kua.php"] [unique_id "al9INE0Dwhk5-Z44XrpAdgAAArE"]
[Tue Jul 21 07:21:40.426245 2026] [security2:error] [pid 229246:tid 229459] [client 172.245.102.46:23747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9INCBMYeh5YLVG45xk6QAAAmc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:40.463355 2026] [proxy:error] [pid 229246:tid 229394] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.463427 2026] [proxy_http:error] [pid 229246:tid 229394] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.464396 2026] [proxy:error] [pid 229246:tid 229394] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.464448 2026] [proxy_http:error] [pid 229246:tid 229394] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.548741 2026] [proxy:error] [pid 230252:tid 230410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.548800 2026] [proxy_http:error] [pid 230252:tid 230410] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.549492 2026] [proxy:error] [pid 230252:tid 230410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.549521 2026] [proxy_http:error] [pid 230252:tid 230410] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.652373 2026] [security2:error] [pid 230252:tid 230362] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9INE0Dwhk5-Z44XrpAgwAC92s"]
[Tue Jul 21 07:21:40.652608 2026] [security2:error] [pid 230252:tid 230478] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9INE0Dwhk5-Z44XrpAgwAC92s"]
[Tue Jul 21 07:21:40.750738 2026] [security2:error] [pid 230252:tid 230348] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9INE0Dwhk5-Z44XrpAiQAC-10"]
[Tue Jul 21 07:21:40.750923 2026] [security2:error] [pid 230252:tid 230482] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9INE0Dwhk5-Z44XrpAiQAC-10"]
[Tue Jul 21 07:21:40.777288 2026] [security2:error] [pid 229246:tid 229499] [client 68.235.38.2:45166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9INCBMYeh5YLVG45xk9AAAAo8"]
[Tue Jul 21 07:21:40.777401 2026] [security2:error] [pid 229246:tid 229499] [client 68.235.38.2:45166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9INCBMYeh5YLVG45xk9AAAAo8"]
[Tue Jul 21 07:21:40.795150 2026] [proxy:error] [pid 229246:tid 229473] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.795218 2026] [proxy_http:error] [pid 229246:tid 229473] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.795711 2026] [proxy:error] [pid 229246:tid 229473] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.795746 2026] [proxy_http:error] [pid 229246:tid 229473] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.811761 2026] [security2:error] [pid 230252:tid 230403] [client 139.59.99.58:59963] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.vivaconcierge.com.br"] [uri "/"] [unique_id "al9INE0Dwhk5-Z44XrpAjQAAAqw"]
[Tue Jul 21 07:21:40.851079 2026] [proxy:error] [pid 229246:tid 229424] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.851180 2026] [proxy_http:error] [pid 229246:tid 229424] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.852474 2026] [proxy:error] [pid 229246:tid 229424] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.852536 2026] [proxy_http:error] [pid 229246:tid 229424] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.905756 2026] [proxy:error] [pid 229246:tid 229383] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.905811 2026] [proxy_http:error] [pid 229246:tid 229383] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.906360 2026] [proxy:error] [pid 229246:tid 229383] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.906384 2026] [proxy_http:error] [pid 229246:tid 229383] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.919006 2026] [security2:error] [pid 230252:tid 230386] [client 20.206.105.145:30700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-blog.php"] [unique_id "al9INE0Dwhk5-Z44XrpAkQAAAps"]
[Tue Jul 21 07:21:41.031234 2026] [security2:error] [pid 230252:tid 230474] [client 20.104.96.117:59711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/sixxis.php"] [unique_id "al9INU0Dwhk5-Z44XrpAlgAAAvM"]
[Tue Jul 21 07:21:41.069825 2026] [proxy:error] [pid 229246:tid 229484] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.069890 2026] [proxy_http:error] [pid 229246:tid 229484] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.070498 2026] [proxy:error] [pid 229246:tid 229484] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.070523 2026] [proxy_http:error] [pid 229246:tid 229484] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.135460 2026] [http2:warn] [pid 230252:tid 230438] [client 57.141.18.25:58600] h2_stream(230252-204-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:41.246145 2026] [proxy:error] [pid 229246:tid 229501] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.246206 2026] [proxy_http:error] [pid 229246:tid 229501] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.246683 2026] [proxy:error] [pid 229246:tid 229501] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.246713 2026] [proxy_http:error] [pid 229246:tid 229501] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.254632 2026] [proxy:error] [pid 229246:tid 229486] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.254681 2026] [proxy_http:error] [pid 229246:tid 229486] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.255269 2026] [proxy:error] [pid 229246:tid 229486] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.255297 2026] [proxy_http:error] [pid 229246:tid 229486] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.279713 2026] [proxy:error] [pid 229246:tid 229421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.279788 2026] [proxy_http:error] [pid 229246:tid 229421] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.280545 2026] [proxy:error] [pid 229246:tid 229421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.280599 2026] [proxy_http:error] [pid 229246:tid 229421] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.531253 2026] [proxy:error] [pid 230252:tid 230476] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.531327 2026] [proxy_http:error] [pid 230252:tid 230476] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.532024 2026] [proxy:error] [pid 230252:tid 230476] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.532063 2026] [proxy_http:error] [pid 230252:tid 230476] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.710326 2026] [security2:error] [pid 230252:tid 230419] [client 74.249.245.134:21694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/ws38.php"] [unique_id "al9INU0Dwhk5-Z44XrpArQAAArw"]
[Tue Jul 21 07:21:41.734898 2026] [security2:error] [pid 230252:tid 230456] [client 20.104.96.117:61121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/ip.php"] [unique_id "al9INU0Dwhk5-Z44XrpAsAAAAuE"]
[Tue Jul 21 07:21:41.794687 2026] [proxy:error] [pid 230252:tid 230483] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.794749 2026] [proxy_http:error] [pid 230252:tid 230483] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.795325 2026] [proxy:error] [pid 230252:tid 230483] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.795351 2026] [proxy_http:error] [pid 230252:tid 230483] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.884630 2026] [security2:error] [pid 229246:tid 229403] [client 175.45.70.82:53827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9INSBMYeh5YLVG45xlGwAAAi8"]
[Tue Jul 21 07:21:41.884772 2026] [security2:error] [pid 229246:tid 229403] [client 175.45.70.82:53827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9INSBMYeh5YLVG45xlGwAAAi8"]
[Tue Jul 21 07:21:41.888604 2026] [proxy:error] [pid 230252:tid 230426] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.888697 2026] [proxy_http:error] [pid 230252:tid 230426] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.890031 2026] [proxy:error] [pid 230252:tid 230426] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.890087 2026] [proxy_http:error] [pid 230252:tid 230426] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.982294 2026] [security2:error] [pid 230252:tid 230509] [client 20.206.105.145:30674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-content/admin.php"] [unique_id "al9INU0Dwhk5-Z44XrpAuwAAAxY"]
[Tue Jul 21 07:21:42.063058 2026] [http2:warn] [pid 229246:tid 229465] [client 57.141.18.17:59362] h2_stream(229246-371-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:42.076948 2026] [security2:error] [pid 230252:tid 230481] [client 20.226.60.151:60234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9INk0Dwhk5-Z44XrpAvgAAAvo"]
[Tue Jul 21 07:21:42.186338 2026] [security2:error] [pid 230252:tid 230404] [client 139.135.44.145:53880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9INk0Dwhk5-Z44XrpAwQAAAq0"]
[Tue Jul 21 07:21:42.186478 2026] [security2:error] [pid 230252:tid 230404] [client 139.135.44.145:53880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9INk0Dwhk5-Z44XrpAwQAAAq0"]
[Tue Jul 21 07:21:42.252686 2026] [proxy:error] [pid 230252:tid 230510] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:42.252757 2026] [proxy_http:error] [pid 230252:tid 230510] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:42.253478 2026] [proxy:error] [pid 230252:tid 230510] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:42.253516 2026] [proxy_http:error] [pid 230252:tid 230510] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:42.254220 2026] [proxy:error] [pid 230252:tid 230462] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:42.254333 2026] [proxy_http:error] [pid 230252:tid 230462] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:42.255385 2026] [proxy:error] [pid 230252:tid 230462] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:42.255449 2026] [proxy_http:error] [pid 230252:tid 230462] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:42.508689 2026] [security2:error] [pid 230252:tid 230436] [client 64.23.218.208:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "al9INk0Dwhk5-Z44XrpAyAAAAs0"]
[Tue Jul 21 07:21:42.585427 2026] [security2:error] [pid 229246:tid 229489] [client 64.23.218.208:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "al9INiBMYeh5YLVG45xlLAAAAoU"]
[Tue Jul 21 07:21:42.627343 2026] [http2:warn] [pid 230252:tid 230391] [client 57.141.18.117:34682] h2_stream(230252-212-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:42.730320 2026] [security2:error] [pid 229246:tid 229479] [client 167.71.175.236:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9INiBMYeh5YLVG45xlMgAAAns"]
[Tue Jul 21 07:21:42.734516 2026] [security2:error] [pid 230252:tid 230485] [client 165.22.235.3:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9INk0Dwhk5-Z44XrpAzgAAAv4"]
[Tue Jul 21 07:21:42.772971 2026] [proxy:error] [pid 230252:tid 230459] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:42.773046 2026] [proxy_http:error] [pid 230252:tid 230459] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:42.773910 2026] [proxy:error] [pid 230252:tid 230459] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:42.773943 2026] [proxy_http:error] [pid 230252:tid 230459] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:42.851285 2026] [security2:error] [pid 230252:tid 230439] [client 167.71.175.236:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.polianoduarteramos1782482019000.polianoduarteramos1781890012818.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9INk0Dwhk5-Z44XrpA0gAAAtA"]
[Tue Jul 21 07:21:42.857289 2026] [security2:error] [pid 230252:tid 230293] [remote 167.172.232.142:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9INk0Dwhk5-Z44XrpA0wACqyc"]
[Tue Jul 21 07:21:42.924154 2026] [security2:error] [pid 230252:tid 230409] [client 165.227.84.14:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.polianoduarteramos1782482019000.polianoduarteramos1781890012818.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9INk0Dwhk5-Z44XrpA1AAAArI"]
[Tue Jul 21 07:21:42.929260 2026] [security2:error] [pid 230252:tid 230341] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9INk0Dwhk5-Z44XrpA1QACx1Y"]
[Tue Jul 21 07:21:42.929412 2026] [security2:error] [pid 230252:tid 230430] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9INk0Dwhk5-Z44XrpA1QACx1Y"]
[Tue Jul 21 07:21:42.962300 2026] [security2:error] [pid 230252:tid 230481] [client 206.189.19.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "al9INk0Dwhk5-Z44XrpA1gAAAvo"]
[Tue Jul 21 07:21:43.056542 2026] [security2:error] [pid 230252:tid 230404] [client 157.230.19.140:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "al9IN00Dwhk5-Z44XrpA2gAAAq0"]
[Tue Jul 21 07:21:43.062538 2026] [security2:error] [pid 230252:tid 230486] [client 20.104.96.117:64060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9IN00Dwhk5-Z44XrpA2wAAAv8"]
[Tue Jul 21 07:21:43.092161 2026] [proxy:error] [pid 230252:tid 230462] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:43.092233 2026] [proxy_http:error] [pid 230252:tid 230462] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:43.092928 2026] [proxy:error] [pid 230252:tid 230462] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:43.092956 2026] [proxy_http:error] [pid 230252:tid 230462] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:43.093231 2026] [security2:error] [pid 230252:tid 230463] [client 206.189.233.36:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "polianoduarteramos1782482019000.polianoduarteramos1781890012818.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9IN00Dwhk5-Z44XrpA3QAAAug"]
[Tue Jul 21 07:21:43.169838 2026] [security2:error] [pid 230252:tid 230472] [client 20.226.60.151:60254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9IN00Dwhk5-Z44XrpA3gAAAvE"]
[Tue Jul 21 07:21:43.212667 2026] [security2:error] [pid 230252:tid 230451] [client 146.190.63.248:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "polianoduarteramos1782482019000.polianoduarteramos1781890012818.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9IN00Dwhk5-Z44XrpA3wAAAtw"]
[Tue Jul 21 07:21:43.246992 2026] [security2:error] [pid 230252:tid 230500] [client 134.209.25.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "al9IN00Dwhk5-Z44XrpA4QAAAw0"]
[Tue Jul 21 07:21:43.253224 2026] [security2:error] [pid 229246:tid 229491] [client 143.110.213.72:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9INyBMYeh5YLVG45xlNwAAAoc"]
[Tue Jul 21 07:21:43.269336 2026] [security2:error] [pid 230252:tid 230411] [client 64.226.65.160:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al9IN00Dwhk5-Z44XrpA4wAAArQ"]
[Tue Jul 21 07:21:43.280397 2026] [security2:error] [pid 230252:tid 230458] [client 147.182.200.94:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9IN00Dwhk5-Z44XrpA5AAAAuM"]
[Tue Jul 21 07:21:43.302565 2026] [security2:error] [pid 230252:tid 230453] [client 20.206.105.145:30672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/adminfuns.php"] [unique_id "al9IN00Dwhk5-Z44XrpA5QAAAt4"]
[Tue Jul 21 07:21:43.330682 2026] [security2:error] [pid 230252:tid 230485] [client 20.104.96.117:59155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/kq1.php"] [unique_id "al9IN00Dwhk5-Z44XrpA6AAAAv4"]
[Tue Jul 21 07:21:43.340790 2026] [http2:warn] [pid 229246:tid 229376] [client 57.141.18.100:55082] h2_stream(229246-373-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:43.366073 2026] [security2:error] [pid 229246:tid 229382] [client 143.110.217.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "al9INyBMYeh5YLVG45xlOAAAAho"]
[Tue Jul 21 07:21:43.376274 2026] [security2:error] [pid 230252:tid 230270] [remote 110.249.201.7:62496] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "issimastore.com"] [uri "/imprensa/ficha_cadastral.pdf"] [unique_id "al9IN00Dwhk5-Z44XrpA7QACqxA"]
[Tue Jul 21 07:21:43.386990 2026] [security2:error] [pid 230252:tid 230420] [client 139.59.99.58:60461] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.vivaconcierge.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9IN00Dwhk5-Z44XrpA7gAAAr0"]
[Tue Jul 21 07:21:43.507894 2026] [security2:error] [pid 230252:tid 230432] [client 207.154.197.113:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9IN00Dwhk5-Z44XrpA7wAAAsk"]
[Tue Jul 21 07:21:43.594158 2026] [security2:error] [pid 229246:tid 229480] [client 138.68.144.227:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9INyBMYeh5YLVG45xlOwAAAnw"]
[Tue Jul 21 07:21:43.754920 2026] [security2:error] [pid 230252:tid 230410] [client 46.101.1.225:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al9IN00Dwhk5-Z44XrpA8gAAArM"]
[Tue Jul 21 07:21:43.839843 2026] [security2:error] [pid 230252:tid 230385] [client 47.128.31.153:17358] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cestabasicadocarlao.com.br"] [uri "/robots.txt"] [unique_id "al9IN00Dwhk5-Z44XrpA-QAAApo"]
[Tue Jul 21 07:21:43.927843 2026] [security2:error] [pid 230252:tid 230506] [client 139.59.132.8:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "al9IN00Dwhk5-Z44XrpA-gAAAxM"]
[Tue Jul 21 07:21:43.968840 2026] [security2:error] [pid 230252:tid 230277] [remote 138.197.191.87:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9IN00Dwhk5-Z44XrpA-wAC6Bc"]
[Tue Jul 21 07:21:44.237716 2026] [security2:error] [pid 229246:tid 229494] [client 20.206.105.145:30671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/goods.php"] [unique_id "al9IOCBMYeh5YLVG45xlSAAAAoo"]
[Tue Jul 21 07:21:44.238638 2026] [security2:error] [pid 230252:tid 230414] [client 20.226.60.151:54526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/sym403.php"] [unique_id "al9IOE0Dwhk5-Z44XrpBAAAAArc"]
[Tue Jul 21 07:21:44.334897 2026] [security2:error] [pid 229246:tid 229400] [client 20.104.96.117:62934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9IOCBMYeh5YLVG45xlTQAAAiw"]
[Tue Jul 21 07:21:44.358713 2026] [security2:error] [pid 229246:tid 229394] [client 139.59.136.184:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "al9IOCBMYeh5YLVG45xlTgAAAiY"]
[Tue Jul 21 07:21:44.360073 2026] [security2:error] [pid 229246:tid 229423] [client 20.226.60.151:60251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/xyn.php"] [unique_id "al9IOCBMYeh5YLVG45xlTwAAAkM"]
[Tue Jul 21 07:21:44.515005 2026] [http2:warn] [pid 229246:tid 229397] [client 57.141.18.39:62478] h2_stream(229246-381-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:44.523604 2026] [security2:error] [pid 230252:tid 230485] [client 142.93.143.8:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9IOE0Dwhk5-Z44XrpBAgAAAv4"]
[Tue Jul 21 07:21:44.643877 2026] [security2:error] [pid 230252:tid 230504] [client 68.183.180.73:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9IOE0Dwhk5-Z44XrpBAwAAAxE"]
[Tue Jul 21 07:21:44.663071 2026] [security2:error] [pid 230252:tid 230402] [client 20.104.96.117:59653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9IOE0Dwhk5-Z44XrpBBAAAAqs"]
[Tue Jul 21 07:21:44.791039 2026] [security2:error] [pid 229246:tid 229270] [remote 45.117.83.212:32862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9IOCBMYeh5YLVG45xlVAACiBc"]
[Tue Jul 21 07:21:44.791179 2026] [security2:error] [pid 229246:tid 229492] [client 45.117.83.212:32862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9IOCBMYeh5YLVG45xlVAACiBc"]
[Tue Jul 21 07:21:44.890594 2026] [security2:error] [pid 230252:tid 230464] [client 110.249.202.98:28772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "issimastore.com"] [uri "/robots.txt"] [unique_id "al9IOE0Dwhk5-Z44XrpBCwAAAuk"]
[Tue Jul 21 07:21:44.944245 2026] [security2:error] [pid 230252:tid 230399] [client 20.206.105.145:30608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/ms-edit.php"] [unique_id "al9IOE0Dwhk5-Z44XrpBDwAAAqg"]
[Tue Jul 21 07:21:45.030316 2026] [security2:error] [pid 229246:tid 229398] [client 103.162.129.114:63700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IOSBMYeh5YLVG45xlWgAAAio"]
[Tue Jul 21 07:21:45.030525 2026] [security2:error] [pid 229246:tid 229398] [client 103.162.129.114:63700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IOSBMYeh5YLVG45xlWgAAAio"]
[Tue Jul 21 07:21:45.140214 2026] [security2:error] [pid 230252:tid 230496] [client 103.121.156.110:63881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IOU0Dwhk5-Z44XrpBGAAAAwk"]
[Tue Jul 21 07:21:45.140379 2026] [security2:error] [pid 230252:tid 230496] [client 103.121.156.110:63881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IOU0Dwhk5-Z44XrpBGAAAAwk"]
[Tue Jul 21 07:21:45.146221 2026] [http2:warn] [pid 229246:tid 229419] [client 57.141.18.57:38628] h2_stream(229246-386-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:45.249872 2026] [proxy:error] [pid 230252:tid 230472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:45.249919 2026] [proxy_http:error] [pid 230252:tid 230472] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:45.250449 2026] [proxy:error] [pid 230252:tid 230472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:45.250469 2026] [proxy_http:error] [pid 230252:tid 230472] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:45.267859 2026] [proxy:error] [pid 230252:tid 230506] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:45.267894 2026] [proxy_http:error] [pid 230252:tid 230506] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:45.268310 2026] [proxy:error] [pid 230252:tid 230506] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:45.268329 2026] [proxy_http:error] [pid 230252:tid 230506] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:45.337946 2026] [security2:error] [pid 230252:tid 230419] [client 193.36.225.73:26839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IOU0Dwhk5-Z44XrpBGQAAArw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:45.458753 2026] [security2:error] [pid 229246:tid 229452] [client 20.206.105.145:30625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/222.php"] [unique_id "al9IOSBMYeh5YLVG45xlZQAAAmA"]
[Tue Jul 21 07:21:45.583243 2026] [proxy:error] [pid 230252:tid 230485] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:45.583312 2026] [proxy_http:error] [pid 230252:tid 230485] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:45.583949 2026] [proxy:error] [pid 230252:tid 230485] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:45.583982 2026] [proxy_http:error] [pid 230252:tid 230485] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:45.683349 2026] [security2:error] [pid 230252:tid 230511] [client 20.206.105.145:30596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/cgi-bin/index.php"] [unique_id "al9IOU0Dwhk5-Z44XrpBJAAAAxg"]
[Tue Jul 21 07:21:45.753509 2026] [security2:error] [pid 229246:tid 229275] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IOSBMYeh5YLVG45xlZwACGRw"]
[Tue Jul 21 07:21:45.753682 2026] [security2:error] [pid 229246:tid 229381] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IOSBMYeh5YLVG45xlZwACGRw"]
[Tue Jul 21 07:21:45.923594 2026] [security2:error] [pid 229246:tid 229451] [client 68.235.38.2:41102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9IOSBMYeh5YLVG45xlawAAAl8"]
[Tue Jul 21 07:21:45.923693 2026] [security2:error] [pid 229246:tid 229451] [client 68.235.38.2:41102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9IOSBMYeh5YLVG45xlawAAAl8"]
[Tue Jul 21 07:21:45.948569 2026] [proxy:error] [pid 229246:tid 229494] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:45.948640 2026] [proxy_http:error] [pid 229246:tid 229494] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:45.949731 2026] [proxy:error] [pid 229246:tid 229494] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:45.949783 2026] [proxy_http:error] [pid 229246:tid 229494] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:45.970506 2026] [security2:error] [pid 230252:tid 230311] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IOU0Dwhk5-Z44XrpBLAACojk"]
[Tue Jul 21 07:21:45.970635 2026] [security2:error] [pid 230252:tid 230393] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IOU0Dwhk5-Z44XrpBLAACojk"]
[Tue Jul 21 07:21:46.084578 2026] [security2:error] [pid 230252:tid 230463] [client 20.206.105.145:30620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/BDKR28WP.php"] [unique_id "al9IOk0Dwhk5-Z44XrpBLQAAAug"]
[Tue Jul 21 07:21:46.092453 2026] [http2:warn] [pid 229246:tid 229467] [client 57.141.18.20:40562] h2_stream(229246-390-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:46.133487 2026] [security2:error] [pid 229246:tid 229399] [client 74.249.245.134:61528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/a7.php"] [unique_id "al9IOiBMYeh5YLVG45xlbgAAAis"]
[Tue Jul 21 07:21:46.146541 2026] [autoindex:error] [pid 230252:tid 230495] [client 148.113.192.228:42884] AH01276: Cannot serve directory /home3/edua2728/anshin.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:21:46.207908 2026] [security2:error] [pid 229246:tid 229394] [client 20.104.96.117:62918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/media.php"] [unique_id "al9IOiBMYeh5YLVG45xlcAAAAiY"]
[Tue Jul 21 07:21:46.667686 2026] [security2:error] [pid 229246:tid 229432] [client 20.226.60.151:60164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/patie.php"] [unique_id "al9IOiBMYeh5YLVG45xldgAAAkw"]
[Tue Jul 21 07:21:46.676536 2026] [security2:error] [pid 230252:tid 230451] [client 20.206.105.145:30624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/raw.php"] [unique_id "al9IOk0Dwhk5-Z44XrpBOgAAAtw"]
[Tue Jul 21 07:21:46.885066 2026] [security2:error] [pid 229246:tid 229403] [client 45.251.232.145:49948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IOiBMYeh5YLVG45xleAAAAi8"]
[Tue Jul 21 07:21:46.885215 2026] [security2:error] [pid 229246:tid 229403] [client 45.251.232.145:49948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IOiBMYeh5YLVG45xleAAAAi8"]
[Tue Jul 21 07:21:46.901195 2026] [security2:error] [pid 229246:tid 229493] [client 20.206.105.145:30716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/abcd.php"] [unique_id "al9IOiBMYeh5YLVG45xleQAAAok"]
[Tue Jul 21 07:21:47.108405 2026] [security2:error] [pid 230252:tid 230506] [client 20.206.105.145:30714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/a1.php"] [unique_id "al9IO00Dwhk5-Z44XrpBRwAAAxM"]
[Tue Jul 21 07:21:47.247682 2026] [proxy:error] [pid 230252:tid 230495] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:47.247749 2026] [proxy_http:error] [pid 230252:tid 230495] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:47.248291 2026] [proxy:error] [pid 230252:tid 230495] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:47.248318 2026] [proxy_http:error] [pid 230252:tid 230495] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:47.267917 2026] [proxy:error] [pid 230252:tid 230454] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:47.267980 2026] [proxy_http:error] [pid 230252:tid 230454] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:47.268659 2026] [proxy:error] [pid 230252:tid 230454] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:47.268694 2026] [proxy_http:error] [pid 230252:tid 230454] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:47.394885 2026] [security2:error] [pid 229246:tid 229262] [remote 64.23.157.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9IOyBMYeh5YLVG45xlhwACgg8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:21:47.399498 2026] [http2:warn] [pid 229246:tid 229415] [client 57.141.18.24:32594] h2_stream(229246-392-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:47.437834 2026] [security2:error] [pid 229246:tid 229454] [client 20.206.105.145:30662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9IOyBMYeh5YLVG45xljQAAAmI"]
[Tue Jul 21 07:21:47.443672 2026] [security2:error] [pid 230252:tid 230290] [remote 64.23.157.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9IO00Dwhk5-Z44XrpBTQACoiQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:21:47.517366 2026] [security2:error] [pid 230252:tid 230419] [client 14.139.42.196:10874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IO00Dwhk5-Z44XrpBVAAAArw"]
[Tue Jul 21 07:21:47.517455 2026] [security2:error] [pid 230252:tid 230419] [client 14.139.42.196:10874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IO00Dwhk5-Z44XrpBVAAAArw"]
[Tue Jul 21 07:21:47.708025 2026] [security2:error] [pid 229246:tid 229495] [client 20.104.96.117:64002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/images.php"] [unique_id "al9IOyBMYeh5YLVG45xlkAAAAos"]
[Tue Jul 21 07:21:47.739771 2026] [security2:error] [pid 230252:tid 230421] [client 20.206.105.145:30666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/cgi-bin/admin.php"] [unique_id "al9IO00Dwhk5-Z44XrpBWwAAAr4"]
[Tue Jul 21 07:21:47.765484 2026] [proxy:error] [pid 230252:tid 230456] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:47.765542 2026] [proxy_http:error] [pid 230252:tid 230456] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:47.765976 2026] [proxy:error] [pid 230252:tid 230456] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:47.765998 2026] [proxy_http:error] [pid 230252:tid 230456] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:47.935658 2026] [security2:error] [pid 230252:tid 230409] [client 20.104.96.117:59681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/h02ugyh.php"] [unique_id "al9IO00Dwhk5-Z44XrpBZQAAArI"]
[Tue Jul 21 07:21:48.014905 2026] [security2:error] [pid 230252:tid 230368] [remote 64.23.157.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9IPE0Dwhk5-Z44XrpBaQACz3E"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:21:48.032211 2026] [security2:error] [pid 230252:tid 230299] [remote 64.23.157.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9IPE0Dwhk5-Z44XrpBagACyS0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:21:48.052695 2026] [proxy:error] [pid 229246:tid 229425] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.052768 2026] [proxy_http:error] [pid 229246:tid 229425] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.053521 2026] [proxy:error] [pid 229246:tid 229425] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.053558 2026] [proxy_http:error] [pid 229246:tid 229425] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.058151 2026] [access_compat:error] [pid 230252:tid 230454] [client 162.241.63.68:23230] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:21:48.078908 2026] [security2:error] [pid 230252:tid 230393] [client 20.206.105.145:30658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-content/BypassBest.php"] [unique_id "al9IPE0Dwhk5-Z44XrpBbAAAAqI"]
[Tue Jul 21 07:21:48.195665 2026] [http2:warn] [pid 230252:tid 230418] [client 57.141.18.33:27588] h2_stream(230252-221-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:48.238904 2026] [security2:error] [pid 229246:tid 229367] [remote 64.23.157.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9IPCBMYeh5YLVG45xlmwACfng"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:21:48.258549 2026] [proxy:error] [pid 230252:tid 230456] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.258614 2026] [proxy_http:error] [pid 230252:tid 230456] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.259186 2026] [proxy:error] [pid 230252:tid 230456] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.259210 2026] [proxy_http:error] [pid 230252:tid 230456] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.276284 2026] [proxy:error] [pid 229246:tid 229398] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.276344 2026] [proxy_http:error] [pid 229246:tid 229398] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.277080 2026] [proxy:error] [pid 229246:tid 229398] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.277114 2026] [proxy_http:error] [pid 229246:tid 229398] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.278466 2026] [security2:error] [pid 230252:tid 230395] [client 74.249.245.134:44067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/classsmtps.php"] [unique_id "al9IPE0Dwhk5-Z44XrpBeQAAAqQ"]
[Tue Jul 21 07:21:48.296575 2026] [security2:error] [pid 230252:tid 230265] [remote 64.23.157.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9IPE0Dwhk5-Z44XrpBfQAC6As"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:21:48.373425 2026] [security2:error] [pid 229246:tid 229315] [remote 64.23.157.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9IOyBMYeh5YLVG45xlhgACkUQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:21:48.473166 2026] [security2:error] [pid 230252:tid 230268] [remote 64.23.157.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9IPE0Dwhk5-Z44XrpBiAACuQ4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:21:48.489059 2026] [security2:error] [pid 230252:tid 230294] [remote 64.23.157.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9IO00Dwhk5-Z44XrpBUQAC6Cg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:21:48.528424 2026] [security2:error] [pid 230252:tid 230287] [remote 64.23.157.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9IPE0Dwhk5-Z44XrpBiwACtyE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:21:48.582355 2026] [security2:error] [pid 230252:tid 230263] [remote 64.23.157.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9IPE0Dwhk5-Z44XrpBjQAC4wk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:21:48.633631 2026] [core:crit] [pid 230252:tid 230419] (13)Permission denied: [client 45.156.129.171:44938] AH00529: /home4/moadvo53/public_html/cgi-bin/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home4/moadvo53/public_html/cgi-bin/' is executable
[Tue Jul 21 07:21:48.652881 2026] [proxy:error] [pid 230252:tid 230447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.652955 2026] [proxy_http:error] [pid 230252:tid 230447] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.653746 2026] [proxy:error] [pid 230252:tid 230447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.653790 2026] [proxy_http:error] [pid 230252:tid 230447] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.759423 2026] [security2:error] [pid 230252:tid 230366] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IPE0Dwhk5-Z44XrpBmAACyW8"]
[Tue Jul 21 07:21:48.759575 2026] [security2:error] [pid 230252:tid 230432] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IPE0Dwhk5-Z44XrpBmAACyW8"]
[Tue Jul 21 07:21:48.760604 2026] [proxy:error] [pid 230252:tid 230439] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.760680 2026] [proxy_http:error] [pid 230252:tid 230439] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.761652 2026] [proxy:error] [pid 230252:tid 230439] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.761694 2026] [proxy_http:error] [pid 230252:tid 230439] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.771466 2026] [security2:error] [pid 229246:tid 229480] [client 20.104.96.117:64055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/gecko.php"] [unique_id "al9IPCBMYeh5YLVG45xlsAAAAnw"]
[Tue Jul 21 07:21:48.834735 2026] [proxy:error] [pid 230252:tid 230492] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.834797 2026] [proxy_http:error] [pid 230252:tid 230492] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.835254 2026] [proxy:error] [pid 230252:tid 230492] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.835278 2026] [proxy_http:error] [pid 230252:tid 230492] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.925681 2026] [proxy:error] [pid 230252:tid 230451] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.925751 2026] [proxy_http:error] [pid 230252:tid 230451] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.926481 2026] [proxy:error] [pid 230252:tid 230451] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.926512 2026] [proxy_http:error] [pid 230252:tid 230451] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.928749 2026] [security2:error] [pid 229246:tid 229380] [client 20.206.105.145:30704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/simple.php"] [unique_id "al9IPCBMYeh5YLVG45xltAAAAhg"]
[Tue Jul 21 07:21:49.035973 2026] [proxy:error] [pid 230252:tid 230479] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.036037 2026] [proxy_http:error] [pid 230252:tid 230479] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.036481 2026] [proxy:error] [pid 230252:tid 230479] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.036503 2026] [proxy_http:error] [pid 230252:tid 230479] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.144421 2026] [proxy:error] [pid 230252:tid 230404] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.144487 2026] [proxy_http:error] [pid 230252:tid 230404] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.144970 2026] [proxy:error] [pid 230252:tid 230404] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.144999 2026] [proxy_http:error] [pid 230252:tid 230404] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.242566 2026] [http2:warn] [pid 229246:tid 229502] [client 57.141.18.89:26280] h2_stream(229246-394-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:49.281599 2026] [proxy:error] [pid 229246:tid 229414] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.281704 2026] [proxy_http:error] [pid 229246:tid 229414] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.283206 2026] [proxy:error] [pid 229246:tid 229414] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.283288 2026] [proxy_http:error] [pid 229246:tid 229414] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.299972 2026] [proxy:error] [pid 229246:tid 229404] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.300045 2026] [proxy_http:error] [pid 229246:tid 229404] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.300678 2026] [proxy:error] [pid 229246:tid 229404] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.300713 2026] [proxy_http:error] [pid 229246:tid 229404] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.424150 2026] [proxy:error] [pid 230252:tid 230484] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.424215 2026] [proxy_http:error] [pid 230252:tid 230484] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.424861 2026] [proxy:error] [pid 230252:tid 230484] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.424888 2026] [proxy_http:error] [pid 230252:tid 230484] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.533006 2026] [proxy:error] [pid 229246:tid 229423] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.533071 2026] [proxy_http:error] [pid 229246:tid 229423] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.533622 2026] [proxy:error] [pid 229246:tid 229423] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.533647 2026] [proxy_http:error] [pid 229246:tid 229423] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.656837 2026] [security2:error] [pid 230252:tid 230412] [client 136.144.33.99:24769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IPU0Dwhk5-Z44XrpByQAAArU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:49.657657 2026] [security2:error] [pid 230252:tid 230440] [client 20.206.105.145:30667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/xxx.php"] [unique_id "al9IPU0Dwhk5-Z44XrpBygAAAtE"]
[Tue Jul 21 07:21:49.684186 2026] [proxy:error] [pid 230252:tid 230478] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.684271 2026] [proxy_http:error] [pid 230252:tid 230478] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.684974 2026] [proxy:error] [pid 230252:tid 230478] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.685017 2026] [proxy_http:error] [pid 230252:tid 230478] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.739047 2026] [proxy:error] [pid 230252:tid 230392] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.739106 2026] [proxy_http:error] [pid 230252:tid 230392] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.739561 2026] [proxy:error] [pid 230252:tid 230392] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.739593 2026] [proxy_http:error] [pid 230252:tid 230392] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.761981 2026] [security2:error] [pid 230252:tid 230453] [client 20.104.96.117:59705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-temp.php"] [unique_id "al9IPU0Dwhk5-Z44XrpB0AAAAt4"]
[Tue Jul 21 07:21:49.810058 2026] [proxy:error] [pid 229246:tid 229499] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.810127 2026] [proxy_http:error] [pid 229246:tid 229499] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.810271 2026] [security2:error] [pid 230252:tid 230482] [client 20.104.96.117:64010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/82.php"] [unique_id "al9IPU0Dwhk5-Z44XrpB0QAAAvs"]
[Tue Jul 21 07:21:49.810803 2026] [proxy:error] [pid 229246:tid 229499] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.810832 2026] [proxy_http:error] [pid 229246:tid 229499] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.920078 2026] [proxy:error] [pid 230252:tid 230438] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.920162 2026] [proxy_http:error] [pid 230252:tid 230438] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.920857 2026] [proxy:error] [pid 230252:tid 230438] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.920896 2026] [proxy_http:error] [pid 230252:tid 230438] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.948696 2026] [security2:error] [pid 230252:tid 230465] [client 20.206.105.145:30668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/hypo.php"] [unique_id "al9IPU0Dwhk5-Z44XrpB2AAAAuo"]
[Tue Jul 21 07:21:50.083892 2026] [http2:warn] [pid 229246:tid 229437] [client 57.141.18.81:35606] h2_stream(229246-395-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:50.134253 2026] [proxy:error] [pid 229246:tid 229433] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.134327 2026] [proxy_http:error] [pid 229246:tid 229433] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.134838 2026] [proxy:error] [pid 229246:tid 229433] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.134867 2026] [proxy_http:error] [pid 229246:tid 229433] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.160822 2026] [security2:error] [pid 230252:tid 230509] [client 74.249.245.134:48490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/rip.php"] [unique_id "al9IPk0Dwhk5-Z44XrpB3gAAAxY"]
[Tue Jul 21 07:21:50.210001 2026] [proxy:error] [pid 230252:tid 230421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.210072 2026] [proxy_http:error] [pid 230252:tid 230421] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.210868 2026] [proxy:error] [pid 230252:tid 230421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.210900 2026] [proxy_http:error] [pid 230252:tid 230421] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.233877 2026] [proxy:error] [pid 230252:tid 230419] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.233936 2026] [proxy_http:error] [pid 230252:tid 230419] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.234528 2026] [proxy:error] [pid 230252:tid 230419] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.234555 2026] [proxy_http:error] [pid 230252:tid 230419] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.308170 2026] [proxy:error] [pid 229246:tid 229390] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.308232 2026] [proxy_http:error] [pid 229246:tid 229390] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.308683 2026] [proxy:error] [pid 229246:tid 229390] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.308717 2026] [proxy_http:error] [pid 229246:tid 229390] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.383084 2026] [security2:error] [pid 229246:tid 229428] [client 20.220.225.223:34185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/ez.php"] [unique_id "al9IPiBMYeh5YLVG45xl4AAAAkg"]
[Tue Jul 21 07:21:50.396145 2026] [security2:error] [pid 230252:tid 230478] [client 20.226.60.151:60168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/aa.php"] [unique_id "al9IPk0Dwhk5-Z44XrpB6AAAAvc"]
[Tue Jul 21 07:21:50.472277 2026] [security2:error] [pid 229246:tid 229472] [client 103.174.34.15:64777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IPiBMYeh5YLVG45xl4QAAAnQ"]
[Tue Jul 21 07:21:50.472392 2026] [security2:error] [pid 229246:tid 229472] [client 103.174.34.15:64777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IPiBMYeh5YLVG45xl4QAAAnQ"]
[Tue Jul 21 07:21:50.481998 2026] [security2:error] [pid 229246:tid 229349] [remote 132.148.72.88:58730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "powertronicseguranca.com"] [uri "/wp-login.php"] [unique_id "al9IPiBMYeh5YLVG45xl4gACTmY"]
[Tue Jul 21 07:21:50.521504 2026] [proxy:error] [pid 230252:tid 230475] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.521570 2026] [proxy_http:error] [pid 230252:tid 230475] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.522277 2026] [proxy:error] [pid 230252:tid 230475] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.522310 2026] [proxy_http:error] [pid 230252:tid 230475] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.689882 2026] [security2:error] [pid 230252:tid 230298] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IPk0Dwhk5-Z44XrpB9AACySw"]
[Tue Jul 21 07:21:50.690037 2026] [security2:error] [pid 230252:tid 230432] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IPk0Dwhk5-Z44XrpB9AACySw"]
[Tue Jul 21 07:21:50.698010 2026] [proxy:error] [pid 230252:tid 230438] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.698077 2026] [proxy_http:error] [pid 230252:tid 230438] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.698754 2026] [proxy:error] [pid 230252:tid 230438] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.698782 2026] [proxy_http:error] [pid 230252:tid 230438] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.702462 2026] [proxy:error] [pid 230252:tid 230405] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.702523 2026] [proxy_http:error] [pid 230252:tid 230405] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.703013 2026] [proxy:error] [pid 230252:tid 230405] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.703037 2026] [proxy_http:error] [pid 230252:tid 230405] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.898958 2026] [security2:error] [pid 230252:tid 230331] [remote 192.241.143.148:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.hauptmann.com.br"] [uri "/wp-login.php"] [unique_id "al9IPk0Dwhk5-Z44XrpB_AACokw"]
[Tue Jul 21 07:21:50.912654 2026] [proxy:error] [pid 230252:tid 230447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.912720 2026] [proxy_http:error] [pid 230252:tid 230447] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.913485 2026] [proxy:error] [pid 230252:tid 230447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.913516 2026] [proxy_http:error] [pid 230252:tid 230447] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.919683 2026] [security2:error] [pid 230252:tid 230402] [client 114.119.136.141:51295] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "projetoflechas.org.br"] [uri "/videos/flechas-para-as-nacoes-2011"] [unique_id "al9IPk0Dwhk5-Z44XrpB_gAAAqs"], referer: http://projetoflechas.org.br/videos/flechas-para-as-nacoes-2011?shared=email&msg=fail
[Tue Jul 21 07:21:51.199732 2026] [proxy:error] [pid 229246:tid 229383] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:51.199791 2026] [proxy_http:error] [pid 229246:tid 229383] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:51.200362 2026] [proxy:error] [pid 229246:tid 229383] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:51.200391 2026] [proxy_http:error] [pid 229246:tid 229383] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:51.297230 2026] [http2:warn] [pid 230252:tid 230449] [client 57.141.18.50:45830] h2_stream(230252-230-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:51.387587 2026] [security2:error] [pid 230252:tid 230283] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IP00Dwhk5-Z44XrpCCQACtB0"]
[Tue Jul 21 07:21:51.387741 2026] [security2:error] [pid 230252:tid 230411] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IP00Dwhk5-Z44XrpCCQACtB0"]
[Tue Jul 21 07:21:51.404472 2026] [security2:error] [pid 230252:tid 230492] [client 20.220.225.223:59471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/bootstrap.php"] [unique_id "al9IP00Dwhk5-Z44XrpCCwAAAwU"]
[Tue Jul 21 07:21:51.410510 2026] [security2:error] [pid 230252:tid 230297] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IP00Dwhk5-Z44XrpCDAAC4Cs"]
[Tue Jul 21 07:21:51.410745 2026] [security2:error] [pid 230252:tid 230455] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IP00Dwhk5-Z44XrpCDAAC4Cs"]
[Tue Jul 21 07:21:51.475844 2026] [security2:error] [pid 229246:tid 229416] [client 20.206.105.145:30529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/chosen.php"] [unique_id "al9IPyBMYeh5YLVG45xl7QAAAjw"]
[Tue Jul 21 07:21:51.507907 2026] [security2:error] [pid 229246:tid 229486] [client 20.104.96.117:59197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9IPyBMYeh5YLVG45xl7gAAAoI"]
[Tue Jul 21 07:21:51.515807 2026] [security2:error] [pid 229246:tid 229454] [client 20.104.96.117:64001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/admin.php"] [unique_id "al9IPyBMYeh5YLVG45xl7wAAAmI"]
[Tue Jul 21 07:21:51.584723 2026] [security2:error] [pid 230252:tid 230460] [client 20.226.60.151:54570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/v543.php"] [unique_id "al9IP00Dwhk5-Z44XrpCEAAAAuU"]
[Tue Jul 21 07:21:51.655228 2026] [proxy:error] [pid 230252:tid 230389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:51.655301 2026] [proxy_http:error] [pid 230252:tid 230389] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:51.655822 2026] [proxy:error] [pid 230252:tid 230389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:51.655847 2026] [proxy_http:error] [pid 230252:tid 230389] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:51.689282 2026] [proxy:error] [pid 230252:tid 230493] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:51.689344 2026] [proxy_http:error] [pid 230252:tid 230493] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:51.690067 2026] [proxy:error] [pid 230252:tid 230493] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:51.690095 2026] [proxy_http:error] [pid 230252:tid 230493] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:51.716459 2026] [security2:error] [pid 230252:tid 230415] [client 74.249.245.134:62472] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "drjoaoguedes.com"] [uri "/1.php"] [unique_id "al9IP00Dwhk5-Z44XrpCFQAAArg"]
[Tue Jul 21 07:21:51.716560 2026] [security2:error] [pid 230252:tid 230415] [client 74.249.245.134:62472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/1.php"] [unique_id "al9IP00Dwhk5-Z44XrpCFQAAArg"]
[Tue Jul 21 07:21:51.899188 2026] [security2:error] [pid 230252:tid 230391] [client 165.22.235.3:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.235.22.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IP00Dwhk5-Z44XrpCHQAAAqA"]
[Tue Jul 21 07:21:51.902632 2026] [proxy:error] [pid 230252:tid 230484] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:51.902707 2026] [proxy_http:error] [pid 230252:tid 230484] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:51.903783 2026] [proxy:error] [pid 230252:tid 230484] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:51.903835 2026] [proxy_http:error] [pid 230252:tid 230484] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:51.917569 2026] [http2:warn] [pid 230252:tid 230467] [client 57.141.18.85:56220] h2_stream(230252-232-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:52.036876 2026] [security2:error] [pid 230252:tid 230393] [client 167.71.175.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.175.71.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IP00Dwhk5-Z44XrpCHAAAAqI"]
[Tue Jul 21 07:21:52.297949 2026] [security2:error] [pid 230252:tid 230504] [client 20.220.225.223:47839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/wp-editor.php"] [unique_id "al9IQE0Dwhk5-Z44XrpCLAAAAxE"]
[Tue Jul 21 07:21:52.358439 2026] [security2:error] [pid 229246:tid 229465] [client 206.189.233.36:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.233.189.206.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "polianoduarteramos1782482019000.polianoduarteramos1781890012818.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQCBMYeh5YLVG45xl9gAAAm0"]
[Tue Jul 21 07:21:52.381625 2026] [security2:error] [pid 230252:tid 230420] [client 64.23.218.208:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.218.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQE0Dwhk5-Z44XrpCLgAAAr0"]
[Tue Jul 21 07:21:52.521193 2026] [security2:error] [pid 229246:tid 229495] [client 64.23.218.208:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.218.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQCBMYeh5YLVG45xl9wAAAos"]
[Tue Jul 21 07:21:52.767424 2026] [security2:error] [pid 230252:tid 230405] [client 206.189.19.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.19.189.206.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQE0Dwhk5-Z44XrpCMwAAAq4"]
[Tue Jul 21 07:21:52.817408 2026] [http2:warn] [pid 230252:tid 230508] [client 57.141.18.119:39444] h2_stream(230252-235-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:52.984161 2026] [security2:error] [pid 230252:tid 230500] [client 74.7.241.190:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "printcom.com.br"] [uri "/index.php"] [unique_id "al9IQE0Dwhk5-Z44XrpCNgADDWM"]
[Tue Jul 21 07:21:53.104821 2026] [security2:error] [pid 230252:tid 230389] [client 139.135.44.145:54702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCPgAAAp4"]
[Tue Jul 21 07:21:53.104952 2026] [security2:error] [pid 230252:tid 230389] [client 139.135.44.145:54702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCPgAAAp4"]
[Tue Jul 21 07:21:53.203054 2026] [security2:error] [pid 230252:tid 230402] [client 74.249.245.134:50005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/chosen.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCQAAAAqs"]
[Tue Jul 21 07:21:53.204704 2026] [security2:error] [pid 230252:tid 230421] [client 20.197.192.193:42214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCQQAAAr4"]
[Tue Jul 21 07:21:53.205801 2026] [proxy:error] [pid 230252:tid 230463] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:53.205871 2026] [proxy_http:error] [pid 230252:tid 230463] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:53.206880 2026] [proxy:error] [pid 230252:tid 230463] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:53.206920 2026] [proxy_http:error] [pid 230252:tid 230463] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:53.240164 2026] [security2:error] [pid 230252:tid 230404] [client 175.45.70.82:54333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCRAAAAq0"]
[Tue Jul 21 07:21:53.240302 2026] [security2:error] [pid 230252:tid 230404] [client 175.45.70.82:54333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCRAAAAq0"]
[Tue Jul 21 07:21:53.257007 2026] [security2:error] [pid 229246:tid 229481] [client 146.190.63.248:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.63.190.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "polianoduarteramos1782482019000.polianoduarteramos1781890012818.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQSBMYeh5YLVG45xmAQAAAn0"]
[Tue Jul 21 07:21:53.286869 2026] [security2:error] [pid 230252:tid 230412] [client 167.71.175.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.175.71.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.polianoduarteramos1782482019000.polianoduarteramos1781890012818.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCRgAAArU"]
[Tue Jul 21 07:21:53.296973 2026] [security2:error] [pid 230252:tid 230443] [client 165.227.84.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.84.227.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.polianoduarteramos1782482019000.polianoduarteramos1781890012818.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCRwAAAtQ"]
[Tue Jul 21 07:21:53.348179 2026] [security2:error] [pid 230252:tid 230504] [client 20.197.192.193:41568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCSQAAAxE"]
[Tue Jul 21 07:21:53.371117 2026] [security2:error] [pid 230252:tid 230475] [client 20.197.192.193:42217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/dp.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCSwAAAvQ"]
[Tue Jul 21 07:21:53.385717 2026] [security2:error] [pid 229246:tid 229485] [client 20.197.192.193:42223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/old.php"] [unique_id "al9IQSBMYeh5YLVG45xmCAAAAoE"]
[Tue Jul 21 07:21:53.402323 2026] [security2:error] [pid 230252:tid 230411] [client 20.197.192.193:41596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/ms-new.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCTAAAArQ"]
[Tue Jul 21 07:21:53.416390 2026] [security2:error] [pid 229246:tid 229382] [client 20.197.192.193:42183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/track.php"] [unique_id "al9IQSBMYeh5YLVG45xmCgAAAho"]
[Tue Jul 21 07:21:53.431651 2026] [security2:error] [pid 229246:tid 229406] [client 20.197.192.193:42206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/2352356666.php"] [unique_id "al9IQSBMYeh5YLVG45xmDAAAAjI"]
[Tue Jul 21 07:21:53.449092 2026] [security2:error] [pid 229246:tid 229388] [client 20.197.192.193:42185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/pn.php"] [unique_id "al9IQSBMYeh5YLVG45xmDgAAAiA"]
[Tue Jul 21 07:21:53.463764 2026] [security2:error] [pid 230252:tid 230312] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCTgAC4Do"]
[Tue Jul 21 07:21:53.463920 2026] [security2:error] [pid 230252:tid 230455] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCTgAC4Do"]
[Tue Jul 21 07:21:53.466438 2026] [security2:error] [pid 229246:tid 229472] [client 20.197.192.193:42189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9IQSBMYeh5YLVG45xmDwAAAnQ"]
[Tue Jul 21 07:21:53.482733 2026] [security2:error] [pid 229246:tid 229452] [client 20.197.192.193:41545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/dr.php"] [unique_id "al9IQSBMYeh5YLVG45xmEAAAAmA"]
[Tue Jul 21 07:21:53.498673 2026] [security2:error] [pid 229246:tid 229477] [client 20.197.192.193:41591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/2x.php"] [unique_id "al9IQSBMYeh5YLVG45xmEQAAAnk"]
[Tue Jul 21 07:21:53.539415 2026] [security2:error] [pid 229246:tid 229421] [client 147.182.200.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.200.182.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQSBMYeh5YLVG45xmEgAAAkE"]
[Tue Jul 21 07:21:53.541872 2026] [security2:error] [pid 229246:tid 229380] [client 20.197.192.193:42193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/kq1.php"] [unique_id "al9IQSBMYeh5YLVG45xmEwAAAhg"]
[Tue Jul 21 07:21:53.554318 2026] [security2:error] [pid 229246:tid 229447] [client 157.230.19.140:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.19.230.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQSBMYeh5YLVG45xmFAAAAls"]
[Tue Jul 21 07:21:53.569460 2026] [security2:error] [pid 230252:tid 230459] [client 20.197.192.193:41593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/zzz.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCUgAAAuQ"]
[Tue Jul 21 07:21:53.578632 2026] [security2:error] [pid 230252:tid 230464] [client 20.220.225.223:34303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/fz.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCUwAAAuk"]
[Tue Jul 21 07:21:53.582335 2026] [security2:error] [pid 229246:tid 229407] [client 143.110.217.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.217.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQCBMYeh5YLVG45xl-QAAAjM"]
[Tue Jul 21 07:21:53.583782 2026] [security2:error] [pid 229246:tid 229381] [client 20.104.96.117:61122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9IQSBMYeh5YLVG45xmFQAAAhk"]
[Tue Jul 21 07:21:53.592701 2026] [security2:error] [pid 230252:tid 230414] [client 20.197.192.193:42227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/wicked.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCVAAAArc"]
[Tue Jul 21 07:21:53.613652 2026] [security2:error] [pid 230252:tid 230453] [client 207.154.197.113:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.197.154.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCTQAAAt4"]
[Tue Jul 21 07:21:53.621075 2026] [security2:error] [pid 229246:tid 229448] [client 20.197.192.193:42197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/edit.php"] [unique_id "al9IQSBMYeh5YLVG45xmFwAAAlw"]
[Tue Jul 21 07:21:53.641409 2026] [proxy:error] [pid 229246:tid 229402] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:53.641473 2026] [proxy_http:error] [pid 229246:tid 229402] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:53.642063 2026] [proxy:error] [pid 229246:tid 229402] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:53.642088 2026] [proxy_http:error] [pid 229246:tid 229402] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:53.657449 2026] [security2:error] [pid 230252:tid 230421] [client 20.197.192.193:42191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/kua.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCVQAAAr4"]
[Tue Jul 21 07:21:53.695892 2026] [proxy:error] [pid 229246:tid 229397] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:53.695962 2026] [proxy_http:error] [pid 229246:tid 229397] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:53.696621 2026] [proxy:error] [pid 229246:tid 229397] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:53.696650 2026] [proxy_http:error] [pid 229246:tid 229397] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:53.698270 2026] [security2:error] [pid 230252:tid 230506] [client 20.197.192.193:42210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/ez.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCVwAAAxM"]
[Tue Jul 21 07:21:53.726728 2026] [security2:error] [pid 229246:tid 229457] [client 143.110.213.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.213.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQCBMYeh5YLVG45xl_QAAAmU"]
[Tue Jul 21 07:21:53.727973 2026] [security2:error] [pid 229246:tid 229478] [client 20.197.192.193:41558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/fz.php"] [unique_id "al9IQSBMYeh5YLVG45xmGwAAAno"]
[Tue Jul 21 07:21:53.734192 2026] [security2:error] [pid 230252:tid 230410] [client 193.36.225.56:63057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCUQAAArM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:53.747644 2026] [security2:error] [pid 230252:tid 230492] [client 20.197.192.193:48936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/la.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCWwAAAwU"]
[Tue Jul 21 07:21:53.762007 2026] [security2:error] [pid 229246:tid 229430] [client 134.209.25.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.25.209.134.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQSBMYeh5YLVG45xmFgAAAko"]
[Tue Jul 21 07:21:53.779722 2026] [security2:error] [pid 230252:tid 230482] [client 20.197.192.193:41582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCXgAAAvs"]
[Tue Jul 21 07:21:53.786644 2026] [security2:error] [pid 229246:tid 229404] [client 20.197.192.193:27133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/ms.php"] [unique_id "al9IQSBMYeh5YLVG45xmIgAAAjA"]
[Tue Jul 21 07:21:53.808597 2026] [security2:error] [pid 229246:tid 229465] [client 20.197.192.193:42224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/inso.php"] [unique_id "al9IQSBMYeh5YLVG45xmIwAAAm0"]
[Tue Jul 21 07:21:53.821619 2026] [security2:error] [pid 229246:tid 229376] [client 20.104.96.117:64014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/adminner.php"] [unique_id "al9IQSBMYeh5YLVG45xmJQAAAhQ"]
[Tue Jul 21 07:21:53.834946 2026] [security2:error] [pid 229246:tid 229495] [client 20.197.192.193:41559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/wpx.php"] [unique_id "al9IQSBMYeh5YLVG45xmJgAAAos"]
[Tue Jul 21 07:21:53.864176 2026] [security2:error] [pid 229246:tid 229441] [client 20.197.192.193:41579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/berlin.php"] [unique_id "al9IQSBMYeh5YLVG45xmJwAAAlU"]
[Tue Jul 21 07:21:53.883205 2026] [http2:warn] [pid 229246:tid 229500] [client 57.141.18.60:39706] h2_stream(229246-404-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:53.885797 2026] [security2:error] [pid 230252:tid 230465] [client 20.197.192.193:48930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/billur.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCZgAAAuo"]
[Tue Jul 21 07:21:53.891870 2026] [proxy:error] [pid 229246:tid 229396] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:53.891946 2026] [proxy_http:error] [pid 229246:tid 229396] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:53.893320 2026] [proxy:error] [pid 229246:tid 229396] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:53.893367 2026] [proxy_http:error] [pid 229246:tid 229396] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:53.910861 2026] [security2:error] [pid 230252:tid 230405] [client 20.197.192.193:48896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/mimpi.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCZwAAAq4"]
[Tue Jul 21 07:21:53.933191 2026] [security2:error] [pid 230252:tid 230416] [client 20.197.192.193:42220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/dp.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCaAAAArk"]
[Tue Jul 21 07:21:53.962890 2026] [security2:error] [pid 230252:tid 230464] [client 20.197.192.193:42232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/bootstrap.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCaQAAAuk"]
[Tue Jul 21 07:21:53.992713 2026] [security2:error] [pid 230252:tid 230509] [client 20.197.192.193:41573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/wp-editor.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCagAAAxY"]
[Tue Jul 21 07:21:54.014933 2026] [security2:error] [pid 230252:tid 230510] [client 20.197.192.193:48901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/cro.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCbQAAAxc"]
[Tue Jul 21 07:21:54.027249 2026] [security2:error] [pid 229246:tid 229482] [client 20.197.192.193:42235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/cron-tab.php"] [unique_id "al9IQiBMYeh5YLVG45xmKQAAAn4"]
[Tue Jul 21 07:21:54.038343 2026] [security2:error] [pid 230252:tid 230506] [client 20.206.105.145:30558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/file5.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCbwAAAxM"]
[Tue Jul 21 07:21:54.039907 2026] [security2:error] [pid 230252:tid 230399] [client 20.197.192.193:48946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/koiy.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCcAAAAqg"]
[Tue Jul 21 07:21:54.059962 2026] [security2:error] [pid 230252:tid 230478] [client 20.197.192.193:48932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/hp2.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCcgAAAvc"]
[Tue Jul 21 07:21:54.087545 2026] [security2:error] [pid 230252:tid 230410] [client 46.101.1.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.1.101.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCcwAAArM"]
[Tue Jul 21 07:21:54.131364 2026] [security2:error] [pid 229246:tid 229425] [client 20.197.192.193:42211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/hp3.php"] [unique_id "al9IQiBMYeh5YLVG45xmKwAAAkU"]
[Tue Jul 21 07:21:54.160985 2026] [security2:error] [pid 230252:tid 230389] [client 64.226.65.160:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.65.226.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCawAAAp4"]
[Tue Jul 21 07:21:54.223751 2026] [security2:error] [pid 230252:tid 230477] [client 74.249.245.134:44059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/css.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCdwAAAvY"]
[Tue Jul 21 07:21:54.241653 2026] [security2:error] [pid 229246:tid 229491] [client 20.197.192.193:42179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/aa1.php"] [unique_id "al9IQiBMYeh5YLVG45xmMAAAAoc"]
[Tue Jul 21 07:21:54.259584 2026] [security2:error] [pid 229246:tid 229479] [client 139.59.132.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.132.59.139.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQiBMYeh5YLVG45xmMQAAAns"]
[Tue Jul 21 07:21:54.320276 2026] [security2:error] [pid 229246:tid 229432] [client 20.197.192.193:42222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/acew67.php"] [unique_id "al9IQiBMYeh5YLVG45xmMwAAAkw"]
[Tue Jul 21 07:21:54.351435 2026] [security2:error] [pid 229246:tid 229406] [client 20.197.192.193:60461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/bscclapb.php"] [unique_id "al9IQiBMYeh5YLVG45xmNAAAAjI"]
[Tue Jul 21 07:21:54.403000 2026] [http2:warn] [pid 230252:tid 230491] [client 57.141.18.70:52906] h2_stream(230252-241-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:54.403215 2026] [security2:error] [pid 229246:tid 229450] [client 20.197.192.193:42216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/else1.php"] [unique_id "al9IQiBMYeh5YLVG45xmNgAAAl4"]
[Tue Jul 21 07:21:54.432250 2026] [security2:error] [pid 230252:tid 230479] [client 20.197.192.193:48918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/tkikikoko.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCegAAAvg"]
[Tue Jul 21 07:21:54.450792 2026] [security2:error] [pid 230252:tid 230402] [client 20.197.192.193:42207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCewAAAqs"]
[Tue Jul 21 07:21:54.470015 2026] [security2:error] [pid 229246:tid 229472] [client 20.226.60.151:60264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/xwpg.php"] [unique_id "al9IQiBMYeh5YLVG45xmOAAAAnQ"]
[Tue Jul 21 07:21:54.471411 2026] [security2:error] [pid 229246:tid 229434] [client 20.197.192.193:48931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/wp-css.php"] [unique_id "al9IQiBMYeh5YLVG45xmOQAAAk4"]
[Tue Jul 21 07:21:54.493289 2026] [security2:error] [pid 230252:tid 230409] [client 20.197.192.193:60437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/wp-explorer.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCfgAAArI"]
[Tue Jul 21 07:21:54.515310 2026] [security2:error] [pid 230252:tid 230442] [client 20.197.192.193:41565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/akismet.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCfwAAAtM"]
[Tue Jul 21 07:21:54.532430 2026] [security2:error] [pid 230252:tid 230459] [client 20.197.192.193:41594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/ace2.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCgAAAAuQ"]
[Tue Jul 21 07:21:54.551758 2026] [security2:error] [pid 230252:tid 230386] [client 20.197.192.193:41576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/ms.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCgQAAAps"]
[Tue Jul 21 07:21:54.596676 2026] [proxy:error] [pid 229246:tid 229492] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:54.596742 2026] [proxy_http:error] [pid 229246:tid 229492] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:54.597433 2026] [proxy:error] [pid 229246:tid 229492] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:54.597460 2026] [proxy_http:error] [pid 229246:tid 229492] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:54.676399 2026] [security2:error] [pid 230252:tid 230373] [remote 167.172.232.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.232.172.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCUAAC53Y"]
[Tue Jul 21 07:21:54.776225 2026] [security2:error] [pid 229246:tid 229383] [client 134.19.179.187:34518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9IQiBMYeh5YLVG45xmQQAAAhs"]
[Tue Jul 21 07:21:54.776328 2026] [security2:error] [pid 229246:tid 229383] [client 134.19.179.187:34518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9IQiBMYeh5YLVG45xmQQAAAhs"]
[Tue Jul 21 07:21:54.845951 2026] [security2:error] [pid 230252:tid 230379] [remote 138.197.191.87:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.191.197.138.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCXwAC33w"]
[Tue Jul 21 07:21:55.037486 2026] [proxy:error] [pid 230252:tid 230410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:55.037577 2026] [proxy_http:error] [pid 230252:tid 230410] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:55.038465 2026] [proxy:error] [pid 230252:tid 230410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:55.038513 2026] [proxy_http:error] [pid 230252:tid 230410] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:55.091759 2026] [proxy:error] [pid 229246:tid 229440] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:55.091836 2026] [proxy_http:error] [pid 229246:tid 229440] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:55.092340 2026] [proxy:error] [pid 229246:tid 229440] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:55.092369 2026] [proxy_http:error] [pid 229246:tid 229440] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:55.129059 2026] [security2:error] [pid 230252:tid 230511] [client 139.59.136.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.136.59.139.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCdgAAAxg"]
[Tue Jul 21 07:21:55.215199 2026] [http2:warn] [pid 230252:tid 230437] [client 57.141.18.107:62350] h2_stream(230252-244-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:55.261917 2026] [proxy:error] [pid 230252:tid 230385] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:55.261984 2026] [proxy_http:error] [pid 230252:tid 230385] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:55.262648 2026] [proxy:error] [pid 230252:tid 230385] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:55.262677 2026] [proxy_http:error] [pid 230252:tid 230385] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:55.449061 2026] [security2:error] [pid 229246:tid 229419] [client 20.104.96.117:59161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/jj.php"] [unique_id "al9IQyBMYeh5YLVG45xmUgAAAj8"]
[Tue Jul 21 07:21:55.543173 2026] [security2:error] [pid 230252:tid 230484] [client 74.249.245.134:42870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/php.php"] [unique_id "al9IQ00Dwhk5-Z44XrpClAAAAv0"]
[Tue Jul 21 07:21:55.598595 2026] [proxy:error] [pid 230252:tid 230458] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:55.598685 2026] [proxy_http:error] [pid 230252:tid 230458] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:55.600311 2026] [proxy:error] [pid 230252:tid 230458] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:55.600381 2026] [proxy_http:error] [pid 230252:tid 230458] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:55.716524 2026] [security2:error] [pid 230252:tid 230483] [client 103.162.129.114:64168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IQ00Dwhk5-Z44XrpCmAAAAvw"]
[Tue Jul 21 07:21:55.716676 2026] [security2:error] [pid 230252:tid 230483] [client 103.162.129.114:64168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IQ00Dwhk5-Z44XrpCmAAAAvw"]
[Tue Jul 21 07:21:55.724551 2026] [security2:error] [pid 230252:tid 230464] [client 20.226.60.151:60170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/ops.php"] [unique_id "al9IQ00Dwhk5-Z44XrpCmgAAAuk"]
[Tue Jul 21 07:21:55.735017 2026] [security2:error] [pid 230252:tid 230492] [client 103.121.156.110:64199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IQ00Dwhk5-Z44XrpCmwAAAwU"]
[Tue Jul 21 07:21:55.735124 2026] [security2:error] [pid 230252:tid 230492] [client 103.121.156.110:64199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IQ00Dwhk5-Z44XrpCmwAAAwU"]
[Tue Jul 21 07:21:55.870430 2026] [security2:error] [pid 229246:tid 229485] [client 142.93.143.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.143.93.142.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQyBMYeh5YLVG45xmXQAAAoE"]
[Tue Jul 21 07:21:55.886211 2026] [security2:error] [pid 230252:tid 230399] [client 20.104.96.117:64013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/admin.php"] [unique_id "al9IQ00Dwhk5-Z44XrpCogAAAqg"]
[Tue Jul 21 07:21:55.940844 2026] [security2:error] [pid 229246:tid 229384] [client 138.68.144.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.144.68.138.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQiBMYeh5YLVG45xmQgAAAhw"]
[Tue Jul 21 07:21:56.002272 2026] [proxy:error] [pid 230252:tid 230478] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:56.002346 2026] [proxy_http:error] [pid 230252:tid 230478] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:56.002797 2026] [proxy:error] [pid 230252:tid 230478] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:56.002840 2026] [proxy_http:error] [pid 230252:tid 230478] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:56.092018 2026] [proxy:error] [pid 230252:tid 230440] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:56.092083 2026] [proxy_http:error] [pid 230252:tid 230440] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:56.092733 2026] [proxy:error] [pid 230252:tid 230440] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:56.092772 2026] [proxy_http:error] [pid 230252:tid 230440] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:56.166204 2026] [security2:error] [pid 230252:tid 230402] [client 20.226.60.151:54530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/sixxis.php"] [unique_id "al9IRE0Dwhk5-Z44XrpCqwAAAqs"]
[Tue Jul 21 07:21:56.173464 2026] [http2:warn] [pid 229246:tid 229446] [client 185.89.42.54:49789] h2_stream(229246-433-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:56.262365 2026] [proxy:error] [pid 230252:tid 230484] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:56.262439 2026] [proxy_http:error] [pid 230252:tid 230484] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:56.263213 2026] [proxy:error] [pid 230252:tid 230484] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:56.263252 2026] [proxy_http:error] [pid 230252:tid 230484] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:56.429681 2026] [security2:error] [pid 230252:tid 230338] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IRE0Dwhk5-Z44XrpCtgACm1M"]
[Tue Jul 21 07:21:56.429880 2026] [security2:error] [pid 230252:tid 230386] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IRE0Dwhk5-Z44XrpCtgACm1M"]
[Tue Jul 21 07:21:56.474383 2026] [http2:warn] [pid 230252:tid 230503] [client 57.141.18.105:58254] h2_stream(230252-247-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:56.597358 2026] [proxy:error] [pid 230252:tid 230421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:56.597443 2026] [proxy_http:error] [pid 230252:tid 230421] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:56.598850 2026] [proxy:error] [pid 230252:tid 230421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:56.598889 2026] [proxy_http:error] [pid 230252:tid 230421] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:56.622750 2026] [security2:error] [pid 230252:tid 230399] [client 20.226.60.151:60265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/mac.php"] [unique_id "al9IRE0Dwhk5-Z44XrpCugAAAqg"]
[Tue Jul 21 07:21:56.994758 2026] [proxy:error] [pid 230252:tid 230432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:56.994832 2026] [proxy_http:error] [pid 230252:tid 230432] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:56.995450 2026] [proxy:error] [pid 230252:tid 230432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:56.995473 2026] [proxy_http:error] [pid 230252:tid 230432] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:57.024546 2026] [security2:error] [pid 230252:tid 230405] [client 74.249.245.134:62509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/aa.php"] [unique_id "al9IRU0Dwhk5-Z44XrpCyQAAAq4"]
[Tue Jul 21 07:21:57.090482 2026] [proxy:error] [pid 230252:tid 230458] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:57.090549 2026] [proxy_http:error] [pid 230252:tid 230458] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:57.091200 2026] [proxy:error] [pid 230252:tid 230458] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:57.091229 2026] [proxy_http:error] [pid 230252:tid 230458] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:57.115342 2026] [http2:warn] [pid 230252:tid 230469] [client 57.141.18.97:65264] h2_stream(230252-250-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:57.222446 2026] [security2:error] [pid 230252:tid 230483] [client 20.104.96.117:61174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9IRU0Dwhk5-Z44XrpCzQAAAvw"]
[Tue Jul 21 07:21:57.385848 2026] [proxy:error] [pid 230252:tid 230454] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:57.385914 2026] [proxy_http:error] [pid 230252:tid 230454] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:57.386371 2026] [proxy:error] [pid 230252:tid 230454] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:57.386403 2026] [proxy_http:error] [pid 230252:tid 230454] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:57.422658 2026] [security2:error] [pid 230252:tid 230443] [client 45.251.232.145:50464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IRU0Dwhk5-Z44XrpC1QAAAtQ"]
[Tue Jul 21 07:21:57.422796 2026] [security2:error] [pid 230252:tid 230443] [client 45.251.232.145:50464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IRU0Dwhk5-Z44XrpC1QAAAtQ"]
[Tue Jul 21 07:21:57.522882 2026] [security2:error] [pid 230252:tid 230455] [client 136.144.33.97:50737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IRU0Dwhk5-Z44XrpC2AAAAuA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:57.602758 2026] [proxy:error] [pid 230252:tid 230456] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:57.602861 2026] [proxy_http:error] [pid 230252:tid 230456] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:57.604037 2026] [proxy:error] [pid 230252:tid 230456] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:57.604097 2026] [proxy_http:error] [pid 230252:tid 230456] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:57.614892 2026] [security2:error] [pid 229246:tid 229387] [client 20.226.60.151:60177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/mg.php"] [unique_id "al9IRSBMYeh5YLVG45xmfgAAAh8"]
[Tue Jul 21 07:21:57.687393 2026] [security2:error] [pid 230252:tid 230440] [client 20.206.105.145:30600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/file.php"] [unique_id "al9IRU0Dwhk5-Z44XrpC3gAAAtE"]
[Tue Jul 21 07:21:57.771143 2026] [security2:error] [pid 230252:tid 230293] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IRU0Dwhk5-Z44XrpC4AAC9Cc"]
[Tue Jul 21 07:21:57.771326 2026] [security2:error] [pid 230252:tid 230475] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IRU0Dwhk5-Z44XrpC4AAC9Cc"]
[Tue Jul 21 07:21:57.809601 2026] [security2:error] [pid 229246:tid 229388] [client 68.183.180.73:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.180.183.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IRCBMYeh5YLVG45xmZwAAAiA"]
[Tue Jul 21 07:21:57.998065 2026] [proxy:error] [pid 230252:tid 230416] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:57.998138 2026] [proxy_http:error] [pid 230252:tid 230416] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:57.998701 2026] [proxy:error] [pid 230252:tid 230416] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:57.998724 2026] [proxy_http:error] [pid 230252:tid 230416] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:58.011940 2026] [security2:error] [pid 230252:tid 230419] [client 20.226.60.151:60739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/ip.php"] [unique_id "al9IRk0Dwhk5-Z44XrpC6gAAArw"]
[Tue Jul 21 07:21:58.088771 2026] [proxy:error] [pid 230252:tid 230460] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:58.088855 2026] [proxy_http:error] [pid 230252:tid 230460] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:58.089832 2026] [proxy:error] [pid 230252:tid 230460] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:58.089867 2026] [proxy_http:error] [pid 230252:tid 230460] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:58.157011 2026] [security2:error] [pid 230252:tid 230385] [client 14.139.42.196:9421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IRk0Dwhk5-Z44XrpC7wAAApo"]
[Tue Jul 21 07:21:58.157182 2026] [security2:error] [pid 230252:tid 230385] [client 14.139.42.196:9421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IRk0Dwhk5-Z44XrpC7wAAApo"]
[Tue Jul 21 07:21:58.247632 2026] [security2:error] [pid 230252:tid 230430] [client 134.19.179.187:40206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9IRk0Dwhk5-Z44XrpC8AAAAsc"]
[Tue Jul 21 07:21:58.247734 2026] [security2:error] [pid 230252:tid 230430] [client 134.19.179.187:40206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9IRk0Dwhk5-Z44XrpC8AAAAsc"]
[Tue Jul 21 07:21:58.256061 2026] [proxy:error] [pid 229246:tid 229396] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:58.256142 2026] [proxy_http:error] [pid 229246:tid 229396] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:58.256725 2026] [proxy:error] [pid 229246:tid 229396] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:58.256753 2026] [proxy_http:error] [pid 229246:tid 229396] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:58.275266 2026] [http2:warn] [pid 230252:tid 230494] [client 57.141.18.54:21978] h2_stream(230252-252-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:58.405879 2026] [security2:error] [pid 229246:tid 229503] [client 114.119.159.177:46511] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.meuflatnapraia.com.br"] [uri "/image/d235/meu-flat-na-praia-centro-de-porto-de-galinhas-conforto-e-loc-67641776af42c390b5aabfcc"] [unique_id "al9IRiBMYeh5YLVG45xmigAAApM"], referer: https://www.meuflatnapraia.com.br/pt/apartment/MJ01I/a-50m-do-mar-no-centro-de-porto-de-galinhas.
[Tue Jul 21 07:21:58.434045 2026] [security2:error] [pid 229246:tid 229481] [client 20.104.96.117:62943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/k.php"] [unique_id "al9IRiBMYeh5YLVG45xmiwAAAn0"]
[Tue Jul 21 07:21:58.461725 2026] [security2:error] [pid 229246:tid 229489] [client 68.235.38.2:50612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9IRiBMYeh5YLVG45xmjgAAAoU"]
[Tue Jul 21 07:21:58.461829 2026] [security2:error] [pid 229246:tid 229489] [client 68.235.38.2:50612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9IRiBMYeh5YLVG45xmjgAAAoU"]
[Tue Jul 21 07:21:58.603261 2026] [proxy:error] [pid 230252:tid 230506] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:58.603338 2026] [proxy_http:error] [pid 230252:tid 230506] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:58.604245 2026] [proxy:error] [pid 230252:tid 230506] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:58.604292 2026] [proxy_http:error] [pid 230252:tid 230506] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:58.610893 2026] [security2:error] [pid 230252:tid 230493] [client 20.206.105.145:30691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/aa2.php"] [unique_id "al9IRk0Dwhk5-Z44XrpC_QAAAwY"]
[Tue Jul 21 07:21:58.625653 2026] [http2:warn] [pid 229246:tid 229378] [client 57.141.18.7:64074] h2_stream(229246-412-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:58.895904 2026] [security2:error] [pid 230252:tid 230462] [client 74.7.230.56:55276] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lojadoclimatizador.com.br"] [uri "/index.php"] [unique_id "al9IRk0Dwhk5-Z44XrpC7QAC51Q"]
[Tue Jul 21 07:21:59.001926 2026] [proxy:error] [pid 229246:tid 229459] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:59.002002 2026] [proxy_http:error] [pid 229246:tid 229459] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:59.002938 2026] [proxy:error] [pid 229246:tid 229459] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:59.002979 2026] [proxy_http:error] [pid 229246:tid 229459] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:59.086338 2026] [proxy:error] [pid 230252:tid 230463] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:59.086401 2026] [proxy_http:error] [pid 230252:tid 230463] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:59.087020 2026] [proxy:error] [pid 230252:tid 230463] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:59.087047 2026] [proxy_http:error] [pid 230252:tid 230463] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:59.096383 2026] [security2:error] [pid 230252:tid 230399] [client 20.226.60.151:50773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-post-data.php"] [unique_id "al9IR00Dwhk5-Z44XrpDCwAAAqg"]
[Tue Jul 21 07:21:59.149011 2026] [http2:warn] [pid 229246:tid 229458] [client 57.141.18.94:36194] h2_stream(229246-415-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:59.199938 2026] [security2:error] [pid 229246:tid 229425] [client 14.237.123.123:61258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.123.237.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giselesaballo.online"] [uri "/xmlrpc.php"] [unique_id "al9IRyBMYeh5YLVG45xmnAAAAkU"]
[Tue Jul 21 07:21:59.200127 2026] [security2:error] [pid 229246:tid 229425] [client 14.237.123.123:61258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giselesaballo.online"] [uri "/xmlrpc.php"] [unique_id "al9IRyBMYeh5YLVG45xmnAAAAkU"]
[Tue Jul 21 07:21:59.367507 2026] [proxy:error] [pid 229246:tid 229472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:59.367573 2026] [proxy_http:error] [pid 229246:tid 229472] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:59.368079 2026] [proxy:error] [pid 229246:tid 229472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:59.368116 2026] [proxy_http:error] [pid 229246:tid 229472] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:59.439554 2026] [security2:error] [pid 229246:tid 229437] [client 20.206.105.145:30676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/ccou.php"] [unique_id "al9IRyBMYeh5YLVG45xmoQAAAlE"]
[Tue Jul 21 07:21:59.443511 2026] [core:alert] [pid 229246:tid 229477] [client 57.141.18.104:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:21:59.493629 2026] [security2:error] [pid 230252:tid 230359] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IR00Dwhk5-Z44XrpDFwACtWg"]
[Tue Jul 21 07:21:59.493823 2026] [security2:error] [pid 230252:tid 230412] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IR00Dwhk5-Z44XrpDFwACtWg"]
[Tue Jul 21 07:21:59.570069 2026] [security2:error] [pid 229246:tid 229470] [client 68.235.38.2:50620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9IRyBMYeh5YLVG45xmqgAAAnI"]
[Tue Jul 21 07:21:59.570189 2026] [security2:error] [pid 229246:tid 229470] [client 68.235.38.2:50620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9IRyBMYeh5YLVG45xmqgAAAnI"]
[Tue Jul 21 07:21:59.601557 2026] [proxy:error] [pid 230252:tid 230426] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:59.601623 2026] [proxy_http:error] [pid 230252:tid 230426] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:59.602243 2026] [proxy:error] [pid 230252:tid 230426] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:59.602271 2026] [proxy_http:error] [pid 230252:tid 230426] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:59.717406 2026] [security2:error] [pid 230252:tid 230392] [client 20.104.96.117:59167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/txets.php"] [unique_id "al9IR00Dwhk5-Z44XrpDHAAAAqE"]
[Tue Jul 21 07:21:59.747972 2026] [security2:error] [pid 229246:tid 229442] [client 74.249.245.134:21813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/bolt.php"] [unique_id "al9IRyBMYeh5YLVG45xmrwAAAlY"]
[Tue Jul 21 07:21:59.826081 2026] [security2:error] [pid 230252:tid 230476] [client 134.19.179.187:43926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9IR00Dwhk5-Z44XrpDHgAAAvU"]
[Tue Jul 21 07:21:59.826193 2026] [security2:error] [pid 230252:tid 230476] [client 134.19.179.187:43926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9IR00Dwhk5-Z44XrpDHgAAAvU"]
[Tue Jul 21 07:21:59.944645 2026] [security2:error] [pid 229246:tid 229441] [client 20.226.60.151:54466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/kq1.php"] [unique_id "al9IRyBMYeh5YLVG45xmtQAAAlU"]
[Tue Jul 21 07:21:59.998473 2026] [proxy:error] [pid 229246:tid 229475] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:59.998559 2026] [proxy_http:error] [pid 229246:tid 229475] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:59.999882 2026] [proxy:error] [pid 229246:tid 229475] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:59.999940 2026] [proxy_http:error] [pid 229246:tid 229475] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:00.088980 2026] [proxy:error] [pid 229246:tid 229482] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:00.089041 2026] [proxy_http:error] [pid 229246:tid 229482] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:00.089595 2026] [proxy:error] [pid 229246:tid 229482] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:00.089627 2026] [proxy_http:error] [pid 229246:tid 229482] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:00.147273 2026] [security2:error] [pid 230252:tid 230391] [client 20.206.105.145:30650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/dr.php"] [unique_id "al9ISE0Dwhk5-Z44XrpDJwAAAqA"]
[Tue Jul 21 07:22:00.269369 2026] [proxy:error] [pid 230252:tid 230410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:00.269440 2026] [proxy_http:error] [pid 230252:tid 230410] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:00.270124 2026] [proxy:error] [pid 230252:tid 230410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:00.270173 2026] [proxy_http:error] [pid 230252:tid 230410] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:00.481531 2026] [security2:error] [pid 229246:tid 229489] [client 20.226.60.151:60252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/pucci.php"] [unique_id "al9ISCBMYeh5YLVG45xmvQAAAoU"]
[Tue Jul 21 07:22:00.594679 2026] [security2:error] [pid 229246:tid 229283] [remote 81.173.115.7:44836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "financasparaempreendedoras.com"] [uri "/wp-login.php"] [unique_id "al9ISCBMYeh5YLVG45xmvwACNCQ"]
[Tue Jul 21 07:22:00.679698 2026] [security2:error] [pid 230252:tid 230411] [client 20.220.225.223:36832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/cro.php"] [unique_id "al9ISE0Dwhk5-Z44XrpDMgAAArQ"]
[Tue Jul 21 07:22:00.707051 2026] [proxy:error] [pid 230252:tid 230493] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:00.707114 2026] [proxy_http:error] [pid 230252:tid 230493] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:00.707618 2026] [proxy:error] [pid 230252:tid 230493] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:00.707642 2026] [proxy_http:error] [pid 230252:tid 230493] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:00.809101 2026] [security2:error] [pid 229246:tid 229501] [client 20.104.96.117:64042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/blurbs.php"] [unique_id "al9ISCBMYeh5YLVG45xmxwAAApE"]
[Tue Jul 21 07:22:00.842901 2026] [security2:error] [pid 229246:tid 229382] [client 20.220.225.223:34179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/la.php"] [unique_id "al9ISCBMYeh5YLVG45xmyAAAAho"]
[Tue Jul 21 07:22:00.859373 2026] [http2:warn] [pid 230252:tid 230433] [client 57.141.18.61:45498] h2_stream(230252-255-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:01.000880 2026] [security2:error] [pid 230252:tid 230414] [client 74.249.245.134:56989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/x.php"] [unique_id "al9ISU0Dwhk5-Z44XrpDPgAAArc"]
[Tue Jul 21 07:22:01.002087 2026] [proxy:error] [pid 230252:tid 230386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:01.002177 2026] [proxy_http:error] [pid 230252:tid 230386] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:01.003451 2026] [proxy:error] [pid 230252:tid 230386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:01.003493 2026] [proxy_http:error] [pid 230252:tid 230386] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:01.090970 2026] [proxy:error] [pid 230252:tid 230399] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:01.091033 2026] [proxy_http:error] [pid 230252:tid 230399] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:01.091631 2026] [proxy:error] [pid 230252:tid 230399] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:01.091654 2026] [proxy_http:error] [pid 230252:tid 230399] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:01.206975 2026] [security2:error] [pid 230252:tid 230344] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ISU0Dwhk5-Z44XrpDRgAC9Vk"]
[Tue Jul 21 07:22:01.207116 2026] [security2:error] [pid 230252:tid 230476] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ISU0Dwhk5-Z44XrpDRgAC9Vk"]
[Tue Jul 21 07:22:01.260044 2026] [proxy:error] [pid 230252:tid 230504] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:01.260108 2026] [proxy_http:error] [pid 230252:tid 230504] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:01.260794 2026] [proxy:error] [pid 230252:tid 230504] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:01.260831 2026] [proxy_http:error] [pid 230252:tid 230504] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:01.313260 2026] [security2:error] [pid 229246:tid 229433] [client 103.174.34.15:65235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ISSBMYeh5YLVG45xmzQAAAk0"]
[Tue Jul 21 07:22:01.313421 2026] [security2:error] [pid 229246:tid 229433] [client 103.174.34.15:65235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ISSBMYeh5YLVG45xmzQAAAk0"]
[Tue Jul 21 07:22:01.402705 2026] [security2:error] [pid 229246:tid 229472] [client 20.104.96.117:59697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/dex.php"] [unique_id "al9ISSBMYeh5YLVG45xmzwAAAnQ"]
[Tue Jul 21 07:22:01.608555 2026] [proxy:error] [pid 229246:tid 229471] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:01.608633 2026] [proxy_http:error] [pid 229246:tid 229471] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:01.609483 2026] [proxy:error] [pid 229246:tid 229471] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:01.609535 2026] [proxy_http:error] [pid 229246:tid 229471] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:01.772688 2026] [http2:warn] [pid 229246:tid 229426] [client 57.141.18.69:43388] h2_stream(229246-423-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:01.975113 2026] [security2:error] [pid 230252:tid 230308] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ISU0Dwhk5-Z44XrpDWgACozY"]
[Tue Jul 21 07:22:01.975321 2026] [security2:error] [pid 230252:tid 230394] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ISU0Dwhk5-Z44XrpDWgACozY"]
[Tue Jul 21 07:22:02.019856 2026] [security2:error] [pid 230252:tid 230458] [client 136.144.33.97:48303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9ISk0Dwhk5-Z44XrpDXQAAAuM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:02.020486 2026] [proxy:error] [pid 230252:tid 230480] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:02.020560 2026] [proxy_http:error] [pid 230252:tid 230480] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:02.021505 2026] [proxy:error] [pid 230252:tid 230480] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:02.021541 2026] [proxy_http:error] [pid 230252:tid 230480] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:02.182533 2026] [proxy:error] [pid 230252:tid 230449] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:02.182630 2026] [proxy_http:error] [pid 230252:tid 230449] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:02.184199 2026] [proxy:error] [pid 230252:tid 230449] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:02.184254 2026] [proxy_http:error] [pid 230252:tid 230449] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:02.191210 2026] [security2:error] [pid 230252:tid 230368] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9ISk0Dwhk5-Z44XrpDYgACm3E"]
[Tue Jul 21 07:22:02.191416 2026] [security2:error] [pid 230252:tid 230386] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9ISk0Dwhk5-Z44XrpDYgACm3E"]
[Tue Jul 21 07:22:02.267353 2026] [proxy:error] [pid 229246:tid 229442] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:02.267439 2026] [proxy_http:error] [pid 229246:tid 229442] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:02.268824 2026] [proxy:error] [pid 229246:tid 229442] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:02.268876 2026] [proxy_http:error] [pid 229246:tid 229442] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:02.301177 2026] [http2:warn] [pid 230252:tid 230422] [client 57.141.18.101:20786] h2_stream(230252-258-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:02.400118 2026] [security2:error] [pid 230252:tid 230472] [client 20.206.105.145:30663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/file31.php"] [unique_id "al9ISk0Dwhk5-Z44XrpDZgAAAvE"]
[Tue Jul 21 07:22:02.480337 2026] [security2:error] [pid 230252:tid 230430] [client 20.226.60.151:60240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/black.php"] [unique_id "al9ISk0Dwhk5-Z44XrpDZwAAAsc"]
[Tue Jul 21 07:22:02.749025 2026] [security2:error] [pid 229246:tid 229481] [client 20.104.96.117:64061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/bajah.php"] [unique_id "al9ISiBMYeh5YLVG45xm5gAAAn0"]
[Tue Jul 21 07:22:03.079929 2026] [security2:error] [pid 230252:tid 230460] [client 20.104.96.117:59192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/xpwer1.php"] [unique_id "al9IS00Dwhk5-Z44XrpDawAAAuU"]
[Tue Jul 21 07:22:03.293359 2026] [security2:error] [pid 229246:tid 229419] [client 175.45.70.82:54824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ISyBMYeh5YLVG45xm6wAAAj8"]
[Tue Jul 21 07:22:03.293462 2026] [security2:error] [pid 229246:tid 229419] [client 175.45.70.82:54824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ISyBMYeh5YLVG45xm6wAAAj8"]
[Tue Jul 21 07:22:03.433257 2026] [security2:error] [pid 229246:tid 229460] [client 20.226.60.151:61057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9ISyBMYeh5YLVG45xm7wAAAmg"]
[Tue Jul 21 07:22:03.461300 2026] [security2:error] [pid 229246:tid 229450] [client 20.104.96.117:64054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/a.php"] [unique_id "al9ISyBMYeh5YLVG45xm8AAAAl4"]
[Tue Jul 21 07:22:03.614348 2026] [http2:warn] [pid 229246:tid 229385] [client 57.141.18.50:24338] h2_stream(229246-424-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:03.894095 2026] [security2:error] [pid 230252:tid 230458] [client 139.135.44.145:53552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IS00Dwhk5-Z44XrpDcwAAAuM"]
[Tue Jul 21 07:22:03.894269 2026] [security2:error] [pid 230252:tid 230458] [client 139.135.44.145:53552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IS00Dwhk5-Z44XrpDcwAAAuM"]
[Tue Jul 21 07:22:03.975537 2026] [security2:error] [pid 229246:tid 229368] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9ISyBMYeh5YLVG45xm-wACfHk"]
[Tue Jul 21 07:22:03.975671 2026] [security2:error] [pid 229246:tid 229480] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9ISyBMYeh5YLVG45xm-wACfHk"]
[Tue Jul 21 07:22:04.076577 2026] [http2:warn] [pid 230252:tid 230427] [client 57.141.18.17:26292] h2_stream(230252-264-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:04.117903 2026] [security2:error] [pid 229246:tid 229452] [client 20.104.96.117:59706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/flox.php"] [unique_id "al9ITCBMYeh5YLVG45xm_wAAAmA"]
[Tue Jul 21 07:22:04.456828 2026] [security2:error] [pid 230252:tid 230436] [client 92.119.178.3:57712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9ITE0Dwhk5-Z44XrpDdgAAAs0"]
[Tue Jul 21 07:22:04.456929 2026] [security2:error] [pid 230252:tid 230436] [client 92.119.178.3:57712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9ITE0Dwhk5-Z44XrpDdgAAAs0"]
[Tue Jul 21 07:22:04.545012 2026] [security2:error] [pid 229246:tid 229392] [client 20.104.96.117:64033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/edit.php"] [unique_id "al9ITCBMYeh5YLVG45xnBgAAAiQ"]
[Tue Jul 21 07:22:04.547244 2026] [security2:error] [pid 230252:tid 230402] [client 20.220.225.223:47833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/cron-tab.php"] [unique_id "al9ITE0Dwhk5-Z44XrpDdwAAAqs"]
[Tue Jul 21 07:22:04.752142 2026] [security2:error] [pid 229246:tid 229481] [client 20.206.105.145:30643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/file6.php"] [unique_id "al9ITCBMYeh5YLVG45xnCQAAAn0"]
[Tue Jul 21 07:22:04.867365 2026] [security2:error] [pid 230252:tid 230454] [client 134.19.179.187:40214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9ITE0Dwhk5-Z44XrpDeQAAAt8"]
[Tue Jul 21 07:22:04.867475 2026] [security2:error] [pid 230252:tid 230454] [client 134.19.179.187:40214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9ITE0Dwhk5-Z44XrpDeQAAAt8"]
[Tue Jul 21 07:22:04.879927 2026] [security2:error] [pid 229246:tid 229377] [client 20.226.60.151:60275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/zlece.php"] [unique_id "al9ITCBMYeh5YLVG45xnDgAAAhU"]
[Tue Jul 21 07:22:04.998243 2026] [security2:error] [pid 229246:tid 229399] [client 74.249.245.134:15054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/jga.php"] [unique_id "al9ITCBMYeh5YLVG45xnDwAAAis"]
[Tue Jul 21 07:22:05.254042 2026] [http2:warn] [pid 230252:tid 230397] [client 57.141.18.86:27468] h2_stream(230252-269-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:05.355945 2026] [security2:error] [pid 229246:tid 229495] [client 20.104.96.117:61153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/popo.php"] [unique_id "al9ITSBMYeh5YLVG45xnFAAAAos"]
[Tue Jul 21 07:22:05.635322 2026] [security2:error] [pid 229246:tid 229406] [client 173.252.95.7:34466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ITSBMYeh5YLVG45xnFgAAAjI"]
[Tue Jul 21 07:22:05.667637 2026] [security2:error] [pid 229246:tid 229431] [client 20.104.96.117:62914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/hosty.php"] [unique_id "al9ITSBMYeh5YLVG45xnFwAAAks"]
[Tue Jul 21 07:22:05.979181 2026] [http2:warn] [pid 229246:tid 229413] [client 57.141.18.14:27858] h2_stream(229246-430-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:06.055887 2026] [security2:error] [pid 230252:tid 230438] [client 20.104.96.117:59677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/yas.php"] [unique_id "al9ITk0Dwhk5-Z44XrpDhwAAAs8"]
[Tue Jul 21 07:22:06.117524 2026] [security2:error] [pid 229246:tid 229416] [client 20.206.105.145:30609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/file15.php"] [unique_id "al9ITiBMYeh5YLVG45xnHAAAAjw"]
[Tue Jul 21 07:22:06.127486 2026] [security2:error] [pid 229246:tid 229428] [client 20.220.225.223:59467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/koiy.php"] [unique_id "al9ITiBMYeh5YLVG45xnHQAAAkg"]
[Tue Jul 21 07:22:06.342666 2026] [security2:error] [pid 229246:tid 229397] [client 20.226.60.151:61091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/h02ugyh.php"] [unique_id "al9ITiBMYeh5YLVG45xnIAAAAik"]
[Tue Jul 21 07:22:06.366723 2026] [security2:error] [pid 229246:tid 229484] [client 20.220.225.223:34293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9ITiBMYeh5YLVG45xnIQAAAoA"]
[Tue Jul 21 07:22:06.484009 2026] [security2:error] [pid 229246:tid 229479] [client 103.121.156.110:64533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9ITiBMYeh5YLVG45xnIwAAAns"]
[Tue Jul 21 07:22:06.484176 2026] [security2:error] [pid 229246:tid 229479] [client 103.121.156.110:64533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9ITiBMYeh5YLVG45xnIwAAAns"]
[Tue Jul 21 07:22:06.813860 2026] [security2:error] [pid 230252:tid 230418] [client 20.206.105.145:30647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/jp.php"] [unique_id "al9ITk0Dwhk5-Z44XrpDjAAAArs"]
[Tue Jul 21 07:22:06.821298 2026] [security2:error] [pid 230252:tid 230472] [client 20.104.96.117:62933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/k.php"] [unique_id "al9ITk0Dwhk5-Z44XrpDjQAAAvE"]
[Tue Jul 21 07:22:06.858226 2026] [security2:error] [pid 229246:tid 229306] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9ITiBMYeh5YLVG45xnKAACSjs"]
[Tue Jul 21 07:22:06.858394 2026] [security2:error] [pid 229246:tid 229430] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9ITiBMYeh5YLVG45xnKAACSjs"]
[Tue Jul 21 07:22:07.010182 2026] [security2:error] [pid 230252:tid 230393] [client 193.36.225.70:47123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IT00Dwhk5-Z44XrpDjwAAAqI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:07.031419 2026] [security2:error] [pid 229246:tid 229489] [client 74.249.245.134:57007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/k.php"] [unique_id "al9ITyBMYeh5YLVG45xnLQAAAoU"]
[Tue Jul 21 07:22:07.456780 2026] [security2:error] [pid 230252:tid 230419] [client 20.206.105.145:30703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/f35.php"] [unique_id "al9IT00Dwhk5-Z44XrpDkwAAArw"]
[Tue Jul 21 07:22:07.499546 2026] [security2:error] [pid 229246:tid 229345] [remote 188.164.197.230:33430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roha.life"] [uri "/wp-login.php"] [unique_id "al9ITyBMYeh5YLVG45xnMgACfWI"]
[Tue Jul 21 07:22:07.562418 2026] [security2:error] [pid 229246:tid 229252] [remote 119.195.102.159:55212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9ITyBMYeh5YLVG45xnNAACOgU"]
[Tue Jul 21 07:22:07.593005 2026] [security2:error] [pid 230252:tid 230464] [client 20.104.96.117:61071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/file61.php"] [unique_id "al9IT00Dwhk5-Z44XrpDlgAAAuk"]
[Tue Jul 21 07:22:07.667495 2026] [security2:error] [pid 229246:tid 229419] [client 20.104.96.117:64044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/aaa.php"] [unique_id "al9ITyBMYeh5YLVG45xnNwAAAj8"]
[Tue Jul 21 07:22:07.881632 2026] [security2:error] [pid 230252:tid 230508] [client 45.251.232.145:50989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IT00Dwhk5-Z44XrpDlwAAAxU"]
[Tue Jul 21 07:22:07.881826 2026] [security2:error] [pid 230252:tid 230508] [client 45.251.232.145:50989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IT00Dwhk5-Z44XrpDlwAAAxU"]
[Tue Jul 21 07:22:07.984141 2026] [security2:error] [pid 230252:tid 230476] [client 20.206.105.145:30689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-load.php"] [unique_id "al9IT00Dwhk5-Z44XrpDmgAAAvU"]
[Tue Jul 21 07:22:08.104767 2026] [security2:error] [pid 230252:tid 230389] [client 103.162.129.114:64677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IUE0Dwhk5-Z44XrpDmwAAAp4"]
[Tue Jul 21 07:22:08.104929 2026] [security2:error] [pid 230252:tid 230389] [client 103.162.129.114:64677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IUE0Dwhk5-Z44XrpDmwAAAp4"]
[Tue Jul 21 07:22:08.156489 2026] [security2:error] [pid 229246:tid 229431] [client 20.226.60.151:60167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/vssrs.php"] [unique_id "al9IUCBMYeh5YLVG45xnOwAAAks"]
[Tue Jul 21 07:22:08.231041 2026] [security2:error] [pid 229246:tid 229492] [client 20.104.96.117:62912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/file5.php"] [unique_id "al9IUCBMYeh5YLVG45xnPAAAAog"]
[Tue Jul 21 07:22:08.478066 2026] [http2:warn] [pid 229246:tid 229412] [client 57.141.18.43:25632] h2_stream(229246-438-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:08.688583 2026] [security2:error] [pid 230252:tid 230484] [client 20.220.225.223:47836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/hp2.php"] [unique_id "al9IUE0Dwhk5-Z44XrpDoQAAAv0"]
[Tue Jul 21 07:22:08.761084 2026] [security2:error] [pid 229246:tid 229434] [client 20.104.96.117:64058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/222.php"] [unique_id "al9IUCBMYeh5YLVG45xnQAAAAk4"]
[Tue Jul 21 07:22:08.815471 2026] [security2:error] [pid 229246:tid 229397] [client 20.226.60.151:60286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wicked.php"] [unique_id "al9IUCBMYeh5YLVG45xnQgAAAik"]
[Tue Jul 21 07:22:08.924497 2026] [security2:error] [pid 229246:tid 229499] [client 14.139.42.196:17998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IUCBMYeh5YLVG45xnRAAAAo8"]
[Tue Jul 21 07:22:08.924610 2026] [security2:error] [pid 229246:tid 229499] [client 14.139.42.196:17998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IUCBMYeh5YLVG45xnRAAAAo8"]
[Tue Jul 21 07:22:09.041146 2026] [security2:error] [pid 230252:tid 230387] [client 20.206.105.145:30636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9IUU0Dwhk5-Z44XrpDpQAAApw"]
[Tue Jul 21 07:22:09.072683 2026] [http2:warn] [pid 230252:tid 230470] [client 57.141.18.63:60854] h2_stream(230252-282-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:09.178856 2026] [rewrite:error] [pid 229246:tid 229400] [client 57.141.18.104:0] AH10411: Rewritten query string contains control characters or spaces
[Tue Jul 21 07:22:09.395503 2026] [security2:error] [pid 229246:tid 229465] [client 20.104.96.117:59165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/water.php"] [unique_id "al9IUSBMYeh5YLVG45xnTgAAAm0"]
[Tue Jul 21 07:22:09.397218 2026] [security2:error] [pid 229246:tid 229425] [client 74.249.245.134:58074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/vx.php"] [unique_id "al9IUSBMYeh5YLVG45xnTwAAAkU"]
[Tue Jul 21 07:22:09.409356 2026] [security2:error] [pid 229246:tid 229480] [client 20.226.60.151:60174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/24.php"] [unique_id "al9IUSBMYeh5YLVG45xnUQAAAnw"]
[Tue Jul 21 07:22:09.471673 2026] [security2:error] [pid 230252:tid 230399] [client 20.104.96.117:62913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/test.php"] [unique_id "al9IUU0Dwhk5-Z44XrpDpwAAAqg"]
[Tue Jul 21 07:22:09.904531 2026] [http2:warn] [pid 230252:tid 230396] [client 57.141.18.82:48686] h2_stream(230252-287-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:09.941861 2026] [security2:error] [pid 229246:tid 229399] [client 20.220.225.223:36804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/hp3.php"] [unique_id "al9IUSBMYeh5YLVG45xnWQAAAis"]
[Tue Jul 21 07:22:10.114427 2026] [security2:error] [pid 230252:tid 230494] [client 20.206.105.145:30593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-links.php"] [unique_id "al9IUk0Dwhk5-Z44XrpDqwAAAwc"]
[Tue Jul 21 07:22:10.156721 2026] [security2:error] [pid 229246:tid 229324] [remote 185.22.228.25:33540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.228.22.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9IUSBMYeh5YLVG45xnSQACXU0"]
[Tue Jul 21 07:22:10.277022 2026] [security2:error] [pid 229246:tid 229299] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IUiBMYeh5YLVG45xnYAACfjQ"]
[Tue Jul 21 07:22:10.277206 2026] [security2:error] [pid 229246:tid 229482] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IUiBMYeh5YLVG45xnYAACfjQ"]
[Tue Jul 21 07:22:10.370367 2026] [security2:error] [pid 230252:tid 230464] [client 20.104.96.117:59142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/nano.php"] [unique_id "al9IUk0Dwhk5-Z44XrpDsQAAAuk"]
[Tue Jul 21 07:22:10.616459 2026] [security2:error] [pid 229246:tid 229433] [client 20.104.96.117:62953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/aaa.php"] [unique_id "al9IUiBMYeh5YLVG45xnaAAAAk0"]
[Tue Jul 21 07:22:10.828585 2026] [security2:error] [pid 230252:tid 230391] [client 20.104.96.117:59691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/moon.php"] [unique_id "al9IUk0Dwhk5-Z44XrpDuQAAAqA"]
[Tue Jul 21 07:22:10.878096 2026] [http2:warn] [pid 230252:tid 230407] [client 57.141.18.24:46376] h2_stream(230252-291-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:11.075025 2026] [security2:error] [pid 229246:tid 229477] [client 20.206.105.145:30656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/solo1.php"] [unique_id "al9IUyBMYeh5YLVG45xnbgAAAnk"]
[Tue Jul 21 07:22:11.120966 2026] [security2:error] [pid 229246:tid 229457] [client 74.249.245.134:56997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/ws77.php"] [unique_id "al9IUyBMYeh5YLVG45xnbwAAAmU"]
[Tue Jul 21 07:22:11.140225 2026] [security2:error] [pid 230252:tid 230273] [remote 47.90.200.158:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "raquelmiriandasilva1748099894000.tavarescont.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9IUk0Dwhk5-Z44XrpDugACmxM"]
[Tue Jul 21 07:22:11.490416 2026] [security2:error] [pid 229246:tid 229337] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IUyBMYeh5YLVG45xncgACj1o"]
[Tue Jul 21 07:22:11.490549 2026] [security2:error] [pid 229246:tid 229499] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IUyBMYeh5YLVG45xncgACj1o"]
[Tue Jul 21 07:22:11.502628 2026] [security2:error] [pid 230252:tid 230418] [client 20.104.96.117:64045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/11.php"] [unique_id "al9IU00Dwhk5-Z44XrpDvgAAArs"]
[Tue Jul 21 07:22:11.528248 2026] [security2:error] [pid 229246:tid 229367] [remote 47.90.200.158:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "raquelmiriandasilva1748099894000.tavarescont.com.br"] [uri "/"] [unique_id "al9IUyBMYeh5YLVG45xncwACcng"]
[Tue Jul 21 07:22:11.579518 2026] [http2:warn] [pid 230252:tid 230434] [client 57.141.18.47:23726] h2_stream(230252-292-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:11.739848 2026] [security2:error] [pid 230252:tid 230465] [client 20.206.105.145:30606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/sixxis.php"] [unique_id "al9IU00Dwhk5-Z44XrpDwAAAAuo"]
[Tue Jul 21 07:22:11.760933 2026] [security2:error] [pid 230252:tid 230346] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IU00Dwhk5-Z44XrpDwQACqFs"]
[Tue Jul 21 07:22:11.761120 2026] [security2:error] [pid 230252:tid 230399] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IU00Dwhk5-Z44XrpDwQACqFs"]
[Tue Jul 21 07:22:11.879273 2026] [security2:error] [pid 230252:tid 230500] [client 20.104.96.117:64023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/mac.php"] [unique_id "al9IU00Dwhk5-Z44XrpDxAAAAw0"]
[Tue Jul 21 07:22:11.928586 2026] [security2:error] [pid 230252:tid 230340] [remote 47.90.200.158:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "raquelmiriandasilva1748099894000.tavarescont.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9IU00Dwhk5-Z44XrpDxQAColU"]
[Tue Jul 21 07:22:12.020544 2026] [security2:error] [pid 230252:tid 230442] [client 20.104.96.117:59178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-info.php"] [unique_id "al9IVE0Dwhk5-Z44XrpDxwAAAtM"]
[Tue Jul 21 07:22:12.068332 2026] [security2:error] [pid 230252:tid 230384] [client 103.174.34.15:49308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IVE0Dwhk5-Z44XrpDyAAAApk"]
[Tue Jul 21 07:22:12.068468 2026] [security2:error] [pid 230252:tid 230384] [client 103.174.34.15:49308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IVE0Dwhk5-Z44XrpDyAAAApk"]
[Tue Jul 21 07:22:12.068938 2026] [security2:error] [pid 230252:tid 230463] [client 20.220.225.223:36856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/aa1.php"] [unique_id "al9IVE0Dwhk5-Z44XrpDyQAAAug"]
[Tue Jul 21 07:22:12.091467 2026] [security2:error] [pid 229246:tid 229417] [client 20.226.60.151:60257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/xacs.php"] [unique_id "al9IVCBMYeh5YLVG45xnewAAAj0"]
[Tue Jul 21 07:22:12.165113 2026] [security2:error] [pid 229246:tid 229418] [client 20.206.105.145:30542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/2P.update.php"] [unique_id "al9IVCBMYeh5YLVG45xngAAAAj4"]
[Tue Jul 21 07:22:12.191072 2026] [security2:error] [pid 230252:tid 230419] [client 74.249.245.134:50036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/2.php"] [unique_id "al9IVE0Dwhk5-Z44XrpDywAAArw"]
[Tue Jul 21 07:22:12.209485 2026] [http2:warn] [pid 229246:tid 229469] [client 57.141.18.37:55552] h2_stream(229246-445-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:12.321671 2026] [security2:error] [pid 230252:tid 230327] [remote 47.90.200.158:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "raquelmiriandasilva1748099894000.tavarescont.com.br"] [uri "/"] [unique_id "al9IVE0Dwhk5-Z44XrpDzQACrEg"]
[Tue Jul 21 07:22:12.360216 2026] [security2:error] [pid 230252:tid 230487] [client 20.104.96.117:62931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/chosen.php"] [unique_id "al9IVE0Dwhk5-Z44XrpDzgAAAwA"]
[Tue Jul 21 07:22:12.484400 2026] [security2:error] [pid 230252:tid 230323] [remote 47.90.200.158:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "raquelmiriandasilva1748099894000.tavarescont.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9IVE0Dwhk5-Z44XrpD0wAC9UU"]
[Tue Jul 21 07:22:12.520723 2026] [security2:error] [pid 229246:tid 229311] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IVCBMYeh5YLVG45xnggACk0A"]
[Tue Jul 21 07:22:12.520926 2026] [security2:error] [pid 229246:tid 229503] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IVCBMYeh5YLVG45xnggACk0A"]
[Tue Jul 21 07:22:12.768997 2026] [security2:error] [pid 229246:tid 229414] [client 134.19.179.187:51706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9IVCBMYeh5YLVG45xniAAAAjo"]
[Tue Jul 21 07:22:12.769482 2026] [security2:error] [pid 229246:tid 229414] [client 134.19.179.187:51706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9IVCBMYeh5YLVG45xniAAAAjo"]
[Tue Jul 21 07:22:12.798687 2026] [security2:error] [pid 230252:tid 230354] [remote 205.196.217.58:55016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.217.196.205.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cestabasicadocarlao.com.br"] [uri "/wp-login.php"] [unique_id "al9IU00Dwhk5-Z44XrpDwgAC4WM"]
[Tue Jul 21 07:22:12.802535 2026] [security2:error] [pid 230252:tid 230481] [client 20.220.225.223:47809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/acew67.php"] [unique_id "al9IVE0Dwhk5-Z44XrpD2AAAAvo"]
[Tue Jul 21 07:22:12.867668 2026] [security2:error] [pid 229246:tid 229424] [client 20.206.105.145:30579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/a.php"] [unique_id "al9IVCBMYeh5YLVG45xnigAAAkQ"]
[Tue Jul 21 07:22:12.876199 2026] [security2:error] [pid 230252:tid 230348] [remote 47.90.200.158:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "raquelmiriandasilva1748099894000.tavarescont.com.br"] [uri "/"] [unique_id "al9IVE0Dwhk5-Z44XrpD2gACoF0"]
[Tue Jul 21 07:22:12.958187 2026] [security2:error] [pid 229246:tid 229352] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IVCBMYeh5YLVG45xniwACNGk"]
[Tue Jul 21 07:22:12.958350 2026] [security2:error] [pid 229246:tid 229408] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IVCBMYeh5YLVG45xniwACNGk"]
[Tue Jul 21 07:22:12.985747 2026] [security2:error] [pid 230252:tid 230386] [client 20.104.96.117:62938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/cream1.php"] [unique_id "al9IVE0Dwhk5-Z44XrpD2wAAAps"]
[Tue Jul 21 07:22:12.999908 2026] [security2:error] [pid 230252:tid 230436] [client 193.36.225.60:64557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IVE0Dwhk5-Z44XrpD2QAAAs0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:13.130469 2026] [security2:error] [pid 230252:tid 230443] [client 20.104.96.117:61157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/2000.php"] [unique_id "al9IVU0Dwhk5-Z44XrpD3AAAAtQ"]
[Tue Jul 21 07:22:13.269577 2026] [security2:error] [pid 230252:tid 230338] [remote 47.90.200.158:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "raquelmiriandasilva1748099894000.tavarescont.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9IVU0Dwhk5-Z44XrpD3wAC8VM"]
[Tue Jul 21 07:22:13.412636 2026] [security2:error] [pid 230252:tid 230451] [client 20.206.105.145:30537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/k.php"] [unique_id "al9IVU0Dwhk5-Z44XrpD4QAAAtw"]
[Tue Jul 21 07:22:13.668704 2026] [security2:error] [pid 230252:tid 230301] [remote 47.90.200.158:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "raquelmiriandasilva1748099894000.tavarescont.com.br"] [uri "/"] [unique_id "al9IVU0Dwhk5-Z44XrpD5AAC9i8"]
[Tue Jul 21 07:22:13.711545 2026] [security2:error] [pid 229246:tid 229453] [client 20.226.60.151:54550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-temp.php"] [unique_id "al9IVSBMYeh5YLVG45xnlwAAAmE"]
[Tue Jul 21 07:22:13.744274 2026] [proxy:error] [pid 230252:tid 230437] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:13.744347 2026] [proxy_http:error] [pid 230252:tid 230437] [client 20.104.96.117:4162] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:13.745109 2026] [proxy:error] [pid 230252:tid 230437] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:13.745151 2026] [proxy_http:error] [pid 230252:tid 230437] [client 20.104.96.117:4162] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:13.789730 2026] [security2:error] [pid 230252:tid 230499] [client 20.206.105.145:30491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/w.php"] [unique_id "al9IVU0Dwhk5-Z44XrpD6QAAAww"]
[Tue Jul 21 07:22:13.831646 2026] [security2:error] [pid 229246:tid 229277] [remote 114.34.90.9:50594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.90.34.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/wp-login.php"] [unique_id "al9IVSBMYeh5YLVG45xnmQACaB4"]
[Tue Jul 21 07:22:14.010190 2026] [http2:warn] [pid 229246:tid 229455] [client 57.141.18.54:40292] h2_stream(229246-451-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:14.132721 2026] [security2:error] [pid 230252:tid 230450] [client 175.45.70.82:55335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IVk0Dwhk5-Z44XrpD7gAAAts"]
[Tue Jul 21 07:22:14.132898 2026] [security2:error] [pid 230252:tid 230450] [client 175.45.70.82:55335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IVk0Dwhk5-Z44XrpD7gAAAts"]
[Tue Jul 21 07:22:14.170760 2026] [security2:error] [pid 230252:tid 230483] [client 74.249.245.134:15089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/asd.php"] [unique_id "al9IVk0Dwhk5-Z44XrpD8AAAAvw"]
[Tue Jul 21 07:22:14.179060 2026] [autoindex:error] [pid 230252:tid 230469] [client 35.196.36.160:52583] AH01276: Cannot serve directory /home1/ofic8899/prime-website.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:22:14.235950 2026] [security2:error] [pid 230252:tid 230395] [client 20.206.105.145:30628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/insc.php"] [unique_id "al9IVk0Dwhk5-Z44XrpD8wAAAqQ"]
[Tue Jul 21 07:22:14.294998 2026] [security2:error] [pid 229246:tid 229389] [client 74.7.175.184:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "brasilcertdigital.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9IViBMYeh5YLVG45xnnwAAAiE"]
[Tue Jul 21 07:22:14.296931 2026] [security2:error] [pid 229246:tid 229502] [client 74.7.175.184:52144] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "brasilcertdigital.com.br"] [uri "/robots.txt"] [unique_id "al9IViBMYeh5YLVG45xnngACklA"]
[Tue Jul 21 07:22:14.506942 2026] [security2:error] [pid 229246:tid 229390] [client 20.197.192.193:53139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9IViBMYeh5YLVG45xnowAAAiI"]
[Tue Jul 21 07:22:14.598654 2026] [security2:error] [pid 230252:tid 230440] [client 20.206.105.145:30488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9IVk0Dwhk5-Z44XrpD-gAAAtE"]
[Tue Jul 21 07:22:14.626922 2026] [security2:error] [pid 230252:tid 230272] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IVk0Dwhk5-Z44XrpD-wADEBI"]
[Tue Jul 21 07:22:14.627098 2026] [security2:error] [pid 230252:tid 230503] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IVk0Dwhk5-Z44XrpD-wADEBI"]
[Tue Jul 21 07:22:14.662920 2026] [http2:warn] [pid 229246:tid 229445] [client 57.141.18.26:39468] h2_stream(229246-454-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:14.670330 2026] [security2:error] [pid 230252:tid 230387] [client 35.196.36.160:52583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.36.196.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IVk0Dwhk5-Z44XrpD_AAAApw"]
[Tue Jul 21 07:22:14.673469 2026] [proxy:error] [pid 230252:tid 230420] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:14.673541 2026] [proxy_http:error] [pid 230252:tid 230420] [client 20.104.96.117:64063] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:14.674222 2026] [proxy:error] [pid 230252:tid 230420] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:14.674258 2026] [proxy_http:error] [pid 230252:tid 230420] [client 20.104.96.117:64063] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:14.722025 2026] [security2:error] [pid 230252:tid 230506] [client 20.104.96.117:61170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/122.php"] [unique_id "al9IVk0Dwhk5-Z44XrpD_gAAAxM"]
[Tue Jul 21 07:22:14.724385 2026] [security2:error] [pid 230252:tid 230459] [client 139.135.44.145:54396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IVk0Dwhk5-Z44XrpD_wAAAuQ"]
[Tue Jul 21 07:22:14.725348 2026] [security2:error] [pid 230252:tid 230459] [client 139.135.44.145:54396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IVk0Dwhk5-Z44XrpD_wAAAuQ"]
[Tue Jul 21 07:22:14.856570 2026] [security2:error] [pid 229246:tid 229387] [client 74.7.175.184:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "brasilcertdigital.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9IViBMYeh5YLVG45xnqAAAAh8"]
[Tue Jul 21 07:22:14.857009 2026] [security2:error] [pid 229246:tid 229421] [client 74.7.175.184:40486] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "brasilcertdigital.com.br"] [uri "/robots.txt"] [unique_id "al9IViBMYeh5YLVG45xnpwAAAkE"]
[Tue Jul 21 07:22:14.921472 2026] [security2:error] [pid 230252:tid 230442] [client 20.206.105.145:30688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/u.php"] [unique_id "al9IVk0Dwhk5-Z44XrpEAgAAAtM"]
[Tue Jul 21 07:22:15.086951 2026] [security2:error] [pid 229246:tid 229440] [client 35.196.36.160:52212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9IVyBMYeh5YLVG45xnrgAAAlQ"]
[Tue Jul 21 07:22:15.092971 2026] [security2:error] [pid 230252:tid 230477] [client 20.206.105.145:30539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/sss.php"] [unique_id "al9IV00Dwhk5-Z44XrpEBAAAAvY"]
[Tue Jul 21 07:22:15.099208 2026] [security2:error] [pid 230252:tid 230493] [client 92.119.178.3:51896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9IV00Dwhk5-Z44XrpEBQAAAwY"]
[Tue Jul 21 07:22:15.099284 2026] [security2:error] [pid 230252:tid 230493] [client 92.119.178.3:51896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9IV00Dwhk5-Z44XrpEBQAAAwY"]
[Tue Jul 21 07:22:15.435570 2026] [security2:error] [pid 229246:tid 229489] [client 35.196.36.160:63060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9IVyBMYeh5YLVG45xntAAAAoU"]
[Tue Jul 21 07:22:15.449667 2026] [security2:error] [pid 229246:tid 229474] [client 74.249.245.134:49716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/default.php"] [unique_id "al9IVyBMYeh5YLVG45xntQAAAnY"]
[Tue Jul 21 07:22:15.486722 2026] [security2:error] [pid 230252:tid 230438] [client 20.206.105.145:30679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/sss.php"] [unique_id "al9IV00Dwhk5-Z44XrpEBwAAAs8"]
[Tue Jul 21 07:22:15.533658 2026] [security2:error] [pid 229246:tid 229429] [client 20.226.60.151:60166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/zildan.php"] [unique_id "al9IVyBMYeh5YLVG45xntwAAAkk"]
[Tue Jul 21 07:22:15.683827 2026] [security2:error] [pid 229246:tid 229424] [client 20.104.96.117:64047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/dr.php"] [unique_id "al9IVyBMYeh5YLVG45xnugAAAkQ"]
[Tue Jul 21 07:22:15.845693 2026] [security2:error] [pid 229246:tid 229419] [client 20.226.60.151:60175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/csa.php"] [unique_id "al9IVyBMYeh5YLVG45xnvwAAAj8"]
[Tue Jul 21 07:22:15.881900 2026] [security2:error] [pid 229246:tid 229385] [client 35.196.36.160:64599] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9IVyBMYeh5YLVG45xnwAAAAh0"]
[Tue Jul 21 07:22:15.886184 2026] [security2:error] [pid 229246:tid 229451] [client 20.226.60.151:60268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/w3llscc.php"] [unique_id "al9IVyBMYeh5YLVG45xnwQAAAl8"]
[Tue Jul 21 07:22:15.977702 2026] [security2:error] [pid 230252:tid 230480] [client 20.104.96.117:59198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/mds.php"] [unique_id "al9IV00Dwhk5-Z44XrpECwAAAvk"]
[Tue Jul 21 07:22:15.979832 2026] [security2:error] [pid 229246:tid 229411] [client 20.151.10.161:26428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9IVyBMYeh5YLVG45xnwgAAAjc"]
[Tue Jul 21 07:22:16.000025 2026] [security2:error] [pid 230252:tid 230389] [client 20.206.105.145:30607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/c.php"] [unique_id "al9IV00Dwhk5-Z44XrpEDAAAAp4"]
[Tue Jul 21 07:22:16.130242 2026] [security2:error] [pid 230252:tid 230450] [client 20.226.60.151:60213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wpx.php"] [unique_id "al9IWE0Dwhk5-Z44XrpEDQAAAts"]
[Tue Jul 21 07:22:16.153780 2026] [security2:error] [pid 229246:tid 229467] [client 173.252.95.31:49170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9IWCBMYeh5YLVG45xnxQAAAm8"]
[Tue Jul 21 07:22:16.155304 2026] [http2:warn] [pid 230252:tid 230466] [client 57.141.18.77:62232] h2_stream(230252-297-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:16.295237 2026] [security2:error] [pid 230252:tid 230458] [client 35.196.36.160:63062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9IWE0Dwhk5-Z44XrpEDwAAAuM"]
[Tue Jul 21 07:22:16.331742 2026] [security2:error] [pid 229246:tid 229383] [client 20.197.192.193:52252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9IWCBMYeh5YLVG45xnyQAAAhs"]
[Tue Jul 21 07:22:16.514589 2026] [security2:error] [pid 229246:tid 229397] [client 20.151.10.161:26429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9IWCBMYeh5YLVG45xnzAAAAik"]
[Tue Jul 21 07:22:16.545609 2026] [security2:error] [pid 229246:tid 229434] [client 20.104.96.117:62947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/x.php"] [unique_id "al9IWCBMYeh5YLVG45xnzQAAAk4"]
[Tue Jul 21 07:22:16.705616 2026] [security2:error] [pid 230252:tid 230457] [client 35.196.36.160:56399] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9IWE0Dwhk5-Z44XrpEEwAAAuI"]
[Tue Jul 21 07:22:16.738514 2026] [security2:error] [pid 229246:tid 229462] [client 20.220.225.223:34251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/inso.php"] [unique_id "al9IWCBMYeh5YLVG45xnzwAAAmo"]
[Tue Jul 21 07:22:16.829276 2026] [security2:error] [pid 229246:tid 229470] [client 20.206.105.145:30693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/aa.php"] [unique_id "al9IWCBMYeh5YLVG45xn0wAAAnI"]
[Tue Jul 21 07:22:16.925403 2026] [security2:error] [pid 229246:tid 229421] [client 20.151.10.161:26420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/x.php"] [unique_id "al9IWCBMYeh5YLVG45xn1QAAAkE"]
[Tue Jul 21 07:22:16.980109 2026] [security2:error] [pid 229246:tid 229409] [client 74.249.245.134:56987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/gettest.php"] [unique_id "al9IWCBMYeh5YLVG45xn1gAAAjU"]
[Tue Jul 21 07:22:16.987596 2026] [security2:error] [pid 230252:tid 230472] [client 35.196.36.160:51534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9IWE0Dwhk5-Z44XrpEFgAAAvE"]
[Tue Jul 21 07:22:17.098922 2026] [security2:error] [pid 230252:tid 230503] [client 20.220.225.223:59472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/bscclapb.php"] [unique_id "al9IWU0Dwhk5-Z44XrpEFwAAAxA"]
[Tue Jul 21 07:22:17.214626 2026] [security2:error] [pid 229246:tid 229457] [client 103.121.156.110:64863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IWSBMYeh5YLVG45xn1wAAAmU"]
[Tue Jul 21 07:22:17.214764 2026] [security2:error] [pid 229246:tid 229457] [client 103.121.156.110:64863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IWSBMYeh5YLVG45xn1wAAAmU"]
[Tue Jul 21 07:22:17.445717 2026] [security2:error] [pid 229246:tid 229452] [client 35.196.36.160:60802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9IWSBMYeh5YLVG45xn3QAAAmA"]
[Tue Jul 21 07:22:17.482979 2026] [security2:error] [pid 230252:tid 230486] [client 20.151.10.161:26403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/j260624_13.php"] [unique_id "al9IWU0Dwhk5-Z44XrpEGwAAAv8"]
[Tue Jul 21 07:22:17.610634 2026] [security2:error] [pid 230252:tid 230499] [client 20.226.60.151:60198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-css.php"] [unique_id "al9IWU0Dwhk5-Z44XrpEHQAAAww"]
[Tue Jul 21 07:22:17.616303 2026] [security2:error] [pid 230252:tid 230454] [client 20.104.96.117:62924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/155.php"] [unique_id "al9IWU0Dwhk5-Z44XrpEHgAAAt8"]
[Tue Jul 21 07:22:17.725162 2026] [http2:warn] [pid 229246:tid 229379] [client 57.141.18.1:36848] h2_stream(229246-464-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:17.725237 2026] [security2:error] [pid 229246:tid 229491] [client 20.206.105.145:30653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/100.php"] [unique_id "al9IWSBMYeh5YLVG45xn4AAAAoc"]
[Tue Jul 21 07:22:17.740443 2026] [security2:error] [pid 230252:tid 230432] [client 35.196.36.160:52585] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9IWU0Dwhk5-Z44XrpEIwAAAsk"]
[Tue Jul 21 07:22:18.125046 2026] [security2:error] [pid 229246:tid 229435] [client 35.196.36.160:65426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9IWiBMYeh5YLVG45xn5wAAAk8"]
[Tue Jul 21 07:22:18.173893 2026] [security2:error] [pid 229246:tid 229450] [client 20.104.96.117:61104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-blink.php"] [unique_id "al9IWiBMYeh5YLVG45xn6AAAAl4"]
[Tue Jul 21 07:22:18.207726 2026] [security2:error] [pid 229246:tid 229408] [client 20.226.60.151:50783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/ho.php"] [unique_id "al9IWiBMYeh5YLVG45xn6QAAAjQ"]
[Tue Jul 21 07:22:18.338871 2026] [security2:error] [pid 230252:tid 230278] [remote 188.95.113.76:40794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9IWk0Dwhk5-Z44XrpEJwAC-hg"]
[Tue Jul 21 07:22:18.339069 2026] [security2:error] [pid 230252:tid 230481] [client 188.95.113.76:40794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9IWk0Dwhk5-Z44XrpEJwAC-hg"]
[Tue Jul 21 07:22:18.349069 2026] [security2:error] [pid 230252:tid 230467] [client 20.151.10.161:26416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/d62.php"] [unique_id "al9IWk0Dwhk5-Z44XrpEKAAAAuw"]
[Tue Jul 21 07:22:18.353670 2026] [security2:error] [pid 230252:tid 230422] [client 45.251.232.145:51513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IWk0Dwhk5-Z44XrpEKQAAAr8"]
[Tue Jul 21 07:22:18.353891 2026] [security2:error] [pid 230252:tid 230422] [client 45.251.232.145:51513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IWk0Dwhk5-Z44XrpEKQAAAr8"]
[Tue Jul 21 07:22:18.434371 2026] [security2:error] [pid 230252:tid 230504] [client 35.196.36.160:57798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9IWk0Dwhk5-Z44XrpEKgAAAxE"]
[Tue Jul 21 07:22:18.474424 2026] [security2:error] [pid 229246:tid 229437] [client 136.144.33.110:53435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IWiBMYeh5YLVG45xn7QAAAlE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:18.528641 2026] [security2:error] [pid 229246:tid 229406] [client 20.104.96.117:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/ops.php"] [unique_id "al9IWiBMYeh5YLVG45xn7wAAAjI"]
[Tue Jul 21 07:22:18.543213 2026] [security2:error] [pid 229246:tid 229391] [client 74.249.245.134:61845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/tfm.php"] [unique_id "al9IWiBMYeh5YLVG45xn8AAAAiM"]
[Tue Jul 21 07:22:18.669236 2026] [security2:error] [pid 230252:tid 230387] [client 20.206.105.145:30623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/footer.php"] [unique_id "al9IWk0Dwhk5-Z44XrpELQAAApw"]
[Tue Jul 21 07:22:18.699608 2026] [security2:error] [pid 230252:tid 230459] [client 35.196.36.160:49391] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9IWk0Dwhk5-Z44XrpELgAAAuQ"]
[Tue Jul 21 07:22:18.867617 2026] [security2:error] [pid 229246:tid 229389] [client 20.206.105.145:30605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/users.php"] [unique_id "al9IWiBMYeh5YLVG45xn9gAAAiE"]
[Tue Jul 21 07:22:18.906227 2026] [security2:error] [pid 230252:tid 230384] [client 20.226.60.151:60186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/xy.php"] [unique_id "al9IWk0Dwhk5-Z44XrpEMAAAApk"]
[Tue Jul 21 07:22:18.980555 2026] [security2:error] [pid 229246:tid 229492] [client 20.226.60.151:54504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9IWiBMYeh5YLVG45xn9wAAAog"]
[Tue Jul 21 07:22:19.054778 2026] [security2:error] [pid 229246:tid 229428] [client 35.196.36.160:51111] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9IWyBMYeh5YLVG45xn-wAAAkg"]
[Tue Jul 21 07:22:19.156055 2026] [http2:warn] [pid 229246:tid 229405] [client 57.141.18.38:48942] h2_stream(229246-466-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:19.290159 2026] [security2:error] [pid 230252:tid 230385] [client 20.197.192.193:53152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/wander.php"] [unique_id "al9IW00Dwhk5-Z44XrpENAAAApo"]
[Tue Jul 21 07:22:19.324301 2026] [security2:error] [pid 230252:tid 230503] [client 103.162.129.114:65188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IW00Dwhk5-Z44XrpENQAAAxA"]
[Tue Jul 21 07:22:19.324420 2026] [security2:error] [pid 230252:tid 230503] [client 103.162.129.114:65188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IW00Dwhk5-Z44XrpENQAAAxA"]
[Tue Jul 21 07:22:19.336805 2026] [security2:error] [pid 230252:tid 230453] [client 20.206.105.145:30547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/177.php"] [unique_id "al9IW00Dwhk5-Z44XrpENgAAAt4"]
[Tue Jul 21 07:22:19.506612 2026] [security2:error] [pid 230252:tid 230442] [client 74.249.245.134:62535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/ws81.php"] [unique_id "al9IW00Dwhk5-Z44XrpENwAAAtM"]
[Tue Jul 21 07:22:19.581025 2026] [security2:error] [pid 229246:tid 229390] [client 14.139.42.196:28037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IWyBMYeh5YLVG45xoAgAAAiI"]
[Tue Jul 21 07:22:19.581223 2026] [security2:error] [pid 229246:tid 229390] [client 14.139.42.196:28037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IWyBMYeh5YLVG45xoAgAAAiI"]
[Tue Jul 21 07:22:19.712279 2026] [security2:error] [pid 229246:tid 229430] [client 20.151.10.161:26401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/ups.php"] [unique_id "al9IWyBMYeh5YLVG45xoBQAAAko"]
[Tue Jul 21 07:22:19.787516 2026] [security2:error] [pid 229246:tid 229409] [client 20.104.96.117:5100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/file31.php"] [unique_id "al9IWyBMYeh5YLVG45xoBgAAAjU"]
[Tue Jul 21 07:22:19.820933 2026] [security2:error] [pid 230252:tid 230395] [client 134.19.179.187:40028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9IW00Dwhk5-Z44XrpEOAAAAqQ"]
[Tue Jul 21 07:22:19.821019 2026] [security2:error] [pid 230252:tid 230395] [client 134.19.179.187:40028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9IW00Dwhk5-Z44XrpEOAAAAqQ"]
[Tue Jul 21 07:22:19.909482 2026] [security2:error] [pid 229246:tid 229499] [client 20.226.60.151:60276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/loader.php"] [unique_id "al9IWyBMYeh5YLVG45xoBwAAAo8"]
[Tue Jul 21 07:22:20.112416 2026] [security2:error] [pid 229246:tid 229398] [client 20.104.96.117:59162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/zc-208.php"] [unique_id "al9IXCBMYeh5YLVG45xoDAAAAio"]
[Tue Jul 21 07:22:20.143718 2026] [http2:warn] [pid 229246:tid 229422] [client 57.141.18.31:46178] h2_stream(229246-467-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:20.202670 2026] [security2:error] [pid 230252:tid 230456] [client 20.206.105.145:30637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/config.php"] [unique_id "al9IXE0Dwhk5-Z44XrpEOwAAAuE"]
[Tue Jul 21 07:22:20.214137 2026] [security2:error] [pid 230252:tid 230423] [client 20.220.225.223:34246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/wpx.php"] [unique_id "al9IXE0Dwhk5-Z44XrpEPAAAAsA"]
[Tue Jul 21 07:22:20.427704 2026] [security2:error] [pid 230252:tid 230422] [client 20.151.10.161:26417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/k.php"] [unique_id "al9IXE0Dwhk5-Z44XrpEPgAAAr8"]
[Tue Jul 21 07:22:20.624938 2026] [security2:error] [pid 229246:tid 229388] [client 20.197.192.193:53154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/jga.php"] [unique_id "al9IXCBMYeh5YLVG45xoFQAAAiA"]
[Tue Jul 21 07:22:20.893212 2026] [autoindex:error] [pid 230252:tid 230418] [client 44.220.233.148:16812] AH01276: Cannot serve directory /home2/bavosc49/juridic.bavos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:22:20.934310 2026] [security2:error] [pid 229246:tid 229313] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IXCBMYeh5YLVG45xoGAACT0I"]
[Tue Jul 21 07:22:20.934537 2026] [security2:error] [pid 229246:tid 229435] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IXCBMYeh5YLVG45xoGAACT0I"]
[Tue Jul 21 07:22:21.012179 2026] [security2:error] [pid 230252:tid 230440] [client 20.220.225.223:43046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/else1.php"] [unique_id "al9IXU0Dwhk5-Z44XrpERQAAAtE"]
[Tue Jul 21 07:22:21.078350 2026] [security2:error] [pid 230252:tid 230433] [client 20.206.105.145:30550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/gettest.php"] [unique_id "al9IXU0Dwhk5-Z44XrpERgAAAso"]
[Tue Jul 21 07:22:21.141286 2026] [security2:error] [pid 229246:tid 229437] [client 20.151.10.161:26422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/k2.php"] [unique_id "al9IXSBMYeh5YLVG45xoHAAAAlE"]
[Tue Jul 21 07:22:21.208013 2026] [security2:error] [pid 229246:tid 229451] [client 20.104.96.117:59171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/sid4.php"] [unique_id "al9IXSBMYeh5YLVG45xoHgAAAl8"]
[Tue Jul 21 07:22:21.257038 2026] [security2:error] [pid 229246:tid 229391] [client 20.226.60.151:60260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/spadex.php"] [unique_id "al9IXSBMYeh5YLVG45xoHwAAAiM"]
[Tue Jul 21 07:22:21.289562 2026] [security2:error] [pid 229246:tid 229454] [client 20.104.96.117:5103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/file6.php"] [unique_id "al9IXSBMYeh5YLVG45xoIAAAAmI"]
[Tue Jul 21 07:22:21.306894 2026] [security2:error] [pid 230252:tid 230292] [remote 160.187.68.132:58918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "knconteudo.com"] [uri "/wp-login.php"] [unique_id "al9IXU0Dwhk5-Z44XrpESAAC5SY"]
[Tue Jul 21 07:22:21.527095 2026] [http2:warn] [pid 230252:tid 230498] [client 57.141.18.56:23924] h2_stream(230252-313-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:21.556079 2026] [security2:error] [pid 229246:tid 229433] [client 20.151.10.161:26499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/k3.php"] [unique_id "al9IXSBMYeh5YLVG45xoIgAAAk0"]
[Tue Jul 21 07:22:21.629376 2026] [security2:error] [pid 229246:tid 229383] [client 37.59.204.139:36380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "hctreinamentos.net"] [uri "/robots.txt"] [unique_id "al9IXSBMYeh5YLVG45xoIwAAAhs"]
[Tue Jul 21 07:22:21.629510 2026] [security2:error] [pid 229246:tid 229383] [client 37.59.204.139:36380] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "hctreinamentos.net"] [uri "/robots.txt"] [unique_id "al9IXSBMYeh5YLVG45xoIwAAAhs"]
[Tue Jul 21 07:22:21.882022 2026] [security2:error] [pid 230252:tid 230479] [client 20.226.60.151:54583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9IXU0Dwhk5-Z44XrpESwAAAvg"]
[Tue Jul 21 07:22:21.937094 2026] [security2:error] [pid 229246:tid 229402] [client 20.104.96.117:61057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wmore1.php"] [unique_id "al9IXSBMYeh5YLVG45xoLQAAAi4"]
[Tue Jul 21 07:22:22.038481 2026] [security2:error] [pid 229246:tid 229442] [client 74.249.245.134:62537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/222.php"] [unique_id "al9IXiBMYeh5YLVG45xoLgAAAlY"]
[Tue Jul 21 07:22:22.057489 2026] [proxy:error] [pid 230252:tid 230384] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:22.057582 2026] [proxy_http:error] [pid 230252:tid 230384] [client 20.104.96.117:62916] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:22.058829 2026] [proxy:error] [pid 230252:tid 230384] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:22.058893 2026] [proxy_http:error] [pid 230252:tid 230384] [client 20.104.96.117:62916] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:22.066756 2026] [security2:error] [pid 230252:tid 230477] [client 20.226.60.151:54574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/jj.php"] [unique_id "al9IXk0Dwhk5-Z44XrpETwAAAvY"]
[Tue Jul 21 07:22:22.219463 2026] [security2:error] [pid 230252:tid 230470] [client 20.151.10.161:26509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/k4.php"] [unique_id "al9IXk0Dwhk5-Z44XrpEUQAAAu8"]
[Tue Jul 21 07:22:22.251148 2026] [security2:error] [pid 229246:tid 229441] [client 20.104.96.117:61163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/solo1.php"] [unique_id "al9IXiBMYeh5YLVG45xoMgAAAlU"]
[Tue Jul 21 07:22:22.298116 2026] [security2:error] [pid 230252:tid 230314] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IXk0Dwhk5-Z44XrpEUgADDDw"]
[Tue Jul 21 07:22:22.298349 2026] [security2:error] [pid 230252:tid 230499] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IXk0Dwhk5-Z44XrpEUgADDDw"]
[Tue Jul 21 07:22:22.637313 2026] [security2:error] [pid 230252:tid 230389] [client 20.206.105.145:30545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/min.php"] [unique_id "al9IXk0Dwhk5-Z44XrpEVgAAAp4"]
[Tue Jul 21 07:22:22.702748 2026] [security2:error] [pid 230252:tid 230483] [client 20.226.60.151:60277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/2x.php"] [unique_id "al9IXk0Dwhk5-Z44XrpEWQAAAvw"]
[Tue Jul 21 07:22:22.751520 2026] [security2:error] [pid 230252:tid 230480] [client 20.220.225.223:36828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/tkikikoko.php"] [unique_id "al9IXk0Dwhk5-Z44XrpEWgAAAvk"]
[Tue Jul 21 07:22:22.767831 2026] [http2:warn] [pid 229246:tid 229466] [client 57.141.18.79:37592] h2_stream(229246-472-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:22.796261 2026] [security2:error] [pid 229246:tid 229418] [client 20.104.96.117:60935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/cong.php"] [unique_id "al9IXiBMYeh5YLVG45xoOQAAAj4"]
[Tue Jul 21 07:22:22.834608 2026] [security2:error] [pid 229246:tid 229463] [client 103.174.34.15:49780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IXiBMYeh5YLVG45xoOwAAAms"]
[Tue Jul 21 07:22:22.834780 2026] [security2:error] [pid 229246:tid 229463] [client 103.174.34.15:49780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IXiBMYeh5YLVG45xoOwAAAms"]
[Tue Jul 21 07:22:22.855285 2026] [security2:error] [pid 230252:tid 230391] [client 74.249.245.134:62586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/t.php"] [unique_id "al9IXk0Dwhk5-Z44XrpEWwAAAqA"]
[Tue Jul 21 07:22:22.981746 2026] [security2:error] [pid 230252:tid 230423] [client 20.104.96.117:62959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/adminfuns.php"] [unique_id "al9IXk0Dwhk5-Z44XrpEXQAAAsA"]
[Tue Jul 21 07:22:23.039161 2026] [security2:error] [pid 230252:tid 230467] [client 20.151.10.161:26522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/k5.php"] [unique_id "al9IX00Dwhk5-Z44XrpEXgAAAuw"]
[Tue Jul 21 07:22:23.068568 2026] [security2:error] [pid 230252:tid 230311] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IX00Dwhk5-Z44XrpEXwAC4zk"]
[Tue Jul 21 07:22:23.068763 2026] [security2:error] [pid 230252:tid 230458] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IX00Dwhk5-Z44XrpEXwAC4zk"]
[Tue Jul 21 07:22:23.134374 2026] [security2:error] [pid 230252:tid 230303] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IX00Dwhk5-Z44XrpEYAACmzE"]
[Tue Jul 21 07:22:23.134511 2026] [security2:error] [pid 230252:tid 230386] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IX00Dwhk5-Z44XrpEYAACmzE"]
[Tue Jul 21 07:22:23.171399 2026] [security2:error] [pid 229246:tid 229407] [client 136.144.33.102:61343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IXyBMYeh5YLVG45xoPQAAAjM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:23.404996 2026] [security2:error] [pid 230252:tid 230478] [client 20.104.96.117:61151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/public/css.php"] [unique_id "al9IX00Dwhk5-Z44XrpEYwAAAvc"]
[Tue Jul 21 07:22:23.428175 2026] [security2:error] [pid 230252:tid 230421] [client 20.197.192.193:52257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/x.php"] [unique_id "al9IX00Dwhk5-Z44XrpEZAAAAr4"]
[Tue Jul 21 07:22:23.543022 2026] [security2:error] [pid 230252:tid 230433] [client 20.151.10.161:26372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/w.php"] [unique_id "al9IX00Dwhk5-Z44XrpEZQAAAso"]
[Tue Jul 21 07:22:23.568367 2026] [security2:error] [pid 230252:tid 230506] [client 20.206.105.145:30630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/edorxrr.php"] [unique_id "al9IX00Dwhk5-Z44XrpEZgAAAxM"]
[Tue Jul 21 07:22:23.676621 2026] [security2:error] [pid 229246:tid 229481] [client 20.226.60.151:50756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/ctex1.php"] [unique_id "al9IXyBMYeh5YLVG45xoQgAAAn0"]
[Tue Jul 21 07:22:23.730662 2026] [security2:error] [pid 229246:tid 229321] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IXyBMYeh5YLVG45xoQwACOko"]
[Tue Jul 21 07:22:23.730818 2026] [security2:error] [pid 229246:tid 229414] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IXyBMYeh5YLVG45xoQwACOko"]
[Tue Jul 21 07:22:23.900592 2026] [security2:error] [pid 230252:tid 230397] [client 20.104.96.117:59136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/output.php"] [unique_id "al9IX00Dwhk5-Z44XrpEbQAAAqY"]
[Tue Jul 21 07:22:23.909950 2026] [security2:error] [pid 229246:tid 229449] [client 20.151.10.161:26431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/fpwch.php"] [unique_id "al9IXyBMYeh5YLVG45xoSQAAAl0"]
[Tue Jul 21 07:22:24.002306 2026] [security2:error] [pid 229246:tid 229406] [client 20.104.96.117:62927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/goods.php"] [unique_id "al9IYCBMYeh5YLVG45xoSgAAAjI"]
[Tue Jul 21 07:22:24.152379 2026] [http2:warn] [pid 230252:tid 230406] [client 57.141.18.112:41010] h2_stream(230252-319-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:24.535372 2026] [security2:error] [pid 230252:tid 230395] [client 20.151.10.161:26508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/w2025.php"] [unique_id "al9IYE0Dwhk5-Z44XrpEdgAAAqQ"]
[Tue Jul 21 07:22:24.563656 2026] [security2:error] [pid 229246:tid 229383] [client 74.249.245.134:62416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/a.php"] [unique_id "al9IYCBMYeh5YLVG45xoUQAAAhs"]
[Tue Jul 21 07:22:24.630839 2026] [security2:error] [pid 230252:tid 230483] [client 20.104.96.117:59177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-file-120.php"] [unique_id "al9IYE0Dwhk5-Z44XrpEdwAAAvw"]
[Tue Jul 21 07:22:24.676621 2026] [security2:error] [pid 230252:tid 230491] [client 20.104.96.117:64039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/100.php"] [unique_id "al9IYE0Dwhk5-Z44XrpEeAAAAwQ"]
[Tue Jul 21 07:22:24.918784 2026] [security2:error] [pid 230252:tid 230499] [client 175.45.70.82:55839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IYE0Dwhk5-Z44XrpEfAAAAww"]
[Tue Jul 21 07:22:24.918967 2026] [security2:error] [pid 230252:tid 230499] [client 175.45.70.82:55839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IYE0Dwhk5-Z44XrpEfAAAAww"]
[Tue Jul 21 07:22:25.151728 2026] [security2:error] [pid 229246:tid 229385] [client 20.151.10.161:26514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/scxy.php"] [unique_id "al9IYSBMYeh5YLVG45xoWQAAAh0"]
[Tue Jul 21 07:22:25.155857 2026] [security2:error] [pid 229246:tid 229277] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IYSBMYeh5YLVG45xoWgACSB4"]
[Tue Jul 21 07:22:25.156015 2026] [security2:error] [pid 229246:tid 229428] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IYSBMYeh5YLVG45xoWgACSB4"]
[Tue Jul 21 07:22:25.162151 2026] [security2:error] [pid 229246:tid 229443] [client 20.104.96.117:61130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/special.php"] [unique_id "al9IYSBMYeh5YLVG45xoWwAAAlc"]
[Tue Jul 21 07:22:25.300608 2026] [security2:error] [pid 230252:tid 230492] [client 185.198.240.209:27417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9IYU0Dwhk5-Z44XrpEgQAAAwU"]
[Tue Jul 21 07:22:25.323634 2026] [security2:error] [pid 230252:tid 230421] [client 20.206.105.145:30641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/hur.php"] [unique_id "al9IYU0Dwhk5-Z44XrpEggAAAr4"]
[Tue Jul 21 07:22:25.516259 2026] [http2:warn] [pid 229246:tid 229439] [client 57.141.18.119:41986] h2_stream(229246-476-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:25.606783 2026] [security2:error] [pid 229246:tid 229416] [client 139.135.44.145:53292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IYSBMYeh5YLVG45xoZAAAAjw"]
[Tue Jul 21 07:22:25.606905 2026] [security2:error] [pid 229246:tid 229416] [client 139.135.44.145:53292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IYSBMYeh5YLVG45xoZAAAAjw"]
[Tue Jul 21 07:22:25.627585 2026] [security2:error] [pid 229246:tid 229404] [client 20.104.96.117:64050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/about.php"] [unique_id "al9IYSBMYeh5YLVG45xoZQAAAjA"]
[Tue Jul 21 07:22:25.689651 2026] [security2:error] [pid 229246:tid 229398] [client 20.104.96.117:59685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/as.php"] [unique_id "al9IYSBMYeh5YLVG45xoZgAAAio"]
[Tue Jul 21 07:22:25.748557 2026] [security2:error] [pid 229246:tid 229392] [client 20.151.10.161:26404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/FWAZ.php"] [unique_id "al9IYSBMYeh5YLVG45xoZwAAAiQ"]
[Tue Jul 21 07:22:25.782959 2026] [security2:error] [pid 230252:tid 230460] [client 20.226.60.151:60246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/edorxrr.php"] [unique_id "al9IYU0Dwhk5-Z44XrpEhAAAAuU"]
[Tue Jul 21 07:22:25.853548 2026] [security2:error] [pid 229246:tid 229457] [client 20.206.105.145:30594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/zoro.php"] [unique_id "al9IYSBMYeh5YLVG45xoagAAAmU"]
[Tue Jul 21 07:22:26.182211 2026] [security2:error] [pid 229246:tid 229403] [client 20.104.96.117:62950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/about.php"] [unique_id "al9IYiBMYeh5YLVG45xocgAAAi8"]
[Tue Jul 21 07:22:26.266061 2026] [security2:error] [pid 229246:tid 229481] [client 20.151.10.161:26555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/qterm.php"] [unique_id "al9IYiBMYeh5YLVG45xocwAAAn0"]
[Tue Jul 21 07:22:26.350707 2026] [http2:warn] [pid 229246:tid 229487] [client 57.141.18.66:31450] h2_stream(229246-478-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:26.519246 2026] [security2:error] [pid 229246:tid 229494] [client 20.104.96.117:59661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9IYiBMYeh5YLVG45xoeQAAAoo"]
[Tue Jul 21 07:22:26.816237 2026] [security2:error] [pid 230252:tid 230494] [client 20.104.96.117:64043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/admin.php"] [unique_id "al9IYk0Dwhk5-Z44XrpEiAAAAwc"]
[Tue Jul 21 07:22:26.856644 2026] [security2:error] [pid 230252:tid 230407] [client 20.151.10.161:26389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/blurbs.php"] [unique_id "al9IYk0Dwhk5-Z44XrpEiQAAArA"]
[Tue Jul 21 07:22:26.905075 2026] [security2:error] [pid 230252:tid 230438] [client 20.226.60.151:54503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9IYk0Dwhk5-Z44XrpEiwAAAs8"]
[Tue Jul 21 07:22:27.228665 2026] [security2:error] [pid 229246:tid 229399] [client 20.104.96.117:61134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/w1px.php"] [unique_id "al9IYyBMYeh5YLVG45xohgAAAis"]
[Tue Jul 21 07:22:27.239895 2026] [security2:error] [pid 229246:tid 229445] [client 20.151.10.161:26507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/v543.php"] [unique_id "al9IYyBMYeh5YLVG45xohwAAAlk"]
[Tue Jul 21 07:22:27.464297 2026] [security2:error] [pid 230252:tid 230469] [client 185.198.240.196:21671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9IYU0Dwhk5-Z44XrpEgAAAAu4"]
[Tue Jul 21 07:22:27.561431 2026] [security2:error] [pid 230252:tid 230442] [client 74.249.245.134:62341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/a1.php"] [unique_id "al9IY00Dwhk5-Z44XrpEkAAAAtM"]
[Tue Jul 21 07:22:27.687649 2026] [security2:error] [pid 229246:tid 229462] [client 20.104.96.117:5066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/admin.php"] [unique_id "al9IYyBMYeh5YLVG45xokQAAAmo"]
[Tue Jul 21 07:22:27.750304 2026] [security2:error] [pid 230252:tid 230480] [client 20.151.10.161:26397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/w3lls.php"] [unique_id "al9IY00Dwhk5-Z44XrpEkwAAAvk"]
[Tue Jul 21 07:22:27.816579 2026] [security2:error] [pid 230252:tid 230396] [client 20.226.60.151:60236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/miru1.php"] [unique_id "al9IY00Dwhk5-Z44XrpElAAAAqU"]
[Tue Jul 21 07:22:27.894742 2026] [security2:error] [pid 230252:tid 230416] [client 103.121.156.110:65188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IY00Dwhk5-Z44XrpElQAAArk"]
[Tue Jul 21 07:22:27.894899 2026] [security2:error] [pid 230252:tid 230416] [client 103.121.156.110:65188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IY00Dwhk5-Z44XrpElQAAArk"]
[Tue Jul 21 07:22:27.912726 2026] [security2:error] [pid 230252:tid 230420] [client 136.144.33.101:46125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IY00Dwhk5-Z44XrpEkgAAAr0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:27.941491 2026] [security2:error] [pid 229246:tid 229479] [client 20.206.105.145:30701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/coffexium.php"] [unique_id "al9IYyBMYeh5YLVG45xokgAAAns"]
[Tue Jul 21 07:22:28.273402 2026] [http2:warn] [pid 230252:tid 230502] [client 57.141.18.57:42696] h2_stream(230252-327-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:28.399790 2026] [security2:error] [pid 230252:tid 230460] [client 20.151.10.161:26519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-ws68.php"] [unique_id "al9IZE0Dwhk5-Z44XrpEnwAAAuU"]
[Tue Jul 21 07:22:28.447871 2026] [security2:error] [pid 229246:tid 229436] [client 20.104.96.117:64053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/themes.php"] [unique_id "al9IZCBMYeh5YLVG45xonwAAAlA"]
[Tue Jul 21 07:22:28.614498 2026] [security2:error] [pid 229246:tid 229469] [client 20.226.60.151:60241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/sump1.php"] [unique_id "al9IZCBMYeh5YLVG45xopgAAAnE"]
[Tue Jul 21 07:22:28.833112 2026] [security2:error] [pid 230252:tid 230443] [client 45.251.232.145:52031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IZE0Dwhk5-Z44XrpEpgAAAtQ"]
[Tue Jul 21 07:22:28.833216 2026] [security2:error] [pid 230252:tid 230443] [client 45.251.232.145:52031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IZE0Dwhk5-Z44XrpEpgAAAtQ"]
[Tue Jul 21 07:22:29.043862 2026] [security2:error] [pid 230252:tid 230391] [client 20.104.96.117:59169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/yawa.php"] [unique_id "al9IZU0Dwhk5-Z44XrpEqwAAAqA"]
[Tue Jul 21 07:22:29.169576 2026] [security2:error] [pid 229246:tid 229500] [client 20.220.225.223:34275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/berlin.php"] [unique_id "al9IZSBMYeh5YLVG45xoswAAApA"]
[Tue Jul 21 07:22:29.227630 2026] [security2:error] [pid 230252:tid 230416] [client 20.226.60.151:60199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/file5.php"] [unique_id "al9IZU0Dwhk5-Z44XrpErAAAArk"]
[Tue Jul 21 07:22:29.364463 2026] [security2:error] [pid 230252:tid 230458] [client 20.220.225.223:43052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9IZU0Dwhk5-Z44XrpErQAAAuM"]
[Tue Jul 21 07:22:29.408112 2026] [security2:error] [pid 230252:tid 230386] [client 20.151.10.161:26400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/xyn.php"] [unique_id "al9IZU0Dwhk5-Z44XrpErgAAAps"]
[Tue Jul 21 07:22:29.672696 2026] [http2:warn] [pid 230252:tid 230471] [client 57.141.18.95:36116] h2_stream(230252-330-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:29.861306 2026] [security2:error] [pid 229246:tid 229492] [client 20.206.105.145:30601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/app.php"] [unique_id "al9IZSBMYeh5YLVG45xouQAAAog"]
[Tue Jul 21 07:22:29.953606 2026] [security2:error] [pid 229246:tid 229477] [client 20.151.10.161:26390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/green3.php"] [unique_id "al9IZSBMYeh5YLVG45xouwAAAnk"]
[Tue Jul 21 07:22:30.155696 2026] [security2:error] [pid 230252:tid 230466] [client 20.226.60.151:60259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/0xD.php"] [unique_id "al9IZk0Dwhk5-Z44XrpEuQAAAus"]
[Tue Jul 21 07:22:30.185839 2026] [security2:error] [pid 230252:tid 230500] [client 20.197.192.193:52256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/tinyfilemanager.php"] [unique_id "al9IZk0Dwhk5-Z44XrpEugAAAw0"]
[Tue Jul 21 07:22:30.611097 2026] [security2:error] [pid 230252:tid 230438] [client 20.226.60.151:54484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/txets.php"] [unique_id "al9IZk0Dwhk5-Z44XrpExgAAAs8"]
[Tue Jul 21 07:22:30.634795 2026] [security2:error] [pid 230252:tid 230503] [client 20.151.10.161:26511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/ccs.php"] [unique_id "al9IZk0Dwhk5-Z44XrpExwAAAxA"]
[Tue Jul 21 07:22:30.865738 2026] [security2:error] [pid 229246:tid 229430] [client 20.226.60.151:60271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/fnstall.php"] [unique_id "al9IZiBMYeh5YLVG45xoyQAAAko"]
[Tue Jul 21 07:22:30.900423 2026] [security2:error] [pid 229246:tid 229409] [client 20.104.96.117:59195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/js.php"] [unique_id "al9IZiBMYeh5YLVG45xoygAAAjU"]
[Tue Jul 21 07:22:31.085481 2026] [http2:warn] [pid 230252:tid 230473] [client 57.141.18.5:61110] h2_stream(230252-335-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:31.162498 2026] [security2:error] [pid 230252:tid 230454] [client 20.151.10.161:26405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/ccc.php"] [unique_id "al9IZ00Dwhk5-Z44XrpEyQAAAt8"]
[Tue Jul 21 07:22:31.333475 2026] [proxy:error] [pid 230252:tid 230391] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:31.333550 2026] [proxy_http:error] [pid 230252:tid 230391] [client 20.104.96.117:64004] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:31.334164 2026] [proxy:error] [pid 230252:tid 230391] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:31.334193 2026] [proxy_http:error] [pid 230252:tid 230391] [client 20.104.96.117:64004] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:31.572473 2026] [security2:error] [pid 230252:tid 230481] [client 20.220.225.223:46137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9IZ00Dwhk5-Z44XrpE4AAAAvo"]
[Tue Jul 21 07:22:31.591011 2026] [security2:error] [pid 229246:tid 229298] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IZyBMYeh5YLVG45xo2QACfDM"]
[Tue Jul 21 07:22:31.591121 2026] [security2:error] [pid 229246:tid 229480] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IZyBMYeh5YLVG45xo2QACfDM"]
[Tue Jul 21 07:22:31.627027 2026] [security2:error] [pid 230252:tid 230415] [client 20.151.10.161:26370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/get.php"] [unique_id "al9IZ00Dwhk5-Z44XrpE4gAAArg"]
[Tue Jul 21 07:22:31.911890 2026] [security2:error] [pid 229246:tid 229502] [client 103.162.129.114:49345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IZyBMYeh5YLVG45xo3gAAApI"]
[Tue Jul 21 07:22:31.912041 2026] [security2:error] [pid 229246:tid 229502] [client 103.162.129.114:49345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IZyBMYeh5YLVG45xo3gAAApI"]
[Tue Jul 21 07:22:31.929876 2026] [security2:error] [pid 230252:tid 230399] [client 20.104.96.117:59660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/core.php"] [unique_id "al9IZ00Dwhk5-Z44XrpE8QAAAqg"]
[Tue Jul 21 07:22:31.931627 2026] [proxy:error] [pid 230252:tid 230478] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:31.931679 2026] [proxy_http:error] [pid 230252:tid 230478] [client 20.104.96.117:5091] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:31.932295 2026] [proxy:error] [pid 230252:tid 230478] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:31.932323 2026] [proxy_http:error] [pid 230252:tid 230478] [client 20.104.96.117:5091] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:31.961245 2026] [security2:error] [pid 230252:tid 230440] [client 74.249.245.134:61258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/w.php"] [unique_id "al9IZ00Dwhk5-Z44XrpE8wAAAtE"]
[Tue Jul 21 07:22:32.151010 2026] [security2:error] [pid 229246:tid 229455] [client 20.10.88.227:3522] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "shop-officialstore.com"] [uri "/index.php"] [unique_id "al9IZyBMYeh5YLVG45xo4AAAAmM"]
[Tue Jul 21 07:22:32.210909 2026] [http2:warn] [pid 229246:tid 229490] [client 57.141.18.14:33272] h2_stream(229246-489-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:32.408962 2026] [security2:error] [pid 229246:tid 229433] [client 20.220.225.223:34277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/billur.php"] [unique_id "al9IaCBMYeh5YLVG45xo6QAAAk0"]
[Tue Jul 21 07:22:32.424540 2026] [security2:error] [pid 230252:tid 230492] [client 20.151.10.161:26413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/images.php"] [unique_id "al9IaE0Dwhk5-Z44XrpE-AAAAwU"]
[Tue Jul 21 07:22:32.588048 2026] [security2:error] [pid 230252:tid 230487] [client 20.206.105.145:30595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/core.php"] [unique_id "al9IaE0Dwhk5-Z44XrpE-gAAAwA"]
[Tue Jul 21 07:22:32.636894 2026] [security2:error] [pid 230252:tid 230472] [client 74.7.241.151:45736] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "aron.adv.br"] [uri "/robots.txt"] [unique_id "al9IaE0Dwhk5-Z44XrpE-wAC8UU"]
[Tue Jul 21 07:22:32.775966 2026] [security2:error] [pid 230252:tid 230449] [client 172.245.102.46:40931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IaE0Dwhk5-Z44XrpFBgAAAto"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:32.828860 2026] [security2:error] [pid 230252:tid 230325] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IaE0Dwhk5-Z44XrpFFAACtUY"]
[Tue Jul 21 07:22:32.828987 2026] [security2:error] [pid 230252:tid 230412] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IaE0Dwhk5-Z44XrpFFAACtUY"]
[Tue Jul 21 07:22:32.879242 2026] [security2:error] [pid 230252:tid 230396] [client 20.104.96.117:5114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/.well-known/about.php"] [unique_id "al9IaE0Dwhk5-Z44XrpFJAAAAqU"]
[Tue Jul 21 07:22:32.967578 2026] [security2:error] [pid 230252:tid 230436] [client 20.197.192.193:52269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/ee.php"] [unique_id "al9IaE0Dwhk5-Z44XrpFJgAAAs0"]
[Tue Jul 21 07:22:33.216578 2026] [security2:error] [pid 229246:tid 229479] [client 20.226.60.151:60184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/acp.php"] [unique_id "al9IaSBMYeh5YLVG45xo9QAAAns"]
[Tue Jul 21 07:22:33.300483 2026] [http2:warn] [pid 230252:tid 230489] [client 57.141.18.78:62724] h2_stream(230252-342-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:33.393216 2026] [security2:error] [pid 230252:tid 230405] [client 20.104.96.117:64025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9IaU0Dwhk5-Z44XrpFMAAAAq4"]
[Tue Jul 21 07:22:33.522749 2026] [security2:error] [pid 230252:tid 230399] [client 20.151.10.161:26516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/alls.php"] [unique_id "al9IaU0Dwhk5-Z44XrpFNAAAAqg"]
[Tue Jul 21 07:22:33.581826 2026] [security2:error] [pid 230252:tid 230352] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IaU0Dwhk5-Z44XrpFNgACu2E"]
[Tue Jul 21 07:22:33.581966 2026] [security2:error] [pid 230252:tid 230418] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IaU0Dwhk5-Z44XrpFNgACu2E"]
[Tue Jul 21 07:22:33.621560 2026] [security2:error] [pid 229246:tid 229430] [client 20.104.96.117:59676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/19.php"] [unique_id "al9IaSBMYeh5YLVG45xo-QAAAko"]
[Tue Jul 21 07:22:33.623733 2026] [security2:error] [pid 229246:tid 229366] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IaSBMYeh5YLVG45xo-gACGXc"]
[Tue Jul 21 07:22:33.623869 2026] [security2:error] [pid 229246:tid 229381] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IaSBMYeh5YLVG45xo-gACGXc"]
[Tue Jul 21 07:22:33.638114 2026] [security2:error] [pid 230252:tid 230266] [remote 47.128.56.60:48666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dscbrasil.com.br"] [uri "/inicial"] [unique_id "al9IaU0Dwhk5-Z44XrpFOAAC0Qw"]
[Tue Jul 21 07:22:33.651231 2026] [security2:error] [pid 229246:tid 229391] [client 103.174.34.15:50242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IaSBMYeh5YLVG45xo-wAAAiM"]
[Tue Jul 21 07:22:33.651396 2026] [security2:error] [pid 229246:tid 229391] [client 103.174.34.15:50242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IaSBMYeh5YLVG45xo-wAAAiM"]
[Tue Jul 21 07:22:33.798864 2026] [security2:error] [pid 230252:tid 230466] [client 142.44.233.209:31280] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "robertinhoimoveis.com.br"] [uri "/robots.txt"] [unique_id "al9IaU0Dwhk5-Z44XrpFOQAAAus"]
[Tue Jul 21 07:22:33.798962 2026] [security2:error] [pid 230252:tid 230466] [client 142.44.233.209:31280] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "robertinhoimoveis.com.br"] [uri "/robots.txt"] [unique_id "al9IaU0Dwhk5-Z44XrpFOQAAAus"]
[Tue Jul 21 07:22:33.960424 2026] [security2:error] [pid 229246:tid 229429] [client 20.151.10.161:26374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/yyu.php"] [unique_id "al9IaSBMYeh5YLVG45xpAgAAAkk"]
[Tue Jul 21 07:22:34.310697 2026] [security2:error] [pid 230252:tid 230421] [client 20.151.10.161:26523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/by.php"] [unique_id "al9Iak0Dwhk5-Z44XrpFPAAAAr4"]
[Tue Jul 21 07:22:34.376322 2026] [security2:error] [pid 229246:tid 229470] [client 20.104.96.117:5071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/wefile.php"] [unique_id "al9IaiBMYeh5YLVG45xpDgAAAnI"]
[Tue Jul 21 07:22:34.543253 2026] [security2:error] [pid 229246:tid 229349] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IaiBMYeh5YLVG45xpDwACXmY"]
[Tue Jul 21 07:22:34.543412 2026] [security2:error] [pid 229246:tid 229450] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IaiBMYeh5YLVG45xpDwACXmY"]
[Tue Jul 21 07:22:34.600705 2026] [security2:error] [pid 230252:tid 230487] [client 20.206.105.145:30557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/main.php"] [unique_id "al9Iak0Dwhk5-Z44XrpFPgAAAwA"]
[Tue Jul 21 07:22:34.659021 2026] [security2:error] [pid 230252:tid 230385] [client 20.151.10.161:26526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/FAQ.php"] [unique_id "al9Iak0Dwhk5-Z44XrpFQAAAApo"]
[Tue Jul 21 07:22:34.708528 2026] [security2:error] [pid 230252:tid 230506] [client 20.104.96.117:61065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/inc.php"] [unique_id "al9Iak0Dwhk5-Z44XrpFRAAAAxM"]
[Tue Jul 21 07:22:34.930795 2026] [security2:error] [pid 229246:tid 229414] [client 20.104.96.117:5062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9IaiBMYeh5YLVG45xpHAAAAjo"]
[Tue Jul 21 07:22:35.004535 2026] [security2:error] [pid 230252:tid 230432] [client 20.151.10.161:26384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/coffexium.php"] [unique_id "al9Ia00Dwhk5-Z44XrpFRgAAAsk"]
[Tue Jul 21 07:22:35.068651 2026] [http2:warn] [pid 230252:tid 230448] [client 57.141.18.23:31734] h2_stream(230252-349-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:35.102944 2026] [security2:error] [pid 230252:tid 230407] [client 185.198.240.97:25107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "imperdivelbestpromotionofthedaytodayonly.com"] [uri "/wp-login.php"] [unique_id "al9IaE0Dwhk5-Z44XrpFJwAAArA"]
[Tue Jul 21 07:22:35.221277 2026] [security2:error] [pid 229246:tid 229467] [client 142.44.225.88:22172] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "robertinhoimoveis.com.br"] [uri "/"] [unique_id "al9IayBMYeh5YLVG45xpHwAAAm8"]
[Tue Jul 21 07:22:35.221395 2026] [security2:error] [pid 229246:tid 229467] [client 142.44.225.88:22172] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "robertinhoimoveis.com.br"] [uri "/"] [unique_id "al9IayBMYeh5YLVG45xpHwAAAm8"]
[Tue Jul 21 07:22:35.330841 2026] [security2:error] [pid 230252:tid 230429] [client 20.104.96.117:59699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9Ia00Dwhk5-Z44XrpFSQAAAsY"]
[Tue Jul 21 07:22:35.365729 2026] [security2:error] [pid 230252:tid 230465] [client 74.7.230.13:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.boostryourorders.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "al9Ia00Dwhk5-Z44XrpFSgAC6hs"]
[Tue Jul 21 07:22:35.374913 2026] [security2:error] [pid 230252:tid 230396] [client 20.226.60.151:60239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/mosty.php"] [unique_id "al9Ia00Dwhk5-Z44XrpFSwAAAqU"]
[Tue Jul 21 07:22:35.385405 2026] [security2:error] [pid 230252:tid 230420] [client 20.151.10.161:26378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/red.php"] [unique_id "al9Ia00Dwhk5-Z44XrpFTAAAAr0"]
[Tue Jul 21 07:22:35.507850 2026] [proxy:error] [pid 229246:tid 229498] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:35.507939 2026] [proxy_http:error] [pid 229246:tid 229498] [client 20.104.96.117:5059] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:35.508641 2026] [proxy:error] [pid 229246:tid 229498] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:35.508685 2026] [proxy_http:error] [pid 229246:tid 229498] [client 20.104.96.117:5059] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:35.661252 2026] [security2:error] [pid 229246:tid 229501] [client 175.45.70.82:56346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IayBMYeh5YLVG45xpKAAAApE"]
[Tue Jul 21 07:22:35.661399 2026] [security2:error] [pid 229246:tid 229501] [client 175.45.70.82:56346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IayBMYeh5YLVG45xpKAAAApE"]
[Tue Jul 21 07:22:35.749682 2026] [security2:error] [pid 230252:tid 230371] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Ia00Dwhk5-Z44XrpFUQACuXQ"]
[Tue Jul 21 07:22:35.749959 2026] [security2:error] [pid 230252:tid 230416] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Ia00Dwhk5-Z44XrpFUQACuXQ"]
[Tue Jul 21 07:22:35.951555 2026] [http2:warn] [pid 229246:tid 229444] [client 57.141.18.16:21870] h2_stream(229246-491-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:35.957121 2026] [security2:error] [pid 230252:tid 230418] [client 20.151.10.161:26393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9Ia00Dwhk5-Z44XrpFVAAAArs"]
[Tue Jul 21 07:22:36.017553 2026] [security2:error] [pid 229246:tid 229487] [client 148.113.130.54:60522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "hctreinamentos.net"] [uri "/"] [unique_id "al9IbCBMYeh5YLVG45xpMQAAAoM"]
[Tue Jul 21 07:22:36.017670 2026] [security2:error] [pid 229246:tid 229487] [client 148.113.130.54:60522] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "hctreinamentos.net"] [uri "/"] [unique_id "al9IbCBMYeh5YLVG45xpMQAAAoM"]
[Tue Jul 21 07:22:36.091705 2026] [proxy:error] [pid 230252:tid 230427] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:36.091783 2026] [proxy_http:error] [pid 230252:tid 230427] [client 20.104.96.117:64032] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:36.092661 2026] [proxy:error] [pid 230252:tid 230427] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:36.092706 2026] [proxy_http:error] [pid 230252:tid 230427] [client 20.104.96.117:64032] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:36.198452 2026] [security2:error] [pid 230252:tid 230384] [client 20.206.105.145:30618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/init.php"] [unique_id "al9IbE0Dwhk5-Z44XrpFVgAAApk"]
[Tue Jul 21 07:22:36.268205 2026] [security2:error] [pid 230252:tid 230511] [client 20.104.96.117:61127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9IbE0Dwhk5-Z44XrpFWAAAAxg"]
[Tue Jul 21 07:22:36.369882 2026] [security2:error] [pid 229246:tid 229418] [client 20.220.225.223:47855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/wp-css.php"] [unique_id "al9IbCBMYeh5YLVG45xpNAAAAj4"]
[Tue Jul 21 07:22:36.505234 2026] [security2:error] [pid 230252:tid 230472] [client 20.151.10.161:26505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/footer.php"] [unique_id "al9IbE0Dwhk5-Z44XrpFXgAAAvE"]
[Tue Jul 21 07:22:36.664912 2026] [security2:error] [pid 230252:tid 230492] [client 20.206.105.145:30670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/prekel.php"] [unique_id "al9IbE0Dwhk5-Z44XrpFXwAAAwU"]
[Tue Jul 21 07:22:36.839750 2026] [security2:error] [pid 229246:tid 229471] [client 20.104.96.117:62929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9IbCBMYeh5YLVG45xpOwAAAnM"]
[Tue Jul 21 07:22:36.849035 2026] [security2:error] [pid 230252:tid 230506] [client 20.220.225.223:45956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9IbE0Dwhk5-Z44XrpFYAAAAxM"]
[Tue Jul 21 07:22:36.875643 2026] [security2:error] [pid 230252:tid 230433] [client 139.135.44.145:54048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IbE0Dwhk5-Z44XrpFYwAAAso"]
[Tue Jul 21 07:22:36.875792 2026] [security2:error] [pid 230252:tid 230433] [client 139.135.44.145:54048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IbE0Dwhk5-Z44XrpFYwAAAso"]
[Tue Jul 21 07:22:36.945399 2026] [security2:error] [pid 229246:tid 229392] [client 20.197.192.193:53145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/blue.php"] [unique_id "al9IbCBMYeh5YLVG45xpPwAAAiQ"]
[Tue Jul 21 07:22:36.982485 2026] [security2:error] [pid 229246:tid 229260] [remote 74.7.241.41:34014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/wp-login.php"] [unique_id "al9IayBMYeh5YLVG45xpLAACWw0"], referer: https://brasilcertdigital.com.br/wp-admin/
[Tue Jul 21 07:22:37.130261 2026] [security2:error] [pid 229246:tid 229425] [client 20.151.10.161:26530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-content/index.php"] [unique_id "al9IbSBMYeh5YLVG45xpQQAAAkU"]
[Tue Jul 21 07:22:37.209027 2026] [security2:error] [pid 230252:tid 230508] [client 20.104.96.117:59701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/ss.php"] [unique_id "al9IbU0Dwhk5-Z44XrpFZgAAAxU"]
[Tue Jul 21 07:22:37.227164 2026] [security2:error] [pid 230252:tid 230429] [client 20.226.60.151:60287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/6.php"] [unique_id "al9IbU0Dwhk5-Z44XrpFawAAAsY"]
[Tue Jul 21 07:22:37.303003 2026] [security2:error] [pid 230252:tid 230471] [client 20.104.96.117:5067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/8.php"] [unique_id "al9IbU0Dwhk5-Z44XrpFbAAAAvA"]
[Tue Jul 21 07:22:37.383965 2026] [security2:error] [pid 229246:tid 229437] [client 172.245.102.46:54011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IbSBMYeh5YLVG45xpQwAAAlE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:37.390845 2026] [security2:error] [pid 230252:tid 230502] [client 109.248.148.246:38082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IbE0Dwhk5-Z44XrpFXQAAAw8"]
[Tue Jul 21 07:22:37.390981 2026] [security2:error] [pid 230252:tid 230502] [client 109.248.148.246:38082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IbE0Dwhk5-Z44XrpFXQAAAw8"]
[Tue Jul 21 07:22:37.685631 2026] [security2:error] [pid 230252:tid 230499] [client 109.248.148.246:38086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9IbU0Dwhk5-Z44XrpFcAAAAww"]
[Tue Jul 21 07:22:37.685730 2026] [security2:error] [pid 230252:tid 230499] [client 109.248.148.246:38086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9IbU0Dwhk5-Z44XrpFcAAAAww"]
[Tue Jul 21 07:22:37.788719 2026] [security2:error] [pid 230252:tid 230458] [client 20.104.96.117:61062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/min.php"] [unique_id "al9IbU0Dwhk5-Z44XrpFcQAAAuM"]
[Tue Jul 21 07:22:37.820235 2026] [http2:warn] [pid 230252:tid 230461] [client 57.141.18.57:24118] h2_stream(230252-359-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:37.913685 2026] [security2:error] [pid 230252:tid 230384] [client 20.226.60.151:60281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9IbU0Dwhk5-Z44XrpFcgAAApk"]
[Tue Jul 21 07:22:37.995750 2026] [security2:error] [pid 229246:tid 229454] [client 20.206.105.145:30699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/0.php"] [unique_id "al9IbSBMYeh5YLVG45xpTwAAAmI"]
[Tue Jul 21 07:22:38.082258 2026] [security2:error] [pid 229246:tid 229382] [client 20.104.96.117:5076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9IbiBMYeh5YLVG45xpUQAAAho"]
[Tue Jul 21 07:22:38.191425 2026] [security2:error] [pid 230252:tid 230312] [remote 209.97.182.179:36134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.182.97.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "selleto.com.br"] [uri "/wp-login.php"] [unique_id "al9Ibk0Dwhk5-Z44XrpFdgACrjo"]
[Tue Jul 21 07:22:38.541272 2026] [security2:error] [pid 229246:tid 229455] [client 103.121.156.110:65516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IbiBMYeh5YLVG45xpWAAAAmM"]
[Tue Jul 21 07:22:38.541473 2026] [security2:error] [pid 229246:tid 229455] [client 103.121.156.110:65516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IbiBMYeh5YLVG45xpWAAAAmM"]
[Tue Jul 21 07:22:38.628587 2026] [security2:error] [pid 230252:tid 230429] [client 20.104.96.117:4175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/f6.php"] [unique_id "al9Ibk0Dwhk5-Z44XrpFgQAAAsY"]
[Tue Jul 21 07:22:38.680923 2026] [security2:error] [pid 229246:tid 229385] [client 20.151.10.161:26369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/zoro.php"] [unique_id "al9IbiBMYeh5YLVG45xpWgAAAh0"]
[Tue Jul 21 07:22:38.882972 2026] [security2:error] [pid 229246:tid 229405] [client 20.220.225.223:36820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/wp-explorer.php"] [unique_id "al9IbiBMYeh5YLVG45xpXAAAAjE"]
[Tue Jul 21 07:22:39.171708 2026] [security2:error] [pid 229246:tid 229465] [client 20.104.96.117:64040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/inputs.php"] [unique_id "al9IbyBMYeh5YLVG45xpZgAAAm0"]
[Tue Jul 21 07:22:39.249295 2026] [security2:error] [pid 229246:tid 229463] [client 74.249.245.134:62344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-good.php"] [unique_id "al9IbyBMYeh5YLVG45xpaAAAAms"]
[Tue Jul 21 07:22:39.280919 2026] [security2:error] [pid 229246:tid 229318] [remote 57.141.18.55:38938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9IbyBMYeh5YLVG45xpawACQUc"]
[Tue Jul 21 07:22:39.319541 2026] [security2:error] [pid 229246:tid 229446] [client 45.251.232.145:52554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IbyBMYeh5YLVG45xpbQAAAlo"]
[Tue Jul 21 07:22:39.319645 2026] [security2:error] [pid 229246:tid 229446] [client 45.251.232.145:52554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IbyBMYeh5YLVG45xpbQAAAlo"]
[Tue Jul 21 07:22:39.393803 2026] [security2:error] [pid 229246:tid 229486] [client 20.104.96.117:61059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9IbyBMYeh5YLVG45xpbgAAAoI"]
[Tue Jul 21 07:22:39.609921 2026] [security2:error] [pid 229246:tid 229457] [client 20.104.96.117:4160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/inputs.php"] [unique_id "al9IbyBMYeh5YLVG45xpdQAAAmU"]
[Tue Jul 21 07:22:39.703644 2026] [security2:error] [pid 229246:tid 229325] [remote 104.43.50.80:42439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.50.43.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "umapsicologiaqueprovoca.com"] [uri "/wp-login.php"] [unique_id "al9IbyBMYeh5YLVG45xpdgACK04"]
[Tue Jul 21 07:22:39.723762 2026] [http2:warn] [pid 230252:tid 230507] [client 57.141.18.22:42140] h2_stream(230252-361-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:40.008165 2026] [security2:error] [pid 230252:tid 230415] [client 20.226.60.151:60173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/qqqa.php"] [unique_id "al9IcE0Dwhk5-Z44XrpFiQAAArg"]
[Tue Jul 21 07:22:40.010741 2026] [security2:error] [pid 229246:tid 229250] [remote 216.73.160.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marketingderua.com.br"] [uri "/wp-login.php"] [unique_id "al9IcCBMYeh5YLVG45xpewACfAM"]
[Tue Jul 21 07:22:40.040764 2026] [security2:error] [pid 230252:tid 230459] [client 20.151.10.161:26496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/admin.php"] [unique_id "al9IcE0Dwhk5-Z44XrpFigAAAuQ"]
[Tue Jul 21 07:22:40.045039 2026] [security2:error] [pid 230252:tid 230498] [client 20.104.96.117:62969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/classwithtostring.php"] [unique_id "al9IcE0Dwhk5-Z44XrpFiwAAAws"]
[Tue Jul 21 07:22:40.196675 2026] [security2:error] [pid 229246:tid 229494] [client 20.220.225.223:59470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/akismet.php"] [unique_id "al9IcCBMYeh5YLVG45xpgQAAAoo"]
[Tue Jul 21 07:22:40.475072 2026] [security2:error] [pid 229246:tid 229379] [client 20.197.192.193:52275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/wp-signup.php"] [unique_id "al9IcCBMYeh5YLVG45xphAAAAhc"]
[Tue Jul 21 07:22:40.558721 2026] [http2:warn] [pid 230252:tid 230497] [client 57.141.18.114:49560] h2_stream(230252-364-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:40.708590 2026] [security2:error] [pid 230252:tid 230423] [client 20.104.96.117:62935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9IcE0Dwhk5-Z44XrpFjgAAAsA"]
[Tue Jul 21 07:22:40.806963 2026] [security2:error] [pid 229246:tid 229411] [client 20.206.105.145:30673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/BDKR28.php"] [unique_id "al9IcCBMYeh5YLVG45xpjAAAAjc"]
[Tue Jul 21 07:22:40.912574 2026] [security2:error] [pid 229246:tid 229478] [client 103.162.129.114:49808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IcCBMYeh5YLVG45xpjgAAAno"]
[Tue Jul 21 07:22:40.912738 2026] [security2:error] [pid 229246:tid 229478] [client 103.162.129.114:49808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IcCBMYeh5YLVG45xpjgAAAno"]
[Tue Jul 21 07:22:40.918201 2026] [security2:error] [pid 230252:tid 230489] [client 20.104.96.117:59695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9IcE0Dwhk5-Z44XrpFkAAAAwI"]
[Tue Jul 21 07:22:41.134615 2026] [security2:error] [pid 229246:tid 229387] [client 20.104.96.117:64035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/wp-blog.php"] [unique_id "al9IcSBMYeh5YLVG45xpkgAAAh8"]
[Tue Jul 21 07:22:41.154254 2026] [security2:error] [pid 230252:tid 230429] [client 20.220.225.223:46125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/dp.php"] [unique_id "al9IcU0Dwhk5-Z44XrpFkwAAAsY"]
[Tue Jul 21 07:22:41.202694 2026] [security2:error] [pid 229246:tid 229257] [remote 198.244.242.59:53762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "arthromdcanada.online"] [uri "/robots.txt"] [unique_id "al9IcSBMYeh5YLVG45xplAACjgo"]
[Tue Jul 21 07:22:41.202971 2026] [security2:error] [pid 229246:tid 229498] [client 198.244.242.59:53762] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arthromdcanada.online"] [uri "/robots.txt"] [unique_id "al9IcSBMYeh5YLVG45xplAACjgo"]
[Tue Jul 21 07:22:41.484879 2026] [proxy:error] [pid 230252:tid 230504] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:41.484959 2026] [proxy_http:error] [pid 230252:tid 230504] [client 20.104.96.117:5057] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:41.485628 2026] [proxy:error] [pid 230252:tid 230504] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:41.485657 2026] [proxy_http:error] [pid 230252:tid 230504] [client 20.104.96.117:5057] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:41.586183 2026] [security2:error] [pid 229246:tid 229409] [client 20.104.96.117:59173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9IcSBMYeh5YLVG45xpmQAAAjU"]
[Tue Jul 21 07:22:41.705293 2026] [security2:error] [pid 229246:tid 229463] [client 20.226.60.151:60182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/aunmc.php"] [unique_id "al9IcSBMYeh5YLVG45xpnAAAAms"]
[Tue Jul 21 07:22:41.746638 2026] [http2:warn] [pid 230252:tid 230400] [client 57.141.18.30:34696] h2_stream(230252-367-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:41.765196 2026] [security2:error] [pid 230252:tid 230458] [client 20.226.60.151:54496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/dex.php"] [unique_id "al9IcU0Dwhk5-Z44XrpFmwAAAuM"]
[Tue Jul 21 07:22:41.927178 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:26542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/greap.php"] [unique_id "al9IcSBMYeh5YLVG45xpngAAAlo"]
[Tue Jul 21 07:22:41.990090 2026] [security2:error] [pid 229246:tid 229486] [client 20.104.96.117:62949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9IcSBMYeh5YLVG45xpnwAAAoI"]
[Tue Jul 21 07:22:42.098544 2026] [security2:error] [pid 230252:tid 230420] [client 117.251.86.144:57674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9IcU0Dwhk5-Z44XrpFnQAAAr0"]
[Tue Jul 21 07:22:42.098775 2026] [security2:error] [pid 230252:tid 230420] [client 117.251.86.144:57674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9IcU0Dwhk5-Z44XrpFnQAAAr0"]
[Tue Jul 21 07:22:42.168073 2026] [security2:error] [pid 230252:tid 230464] [client 20.104.96.117:59708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9Ick0Dwhk5-Z44XrpFpAAAAuk"]
[Tue Jul 21 07:22:42.219047 2026] [security2:error] [pid 229246:tid 229447] [client 20.220.225.223:36829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/ace2.php"] [unique_id "al9IciBMYeh5YLVG45xppAAAAls"]
[Tue Jul 21 07:22:42.454959 2026] [security2:error] [pid 230252:tid 230323] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Ick0Dwhk5-Z44XrpFqQAC5EU"]
[Tue Jul 21 07:22:42.455178 2026] [security2:error] [pid 230252:tid 230459] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Ick0Dwhk5-Z44XrpFqQAC5EU"]
[Tue Jul 21 07:22:42.613513 2026] [security2:error] [pid 229246:tid 229403] [client 136.144.33.110:21443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IciBMYeh5YLVG45xpqAAAAi8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:42.621554 2026] [http2:warn] [pid 229246:tid 229497] [client 57.141.18.93:32018] h2_stream(229246-498-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:42.673554 2026] [security2:error] [pid 230252:tid 230438] [client 20.104.96.117:61181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/albin.php"] [unique_id "al9Ick0Dwhk5-Z44XrpFqwAAAs8"]
[Tue Jul 21 07:22:42.724321 2026] [security2:error] [pid 230252:tid 230503] [client 20.104.96.117:5058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/ms-edit.php"] [unique_id "al9Ick0Dwhk5-Z44XrpFrQAAAxA"]
[Tue Jul 21 07:22:42.919529 2026] [security2:error] [pid 229246:tid 229355] [remote 54.39.89.167:63428] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "arthromdcanada.online"] [uri "/"] [unique_id "al9IciBMYeh5YLVG45xpsQACUWw"]
[Tue Jul 21 07:22:42.919746 2026] [security2:error] [pid 229246:tid 229437] [client 54.39.89.167:63428] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arthromdcanada.online"] [uri "/"] [unique_id "al9IciBMYeh5YLVG45xpsQACUWw"]
[Tue Jul 21 07:22:43.002411 2026] [security2:error] [pid 229246:tid 229494] [client 20.104.96.117:61175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/cilus.php"] [unique_id "al9IcyBMYeh5YLVG45xpsgAAAoo"]
[Tue Jul 21 07:22:43.057022 2026] [security2:error] [pid 229246:tid 229452] [client 20.220.225.223:60090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/ms.php"] [unique_id "al9IcyBMYeh5YLVG45xptAAAAmA"]
[Tue Jul 21 07:22:43.213223 2026] [security2:error] [pid 230252:tid 230412] [client 20.104.96.117:5082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9Ic00Dwhk5-Z44XrpFsQAAArU"]
[Tue Jul 21 07:22:43.291504 2026] [security2:error] [pid 230252:tid 230429] [client 20.226.60.151:60169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/uoocf.php"] [unique_id "al9Ic00Dwhk5-Z44XrpFtAAAAsY"]
[Tue Jul 21 07:22:43.294962 2026] [security2:error] [pid 230252:tid 230436] [client 20.206.105.145:30680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/f35.update.php"] [unique_id "al9Ic00Dwhk5-Z44XrpFtQAAAs0"]
[Tue Jul 21 07:22:43.321489 2026] [security2:error] [pid 229246:tid 229321] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IcyBMYeh5YLVG45xpuwACV0o"]
[Tue Jul 21 07:22:43.321639 2026] [security2:error] [pid 229246:tid 229443] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IcyBMYeh5YLVG45xpuwACV0o"]
[Tue Jul 21 07:22:43.388990 2026] [security2:error] [pid 230252:tid 230389] [client 20.151.10.161:26515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/177.php"] [unique_id "al9Ic00Dwhk5-Z44XrpFtgAAAp4"]
[Tue Jul 21 07:22:43.516464 2026] [security2:error] [pid 230252:tid 230508] [client 20.104.96.117:61156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/gptsh.php"] [unique_id "al9Ic00Dwhk5-Z44XrpFuwAAAxU"]
[Tue Jul 21 07:22:43.757913 2026] [security2:error] [pid 229246:tid 229352] [remote 199.189.225.40:48641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9IcyBMYeh5YLVG45xpxQACMWk"]
[Tue Jul 21 07:22:43.820888 2026] [security2:error] [pid 229246:tid 229387] [client 20.104.96.117:61113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/rithin.php"] [unique_id "al9IcyBMYeh5YLVG45xpyAAAAh8"]
[Tue Jul 21 07:22:43.892908 2026] [proxy:error] [pid 229246:tid 229434] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:43.892983 2026] [proxy_http:error] [pid 229246:tid 229434] [client 20.104.96.117:64057] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:43.893634 2026] [proxy:error] [pid 229246:tid 229434] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:43.893663 2026] [proxy_http:error] [pid 229246:tid 229434] [client 20.104.96.117:64057] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:44.098204 2026] [security2:error] [pid 230252:tid 230478] [client 20.151.10.161:26399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/199.php"] [unique_id "al9IdE0Dwhk5-Z44XrpFwAAAAvc"]
[Tue Jul 21 07:22:44.122170 2026] [security2:error] [pid 229246:tid 229472] [client 20.104.96.117:59692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/fffm.php"] [unique_id "al9IdCBMYeh5YLVG45xpzQAAAnQ"]
[Tue Jul 21 07:22:44.153912 2026] [security2:error] [pid 230252:tid 230362] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IdE0Dwhk5-Z44XrpFwgACxGs"]
[Tue Jul 21 07:22:44.154150 2026] [security2:error] [pid 230252:tid 230427] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IdE0Dwhk5-Z44XrpFwgACxGs"]
[Tue Jul 21 07:22:44.200165 2026] [security2:error] [pid 229246:tid 229426] [client 20.206.105.145:30546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/f900.php"] [unique_id "al9IdCBMYeh5YLVG45xpzgAAAkY"]
[Tue Jul 21 07:22:44.250027 2026] [security2:error] [pid 229246:tid 229310] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IdCBMYeh5YLVG45xp1gACPj8"]
[Tue Jul 21 07:22:44.250157 2026] [security2:error] [pid 229246:tid 229418] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IdCBMYeh5YLVG45xp1gACPj8"]
[Tue Jul 21 07:22:44.292557 2026] [security2:error] [pid 229246:tid 229400] [client 20.197.192.193:53122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/csa.php"] [unique_id "al9IdCBMYeh5YLVG45xp1wAAAiw"]
[Tue Jul 21 07:22:44.485042 2026] [security2:error] [pid 230252:tid 230387] [client 20.104.96.117:5078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9IdE0Dwhk5-Z44XrpFxwAAApw"]
[Tue Jul 21 07:22:44.537948 2026] [security2:error] [pid 230252:tid 230394] [client 20.104.96.117:61123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/dfre.php"] [unique_id "al9IdE0Dwhk5-Z44XrpFyAAAAqM"]
[Tue Jul 21 07:22:44.584310 2026] [security2:error] [pid 230252:tid 230469] [client 103.174.34.15:50715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IdE0Dwhk5-Z44XrpFygAAAu4"]
[Tue Jul 21 07:22:44.599156 2026] [security2:error] [pid 230252:tid 230469] [client 103.174.34.15:50715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IdE0Dwhk5-Z44XrpFygAAAu4"]
[Tue Jul 21 07:22:44.688948 2026] [security2:error] [pid 230252:tid 230338] [remote 157.66.26.183:43862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9IdE0Dwhk5-Z44XrpFywAC7FM"]
[Tue Jul 21 07:22:44.804175 2026] [security2:error] [pid 229246:tid 229471] [client 20.151.10.161:26445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/file52.php"] [unique_id "al9IdCBMYeh5YLVG45xp4AAAAnM"]
[Tue Jul 21 07:22:44.867896 2026] [security2:error] [pid 230252:tid 230403] [client 20.104.96.117:59704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-happy.php"] [unique_id "al9IdE0Dwhk5-Z44XrpFzQAAAqw"]
[Tue Jul 21 07:22:44.956675 2026] [http2:warn] [pid 229246:tid 229456] [client 57.141.18.47:60312] h2_stream(229246-502-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:45.149115 2026] [proxy:error] [pid 230252:tid 230386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:45.149199 2026] [proxy_http:error] [pid 230252:tid 230386] [client 20.104.96.117:64026] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:45.149781 2026] [proxy:error] [pid 230252:tid 230386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:45.149822 2026] [proxy_http:error] [pid 230252:tid 230386] [client 20.104.96.117:64026] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:45.152728 2026] [security2:error] [pid 230252:tid 230335] [remote 45.117.83.212:50196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supremaservices.net"] [uri "/wp-login.php"] [unique_id "al9IdU0Dwhk5-Z44XrpF0wACx1A"]
[Tue Jul 21 07:22:45.162380 2026] [security2:error] [pid 230252:tid 230432] [client 20.220.225.223:46006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/old.php"] [unique_id "al9IdU0Dwhk5-Z44XrpF1AAAAsk"]
[Tue Jul 21 07:22:45.245084 2026] [security2:error] [pid 230252:tid 230504] [client 20.104.96.117:59153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/fpr4.php"] [unique_id "al9IdU0Dwhk5-Z44XrpF1QAAAxE"]
[Tue Jul 21 07:22:45.271665 2026] [security2:error] [pid 230252:tid 230491] [client 20.206.105.145:30616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/xmrl.php"] [unique_id "al9IdU0Dwhk5-Z44XrpF1gAAAwQ"]
[Tue Jul 21 07:22:45.314968 2026] [security2:error] [pid 230252:tid 230301] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IdU0Dwhk5-Z44XrpF1wAC0y8"]
[Tue Jul 21 07:22:45.315188 2026] [security2:error] [pid 230252:tid 230442] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IdU0Dwhk5-Z44XrpF1wAC0y8"]
[Tue Jul 21 07:22:45.422085 2026] [security2:error] [pid 229246:tid 229382] [client 20.226.60.151:60242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/iywwi.php"] [unique_id "al9IdSBMYeh5YLVG45xp6gAAAho"]
[Tue Jul 21 07:22:45.913517 2026] [security2:error] [pid 230252:tid 230387] [client 20.104.96.117:60946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/file88.php"] [unique_id "al9IdU0Dwhk5-Z44XrpF3wAAApw"]
[Tue Jul 21 07:22:46.028839 2026] [http2:warn] [pid 230252:tid 230388] [client 57.141.18.116:25528] h2_stream(230252-382-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:46.060749 2026] [security2:error] [pid 230252:tid 230480] [client 20.226.60.151:60200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/gqgsa.php"] [unique_id "al9Idk0Dwhk5-Z44XrpF4wAAAvk"]
[Tue Jul 21 07:22:46.088888 2026] [security2:error] [pid 230252:tid 230418] [client 74.249.245.134:60747] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "drjoaoguedes.com"] [uri "/.info.php"] [unique_id "al9Idk0Dwhk5-Z44XrpF5AAAArs"]
[Tue Jul 21 07:22:46.212499 2026] [security2:error] [pid 229246:tid 229477] [client 20.151.10.161:26513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/122.php"] [unique_id "al9IdiBMYeh5YLVG45xp8wAAAnk"]
[Tue Jul 21 07:22:46.225576 2026] [security2:error] [pid 229246:tid 229492] [client 20.206.105.145:30534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/memberfuns.php"] [unique_id "al9IdiBMYeh5YLVG45xp9AAAAog"]
[Tue Jul 21 07:22:46.283466 2026] [proxy:error] [pid 229246:tid 229441] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:46.283537 2026] [proxy_http:error] [pid 229246:tid 229441] [client 20.104.96.117:64037] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:46.284256 2026] [proxy:error] [pid 229246:tid 229441] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:46.284295 2026] [proxy_http:error] [pid 229246:tid 229441] [client 20.104.96.117:64037] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:46.406151 2026] [security2:error] [pid 230252:tid 230477] [client 175.45.70.82:56849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Idk0Dwhk5-Z44XrpF5gAAAvY"]
[Tue Jul 21 07:22:46.406245 2026] [security2:error] [pid 230252:tid 230477] [client 175.45.70.82:56849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Idk0Dwhk5-Z44XrpF5gAAAvY"]
[Tue Jul 21 07:22:46.429724 2026] [security2:error] [pid 229246:tid 229260] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IdiBMYeh5YLVG45xp-wACbg0"]
[Tue Jul 21 07:22:46.429896 2026] [security2:error] [pid 229246:tid 229466] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IdiBMYeh5YLVG45xp-wACbg0"]
[Tue Jul 21 07:22:46.529577 2026] [security2:error] [pid 230252:tid 230459] [client 20.220.225.223:34268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/mimpi.php"] [unique_id "al9Idk0Dwhk5-Z44XrpF5wAAAuQ"]
[Tue Jul 21 07:22:46.594521 2026] [security2:error] [pid 230252:tid 230487] [client 74.249.245.134:50272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/item.php"] [unique_id "al9Idk0Dwhk5-Z44XrpF6QAAAwA"]
[Tue Jul 21 07:22:46.743600 2026] [security2:error] [pid 230252:tid 230476] [client 20.104.96.117:59649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/ccc.php"] [unique_id "al9Idk0Dwhk5-Z44XrpF6gAAAvU"]
[Tue Jul 21 07:22:46.821553 2026] [security2:error] [pid 229246:tid 229487] [client 20.151.10.161:26426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/green1.php"] [unique_id "al9IdiBMYeh5YLVG45xp_gAAAoM"]
[Tue Jul 21 07:22:46.849061 2026] [http2:warn] [pid 229246:tid 229496] [client 57.141.18.42:65424] h2_stream(229246-504-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:46.956480 2026] [security2:error] [pid 230252:tid 230436] [client 20.104.96.117:62946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/abcd.php"] [unique_id "al9Idk0Dwhk5-Z44XrpF6wAAAs0"]
[Tue Jul 21 07:22:47.018906 2026] [security2:error] [pid 229246:tid 229413] [client 14.139.42.196:7606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IdyBMYeh5YLVG45xqBAAAAjk"]
[Tue Jul 21 07:22:47.019026 2026] [security2:error] [pid 229246:tid 229413] [client 14.139.42.196:7606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IdyBMYeh5YLVG45xqBAAAAjk"]
[Tue Jul 21 07:22:47.217069 2026] [security2:error] [pid 230252:tid 230455] [client 20.206.105.145:30686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/ms.php"] [unique_id "al9Id00Dwhk5-Z44XrpF7AAAAuA"]
[Tue Jul 21 07:22:47.256113 2026] [security2:error] [pid 229246:tid 229419] [client 20.226.60.151:60245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/elbzl.php"] [unique_id "al9IdyBMYeh5YLVG45xqBgAAAj8"]
[Tue Jul 21 07:22:47.355801 2026] [security2:error] [pid 230252:tid 230458] [client 136.144.33.28:24257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Id00Dwhk5-Z44XrpF7QAAAuM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:47.553333 2026] [security2:error] [pid 230252:tid 230499] [client 20.151.10.161:26427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/biufile.php"] [unique_id "al9Id00Dwhk5-Z44XrpF8AAAAww"]
[Tue Jul 21 07:22:47.649296 2026] [security2:error] [pid 230252:tid 230471] [client 20.104.96.117:5069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/file15.php"] [unique_id "al9Id00Dwhk5-Z44XrpF8gAAAvA"]
[Tue Jul 21 07:22:47.692340 2026] [security2:error] [pid 229246:tid 229499] [client 139.135.44.145:54843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IdyBMYeh5YLVG45xqCwAAAo8"]
[Tue Jul 21 07:22:47.692485 2026] [security2:error] [pid 229246:tid 229499] [client 139.135.44.145:54843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IdyBMYeh5YLVG45xqCwAAAo8"]
[Tue Jul 21 07:22:47.774461 2026] [security2:error] [pid 230252:tid 230416] [client 20.206.105.145:30551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/zz.php"] [unique_id "al9Id00Dwhk5-Z44XrpF9AAAArk"]
[Tue Jul 21 07:22:47.797154 2026] [security2:error] [pid 230252:tid 230440] [client 109.248.148.246:43020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Id00Dwhk5-Z44XrpF9QAAAtE"]
[Tue Jul 21 07:22:47.797248 2026] [security2:error] [pid 230252:tid 230440] [client 109.248.148.246:43020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Id00Dwhk5-Z44XrpF9QAAAtE"]
[Tue Jul 21 07:22:47.824887 2026] [security2:error] [pid 230252:tid 230478] [client 20.226.60.151:60238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/adjig.php"] [unique_id "al9Id00Dwhk5-Z44XrpF9gAAAvc"]
[Tue Jul 21 07:22:47.838561 2026] [security2:error] [pid 230252:tid 230427] [client 20.104.96.117:61166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/777.php"] [unique_id "al9Id00Dwhk5-Z44XrpF9wAAAsQ"]
[Tue Jul 21 07:22:48.206870 2026] [security2:error] [pid 229246:tid 229437] [client 20.206.105.145:30570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/for.php"] [unique_id "al9IeCBMYeh5YLVG45xqEQAAAlE"]
[Tue Jul 21 07:22:48.274420 2026] [security2:error] [pid 229246:tid 229502] [client 20.197.192.193:53128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/min.php"] [unique_id "al9IeCBMYeh5YLVG45xqEgAAApI"]
[Tue Jul 21 07:22:48.432926 2026] [access_compat:error] [pid 229246:tid 229500] [client 162.241.63.68:31320] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:22:48.499184 2026] [security2:error] [pid 230252:tid 230476] [client 20.206.105.145:30531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/yup.php"] [unique_id "al9IeE0Dwhk5-Z44XrpF_wAAAvU"]
[Tue Jul 21 07:22:48.570217 2026] [security2:error] [pid 230252:tid 230436] [client 20.226.60.151:60279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/byp.php"] [unique_id "al9IeE0Dwhk5-Z44XrpGAgAAAs0"]
[Tue Jul 21 07:22:48.640218 2026] [security2:error] [pid 230252:tid 230430] [client 20.104.96.117:62955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/jp.php"] [unique_id "al9IeE0Dwhk5-Z44XrpGBQAAAsc"]
[Tue Jul 21 07:22:48.659052 2026] [security2:error] [pid 230252:tid 230432] [client 20.151.10.161:26531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wpconf.php"] [unique_id "al9IeE0Dwhk5-Z44XrpGBwAAAsk"]
[Tue Jul 21 07:22:48.707769 2026] [http2:warn] [pid 230252:tid 230425] [client 57.141.18.90:23544] h2_stream(230252-391-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:48.777407 2026] [security2:error] [pid 230252:tid 230465] [client 194.147.58.101:39978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "ns1102.hostgator.com.br"] [uri "/core/ajax/user.ajax.php"] [unique_id "al9IeE0Dwhk5-Z44XrpGCwAAAuo"]
[Tue Jul 21 07:22:48.857394 2026] [security2:error] [pid 229246:tid 229412] [client 20.226.60.151:60215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9IeCBMYeh5YLVG45xqGgAAAjg"]
[Tue Jul 21 07:22:48.859026 2026] [security2:error] [pid 230252:tid 230412] [client 20.206.105.145:30598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wpxml.php"] [unique_id "al9IeE0Dwhk5-Z44XrpGDQAAArU"]
[Tue Jul 21 07:22:48.979186 2026] [security2:error] [pid 230252:tid 230442] [client 20.226.60.151:60273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/classwithtostring.php"] [unique_id "al9IeE0Dwhk5-Z44XrpGDwAAAtM"]
[Tue Jul 21 07:22:49.039235 2026] [security2:error] [pid 229246:tid 229431] [client 20.104.96.117:61136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/for.php"] [unique_id "al9IeSBMYeh5YLVG45xqIQAAAks"]
[Tue Jul 21 07:22:49.048141 2026] [security2:error] [pid 230252:tid 230483] [client 20.220.225.223:46003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/ms-new.php"] [unique_id "al9IeU0Dwhk5-Z44XrpGEAAAAvw"]
[Tue Jul 21 07:22:49.097289 2026] [security2:error] [pid 229246:tid 229387] [client 20.206.105.145:30571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/fffm.php"] [unique_id "al9IeSBMYeh5YLVG45xqJQAAAh8"]
[Tue Jul 21 07:22:49.172037 2026] [security2:error] [pid 229246:tid 229441] [client 20.206.105.145:30649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/gecko.php"] [unique_id "al9IeSBMYeh5YLVG45xqJwAAAlU"]
[Tue Jul 21 07:22:49.273293 2026] [security2:error] [pid 230252:tid 230455] [client 103.121.156.110:49458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IeU0Dwhk5-Z44XrpGEgAAAuA"]
[Tue Jul 21 07:22:49.273430 2026] [security2:error] [pid 230252:tid 230455] [client 103.121.156.110:49458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IeU0Dwhk5-Z44XrpGEgAAAuA"]
[Tue Jul 21 07:22:49.433294 2026] [security2:error] [pid 230252:tid 230497] [client 20.206.105.145:30642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/a1.php"] [unique_id "al9IeU0Dwhk5-Z44XrpGFgAAAwo"]
[Tue Jul 21 07:22:49.585040 2026] [security2:error] [pid 229246:tid 229463] [client 20.206.105.145:30544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/k2.php"] [unique_id "al9IeSBMYeh5YLVG45xqLQAAAms"]
[Tue Jul 21 07:22:49.586472 2026] [security2:error] [pid 230252:tid 230385] [client 20.226.60.151:60194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/root.php"] [unique_id "al9IeU0Dwhk5-Z44XrpGGQAAApo"]
[Tue Jul 21 07:22:49.644023 2026] [security2:error] [pid 230252:tid 230468] [client 20.104.96.117:64059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/f35.php"] [unique_id "al9IeU0Dwhk5-Z44XrpGGgAAAu0"]
[Tue Jul 21 07:22:49.774480 2026] [security2:error] [pid 230252:tid 230477] [client 20.206.105.145:30576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/82.php"] [unique_id "al9IeU0Dwhk5-Z44XrpGGwAAAvY"]
[Tue Jul 21 07:22:49.802310 2026] [security2:error] [pid 230252:tid 230420] [client 45.251.232.145:53077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IeU0Dwhk5-Z44XrpGHAAAAr0"]
[Tue Jul 21 07:22:49.802428 2026] [security2:error] [pid 230252:tid 230420] [client 45.251.232.145:53077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IeU0Dwhk5-Z44XrpGHAAAAr0"]
[Tue Jul 21 07:22:49.807764 2026] [security2:error] [pid 229246:tid 229401] [client 20.104.96.117:59168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/ssla.php"] [unique_id "al9IeSBMYeh5YLVG45xqMAAAAi0"]
[Tue Jul 21 07:22:50.009530 2026] [security2:error] [pid 230252:tid 230503] [client 109.248.148.246:46824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Iek0Dwhk5-Z44XrpGHQAAAxA"]
[Tue Jul 21 07:22:50.009625 2026] [security2:error] [pid 230252:tid 230503] [client 109.248.148.246:46824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Iek0Dwhk5-Z44XrpGHQAAAxA"]
[Tue Jul 21 07:22:50.011217 2026] [security2:error] [pid 230252:tid 230476] [client 20.206.105.145:30702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/config.json.php"] [unique_id "al9Iek0Dwhk5-Z44XrpGHgAAAvU"]
[Tue Jul 21 07:22:50.182145 2026] [security2:error] [pid 230252:tid 230436] [client 62.102.148.164:54212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Iek0Dwhk5-Z44XrpGHwAAAs0"]
[Tue Jul 21 07:22:50.182253 2026] [security2:error] [pid 230252:tid 230436] [client 62.102.148.164:54212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Iek0Dwhk5-Z44XrpGHwAAAs0"]
[Tue Jul 21 07:22:50.367455 2026] [security2:error] [pid 229246:tid 229485] [client 20.104.96.117:64051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/wp-load.php"] [unique_id "al9IeiBMYeh5YLVG45xqSwAAAoE"]
[Tue Jul 21 07:22:50.371872 2026] [security2:error] [pid 229246:tid 229458] [client 20.226.60.151:60232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/sym403.php"] [unique_id "al9IeiBMYeh5YLVG45xqTAAAAmY"]
[Tue Jul 21 07:22:50.377150 2026] [http2:warn] [pid 229246:tid 229386] [client 57.141.18.81:30240] h2_stream(229246-507-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:50.412303 2026] [security2:error] [pid 230252:tid 230506] [client 20.206.105.145:30568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/fpwch.php"] [unique_id "al9Iek0Dwhk5-Z44XrpGJQAAAxM"]
[Tue Jul 21 07:22:50.691246 2026] [security2:error] [pid 230252:tid 230416] [client 20.226.60.151:60193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/v543.php"] [unique_id "al9Iek0Dwhk5-Z44XrpGKAAAArk"]
[Tue Jul 21 07:22:50.726782 2026] [security2:error] [pid 229246:tid 229495] [client 20.104.96.117:59196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/zc-131.php"] [unique_id "al9IeiBMYeh5YLVG45xqUgAAAos"]
[Tue Jul 21 07:22:50.824321 2026] [security2:error] [pid 229246:tid 229350] [remote 182.77.62.24:35252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojadedoces.com"] [uri "/wp-login.php"] [unique_id "al9IeiBMYeh5YLVG45xqXwACK2c"]
[Tue Jul 21 07:22:51.135791 2026] [security2:error] [pid 230252:tid 230473] [client 20.151.10.161:26437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/mosty.php"] [unique_id "al9Ie00Dwhk5-Z44XrpGKgAAAvI"]
[Tue Jul 21 07:22:51.227985 2026] [security2:error] [pid 229246:tid 229483] [client 20.226.60.151:50764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/sixxis.php"] [unique_id "al9IeyBMYeh5YLVG45xqaQAAAn8"]
[Tue Jul 21 07:22:51.278152 2026] [security2:error] [pid 230252:tid 230511] [client 20.197.192.193:52244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/echkm.php"] [unique_id "al9Ie00Dwhk5-Z44XrpGMQAAAxg"]
[Tue Jul 21 07:22:51.622406 2026] [http2:warn] [pid 230252:tid 230413] [client 57.141.18.113:24270] h2_stream(230252-395-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:51.625526 2026] [security2:error] [pid 229246:tid 229304] [remote 150.95.80.135:51516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.80.95.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "health-24.shop"] [uri "/wp-login.php"] [unique_id "al9IeyBMYeh5YLVG45xqcAACTTk"]
[Tue Jul 21 07:22:51.677193 2026] [security2:error] [pid 230252:tid 230497] [client 103.162.129.114:50284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Ie00Dwhk5-Z44XrpGOAAAAwo"]
[Tue Jul 21 07:22:51.677311 2026] [security2:error] [pid 230252:tid 230497] [client 103.162.129.114:50284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Ie00Dwhk5-Z44XrpGOAAAAwo"]
[Tue Jul 21 07:22:51.960806 2026] [security2:error] [pid 229246:tid 229486] [client 20.104.96.117:64012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/xyn.php"] [unique_id "al9IeyBMYeh5YLVG45xqdwAAAoI"]
[Tue Jul 21 07:22:52.107208 2026] [security2:error] [pid 229246:tid 229466] [client 14.139.42.196:4393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IfCBMYeh5YLVG45xqegAAAm4"]
[Tue Jul 21 07:22:52.107314 2026] [security2:error] [pid 229246:tid 229466] [client 14.139.42.196:4393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IfCBMYeh5YLVG45xqegAAAm4"]
[Tue Jul 21 07:22:52.235449 2026] [security2:error] [pid 230252:tid 230503] [client 117.251.86.144:38726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9IfE0Dwhk5-Z44XrpGPAAAAxA"]
[Tue Jul 21 07:22:52.235584 2026] [security2:error] [pid 230252:tid 230503] [client 117.251.86.144:38726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9IfE0Dwhk5-Z44XrpGPAAAAxA"]
[Tue Jul 21 07:22:52.510260 2026] [security2:error] [pid 230252:tid 230433] [client 136.144.33.104:26843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IfE0Dwhk5-Z44XrpGPQAAAso"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:52.606365 2026] [security2:error] [pid 230252:tid 230440] [client 20.226.60.151:60223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/ip.php"] [unique_id "al9IfE0Dwhk5-Z44XrpGPwAAAtE"]
[Tue Jul 21 07:22:52.865178 2026] [http2:warn] [pid 229246:tid 229410] [client 57.141.18.16:35932] h2_stream(229246-513-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:53.179438 2026] [security2:error] [pid 230252:tid 230458] [client 20.226.60.151:54471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/xpwer1.php"] [unique_id "al9IfU0Dwhk5-Z44XrpGRAAAAuM"]
[Tue Jul 21 07:22:53.280915 2026] [security2:error] [pid 229246:tid 229357] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IfSBMYeh5YLVG45xqmQACMm4"]
[Tue Jul 21 07:22:53.281073 2026] [security2:error] [pid 229246:tid 229406] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IfSBMYeh5YLVG45xqmQACMm4"]
[Tue Jul 21 07:22:53.387847 2026] [http2:warn] [pid 230252:tid 230435] [client 57.141.18.98:20822] h2_stream(230252-401-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:53.845919 2026] [security2:error] [pid 230252:tid 230385] [client 20.226.60.151:60171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/kq1.php"] [unique_id "al9IfU0Dwhk5-Z44XrpGTgAAApo"]
[Tue Jul 21 07:22:53.863665 2026] [security2:error] [pid 229246:tid 229374] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IfSBMYeh5YLVG45xqoAACjn8"]
[Tue Jul 21 07:22:53.863808 2026] [security2:error] [pid 229246:tid 229498] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IfSBMYeh5YLVG45xqoAACjn8"]
[Tue Jul 21 07:22:54.198284 2026] [security2:error] [pid 229246:tid 229501] [client 20.151.10.161:26383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/dejavu.php"] [unique_id "al9IfiBMYeh5YLVG45xqowAAApE"]
[Tue Jul 21 07:22:54.472057 2026] [security2:error] [pid 230252:tid 230483] [client 74.249.245.134:43210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/albin.php"] [unique_id "al9Ifk0Dwhk5-Z44XrpGVgAAAvw"]
[Tue Jul 21 07:22:54.731733 2026] [security2:error] [pid 229246:tid 229364] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IfiBMYeh5YLVG45xqrgACiHU"]
[Tue Jul 21 07:22:54.731878 2026] [security2:error] [pid 229246:tid 229492] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IfiBMYeh5YLVG45xqrgACiHU"]
[Tue Jul 21 07:22:54.775063 2026] [proxy:error] [pid 230252:tid 230400] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:54.775151 2026] [proxy_http:error] [pid 230252:tid 230400] [client 20.104.96.117:4190] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:54.775742 2026] [proxy:error] [pid 230252:tid 230400] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:54.775769 2026] [proxy_http:error] [pid 230252:tid 230400] [client 20.104.96.117:4190] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:54.867386 2026] [http2:warn] [pid 230252:tid 230401] [client 57.141.18.121:44834] h2_stream(230252-405-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:54.989522 2026] [security2:error] [pid 229246:tid 229287] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IfiBMYeh5YLVG45xqswACKig"]
[Tue Jul 21 07:22:54.989708 2026] [security2:error] [pid 229246:tid 229398] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IfiBMYeh5YLVG45xqswACKig"]
[Tue Jul 21 07:22:55.355344 2026] [security2:error] [pid 230252:tid 230489] [client 213.152.162.104:43166] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Ifk0Dwhk5-Z44XrpGVAAAAwI"]
[Tue Jul 21 07:22:55.355466 2026] [security2:error] [pid 230252:tid 230489] [client 213.152.162.104:43166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Ifk0Dwhk5-Z44XrpGVAAAAwI"]
[Tue Jul 21 07:22:55.409698 2026] [security2:error] [pid 229246:tid 229447] [client 103.174.34.15:51186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IfyBMYeh5YLVG45xqtwAAAls"]
[Tue Jul 21 07:22:55.409881 2026] [security2:error] [pid 229246:tid 229447] [client 103.174.34.15:51186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IfyBMYeh5YLVG45xqtwAAAls"]
[Tue Jul 21 07:22:55.523176 2026] [security2:error] [pid 229246:tid 229402] [client 20.220.225.223:46107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/track.php"] [unique_id "al9IfyBMYeh5YLVG45xqugAAAi4"]
[Tue Jul 21 07:22:55.530688 2026] [security2:error] [pid 230252:tid 230480] [client 20.226.60.151:60162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9If00Dwhk5-Z44XrpGWwAAAvk"]
[Tue Jul 21 07:22:55.537276 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:49124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9If00Dwhk5-Z44XrpGXAAAAwY"]
[Tue Jul 21 07:22:55.713621 2026] [security2:error] [pid 230252:tid 230481] [client 82.102.28.107:33530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9If00Dwhk5-Z44XrpGXQAAAvo"]
[Tue Jul 21 07:22:55.713740 2026] [security2:error] [pid 230252:tid 230481] [client 82.102.28.107:33530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9If00Dwhk5-Z44XrpGXQAAAvo"]
[Tue Jul 21 07:22:55.793387 2026] [security2:error] [pid 230252:tid 230394] [client 109.248.148.246:46840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9If00Dwhk5-Z44XrpGXgAAAqM"]
[Tue Jul 21 07:22:55.793494 2026] [security2:error] [pid 230252:tid 230394] [client 109.248.148.246:46840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9If00Dwhk5-Z44XrpGXgAAAqM"]
[Tue Jul 21 07:22:56.091846 2026] [security2:error] [pid 230252:tid 230487] [client 20.151.10.161:26546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/aaf.php"] [unique_id "al9IgE0Dwhk5-Z44XrpGYAAAAwA"]
[Tue Jul 21 07:22:56.140212 2026] [security2:error] [pid 229246:tid 229318] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IgCBMYeh5YLVG45xqxAACXkc"]
[Tue Jul 21 07:22:56.140357 2026] [security2:error] [pid 229246:tid 229450] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IgCBMYeh5YLVG45xqxAACXkc"]
[Tue Jul 21 07:22:56.306803 2026] [security2:error] [pid 230252:tid 230412] [client 62.102.148.164:46154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9IgE0Dwhk5-Z44XrpGZgAAArU"]
[Tue Jul 21 07:22:56.306911 2026] [security2:error] [pid 230252:tid 230412] [client 62.102.148.164:46154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9IgE0Dwhk5-Z44XrpGZgAAArU"]
[Tue Jul 21 07:22:56.389724 2026] [security2:error] [pid 229246:tid 229382] [client 190.92.174.183:46570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IgCBMYeh5YLVG45xqyQAAAho"]
[Tue Jul 21 07:22:56.389840 2026] [security2:error] [pid 229246:tid 229382] [client 190.92.174.183:46570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IgCBMYeh5YLVG45xqyQAAAho"]
[Tue Jul 21 07:22:56.510366 2026] [security2:error] [pid 229246:tid 229408] [client 128.140.106.114:20642] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9IgCBMYeh5YLVG45xqzwAAAjQ"], referer: https://artetoner.com.br
[Tue Jul 21 07:22:56.731167 2026] [http2:warn] [pid 230252:tid 230488] [client 57.141.18.69:33188] h2_stream(230252-409-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:56.766008 2026] [security2:error] [pid 230252:tid 230440] [client 20.151.10.161:26412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/term.php"] [unique_id "al9IgE0Dwhk5-Z44XrpGbQAAAtE"]
[Tue Jul 21 07:22:56.975350 2026] [security2:error] [pid 230252:tid 230368] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IgE0Dwhk5-Z44XrpGcQACmXE"]
[Tue Jul 21 07:22:56.975559 2026] [security2:error] [pid 230252:tid 230384] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IgE0Dwhk5-Z44XrpGcQACmXE"]
[Tue Jul 21 07:22:57.021002 2026] [security2:error] [pid 230252:tid 230388] [client 190.92.174.183:46584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IgU0Dwhk5-Z44XrpGdAAAAp0"]
[Tue Jul 21 07:22:57.021135 2026] [security2:error] [pid 230252:tid 230388] [client 190.92.174.183:46584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IgU0Dwhk5-Z44XrpGdAAAAp0"]
[Tue Jul 21 07:22:57.238071 2026] [security2:error] [pid 230252:tid 230461] [client 175.45.70.82:57354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IgU0Dwhk5-Z44XrpGegAAAuY"]
[Tue Jul 21 07:22:57.238217 2026] [security2:error] [pid 230252:tid 230461] [client 175.45.70.82:57354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IgU0Dwhk5-Z44XrpGegAAAuY"]
[Tue Jul 21 07:22:57.258848 2026] [security2:error] [pid 230252:tid 230511] [client 20.220.225.223:45955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/2352356666.php"] [unique_id "al9IgU0Dwhk5-Z44XrpGfAAAAxg"]
[Tue Jul 21 07:22:57.264228 2026] [security2:error] [pid 229246:tid 229385] [client 20.151.10.161:26517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/ha.php"] [unique_id "al9IgSBMYeh5YLVG45xq1gAAAh0"]
[Tue Jul 21 07:22:57.408023 2026] [proxy:error] [pid 230252:tid 230425] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:57.408098 2026] [proxy_http:error] [pid 230252:tid 230425] [client 20.104.96.117:4184] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:57.408609 2026] [proxy:error] [pid 230252:tid 230425] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:57.408644 2026] [proxy_http:error] [pid 230252:tid 230425] [client 20.104.96.117:4184] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:57.452796 2026] [security2:error] [pid 230252:tid 230405] [client 193.36.225.10:48545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IgU0Dwhk5-Z44XrpGgAAAAq4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:57.489367 2026] [security2:error] [pid 230252:tid 230438] [client 20.226.60.151:60263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/h02ugyh.php"] [unique_id "al9IgU0Dwhk5-Z44XrpGgQAAAs8"]
[Tue Jul 21 07:22:57.531981 2026] [http2:warn] [pid 230252:tid 230424] [client 57.141.18.76:54994] h2_stream(230252-413-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:57.899609 2026] [security2:error] [pid 229246:tid 229479] [client 20.151.10.161:26411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/hur.php"] [unique_id "al9IgSBMYeh5YLVG45xq2wAAAns"]
[Tue Jul 21 07:22:58.118393 2026] [security2:error] [pid 229246:tid 229386] [client 20.151.10.161:49116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9IgiBMYeh5YLVG45xq4QAAAh4"]
[Tue Jul 21 07:22:58.373554 2026] [security2:error] [pid 230252:tid 230442] [client 20.151.10.161:26524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/h02ugyh.php"] [unique_id "al9Igk0Dwhk5-Z44XrpGnAAAAtM"]
[Tue Jul 21 07:22:58.401992 2026] [security2:error] [pid 229246:tid 229413] [client 20.104.96.117:5101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/ccc.php"] [unique_id "al9IgiBMYeh5YLVG45xq5gAAAjk"]
[Tue Jul 21 07:22:58.521074 2026] [security2:error] [pid 230252:tid 230465] [client 20.226.60.151:61090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/flox.php"] [unique_id "al9Igk0Dwhk5-Z44XrpGnQAAAuo"]
[Tue Jul 21 07:22:58.646661 2026] [security2:error] [pid 229246:tid 229448] [client 139.135.44.145:53697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IgiBMYeh5YLVG45xq6gAAAlw"]
[Tue Jul 21 07:22:58.646793 2026] [security2:error] [pid 229246:tid 229448] [client 139.135.44.145:53697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IgiBMYeh5YLVG45xq6gAAAlw"]
[Tue Jul 21 07:22:59.084766 2026] [security2:error] [pid 229246:tid 229422] [client 20.226.60.151:60181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-temp.php"] [unique_id "al9IgyBMYeh5YLVG45xq8AAAAkI"]
[Tue Jul 21 07:22:59.189662 2026] [http2:warn] [pid 230252:tid 230501] [client 57.141.18.112:64614] h2_stream(230252-423-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:59.388059 2026] [security2:error] [pid 229246:tid 229437] [client 74.249.245.134:50255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/alfa.php"] [unique_id "al9IgyBMYeh5YLVG45xq8wAAAlE"]
[Tue Jul 21 07:22:59.602824 2026] [security2:error] [pid 230252:tid 230473] [client 20.151.10.161:26414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/seiso.php"] [unique_id "al9Ig00Dwhk5-Z44XrpGrAAAAvI"]
[Tue Jul 21 07:22:59.613545 2026] [security2:error] [pid 230252:tid 230346] [remote 192.241.143.148:35606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bestsellerdigital.com.br"] [uri "/wp-login.php"] [unique_id "al9Ig00Dwhk5-Z44XrpGrQAC41s"]
[Tue Jul 21 07:22:59.822565 2026] [security2:error] [pid 230252:tid 230488] [client 20.197.192.193:53170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/mac.php"] [unique_id "al9Ig00Dwhk5-Z44XrpGsQAAAwE"]
[Tue Jul 21 07:22:59.875647 2026] [security2:error] [pid 230252:tid 230476] [client 20.104.96.117:64041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/w.php"] [unique_id "al9Ig00Dwhk5-Z44XrpGswAAAvU"]
[Tue Jul 21 07:22:59.940026 2026] [security2:error] [pid 230252:tid 230493] [client 103.121.156.110:49793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Ig00Dwhk5-Z44XrpGtQAAAwY"]
[Tue Jul 21 07:22:59.940174 2026] [security2:error] [pid 230252:tid 230493] [client 103.121.156.110:49793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Ig00Dwhk5-Z44XrpGtQAAAwY"]
[Tue Jul 21 07:23:00.003163 2026] [core:error] [pid 230252:tid 230333] [remote 87.250.224.96:63146] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:23:00.003193 2026] [core:error] [pid 230252:tid 230333] [remote 87.250.224.96:63146] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:23:00.255730 2026] [security2:error] [pid 230252:tid 230461] [client 45.251.232.145:53588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IhE0Dwhk5-Z44XrpGvgAAAuY"]
[Tue Jul 21 07:23:00.255840 2026] [security2:error] [pid 230252:tid 230461] [client 45.251.232.145:53588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IhE0Dwhk5-Z44XrpGvgAAAuY"]
[Tue Jul 21 07:23:00.463582 2026] [security2:error] [pid 229246:tid 229367] [remote 154.61.75.100:53640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9IhCBMYeh5YLVG45xrAAACQXg"]
[Tue Jul 21 07:23:00.671664 2026] [security2:error] [pid 230252:tid 230465] [client 109.248.148.246:46092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9IhE0Dwhk5-Z44XrpGwAAAAuo"]
[Tue Jul 21 07:23:00.671769 2026] [security2:error] [pid 230252:tid 230465] [client 109.248.148.246:46092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9IhE0Dwhk5-Z44XrpGwAAAAuo"]
[Tue Jul 21 07:23:00.965671 2026] [security2:error] [pid 230252:tid 230440] [client 20.151.10.161:26504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/155.php"] [unique_id "al9IhE0Dwhk5-Z44XrpGxAAAAtE"]
[Tue Jul 21 07:23:01.019864 2026] [security2:error] [pid 230252:tid 230417] [client 20.151.10.161:49140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/x.php"] [unique_id "al9IhU0Dwhk5-Z44XrpGxQAAAro"]
[Tue Jul 21 07:23:01.126018 2026] [security2:error] [pid 229246:tid 229477] [client 20.226.60.151:54475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/popo.php"] [unique_id "al9IhSBMYeh5YLVG45xrBQAAAnk"]
[Tue Jul 21 07:23:01.297667 2026] [security2:error] [pid 229246:tid 229451] [client 20.104.96.117:62962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9IhSBMYeh5YLVG45xrDAAAAl8"]
[Tue Jul 21 07:23:01.360102 2026] [security2:error] [pid 229246:tid 229472] [client 20.226.60.151:60176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9IhSBMYeh5YLVG45xrDwAAAnQ"]
[Tue Jul 21 07:23:01.441709 2026] [security2:error] [pid 229246:tid 229430] [client 20.220.225.223:34292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/dp.php"] [unique_id "al9IhSBMYeh5YLVG45xrEAAAAko"]
[Tue Jul 21 07:23:01.604597 2026] [security2:error] [pid 229246:tid 229466] [client 20.220.225.223:45974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/pn.php"] [unique_id "al9IhSBMYeh5YLVG45xrEgAAAm4"]
[Tue Jul 21 07:23:01.875366 2026] [security2:error] [pid 230252:tid 230407] [client 20.104.96.117:4174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/FWAZ.php"] [unique_id "al9IhU0Dwhk5-Z44XrpG0wAAArA"]
[Tue Jul 21 07:23:02.181910 2026] [security2:error] [pid 230252:tid 230397] [client 172.245.102.44:25671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Ihk0Dwhk5-Z44XrpG1AAAAqY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:02.365359 2026] [security2:error] [pid 230252:tid 230432] [client 74.7.175.185:41220] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.bug.esidiomass.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9Ihk0Dwhk5-Z44XrpG2QACyUU"]
[Tue Jul 21 07:23:02.405345 2026] [security2:error] [pid 230252:tid 230465] [client 20.197.192.193:52266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/samll.php"] [unique_id "al9Ihk0Dwhk5-Z44XrpG2wAAAuo"]
[Tue Jul 21 07:23:02.464618 2026] [security2:error] [pid 230252:tid 230385] [client 103.162.129.114:50763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Ihk0Dwhk5-Z44XrpG3gAAApo"]
[Tue Jul 21 07:23:02.464785 2026] [security2:error] [pid 230252:tid 230385] [client 103.162.129.114:50763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Ihk0Dwhk5-Z44XrpG3gAAApo"]
[Tue Jul 21 07:23:02.497546 2026] [security2:error] [pid 230252:tid 230459] [client 74.7.230.24:33914] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "esidiomass.com.br"] [uri "/robots.txt"] [unique_id "al9Ihk0Dwhk5-Z44XrpG3wAAAuQ"]
[Tue Jul 21 07:23:02.502461 2026] [security2:error] [pid 229246:tid 229401] [client 190.92.174.183:39980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IhiBMYeh5YLVG45xrHQAAAi0"]
[Tue Jul 21 07:23:02.502550 2026] [security2:error] [pid 229246:tid 229401] [client 190.92.174.183:39980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IhiBMYeh5YLVG45xrHQAAAi0"]
[Tue Jul 21 07:23:02.503387 2026] [security2:error] [pid 230252:tid 230429] [client 20.104.96.117:64031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/miru1.php"] [unique_id "al9Ihk0Dwhk5-Z44XrpG4AAAAsY"]
[Tue Jul 21 07:23:02.750204 2026] [security2:error] [pid 230252:tid 230471] [client 14.139.42.196:6558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ihk0Dwhk5-Z44XrpG4gAAAvA"]
[Tue Jul 21 07:23:02.750310 2026] [security2:error] [pid 230252:tid 230471] [client 14.139.42.196:6558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ihk0Dwhk5-Z44XrpG4gAAAvA"]
[Tue Jul 21 07:23:02.753439 2026] [security2:error] [pid 229246:tid 229457] [client 20.197.192.193:53124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/abcd.php"] [unique_id "al9IhiBMYeh5YLVG45xrIgAAAmU"]
[Tue Jul 21 07:23:02.764033 2026] [security2:error] [pid 230252:tid 230403] [client 74.7.230.24:51660] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "esidiomass.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9Ihk0Dwhk5-Z44XrpG5AACrGM"], referer: http://esidiomass.com.br/robots.txt
[Tue Jul 21 07:23:02.764785 2026] [security2:error] [pid 230252:tid 230403] [client 74.7.230.24:51660] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "esidiomass.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9Ihk0Dwhk5-Z44XrpG4wACrG4"]
[Tue Jul 21 07:23:02.805600 2026] [security2:error] [pid 229246:tid 229487] [client 20.151.10.161:49101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/j260624_13.php"] [unique_id "al9IhiBMYeh5YLVG45xrIwAAAoM"]
[Tue Jul 21 07:23:02.819411 2026] [security2:error] [pid 230252:tid 230421] [client 190.92.174.183:46588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "al9Ihk0Dwhk5-Z44XrpG5gAAAr4"]
[Tue Jul 21 07:23:02.819500 2026] [security2:error] [pid 230252:tid 230421] [client 190.92.174.183:46588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "al9Ihk0Dwhk5-Z44XrpG5gAAAr4"]
[Tue Jul 21 07:23:02.912709 2026] [security2:error] [pid 229246:tid 229481] [client 20.151.10.161:26527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/ppp.php"] [unique_id "al9IhiBMYeh5YLVG45xrJwAAAn0"]
[Tue Jul 21 07:23:02.950787 2026] [security2:error] [pid 229246:tid 229437] [client 20.104.96.117:64046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/aa.php"] [unique_id "al9IhiBMYeh5YLVG45xrKAAAAlE"]
[Tue Jul 21 07:23:03.075742 2026] [security2:error] [pid 230252:tid 230507] [client 117.251.86.144:39216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Ih00Dwhk5-Z44XrpG6wAAAxQ"]
[Tue Jul 21 07:23:03.075880 2026] [security2:error] [pid 230252:tid 230507] [client 117.251.86.144:39216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Ih00Dwhk5-Z44XrpG6wAAAxQ"]
[Tue Jul 21 07:23:03.216919 2026] [security2:error] [pid 229246:tid 229452] [client 213.152.162.104:36928] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9IhyBMYeh5YLVG45xrKwAAAmA"]
[Tue Jul 21 07:23:03.217018 2026] [security2:error] [pid 229246:tid 229452] [client 213.152.162.104:36928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9IhyBMYeh5YLVG45xrKwAAAmA"]
[Tue Jul 21 07:23:03.461936 2026] [security2:error] [pid 230252:tid 230472] [client 190.92.174.183:41400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "al9Ih00Dwhk5-Z44XrpG8gAAAvE"]
[Tue Jul 21 07:23:03.462138 2026] [security2:error] [pid 230252:tid 230472] [client 190.92.174.183:41400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "al9Ih00Dwhk5-Z44XrpG8gAAAvE"]
[Tue Jul 21 07:23:03.517770 2026] [security2:error] [pid 229246:tid 229382] [client 20.104.96.117:64021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/122.php"] [unique_id "al9IhyBMYeh5YLVG45xrLwAAAho"]
[Tue Jul 21 07:23:04.048622 2026] [proxy:error] [pid 230252:tid 230457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:04.048696 2026] [proxy_http:error] [pid 230252:tid 230457] [client 20.226.60.151:60205] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:04.049325 2026] [proxy:error] [pid 230252:tid 230457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:04.049352 2026] [proxy_http:error] [pid 230252:tid 230457] [client 20.226.60.151:60205] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:04.203955 2026] [security2:error] [pid 230252:tid 230431] [client 190.92.174.183:41406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/site/xmlrpc.php"] [unique_id "al9IiE0Dwhk5-Z44XrpG-gAAAsg"]
[Tue Jul 21 07:23:04.204103 2026] [security2:error] [pid 230252:tid 230431] [client 190.92.174.183:41406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/site/xmlrpc.php"] [unique_id "al9IiE0Dwhk5-Z44XrpG-gAAAsg"]
[Tue Jul 21 07:23:04.209454 2026] [security2:error] [pid 229246:tid 229274] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IiCBMYeh5YLVG45xrPAACQRs"]
[Tue Jul 21 07:23:04.209665 2026] [security2:error] [pid 229246:tid 229421] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IiCBMYeh5YLVG45xrPAACQRs"]
[Tue Jul 21 07:23:04.256256 2026] [security2:error] [pid 230252:tid 230498] [client 20.104.96.117:5115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/get.php"] [unique_id "al9IiE0Dwhk5-Z44XrpG-wAAAws"]
[Tue Jul 21 07:23:04.412952 2026] [security2:error] [pid 229246:tid 229276] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IiCBMYeh5YLVG45xrQAACkh0"]
[Tue Jul 21 07:23:04.413113 2026] [security2:error] [pid 229246:tid 229502] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IiCBMYeh5YLVG45xrQAACkh0"]
[Tue Jul 21 07:23:04.511301 2026] [security2:error] [pid 229246:tid 229498] [client 20.220.225.223:45967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-wpbak.php"] [unique_id "al9IiCBMYeh5YLVG45xrQwAAAo4"]
[Tue Jul 21 07:23:04.524514 2026] [security2:error] [pid 230252:tid 230436] [client 20.151.10.161:49038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/d62.php"] [unique_id "al9IiE0Dwhk5-Z44XrpG_gAAAs0"]
[Tue Jul 21 07:23:04.926904 2026] [security2:error] [pid 229246:tid 229409] [client 190.92.174.183:41408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/news/xmlrpc.php"] [unique_id "al9IiCBMYeh5YLVG45xrSgAAAjU"]
[Tue Jul 21 07:23:04.927031 2026] [security2:error] [pid 229246:tid 229409] [client 190.92.174.183:41408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/news/xmlrpc.php"] [unique_id "al9IiCBMYeh5YLVG45xrSgAAAjU"]
[Tue Jul 21 07:23:05.014735 2026] [security2:error] [pid 230252:tid 230480] [client 20.104.96.117:62917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/as.php"] [unique_id "al9IiU0Dwhk5-Z44XrpHCAAAAvk"]
[Tue Jul 21 07:23:05.139988 2026] [security2:error] [pid 230252:tid 230493] [client 20.197.192.193:53143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/xyn.php"] [unique_id "al9IiU0Dwhk5-Z44XrpHCgAAAwY"]
[Tue Jul 21 07:23:05.232642 2026] [security2:error] [pid 230252:tid 230339] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IiU0Dwhk5-Z44XrpHDAADDlQ"]
[Tue Jul 21 07:23:05.232824 2026] [security2:error] [pid 230252:tid 230501] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IiU0Dwhk5-Z44XrpHDAADDlQ"]
[Tue Jul 21 07:23:05.376277 2026] [security2:error] [pid 229246:tid 229385] [client 20.220.225.223:45969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/dr.php"] [unique_id "al9IiSBMYeh5YLVG45xrUQAAAh0"]
[Tue Jul 21 07:23:05.523921 2026] [security2:error] [pid 230252:tid 230375] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IiU0Dwhk5-Z44XrpHDgAC93g"]
[Tue Jul 21 07:23:05.524054 2026] [security2:error] [pid 230252:tid 230478] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IiU0Dwhk5-Z44XrpHDgAC93g"]
[Tue Jul 21 07:23:05.647209 2026] [security2:error] [pid 230252:tid 230473] [client 20.151.10.161:49141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/ups.php"] [unique_id "al9IiU0Dwhk5-Z44XrpHDwAAAvI"]
[Tue Jul 21 07:23:05.869479 2026] [security2:error] [pid 230252:tid 230430] [client 190.92.174.183:41410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/web/xmlrpc.php"] [unique_id "al9IiU0Dwhk5-Z44XrpHEgAAAsc"]
[Tue Jul 21 07:23:05.869642 2026] [security2:error] [pid 230252:tid 230430] [client 190.92.174.183:41410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/web/xmlrpc.php"] [unique_id "al9IiU0Dwhk5-Z44XrpHEgAAAsc"]
[Tue Jul 21 07:23:06.299327 2026] [security2:error] [pid 229246:tid 229487] [client 20.104.96.117:62956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/ccou.php"] [unique_id "al9IiiBMYeh5YLVG45xrXQAAAoM"]
[Tue Jul 21 07:23:06.313617 2026] [security2:error] [pid 230252:tid 230472] [client 103.174.34.15:51657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Iik0Dwhk5-Z44XrpHGAAAAvE"]
[Tue Jul 21 07:23:06.313721 2026] [security2:error] [pid 230252:tid 230472] [client 103.174.34.15:51657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Iik0Dwhk5-Z44XrpHGAAAAvE"]
[Tue Jul 21 07:23:06.327034 2026] [security2:error] [pid 230252:tid 230442] [client 109.248.148.246:46096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Iik0Dwhk5-Z44XrpHGQAAAtM"]
[Tue Jul 21 07:23:06.327107 2026] [security2:error] [pid 230252:tid 230442] [client 109.248.148.246:46096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Iik0Dwhk5-Z44XrpHGQAAAtM"]
[Tue Jul 21 07:23:06.436470 2026] [core:alert] [pid 230252:tid 230498] [client 57.141.18.15:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:23:06.471716 2026] [security2:error] [pid 230252:tid 230422] [client 20.220.225.223:46123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/2x.php"] [unique_id "al9Iik0Dwhk5-Z44XrpHHAAAAr8"]
[Tue Jul 21 07:23:06.586151 2026] [security2:error] [pid 230252:tid 230385] [client 190.92.174.183:41414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/main/xmlrpc.php"] [unique_id "al9Iik0Dwhk5-Z44XrpHIAAAApo"]
[Tue Jul 21 07:23:06.586250 2026] [security2:error] [pid 230252:tid 230385] [client 190.92.174.183:41414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/main/xmlrpc.php"] [unique_id "al9Iik0Dwhk5-Z44XrpHIAAAApo"]
[Tue Jul 21 07:23:06.773524 2026] [security2:error] [pid 229246:tid 229393] [client 20.226.60.151:56907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9IiiBMYeh5YLVG45xrYwAAAiU"]
[Tue Jul 21 07:23:06.834686 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:49054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/k.php"] [unique_id "al9IiiBMYeh5YLVG45xrZAAAAlo"]
[Tue Jul 21 07:23:06.947188 2026] [security2:error] [pid 230252:tid 230353] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Iik0Dwhk5-Z44XrpHIwACsWI"]
[Tue Jul 21 07:23:06.947342 2026] [security2:error] [pid 230252:tid 230408] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Iik0Dwhk5-Z44XrpHIwACsWI"]
[Tue Jul 21 07:23:07.154304 2026] [security2:error] [pid 229246:tid 229458] [client 204.12.208.18:56720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/wp-includes/addb8871/index.php"] [unique_id "al9IiyBMYeh5YLVG45xraQAAAmY"], referer: https://rkcentroautomotivoo.com.br/wp-includes/addb8871/index.php
[Tue Jul 21 07:23:07.181493 2026] [security2:error] [pid 230252:tid 230489] [client 213.152.162.104:51196] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHKAAAAwI"]
[Tue Jul 21 07:23:07.181601 2026] [security2:error] [pid 230252:tid 230489] [client 213.152.162.104:51196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHKAAAAwI"]
[Tue Jul 21 07:23:07.229239 2026] [security2:error] [pid 230252:tid 230507] [client 190.92.174.183:41416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/cms/xmlrpc.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHKgAAAxQ"]
[Tue Jul 21 07:23:07.229371 2026] [security2:error] [pid 230252:tid 230507] [client 190.92.174.183:41416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/cms/xmlrpc.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHKgAAAxQ"]
[Tue Jul 21 07:23:07.278977 2026] [security2:error] [pid 230252:tid 230504] [client 20.220.225.223:46123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/kq1.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHKwAAAxE"]
[Tue Jul 21 07:23:07.558874 2026] [security2:error] [pid 230252:tid 230292] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHMAACyCY"]
[Tue Jul 21 07:23:07.559056 2026] [security2:error] [pid 230252:tid 230431] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHMAACyCY"]
[Tue Jul 21 07:23:07.659087 2026] [autoindex:error] [pid 230252:tid 230314] [remote 74.7.243.194:50920] AH01276: Cannot serve directory /home1/imperd48/ussabinooffers.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:23:07.677942 2026] [security2:error] [pid 230252:tid 230481] [client 74.7.241.149:59064] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ussabinooffers.com.imperdivelbestpromotionofthedaytodayonly.com"] [uri "/cgi-sys/404.html"] [unique_id "al9Ii00Dwhk5-Z44XrpHMwAC-iM"]
[Tue Jul 21 07:23:07.691596 2026] [security2:error] [pid 230252:tid 230474] [client 204.12.208.18:56733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/wp-includes/addb8871/index.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHNAAAAvM"], referer: https://rkcentroautomotivoo.com.br/wp-includes/addb8871/index.php
[Tue Jul 21 07:23:07.732557 2026] [security2:error] [pid 230252:tid 230461] [client 20.226.60.151:56833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHNQAAAuY"]
[Tue Jul 21 07:23:07.874943 2026] [security2:error] [pid 230252:tid 230467] [client 190.92.174.183:41424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/wpsite/xmlrpc.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHNgAAAuw"]
[Tue Jul 21 07:23:07.875076 2026] [security2:error] [pid 230252:tid 230467] [client 190.92.174.183:41424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/wpsite/xmlrpc.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHNgAAAuw"]
[Tue Jul 21 07:23:07.930247 2026] [security2:error] [pid 230252:tid 230503] [client 20.197.192.193:52277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/byp8.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHNwAAAxA"]
[Tue Jul 21 07:23:07.935456 2026] [security2:error] [pid 230252:tid 230420] [client 109.248.148.246:56324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHOQAAAr0"]
[Tue Jul 21 07:23:07.935536 2026] [security2:error] [pid 230252:tid 230420] [client 109.248.148.246:56324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHOQAAAr0"]
[Tue Jul 21 07:23:08.051467 2026] [security2:error] [pid 229246:tid 229416] [client 175.45.70.82:57861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IjCBMYeh5YLVG45xrcwAAAjw"]
[Tue Jul 21 07:23:08.051576 2026] [security2:error] [pid 229246:tid 229416] [client 175.45.70.82:57861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IjCBMYeh5YLVG45xrcwAAAjw"]
[Tue Jul 21 07:23:08.183411 2026] [security2:error] [pid 230252:tid 230408] [client 20.197.192.193:53150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/user.php"] [unique_id "al9IjE0Dwhk5-Z44XrpHPQAAArE"]
[Tue Jul 21 07:23:08.222994 2026] [security2:error] [pid 230252:tid 230502] [client 136.144.33.98:35859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IjE0Dwhk5-Z44XrpHPgAAAw8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:08.223725 2026] [security2:error] [pid 230252:tid 230413] [client 213.152.162.104:37148] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9IjE0Dwhk5-Z44XrpHQAAAArY"]
[Tue Jul 21 07:23:08.223801 2026] [security2:error] [pid 230252:tid 230413] [client 213.152.162.104:37148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9IjE0Dwhk5-Z44XrpHQAAAArY"]
[Tue Jul 21 07:23:08.243472 2026] [security2:error] [pid 229246:tid 229387] [client 204.12.208.18:56742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/wp-includes/addb8871/index.php"] [unique_id "al9IjCBMYeh5YLVG45xrdgAAAh8"], referer: https://rkcentroautomotivoo.com.br/wp-includes/addb8871/index.php
[Tue Jul 21 07:23:08.330066 2026] [security2:error] [pid 229246:tid 229383] [client 20.151.10.161:49031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/k2.php"] [unique_id "al9IjCBMYeh5YLVG45xreAAAAhs"]
[Tue Jul 21 07:23:08.509561 2026] [security2:error] [pid 229246:tid 229480] [client 190.92.174.183:41426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/old/xmlrpc.php"] [unique_id "al9IjCBMYeh5YLVG45xrewAAAnw"]
[Tue Jul 21 07:23:08.509680 2026] [security2:error] [pid 229246:tid 229480] [client 190.92.174.183:41426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/old/xmlrpc.php"] [unique_id "al9IjCBMYeh5YLVG45xrewAAAnw"]
[Tue Jul 21 07:23:08.684703 2026] [security2:error] [pid 229246:tid 229406] [client 20.226.60.151:54551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/yas.php"] [unique_id "al9IjCBMYeh5YLVG45xrfgAAAjI"]
[Tue Jul 21 07:23:08.760093 2026] [security2:error] [pid 229246:tid 229451] [client 74.249.245.134:42800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/autoload_classmap.php"] [unique_id "al9IjCBMYeh5YLVG45xrgAAAAl8"]
[Tue Jul 21 07:23:08.837834 2026] [security2:error] [pid 230252:tid 230427] [client 20.104.96.117:5112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/w3lls.php"] [unique_id "al9IjE0Dwhk5-Z44XrpHRAAAAsQ"]
[Tue Jul 21 07:23:08.893697 2026] [security2:error] [pid 230252:tid 230473] [client 20.226.60.151:56865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/media.php"] [unique_id "al9IjE0Dwhk5-Z44XrpHRQAAAvI"]
[Tue Jul 21 07:23:08.980337 2026] [security2:error] [pid 229246:tid 229484] [client 197.11.70.196:46042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.70.11.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grupotecc.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IiyBMYeh5YLVG45xrcAAAAoA"]
[Tue Jul 21 07:23:08.980493 2026] [security2:error] [pid 229246:tid 229484] [client 197.11.70.196:46042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grupotecc.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IiyBMYeh5YLVG45xrcAAAAoA"]
[Tue Jul 21 07:23:08.993291 2026] [security2:error] [pid 230252:tid 230511] [client 20.226.60.151:60192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9IjE0Dwhk5-Z44XrpHRgAAAxg"]
[Tue Jul 21 07:23:09.139378 2026] [security2:error] [pid 230252:tid 230431] [client 190.92.174.183:41434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/new/xmlrpc.php"] [unique_id "al9IjU0Dwhk5-Z44XrpHSQAAAsg"]
[Tue Jul 21 07:23:09.139492 2026] [security2:error] [pid 230252:tid 230431] [client 190.92.174.183:41434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/new/xmlrpc.php"] [unique_id "al9IjU0Dwhk5-Z44XrpHSQAAAsg"]
[Tue Jul 21 07:23:09.236532 2026] [security2:error] [pid 229246:tid 229430] [client 74.7.241.175:35124] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.letsgotaxi.com.br.hostag.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9IjSBMYeh5YLVG45xrhQACSi4"]
[Tue Jul 21 07:23:09.479224 2026] [security2:error] [pid 229246:tid 229418] [client 20.220.225.223:46091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/zzz.php"] [unique_id "al9IjSBMYeh5YLVG45xriQAAAj4"]
[Tue Jul 21 07:23:09.552344 2026] [security2:error] [pid 230252:tid 230474] [client 74.7.228.54:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "unigein.com.br"] [uri "/index.php"] [unique_id "al9IjU0Dwhk5-Z44XrpHTgAAAvM"]
[Tue Jul 21 07:23:09.552699 2026] [security2:error] [pid 230252:tid 230428] [client 74.7.228.54:40052] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "unigein.com.br"] [uri "/robots.txt"] [unique_id "al9IjU0Dwhk5-Z44XrpHTQAAAsU"]
[Tue Jul 21 07:23:09.747691 2026] [security2:error] [pid 230252:tid 230488] [client 139.135.44.145:54552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IjU0Dwhk5-Z44XrpHTwAAAwE"]
[Tue Jul 21 07:23:09.747823 2026] [security2:error] [pid 230252:tid 230488] [client 139.135.44.145:54552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IjU0Dwhk5-Z44XrpHTwAAAwE"]
[Tue Jul 21 07:23:09.902079 2026] [security2:error] [pid 229246:tid 229487] [client 20.151.10.161:49098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/k3.php"] [unique_id "al9IjSBMYeh5YLVG45xrkgAAAoM"]
[Tue Jul 21 07:23:10.072106 2026] [security2:error] [pid 229246:tid 229402] [client 20.226.60.151:56847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/images.php"] [unique_id "al9IjiBMYeh5YLVG45xrlgAAAi4"]
[Tue Jul 21 07:23:10.158501 2026] [security2:error] [pid 230252:tid 230471] [client 109.248.148.246:52622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Ijk0Dwhk5-Z44XrpHVQAAAvA"]
[Tue Jul 21 07:23:10.158621 2026] [security2:error] [pid 230252:tid 230471] [client 109.248.148.246:52622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Ijk0Dwhk5-Z44XrpHVQAAAvA"]
[Tue Jul 21 07:23:10.237385 2026] [security2:error] [pid 229246:tid 229500] [client 20.151.10.161:26418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/201.php"] [unique_id "al9IjiBMYeh5YLVG45xrmQAAApA"]
[Tue Jul 21 07:23:10.630066 2026] [security2:error] [pid 230252:tid 230416] [client 103.121.156.110:50123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Ijk0Dwhk5-Z44XrpHVgAAArk"]
[Tue Jul 21 07:23:10.630225 2026] [security2:error] [pid 230252:tid 230416] [client 103.121.156.110:50123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Ijk0Dwhk5-Z44XrpHVgAAArk"]
[Tue Jul 21 07:23:10.665415 2026] [security2:error] [pid 230252:tid 230389] [client 74.7.241.166:60740] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "clinicaqualis.com.br"] [uri "/index.php"] [unique_id "al9IjU0Dwhk5-Z44XrpHUwACnnI"]
[Tue Jul 21 07:23:10.803610 2026] [security2:error] [pid 229246:tid 229481] [client 45.251.232.145:54115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IjiBMYeh5YLVG45xrpAAAAn0"]
[Tue Jul 21 07:23:10.803715 2026] [security2:error] [pid 229246:tid 229481] [client 45.251.232.145:54115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IjiBMYeh5YLVG45xrpAAAAn0"]
[Tue Jul 21 07:23:11.117388 2026] [security2:error] [pid 230252:tid 230455] [client 20.226.60.151:60204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/jj.php"] [unique_id "al9Ij00Dwhk5-Z44XrpHWwAAAuA"]
[Tue Jul 21 07:23:11.469641 2026] [security2:error] [pid 230252:tid 230452] [client 20.226.60.151:56853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/gecko.php"] [unique_id "al9Ij00Dwhk5-Z44XrpHXQAAAt0"]
[Tue Jul 21 07:23:11.485896 2026] [security2:error] [pid 230252:tid 230499] [client 190.92.174.183:50330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/wp-login.php"] [unique_id "al9Ij00Dwhk5-Z44XrpHXgAAAww"], referer: https://northcomm.com.br/wp-admin/
[Tue Jul 21 07:23:11.849017 2026] [security2:error] [pid 230252:tid 230487] [client 190.92.174.183:41448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/wp-login.php"] [unique_id "al9Ij00Dwhk5-Z44XrpHZAAAAwA"]
[Tue Jul 21 07:23:12.340904 2026] [security2:error] [pid 229246:tid 229451] [client 20.220.225.223:34203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/bootstrap.php"] [unique_id "al9IkCBMYeh5YLVG45xrtQAAAl8"]
[Tue Jul 21 07:23:12.362012 2026] [security2:error] [pid 229246:tid 229465] [client 20.226.60.151:50688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9IkCBMYeh5YLVG45xrtgAAAm0"]
[Tue Jul 21 07:23:12.418528 2026] [security2:error] [pid 229246:tid 229433] [client 20.104.96.117:62920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/test1.php"] [unique_id "al9IkCBMYeh5YLVG45xrtwAAAk0"]
[Tue Jul 21 07:23:12.465549 2026] [security2:error] [pid 229246:tid 229428] [client 74.249.245.134:61978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/av.php"] [unique_id "al9IkCBMYeh5YLVG45xruQAAAkg"]
[Tue Jul 21 07:23:12.742111 2026] [security2:error] [pid 230252:tid 230432] [client 20.226.60.151:60233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/txets.php"] [unique_id "al9IkE0Dwhk5-Z44XrpHawAAAsk"]
[Tue Jul 21 07:23:12.807202 2026] [security2:error] [pid 230252:tid 230444] [client 20.226.60.151:56918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/82.php"] [unique_id "al9IkE0Dwhk5-Z44XrpHbwAAAtU"]
[Tue Jul 21 07:23:12.936342 2026] [security2:error] [pid 230252:tid 230389] [client 20.104.96.117:64003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/database.php"] [unique_id "al9IkE0Dwhk5-Z44XrpHcgAAAp4"]
[Tue Jul 21 07:23:13.299287 2026] [security2:error] [pid 229246:tid 229447] [client 20.220.225.223:45412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wicked.php"] [unique_id "al9IkSBMYeh5YLVG45xrygAAAls"]
[Tue Jul 21 07:23:13.312216 2026] [security2:error] [pid 229246:tid 229391] [client 103.162.129.114:51235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IkSBMYeh5YLVG45xrywAAAiM"]
[Tue Jul 21 07:23:13.312311 2026] [security2:error] [pid 229246:tid 229391] [client 103.162.129.114:51235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IkSBMYeh5YLVG45xrywAAAiM"]
[Tue Jul 21 07:23:13.393745 2026] [security2:error] [pid 229246:tid 229490] [client 20.197.192.193:52283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/ops.php"] [unique_id "al9IkSBMYeh5YLVG45xrzQAAAoY"]
[Tue Jul 21 07:23:13.675612 2026] [security2:error] [pid 229246:tid 229437] [client 20.226.60.151:60249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/dex.php"] [unique_id "al9IkSBMYeh5YLVG45xr0gAAAlE"]
[Tue Jul 21 07:23:13.692807 2026] [security2:error] [pid 229246:tid 229393] [client 20.226.60.151:56908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/admin.php"] [unique_id "al9IkSBMYeh5YLVG45xr1AAAAiU"]
[Tue Jul 21 07:23:13.751076 2026] [security2:error] [pid 229246:tid 229473] [client 20.226.60.151:61104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/file61.php"] [unique_id "al9IkSBMYeh5YLVG45xr1QAAAnU"]
[Tue Jul 21 07:23:13.828720 2026] [security2:error] [pid 230252:tid 230418] [client 14.139.42.196:2616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IkU0Dwhk5-Z44XrpHegAAArs"]
[Tue Jul 21 07:23:13.828916 2026] [security2:error] [pid 230252:tid 230418] [client 14.139.42.196:2616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IkU0Dwhk5-Z44XrpHegAAArs"]
[Tue Jul 21 07:23:13.838842 2026] [security2:error] [pid 230252:tid 230501] [client 117.251.86.144:36488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9IkU0Dwhk5-Z44XrpHewAAAw4"]
[Tue Jul 21 07:23:13.838949 2026] [security2:error] [pid 230252:tid 230501] [client 117.251.86.144:36488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9IkU0Dwhk5-Z44XrpHewAAAw4"]
[Tue Jul 21 07:23:14.078502 2026] [security2:error] [pid 229246:tid 229396] [client 20.151.10.161:48599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/k4.php"] [unique_id "al9IkiBMYeh5YLVG45xr3gAAAig"]
[Tue Jul 21 07:23:14.270917 2026] [security2:error] [pid 230252:tid 230497] [client 20.226.60.151:60218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/xpwer1.php"] [unique_id "al9Ikk0Dwhk5-Z44XrpHfAAAAwo"]
[Tue Jul 21 07:23:14.320497 2026] [security2:error] [pid 229246:tid 229502] [client 172.245.102.41:37253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IkSBMYeh5YLVG45xrxAAAApI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:14.440795 2026] [security2:error] [pid 229246:tid 229387] [client 74.249.245.134:56027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/gg.php"] [unique_id "al9IkiBMYeh5YLVG45xr5gAAAh8"]
[Tue Jul 21 07:23:14.623338 2026] [security2:error] [pid 229246:tid 229408] [client 109.248.148.246:52636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9IkiBMYeh5YLVG45xr6QAAAjQ"]
[Tue Jul 21 07:23:14.623463 2026] [security2:error] [pid 229246:tid 229408] [client 109.248.148.246:52636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9IkiBMYeh5YLVG45xr6QAAAjQ"]
[Tue Jul 21 07:23:14.694568 2026] [security2:error] [pid 230252:tid 230464] [client 20.226.60.151:56916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/adminner.php"] [unique_id "al9Ikk0Dwhk5-Z44XrpHfwAAAuk"]
[Tue Jul 21 07:23:14.901319 2026] [security2:error] [pid 229246:tid 229433] [client 20.104.96.117:62930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/file.php"] [unique_id "al9IkiBMYeh5YLVG45xr8AAAAk0"]
[Tue Jul 21 07:23:14.927915 2026] [security2:error] [pid 229246:tid 229291] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IkiBMYeh5YLVG45xr8QACfCw"]
[Tue Jul 21 07:23:14.928121 2026] [security2:error] [pid 229246:tid 229480] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IkiBMYeh5YLVG45xr8QACfCw"]
[Tue Jul 21 07:23:15.062244 2026] [security2:error] [pid 229246:tid 229362] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IkyBMYeh5YLVG45xr9wACMnM"]
[Tue Jul 21 07:23:15.062426 2026] [security2:error] [pid 229246:tid 229406] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IkyBMYeh5YLVG45xr9wACMnM"]
[Tue Jul 21 07:23:15.127628 2026] [security2:error] [pid 229246:tid 229260] [remote 216.73.216.115:46829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swingcuiaba.com.br"] [uri "/goods.php"] [unique_id "al9IkyBMYeh5YLVG45xr-AACNg0"]
[Tue Jul 21 07:23:15.176452 2026] [security2:error] [pid 229246:tid 229426] [client 141.11.107.74:51834] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "whm.arcoll.com.br"] [uri "/___proxy_subdomain_whm/"] [unique_id "al9IkyBMYeh5YLVG45xr-QAAAkY"]
[Tue Jul 21 07:23:15.197053 2026] [security2:error] [pid 229246:tid 229398] [client 141.11.107.74:51840] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ftp.arcoll.com.br"] [uri "/"] [unique_id "al9IkyBMYeh5YLVG45xr_AAAAio"]
[Tue Jul 21 07:23:15.240909 2026] [security2:error] [pid 229246:tid 229472] [client 141.11.107.74:51859] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcontacts.arcoll.com.br"] [uri "/___proxy_subdomain_cpcontacts/"] [unique_id "al9IkyBMYeh5YLVG45xr_QAAAnQ"]
[Tue Jul 21 07:23:15.248146 2026] [security2:error] [pid 229246:tid 229479] [client 141.11.107.74:51868] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "arcoll.com.br"] [uri "/"] [unique_id "al9IkyBMYeh5YLVG45xr_gAAAns"]
[Tue Jul 21 07:23:15.261239 2026] [security2:error] [pid 230252:tid 230474] [client 141.11.107.74:51882] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.arcoll.com.br"] [uri "/___proxy_subdomain_webmail/"] [unique_id "al9Ik00Dwhk5-Z44XrpHggAAAvM"]
[Tue Jul 21 07:23:15.261239 2026] [security2:error] [pid 229246:tid 229399] [client 141.11.107.74:51883] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.arcoll.com.br"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "al9IkyBMYeh5YLVG45xr_wAAAis"]
[Tue Jul 21 07:23:15.261239 2026] [security2:error] [pid 229246:tid 229461] [client 141.11.107.74:51878] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.arcoll.com.br"] [uri "/"] [unique_id "al9IkyBMYeh5YLVG45xsAAAAAmk"]
[Tue Jul 21 07:23:15.262992 2026] [security2:error] [pid 230252:tid 230461] [client 141.11.107.74:51877] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.arcoll.com.br"] [uri "/___proxy_subdomain_webdisk/"] [unique_id "al9Ik00Dwhk5-Z44XrpHgwAAAuY"]
[Tue Jul 21 07:23:15.384881 2026] [security2:error] [pid 230252:tid 230488] [client 20.226.60.151:56955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/admin.php"] [unique_id "al9Ik00Dwhk5-Z44XrpHhQAAAwE"]
[Tue Jul 21 07:23:15.446770 2026] [security2:error] [pid 230252:tid 230403] [client 141.11.107.74:51951] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.arcoll.com.br"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "al9Ik00Dwhk5-Z44XrpHiAAAAqw"]
[Tue Jul 21 07:23:15.752889 2026] [security2:error] [pid 229246:tid 229332] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IkyBMYeh5YLVG45xsCAAChlU"]
[Tue Jul 21 07:23:15.753024 2026] [security2:error] [pid 229246:tid 229490] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IkyBMYeh5YLVG45xsCAAChlU"]
[Tue Jul 21 07:23:15.903177 2026] [security2:error] [pid 230252:tid 230408] [client 20.226.60.151:60178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/flox.php"] [unique_id "al9Ik00Dwhk5-Z44XrpHjQAAArE"]
[Tue Jul 21 07:23:15.995771 2026] [security2:error] [pid 230252:tid 230276] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ik00Dwhk5-Z44XrpHjwAC1RY"]
[Tue Jul 21 07:23:15.995927 2026] [security2:error] [pid 230252:tid 230444] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ik00Dwhk5-Z44XrpHjwAC1RY"]
[Tue Jul 21 07:23:16.274153 2026] [security2:error] [pid 230252:tid 230429] [client 20.151.10.161:26419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/ops.php"] [unique_id "al9IlE0Dwhk5-Z44XrpHlAAAAsY"]
[Tue Jul 21 07:23:16.761011 2026] [security2:error] [pid 229246:tid 229407] [client 20.197.192.193:53155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/term.php"] [unique_id "al9IlCBMYeh5YLVG45xsFQAAAjM"]
[Tue Jul 21 07:23:16.843009 2026] [security2:error] [pid 229246:tid 229495] [client 20.226.60.151:56896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/k.php"] [unique_id "al9IlCBMYeh5YLVG45xsFwAAAos"]
[Tue Jul 21 07:23:17.023709 2026] [security2:error] [pid 230252:tid 230405] [client 74.249.245.134:59798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/sql.php"] [unique_id "al9IlU0Dwhk5-Z44XrpHmQAAAq4"]
[Tue Jul 21 07:23:17.101209 2026] [security2:error] [pid 230252:tid 230499] [client 103.174.34.15:52132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IlU0Dwhk5-Z44XrpHmgAAAww"]
[Tue Jul 21 07:23:17.107536 2026] [security2:error] [pid 230252:tid 230499] [client 103.174.34.15:52132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IlU0Dwhk5-Z44XrpHmgAAAww"]
[Tue Jul 21 07:23:17.109489 2026] [security2:error] [pid 230252:tid 230447] [client 20.104.96.117:64020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/file.php"] [unique_id "al9IlU0Dwhk5-Z44XrpHmwAAAtg"]
[Tue Jul 21 07:23:17.268847 2026] [security2:error] [pid 229246:tid 229497] [client 20.226.60.151:50812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/popo.php"] [unique_id "al9IlSBMYeh5YLVG45xsGwAAAo0"]
[Tue Jul 21 07:23:17.756487 2026] [security2:error] [pid 230252:tid 230352] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IlU0Dwhk5-Z44XrpHogACqWE"]
[Tue Jul 21 07:23:17.756690 2026] [security2:error] [pid 230252:tid 230400] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IlU0Dwhk5-Z44XrpHogACqWE"]
[Tue Jul 21 07:23:18.077098 2026] [security2:error] [pid 229246:tid 229369] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IliBMYeh5YLVG45xsKAACG3o"]
[Tue Jul 21 07:23:18.077245 2026] [security2:error] [pid 229246:tid 229383] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IliBMYeh5YLVG45xsKAACG3o"]
[Tue Jul 21 07:23:18.321519 2026] [security2:error] [pid 230252:tid 230478] [client 193.36.225.65:43377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Ilk0Dwhk5-Z44XrpHpAAAAvc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:18.365891 2026] [security2:error] [pid 230252:tid 230487] [client 109.248.148.246:36026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Ilk0Dwhk5-Z44XrpHpQAAAwA"]
[Tue Jul 21 07:23:18.365989 2026] [security2:error] [pid 230252:tid 230487] [client 109.248.148.246:36026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Ilk0Dwhk5-Z44XrpHpQAAAwA"]
[Tue Jul 21 07:23:18.416002 2026] [security2:error] [pid 229246:tid 229465] [client 20.226.60.151:56848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/blurbs.php"] [unique_id "al9IliBMYeh5YLVG45xsLQAAAm0"]
[Tue Jul 21 07:23:18.836594 2026] [security2:error] [pid 230252:tid 230481] [client 175.45.70.82:58362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ilk0Dwhk5-Z44XrpHqAAAAvo"]
[Tue Jul 21 07:23:18.836702 2026] [security2:error] [pid 230252:tid 230481] [client 175.45.70.82:58362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ilk0Dwhk5-Z44XrpHqAAAAvo"]
[Tue Jul 21 07:23:19.106611 2026] [security2:error] [pid 229246:tid 229489] [client 20.104.96.117:64009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/777.php"] [unique_id "al9IlyBMYeh5YLVG45xsNgAAAoU"]
[Tue Jul 21 07:23:19.456265 2026] [security2:error] [pid 230252:tid 230420] [client 109.248.148.246:36042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9Il00Dwhk5-Z44XrpHqgAAAr0"]
[Tue Jul 21 07:23:19.456361 2026] [security2:error] [pid 230252:tid 230420] [client 109.248.148.246:36042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9Il00Dwhk5-Z44XrpHqgAAAr0"]
[Tue Jul 21 07:23:19.688235 2026] [security2:error] [pid 230252:tid 230439] [client 20.104.96.117:4167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/ssixta.php"] [unique_id "al9Il00Dwhk5-Z44XrpHrwAAAtA"]
[Tue Jul 21 07:23:19.912084 2026] [security2:error] [pid 229246:tid 229468] [client 20.226.60.151:60188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/yas.php"] [unique_id "al9IlyBMYeh5YLVG45xsgAAAAnA"]
[Tue Jul 21 07:23:19.945604 2026] [security2:error] [pid 229246:tid 229460] [client 20.226.60.151:54579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/water.php"] [unique_id "al9IlyBMYeh5YLVG45xshQAAAmg"]
[Tue Jul 21 07:23:20.114725 2026] [security2:error] [pid 230252:tid 230441] [client 20.226.60.151:56951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/bajah.php"] [unique_id "al9ImE0Dwhk5-Z44XrpHtgAAAtI"]
[Tue Jul 21 07:23:20.309457 2026] [security2:error] [pid 229246:tid 229389] [client 20.151.10.161:26452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/ingfo.php"] [unique_id "al9ImCBMYeh5YLVG45xsiwAAAiE"]
[Tue Jul 21 07:23:20.327083 2026] [security2:error] [pid 229246:tid 229405] [client 139.135.44.145:53420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ImCBMYeh5YLVG45xsjAAAAjE"]
[Tue Jul 21 07:23:20.327199 2026] [security2:error] [pid 229246:tid 229405] [client 139.135.44.145:53420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ImCBMYeh5YLVG45xsjAAAAjE"]
[Tue Jul 21 07:23:20.455871 2026] [security2:error] [pid 229246:tid 229433] [client 20.104.96.117:62915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/1c.php"] [unique_id "al9ImCBMYeh5YLVG45xsjgAAAk0"]
[Tue Jul 21 07:23:20.842989 2026] [security2:error] [pid 230252:tid 230430] [client 20.104.96.117:64027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/test2.php"] [unique_id "al9ImE0Dwhk5-Z44XrpHuwAAAsc"]
[Tue Jul 21 07:23:20.940562 2026] [security2:error] [pid 229246:tid 229470] [client 109.248.148.246:54774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ImCBMYeh5YLVG45xskwAAAnI"]
[Tue Jul 21 07:23:20.940669 2026] [security2:error] [pid 229246:tid 229470] [client 109.248.148.246:54774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ImCBMYeh5YLVG45xskwAAAnI"]
[Tue Jul 21 07:23:21.029596 2026] [security2:error] [pid 230252:tid 230260] [remote 154.61.75.100:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/wp-login.php"] [unique_id "al9ImU0Dwhk5-Z44XrpHvwAC4gY"]
[Tue Jul 21 07:23:21.032705 2026] [security2:error] [pid 229246:tid 229489] [client 62.102.148.164:33234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9ImSBMYeh5YLVG45xslQAAAoU"]
[Tue Jul 21 07:23:21.032782 2026] [security2:error] [pid 229246:tid 229489] [client 62.102.148.164:33234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9ImSBMYeh5YLVG45xslQAAAoU"]
[Tue Jul 21 07:23:21.194481 2026] [security2:error] [pid 230252:tid 230473] [client 103.121.156.110:50474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9ImU0Dwhk5-Z44XrpHwAAAAvI"]
[Tue Jul 21 07:23:21.194630 2026] [security2:error] [pid 230252:tid 230473] [client 103.121.156.110:50474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9ImU0Dwhk5-Z44XrpHwAAAAvI"]
[Tue Jul 21 07:23:21.269393 2026] [security2:error] [pid 230252:tid 230418] [client 45.251.232.145:54640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ImU0Dwhk5-Z44XrpHwgAAArs"]
[Tue Jul 21 07:23:21.269508 2026] [security2:error] [pid 230252:tid 230418] [client 45.251.232.145:54640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ImU0Dwhk5-Z44XrpHwgAAArs"]
[Tue Jul 21 07:23:21.413358 2026] [security2:error] [pid 229246:tid 229440] [client 20.151.10.161:26379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/error_log.php"] [unique_id "al9ImSBMYeh5YLVG45xsmgAAAlQ"]
[Tue Jul 21 07:23:21.434153 2026] [security2:error] [pid 230252:tid 230507] [client 20.226.60.151:56926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/a.php"] [unique_id "al9ImU0Dwhk5-Z44XrpHwwAAAxQ"]
[Tue Jul 21 07:23:21.440907 2026] [security2:error] [pid 230252:tid 230506] [client 20.104.96.117:4177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/buy.php"] [unique_id "al9ImU0Dwhk5-Z44XrpHxAAAAxM"]
[Tue Jul 21 07:23:21.578642 2026] [security2:error] [pid 229246:tid 229453] [client 62.102.148.164:59688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9ImSBMYeh5YLVG45xsmwAAAmE"]
[Tue Jul 21 07:23:21.578750 2026] [security2:error] [pid 229246:tid 229453] [client 62.102.148.164:59688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9ImSBMYeh5YLVG45xsmwAAAmE"]
[Tue Jul 21 07:23:21.812907 2026] [security2:error] [pid 230252:tid 230491] [client 20.151.10.161:49119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/k5.php"] [unique_id "al9ImU0Dwhk5-Z44XrpHyAAAAwQ"]
[Tue Jul 21 07:23:21.817048 2026] [security2:error] [pid 230252:tid 230432] [client 20.104.96.117:64007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/ssend.php"] [unique_id "al9ImU0Dwhk5-Z44XrpHyQAAAsk"]
[Tue Jul 21 07:23:22.115200 2026] [security2:error] [pid 229246:tid 229491] [client 20.151.10.161:26497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/xenon1337.php"] [unique_id "al9ImiBMYeh5YLVG45xsowAAAoc"]
[Tue Jul 21 07:23:22.139249 2026] [security2:error] [pid 230252:tid 230403] [client 20.104.96.117:62941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/item.php"] [unique_id "al9Imk0Dwhk5-Z44XrpHywAAAqw"]
[Tue Jul 21 07:23:22.271919 2026] [security2:error] [pid 229246:tid 229426] [client 193.36.225.58:37857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9ImiBMYeh5YLVG45xsogAAAkY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:22.544363 2026] [security2:error] [pid 230252:tid 230455] [client 20.220.225.223:34243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/wp-editor.php"] [unique_id "al9Imk0Dwhk5-Z44XrpH0gAAAuA"]
[Tue Jul 21 07:23:22.618499 2026] [security2:error] [pid 230252:tid 230452] [client 20.104.96.117:5061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/ss.php"] [unique_id "al9Imk0Dwhk5-Z44XrpH0wAAAt0"]
[Tue Jul 21 07:23:22.664556 2026] [security2:error] [pid 230252:tid 230413] [client 74.249.245.134:42774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/up.php"] [unique_id "al9Imk0Dwhk5-Z44XrpH1AAAArY"]
[Tue Jul 21 07:23:22.867428 2026] [security2:error] [pid 230252:tid 230469] [client 20.197.192.193:52276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/ah25.php"] [unique_id "al9Imk0Dwhk5-Z44XrpH2QAAAu4"]
[Tue Jul 21 07:23:22.988714 2026] [security2:error] [pid 229246:tid 229392] [client 20.226.60.151:56917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/edit.php"] [unique_id "al9ImiBMYeh5YLVG45xsrQAAAiQ"]
[Tue Jul 21 07:23:23.083004 2026] [security2:error] [pid 230252:tid 230497] [client 20.104.96.117:62922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/hypo.php"] [unique_id "al9Im00Dwhk5-Z44XrpH2gAAAwo"]
[Tue Jul 21 07:23:23.624401 2026] [security2:error] [pid 230252:tid 230428] [client 20.104.96.117:5080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/users.php"] [unique_id "al9Im00Dwhk5-Z44XrpH4QAAAsU"]
[Tue Jul 21 07:23:23.678164 2026] [security2:error] [pid 230252:tid 230422] [client 20.151.10.161:49111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/w.php"] [unique_id "al9Im00Dwhk5-Z44XrpH4gAAAr8"]
[Tue Jul 21 07:23:23.679809 2026] [security2:error] [pid 229246:tid 229411] [client 20.226.60.151:60163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/file61.php"] [unique_id "al9ImyBMYeh5YLVG45xsuQAAAjc"]
[Tue Jul 21 07:23:23.960938 2026] [security2:error] [pid 230252:tid 230472] [client 103.162.129.114:51726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Im00Dwhk5-Z44XrpH5QAAAvE"]
[Tue Jul 21 07:23:23.961048 2026] [security2:error] [pid 230252:tid 230472] [client 103.162.129.114:51726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Im00Dwhk5-Z44XrpH5QAAAvE"]
[Tue Jul 21 07:23:23.969529 2026] [security2:error] [pid 230252:tid 230300] [remote 51.161.65.213:29676] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "neuroalfabetizaanacolombo.com"] [uri "/"] [unique_id "al9Im00Dwhk5-Z44XrpH5gACyS4"]
[Tue Jul 21 07:23:23.969636 2026] [security2:error] [pid 230252:tid 230432] [client 51.161.65.213:29676] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "neuroalfabetizaanacolombo.com"] [uri "/"] [unique_id "al9Im00Dwhk5-Z44XrpH5gACyS4"]
[Tue Jul 21 07:23:24.187495 2026] [security2:error] [pid 230252:tid 230467] [client 14.139.42.196:12431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9InE0Dwhk5-Z44XrpH5wAAAuw"]
[Tue Jul 21 07:23:24.187622 2026] [security2:error] [pid 230252:tid 230467] [client 14.139.42.196:12431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9InE0Dwhk5-Z44XrpH5wAAAuw"]
[Tue Jul 21 07:23:24.235361 2026] [security2:error] [pid 229246:tid 229383] [client 20.104.96.117:5073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/177.php"] [unique_id "al9InCBMYeh5YLVG45xsvwAAAhs"]
[Tue Jul 21 07:23:24.528032 2026] [security2:error] [pid 230252:tid 230408] [client 20.104.96.117:64041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/config.php"] [unique_id "al9InE0Dwhk5-Z44XrpH6gAAArE"]
[Tue Jul 21 07:23:24.535747 2026] [security2:error] [pid 229246:tid 229501] [client 20.226.60.151:56879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/hosty.php"] [unique_id "al9InCBMYeh5YLVG45xsxAAAApE"]
[Tue Jul 21 07:23:24.584759 2026] [security2:error] [pid 230252:tid 230481] [client 117.251.86.144:51968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9InE0Dwhk5-Z44XrpH7AAAAvo"]
[Tue Jul 21 07:23:24.584902 2026] [security2:error] [pid 230252:tid 230481] [client 117.251.86.144:51968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9InE0Dwhk5-Z44XrpH7AAAAvo"]
[Tue Jul 21 07:23:24.616889 2026] [security2:error] [pid 230252:tid 230279] [remote 157.66.26.183:60696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9InE0Dwhk5-Z44XrpH7QACoRk"]
[Tue Jul 21 07:23:25.008716 2026] [security2:error] [pid 229246:tid 229484] [client 20.104.96.117:64049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/gettest.php"] [unique_id "al9InSBMYeh5YLVG45xszgAAAoA"]
[Tue Jul 21 07:23:25.020755 2026] [security2:error] [pid 229246:tid 229477] [client 20.226.60.151:54586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/nano.php"] [unique_id "al9InSBMYeh5YLVG45xszwAAAnk"]
[Tue Jul 21 07:23:25.036624 2026] [security2:error] [pid 229246:tid 229398] [client 20.151.10.161:26398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/test11.php"] [unique_id "al9InSBMYeh5YLVG45xs0gAAAio"]
[Tue Jul 21 07:23:25.160530 2026] [security2:error] [pid 230252:tid 230417] [client 62.102.148.164:59696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9InU0Dwhk5-Z44XrpH8wAAAro"]
[Tue Jul 21 07:23:25.160625 2026] [security2:error] [pid 230252:tid 230417] [client 62.102.148.164:59696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9InU0Dwhk5-Z44XrpH8wAAAro"]
[Tue Jul 21 07:23:25.223019 2026] [security2:error] [pid 230252:tid 230452] [client 20.226.60.151:60244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/water.php"] [unique_id "al9InU0Dwhk5-Z44XrpH9AAAAt0"]
[Tue Jul 21 07:23:25.455138 2026] [security2:error] [pid 230252:tid 230322] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9InU0Dwhk5-Z44XrpH9wACzUQ"]
[Tue Jul 21 07:23:25.455314 2026] [security2:error] [pid 230252:tid 230436] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9InU0Dwhk5-Z44XrpH9wACzUQ"]
[Tue Jul 21 07:23:25.466135 2026] [security2:error] [pid 230252:tid 230501] [client 20.104.96.117:62971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/min.php"] [unique_id "al9InU0Dwhk5-Z44XrpH-AAAAw4"]
[Tue Jul 21 07:23:25.849598 2026] [security2:error] [pid 230252:tid 230296] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9InU0Dwhk5-Z44XrpH_AAC2Co"]
[Tue Jul 21 07:23:25.849772 2026] [security2:error] [pid 230252:tid 230447] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9InU0Dwhk5-Z44XrpH_AAC2Co"]
[Tue Jul 21 07:23:25.928914 2026] [security2:error] [pid 230252:tid 230418] [client 20.104.96.117:62974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/dvjul.php"] [unique_id "al9InU0Dwhk5-Z44XrpIAAAAArs"]
[Tue Jul 21 07:23:25.969317 2026] [security2:error] [pid 229246:tid 229393] [client 20.151.10.161:49046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/fpwch.php"] [unique_id "al9InSBMYeh5YLVG45xs3QAAAiU"]
[Tue Jul 21 07:23:26.032752 2026] [security2:error] [pid 230252:tid 230307] [remote 150.95.80.135:40618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.80.95.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9Ink0Dwhk5-Z44XrpIBAAC0jU"]
[Tue Jul 21 07:23:26.032904 2026] [security2:error] [pid 230252:tid 230441] [client 150.95.80.135:40618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9Ink0Dwhk5-Z44XrpIBAAC0jU"]
[Tue Jul 21 07:23:26.330476 2026] [security2:error] [pid 230252:tid 230367] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ink0Dwhk5-Z44XrpIBgADAHA"]
[Tue Jul 21 07:23:26.330675 2026] [security2:error] [pid 230252:tid 230487] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ink0Dwhk5-Z44XrpIBgADAHA"]
[Tue Jul 21 07:23:26.410255 2026] [security2:error] [pid 229246:tid 229473] [client 20.104.96.117:64022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/biufile.php"] [unique_id "al9IniBMYeh5YLVG45xs4wAAAnU"]
[Tue Jul 21 07:23:26.455896 2026] [security2:error] [pid 230252:tid 230464] [client 20.226.60.151:56937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/k.php"] [unique_id "al9Ink0Dwhk5-Z44XrpICwAAAuk"]
[Tue Jul 21 07:23:26.542352 2026] [security2:error] [pid 230252:tid 230294] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ink0Dwhk5-Z44XrpIDQACySg"]
[Tue Jul 21 07:23:26.542506 2026] [security2:error] [pid 230252:tid 230432] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ink0Dwhk5-Z44XrpIDQACySg"]
[Tue Jul 21 07:23:26.839108 2026] [security2:error] [pid 230252:tid 230455] [client 20.104.96.117:62925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/av.php"] [unique_id "al9Ink0Dwhk5-Z44XrpIEQAAAuA"]
[Tue Jul 21 07:23:26.885276 2026] [security2:error] [pid 230252:tid 230452] [client 20.151.10.161:49030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/w2025.php"] [unique_id "al9Ink0Dwhk5-Z44XrpIEgAAAt0"]
[Tue Jul 21 07:23:27.152462 2026] [security2:error] [pid 229246:tid 229496] [client 34.62.211.118:60889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.211.62.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sevenviewlentes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9InyBMYeh5YLVG45xs7wAAAow"]
[Tue Jul 21 07:23:27.165457 2026] [security2:error] [pid 229246:tid 229490] [client 136.144.33.111:27757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9InyBMYeh5YLVG45xs8QAAAoY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:27.268553 2026] [security2:error] [pid 230252:tid 230441] [client 20.104.96.117:62921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/coffexium.php"] [unique_id "al9In00Dwhk5-Z44XrpIOgAAAtI"]
[Tue Jul 21 07:23:27.330413 2026] [security2:error] [pid 229246:tid 229387] [client 109.248.148.246:36062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9InyBMYeh5YLVG45xs8gAAAh8"]
[Tue Jul 21 07:23:27.330510 2026] [security2:error] [pid 229246:tid 229387] [client 109.248.148.246:36062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9InyBMYeh5YLVG45xs8gAAAh8"]
[Tue Jul 21 07:23:27.404999 2026] [security2:error] [pid 230252:tid 230457] [client 20.226.60.151:54582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/moon.php"] [unique_id "al9In00Dwhk5-Z44XrpIRgAAAuI"]
[Tue Jul 21 07:23:27.741864 2026] [security2:error] [pid 229246:tid 229412] [client 20.104.96.117:4172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/core.php"] [unique_id "al9InyBMYeh5YLVG45xs-QAAAjg"]
[Tue Jul 21 07:23:28.005324 2026] [security2:error] [pid 229246:tid 229386] [client 20.226.60.151:56957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/aaa.php"] [unique_id "al9IoCBMYeh5YLVG45xs_QAAAh4"]
[Tue Jul 21 07:23:28.099891 2026] [security2:error] [pid 230252:tid 230420] [client 20.104.96.117:62942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/als.php"] [unique_id "al9IoE0Dwhk5-Z44XrpIYQAAAr0"]
[Tue Jul 21 07:23:28.178479 2026] [security2:error] [pid 229246:tid 229380] [client 34.62.211.118:55250] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9IoCBMYeh5YLVG45xtBQAAAhg"]
[Tue Jul 21 07:23:28.187512 2026] [security2:error] [pid 230252:tid 230446] [client 20.226.60.151:60266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/nano.php"] [unique_id "al9IoE0Dwhk5-Z44XrpIYwAAAtc"]
[Tue Jul 21 07:23:28.495152 2026] [security2:error] [pid 230252:tid 230295] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IoE0Dwhk5-Z44XrpIZgADCCk"]
[Tue Jul 21 07:23:28.495292 2026] [security2:error] [pid 230252:tid 230495] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IoE0Dwhk5-Z44XrpIZgADCCk"]
[Tue Jul 21 07:23:28.498288 2026] [security2:error] [pid 230252:tid 230416] [client 20.104.96.117:62937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/simple.php"] [unique_id "al9IoE0Dwhk5-Z44XrpIZwAAArk"]
[Tue Jul 21 07:23:28.615349 2026] [security2:error] [pid 230252:tid 230256] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IoE0Dwhk5-Z44XrpIqwACyQI"]
[Tue Jul 21 07:23:28.615497 2026] [security2:error] [pid 230252:tid 230432] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IoE0Dwhk5-Z44XrpIqwACyQI"]
[Tue Jul 21 07:23:28.687794 2026] [security2:error] [pid 230252:tid 230447] [client 20.226.60.151:60253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/moon.php"] [unique_id "al9IoE0Dwhk5-Z44XrpIrgAAAtg"]
[Tue Jul 21 07:23:29.094029 2026] [security2:error] [pid 230252:tid 230446] [client 20.104.96.117:64062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/init.php"] [unique_id "al9IoU0Dwhk5-Z44XrpIvAAAAtc"]
[Tue Jul 21 07:23:29.132595 2026] [security2:error] [pid 230252:tid 230427] [client 20.226.60.151:56929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/file5.php"] [unique_id "al9IoU0Dwhk5-Z44XrpIvQAAAsQ"]
[Tue Jul 21 07:23:29.156552 2026] [security2:error] [pid 230252:tid 230388] [client 20.220.225.223:34287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/cro.php"] [unique_id "al9IoU0Dwhk5-Z44XrpIvgAAAp0"]
[Tue Jul 21 07:23:29.192457 2026] [security2:error] [pid 229246:tid 229435] [client 34.62.211.118:50147] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9IoSBMYeh5YLVG45xtFAAAAk8"]
[Tue Jul 21 07:23:29.295276 2026] [security2:error] [pid 230252:tid 230480] [client 20.226.60.151:50785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-info.php"] [unique_id "al9IoU0Dwhk5-Z44XrpIvwAAAvk"]
[Tue Jul 21 07:23:29.510249 2026] [security2:error] [pid 229246:tid 229446] [client 20.104.96.117:64015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/fpwch.php"] [unique_id "al9IoSBMYeh5YLVG45xtGQAAAlo"]
[Tue Jul 21 07:23:29.587103 2026] [security2:error] [pid 229246:tid 229494] [client 175.45.70.82:58859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IoSBMYeh5YLVG45xtHAAAAoo"]
[Tue Jul 21 07:23:29.587206 2026] [security2:error] [pid 229246:tid 229494] [client 175.45.70.82:58859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IoSBMYeh5YLVG45xtHAAAAoo"]
[Tue Jul 21 07:23:29.617790 2026] [security2:error] [pid 230252:tid 230509] [client 103.174.34.15:52616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IoU0Dwhk5-Z44XrpIwgAAAxY"]
[Tue Jul 21 07:23:29.617911 2026] [security2:error] [pid 230252:tid 230509] [client 103.174.34.15:52616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IoU0Dwhk5-Z44XrpIwgAAAxY"]
[Tue Jul 21 07:23:29.916519 2026] [security2:error] [pid 230252:tid 230392] [client 20.104.96.117:64052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/domvf.php"] [unique_id "al9IoU0Dwhk5-Z44XrpIyAAAAqE"]
[Tue Jul 21 07:23:29.957593 2026] [security2:error] [pid 230252:tid 230395] [client 20.151.10.161:26391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/koala.php"] [unique_id "al9IoU0Dwhk5-Z44XrpIzQAAAqQ"]
[Tue Jul 21 07:23:30.053088 2026] [security2:error] [pid 229246:tid 229394] [client 34.62.211.118:56830] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9IoiBMYeh5YLVG45xtIgAAAiY"]
[Tue Jul 21 07:23:30.131067 2026] [security2:error] [pid 230252:tid 230499] [client 213.152.162.104:53330] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9Iok0Dwhk5-Z44XrpIzgAAAww"]
[Tue Jul 21 07:23:30.131223 2026] [security2:error] [pid 230252:tid 230499] [client 213.152.162.104:53330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9Iok0Dwhk5-Z44XrpIzgAAAww"]
[Tue Jul 21 07:23:30.227569 2026] [security2:error] [pid 230252:tid 230408] [client 20.220.225.223:34184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/cron-tab.php"] [unique_id "al9Iok0Dwhk5-Z44XrpI0QAAArE"]
[Tue Jul 21 07:23:30.287196 2026] [security2:error] [pid 230252:tid 230498] [client 20.226.60.151:50759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/2000.php"] [unique_id "al9Iok0Dwhk5-Z44XrpI0gAAAws"]
[Tue Jul 21 07:23:30.383154 2026] [security2:error] [pid 230252:tid 230475] [client 20.226.60.151:56864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/222.php"] [unique_id "al9Iok0Dwhk5-Z44XrpI0wAAAvQ"]
[Tue Jul 21 07:23:30.400501 2026] [security2:error] [pid 230252:tid 230457] [client 20.104.96.117:4179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/wp.php"] [unique_id "al9Iok0Dwhk5-Z44XrpI1AAAAuI"]
[Tue Jul 21 07:23:30.810982 2026] [security2:error] [pid 229246:tid 229467] [client 20.226.60.151:54488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-info.php"] [unique_id "al9IoiBMYeh5YLVG45xtKQAAAm8"]
[Tue Jul 21 07:23:30.876066 2026] [security2:error] [pid 229246:tid 229377] [client 20.104.96.117:64056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/class.php"] [unique_id "al9IoiBMYeh5YLVG45xtKwAAAhU"]
[Tue Jul 21 07:23:30.879743 2026] [security2:error] [pid 229246:tid 229423] [client 34.62.211.118:58086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9IoiBMYeh5YLVG45xtLAAAAkM"]
[Tue Jul 21 07:23:30.916667 2026] [security2:error] [pid 229246:tid 229383] [client 74.249.245.134:62143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/66.php"] [unique_id "al9IoiBMYeh5YLVG45xtLQAAAhs"]
[Tue Jul 21 07:23:31.194196 2026] [security2:error] [pid 229246:tid 229501] [client 20.104.96.117:64019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/echkm.php"] [unique_id "al9IoyBMYeh5YLVG45xtMAAAApE"]
[Tue Jul 21 07:23:31.249275 2026] [security2:error] [pid 230252:tid 230478] [client 139.135.44.145:54219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Io00Dwhk5-Z44XrpI1wAAAvc"]
[Tue Jul 21 07:23:31.249372 2026] [security2:error] [pid 230252:tid 230478] [client 139.135.44.145:54219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Io00Dwhk5-Z44XrpI1wAAAvc"]
[Tue Jul 21 07:23:31.282879 2026] [security2:error] [pid 229246:tid 229427] [client 20.197.192.193:52247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/8.php"] [unique_id "al9IoyBMYeh5YLVG45xtNQAAAkc"]
[Tue Jul 21 07:23:31.312555 2026] [security2:error] [pid 230252:tid 230501] [client 193.36.225.70:52829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Io00Dwhk5-Z44XrpI1gAAAw4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:31.342389 2026] [security2:error] [pid 229246:tid 229406] [client 20.151.10.161:49122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/scxy.php"] [unique_id "al9IoyBMYeh5YLVG45xtNgAAAjI"]
[Tue Jul 21 07:23:31.475215 2026] [security2:error] [pid 229246:tid 229390] [client 20.104.96.117:5098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/lib.php"] [unique_id "al9IoyBMYeh5YLVG45xtOAAAAiI"]
[Tue Jul 21 07:23:31.653299 2026] [security2:error] [pid 230252:tid 230420] [client 20.226.60.151:63343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/test.php"] [unique_id "al9Io00Dwhk5-Z44XrpI2AAAAr0"]
[Tue Jul 21 07:23:31.729519 2026] [security2:error] [pid 229246:tid 229430] [client 34.62.211.118:52005] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9IoyBMYeh5YLVG45xtPQAAAko"]
[Tue Jul 21 07:23:31.751342 2026] [security2:error] [pid 229246:tid 229412] [client 45.251.232.145:55248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IoyBMYeh5YLVG45xtPwAAAjg"]
[Tue Jul 21 07:23:31.751461 2026] [security2:error] [pid 229246:tid 229412] [client 45.251.232.145:55248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IoyBMYeh5YLVG45xtPwAAAjg"]
[Tue Jul 21 07:23:31.759758 2026] [security2:error] [pid 230252:tid 230486] [client 20.104.96.117:4181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/login.php"] [unique_id "al9Io00Dwhk5-Z44XrpI3AAAAv8"]
[Tue Jul 21 07:23:31.848745 2026] [security2:error] [pid 229246:tid 229441] [client 103.121.156.110:50821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IoyBMYeh5YLVG45xtQQAAAlU"]
[Tue Jul 21 07:23:31.848879 2026] [security2:error] [pid 229246:tid 229441] [client 103.121.156.110:50821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IoyBMYeh5YLVG45xtQQAAAlU"]
[Tue Jul 21 07:23:31.963307 2026] [security2:error] [pid 230252:tid 230401] [client 20.226.60.151:60274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/122.php"] [unique_id "al9Io00Dwhk5-Z44XrpI3wAAAqo"]
[Tue Jul 21 07:23:32.126280 2026] [security2:error] [pid 230252:tid 230414] [client 20.220.225.223:46089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/kua.php"] [unique_id "al9IpE0Dwhk5-Z44XrpI4AAAArc"]
[Tue Jul 21 07:23:32.231207 2026] [security2:error] [pid 230252:tid 230482] [client 20.104.96.117:5111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/a2.php"] [unique_id "al9IpE0Dwhk5-Z44XrpI4QAAAvs"]
[Tue Jul 21 07:23:32.368173 2026] [security2:error] [pid 230252:tid 230483] [client 20.226.60.151:60202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/mds.php"] [unique_id "al9IpE0Dwhk5-Z44XrpI4gAAAvw"]
[Tue Jul 21 07:23:32.541786 2026] [security2:error] [pid 230252:tid 230392] [client 34.62.211.118:57364] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9IpE0Dwhk5-Z44XrpI4wAAAqE"]
[Tue Jul 21 07:23:32.778585 2026] [security2:error] [pid 229246:tid 229402] [client 20.226.60.151:56845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/aaa.php"] [unique_id "al9IpCBMYeh5YLVG45xtTAAAAi4"]
[Tue Jul 21 07:23:32.861873 2026] [security2:error] [pid 229246:tid 229471] [client 20.226.60.151:50780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-blink.php"] [unique_id "al9IpCBMYeh5YLVG45xtTgAAAnM"]
[Tue Jul 21 07:23:32.861987 2026] [security2:error] [pid 229246:tid 229426] [client 20.104.96.117:4173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/d61.php"] [unique_id "al9IpCBMYeh5YLVG45xtTwAAAkY"]
[Tue Jul 21 07:23:32.912593 2026] [security2:error] [pid 229246:tid 229458] [client 74.249.245.134:60034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/666.php"] [unique_id "al9IpCBMYeh5YLVG45xtUQAAAmY"]
[Tue Jul 21 07:23:33.281586 2026] [security2:error] [pid 230252:tid 230497] [client 20.226.60.151:60191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/zc-208.php"] [unique_id "al9IpU0Dwhk5-Z44XrpI5wAAAwo"]
[Tue Jul 21 07:23:33.418548 2026] [security2:error] [pid 229246:tid 229482] [client 20.104.96.117:4187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/info.php"] [unique_id "al9IpSBMYeh5YLVG45xtVwAAAn4"]
[Tue Jul 21 07:23:33.433491 2026] [security2:error] [pid 229246:tid 229457] [client 34.62.211.118:57223] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9IpSBMYeh5YLVG45xtWAAAAmU"]
[Tue Jul 21 07:23:33.753712 2026] [security2:error] [pid 230252:tid 230502] [client 20.226.60.151:60237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/sid4.php"] [unique_id "al9IpU0Dwhk5-Z44XrpI6wAAAw8"]
[Tue Jul 21 07:23:33.996307 2026] [security2:error] [pid 230252:tid 230464] [client 20.104.96.117:5072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/11.php"] [unique_id "al9IpU0Dwhk5-Z44XrpI7gAAAuk"]
[Tue Jul 21 07:23:34.142566 2026] [security2:error] [pid 230252:tid 230431] [client 20.220.225.223:46094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/ez.php"] [unique_id "al9Ipk0Dwhk5-Z44XrpI7wAAAsg"]
[Tue Jul 21 07:23:34.222732 2026] [proxy:error] [pid 230252:tid 230491] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:34.222797 2026] [proxy_http:error] [pid 230252:tid 230491] [client 20.226.60.151:60216] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:34.223382 2026] [proxy:error] [pid 230252:tid 230491] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:34.223414 2026] [proxy_http:error] [pid 230252:tid 230491] [client 20.226.60.151:60216] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:34.345959 2026] [security2:error] [pid 229246:tid 229483] [client 34.62.211.118:63433] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9IpiBMYeh5YLVG45xtYQAAAn8"]
[Tue Jul 21 07:23:34.450069 2026] [security2:error] [pid 230252:tid 230429] [client 20.104.96.117:5056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/v2.php"] [unique_id "al9Ipk0Dwhk5-Z44XrpI9AAAAsY"]
[Tue Jul 21 07:23:34.672797 2026] [security2:error] [pid 230252:tid 230472] [client 103.162.129.114:52224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Ipk0Dwhk5-Z44XrpI9gAAAvE"]
[Tue Jul 21 07:23:34.672955 2026] [security2:error] [pid 230252:tid 230472] [client 103.162.129.114:52224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Ipk0Dwhk5-Z44XrpI9gAAAvE"]
[Tue Jul 21 07:23:34.750937 2026] [security2:error] [pid 230252:tid 230401] [client 20.226.60.151:56936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/11.php"] [unique_id "al9Ipk0Dwhk5-Z44XrpI9wAAAqo"]
[Tue Jul 21 07:23:34.941966 2026] [security2:error] [pid 230252:tid 230404] [client 20.226.60.151:50711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wmore1.php"] [unique_id "al9Ipk0Dwhk5-Z44XrpI_QAAAq0"]
[Tue Jul 21 07:23:34.951495 2026] [security2:error] [pid 230252:tid 230388] [client 14.139.42.196:11409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ipk0Dwhk5-Z44XrpI_gAAAp0"]
[Tue Jul 21 07:23:34.951647 2026] [security2:error] [pid 230252:tid 230388] [client 14.139.42.196:11409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ipk0Dwhk5-Z44XrpI_gAAAp0"]
[Tue Jul 21 07:23:34.989323 2026] [security2:error] [pid 230252:tid 230468] [client 20.151.10.161:26430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/mac.php"] [unique_id "al9Ipk0Dwhk5-Z44XrpI_wAAAu0"]
[Tue Jul 21 07:23:35.007111 2026] [security2:error] [pid 230252:tid 230444] [client 20.104.96.117:62957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/panel.php"] [unique_id "al9Ip00Dwhk5-Z44XrpJAAAAAtU"]
[Tue Jul 21 07:23:35.165655 2026] [security2:error] [pid 230252:tid 230452] [client 34.62.211.118:52657] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Ip00Dwhk5-Z44XrpJAwAAAt0"]
[Tue Jul 21 07:23:35.318495 2026] [security2:error] [pid 230252:tid 230436] [client 117.251.86.144:37984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Ip00Dwhk5-Z44XrpJBAAAAs0"]
[Tue Jul 21 07:23:35.318624 2026] [security2:error] [pid 230252:tid 230436] [client 117.251.86.144:37984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Ip00Dwhk5-Z44XrpJBAAAAs0"]
[Tue Jul 21 07:23:35.551447 2026] [security2:error] [pid 230252:tid 230507] [client 20.151.10.161:26319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9Ip00Dwhk5-Z44XrpJBgAAAxQ"]
[Tue Jul 21 07:23:35.643689 2026] [security2:error] [pid 230252:tid 230475] [client 20.104.96.117:4245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/dex.php"] [unique_id "al9Ip00Dwhk5-Z44XrpJBwAAAvQ"]
[Tue Jul 21 07:23:35.742446 2026] [security2:error] [pid 230252:tid 230474] [client 20.226.60.151:54590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/2000.php"] [unique_id "al9Ip00Dwhk5-Z44XrpJCAAAAvM"]
[Tue Jul 21 07:23:35.913229 2026] [security2:error] [pid 230252:tid 230389] [client 20.220.225.223:34464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/koiy.php"] [unique_id "al9Ip00Dwhk5-Z44XrpJDAAAAp4"]
[Tue Jul 21 07:23:35.949444 2026] [security2:error] [pid 230252:tid 230311] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ip00Dwhk5-Z44XrpJDQAC0jk"]
[Tue Jul 21 07:23:35.949592 2026] [security2:error] [pid 230252:tid 230441] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ip00Dwhk5-Z44XrpJDQAC0jk"]
[Tue Jul 21 07:23:36.007404 2026] [security2:error] [pid 230252:tid 230464] [client 20.197.192.193:52234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/red.php"] [unique_id "al9IqE0Dwhk5-Z44XrpJDgAAAuk"]
[Tue Jul 21 07:23:36.171968 2026] [security2:error] [pid 229246:tid 229479] [client 34.62.211.118:57636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9IqCBMYeh5YLVG45xtcwAAAns"]
[Tue Jul 21 07:23:36.211966 2026] [security2:error] [pid 230252:tid 230459] [client 20.104.96.117:62963] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/1.php"] [unique_id "al9IqE0Dwhk5-Z44XrpJEAAAAuQ"]
[Tue Jul 21 07:23:36.212088 2026] [security2:error] [pid 230252:tid 230459] [client 20.104.96.117:62963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/1.php"] [unique_id "al9IqE0Dwhk5-Z44XrpJEAAAAuQ"]
[Tue Jul 21 07:23:36.245012 2026] [security2:error] [pid 230252:tid 230471] [client 20.220.225.223:46104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/fz.php"] [unique_id "al9IqE0Dwhk5-Z44XrpJEQAAAvA"]
[Tue Jul 21 07:23:36.263609 2026] [security2:error] [pid 230252:tid 230431] [client 20.226.60.151:56931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/mac.php"] [unique_id "al9IqE0Dwhk5-Z44XrpJEgAAAsg"]
[Tue Jul 21 07:23:36.382245 2026] [security2:error] [pid 230252:tid 230462] [client 193.36.225.69:60971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IqE0Dwhk5-Z44XrpJEwAAAuc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:36.484857 2026] [security2:error] [pid 229246:tid 229486] [client 20.151.10.161:26408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wefile.php"] [unique_id "al9IqCBMYeh5YLVG45xtdgAAAoI"]
[Tue Jul 21 07:23:36.569495 2026] [security2:error] [pid 230252:tid 230351] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IqE0Dwhk5-Z44XrpJFgAC7GA"]
[Tue Jul 21 07:23:36.569681 2026] [security2:error] [pid 230252:tid 230467] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IqE0Dwhk5-Z44XrpJFgAC7GA"]
[Tue Jul 21 07:23:36.593426 2026] [security2:error] [pid 229246:tid 229448] [client 20.104.96.117:5097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/ms.php"] [unique_id "al9IqCBMYeh5YLVG45xteAAAAlw"]
[Tue Jul 21 07:23:36.919370 2026] [security2:error] [pid 230252:tid 230401] [client 20.226.60.151:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/solo1.php"] [unique_id "al9IqE0Dwhk5-Z44XrpJGAAAAqo"]
[Tue Jul 21 07:23:36.940096 2026] [security2:error] [pid 230252:tid 230369] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IqE0Dwhk5-Z44XrpJGwAC8XI"]
[Tue Jul 21 07:23:36.940283 2026] [security2:error] [pid 230252:tid 230472] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IqE0Dwhk5-Z44XrpJGwAC8XI"]
[Tue Jul 21 07:23:37.022524 2026] [security2:error] [pid 229246:tid 229403] [client 34.62.211.118:61993] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9IqSBMYeh5YLVG45xtfwAAAi8"]
[Tue Jul 21 07:23:37.037753 2026] [security2:error] [pid 229246:tid 229292] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IqSBMYeh5YLVG45xtgAACUS0"]
[Tue Jul 21 07:23:37.037891 2026] [security2:error] [pid 229246:tid 229437] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IqSBMYeh5YLVG45xtgAACUS0"]
[Tue Jul 21 07:23:37.073624 2026] [security2:error] [pid 230252:tid 230413] [client 20.226.60.151:56944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/chosen.php"] [unique_id "al9IqU0Dwhk5-Z44XrpJHAAAArY"]
[Tue Jul 21 07:23:37.088353 2026] [proxy:error] [pid 230252:tid 230393] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:37.088426 2026] [proxy_http:error] [pid 230252:tid 230393] [client 20.104.96.117:5105] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:37.089132 2026] [proxy:error] [pid 230252:tid 230393] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:37.089160 2026] [proxy_http:error] [pid 230252:tid 230393] [client 20.104.96.117:5105] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:37.199209 2026] [security2:error] [pid 230252:tid 230468] [client 109.248.148.246:50054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9IqU0Dwhk5-Z44XrpJIQAAAu0"]
[Tue Jul 21 07:23:37.199309 2026] [security2:error] [pid 230252:tid 230468] [client 109.248.148.246:50054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9IqU0Dwhk5-Z44XrpJIQAAAu0"]
[Tue Jul 21 07:23:37.462695 2026] [security2:error] [pid 230252:tid 230410] [client 20.226.60.151:56862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/cream1.php"] [unique_id "al9IqU0Dwhk5-Z44XrpJJAAAArM"]
[Tue Jul 21 07:23:37.473721 2026] [security2:error] [pid 230252:tid 230436] [client 20.104.96.117:62951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/memberfuns.php"] [unique_id "al9IqU0Dwhk5-Z44XrpJJgAAAs0"]
[Tue Jul 21 07:23:37.763462 2026] [security2:error] [pid 229246:tid 229459] [client 20.104.96.117:5064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/0.php"] [unique_id "al9IqSBMYeh5YLVG45xthwAAAmc"]
[Tue Jul 21 07:23:37.881528 2026] [security2:error] [pid 229246:tid 229447] [client 20.151.10.161:49044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/FWAZ.php"] [unique_id "al9IqSBMYeh5YLVG45xtigAAAls"]
[Tue Jul 21 07:23:37.958377 2026] [security2:error] [pid 229246:tid 229462] [client 62.102.148.164:42548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9IqSBMYeh5YLVG45xtjAAAAmo"]
[Tue Jul 21 07:23:37.958470 2026] [security2:error] [pid 229246:tid 229462] [client 62.102.148.164:42548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9IqSBMYeh5YLVG45xtjAAAAmo"]
[Tue Jul 21 07:23:38.036612 2026] [proxy:error] [pid 229246:tid 229273] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:38.036647 2026] [proxy_http:error] [pid 229246:tid 229273] [remote 74.7.175.166:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:38.037217 2026] [proxy:error] [pid 229246:tid 229273] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:38.037239 2026] [proxy_http:error] [pid 229246:tid 229273] [remote 74.7.175.166:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:38.046571 2026] [security2:error] [pid 229246:tid 229496] [client 74.249.245.134:56013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/byp.php"] [unique_id "al9IqiBMYeh5YLVG45xtjwAAAow"]
[Tue Jul 21 07:23:38.065897 2026] [security2:error] [pid 229246:tid 229394] [client 20.104.96.117:64034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/BDKR28.php"] [unique_id "al9IqiBMYeh5YLVG45xtkAAAAiY"]
[Tue Jul 21 07:23:38.147301 2026] [security2:error] [pid 230252:tid 230507] [client 34.62.211.118:62143] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9Iqk0Dwhk5-Z44XrpJLQAAAxQ"]
[Tue Jul 21 07:23:38.441682 2026] [proxy:error] [pid 229246:tid 229499] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:38.441750 2026] [proxy_http:error] [pid 229246:tid 229499] [client 20.226.60.151:50775] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:38.442329 2026] [proxy:error] [pid 229246:tid 229499] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:38.442356 2026] [proxy_http:error] [pid 229246:tid 229499] [client 20.226.60.151:50775] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:38.606401 2026] [security2:error] [pid 230252:tid 230471] [client 20.104.96.117:62936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/green1.php"] [unique_id "al9Iqk0Dwhk5-Z44XrpJMwAAAvA"]
[Tue Jul 21 07:23:38.693987 2026] [security2:error] [pid 230252:tid 230502] [client 103.174.34.15:53109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Iqk0Dwhk5-Z44XrpJNQAAAw8"]
[Tue Jul 21 07:23:38.694151 2026] [security2:error] [pid 230252:tid 230502] [client 103.174.34.15:53109] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Iqk0Dwhk5-Z44XrpJNQAAAw8"]
[Tue Jul 21 07:23:39.120808 2026] [security2:error] [pid 230252:tid 230486] [client 20.151.10.161:26484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Iq00Dwhk5-Z44XrpJOQAAAv8"]
[Tue Jul 21 07:23:39.254008 2026] [security2:error] [pid 230252:tid 230304] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Iq00Dwhk5-Z44XrpJOgAC1zI"]
[Tue Jul 21 07:23:39.254134 2026] [security2:error] [pid 230252:tid 230446] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Iq00Dwhk5-Z44XrpJOgAC1zI"]
[Tue Jul 21 07:23:39.255326 2026] [security2:error] [pid 229246:tid 229255] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IqyBMYeh5YLVG45xtnAACMQg"]
[Tue Jul 21 07:23:39.255437 2026] [security2:error] [pid 229246:tid 229405] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IqyBMYeh5YLVG45xtnAACMQg"]
[Tue Jul 21 07:23:39.262167 2026] [security2:error] [pid 230252:tid 230416] [client 20.104.96.117:62968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/nc4.php"] [unique_id "al9Iq00Dwhk5-Z44XrpJOwAAArk"]
[Tue Jul 21 07:23:39.424636 2026] [security2:error] [pid 230252:tid 230509] [client 20.226.60.151:50782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/cong.php"] [unique_id "al9Iq00Dwhk5-Z44XrpJPAAAAxY"]
[Tue Jul 21 07:23:39.637068 2026] [security2:error] [pid 230252:tid 230414] [client 20.104.96.117:5084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/a1.php"] [unique_id "al9Iq00Dwhk5-Z44XrpJQAAAArc"]
[Tue Jul 21 07:23:39.967085 2026] [security2:error] [pid 230252:tid 230417] [client 20.220.225.223:45966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/la.php"] [unique_id "al9Iq00Dwhk5-Z44XrpJQwAAAro"]
[Tue Jul 21 07:23:40.010995 2026] [security2:error] [pid 230252:tid 230429] [client 213.152.162.104:33660] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9IrE0Dwhk5-Z44XrpJRAAAAsY"]
[Tue Jul 21 07:23:40.011102 2026] [security2:error] [pid 230252:tid 230429] [client 213.152.162.104:33660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9IrE0Dwhk5-Z44XrpJRAAAAsY"]
[Tue Jul 21 07:23:40.026540 2026] [security2:error] [pid 229246:tid 229470] [client 20.104.96.117:64030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/eee.php"] [unique_id "al9IrCBMYeh5YLVG45xtqAAAAnI"]
[Tue Jul 21 07:23:40.147609 2026] [autoindex:error] [pid 230252:tid 230508] [client 20.226.60.151:56877] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:23:40.211365 2026] [autoindex:error] [pid 230252:tid 230497] [client 20.226.60.151:56877] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:23:40.217443 2026] [security2:error] [pid 230252:tid 230412] [client 20.226.60.151:56940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/dr.php"] [unique_id "al9IrE0Dwhk5-Z44XrpJSQAAArU"]
[Tue Jul 21 07:23:40.349957 2026] [security2:error] [pid 229246:tid 229480] [client 175.45.70.82:59362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IrCBMYeh5YLVG45xtqwAAAnw"]
[Tue Jul 21 07:23:40.350151 2026] [security2:error] [pid 229246:tid 229480] [client 175.45.70.82:59362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IrCBMYeh5YLVG45xtqwAAAnw"]
[Tue Jul 21 07:23:40.443835 2026] [security2:error] [pid 230252:tid 230452] [client 20.104.96.117:4180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/wp-aothait.php"] [unique_id "al9IrE0Dwhk5-Z44XrpJSgAAAt0"]
[Tue Jul 21 07:23:40.453642 2026] [security2:error] [pid 230252:tid 230436] [client 20.151.10.161:26424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/2P.php"] [unique_id "al9IrE0Dwhk5-Z44XrpJSwAAAs0"]
[Tue Jul 21 07:23:40.834211 2026] [proxy:error] [pid 229246:tid 229472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:40.834288 2026] [proxy_http:error] [pid 229246:tid 229472] [client 20.226.60.151:60248] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:40.834887 2026] [proxy:error] [pid 229246:tid 229472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:40.834920 2026] [proxy_http:error] [pid 229246:tid 229472] [client 20.226.60.151:60248] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:41.155249 2026] [security2:error] [pid 230252:tid 230507] [client 20.104.96.117:62970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/config.json.php"] [unique_id "al9IrU0Dwhk5-Z44XrpJUgAAAxQ"]
[Tue Jul 21 07:23:41.248880 2026] [security2:error] [pid 230252:tid 230488] [client 74.7.175.185:57158] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.hctreinamentos.net"] [uri "/index.php"] [unique_id "al9IrU0Dwhk5-Z44XrpJUwADAQg"]
[Tue Jul 21 07:23:41.352713 2026] [security2:error] [pid 230252:tid 230476] [client 20.197.192.193:53133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/fffm.php"] [unique_id "al9IrU0Dwhk5-Z44XrpJVAAAAvU"]
[Tue Jul 21 07:23:41.643137 2026] [security2:error] [pid 230252:tid 230419] [client 20.104.96.117:5102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9IrU0Dwhk5-Z44XrpJVwAAArw"]
[Tue Jul 21 07:23:41.800351 2026] [security2:error] [pid 229246:tid 229458] [client 20.226.60.151:56925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/x.php"] [unique_id "al9IrSBMYeh5YLVG45xtvwAAAmY"]
[Tue Jul 21 07:23:41.865392 2026] [security2:error] [pid 229246:tid 229451] [client 193.36.225.63:44221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IrSBMYeh5YLVG45xtvgAAAl8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:41.894389 2026] [security2:error] [pid 229246:tid 229402] [client 20.226.60.151:50793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/public/css.php"] [unique_id "al9IrSBMYeh5YLVG45xtwAAAAi4"]
[Tue Jul 21 07:23:41.963049 2026] [security2:error] [pid 229246:tid 229452] [client 20.151.10.161:26540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/.well-known/about.php"] [unique_id "al9IrSBMYeh5YLVG45xtwgAAAmA"]
[Tue Jul 21 07:23:42.142569 2026] [security2:error] [pid 229246:tid 229459] [client 74.249.245.134:43514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/date.php"] [unique_id "al9IriBMYeh5YLVG45xtwwAAAmc"]
[Tue Jul 21 07:23:42.161525 2026] [security2:error] [pid 230252:tid 230427] [client 20.104.96.117:62944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/k2.php"] [unique_id "al9Irk0Dwhk5-Z44XrpJXQAAAsQ"]
[Tue Jul 21 07:23:42.191438 2026] [security2:error] [pid 229246:tid 229426] [client 139.135.44.145:53186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IriBMYeh5YLVG45xtxQAAAkY"]
[Tue Jul 21 07:23:42.192271 2026] [security2:error] [pid 229246:tid 229426] [client 139.135.44.145:53186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IriBMYeh5YLVG45xtxQAAAkY"]
[Tue Jul 21 07:23:42.220703 2026] [security2:error] [pid 230252:tid 230400] [client 45.251.232.145:56071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Irk0Dwhk5-Z44XrpJXgAAAqk"]
[Tue Jul 21 07:23:42.220800 2026] [security2:error] [pid 230252:tid 230400] [client 45.251.232.145:56071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Irk0Dwhk5-Z44XrpJXgAAAqk"]
[Tue Jul 21 07:23:42.493610 2026] [security2:error] [pid 229246:tid 229421] [client 20.226.60.151:60285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/output.php"] [unique_id "al9IriBMYeh5YLVG45xtygAAAkE"]
[Tue Jul 21 07:23:42.499115 2026] [security2:error] [pid 229246:tid 229456] [client 103.121.156.110:51160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IriBMYeh5YLVG45xtywAAAmQ"]
[Tue Jul 21 07:23:42.499243 2026] [security2:error] [pid 229246:tid 229456] [client 103.121.156.110:51160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IriBMYeh5YLVG45xtywAAAmQ"]
[Tue Jul 21 07:23:42.583243 2026] [security2:error] [pid 230252:tid 230416] [client 213.152.162.104:37556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Irk0Dwhk5-Z44XrpJXwAAArk"]
[Tue Jul 21 07:23:42.583370 2026] [security2:error] [pid 230252:tid 230416] [client 213.152.162.104:37556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Irk0Dwhk5-Z44XrpJXwAAArk"]
[Tue Jul 21 07:23:42.693669 2026] [security2:error] [pid 229246:tid 229429] [client 20.104.96.117:4227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9IriBMYeh5YLVG45xtzAAAAkk"]
[Tue Jul 21 07:23:42.780785 2026] [security2:error] [pid 230252:tid 230482] [client 20.197.192.193:53156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/ftde.php"] [unique_id "al9Irk0Dwhk5-Z44XrpJYQAAAvs"]
[Tue Jul 21 07:23:42.870763 2026] [security2:error] [pid 230252:tid 230458] [client 20.226.60.151:56914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/155.php"] [unique_id "al9Irk0Dwhk5-Z44XrpJYwAAAuM"]
[Tue Jul 21 07:23:42.976337 2026] [security2:error] [pid 229246:tid 229502] [client 20.226.60.151:60235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-file-120.php"] [unique_id "al9IriBMYeh5YLVG45xt0gAAApI"]
[Tue Jul 21 07:23:43.043686 2026] [security2:error] [pid 229246:tid 229467] [client 20.104.96.117:62932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9IryBMYeh5YLVG45xt0wAAAm8"]
[Tue Jul 21 07:23:43.116939 2026] [security2:error] [pid 230252:tid 230358] [remote 69.63.184.23:41596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.184.63.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9Ir00Dwhk5-Z44XrpJZQACmmc"]
[Tue Jul 21 07:23:43.160695 2026] [security2:error] [pid 229246:tid 229400] [client 20.151.10.161:65488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9IryBMYeh5YLVG45xt1AAAAiw"]
[Tue Jul 21 07:23:43.264671 2026] [security2:error] [pid 229246:tid 229411] [client 82.102.28.107:60620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9IryBMYeh5YLVG45xt2AAAAjc"]
[Tue Jul 21 07:23:43.264765 2026] [security2:error] [pid 229246:tid 229411] [client 82.102.28.107:60620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9IryBMYeh5YLVG45xt2AAAAjc"]
[Tue Jul 21 07:23:43.299085 2026] [security2:error] [pid 229246:tid 229381] [client 20.197.192.193:52238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/yup.php"] [unique_id "al9IryBMYeh5YLVG45xt2QAAAhk"]
[Tue Jul 21 07:23:43.428893 2026] [autoindex:error] [pid 229246:tid 229415] [client 54.164.167.77:0] AH01276: Cannot serve directory /home2/jurand34/jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:23:43.444505 2026] [security2:error] [pid 229246:tid 229406] [client 20.197.192.193:52261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/jj.php"] [unique_id "al9IryBMYeh5YLVG45xt3AAAAjI"]
[Tue Jul 21 07:23:43.521806 2026] [security2:error] [pid 229246:tid 229480] [client 20.104.96.117:5119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9IryBMYeh5YLVG45xt4AAAAnw"]
[Tue Jul 21 07:23:43.649768 2026] [security2:error] [pid 229246:tid 229412] [client 20.220.225.223:34295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/hp2.php"] [unique_id "al9IryBMYeh5YLVG45xt4wAAAjg"]
[Tue Jul 21 07:23:43.736476 2026] [security2:error] [pid 230252:tid 230430] [client 20.226.60.151:56837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/ops.php"] [unique_id "al9Ir00Dwhk5-Z44XrpJlgAAAsc"]
[Tue Jul 21 07:23:43.750092 2026] [autoindex:error] [pid 230252:tid 230392] [client 98.91.173.173:0] AH01276: Cannot serve directory /home2/jurand34/jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:23:44.026236 2026] [autoindex:error] [pid 230252:tid 230484] [client 98.91.173.173:0] AH01276: Cannot serve directory /home2/jurand34/jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:23:44.033830 2026] [autoindex:error] [pid 230252:tid 230498] [client 13.219.67.125:0] AH01276: Cannot serve directory /home2/jurand34/jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:23:44.256950 2026] [security2:error] [pid 230252:tid 230478] [client 20.104.96.117:5099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/for.php"] [unique_id "al9IsE0Dwhk5-Z44XrpJpQAAAvc"]
[Tue Jul 21 07:23:44.295177 2026] [security2:error] [pid 230252:tid 230394] [client 20.197.192.193:52270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/dragonshell.php"] [unique_id "al9IsE0Dwhk5-Z44XrpJqAAAAqM"]
[Tue Jul 21 07:23:44.410048 2026] [security2:error] [pid 229246:tid 229491] [client 20.220.225.223:46084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/nhvoanpl.php"] [unique_id "al9IsCBMYeh5YLVG45xt7QAAAoc"]
[Tue Jul 21 07:23:44.456825 2026] [security2:error] [pid 230252:tid 230374] [remote 5.252.52.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tavarescont.com.br"] [uri "/wp-login.php"] [unique_id "al9IsE0Dwhk5-Z44XrpJqQACvHc"]
[Tue Jul 21 07:23:44.458553 2026] [security2:error] [pid 229246:tid 229443] [client 20.151.10.161:49132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/qterm.php"] [unique_id "al9IsCBMYeh5YLVG45xt7gAAAlc"]
[Tue Jul 21 07:23:44.540313 2026] [security2:error] [pid 230252:tid 230450] [client 20.226.60.151:56946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/file31.php"] [unique_id "al9IsE0Dwhk5-Z44XrpJqgAAAts"]
[Tue Jul 21 07:23:44.598161 2026] [security2:error] [pid 229246:tid 229403] [client 20.104.96.117:5107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/raw.php"] [unique_id "al9IsCBMYeh5YLVG45xt8AAAAi8"]
[Tue Jul 21 07:23:44.920946 2026] [security2:error] [pid 230252:tid 230471] [client 20.151.10.161:26502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9IsE0Dwhk5-Z44XrpJsAAAAvA"]
[Tue Jul 21 07:23:45.082407 2026] [security2:error] [pid 229246:tid 229426] [client 20.226.60.151:54573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/122.php"] [unique_id "al9IsSBMYeh5YLVG45xt9gAAAkY"]
[Tue Jul 21 07:23:45.249906 2026] [security2:error] [pid 230252:tid 230254] [remote 34.53.218.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.218.53.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "santaofertas.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IsU0Dwhk5-Z44XrpJswAC-QA"]
[Tue Jul 21 07:23:45.261441 2026] [security2:error] [pid 230252:tid 230401] [client 20.226.60.151:50809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/special.php"] [unique_id "al9IsU0Dwhk5-Z44XrpJtAAAAqo"]
[Tue Jul 21 07:23:45.261676 2026] [security2:error] [pid 230252:tid 230472] [client 20.226.60.151:56867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/file6.php"] [unique_id "al9IsU0Dwhk5-Z44XrpJtQAAAvE"]
[Tue Jul 21 07:23:45.420706 2026] [security2:error] [pid 230252:tid 230270] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9IsU0Dwhk5-Z44XrpJuQACohA"]
[Tue Jul 21 07:23:45.477666 2026] [security2:error] [pid 230252:tid 230467] [client 103.162.129.114:52688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IsU0Dwhk5-Z44XrpJuwAAAuw"]
[Tue Jul 21 07:23:45.477845 2026] [security2:error] [pid 230252:tid 230467] [client 103.162.129.114:52688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IsU0Dwhk5-Z44XrpJuwAAAuw"]
[Tue Jul 21 07:23:45.563979 2026] [security2:error] [pid 230252:tid 230272] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9IsU0Dwhk5-Z44XrpJvAAC1RI"]
[Tue Jul 21 07:23:45.690719 2026] [security2:error] [pid 229246:tid 229447] [client 14.139.42.196:13682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IsSBMYeh5YLVG45xt-wAAAls"]
[Tue Jul 21 07:23:45.690865 2026] [security2:error] [pid 229246:tid 229447] [client 14.139.42.196:13682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IsSBMYeh5YLVG45xt-wAAAls"]
[Tue Jul 21 07:23:45.707057 2026] [security2:error] [pid 230252:tid 230381] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9IsU0Dwhk5-Z44XrpJvgADFX4"]
[Tue Jul 21 07:23:45.794568 2026] [security2:error] [pid 229246:tid 229497] [client 20.151.10.161:65441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9IsSBMYeh5YLVG45xt_AAAAo0"]
[Tue Jul 21 07:23:45.847770 2026] [security2:error] [pid 230252:tid 230349] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9IsU0Dwhk5-Z44XrpJwgACoV4"]
[Tue Jul 21 07:23:46.010510 2026] [security2:error] [pid 230252:tid 230328] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9Isk0Dwhk5-Z44XrpJwwAC8kk"]
[Tue Jul 21 07:23:46.123260 2026] [security2:error] [pid 230252:tid 230385] [client 117.251.86.144:58942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Isk0Dwhk5-Z44XrpJxgAAApo"]
[Tue Jul 21 07:23:46.123378 2026] [security2:error] [pid 230252:tid 230385] [client 117.251.86.144:58942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Isk0Dwhk5-Z44XrpJxgAAApo"]
[Tue Jul 21 07:23:46.193284 2026] [security2:error] [pid 230252:tid 230314] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9Isk0Dwhk5-Z44XrpJxwAC9Dw"]
[Tue Jul 21 07:23:46.381733 2026] [security2:error] [pid 230252:tid 230292] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9Isk0Dwhk5-Z44XrpJzgAC8yY"]
[Tue Jul 21 07:23:46.413138 2026] [security2:error] [pid 230252:tid 230448] [client 74.249.245.134:61767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/pomo.php"] [unique_id "al9Isk0Dwhk5-Z44XrpJzwAAAtk"]
[Tue Jul 21 07:23:46.472240 2026] [security2:error] [pid 230252:tid 230277] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Isk0Dwhk5-Z44XrpJ0AADEBc"]
[Tue Jul 21 07:23:46.472345 2026] [security2:error] [pid 230252:tid 230503] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Isk0Dwhk5-Z44XrpJ0AADEBc"]
[Tue Jul 21 07:23:46.531221 2026] [security2:error] [pid 230252:tid 230325] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Isk0Dwhk5-Z44XrpJ0QAC6UY"]
[Tue Jul 21 07:23:46.638220 2026] [security2:error] [pid 230252:tid 230431] [client 20.197.192.193:53134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/wp-mt.php"] [unique_id "al9Isk0Dwhk5-Z44XrpJ0wAAAsg"]
[Tue Jul 21 07:23:46.733588 2026] [security2:error] [pid 230252:tid 230347] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Isk0Dwhk5-Z44XrpJ1wACmVw"]
[Tue Jul 21 07:23:46.761212 2026] [security2:error] [pid 230252:tid 230411] [client 103.191.123.19:30018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.123.191.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "girassollimpeza.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Isk0Dwhk5-Z44XrpJ2AAAArQ"]
[Tue Jul 21 07:23:46.761331 2026] [security2:error] [pid 230252:tid 230411] [client 103.191.123.19:30018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "girassollimpeza.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Isk0Dwhk5-Z44XrpJ2AAAArQ"]
[Tue Jul 21 07:23:46.779618 2026] [security2:error] [pid 230252:tid 230459] [client 193.36.225.54:52569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Isk0Dwhk5-Z44XrpJ2QAAAuQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:46.873808 2026] [security2:error] [pid 230252:tid 230487] [client 20.220.225.223:45997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/inso.php"] [unique_id "al9Isk0Dwhk5-Z44XrpJ3QAAAwA"]
[Tue Jul 21 07:23:46.945854 2026] [security2:error] [pid 230252:tid 230289] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Isk0Dwhk5-Z44XrpJ3gACxCM"]
[Tue Jul 21 07:23:47.075201 2026] [security2:error] [pid 230252:tid 230445] [client 74.249.245.134:61439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/test1.php"] [unique_id "al9Is00Dwhk5-Z44XrpJ4AAAAtY"]
[Tue Jul 21 07:23:47.077431 2026] [security2:error] [pid 229246:tid 229423] [client 20.220.225.223:34490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/hp3.php"] [unique_id "al9IsyBMYeh5YLVG45xuCQAAAkM"]
[Tue Jul 21 07:23:47.213309 2026] [security2:error] [pid 230252:tid 230458] [client 20.151.10.161:26436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/bob.php"] [unique_id "al9Is00Dwhk5-Z44XrpJ4QAAAuM"]
[Tue Jul 21 07:23:47.260903 2026] [security2:error] [pid 230252:tid 230313] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9Is00Dwhk5-Z44XrpJ4wAC_Ds"]
[Tue Jul 21 07:23:47.293287 2026] [security2:error] [pid 230252:tid 230350] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Is00Dwhk5-Z44XrpJ5QAC518"]
[Tue Jul 21 07:23:47.293440 2026] [security2:error] [pid 230252:tid 230462] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Is00Dwhk5-Z44XrpJ5QAC518"]
[Tue Jul 21 07:23:47.480987 2026] [security2:error] [pid 230252:tid 230444] [client 20.151.10.161:63695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/media.php"] [unique_id "al9Is00Dwhk5-Z44XrpJ6AAAAtU"]
[Tue Jul 21 07:23:47.481910 2026] [security2:error] [pid 230252:tid 230274] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9Is00Dwhk5-Z44XrpJ6QAC0BQ"]
[Tue Jul 21 07:23:47.515175 2026] [security2:error] [pid 230252:tid 230321] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Is00Dwhk5-Z44XrpJ6gACokM"]
[Tue Jul 21 07:23:47.515330 2026] [security2:error] [pid 230252:tid 230393] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Is00Dwhk5-Z44XrpJ6gACokM"]
[Tue Jul 21 07:23:47.613658 2026] [security2:error] [pid 230252:tid 230344] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Is00Dwhk5-Z44XrpJ7AAC9lk"]
[Tue Jul 21 07:23:47.613786 2026] [security2:error] [pid 230252:tid 230477] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Is00Dwhk5-Z44XrpJ7AAC9lk"]
[Tue Jul 21 07:23:48.448810 2026] [autoindex:error] [pid 230252:tid 230484] [client 20.226.60.151:56847] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:23:48.479955 2026] [security2:error] [pid 229246:tid 229398] [client 20.226.60.151:56922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/adminfuns.php"] [unique_id "al9ItCBMYeh5YLVG45xuIAAAAio"]
[Tue Jul 21 07:23:48.493159 2026] [security2:error] [pid 229246:tid 229441] [client 74.249.245.134:21938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/fw.php"] [unique_id "al9ItCBMYeh5YLVG45xuIgAAAlU"]
[Tue Jul 21 07:23:48.740329 2026] [security2:error] [pid 230252:tid 230459] [client 20.226.60.151:60280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/as.php"] [unique_id "al9ItE0Dwhk5-Z44XrpJ_AAAAuQ"]
[Tue Jul 21 07:23:48.818766 2026] [access_compat:error] [pid 230252:tid 230486] [client 162.241.63.68:53204] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:23:49.010586 2026] [security2:error] [pid 230252:tid 230458] [client 149.102.142.63:44864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "bomexito.com.br"] [uri "/"] [unique_id "al9ItU0Dwhk5-Z44XrpKAQAAAuM"]
[Tue Jul 21 07:23:49.251554 2026] [security2:error] [pid 230252:tid 230432] [client 20.151.10.161:49126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/blurbs.php"] [unique_id "al9ItU0Dwhk5-Z44XrpKBgAAAsk"]
[Tue Jul 21 07:23:49.401066 2026] [security2:error] [pid 230252:tid 230412] [client 20.151.10.161:65480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/images.php"] [unique_id "al9ItU0Dwhk5-Z44XrpKBwAAArU"]
[Tue Jul 21 07:23:49.680668 2026] [security2:error] [pid 230252:tid 230440] [client 103.174.34.15:53587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ItU0Dwhk5-Z44XrpKCwAAAtE"]
[Tue Jul 21 07:23:49.680775 2026] [security2:error] [pid 230252:tid 230440] [client 103.174.34.15:53587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ItU0Dwhk5-Z44XrpKCwAAAtE"]
[Tue Jul 21 07:23:49.742029 2026] [security2:error] [pid 230252:tid 230430] [client 142.44.228.250:53658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "egcbatiment.com"] [uri "/robots.txt"] [unique_id "al9ItU0Dwhk5-Z44XrpKDAAAAsc"]
[Tue Jul 21 07:23:49.742115 2026] [security2:error] [pid 230252:tid 230430] [client 142.44.228.250:53658] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "egcbatiment.com"] [uri "/robots.txt"] [unique_id "al9ItU0Dwhk5-Z44XrpKDAAAAsc"]
[Tue Jul 21 07:23:49.918186 2026] [security2:error] [pid 229246:tid 229459] [client 20.226.60.151:56912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/goods.php"] [unique_id "al9ItSBMYeh5YLVG45xuQgAAAmc"]
[Tue Jul 21 07:23:49.920220 2026] [security2:error] [pid 229246:tid 229249] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9ItSBMYeh5YLVG45xuQwACMwI"]
[Tue Jul 21 07:23:49.920341 2026] [security2:error] [pid 229246:tid 229407] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9ItSBMYeh5YLVG45xuQwACMwI"]
[Tue Jul 21 07:23:49.999702 2026] [security2:error] [pid 229246:tid 229298] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9ItSBMYeh5YLVG45xuRgACdTM"]
[Tue Jul 21 07:23:49.999854 2026] [security2:error] [pid 229246:tid 229473] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9ItSBMYeh5YLVG45xuRgACdTM"]
[Tue Jul 21 07:23:50.000163 2026] [security2:error] [pid 229246:tid 229462] [client 20.220.225.223:34242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/aa1.php"] [unique_id "al9ItSBMYeh5YLVG45xuRwAAAmo"]
[Tue Jul 21 07:23:50.316774 2026] [security2:error] [pid 229246:tid 229475] [client 20.226.60.151:50712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9ItiBMYeh5YLVG45xuVgAAAnc"]
[Tue Jul 21 07:23:50.661961 2026] [security2:error] [pid 230252:tid 230449] [client 20.220.225.223:45989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wpx.php"] [unique_id "al9Itk0Dwhk5-Z44XrpKEQAAAto"]
[Tue Jul 21 07:23:50.832996 2026] [security2:error] [pid 230252:tid 230441] [client 20.226.60.151:56934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/100.php"] [unique_id "al9Itk0Dwhk5-Z44XrpKFAAAAtI"]
[Tue Jul 21 07:23:51.042955 2026] [security2:error] [pid 230252:tid 230471] [client 74.249.245.134:33793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/fm.php"] [unique_id "al9It00Dwhk5-Z44XrpKGQAAAvA"]
[Tue Jul 21 07:23:51.136515 2026] [security2:error] [pid 229246:tid 229376] [client 175.45.70.82:59865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ItyBMYeh5YLVG45xubgAAAhQ"]
[Tue Jul 21 07:23:51.136661 2026] [security2:error] [pid 229246:tid 229376] [client 175.45.70.82:59865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ItyBMYeh5YLVG45xubgAAAhQ"]
[Tue Jul 21 07:23:51.173305 2026] [security2:error] [pid 230252:tid 230445] [client 213.152.162.104:56110] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9It00Dwhk5-Z44XrpKHwAAAtY"]
[Tue Jul 21 07:23:51.173393 2026] [security2:error] [pid 230252:tid 230445] [client 213.152.162.104:56110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9It00Dwhk5-Z44XrpKHwAAAtY"]
[Tue Jul 21 07:23:51.223048 2026] [security2:error] [pid 230252:tid 230401] [client 20.151.10.161:49056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/v543.php"] [unique_id "al9It00Dwhk5-Z44XrpKIAAAAqo"]
[Tue Jul 21 07:23:51.233380 2026] [security2:error] [pid 230252:tid 230458] [client 20.220.225.223:34271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/acew67.php"] [unique_id "al9It00Dwhk5-Z44XrpKIQAAAuM"]
[Tue Jul 21 07:23:51.310786 2026] [security2:error] [pid 230252:tid 230466] [client 51.222.168.44:40780] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "egcbatiment.com"] [uri "/"] [unique_id "al9It00Dwhk5-Z44XrpKIwAAAus"]
[Tue Jul 21 07:23:51.310907 2026] [security2:error] [pid 230252:tid 230466] [client 51.222.168.44:40780] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "egcbatiment.com"] [uri "/"] [unique_id "al9It00Dwhk5-Z44XrpKIwAAAus"]
[Tue Jul 21 07:23:51.365447 2026] [security2:error] [pid 229246:tid 229415] [client 20.151.10.161:26465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/crgio.php"] [unique_id "al9ItyBMYeh5YLVG45xucAAAAjs"]
[Tue Jul 21 07:23:51.445774 2026] [security2:error] [pid 230252:tid 230282] [remote 192.241.143.148:35532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "woma.com.br"] [uri "/wp-login.php"] [unique_id "al9It00Dwhk5-Z44XrpKJAADFhw"]
[Tue Jul 21 07:23:51.683282 2026] [security2:error] [pid 230252:tid 230396] [client 20.226.60.151:54483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/mds.php"] [unique_id "al9It00Dwhk5-Z44XrpKKgAAAqU"]
[Tue Jul 21 07:23:51.711857 2026] [security2:error] [pid 229246:tid 229451] [client 136.144.33.53:55811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9ItyBMYeh5YLVG45xudgAAAl8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:51.736009 2026] [security2:error] [pid 229246:tid 229492] [client 20.151.10.161:65506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/adminner.php"] [unique_id "al9ItyBMYeh5YLVG45xueAAAAog"]
[Tue Jul 21 07:23:51.910010 2026] [security2:error] [pid 230252:tid 230432] [client 20.226.60.151:56884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/about.php"] [unique_id "al9It00Dwhk5-Z44XrpKKwAAAsk"]
[Tue Jul 21 07:23:51.937520 2026] [security2:error] [pid 230252:tid 230388] [client 82.102.28.107:35904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9It00Dwhk5-Z44XrpKLAAAAp0"]
[Tue Jul 21 07:23:51.937625 2026] [security2:error] [pid 230252:tid 230388] [client 82.102.28.107:35904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9It00Dwhk5-Z44XrpKLAAAAp0"]
[Tue Jul 21 07:23:52.149161 2026] [security2:error] [pid 230252:tid 230475] [client 74.249.245.134:60041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/ini.php"] [unique_id "al9IuE0Dwhk5-Z44XrpKMgAAAvQ"]
[Tue Jul 21 07:23:52.562987 2026] [security2:error] [pid 230252:tid 230423] [client 20.226.60.151:50774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/w1px.php"] [unique_id "al9IuE0Dwhk5-Z44XrpKNAAAAsA"]
[Tue Jul 21 07:23:52.701300 2026] [security2:error] [pid 229246:tid 229417] [client 213.152.162.104:48302] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IuCBMYeh5YLVG45xuhwAAAj0"]
[Tue Jul 21 07:23:52.701424 2026] [security2:error] [pid 229246:tid 229417] [client 213.152.162.104:48302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IuCBMYeh5YLVG45xuhwAAAj0"]
[Tue Jul 21 07:23:52.712943 2026] [security2:error] [pid 230252:tid 230422] [client 45.251.232.145:56593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IuE0Dwhk5-Z44XrpKOQAAAr8"]
[Tue Jul 21 07:23:52.713052 2026] [security2:error] [pid 230252:tid 230422] [client 45.251.232.145:56593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IuE0Dwhk5-Z44XrpKOQAAAr8"]
[Tue Jul 21 07:23:53.226263 2026] [security2:error] [pid 229246:tid 229384] [client 103.121.156.110:51483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IuSBMYeh5YLVG45xukAAAAhw"]
[Tue Jul 21 07:23:53.226411 2026] [security2:error] [pid 229246:tid 229384] [client 103.121.156.110:51483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IuSBMYeh5YLVG45xukAAAAhw"]
[Tue Jul 21 07:23:53.240185 2026] [security2:error] [pid 229246:tid 229464] [client 20.151.10.161:49115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/w3lls.php"] [unique_id "al9IuSBMYeh5YLVG45xukQAAAmw"]
[Tue Jul 21 07:23:53.281591 2026] [security2:error] [pid 229246:tid 229474] [client 20.226.60.151:54491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-blink.php"] [unique_id "al9IuSBMYeh5YLVG45xukgAAAnY"]
[Tue Jul 21 07:23:53.602993 2026] [security2:error] [pid 229246:tid 229338] [remote 64.225.121.94:42798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/wp-login.php"] [unique_id "al9IuSBMYeh5YLVG45xulQACLVs"]
[Tue Jul 21 07:23:53.717152 2026] [security2:error] [pid 230252:tid 230291] [remote 14.128.14.9:47744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.14.128.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buyonlinetodayatadiscount.net"] [uri "/wp-login.php"] [unique_id "al9IuE0Dwhk5-Z44XrpKOgACmiU"]
[Tue Jul 21 07:23:53.748586 2026] [security2:error] [pid 230252:tid 230487] [client 20.226.60.151:56878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/about.php"] [unique_id "al9IuU0Dwhk5-Z44XrpKPQAAAwA"]
[Tue Jul 21 07:23:54.268377 2026] [security2:error] [pid 230252:tid 230409] [client 139.135.44.145:54021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Iuk0Dwhk5-Z44XrpKQAAAArI"]
[Tue Jul 21 07:23:54.268489 2026] [security2:error] [pid 230252:tid 230409] [client 139.135.44.145:54021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Iuk0Dwhk5-Z44XrpKQAAAArI"]
[Tue Jul 21 07:23:54.372496 2026] [security2:error] [pid 229246:tid 229432] [client 20.226.60.151:60212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/yawa.php"] [unique_id "al9IuiBMYeh5YLVG45xupgAAAkw"]
[Tue Jul 21 07:23:54.420925 2026] [security2:error] [pid 229246:tid 229291] [remote 72.167.132.114:33250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "loopfinancas.com"] [uri "/wp-login.php"] [unique_id "al9IuiBMYeh5YLVG45xupwACQyw"]
[Tue Jul 21 07:23:54.514562 2026] [security2:error] [pid 230252:tid 230483] [client 20.151.10.161:49032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-ws68.php"] [unique_id "al9Iuk0Dwhk5-Z44XrpKQQAAAvw"]
[Tue Jul 21 07:23:54.557990 2026] [security2:error] [pid 229246:tid 229470] [client 20.220.225.223:46117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/berlin.php"] [unique_id "al9IuiBMYeh5YLVG45xuqgAAAnI"]
[Tue Jul 21 07:23:54.726647 2026] [security2:error] [pid 229246:tid 229398] [client 20.226.60.151:63296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/admin.php"] [unique_id "al9IuiBMYeh5YLVG45xurgAAAio"]
[Tue Jul 21 07:23:54.782232 2026] [security2:error] [pid 230252:tid 230444] [client 74.249.245.134:61798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/themes.php"] [unique_id "al9Iuk0Dwhk5-Z44XrpKRQAAAtU"]
[Tue Jul 21 07:23:54.811167 2026] [security2:error] [pid 230252:tid 230468] [client 20.197.192.193:53165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/ww.php"] [unique_id "al9Iuk0Dwhk5-Z44XrpKRwAAAu0"]
[Tue Jul 21 07:23:55.042414 2026] [security2:error] [pid 229246:tid 229477] [client 20.151.10.161:26541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/pucci.php"] [unique_id "al9IuyBMYeh5YLVG45xutgAAAnk"]
[Tue Jul 21 07:23:55.226453 2026] [security2:error] [pid 229246:tid 229454] [client 20.226.60.151:54481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/zc-208.php"] [unique_id "al9IuyBMYeh5YLVG45xuuAAAAmI"]
[Tue Jul 21 07:23:55.281945 2026] [security2:error] [pid 229246:tid 229384] [client 20.226.60.151:56897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/admin.php"] [unique_id "al9IuyBMYeh5YLVG45xuuwAAAhw"]
[Tue Jul 21 07:23:55.289153 2026] [security2:error] [pid 230252:tid 230392] [client 20.151.10.161:65428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/admin.php"] [unique_id "al9Iu00Dwhk5-Z44XrpKSwAAAqE"]
[Tue Jul 21 07:23:55.362413 2026] [security2:error] [pid 230252:tid 230499] [client 20.220.225.223:46014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/billur.php"] [unique_id "al9Iu00Dwhk5-Z44XrpKTAAAAww"]
[Tue Jul 21 07:23:55.550334 2026] [security2:error] [pid 230252:tid 230410] [client 20.151.10.161:49035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/xyn.php"] [unique_id "al9Iu00Dwhk5-Z44XrpKTQAAArM"]
[Tue Jul 21 07:23:56.099939 2026] [security2:error] [pid 230252:tid 230430] [client 20.226.60.151:60220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/js.php"] [unique_id "al9IvE0Dwhk5-Z44XrpKTgAAAsc"]
[Tue Jul 21 07:23:56.236715 2026] [security2:error] [pid 229246:tid 229485] [client 103.162.129.114:53146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IvCBMYeh5YLVG45xuyQAAAoE"]
[Tue Jul 21 07:23:56.237677 2026] [security2:error] [pid 229246:tid 229485] [client 103.162.129.114:53146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IvCBMYeh5YLVG45xuyQAAAoE"]
[Tue Jul 21 07:23:56.585903 2026] [security2:error] [pid 230252:tid 230456] [client 20.151.10.161:49039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/green3.php"] [unique_id "al9IvE0Dwhk5-Z44XrpKUAAAAuE"]
[Tue Jul 21 07:23:56.775941 2026] [security2:error] [pid 229246:tid 229308] [remote 160.187.68.132:55742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9IvCBMYeh5YLVG45xu0AACej0"]
[Tue Jul 21 07:23:56.844691 2026] [security2:error] [pid 229246:tid 229402] [client 117.251.86.144:46802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9IvCBMYeh5YLVG45xu0wAAAi4"]
[Tue Jul 21 07:23:56.844824 2026] [security2:error] [pid 229246:tid 229402] [client 117.251.86.144:46802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9IvCBMYeh5YLVG45xu0wAAAi4"]
[Tue Jul 21 07:23:56.880100 2026] [security2:error] [pid 229246:tid 229406] [client 20.226.60.151:50804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/core.php"] [unique_id "al9IvCBMYeh5YLVG45xu2AAAAjI"]
[Tue Jul 21 07:23:56.955613 2026] [security2:error] [pid 229246:tid 229413] [client 20.151.10.161:65511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/k.php"] [unique_id "al9IvCBMYeh5YLVG45xu2QAAAjk"]
[Tue Jul 21 07:23:56.986273 2026] [security2:error] [pid 230252:tid 230341] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IvE0Dwhk5-Z44XrpKUgACxlY"]
[Tue Jul 21 07:23:56.986382 2026] [security2:error] [pid 230252:tid 230429] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IvE0Dwhk5-Z44XrpKUgACxlY"]
[Tue Jul 21 07:23:57.184110 2026] [security2:error] [pid 229246:tid 229480] [client 172.245.102.45:49109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IvCBMYeh5YLVG45xuxwAAAnw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:57.299845 2026] [security2:error] [pid 229246:tid 229411] [client 20.226.60.151:56941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/themes.php"] [unique_id "al9IvSBMYeh5YLVG45xu3QAAAjc"]
[Tue Jul 21 07:23:57.750470 2026] [security2:error] [pid 230252:tid 230476] [client 20.220.225.223:46085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/mimpi.php"] [unique_id "al9IvU0Dwhk5-Z44XrpKVQAAAvU"]
[Tue Jul 21 07:23:57.790411 2026] [security2:error] [pid 229246:tid 229479] [client 20.226.60.151:54557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/sid4.php"] [unique_id "al9IvSBMYeh5YLVG45xu4gAAAns"]
[Tue Jul 21 07:23:57.963293 2026] [security2:error] [pid 229246:tid 229452] [client 20.226.60.151:60208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/19.php"] [unique_id "al9IvSBMYeh5YLVG45xu7QAAAmA"]
[Tue Jul 21 07:23:58.048326 2026] [security2:error] [pid 229246:tid 229254] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IviBMYeh5YLVG45xu7gACbAc"]
[Tue Jul 21 07:23:58.048487 2026] [security2:error] [pid 229246:tid 229464] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IviBMYeh5YLVG45xu7gACbAc"]
[Tue Jul 21 07:23:58.054357 2026] [security2:error] [pid 229246:tid 229474] [client 20.151.10.161:65422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/x.php"] [unique_id "al9IviBMYeh5YLVG45xu7wAAAnY"]
[Tue Jul 21 07:23:58.066082 2026] [security2:error] [pid 229246:tid 229489] [client 20.151.10.161:26539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-temp.php"] [unique_id "al9IviBMYeh5YLVG45xu8AAAAoU"]
[Tue Jul 21 07:23:58.088153 2026] [security2:error] [pid 229246:tid 229420] [client 74.249.245.134:56475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/dropdown.php"] [unique_id "al9IviBMYeh5YLVG45xu8QAAAkA"]
[Tue Jul 21 07:23:58.100097 2026] [security2:error] [pid 230252:tid 230376] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ivk0Dwhk5-Z44XrpKWQADEHk"]
[Tue Jul 21 07:23:58.100242 2026] [security2:error] [pid 230252:tid 230503] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ivk0Dwhk5-Z44XrpKWQADEHk"]
[Tue Jul 21 07:23:58.101407 2026] [security2:error] [pid 229246:tid 229249] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IviBMYeh5YLVG45xu8gACMwI"]
[Tue Jul 21 07:23:58.101539 2026] [security2:error] [pid 229246:tid 229407] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IviBMYeh5YLVG45xu8gACMwI"]
[Tue Jul 21 07:23:58.487359 2026] [security2:error] [pid 229246:tid 229457] [client 20.197.192.193:52260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/cron.php"] [unique_id "al9IviBMYeh5YLVG45xu9wAAAmU"]
[Tue Jul 21 07:23:59.108529 2026] [security2:error] [pid 229246:tid 229423] [client 20.151.10.161:26396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9IvyBMYeh5YLVG45xvCQAAAkM"]
[Tue Jul 21 07:23:59.123345 2026] [security2:error] [pid 229246:tid 229461] [client 20.226.60.151:50778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/inc.php"] [unique_id "al9IvyBMYeh5YLVG45xvCgAAAmk"]
[Tue Jul 21 07:23:59.139303 2026] [security2:error] [pid 229246:tid 229353] [remote 142.93.10.93:49200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.10.93.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "imperdivelbestpromotionofthedaytodayonly.com"] [uri "/wp-login.php"] [unique_id "al9IvyBMYeh5YLVG45xvCwACbmo"]
[Tue Jul 21 07:23:59.202190 2026] [security2:error] [pid 229246:tid 229413] [client 20.151.10.161:65450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wss.php"] [unique_id "al9IvyBMYeh5YLVG45xvDAAAAjk"]
[Tue Jul 21 07:23:59.437519 2026] [security2:error] [pid 229246:tid 229408] [client 74.249.245.134:60036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-links.php"] [unique_id "al9IvyBMYeh5YLVG45xvEQAAAjQ"]
[Tue Jul 21 07:24:00.000024 2026] [security2:error] [pid 230252:tid 230400] [client 20.151.10.161:65426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/ty.php"] [unique_id "al9Iv00Dwhk5-Z44XrpKXwAAAqk"]
[Tue Jul 21 07:24:00.108051 2026] [security2:error] [pid 230252:tid 230389] [client 20.151.10.161:26533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/puc.php"] [unique_id "al9IwE0Dwhk5-Z44XrpKYwAAAp4"]
[Tue Jul 21 07:24:00.432804 2026] [security2:error] [pid 229246:tid 229398] [client 103.174.34.15:54060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IwCBMYeh5YLVG45xvJAAAAio"]
[Tue Jul 21 07:24:00.432966 2026] [security2:error] [pid 229246:tid 229398] [client 103.174.34.15:54060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IwCBMYeh5YLVG45xvJAAAAio"]
[Tue Jul 21 07:24:00.515318 2026] [security2:error] [pid 230252:tid 230451] [client 20.226.60.151:60267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9IwE0Dwhk5-Z44XrpKZwAAAtw"]
[Tue Jul 21 07:24:00.596094 2026] [security2:error] [pid 229246:tid 229262] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IwCBMYeh5YLVG45xvJgACZQ8"]
[Tue Jul 21 07:24:00.596214 2026] [security2:error] [pid 229246:tid 229457] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IwCBMYeh5YLVG45xvJgACZQ8"]
[Tue Jul 21 07:24:00.752701 2026] [security2:error] [pid 229246:tid 229360] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IwCBMYeh5YLVG45xvKAACJnE"]
[Tue Jul 21 07:24:00.752880 2026] [security2:error] [pid 229246:tid 229394] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IwCBMYeh5YLVG45xvKAACJnE"]
[Tue Jul 21 07:24:01.363547 2026] [security2:error] [pid 230252:tid 230412] [client 20.151.10.161:26423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/themes.php"] [unique_id "al9IwU0Dwhk5-Z44XrpKawAAArU"]
[Tue Jul 21 07:24:01.623566 2026] [security2:error] [pid 229246:tid 229388] [client 20.226.60.151:50692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9IwSBMYeh5YLVG45xvOAAAAiA"]
[Tue Jul 21 07:24:01.736826 2026] [security2:error] [pid 229246:tid 229431] [client 175.45.70.82:60364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IwSBMYeh5YLVG45xvOgAAAks"]
[Tue Jul 21 07:24:01.736960 2026] [security2:error] [pid 229246:tid 229431] [client 175.45.70.82:60364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IwSBMYeh5YLVG45xvOgAAAks"]
[Tue Jul 21 07:24:01.780414 2026] [security2:error] [pid 229246:tid 229415] [client 74.249.245.134:61983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/xmrlpc.php"] [unique_id "al9IwSBMYeh5YLVG45xvOwAAAjs"]
[Tue Jul 21 07:24:01.870263 2026] [security2:error] [pid 230252:tid 230430] [client 20.151.10.161:65483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/155.php"] [unique_id "al9IwU0Dwhk5-Z44XrpKcAAAAsc"]
[Tue Jul 21 07:24:01.903309 2026] [security2:error] [pid 229246:tid 229408] [client 20.197.192.193:53163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/xxx.php"] [unique_id "al9IwSBMYeh5YLVG45xvPgAAAjQ"]
[Tue Jul 21 07:24:01.942449 2026] [security2:error] [pid 229246:tid 229479] [client 20.226.60.151:54499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wmore1.php"] [unique_id "al9IwSBMYeh5YLVG45xvQAAAAns"]
[Tue Jul 21 07:24:02.094373 2026] [security2:error] [pid 229246:tid 229472] [client 20.220.225.223:34283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/bscclapb.php"] [unique_id "al9IwiBMYeh5YLVG45xvRQAAAnQ"]
[Tue Jul 21 07:24:02.137084 2026] [autoindex:error] [pid 229246:tid 229412] [client 20.226.60.151:56849] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:24:02.351526 2026] [security2:error] [pid 229246:tid 229437] [client 193.36.225.72:24899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IwiBMYeh5YLVG45xvSgAAAlE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:24:02.426026 2026] [security2:error] [pid 230252:tid 230454] [client 103.106.20.201:55911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IwU0Dwhk5-Z44XrpKbQAAAt8"]
[Tue Jul 21 07:24:02.426209 2026] [security2:error] [pid 230252:tid 230454] [client 103.106.20.201:55911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IwU0Dwhk5-Z44XrpKbQAAAt8"]
[Tue Jul 21 07:24:02.476674 2026] [security2:error] [pid 230252:tid 230429] [client 20.151.10.161:26371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/dx.php"] [unique_id "al9Iwk0Dwhk5-Z44XrpKdgAAAsY"]
[Tue Jul 21 07:24:02.858446 2026] [security2:error] [pid 229246:tid 229407] [client 74.249.245.134:50592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/htaccess.php"] [unique_id "al9IwiBMYeh5YLVG45xvUAAAAjM"]
[Tue Jul 21 07:24:02.889215 2026] [security2:error] [pid 229246:tid 229384] [client 20.151.10.161:63688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/ops.php"] [unique_id "al9IwiBMYeh5YLVG45xvUQAAAhw"]
[Tue Jul 21 07:24:03.200171 2026] [security2:error] [pid 230252:tid 230508] [client 45.251.232.145:57126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Iw00Dwhk5-Z44XrpKfQAAAxU"]
[Tue Jul 21 07:24:03.200277 2026] [security2:error] [pid 230252:tid 230508] [client 45.251.232.145:57126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Iw00Dwhk5-Z44XrpKfQAAAxU"]
[Tue Jul 21 07:24:03.302341 2026] [security2:error] [pid 229246:tid 229494] [client 20.151.10.161:26518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/p.php"] [unique_id "al9IwyBMYeh5YLVG45xvWAAAAoo"]
[Tue Jul 21 07:24:03.401653 2026] [security2:error] [pid 230252:tid 230400] [client 20.197.192.193:53144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/hunter.php"] [unique_id "al9Iw00Dwhk5-Z44XrpKhQAAAqk"]
[Tue Jul 21 07:24:03.449431 2026] [security2:error] [pid 230252:tid 230478] [client 20.220.225.223:34301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/else1.php"] [unique_id "al9Iw00Dwhk5-Z44XrpKiAAAAvc"]
[Tue Jul 21 07:24:03.846598 2026] [security2:error] [pid 230252:tid 230431] [client 103.121.156.110:51808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Iw00Dwhk5-Z44XrpKjQAAAsg"]
[Tue Jul 21 07:24:03.846744 2026] [security2:error] [pid 230252:tid 230431] [client 103.121.156.110:51808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Iw00Dwhk5-Z44XrpKjQAAAsg"]
[Tue Jul 21 07:24:03.911181 2026] [security2:error] [pid 230252:tid 230396] [client 20.226.60.151:60255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/ss.php"] [unique_id "al9Iw00Dwhk5-Z44XrpKjgAAAqU"]
[Tue Jul 21 07:24:03.926025 2026] [security2:error] [pid 230252:tid 230377] [remote 37.156.145.146:36316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.145.156.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tryhealth.shop"] [uri "/wp-login.php"] [unique_id "al9Iw00Dwhk5-Z44XrpKjwACpno"]
[Tue Jul 21 07:24:04.027190 2026] [security2:error] [pid 230252:tid 230455] [client 20.151.10.161:49117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/ccs.php"] [unique_id "al9IxE0Dwhk5-Z44XrpKkQAAAuA"]
[Tue Jul 21 07:24:04.152764 2026] [security2:error] [pid 230252:tid 230482] [client 139.135.44.145:54884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IxE0Dwhk5-Z44XrpKkwAAAvs"]
[Tue Jul 21 07:24:04.152907 2026] [security2:error] [pid 230252:tid 230482] [client 139.135.44.145:54884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IxE0Dwhk5-Z44XrpKkwAAAvs"]
[Tue Jul 21 07:24:04.525358 2026] [security2:error] [pid 229246:tid 229466] [client 20.151.10.161:26486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/bthil.php"] [unique_id "al9IxCBMYeh5YLVG45xvZwAAAm4"]
[Tue Jul 21 07:24:04.647496 2026] [security2:error] [pid 230252:tid 230440] [client 20.151.10.161:49041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/ccc.php"] [unique_id "al9IxE0Dwhk5-Z44XrpKlgAAAtE"]
[Tue Jul 21 07:24:04.815455 2026] [security2:error] [pid 230252:tid 230496] [client 20.151.10.161:65451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/ingfo.php"] [unique_id "al9IxE0Dwhk5-Z44XrpKmgAAAwk"]
[Tue Jul 21 07:24:04.925312 2026] [security2:error] [pid 230252:tid 230447] [client 172.236.52.146:55540] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "shop-website.oficialwebsite.com.br"] [uri "/"] [unique_id "al9IxE0Dwhk5-Z44XrpKnQAAAtg"]
[Tue Jul 21 07:24:05.204516 2026] [security2:error] [pid 229246:tid 229484] [client 20.151.10.161:65430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/error_log.php"] [unique_id "al9IxSBMYeh5YLVG45xvbQAAAoA"]
[Tue Jul 21 07:24:05.433544 2026] [security2:error] [pid 229246:tid 229451] [client 20.226.60.151:50730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/min.php"] [unique_id "al9IxSBMYeh5YLVG45xvcgAAAl8"]
[Tue Jul 21 07:24:05.434073 2026] [security2:error] [pid 230252:tid 230449] [client 20.220.225.223:34302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/tkikikoko.php"] [unique_id "al9IxU0Dwhk5-Z44XrpKpQAAAto"]
[Tue Jul 21 07:24:05.499465 2026] [security2:error] [pid 230252:tid 230375] [remote 45.135.2.187:29733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.2.135.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "10db.com.br"] [uri "/wp-login.php"] [unique_id "al9IxU0Dwhk5-Z44XrpKpAAC9Xg"]
[Tue Jul 21 07:24:05.604999 2026] [security2:error] [pid 230252:tid 230460] [client 20.197.192.193:52240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/we.php"] [unique_id "al9IxU0Dwhk5-Z44XrpKqAAAAuU"]
[Tue Jul 21 07:24:05.686786 2026] [security2:error] [pid 230252:tid 230403] [client 20.151.10.161:49143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/get.php"] [unique_id "al9IxU0Dwhk5-Z44XrpKqgAAAqw"]
[Tue Jul 21 07:24:05.697249 2026] [security2:error] [pid 230252:tid 230446] [client 74.249.245.134:43487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/readme.php"] [unique_id "al9IxU0Dwhk5-Z44XrpKqwAAAtc"]
[Tue Jul 21 07:24:05.815582 2026] [security2:error] [pid 230252:tid 230409] [client 20.151.10.161:26387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/7.php"] [unique_id "al9IxU0Dwhk5-Z44XrpKrAAAArI"]
[Tue Jul 21 07:24:05.832688 2026] [security2:error] [pid 230252:tid 230389] [client 20.151.10.161:65509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/ok.php"] [unique_id "al9IxU0Dwhk5-Z44XrpKrgAAAp4"]
[Tue Jul 21 07:24:05.884598 2026] [security2:error] [pid 230252:tid 230511] [client 173.252.95.30:63116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9IxU0Dwhk5-Z44XrpKsAAAAxg"]
[Tue Jul 21 07:24:06.300546 2026] [security2:error] [pid 230252:tid 230479] [client 20.226.60.151:50716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9Ixk0Dwhk5-Z44XrpKtAAAAvg"]
[Tue Jul 21 07:24:06.395621 2026] [security2:error] [pid 230252:tid 230335] [remote 5.182.209.54:40424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/wp-login.php"] [unique_id "al9Ixk0Dwhk5-Z44XrpKtwADFVA"]
[Tue Jul 21 07:24:06.893444 2026] [security2:error] [pid 229246:tid 229426] [client 20.151.10.161:65447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/mac.php"] [unique_id "al9IxiBMYeh5YLVG45xvggAAAkY"]
[Tue Jul 21 07:24:06.980690 2026] [security2:error] [pid 229246:tid 229411] [client 103.162.129.114:53604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IxiBMYeh5YLVG45xvgwAAAjc"]
[Tue Jul 21 07:24:06.980825 2026] [security2:error] [pid 229246:tid 229411] [client 103.162.129.114:53604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IxiBMYeh5YLVG45xvgwAAAjc"]
[Tue Jul 21 07:24:07.090516 2026] [security2:error] [pid 230252:tid 230353] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Ix00Dwhk5-Z44XrpKvgACoWI"]
[Tue Jul 21 07:24:07.090688 2026] [security2:error] [pid 230252:tid 230392] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Ix00Dwhk5-Z44XrpKvgACoWI"]
[Tue Jul 21 07:24:07.210542 2026] [security2:error] [pid 229246:tid 229421] [client 20.151.10.161:49037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/images.php"] [unique_id "al9IxyBMYeh5YLVG45xvhgAAAkE"]
[Tue Jul 21 07:24:07.270880 2026] [security2:error] [pid 229246:tid 229480] [client 193.36.225.57:54947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IxyBMYeh5YLVG45xvhAAAAnw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:24:07.274149 2026] [security2:error] [pid 230252:tid 230498] [client 20.226.60.151:60195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9Ix00Dwhk5-Z44XrpKvwAAAws"]
[Tue Jul 21 07:24:07.523918 2026] [security2:error] [pid 229246:tid 229340] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IxyBMYeh5YLVG45xvigACc10"]
[Tue Jul 21 07:24:07.524090 2026] [security2:error] [pid 229246:tid 229471] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IxyBMYeh5YLVG45xvigACc10"]
[Tue Jul 21 07:24:07.536293 2026] [security2:error] [pid 230252:tid 230429] [client 20.151.10.161:2713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vitacorr.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Ix00Dwhk5-Z44XrpKxQAAAsY"]
[Tue Jul 21 07:24:07.546350 2026] [security2:error] [pid 230252:tid 230306] [remote 20.153.140.50:50220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "links.principiamatematica.com"] [uri "/wp-login.php"] [unique_id "al9Ix00Dwhk5-Z44XrpKxgAC8TQ"]
[Tue Jul 21 07:24:07.645709 2026] [security2:error] [pid 229246:tid 229420] [client 117.251.86.144:58078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9IxyBMYeh5YLVG45xvjQAAAkA"]
[Tue Jul 21 07:24:07.645862 2026] [security2:error] [pid 229246:tid 229420] [client 117.251.86.144:58078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9IxyBMYeh5YLVG45xvjQAAAkA"]
[Tue Jul 21 07:24:07.675076 2026] [security2:error] [pid 230252:tid 230428] [client 173.252.95.25:45464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Ix00Dwhk5-Z44XrpKyQAAAsU"]
[Tue Jul 21 07:24:07.812908 2026] [security2:error] [pid 230252:tid 230433] [client 20.151.10.161:2700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vitacorr.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Ix00Dwhk5-Z44XrpKywAAAso"]
[Tue Jul 21 07:24:08.015528 2026] [security2:error] [pid 229246:tid 229333] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9IxiBMYeh5YLVG45xvfwACYFY"]
[Tue Jul 21 07:24:08.015846 2026] [security2:error] [pid 229246:tid 229452] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9IxiBMYeh5YLVG45xvfwACYFY"]
[Tue Jul 21 07:24:08.070470 2026] [security2:error] [pid 229246:tid 229470] [client 20.151.10.161:65477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wefile.php"] [unique_id "al9IyCBMYeh5YLVG45xvkwAAAnI"]
[Tue Jul 21 07:24:08.103149 2026] [security2:error] [pid 229246:tid 229389] [client 20.151.10.161:2987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vitacorr.com.br"] [uri "/images.php"] [unique_id "al9IyCBMYeh5YLVG45xvlAAAAiE"]
[Tue Jul 21 07:24:08.109894 2026] [security2:error] [pid 229246:tid 229442] [client 20.226.60.151:60231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9IyCBMYeh5YLVG45xvlQAAAlY"]
[Tue Jul 21 07:24:08.176037 2026] [security2:error] [pid 229246:tid 229423] [client 20.151.10.161:26458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/8.php"] [unique_id "al9IyCBMYeh5YLVG45xvlgAAAkM"]
[Tue Jul 21 07:24:08.231283 2026] [security2:error] [pid 229246:tid 229388] [client 74.249.245.134:60069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/403.php"] [unique_id "al9IyCBMYeh5YLVG45xvlwAAAiA"]
[Tue Jul 21 07:24:08.379690 2026] [security2:error] [pid 230252:tid 230506] [client 20.151.10.161:2707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vitacorr.com.br"] [uri "/for.php"] [unique_id "al9IyE0Dwhk5-Z44XrpKzQAAAxM"]
[Tue Jul 21 07:24:08.430984 2026] [security2:error] [pid 230252:tid 230436] [client 213.152.162.104:45850] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Ix00Dwhk5-Z44XrpKwgAAAs0"]
[Tue Jul 21 07:24:08.431078 2026] [security2:error] [pid 230252:tid 230436] [client 213.152.162.104:45850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Ix00Dwhk5-Z44XrpKwgAAAs0"]
[Tue Jul 21 07:24:08.558415 2026] [security2:error] [pid 230252:tid 230366] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IyE0Dwhk5-Z44XrpKzwAC6W8"]
[Tue Jul 21 07:24:08.558561 2026] [security2:error] [pid 230252:tid 230464] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IyE0Dwhk5-Z44XrpKzwAC6W8"]
[Tue Jul 21 07:24:08.657285 2026] [security2:error] [pid 230252:tid 230399] [client 20.151.10.161:2724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vitacorr.com.br"] [uri "/2larp.php"] [unique_id "al9IyE0Dwhk5-Z44XrpK0QAAAqg"]
[Tue Jul 21 07:24:08.939207 2026] [security2:error] [pid 229246:tid 229431] [client 20.151.10.161:2697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vitacorr.com.br"] [uri "/adminner.php"] [unique_id "al9IyCBMYeh5YLVG45xvpgAAAks"]
[Tue Jul 21 07:24:09.102111 2026] [security2:error] [pid 229246:tid 229359] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IySBMYeh5YLVG45xvpwACWHA"]
[Tue Jul 21 07:24:09.102243 2026] [security2:error] [pid 229246:tid 229444] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IySBMYeh5YLVG45xvpwACWHA"]
[Tue Jul 21 07:24:09.162536 2026] [security2:error] [pid 230252:tid 230483] [client 20.151.10.161:49100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/alls.php"] [unique_id "al9IyU0Dwhk5-Z44XrpK1QAAAvw"]
[Tue Jul 21 07:24:09.174856 2026] [security2:error] [pid 229246:tid 229258] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IySBMYeh5YLVG45xvqgACdAs"]
[Tue Jul 21 07:24:09.175040 2026] [security2:error] [pid 229246:tid 229472] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IySBMYeh5YLVG45xvqgACdAs"]
[Tue Jul 21 07:24:09.216920 2026] [security2:error] [pid 229246:tid 229474] [client 20.151.10.161:2980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vitacorr.com.br"] [uri "/82.php"] [unique_id "al9IySBMYeh5YLVG45xvqwAAAnY"]
[Tue Jul 21 07:24:09.254646 2026] [security2:error] [pid 230252:tid 230467] [client 20.226.60.151:50797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9IyU0Dwhk5-Z44XrpK1gAAAuw"]
[Tue Jul 21 07:24:09.493390 2026] [security2:error] [pid 229246:tid 229398] [client 20.151.10.161:2714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vitacorr.com.br"] [uri "/kir.php"] [unique_id "al9IySBMYeh5YLVG45xvtAAAAio"]
[Tue Jul 21 07:24:09.668521 2026] [security2:error] [pid 230252:tid 230397] [client 20.220.225.223:34191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9IyU0Dwhk5-Z44XrpK2QAAAqY"]
[Tue Jul 21 07:24:09.749620 2026] [security2:error] [pid 229246:tid 229400] [client 198.20.67.201:38254] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "pedido-online.net"] [uri "/index.php"] [unique_id "al9IySBMYeh5YLVG45xvsgAAAiw"]
[Tue Jul 21 07:24:09.975763 2026] [security2:error] [pid 230252:tid 230415] [client 20.226.60.151:60278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/albin.php"] [unique_id "al9IyU0Dwhk5-Z44XrpK2wAAArg"]
[Tue Jul 21 07:24:10.038314 2026] [security2:error] [pid 229246:tid 229300] [remote 20.153.140.50:53118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peak-bioboost.shop-officialstore.com"] [uri "/wp-login.php"] [unique_id "al9IyiBMYeh5YLVG45xvvQACczU"]
[Tue Jul 21 07:24:10.471944 2026] [security2:error] [pid 230252:tid 230468] [client 20.151.10.161:63742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9Iyk0Dwhk5-Z44XrpK4AAAAu0"]
[Tue Jul 21 07:24:10.546203 2026] [security2:error] [pid 229246:tid 229379] [client 15.220.152.126:57960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.152.220.15.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pacodasrosas.com.br"] [uri "/adminer.php"] [unique_id "al9IySBMYeh5YLVG45xvrgAAAhc"]
[Tue Jul 21 07:24:10.744994 2026] [security2:error] [pid 230252:tid 230507] [client 74.249.245.134:53484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/max.php"] [unique_id "al9Iyk0Dwhk5-Z44XrpK5QAAAxQ"]
[Tue Jul 21 07:24:10.892705 2026] [security2:error] [pid 229246:tid 229468] [client 103.106.20.201:56442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IyiBMYeh5YLVG45xvxQAAAnA"]
[Tue Jul 21 07:24:10.892819 2026] [security2:error] [pid 229246:tid 229468] [client 103.106.20.201:56442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IyiBMYeh5YLVG45xvxQAAAnA"]
[Tue Jul 21 07:24:10.961856 2026] [security2:error] [pid 229246:tid 229423] [client 20.226.60.151:54580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/solo1.php"] [unique_id "al9IyiBMYeh5YLVG45xvxgAAAkM"]
[Tue Jul 21 07:24:10.994724 2026] [security2:error] [pid 229246:tid 229503] [client 20.151.10.161:26534] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/1.php"] [unique_id "al9IyiBMYeh5YLVG45xvyAAAApM"]
[Tue Jul 21 07:24:10.994825 2026] [security2:error] [pid 229246:tid 229503] [client 20.151.10.161:26534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/1.php"] [unique_id "al9IyiBMYeh5YLVG45xvyAAAApM"]
[Tue Jul 21 07:24:11.036705 2026] [security2:error] [pid 230252:tid 230490] [client 62.102.148.164:35016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Iy00Dwhk5-Z44XrpK6AAAAwM"]
[Tue Jul 21 07:24:11.036790 2026] [security2:error] [pid 230252:tid 230490] [client 62.102.148.164:35016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Iy00Dwhk5-Z44XrpK6AAAAwM"]
[Tue Jul 21 07:24:11.162833 2026] [security2:error] [pid 230252:tid 230440] [client 103.174.34.15:54534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Iy00Dwhk5-Z44XrpK6QAAAtE"]
[Tue Jul 21 07:24:11.162942 2026] [security2:error] [pid 230252:tid 230440] [client 103.174.34.15:54534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Iy00Dwhk5-Z44XrpK6QAAAtE"]
[Tue Jul 21 07:24:11.169094 2026] [security2:error] [pid 230252:tid 230346] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Iy00Dwhk5-Z44XrpK6gAC9ls"]
[Tue Jul 21 07:24:11.169217 2026] [security2:error] [pid 230252:tid 230477] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Iy00Dwhk5-Z44XrpK6gAC9ls"]
[Tue Jul 21 07:24:11.215355 2026] [security2:error] [pid 230252:tid 230486] [client 15.220.152.126:4168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.152.220.15.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pacodasrosas.com.br"] [uri "/adminer.php"] [unique_id "al9Iy00Dwhk5-Z44XrpK6wAAAv8"]
[Tue Jul 21 07:24:11.394735 2026] [security2:error] [pid 230252:tid 230449] [client 20.220.225.223:34244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/wp-css.php"] [unique_id "al9Iy00Dwhk5-Z44XrpK7AAAAto"]
[Tue Jul 21 07:24:11.449700 2026] [security2:error] [pid 230252:tid 230422] [client 20.226.60.151:60224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/cilus.php"] [unique_id "al9Iy00Dwhk5-Z44XrpK7QAAAr8"]
[Tue Jul 21 07:24:11.493031 2026] [security2:error] [pid 229246:tid 229296] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IyyBMYeh5YLVG45xvzQACTDE"]
[Tue Jul 21 07:24:11.493201 2026] [security2:error] [pid 229246:tid 229432] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IyyBMYeh5YLVG45xvzQACTDE"]
[Tue Jul 21 07:24:11.673900 2026] [security2:error] [pid 230252:tid 230463] [client 15.220.152.126:7881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.152.220.15.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pacodasrosas.com.br"] [uri "/adminer.php"] [unique_id "al9Iy00Dwhk5-Z44XrpK7gAAAug"]
[Tue Jul 21 07:24:12.113333 2026] [security2:error] [pid 229246:tid 229384] [client 15.220.152.126:10323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.152.220.15.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pacodasrosas.com.br"] [uri "/adminer.php"] [unique_id "al9IzCBMYeh5YLVG45xv2gAAAhw"]
[Tue Jul 21 07:24:12.250669 2026] [security2:error] [pid 230252:tid 230392] [client 193.36.225.61:21497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IzE0Dwhk5-Z44XrpK7wAAAqE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:24:12.390808 2026] [security2:error] [pid 229246:tid 229459] [client 74.249.245.134:62114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/m.php"] [unique_id "al9IzCBMYeh5YLVG45xv3gAAAmc"]
[Tue Jul 21 07:24:12.427355 2026] [security2:error] [pid 229246:tid 229414] [client 175.45.70.82:60868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IzCBMYeh5YLVG45xv4AAAAjo"]
[Tue Jul 21 07:24:12.427459 2026] [security2:error] [pid 229246:tid 229414] [client 175.45.70.82:60868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IzCBMYeh5YLVG45xv4AAAAjo"]
[Tue Jul 21 07:24:12.519361 2026] [security2:error] [pid 230252:tid 230399] [client 20.197.192.193:52231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/phpinfo.php1"] [unique_id "al9IzE0Dwhk5-Z44XrpK9QAAAqg"]
[Tue Jul 21 07:24:12.565297 2026] [proxy:error] [pid 230252:tid 230389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:12.565385 2026] [proxy_http:error] [pid 230252:tid 230389] [client 20.151.10.161:65438] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:12.566790 2026] [proxy:error] [pid 230252:tid 230389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:12.566867 2026] [proxy_http:error] [pid 230252:tid 230389] [client 20.151.10.161:65438] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:12.825167 2026] [security2:error] [pid 229246:tid 229385] [client 20.226.60.151:60165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/gptsh.php"] [unique_id "al9IzCBMYeh5YLVG45xv5gAAAh0"]
[Tue Jul 21 07:24:12.855150 2026] [security2:error] [pid 230252:tid 230462] [client 20.220.225.223:34183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/wp-explorer.php"] [unique_id "al9IzE0Dwhk5-Z44XrpK_AAAAuc"]
[Tue Jul 21 07:24:13.055619 2026] [core:alert] [pid 230252:tid 230444] [client 57.141.18.55:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:24:13.383104 2026] [security2:error] [pid 229246:tid 229421] [client 20.226.60.151:54531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/cong.php"] [unique_id "al9IzSBMYeh5YLVG45xv7wAAAkE"]
[Tue Jul 21 07:24:13.656916 2026] [security2:error] [pid 230252:tid 230469] [client 45.251.232.145:57658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IzU0Dwhk5-Z44XrpLBAAAAu4"]
[Tue Jul 21 07:24:13.657027 2026] [security2:error] [pid 230252:tid 230469] [client 45.251.232.145:57658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IzU0Dwhk5-Z44XrpLBAAAAu4"]
[Tue Jul 21 07:24:14.001877 2026] [security2:error] [pid 230252:tid 230472] [client 62.102.148.164:35020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9Izk0Dwhk5-Z44XrpLCAAAAvE"]
[Tue Jul 21 07:24:14.001978 2026] [security2:error] [pid 230252:tid 230472] [client 62.102.148.164:35020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9Izk0Dwhk5-Z44XrpLCAAAAvE"]
[Tue Jul 21 07:24:14.068631 2026] [security2:error] [pid 230252:tid 230454] [client 74.249.245.134:61958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/click.php"] [unique_id "al9Izk0Dwhk5-Z44XrpLCQAAAt8"]
[Tue Jul 21 07:24:14.140366 2026] [security2:error] [pid 230252:tid 230423] [client 20.151.10.161:49128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/yyu.php"] [unique_id "al9Izk0Dwhk5-Z44XrpLCgAAAsA"]
[Tue Jul 21 07:24:14.283459 2026] [security2:error] [pid 230252:tid 230412] [client 62.102.148.164:35036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Izk0Dwhk5-Z44XrpLDQAAArU"]
[Tue Jul 21 07:24:14.283565 2026] [security2:error] [pid 230252:tid 230412] [client 62.102.148.164:35036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Izk0Dwhk5-Z44XrpLDQAAArU"]
[Tue Jul 21 07:24:14.300806 2026] [security2:error] [pid 229246:tid 229485] [client 20.226.60.151:60183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/rithin.php"] [unique_id "al9IziBMYeh5YLVG45xv_AAAAoE"]
[Tue Jul 21 07:24:14.619559 2026] [security2:error] [pid 230252:tid 230432] [client 103.121.156.110:52144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Izk0Dwhk5-Z44XrpLEAAAAsk"]
[Tue Jul 21 07:24:14.619674 2026] [security2:error] [pid 230252:tid 230432] [client 103.121.156.110:52144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Izk0Dwhk5-Z44XrpLEAAAAsk"]
[Tue Jul 21 07:24:15.079237 2026] [proxy:error] [pid 229246:tid 229412] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:15.079321 2026] [proxy_http:error] [pid 229246:tid 229412] [client 20.151.10.161:65512] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:15.080072 2026] [proxy:error] [pid 229246:tid 229412] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:15.080107 2026] [proxy_http:error] [pid 229246:tid 229412] [client 20.151.10.161:65512] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:15.134562 2026] [security2:error] [pid 230252:tid 230422] [client 82.102.28.107:44688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Iz00Dwhk5-Z44XrpLEgAAAr8"]
[Tue Jul 21 07:24:15.134692 2026] [security2:error] [pid 230252:tid 230422] [client 82.102.28.107:44688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Iz00Dwhk5-Z44XrpLEgAAAr8"]
[Tue Jul 21 07:24:15.160827 2026] [security2:error] [pid 230252:tid 230327] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Iz00Dwhk5-Z44XrpLEwAC2kg"]
[Tue Jul 21 07:24:15.161005 2026] [security2:error] [pid 230252:tid 230449] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Iz00Dwhk5-Z44XrpLEwAC2kg"]
[Tue Jul 21 07:24:15.254586 2026] [security2:error] [pid 229246:tid 229492] [client 139.135.44.145:53819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IzyBMYeh5YLVG45xwBwAAAog"]
[Tue Jul 21 07:24:15.254688 2026] [security2:error] [pid 229246:tid 229492] [client 139.135.44.145:53819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IzyBMYeh5YLVG45xwBwAAAog"]
[Tue Jul 21 07:24:15.404500 2026] [security2:error] [pid 229246:tid 229399] [client 20.220.225.223:34176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/akismet.php"] [unique_id "al9IzyBMYeh5YLVG45xwCAAAAis"]
[Tue Jul 21 07:24:15.660833 2026] [security2:error] [pid 229246:tid 229440] [client 20.226.60.151:50762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/fffm.php"] [unique_id "al9IzyBMYeh5YLVG45xwDwAAAlQ"]
[Tue Jul 21 07:24:16.665747 2026] [security2:error] [pid 229246:tid 229401] [client 74.249.245.134:21025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/lv.php"] [unique_id "al9I0CBMYeh5YLVG45xwGgAAAi0"]
[Tue Jul 21 07:24:16.850320 2026] [security2:error] [pid 230252:tid 230459] [client 20.151.10.161:49047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/by.php"] [unique_id "al9I0E0Dwhk5-Z44XrpLIAAAAuQ"]
[Tue Jul 21 07:24:16.953720 2026] [security2:error] [pid 230252:tid 230433] [client 193.36.225.72:27971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9I0E0Dwhk5-Z44XrpLIQAAAso"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:24:17.076414 2026] [security2:error] [pid 229246:tid 229265] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9I0SBMYeh5YLVG45xwIgACJBI"]
[Tue Jul 21 07:24:17.076599 2026] [security2:error] [pid 229246:tid 229392] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9I0SBMYeh5YLVG45xwIgACJBI"]
[Tue Jul 21 07:24:17.378895 2026] [security2:error] [pid 229246:tid 229394] [client 107.150.61.58:47488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.61.150.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marianapsictrab.com.br"] [uri "/wp-content/qqe70f6e/edit.php"] [unique_id "al9I0SBMYeh5YLVG45xwKAAAAiY"], referer: https://marianapsictrab.com.br/wp-content/qqe70f6e/edit.php
[Tue Jul 21 07:24:17.470865 2026] [security2:error] [pid 230252:tid 230508] [client 20.151.10.161:65463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9I0U0Dwhk5-Z44XrpLJgAAAxU"]
[Tue Jul 21 07:24:17.573482 2026] [security2:error] [pid 230252:tid 230457] [client 20.151.10.161:26512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/100.php"] [unique_id "al9I0U0Dwhk5-Z44XrpLKQAAAuI"]
[Tue Jul 21 07:24:17.726900 2026] [security2:error] [pid 229246:tid 229478] [client 103.162.129.114:54065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9I0SBMYeh5YLVG45xwLgAAAno"]
[Tue Jul 21 07:24:17.727034 2026] [security2:error] [pid 229246:tid 229478] [client 103.162.129.114:54065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9I0SBMYeh5YLVG45xwLgAAAno"]
[Tue Jul 21 07:24:17.762577 2026] [security2:error] [pid 229246:tid 229413] [client 74.7.241.136:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "crislainedefreitasol1782476081805.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9I0SBMYeh5YLVG45xwMAACOR0"]
[Tue Jul 21 07:24:18.044876 2026] [security2:error] [pid 230252:tid 230259] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I0k0Dwhk5-Z44XrpLMgACxgU"]
[Tue Jul 21 07:24:18.044991 2026] [security2:error] [pid 230252:tid 230429] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I0k0Dwhk5-Z44XrpLMgACxgU"]
[Tue Jul 21 07:24:18.126238 2026] [security2:error] [pid 229246:tid 229451] [client 20.151.10.161:49093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/FAQ.php"] [unique_id "al9I0iBMYeh5YLVG45xwNAAAAl8"]
[Tue Jul 21 07:24:18.317185 2026] [security2:error] [pid 229246:tid 229427] [client 20.226.60.151:54571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/public/css.php"] [unique_id "al9I0iBMYeh5YLVG45xwPAAAAkc"]
[Tue Jul 21 07:24:18.383265 2026] [security2:error] [pid 229246:tid 229391] [client 117.251.86.144:59996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9I0iBMYeh5YLVG45xwPQAAAiM"]
[Tue Jul 21 07:24:18.383367 2026] [security2:error] [pid 229246:tid 229391] [client 117.251.86.144:59996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9I0iBMYeh5YLVG45xwPQAAAiM"]
[Tue Jul 21 07:24:18.455845 2026] [security2:error] [pid 230252:tid 230406] [client 20.226.60.151:60179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/dfre.php"] [unique_id "al9I0k0Dwhk5-Z44XrpLPAAAAq8"]
[Tue Jul 21 07:24:18.738012 2026] [security2:error] [pid 230252:tid 230337] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I0k0Dwhk5-Z44XrpLPwACzVI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:18.744554 2026] [security2:error] [pid 229246:tid 229374] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I0iBMYeh5YLVG45xwQQACOn8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:18.770690 2026] [security2:error] [pid 230252:tid 230509] [client 20.226.60.151:50768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-happy.php"] [unique_id "al9I0k0Dwhk5-Z44XrpLSwAAAxY"]
[Tue Jul 21 07:24:18.781754 2026] [security2:error] [pid 230252:tid 230317] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I0k0Dwhk5-Z44XrpLQgAC1z8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:18.892584 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:49090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/coffexium.php"] [unique_id "al9I0iBMYeh5YLVG45xwRQAAAlo"]
[Tue Jul 21 07:24:18.971306 2026] [security2:error] [pid 229246:tid 229260] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I0iBMYeh5YLVG45xwRgACjQ0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:19.025093 2026] [security2:error] [pid 230252:tid 230364] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I000Dwhk5-Z44XrpLiQACuG0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:19.132796 2026] [security2:error] [pid 230252:tid 230319] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I000Dwhk5-Z44XrpLtQAC9kE"]
[Tue Jul 21 07:24:19.132912 2026] [security2:error] [pid 230252:tid 230477] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I000Dwhk5-Z44XrpLtQAC9kE"]
[Tue Jul 21 07:24:19.329973 2026] [security2:error] [pid 230252:tid 230274] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I000Dwhk5-Z44XrpL0wAC_xQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:19.544158 2026] [security2:error] [pid 230252:tid 230289] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I000Dwhk5-Z44XrpL3wADByM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:19.561869 2026] [security2:error] [pid 230252:tid 230350] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I000Dwhk5-Z44XrpL4QADD18"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:19.608217 2026] [security2:error] [pid 230252:tid 230339] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9I000Dwhk5-Z44XrpL4gACqVQ"]
[Tue Jul 21 07:24:19.608389 2026] [security2:error] [pid 230252:tid 230400] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9I000Dwhk5-Z44XrpL4gACqVQ"]
[Tue Jul 21 07:24:19.643639 2026] [security2:error] [pid 230252:tid 230313] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I000Dwhk5-Z44XrpL5wAC4zs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:19.735988 2026] [security2:error] [pid 229246:tid 229291] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I0iBMYeh5YLVG45xwQAACUSw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:19.769419 2026] [security2:error] [pid 230252:tid 230262] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I000Dwhk5-Z44XrpL8wAC0Ag"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:19.784633 2026] [security2:error] [pid 229246:tid 229302] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I0yBMYeh5YLVG45xwXQACYjc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:19.883789 2026] [security2:error] [pid 230252:tid 230263] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I000Dwhk5-Z44XrpL9wACyAk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:19.904229 2026] [security2:error] [pid 230252:tid 230385] [client 20.151.10.161:26545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/about.php"] [unique_id "al9I000Dwhk5-Z44XrpL-AAAApo"]
[Tue Jul 21 07:24:19.918092 2026] [security2:error] [pid 230252:tid 230326] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9I000Dwhk5-Z44XrpL-QACwkc"]
[Tue Jul 21 07:24:19.918225 2026] [security2:error] [pid 230252:tid 230425] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9I000Dwhk5-Z44XrpL-QACwkc"]
[Tue Jul 21 07:24:19.941776 2026] [security2:error] [pid 229246:tid 229481] [client 20.226.60.151:56939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/.well-known/about.php"] [unique_id "al9I0yBMYeh5YLVG45xwYgAAAn0"]
[Tue Jul 21 07:24:19.990003 2026] [security2:error] [pid 230252:tid 230376] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I000Dwhk5-Z44XrpL-gAC7Xk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:20.011464 2026] [security2:error] [pid 230252:tid 230348] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I1E0Dwhk5-Z44XrpL_AAC8V0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:20.126703 2026] [security2:error] [pid 230252:tid 230287] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I1E0Dwhk5-Z44XrpL_gAC5yE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:20.148736 2026] [security2:error] [pid 230252:tid 230483] [client 20.226.60.151:60256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/fpr4.php"] [unique_id "al9I1E0Dwhk5-Z44XrpL_wAAAvw"]
[Tue Jul 21 07:24:20.238257 2026] [security2:error] [pid 229246:tid 229341] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I1CBMYeh5YLVG45xwZAACGl4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:20.282326 2026] [security2:error] [pid 230252:tid 230445] [client 74.249.245.134:50298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/cong.php"] [unique_id "al9I1E0Dwhk5-Z44XrpMAAAAAtY"]
[Tue Jul 21 07:24:20.283605 2026] [security2:error] [pid 230252:tid 230423] [client 20.151.10.161:49088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/red.php"] [unique_id "al9I1E0Dwhk5-Z44XrpMAQAAAsA"]
[Tue Jul 21 07:24:20.340234 2026] [security2:error] [pid 230252:tid 230359] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I1E0Dwhk5-Z44XrpMAgACuGg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:20.645977 2026] [proxy:error] [pid 230252:tid 230486] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:20.646064 2026] [proxy_http:error] [pid 230252:tid 230486] [client 20.151.10.161:65413] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:20.646757 2026] [proxy:error] [pid 230252:tid 230486] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:20.646801 2026] [proxy_http:error] [pid 230252:tid 230486] [client 20.151.10.161:65413] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:21.012410 2026] [security2:error] [pid 230252:tid 230436] [client 20.226.60.151:56870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9I1U0Dwhk5-Z44XrpMPQAAAs0"]
[Tue Jul 21 07:24:21.192517 2026] [security2:error] [pid 230252:tid 230496] [client 2.57.168.28:36069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.168.57.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cursosonlinesiteoficial.com"] [uri "/wp-login.php"] [unique_id "al9I1U0Dwhk5-Z44XrpMPwAAAwk"]
[Tue Jul 21 07:24:21.214695 2026] [proxy:error] [pid 230252:tid 230459] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:21.214773 2026] [proxy_http:error] [pid 230252:tid 230459] [client 20.151.10.161:49025] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:21.215477 2026] [proxy:error] [pid 230252:tid 230459] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:21.215517 2026] [proxy_http:error] [pid 230252:tid 230459] [client 20.151.10.161:49025] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:21.257329 2026] [security2:error] [pid 230252:tid 230411] [client 20.226.60.151:50700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/file88.php"] [unique_id "al9I1U0Dwhk5-Z44XrpMRAAAArQ"]
[Tue Jul 21 07:24:21.331846 2026] [security2:error] [pid 230252:tid 230333] [remote 124.55.178.99:50984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9I1U0Dwhk5-Z44XrpMRQADFE4"]
[Tue Jul 21 07:24:21.356022 2026] [security2:error] [pid 229246:tid 229333] [remote 160.187.68.132:49580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9I1SBMYeh5YLVG45xwbgACaFY"]
[Tue Jul 21 07:24:21.356234 2026] [security2:error] [pid 229246:tid 229460] [client 160.187.68.132:49580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9I1SBMYeh5YLVG45xwbgACaFY"]
[Tue Jul 21 07:24:21.419050 2026] [security2:error] [pid 230252:tid 230451] [client 62.102.148.164:40260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9I1U0Dwhk5-Z44XrpMSgAAAtw"]
[Tue Jul 21 07:24:21.419137 2026] [security2:error] [pid 230252:tid 230451] [client 62.102.148.164:40260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9I1U0Dwhk5-Z44XrpMSgAAAtw"]
[Tue Jul 21 07:24:21.537030 2026] [security2:error] [pid 229246:tid 229287] [remote 65.111.10.106:45779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.10.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9I1SBMYeh5YLVG45xwdAACOCg"]
[Tue Jul 21 07:24:21.578274 2026] [security2:error] [pid 229246:tid 229479] [client 103.106.20.201:57168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I1SBMYeh5YLVG45xwdQAAAns"]
[Tue Jul 21 07:24:21.578404 2026] [security2:error] [pid 229246:tid 229479] [client 103.106.20.201:57168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I1SBMYeh5YLVG45xwdQAAAns"]
[Tue Jul 21 07:24:21.718450 2026] [security2:error] [pid 229246:tid 229368] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9I1SBMYeh5YLVG45xwdwACO3k"]
[Tue Jul 21 07:24:21.718643 2026] [security2:error] [pid 229246:tid 229415] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9I1SBMYeh5YLVG45xwdwACO3k"]
[Tue Jul 21 07:24:21.740334 2026] [security2:error] [pid 230252:tid 230453] [client 193.36.225.63:28417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9I1U0Dwhk5-Z44XrpMVAAAAt4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:24:21.833176 2026] [security2:error] [pid 229246:tid 229469] [client 20.151.10.161:49150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9I1SBMYeh5YLVG45xwegAAAnE"]
[Tue Jul 21 07:24:21.865515 2026] [security2:error] [pid 230252:tid 230264] [remote 142.44.225.172:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "garagemdoluidi.com.br"] [uri "/my-account/lost-password/"] [unique_id "al9I1U0Dwhk5-Z44XrpMVQAC8Qo"]
[Tue Jul 21 07:24:21.865708 2026] [security2:error] [pid 230252:tid 230472] [client 142.44.225.172:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "garagemdoluidi.com.br"] [uri "/my-account/lost-password/"] [unique_id "al9I1U0Dwhk5-Z44XrpMVQAC8Qo"]
[Tue Jul 21 07:24:22.082221 2026] [security2:error] [pid 230252:tid 230403] [client 103.174.34.15:55008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I1k0Dwhk5-Z44XrpMWAAAAqw"]
[Tue Jul 21 07:24:22.082699 2026] [security2:error] [pid 230252:tid 230403] [client 103.174.34.15:55008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I1k0Dwhk5-Z44XrpMWAAAAqw"]
[Tue Jul 21 07:24:22.139838 2026] [security2:error] [pid 230252:tid 230398] [client 20.151.10.161:65501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/like.php"] [unique_id "al9I1k0Dwhk5-Z44XrpMWwAAAqc"]
[Tue Jul 21 07:24:22.267586 2026] [security2:error] [pid 230252:tid 230312] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9I1k0Dwhk5-Z44XrpMXAAC2Do"]
[Tue Jul 21 07:24:22.267759 2026] [security2:error] [pid 230252:tid 230447] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9I1k0Dwhk5-Z44XrpMXAAC2Do"]
[Tue Jul 21 07:24:22.273014 2026] [security2:error] [pid 230252:tid 230500] [client 20.226.60.151:56857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wefile.php"] [unique_id "al9I1k0Dwhk5-Z44XrpMXQAAAw0"]
[Tue Jul 21 07:24:22.331339 2026] [security2:error] [pid 230252:tid 230449] [client 20.151.10.161:26460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/admin.php"] [unique_id "al9I1k0Dwhk5-Z44XrpMXgAAAto"]
[Tue Jul 21 07:24:22.942369 2026] [proxy:error] [pid 230252:tid 230484] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:22.942447 2026] [proxy_http:error] [pid 230252:tid 230484] [client 20.151.10.161:49112] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:22.943226 2026] [proxy:error] [pid 230252:tid 230484] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:22.943272 2026] [proxy_http:error] [pid 230252:tid 230484] [client 20.151.10.161:49112] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:23.132195 2026] [security2:error] [pid 230252:tid 230486] [client 175.45.70.82:61377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I100Dwhk5-Z44XrpMaAAAAv8"]
[Tue Jul 21 07:24:23.132326 2026] [security2:error] [pid 230252:tid 230486] [client 175.45.70.82:61377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I100Dwhk5-Z44XrpMaAAAAv8"]
[Tue Jul 21 07:24:23.141639 2026] [security2:error] [pid 230252:tid 230461] [client 20.226.60.151:50735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/ccc.php"] [unique_id "al9I100Dwhk5-Z44XrpMaQAAAuY"]
[Tue Jul 21 07:24:23.456732 2026] [security2:error] [pid 229246:tid 229364] [remote 116.179.37.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9I1yBMYeh5YLVG45xwiQACHnU"], referer: https://androapkmod.com/tag/block-craft-3d-hack-mod-apk-unlimited-gems/
[Tue Jul 21 07:24:23.547343 2026] [security2:error] [pid 230252:tid 230386] [client 20.220.225.223:34261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/ace2.php"] [unique_id "al9I100Dwhk5-Z44XrpMbgAAAps"]
[Tue Jul 21 07:24:23.691154 2026] [security2:error] [pid 230252:tid 230469] [client 20.151.10.161:49105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/footer.php"] [unique_id "al9I100Dwhk5-Z44XrpMcAAAAu4"]
[Tue Jul 21 07:24:23.697605 2026] [security2:error] [pid 230252:tid 230511] [client 20.226.60.151:56883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9I100Dwhk5-Z44XrpMcQAAAxg"]
[Tue Jul 21 07:24:23.818332 2026] [security2:error] [pid 230252:tid 230472] [client 62.102.148.164:40272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9I100Dwhk5-Z44XrpMcwAAAvE"]
[Tue Jul 21 07:24:23.818436 2026] [security2:error] [pid 230252:tid 230472] [client 62.102.148.164:40272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9I100Dwhk5-Z44XrpMcwAAAvE"]
[Tue Jul 21 07:24:23.914853 2026] [security2:error] [pid 230252:tid 230485] [client 20.220.225.223:48539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-editor.php"] [unique_id "al9I100Dwhk5-Z44XrpMdwAAAv4"]
[Tue Jul 21 07:24:23.934781 2026] [security2:error] [pid 230252:tid 230417] [client 20.151.10.161:26315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/edit.php"] [unique_id "al9I100Dwhk5-Z44XrpMeAAAAro"]
[Tue Jul 21 07:24:23.937805 2026] [security2:error] [pid 229246:tid 229437] [client 74.249.245.134:54466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/brand.php"] [unique_id "al9I1yBMYeh5YLVG45xwkAAAAlE"]
[Tue Jul 21 07:24:23.952237 2026] [security2:error] [pid 230252:tid 230423] [client 20.151.10.161:63683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/.well-known/about.php"] [unique_id "al9I100Dwhk5-Z44XrpMeQAAAsA"]
[Tue Jul 21 07:24:24.030846 2026] [security2:error] [pid 230252:tid 230398] [client 20.52.136.55:1567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9I2E0Dwhk5-Z44XrpMegAAAqc"]
[Tue Jul 21 07:24:24.186940 2026] [security2:error] [pid 230252:tid 230451] [client 45.251.232.145:58181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I2E0Dwhk5-Z44XrpMewAAAtw"]
[Tue Jul 21 07:24:24.187070 2026] [security2:error] [pid 230252:tid 230451] [client 45.251.232.145:58181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I2E0Dwhk5-Z44XrpMewAAAtw"]
[Tue Jul 21 07:24:24.227097 2026] [security2:error] [pid 230252:tid 230409] [client 198.20.67.201:52022] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "pedido-online.net"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "al9I2E0Dwhk5-Z44XrpMfAAAArI"]
[Tue Jul 21 07:24:24.227218 2026] [security2:error] [pid 230252:tid 230409] [client 198.20.67.201:52022] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pedido-online.net"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "al9I2E0Dwhk5-Z44XrpMfAAAArI"]
[Tue Jul 21 07:24:24.973211 2026] [security2:error] [pid 230252:tid 230396] [client 20.220.225.223:34195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/ms.php"] [unique_id "al9I2E0Dwhk5-Z44XrpMhQAAAqU"]
[Tue Jul 21 07:24:25.078559 2026] [proxy:error] [pid 230252:tid 230494] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:25.078639 2026] [proxy_http:error] [pid 230252:tid 230494] [client 20.151.10.161:49096] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:25.079342 2026] [proxy:error] [pid 230252:tid 230494] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:25.079381 2026] [proxy_http:error] [pid 230252:tid 230494] [client 20.151.10.161:49096] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:25.101711 2026] [autoindex:error] [pid 230252:tid 230441] [client 20.226.60.151:56858] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:24:25.274460 2026] [autoindex:error] [pid 230252:tid 230507] [client 20.226.60.151:56858] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:24:25.288313 2026] [security2:error] [pid 230252:tid 230471] [client 103.121.156.110:52477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9I2U0Dwhk5-Z44XrpMkAAAAvA"]
[Tue Jul 21 07:24:25.288454 2026] [security2:error] [pid 230252:tid 230471] [client 103.121.156.110:52477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9I2U0Dwhk5-Z44XrpMkAAAAvA"]
[Tue Jul 21 07:24:26.114637 2026] [security2:error] [pid 230252:tid 230439] [client 139.135.44.145:54706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9I2k0Dwhk5-Z44XrpMmgAAAtA"]
[Tue Jul 21 07:24:26.114751 2026] [security2:error] [pid 230252:tid 230439] [client 139.135.44.145:54706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9I2k0Dwhk5-Z44XrpMmgAAAtA"]
[Tue Jul 21 07:24:26.245896 2026] [security2:error] [pid 229246:tid 229472] [client 20.151.10.161:65502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9I2iBMYeh5YLVG45xwrQAAAnQ"]
[Tue Jul 21 07:24:26.685294 2026] [security2:error] [pid 230252:tid 230419] [client 20.151.10.161:26450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9I2k0Dwhk5-Z44XrpMnwAAArw"]
[Tue Jul 21 07:24:26.764537 2026] [security2:error] [pid 230252:tid 230328] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9I2k0Dwhk5-Z44XrpMoAACr0k"]
[Tue Jul 21 07:24:26.764730 2026] [security2:error] [pid 230252:tid 230406] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9I2k0Dwhk5-Z44XrpMoAACr0k"]
[Tue Jul 21 07:24:26.794295 2026] [security2:error] [pid 230252:tid 230484] [client 193.36.225.67:43129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9I2k0Dwhk5-Z44XrpMoQAAAv0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:24:26.970208 2026] [security2:error] [pid 229246:tid 229493] [client 20.226.60.151:54505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/output.php"] [unique_id "al9I2iBMYeh5YLVG45xwuwAAAok"]
[Tue Jul 21 07:24:27.367760 2026] [security2:error] [pid 229246:tid 229498] [client 20.226.60.151:54540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-file-120.php"] [unique_id "al9I2yBMYeh5YLVG45xwvgAAAo4"]
[Tue Jul 21 07:24:27.389154 2026] [security2:error] [pid 229246:tid 229392] [client 74.249.245.134:43014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/atomlib.php"] [unique_id "al9I2yBMYeh5YLVG45xwwgAAAiQ"]
[Tue Jul 21 07:24:27.492359 2026] [security2:error] [pid 229246:tid 229398] [client 20.226.60.151:54549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/special.php"] [unique_id "al9I2yBMYeh5YLVG45xwxQAAAio"]
[Tue Jul 21 07:24:27.612423 2026] [security2:error] [pid 229246:tid 229437] [client 20.226.60.151:54539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/as.php"] [unique_id "al9I2yBMYeh5YLVG45xwxwAAAlE"]
[Tue Jul 21 07:24:27.618091 2026] [security2:error] [pid 230252:tid 230308] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9I200Dwhk5-Z44XrpMqQADBzY"]
[Tue Jul 21 07:24:27.618297 2026] [security2:error] [pid 230252:tid 230494] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9I200Dwhk5-Z44XrpMqQADBzY"]
[Tue Jul 21 07:24:27.792597 2026] [security2:error] [pid 229246:tid 229448] [client 20.226.60.151:61074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9I2yBMYeh5YLVG45xwygAAAlw"]
[Tue Jul 21 07:24:27.837687 2026] [security2:error] [pid 229246:tid 229309] [remote 5.252.52.249:55490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nocaminhodafe.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I2yBMYeh5YLVG45xwywACfD4"]
[Tue Jul 21 07:24:27.837863 2026] [security2:error] [pid 229246:tid 229480] [client 5.252.52.249:55490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nocaminhodafe.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I2yBMYeh5YLVG45xwywACfD4"]
[Tue Jul 21 07:24:27.919721 2026] [security2:error] [pid 230252:tid 230458] [client 82.102.28.107:35594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9I200Dwhk5-Z44XrpMqgAAAuM"]
[Tue Jul 21 07:24:27.919833 2026] [security2:error] [pid 230252:tid 230458] [client 82.102.28.107:35594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9I200Dwhk5-Z44XrpMqgAAAuM"]
[Tue Jul 21 07:24:27.936766 2026] [security2:error] [pid 229246:tid 229390] [client 20.151.10.161:49129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-content/index.php"] [unique_id "al9I2yBMYeh5YLVG45xwzwAAAiI"]
[Tue Jul 21 07:24:28.198473 2026] [security2:error] [pid 230252:tid 230400] [client 20.226.60.151:61100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/w1px.php"] [unique_id "al9I3E0Dwhk5-Z44XrpMqwAAAqk"]
[Tue Jul 21 07:24:28.526376 2026] [security2:error] [pid 229246:tid 229389] [client 103.162.129.114:54526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9I3CBMYeh5YLVG45xw0wAAAiE"]
[Tue Jul 21 07:24:28.526486 2026] [security2:error] [pid 229246:tid 229389] [client 103.162.129.114:54526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9I3CBMYeh5YLVG45xw0wAAAiE"]
[Tue Jul 21 07:24:28.536647 2026] [security2:error] [pid 230252:tid 230386] [client 20.226.60.151:60197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/777.php"] [unique_id "al9I3E0Dwhk5-Z44XrpMrgAAAps"]
[Tue Jul 21 07:24:28.557890 2026] [security2:error] [pid 230252:tid 230334] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I3E0Dwhk5-Z44XrpMrwAC-E8"]
[Tue Jul 21 07:24:28.558034 2026] [security2:error] [pid 230252:tid 230479] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I3E0Dwhk5-Z44XrpMrwAC-E8"]
[Tue Jul 21 07:24:29.035761 2026] [security2:error] [pid 230252:tid 230397] [client 117.251.86.144:60530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9I3U0Dwhk5-Z44XrpMsAAAAqY"]
[Tue Jul 21 07:24:29.035888 2026] [security2:error] [pid 230252:tid 230397] [client 117.251.86.144:60530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9I3U0Dwhk5-Z44XrpMsAAAAqY"]
[Tue Jul 21 07:24:29.175355 2026] [security2:error] [pid 230252:tid 230476] [client 20.226.60.151:56885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9I3U0Dwhk5-Z44XrpMsQAAAvU"]
[Tue Jul 21 07:24:29.191556 2026] [proxy:error] [pid 229246:tid 229467] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:29.191646 2026] [proxy_http:error] [pid 229246:tid 229467] [client 20.151.10.161:65508] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:29.192263 2026] [proxy:error] [pid 229246:tid 229467] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:29.192293 2026] [proxy_http:error] [pid 229246:tid 229467] [client 20.151.10.161:65508] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:29.285380 2026] [security2:error] [pid 229246:tid 229473] [client 109.248.148.246:59492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9I3SBMYeh5YLVG45xw3wAAAnU"]
[Tue Jul 21 07:24:29.285502 2026] [security2:error] [pid 229246:tid 229473] [client 109.248.148.246:59492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9I3SBMYeh5YLVG45xw3wAAAnU"]
[Tue Jul 21 07:24:29.390717 2026] [security2:error] [pid 230252:tid 230445] [client 20.220.225.223:46115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/cro.php"] [unique_id "al9I3U0Dwhk5-Z44XrpMswAAAtY"]
[Tue Jul 21 07:24:29.446647 2026] [security2:error] [pid 230252:tid 230415] [client 20.151.10.161:49029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/zoro.php"] [unique_id "al9I3U0Dwhk5-Z44XrpMtgAAArg"]
[Tue Jul 21 07:24:29.690837 2026] [security2:error] [pid 229246:tid 229344] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I3SBMYeh5YLVG45xw5wACZmE"]
[Tue Jul 21 07:24:29.691017 2026] [security2:error] [pid 229246:tid 229458] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I3SBMYeh5YLVG45xw5wACZmE"]
[Tue Jul 21 07:24:30.053921 2026] [security2:error] [pid 229246:tid 229328] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9I3iBMYeh5YLVG45xw7gACQVE"]
[Tue Jul 21 07:24:30.054068 2026] [security2:error] [pid 229246:tid 229421] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9I3iBMYeh5YLVG45xw7gACQVE"]
[Tue Jul 21 07:24:30.105200 2026] [security2:error] [pid 229246:tid 229447] [client 20.226.60.151:50791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/for.php"] [unique_id "al9I3iBMYeh5YLVG45xw7wAAAls"]
[Tue Jul 21 07:24:30.324129 2026] [security2:error] [pid 230252:tid 230410] [client 20.220.225.223:46134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/cron-tab.php"] [unique_id "al9I3k0Dwhk5-Z44XrpMuQAAArM"]
[Tue Jul 21 07:24:30.363443 2026] [security2:error] [pid 230252:tid 230403] [client 20.226.60.151:56959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/8.php"] [unique_id "al9I3k0Dwhk5-Z44XrpMugAAAqw"]
[Tue Jul 21 07:24:30.531000 2026] [security2:error] [pid 229246:tid 229380] [client 20.151.10.161:26520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/f6.php"] [unique_id "al9I3iBMYeh5YLVG45xw8wAAAhg"]
[Tue Jul 21 07:24:30.561258 2026] [security2:error] [pid 229246:tid 229398] [client 20.226.60.151:61063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/yawa.php"] [unique_id "al9I3iBMYeh5YLVG45xw9gAAAio"]
[Tue Jul 21 07:24:30.693683 2026] [security2:error] [pid 229246:tid 229253] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9I3iBMYeh5YLVG45xw9wACMQY"]
[Tue Jul 21 07:24:30.693885 2026] [security2:error] [pid 229246:tid 229405] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9I3iBMYeh5YLVG45xw9wACMQY"]
[Tue Jul 21 07:24:30.817967 2026] [security2:error] [pid 229246:tid 229423] [client 213.152.162.104:49786] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9I3iBMYeh5YLVG45xw-gAAAkM"]
[Tue Jul 21 07:24:30.818075 2026] [security2:error] [pid 229246:tid 229423] [client 213.152.162.104:49786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9I3iBMYeh5YLVG45xw-gAAAkM"]
[Tue Jul 21 07:24:31.543356 2026] [proxy:error] [pid 230252:tid 230432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:31.543439 2026] [proxy_http:error] [pid 230252:tid 230432] [client 20.151.10.161:65507] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:31.544199 2026] [proxy:error] [pid 230252:tid 230432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:31.544229 2026] [proxy_http:error] [pid 230252:tid 230432] [client 20.151.10.161:65507] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:31.719775 2026] [security2:error] [pid 230252:tid 230487] [client 74.249.245.134:21429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/0x.php"] [unique_id "al9I300Dwhk5-Z44XrpMwQAAAwA"]
[Tue Jul 21 07:24:32.029661 2026] [security2:error] [pid 229246:tid 229486] [client 20.226.60.151:56868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9I4CBMYeh5YLVG45xxBQAAAoI"]
[Tue Jul 21 07:24:32.079328 2026] [security2:error] [pid 229246:tid 229492] [client 20.151.10.161:48609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/admin.php"] [unique_id "al9I4CBMYeh5YLVG45xxBwAAAog"]
[Tue Jul 21 07:24:32.327057 2026] [security2:error] [pid 229246:tid 229426] [client 103.106.20.201:57756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I4CBMYeh5YLVG45xxCgAAAkY"]
[Tue Jul 21 07:24:32.327189 2026] [security2:error] [pid 229246:tid 229426] [client 103.106.20.201:57756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I4CBMYeh5YLVG45xxCgAAAkY"]
[Tue Jul 21 07:24:32.365484 2026] [security2:error] [pid 229246:tid 229259] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9I4CBMYeh5YLVG45xxCwACOAw"]
[Tue Jul 21 07:24:32.365619 2026] [security2:error] [pid 229246:tid 229412] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9I4CBMYeh5YLVG45xxCwACOAw"]
[Tue Jul 21 07:24:32.416766 2026] [security2:error] [pid 229246:tid 229500] [client 20.151.10.161:65468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/pucci.php"] [unique_id "al9I4CBMYeh5YLVG45xxDgAAApA"]
[Tue Jul 21 07:24:32.663631 2026] [security2:error] [pid 230252:tid 230489] [client 103.174.34.15:55480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I4E0Dwhk5-Z44XrpMxgAAAwI"]
[Tue Jul 21 07:24:32.663762 2026] [security2:error] [pid 230252:tid 230489] [client 103.174.34.15:55480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I4E0Dwhk5-Z44XrpMxgAAAwI"]
[Tue Jul 21 07:24:32.736929 2026] [security2:error] [pid 229246:tid 229417] [client 20.226.60.151:50790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/ssla.php"] [unique_id "al9I4CBMYeh5YLVG45xxFwAAAj0"]
[Tue Jul 21 07:24:32.985341 2026] [security2:error] [pid 230252:tid 230452] [client 62.102.148.164:39406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9I4E0Dwhk5-Z44XrpMygAAAt0"]
[Tue Jul 21 07:24:32.985455 2026] [security2:error] [pid 230252:tid 230452] [client 62.102.148.164:39406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9I4E0Dwhk5-Z44XrpMygAAAt0"]
[Tue Jul 21 07:24:33.001350 2026] [security2:error] [pid 229246:tid 229351] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9I4CBMYeh5YLVG45xxHgACHGg"]
[Tue Jul 21 07:24:33.001479 2026] [security2:error] [pid 229246:tid 229384] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9I4CBMYeh5YLVG45xxHgACHGg"]
[Tue Jul 21 07:24:33.109496 2026] [security2:error] [pid 229246:tid 229475] [client 20.220.225.223:46012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/koiy.php"] [unique_id "al9I4SBMYeh5YLVG45xxIAAAAnc"]
[Tue Jul 21 07:24:33.366205 2026] [security2:error] [pid 229246:tid 229377] [client 20.151.10.161:26551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/inputs.php"] [unique_id "al9I4SBMYeh5YLVG45xxJgAAAhU"]
[Tue Jul 21 07:24:33.371860 2026] [security2:error] [pid 229246:tid 229385] [client 193.36.225.60:65035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9I4SBMYeh5YLVG45xxJwAAAh0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:24:33.416497 2026] [security2:error] [pid 229246:tid 229450] [client 20.226.60.151:56935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/f6.php"] [unique_id "al9I4SBMYeh5YLVG45xxKAAAAl4"]
[Tue Jul 21 07:24:33.853163 2026] [security2:error] [pid 230252:tid 230404] [client 82.102.28.107:42626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9I4U0Dwhk5-Z44XrpMzgAAAq0"]
[Tue Jul 21 07:24:33.853327 2026] [security2:error] [pid 230252:tid 230404] [client 82.102.28.107:42626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9I4U0Dwhk5-Z44XrpMzgAAAq0"]
[Tue Jul 21 07:24:33.971944 2026] [proxy:error] [pid 230252:tid 230444] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:33.972025 2026] [proxy_http:error] [pid 230252:tid 230444] [client 20.151.10.161:65491] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:33.972628 2026] [proxy:error] [pid 230252:tid 230444] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:33.972662 2026] [proxy_http:error] [pid 230252:tid 230444] [client 20.151.10.161:65491] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:34.008978 2026] [security2:error] [pid 229246:tid 229465] [client 175.45.70.82:61886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I4iBMYeh5YLVG45xxNQAAAm0"]
[Tue Jul 21 07:24:34.009126 2026] [security2:error] [pid 229246:tid 229465] [client 175.45.70.82:61886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I4iBMYeh5YLVG45xxNQAAAm0"]
[Tue Jul 21 07:24:34.064106 2026] [security2:error] [pid 230252:tid 230495] [client 47.128.63.113:60158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dralulmabhering.com"] [uri "/robots.txt"] [unique_id "al9I4k0Dwhk5-Z44XrpM0AAAAwg"]
[Tue Jul 21 07:24:34.109617 2026] [security2:error] [pid 230252:tid 230431] [client 20.226.60.151:56851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/inputs.php"] [unique_id "al9I4k0Dwhk5-Z44XrpM0QAAAsg"]
[Tue Jul 21 07:24:34.377798 2026] [security2:error] [pid 230252:tid 230498] [client 20.220.225.223:48535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/hp2.php"] [unique_id "al9I4k0Dwhk5-Z44XrpM1QAAAws"]
[Tue Jul 21 07:24:34.495418 2026] [security2:error] [pid 229246:tid 229492] [client 74.249.245.134:44122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/buy.php"] [unique_id "al9I4iBMYeh5YLVG45xxPwAAAog"]
[Tue Jul 21 07:24:34.683492 2026] [security2:error] [pid 229246:tid 229388] [client 45.251.232.145:58704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I4iBMYeh5YLVG45xxRQAAAiA"]
[Tue Jul 21 07:24:34.683587 2026] [security2:error] [pid 229246:tid 229388] [client 45.251.232.145:58704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I4iBMYeh5YLVG45xxRQAAAiA"]
[Tue Jul 21 07:24:35.007451 2026] [proxy:error] [pid 230252:tid 230392] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:35.007531 2026] [proxy_http:error] [pid 230252:tid 230392] [client 20.151.10.161:65520] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:35.008130 2026] [proxy:error] [pid 230252:tid 230392] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:35.008156 2026] [proxy_http:error] [pid 230252:tid 230392] [client 20.151.10.161:65520] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:35.134195 2026] [security2:error] [pid 229246:tid 229445] [client 20.151.10.161:26443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/av.php"] [unique_id "al9I4yBMYeh5YLVG45xxTQAAAlk"]
[Tue Jul 21 07:24:35.269295 2026] [security2:error] [pid 229246:tid 229472] [client 20.226.60.151:63320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/inputs.php"] [unique_id "al9I4yBMYeh5YLVG45xxUAAAAnQ"]
[Tue Jul 21 07:24:35.568143 2026] [security2:error] [pid 229246:tid 229479] [client 20.220.225.223:46086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/hp3.php"] [unique_id "al9I4yBMYeh5YLVG45xxVAAAAns"]
[Tue Jul 21 07:24:35.721961 2026] [security2:error] [pid 230252:tid 230403] [client 154.192.233.199:59372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I400Dwhk5-Z44XrpM4QAAAqw"]
[Tue Jul 21 07:24:35.722066 2026] [security2:error] [pid 230252:tid 230403] [client 154.192.233.199:59372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I400Dwhk5-Z44XrpM4QAAAqw"]
[Tue Jul 21 07:24:35.843724 2026] [security2:error] [pid 230252:tid 230447] [client 103.121.156.110:52795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9I400Dwhk5-Z44XrpM5gAAAtg"]
[Tue Jul 21 07:24:35.843846 2026] [security2:error] [pid 230252:tid 230447] [client 103.121.156.110:52795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9I400Dwhk5-Z44XrpM5gAAAtg"]
[Tue Jul 21 07:24:36.140298 2026] [security2:error] [pid 230252:tid 230426] [client 20.151.10.161:65460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-temp.php"] [unique_id "al9I5E0Dwhk5-Z44XrpM6gAAAsM"]
[Tue Jul 21 07:24:36.386854 2026] [security2:error] [pid 230252:tid 230506] [client 74.7.244.32:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agmiz.com.br"] [uri "/index.php"] [unique_id "al9I400Dwhk5-Z44XrpM5QAAAxM"]
[Tue Jul 21 07:24:36.387582 2026] [security2:error] [pid 230252:tid 230499] [client 74.7.244.32:49194] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agmiz.com.br"] [uri "/robots.txt"] [unique_id "al9I400Dwhk5-Z44XrpM4wADDBw"]
[Tue Jul 21 07:24:36.476763 2026] [security2:error] [pid 230252:tid 230411] [client 20.151.10.161:49069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/greap.php"] [unique_id "al9I5E0Dwhk5-Z44XrpM7wAAArQ"]
[Tue Jul 21 07:24:37.059248 2026] [security2:error] [pid 230252:tid 230458] [client 139.135.44.145:53578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9I5U0Dwhk5-Z44XrpM9AAAAuM"]
[Tue Jul 21 07:24:37.059455 2026] [security2:error] [pid 230252:tid 230458] [client 139.135.44.145:53578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9I5U0Dwhk5-Z44XrpM9AAAAuM"]
[Tue Jul 21 07:24:37.110743 2026] [proxy:error] [pid 230252:tid 230490] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:37.110844 2026] [proxy_http:error] [pid 230252:tid 230490] [client 20.151.10.161:65482] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:37.111621 2026] [proxy:error] [pid 230252:tid 230490] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:37.111677 2026] [proxy_http:error] [pid 230252:tid 230490] [client 20.151.10.161:65482] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:37.305312 2026] [security2:error] [pid 229246:tid 229382] [client 20.151.10.161:26537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/classwithtostring.php"] [unique_id "al9I5SBMYeh5YLVG45xxdgAAAho"]
[Tue Jul 21 07:24:37.336092 2026] [security2:error] [pid 229246:tid 229396] [client 20.226.60.151:63358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/classwithtostring.php"] [unique_id "al9I5SBMYeh5YLVG45xxdwAAAig"]
[Tue Jul 21 07:24:37.701305 2026] [security2:error] [pid 230252:tid 230397] [client 20.151.10.161:49095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/177.php"] [unique_id "al9I5U0Dwhk5-Z44XrpM-AAAAqY"]
[Tue Jul 21 07:24:37.794202 2026] [security2:error] [pid 230252:tid 230498] [client 74.249.245.134:52122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/sx.php"] [unique_id "al9I5U0Dwhk5-Z44XrpM-gAAAws"]
[Tue Jul 21 07:24:37.800838 2026] [security2:error] [pid 230252:tid 230445] [client 20.226.60.151:50726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/zc-131.php"] [unique_id "al9I5U0Dwhk5-Z44XrpM-wAAAtY"]
[Tue Jul 21 07:24:37.850795 2026] [security2:error] [pid 229246:tid 229419] [client 20.220.225.223:48564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9I5SBMYeh5YLVG45xxfgAAAj8"]
[Tue Jul 21 07:24:37.884948 2026] [security2:error] [pid 230252:tid 230425] [client 20.226.60.151:54492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/js.php"] [unique_id "al9I5U0Dwhk5-Z44XrpM_AAAAsI"]
[Tue Jul 21 07:24:37.956903 2026] [security2:error] [pid 230252:tid 230461] [client 20.220.225.223:45397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/aa1.php"] [unique_id "al9I5U0Dwhk5-Z44XrpM_gAAAuY"]
[Tue Jul 21 07:24:38.153339 2026] [security2:error] [pid 229246:tid 229347] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9I5iBMYeh5YLVG45xxgQACkGQ"]
[Tue Jul 21 07:24:38.153517 2026] [security2:error] [pid 229246:tid 229500] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9I5iBMYeh5YLVG45xxgQACkGQ"]
[Tue Jul 21 07:24:38.368366 2026] [security2:error] [pid 229246:tid 229487] [client 62.102.148.164:44712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9I5iBMYeh5YLVG45xxhgAAAoM"]
[Tue Jul 21 07:24:38.368501 2026] [security2:error] [pid 229246:tid 229487] [client 62.102.148.164:44712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9I5iBMYeh5YLVG45xxhgAAAoM"]
[Tue Jul 21 07:24:38.391541 2026] [security2:error] [pid 229246:tid 229440] [client 20.151.10.161:63658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/xmu.php"] [unique_id "al9I5iBMYeh5YLVG45xxhwAAAlQ"]
[Tue Jul 21 07:24:38.843036 2026] [security2:error] [pid 230252:tid 230483] [client 74.249.245.134:54364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9I5k0Dwhk5-Z44XrpNBAAAAvw"]
[Tue Jul 21 07:24:39.093034 2026] [security2:error] [pid 230252:tid 230341] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I500Dwhk5-Z44XrpNBwACvFY"]
[Tue Jul 21 07:24:39.093200 2026] [security2:error] [pid 230252:tid 230419] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I500Dwhk5-Z44XrpNBwACvFY"]
[Tue Jul 21 07:24:39.212196 2026] [security2:error] [pid 230252:tid 230471] [client 172.245.102.41:52151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9I500Dwhk5-Z44XrpNBgAAAvA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:24:39.233946 2026] [security2:error] [pid 230252:tid 230440] [client 20.151.10.161:49087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/199.php"] [unique_id "al9I500Dwhk5-Z44XrpNCAAAAtE"]
[Tue Jul 21 07:24:39.295087 2026] [security2:error] [pid 230252:tid 230432] [client 173.252.95.62:56136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9I500Dwhk5-Z44XrpNCQAAAsk"]
[Tue Jul 21 07:24:39.492696 2026] [security2:error] [pid 229246:tid 229377] [client 20.220.225.223:48523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/acew67.php"] [unique_id "al9I5yBMYeh5YLVG45xxkgAAAhU"]
[Tue Jul 21 07:24:39.509743 2026] [security2:error] [pid 230252:tid 230429] [client 103.162.129.114:54981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9I500Dwhk5-Z44XrpNCwAAAsY"]
[Tue Jul 21 07:24:39.509874 2026] [security2:error] [pid 230252:tid 230429] [client 103.162.129.114:54981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9I500Dwhk5-Z44XrpNCwAAAsY"]
[Tue Jul 21 07:24:39.558749 2026] [security2:error] [pid 230252:tid 230494] [client 20.220.225.223:45999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9I500Dwhk5-Z44XrpNDQAAAwc"]
[Tue Jul 21 07:24:39.794264 2026] [security2:error] [pid 230252:tid 230449] [client 117.251.86.144:49222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9I500Dwhk5-Z44XrpNDwAAAto"]
[Tue Jul 21 07:24:39.794373 2026] [security2:error] [pid 230252:tid 230449] [client 117.251.86.144:49222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9I500Dwhk5-Z44XrpNDwAAAto"]
[Tue Jul 21 07:24:39.857406 2026] [security2:error] [pid 230252:tid 230422] [client 173.252.95.41:43192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9I500Dwhk5-Z44XrpNEAAAAr8"]
[Tue Jul 21 07:24:39.976752 2026] [security2:error] [pid 229246:tid 229470] [client 20.220.225.223:46116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/dp.php"] [unique_id "al9I5yBMYeh5YLVG45xxmQAAAnI"]
[Tue Jul 21 07:24:39.998521 2026] [security2:error] [pid 229246:tid 229380] [client 20.220.225.223:45993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/bscclapb.php"] [unique_id "al9I5yBMYeh5YLVG45xxmgAAAhg"]
[Tue Jul 21 07:24:40.066305 2026] [security2:error] [pid 230252:tid 230509] [client 20.52.136.55:1757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9I6E0Dwhk5-Z44XrpNEQAAAxY"]
[Tue Jul 21 07:24:40.147893 2026] [security2:error] [pid 229246:tid 229406] [client 20.151.10.161:65456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9I6CBMYeh5YLVG45xxnAAAAjI"]
[Tue Jul 21 07:24:40.195491 2026] [security2:error] [pid 229246:tid 229268] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I6CBMYeh5YLVG45xxnQACSxU"]
[Tue Jul 21 07:24:40.195665 2026] [security2:error] [pid 229246:tid 229431] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I6CBMYeh5YLVG45xxnQACSxU"]
[Tue Jul 21 07:24:40.366435 2026] [security2:error] [pid 230252:tid 230470] [client 20.151.10.161:26444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9I6E0Dwhk5-Z44XrpNFQAAAu8"]
[Tue Jul 21 07:24:40.590112 2026] [security2:error] [pid 230252:tid 230263] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9I6E0Dwhk5-Z44XrpNHQAC4wk"]
[Tue Jul 21 07:24:40.590303 2026] [security2:error] [pid 230252:tid 230458] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9I6E0Dwhk5-Z44XrpNHQAC4wk"]
[Tue Jul 21 07:24:40.870786 2026] [security2:error] [pid 230252:tid 230464] [client 20.151.10.161:49063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/file52.php"] [unique_id "al9I6E0Dwhk5-Z44XrpNJgAAAuk"]
[Tue Jul 21 07:24:40.880216 2026] [security2:error] [pid 229246:tid 229379] [client 74.7.241.130:60590] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "senseriopreto.com.br.hvrtecnologia.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9I6CBMYeh5YLVG45xxpgACFwk"]
[Tue Jul 21 07:24:40.895126 2026] [security2:error] [pid 230252:tid 230485] [client 20.220.225.223:45959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/else1.php"] [unique_id "al9I6E0Dwhk5-Z44XrpNJwAAAv4"]
[Tue Jul 21 07:24:40.914500 2026] [security2:error] [pid 230252:tid 230414] [client 20.226.60.151:56902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9I6E0Dwhk5-Z44XrpNKAAAArc"]
[Tue Jul 21 07:24:41.106364 2026] [security2:error] [pid 230252:tid 230410] [client 20.226.60.151:54529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/core.php"] [unique_id "al9I6U0Dwhk5-Z44XrpNKQAAArM"]
[Tue Jul 21 07:24:41.276200 2026] [security2:error] [pid 229246:tid 229312] [remote 160.187.68.132:51184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arterisplus.tryhealth.shop"] [uri "/wp-login.php"] [unique_id "al9I6SBMYeh5YLVG45xxqgACY0E"]
[Tue Jul 21 07:24:41.495429 2026] [security2:error] [pid 230252:tid 230449] [client 20.220.225.223:45979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/old.php"] [unique_id "al9I6U0Dwhk5-Z44XrpNMwAAAto"]
[Tue Jul 21 07:24:41.534224 2026] [security2:error] [pid 229246:tid 229451] [client 20.151.10.161:63630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/puc.php"] [unique_id "al9I6SBMYeh5YLVG45xxsAAAAl8"]
[Tue Jul 21 07:24:41.715101 2026] [security2:error] [pid 230252:tid 230376] [remote 72.167.132.114:44172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9I6U0Dwhk5-Z44XrpNNwACyXk"]
[Tue Jul 21 07:24:41.755015 2026] [security2:error] [pid 230252:tid 230348] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9I6U0Dwhk5-Z44XrpNOAACw10"]
[Tue Jul 21 07:24:41.755174 2026] [security2:error] [pid 230252:tid 230426] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9I6U0Dwhk5-Z44XrpNOAACw10"]
[Tue Jul 21 07:24:41.770370 2026] [security2:error] [pid 229246:tid 229435] [client 173.252.95.7:46780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9I6SBMYeh5YLVG45xxsgAAAk8"]
[Tue Jul 21 07:24:41.875055 2026] [security2:error] [pid 229246:tid 229325] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9I6SBMYeh5YLVG45xxtgACRk4"]
[Tue Jul 21 07:24:41.875213 2026] [security2:error] [pid 229246:tid 229426] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9I6SBMYeh5YLVG45xxtgACRk4"]
[Tue Jul 21 07:24:41.980552 2026] [security2:error] [pid 230252:tid 230509] [client 20.151.10.161:48580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/122.php"] [unique_id "al9I6U0Dwhk5-Z44XrpNOwAAAxY"]
[Tue Jul 21 07:24:42.514567 2026] [security2:error] [pid 230252:tid 230467] [client 74.249.245.134:47083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/article.php"] [unique_id "al9I6k0Dwhk5-Z44XrpNRQAAAuw"]
[Tue Jul 21 07:24:42.807459 2026] [security2:error] [pid 229246:tid 229436] [client 74.249.245.134:54366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9I6iBMYeh5YLVG45xxvAAAAlA"]
[Tue Jul 21 07:24:42.859324 2026] [security2:error] [pid 229246:tid 229460] [client 20.151.10.161:63684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/themes.php"] [unique_id "al9I6iBMYeh5YLVG45xxvQAAAmg"]
[Tue Jul 21 07:24:42.928487 2026] [security2:error] [pid 230252:tid 230377] [remote 199.189.225.40:55787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9I6k0Dwhk5-Z44XrpNSwACyno"]
[Tue Jul 21 07:24:42.974931 2026] [security2:error] [pid 229246:tid 229253] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9I6iBMYeh5YLVG45xxwgACjwY"]
[Tue Jul 21 07:24:42.975075 2026] [security2:error] [pid 229246:tid 229499] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9I6iBMYeh5YLVG45xxwgACjwY"]
[Tue Jul 21 07:24:43.009529 2026] [security2:error] [pid 229246:tid 229417] [client 20.151.10.161:49066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/green1.php"] [unique_id "al9I6yBMYeh5YLVG45xxwwAAAj0"]
[Tue Jul 21 07:24:43.046129 2026] [security2:error] [pid 230252:tid 230461] [client 20.226.60.151:56877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-blog.php"] [unique_id "al9I600Dwhk5-Z44XrpNTAAAAuY"]
[Tue Jul 21 07:24:43.055687 2026] [security2:error] [pid 230252:tid 230404] [client 103.106.20.201:58351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I600Dwhk5-Z44XrpNTQAAAq0"]
[Tue Jul 21 07:24:43.055848 2026] [security2:error] [pid 230252:tid 230404] [client 103.106.20.201:58351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I600Dwhk5-Z44XrpNTQAAAq0"]
[Tue Jul 21 07:24:43.237064 2026] [security2:error] [pid 229246:tid 229384] [client 74.7.228.25:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.cartoriodecurupira.com.br.bililica.com"] [uri "/index.php"] [unique_id "al9I6yBMYeh5YLVG45xxxwAAAhw"]
[Tue Jul 21 07:24:43.237755 2026] [security2:error] [pid 229246:tid 229472] [client 74.7.228.25:56838] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.cartoriodecurupira.com.br.bililica.com"] [uri "/robots.txt"] [unique_id "al9I6yBMYeh5YLVG45xxxQACdBI"]
[Tue Jul 21 07:24:43.347433 2026] [security2:error] [pid 230252:tid 230417] [client 74.7.228.58:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cartoriodecurupira.com.br"] [uri "/index.php"] [unique_id "al9I600Dwhk5-Z44XrpNTwAAAro"]
[Tue Jul 21 07:24:43.348197 2026] [security2:error] [pid 229246:tid 229425] [client 74.7.228.58:50266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cartoriodecurupira.com.br"] [uri "/robots.txt"] [unique_id "al9I6yBMYeh5YLVG45xxywACRQM"]
[Tue Jul 21 07:24:43.407097 2026] [security2:error] [pid 230252:tid 230454] [client 51.195.244.0:50034] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "dharmanet.com.br"] [uri "/robots.txt"] [unique_id "al9I600Dwhk5-Z44XrpNUQAAAt8"]
[Tue Jul 21 07:24:43.407269 2026] [security2:error] [pid 230252:tid 230454] [client 51.195.244.0:50034] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dharmanet.com.br"] [uri "/robots.txt"] [unique_id "al9I600Dwhk5-Z44XrpNUQAAAt8"]
[Tue Jul 21 07:24:43.433130 2026] [security2:error] [pid 229246:tid 229485] [client 103.174.34.15:55948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I6yBMYeh5YLVG45xx0QAAAoE"]
[Tue Jul 21 07:24:43.433240 2026] [security2:error] [pid 229246:tid 229485] [client 103.174.34.15:55948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I6yBMYeh5YLVG45xx0QAAAoE"]
[Tue Jul 21 07:24:43.464023 2026] [security2:error] [pid 230252:tid 230405] [client 74.249.245.134:50972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/bootstrap.php"] [unique_id "al9I600Dwhk5-Z44XrpNUgAAAq4"]
[Tue Jul 21 07:24:43.526444 2026] [proxy:error] [pid 230252:tid 230451] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:43.526520 2026] [proxy_http:error] [pid 230252:tid 230451] [client 20.151.10.161:63660] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:43.527242 2026] [proxy:error] [pid 230252:tid 230451] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:43.527269 2026] [proxy_http:error] [pid 230252:tid 230451] [client 20.151.10.161:63660] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:43.583885 2026] [security2:error] [pid 230252:tid 230484] [client 20.220.225.223:45982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/ms-new.php"] [unique_id "al9I600Dwhk5-Z44XrpNVAAAAv0"]
[Tue Jul 21 07:24:43.771541 2026] [security2:error] [pid 230252:tid 230494] [client 20.151.10.161:26457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-blog.php"] [unique_id "al9I600Dwhk5-Z44XrpNVgAAAwc"]
[Tue Jul 21 07:24:43.783924 2026] [security2:error] [pid 230252:tid 230281] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9I600Dwhk5-Z44XrpNVwACsRs"]
[Tue Jul 21 07:24:43.784046 2026] [security2:error] [pid 230252:tid 230408] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9I600Dwhk5-Z44XrpNVwACsRs"]
[Tue Jul 21 07:24:43.951129 2026] [security2:error] [pid 230252:tid 230489] [client 20.151.10.161:49055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/biufile.php"] [unique_id "al9I600Dwhk5-Z44XrpNWQAAAwI"]
[Tue Jul 21 07:24:44.490005 2026] [security2:error] [pid 230252:tid 230457] [client 20.151.10.161:63692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/8.php"] [unique_id "al9I7E0Dwhk5-Z44XrpNZAAAAuI"]
[Tue Jul 21 07:24:44.781863 2026] [security2:error] [pid 230252:tid 230447] [client 175.45.70.82:62395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I7E0Dwhk5-Z44XrpNawAAAtg"]
[Tue Jul 21 07:24:44.781994 2026] [security2:error] [pid 230252:tid 230447] [client 175.45.70.82:62395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I7E0Dwhk5-Z44XrpNawAAAtg"]
[Tue Jul 21 07:24:44.808269 2026] [security2:error] [pid 230252:tid 230511] [client 54.39.203.216:42256] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "dharmanet.com.br"] [uri "/"] [unique_id "al9I7E0Dwhk5-Z44XrpNbAAAAxg"]
[Tue Jul 21 07:24:44.808392 2026] [security2:error] [pid 230252:tid 230511] [client 54.39.203.216:42256] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dharmanet.com.br"] [uri "/"] [unique_id "al9I7E0Dwhk5-Z44XrpNbAAAAxg"]
[Tue Jul 21 07:24:44.880796 2026] [security2:error] [pid 230252:tid 230498] [client 20.220.225.223:45391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/tkikikoko.php"] [unique_id "al9I7E0Dwhk5-Z44XrpNbQAAAws"]
[Tue Jul 21 07:24:44.960069 2026] [security2:error] [pid 230252:tid 230478] [client 173.252.95.35:47246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9I7E0Dwhk5-Z44XrpNbwAAAvc"]
[Tue Jul 21 07:24:45.195788 2026] [security2:error] [pid 229246:tid 229320] [remote 182.77.62.24:51764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-login.php"] [unique_id "al9I7SBMYeh5YLVG45xx7QACKUk"]
[Tue Jul 21 07:24:45.209829 2026] [autoindex:error] [pid 230252:tid 230418] [client 20.226.60.151:56841] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:24:45.220353 2026] [security2:error] [pid 229246:tid 229379] [client 45.251.232.145:59236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I7SBMYeh5YLVG45xx7gAAAhc"]
[Tue Jul 21 07:24:45.220473 2026] [security2:error] [pid 229246:tid 229379] [client 45.251.232.145:59236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I7SBMYeh5YLVG45xx7gAAAhc"]
[Tue Jul 21 07:24:45.243075 2026] [security2:error] [pid 229246:tid 229378] [client 20.226.60.151:56909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9I7SBMYeh5YLVG45xx7wAAAhY"]
[Tue Jul 21 07:24:45.431091 2026] [security2:error] [pid 230252:tid 230450] [client 20.151.10.161:65486] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.havoy.com.br"] [uri "/1.php"] [unique_id "al9I7U0Dwhk5-Z44XrpNcQAAAts"]
[Tue Jul 21 07:24:45.431225 2026] [security2:error] [pid 230252:tid 230450] [client 20.151.10.161:65486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/1.php"] [unique_id "al9I7U0Dwhk5-Z44XrpNcQAAAts"]
[Tue Jul 21 07:24:45.778574 2026] [security2:error] [pid 230252:tid 230454] [client 20.151.10.161:49027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wpconf.php"] [unique_id "al9I7U0Dwhk5-Z44XrpNcwAAAt8"]
[Tue Jul 21 07:24:45.917125 2026] [security2:error] [pid 230252:tid 230386] [client 136.144.33.104:29005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9I7U0Dwhk5-Z44XrpNdAAAAps"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:24:46.075967 2026] [security2:error] [pid 230252:tid 230469] [client 20.220.225.223:46143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-Blogs.php"] [unique_id "al9I7k0Dwhk5-Z44XrpNdgAAAu4"]
[Tue Jul 21 07:24:46.276718 2026] [security2:error] [pid 229246:tid 229332] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9I7iBMYeh5YLVG45xyAAACOlU"]
[Tue Jul 21 07:24:46.276916 2026] [security2:error] [pid 229246:tid 229414] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9I7iBMYeh5YLVG45xyAAACOlU"]
[Tue Jul 21 07:24:46.432884 2026] [security2:error] [pid 230252:tid 230452] [client 20.151.10.161:63685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/100.php"] [unique_id "al9I7k0Dwhk5-Z44XrpNgwAAAt0"]
[Tue Jul 21 07:24:46.453214 2026] [security2:error] [pid 230252:tid 230460] [client 74.249.245.134:5504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/wp.php"] [unique_id "al9I7k0Dwhk5-Z44XrpNhAAAAuU"]
[Tue Jul 21 07:24:46.480599 2026] [security2:error] [pid 230252:tid 230419] [client 103.121.156.110:53120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9I7k0Dwhk5-Z44XrpNhQAAArw"]
[Tue Jul 21 07:24:46.480724 2026] [security2:error] [pid 230252:tid 230419] [client 103.121.156.110:53120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9I7k0Dwhk5-Z44XrpNhQAAArw"]
[Tue Jul 21 07:24:46.971339 2026] [security2:error] [pid 230252:tid 230488] [client 154.192.233.199:59882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I7k0Dwhk5-Z44XrpNjAAAAwE"]
[Tue Jul 21 07:24:46.971487 2026] [security2:error] [pid 230252:tid 230488] [client 154.192.233.199:59882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I7k0Dwhk5-Z44XrpNjAAAAwE"]
[Tue Jul 21 07:24:47.205131 2026] [security2:error] [pid 230252:tid 230444] [client 47.128.34.23:40564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alperembalagens.com.br"] [uri "/robots.txt"] [unique_id "al9I700Dwhk5-Z44XrpNjwAAAtU"]
[Tue Jul 21 07:24:47.298591 2026] [security2:error] [pid 230252:tid 230499] [client 20.151.10.161:49146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/mosty.php"] [unique_id "al9I700Dwhk5-Z44XrpNkAAAAww"]
[Tue Jul 21 07:24:47.512556 2026] [security2:error] [pid 230252:tid 230498] [client 20.226.60.151:54535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/19.php"] [unique_id "al9I700Dwhk5-Z44XrpNlAAAAws"]
[Tue Jul 21 07:24:47.619254 2026] [security2:error] [pid 230252:tid 230464] [client 20.151.10.161:65433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/about.php"] [unique_id "al9I700Dwhk5-Z44XrpNlgAAAuk"]
[Tue Jul 21 07:24:47.735529 2026] [security2:error] [pid 230252:tid 230404] [client 20.226.60.151:56876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/ms-edit.php"] [unique_id "al9I700Dwhk5-Z44XrpNlwAAAq0"]
[Tue Jul 21 07:24:47.762679 2026] [security2:error] [pid 230252:tid 230467] [client 139.135.44.145:54386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9I700Dwhk5-Z44XrpNmAAAAuw"]
[Tue Jul 21 07:24:47.762810 2026] [security2:error] [pid 230252:tid 230467] [client 139.135.44.145:54386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9I700Dwhk5-Z44XrpNmAAAAuw"]
[Tue Jul 21 07:24:47.875012 2026] [security2:error] [pid 230252:tid 230423] [client 20.220.225.223:45983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-css.php"] [unique_id "al9I700Dwhk5-Z44XrpNnAAAAsA"]
[Tue Jul 21 07:24:47.975464 2026] [security2:error] [pid 230252:tid 230501] [client 20.52.136.55:1596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/wp.php"] [unique_id "al9I700Dwhk5-Z44XrpNngAAAw4"]
[Tue Jul 21 07:24:48.137711 2026] [security2:error] [pid 230252:tid 230451] [client 20.151.10.161:26554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9I8E0Dwhk5-Z44XrpNpAAAAtw"]
[Tue Jul 21 07:24:48.302404 2026] [security2:error] [pid 230252:tid 230408] [client 20.151.10.161:49148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/dejavu.php"] [unique_id "al9I8E0Dwhk5-Z44XrpNqAAAArE"]
[Tue Jul 21 07:24:48.514641 2026] [security2:error] [pid 229246:tid 229480] [client 20.226.60.151:56950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9I8CBMYeh5YLVG45xyFQAAAnw"]
[Tue Jul 21 07:24:48.524215 2026] [security2:error] [pid 229246:tid 229501] [client 20.151.10.161:65472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/about.php"] [unique_id "al9I8CBMYeh5YLVG45xyFgAAApE"]
[Tue Jul 21 07:24:48.745165 2026] [security2:error] [pid 229246:tid 229365] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9I8CBMYeh5YLVG45xyGwACcXY"]
[Tue Jul 21 07:24:48.745314 2026] [security2:error] [pid 229246:tid 229469] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9I8CBMYeh5YLVG45xyGwACcXY"]
[Tue Jul 21 07:24:49.042847 2026] [security2:error] [pid 230252:tid 230487] [client 74.249.245.134:5550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/new.php"] [unique_id "al9I8U0Dwhk5-Z44XrpNrwAAAwA"]
[Tue Jul 21 07:24:49.108537 2026] [access_compat:error] [pid 230252:tid 230443] [client 162.241.63.68:54566] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:24:49.237441 2026] [security2:error] [pid 230252:tid 230378] [remote 4.205.168.44:36402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/wp-login.php"] [unique_id "al9I8U0Dwhk5-Z44XrpNtQAC5Hs"]
[Tue Jul 21 07:24:49.436768 2026] [security2:error] [pid 230252:tid 230448] [client 20.151.10.161:65409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/admin.php"] [unique_id "al9I8U0Dwhk5-Z44XrpNugAAAtk"]
[Tue Jul 21 07:24:49.577765 2026] [security2:error] [pid 230252:tid 230425] [client 20.151.10.161:49114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/aaf.php"] [unique_id "al9I8U0Dwhk5-Z44XrpNvQAAAsI"]
[Tue Jul 21 07:24:49.582772 2026] [security2:error] [pid 230252:tid 230346] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I8U0Dwhk5-Z44XrpNvAADCFs"]
[Tue Jul 21 07:24:49.582939 2026] [security2:error] [pid 230252:tid 230495] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I8U0Dwhk5-Z44XrpNvAADCFs"]
[Tue Jul 21 07:24:49.940607 2026] [security2:error] [pid 229246:tid 229482] [client 20.220.225.223:46120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-explorer.php"] [unique_id "al9I8SBMYeh5YLVG45xyKQAAAn4"]
[Tue Jul 21 07:24:49.966626 2026] [security2:error] [pid 229246:tid 229456] [client 20.220.225.223:45952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/track.php"] [unique_id "al9I8SBMYeh5YLVG45xyKgAAAmQ"]
[Tue Jul 21 07:24:50.164497 2026] [autoindex:error] [pid 230252:tid 230494] [client 20.226.60.151:56841] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:24:50.170000 2026] [security2:error] [pid 230252:tid 230505] [client 20.226.60.151:56924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9I8k0Dwhk5-Z44XrpNxQAAAxI"]
[Tue Jul 21 07:24:50.242378 2026] [security2:error] [pid 230252:tid 230402] [client 103.162.129.114:55449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9I8k0Dwhk5-Z44XrpNyAAAAqs"]
[Tue Jul 21 07:24:50.242511 2026] [security2:error] [pid 230252:tid 230402] [client 103.162.129.114:55449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9I8k0Dwhk5-Z44XrpNyAAAAqs"]
[Tue Jul 21 07:24:50.434103 2026] [security2:error] [pid 229246:tid 229427] [client 173.252.95.21:64162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9I8iBMYeh5YLVG45xyMAAAAkc"]
[Tue Jul 21 07:24:50.435085 2026] [security2:error] [pid 230252:tid 230451] [client 20.151.10.161:65517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/admin.php"] [unique_id "al9I8k0Dwhk5-Z44XrpNywAAAtw"]
[Tue Jul 21 07:24:50.551209 2026] [security2:error] [pid 230252:tid 230483] [client 20.226.60.151:54591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/inc.php"] [unique_id "al9I8k0Dwhk5-Z44XrpNzwAAAvw"]
[Tue Jul 21 07:24:50.578957 2026] [security2:error] [pid 230252:tid 230478] [client 117.251.86.144:53502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9I8k0Dwhk5-Z44XrpN0QAAAvc"]
[Tue Jul 21 07:24:50.579125 2026] [security2:error] [pid 230252:tid 230478] [client 117.251.86.144:53502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9I8k0Dwhk5-Z44XrpN0QAAAvc"]
[Tue Jul 21 07:24:50.810977 2026] [security2:error] [pid 230252:tid 230323] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I8k0Dwhk5-Z44XrpN1QADAkU"]
[Tue Jul 21 07:24:50.811223 2026] [security2:error] [pid 230252:tid 230489] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I8k0Dwhk5-Z44XrpN1QADAkU"]
[Tue Jul 21 07:24:50.970414 2026] [security2:error] [pid 230252:tid 230470] [client 20.151.10.161:49064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/term.php"] [unique_id "al9I8k0Dwhk5-Z44XrpN1gAAAu8"]
[Tue Jul 21 07:24:51.030153 2026] [security2:error] [pid 229246:tid 229385] [client 20.226.60.151:54474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9I8yBMYeh5YLVG45xyNwAAAh0"]
[Tue Jul 21 07:24:51.097647 2026] [security2:error] [pid 230252:tid 230462] [client 20.151.10.161:63691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/edit.php"] [unique_id "al9I800Dwhk5-Z44XrpN1wAAAuc"]
[Tue Jul 21 07:24:51.320068 2026] [security2:error] [pid 230252:tid 230322] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9I800Dwhk5-Z44XrpN2AACukQ"]
[Tue Jul 21 07:24:51.320228 2026] [security2:error] [pid 230252:tid 230417] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9I800Dwhk5-Z44XrpN2AACukQ"]
[Tue Jul 21 07:24:51.330364 2026] [security2:error] [pid 230252:tid 230437] [client 74.249.245.134:5514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/class-t.api.php"] [unique_id "al9I800Dwhk5-Z44XrpN2QAAAs4"]
[Tue Jul 21 07:24:51.614358 2026] [security2:error] [pid 230252:tid 230459] [client 20.151.10.161:26340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/adminfuns.php"] [unique_id "al9I800Dwhk5-Z44XrpN3AAAAuQ"]
[Tue Jul 21 07:24:51.828404 2026] [security2:error] [pid 230252:tid 230447] [client 20.151.10.161:65414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9I800Dwhk5-Z44XrpN4AAAAtg"]
[Tue Jul 21 07:24:52.051025 2026] [security2:error] [pid 229246:tid 229468] [client 74.249.245.134:5553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/plugins.php"] [unique_id "al9I9CBMYeh5YLVG45xyRQAAAnA"]
[Tue Jul 21 07:24:52.362851 2026] [security2:error] [pid 230252:tid 230404] [client 74.249.245.134:50997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/config-backup.php"] [unique_id "al9I9E0Dwhk5-Z44XrpN5QAAAq0"]
[Tue Jul 21 07:24:52.567688 2026] [security2:error] [pid 230252:tid 230506] [client 74.249.245.134:5506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/jp.php"] [unique_id "al9I9E0Dwhk5-Z44XrpN5gAAAxM"]
[Tue Jul 21 07:24:52.603699 2026] [security2:error] [pid 230252:tid 230370] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9I9E0Dwhk5-Z44XrpN6gAC7XM"]
[Tue Jul 21 07:24:52.603827 2026] [security2:error] [pid 230252:tid 230468] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9I9E0Dwhk5-Z44XrpN6gAC7XM"]
[Tue Jul 21 07:24:52.766127 2026] [security2:error] [pid 230252:tid 230431] [client 193.36.225.54:61647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9I9E0Dwhk5-Z44XrpN6QAAAsg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:24:52.893943 2026] [autoindex:error] [pid 230252:tid 230501] [client 20.226.60.151:56841] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:24:52.933420 2026] [autoindex:error] [pid 230252:tid 230386] [client 20.226.60.151:56841] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:24:52.939404 2026] [security2:error] [pid 230252:tid 230464] [client 20.226.60.151:56863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/abcd.php"] [unique_id "al9I9E0Dwhk5-Z44XrpN8QAAAuk"]
[Tue Jul 21 07:24:53.037938 2026] [security2:error] [pid 229246:tid 229478] [client 74.249.245.134:54369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/error.php"] [unique_id "al9I9SBMYeh5YLVG45xyTgAAAno"]
[Tue Jul 21 07:24:53.225145 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:63713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/f6.php"] [unique_id "al9I9U0Dwhk5-Z44XrpN-AAAAwY"]
[Tue Jul 21 07:24:53.232499 2026] [security2:error] [pid 229246:tid 229448] [client 20.151.10.161:26368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/goods.php"] [unique_id "al9I9SBMYeh5YLVG45xyTwAAAlw"]
[Tue Jul 21 07:24:53.563707 2026] [security2:error] [pid 230252:tid 230391] [client 62.102.148.164:48748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9I9U0Dwhk5-Z44XrpN_AAAAqA"]
[Tue Jul 21 07:24:53.563850 2026] [security2:error] [pid 230252:tid 230391] [client 62.102.148.164:48748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9I9U0Dwhk5-Z44XrpN_AAAAqA"]
[Tue Jul 21 07:24:53.582360 2026] [security2:error] [pid 230252:tid 230316] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9I9U0Dwhk5-Z44XrpN_gACvz4"]
[Tue Jul 21 07:24:53.582480 2026] [security2:error] [pid 230252:tid 230422] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9I9U0Dwhk5-Z44XrpN_gACvz4"]
[Tue Jul 21 07:24:53.585006 2026] [security2:error] [pid 230252:tid 230392] [client 20.52.136.55:1561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/new.php"] [unique_id "al9I9U0Dwhk5-Z44XrpN_wAAAqE"]
[Tue Jul 21 07:24:53.687965 2026] [security2:error] [pid 230252:tid 230449] [client 74.249.245.134:5547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/classwithtostring.php"] [unique_id "al9I9U0Dwhk5-Z44XrpOAAAAAto"]
[Tue Jul 21 07:24:53.812420 2026] [security2:error] [pid 229246:tid 229481] [client 103.106.20.201:58945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I9SBMYeh5YLVG45xyVgAAAn0"]
[Tue Jul 21 07:24:53.812533 2026] [security2:error] [pid 229246:tid 229481] [client 103.106.20.201:58945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I9SBMYeh5YLVG45xyVgAAAn0"]
[Tue Jul 21 07:24:53.812605 2026] [security2:error] [pid 230252:tid 230470] [client 20.151.10.161:65412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/inputs.php"] [unique_id "al9I9U0Dwhk5-Z44XrpOAQAAAu8"]
[Tue Jul 21 07:24:53.893539 2026] [security2:error] [pid 229246:tid 229418] [client 20.151.10.161:49094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/ha.php"] [unique_id "al9I9SBMYeh5YLVG45xyWgAAAj4"]
[Tue Jul 21 07:24:54.083245 2026] [security2:error] [pid 230252:tid 230437] [client 74.249.245.134:5554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/bless.php"] [unique_id "al9I9k0Dwhk5-Z44XrpOBAAAAs4"]
[Tue Jul 21 07:24:54.233795 2026] [security2:error] [pid 229246:tid 229469] [client 103.174.34.15:56422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I9iBMYeh5YLVG45xyXwAAAnE"]
[Tue Jul 21 07:24:54.233934 2026] [security2:error] [pid 229246:tid 229469] [client 103.174.34.15:56422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I9iBMYeh5YLVG45xyXwAAAnE"]
[Tue Jul 21 07:24:54.553377 2026] [security2:error] [pid 230252:tid 230367] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9I9k0Dwhk5-Z44XrpODAACmXA"]
[Tue Jul 21 07:24:54.553532 2026] [security2:error] [pid 230252:tid 230384] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9I9k0Dwhk5-Z44XrpODAACmXA"]
[Tue Jul 21 07:24:54.573374 2026] [security2:error] [pid 230252:tid 230425] [client 20.220.225.223:46131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/akismet.php"] [unique_id "al9I9k0Dwhk5-Z44XrpODQAAAsI"]
[Tue Jul 21 07:24:54.664921 2026] [security2:error] [pid 230252:tid 230488] [client 20.226.60.151:56933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/file15.php"] [unique_id "al9I9k0Dwhk5-Z44XrpODgAAAwE"]
[Tue Jul 21 07:24:54.869215 2026] [security2:error] [pid 230252:tid 230404] [client 20.151.10.161:65519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/inputs.php"] [unique_id "al9I9k0Dwhk5-Z44XrpODwAAAq0"]
[Tue Jul 21 07:24:55.002084 2026] [security2:error] [pid 230252:tid 230506] [client 20.151.10.161:49045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/hur.php"] [unique_id "al9I900Dwhk5-Z44XrpOEAAAAxM"]
[Tue Jul 21 07:24:55.107592 2026] [security2:error] [pid 230252:tid 230418] [client 62.102.148.164:48750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9I900Dwhk5-Z44XrpOEQAAArs"]
[Tue Jul 21 07:24:55.107693 2026] [security2:error] [pid 230252:tid 230418] [client 62.102.148.164:48750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9I900Dwhk5-Z44XrpOEQAAArs"]
[Tue Jul 21 07:24:55.462017 2026] [security2:error] [pid 229246:tid 229473] [client 74.249.245.134:5505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/storage/index.php"] [unique_id "al9I9yBMYeh5YLVG45xybQAAAnU"]
[Tue Jul 21 07:24:55.558842 2026] [security2:error] [pid 230252:tid 230435] [client 49.13.130.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9I900Dwhk5-Z44XrpOFAACzGk"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:24:55.573047 2026] [security2:error] [pid 230252:tid 230395] [client 175.45.70.82:62905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I900Dwhk5-Z44XrpOFQAAAqQ"]
[Tue Jul 21 07:24:55.573192 2026] [security2:error] [pid 230252:tid 230395] [client 175.45.70.82:62905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I900Dwhk5-Z44XrpOFQAAAqQ"]
[Tue Jul 21 07:24:55.615637 2026] [security2:error] [pid 229246:tid 229414] [client 20.151.10.161:65457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/av.php"] [unique_id "al9I9yBMYeh5YLVG45xybgAAAjo"]
[Tue Jul 21 07:24:55.722297 2026] [security2:error] [pid 230252:tid 230414] [client 45.251.232.145:59753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I900Dwhk5-Z44XrpOGAAAArc"]
[Tue Jul 21 07:24:55.722406 2026] [security2:error] [pid 230252:tid 230414] [client 45.251.232.145:59753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I900Dwhk5-Z44XrpOGAAAArc"]
[Tue Jul 21 07:24:56.061524 2026] [security2:error] [pid 229246:tid 229385] [client 20.151.10.161:26385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/ms-edit.php"] [unique_id "al9I-CBMYeh5YLVG45xydQAAAh0"]
[Tue Jul 21 07:24:56.118379 2026] [security2:error] [pid 229246:tid 229400] [client 49.13.130.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9I-CBMYeh5YLVG45xydgACLBE"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:24:56.536213 2026] [security2:error] [pid 229246:tid 229348] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9I-CBMYeh5YLVG45xyfQACJGU"]
[Tue Jul 21 07:24:56.536367 2026] [security2:error] [pid 229246:tid 229392] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9I-CBMYeh5YLVG45xyfQACJGU"]
[Tue Jul 21 07:24:56.558469 2026] [security2:error] [pid 230252:tid 230391] [client 20.151.10.161:65411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/classwithtostring.php"] [unique_id "al9I-E0Dwhk5-Z44XrpOHAAAAqA"]
[Tue Jul 21 07:24:56.691260 2026] [security2:error] [pid 230252:tid 230509] [client 74.249.245.134:5535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/g.php"] [unique_id "al9I-E0Dwhk5-Z44XrpOHwAAAxY"]
[Tue Jul 21 07:24:56.854653 2026] [autoindex:error] [pid 230252:tid 230460] [client 205.210.31.161:58310] AH01276: Cannot serve directory /home1/pedid516/cursodepilacaoprofissional.pedido-online.net/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:24:57.018052 2026] [security2:error] [pid 230252:tid 230459] [client 74.249.245.134:60836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/goods.php"] [unique_id "al9I-U0Dwhk5-Z44XrpOKQAAAuQ"]
[Tue Jul 21 07:24:57.140748 2026] [security2:error] [pid 229246:tid 229425] [client 103.121.156.110:53440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9I-SBMYeh5YLVG45xyhAAAAkU"]
[Tue Jul 21 07:24:57.140893 2026] [security2:error] [pid 229246:tid 229425] [client 103.121.156.110:53440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9I-SBMYeh5YLVG45xyhAAAAkU"]
[Tue Jul 21 07:24:57.155344 2026] [security2:error] [pid 230252:tid 230489] [client 213.152.162.104:40656] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9I-U0Dwhk5-Z44XrpOKgAAAwI"]
[Tue Jul 21 07:24:57.155427 2026] [security2:error] [pid 230252:tid 230489] [client 213.152.162.104:40656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9I-U0Dwhk5-Z44XrpOKgAAAwI"]
[Tue Jul 21 07:24:57.195711 2026] [security2:error] [pid 230252:tid 230490] [client 20.151.10.161:65504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9I-U0Dwhk5-Z44XrpOKwAAAwM"]
[Tue Jul 21 07:24:57.242797 2026] [security2:error] [pid 230252:tid 230499] [client 213.152.162.104:58138] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9I-U0Dwhk5-Z44XrpOLAAAAww"]
[Tue Jul 21 07:24:57.242902 2026] [security2:error] [pid 230252:tid 230499] [client 213.152.162.104:58138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9I-U0Dwhk5-Z44XrpOLAAAAww"]
[Tue Jul 21 07:24:57.412199 2026] [security2:error] [pid 230252:tid 230457] [client 20.226.60.151:56886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/jp.php"] [unique_id "al9I-U0Dwhk5-Z44XrpOLgAAAuI"]
[Tue Jul 21 07:24:57.551013 2026] [security2:error] [pid 229246:tid 229267] [remote 69.63.184.23:36442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.184.63.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9I-SBMYeh5YLVG45xyjAACGRQ"]
[Tue Jul 21 07:24:57.613079 2026] [security2:error] [pid 229246:tid 229474] [client 20.220.225.223:46096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/ace2.php"] [unique_id "al9I-SBMYeh5YLVG45xyjgAAAnY"]
[Tue Jul 21 07:24:57.665608 2026] [security2:error] [pid 229246:tid 229448] [client 20.151.10.161:26409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/222.php"] [unique_id "al9I-SBMYeh5YLVG45xykAAAAlw"]
[Tue Jul 21 07:24:57.676523 2026] [security2:error] [pid 229246:tid 229393] [client 20.226.60.151:54477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9I-SBMYeh5YLVG45xykQAAAiU"]
[Tue Jul 21 07:24:57.717938 2026] [security2:error] [pid 229246:tid 229429] [client 20.151.10.161:65416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-blog.php"] [unique_id "al9I-SBMYeh5YLVG45xykgAAAkk"]
[Tue Jul 21 07:24:57.964330 2026] [security2:error] [pid 229246:tid 229489] [client 74.249.245.134:54353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/nf.php"] [unique_id "al9I-SBMYeh5YLVG45xylAAAAoU"]
[Tue Jul 21 07:24:57.984191 2026] [security2:error] [pid 230252:tid 230488] [client 20.151.10.161:49145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/h02ugyh.php"] [unique_id "al9I-U0Dwhk5-Z44XrpOMgAAAwE"]
[Tue Jul 21 07:24:58.019905 2026] [security2:error] [pid 230252:tid 230467] [client 20.220.225.223:46005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/2352356666.php"] [unique_id "al9I-k0Dwhk5-Z44XrpOMwAAAuw"]
[Tue Jul 21 07:24:58.610632 2026] [security2:error] [pid 230252:tid 230483] [client 136.144.33.28:25095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9I-k0Dwhk5-Z44XrpOOAAAAvw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:24:58.649856 2026] [security2:error] [pid 230252:tid 230479] [client 139.135.44.145:53290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9I-k0Dwhk5-Z44XrpOOQAAAvg"]
[Tue Jul 21 07:24:58.654976 2026] [security2:error] [pid 230252:tid 230479] [client 139.135.44.145:53290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9I-k0Dwhk5-Z44XrpOOQAAAvg"]
[Tue Jul 21 07:24:59.177740 2026] [security2:error] [pid 229246:tid 229492] [client 20.52.136.55:1571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/class-t.api.php"] [unique_id "al9I-yBMYeh5YLVG45xynQAAAog"]
[Tue Jul 21 07:24:59.232292 2026] [security2:error] [pid 230252:tid 230466] [client 20.151.10.161:26543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9I-00Dwhk5-Z44XrpOPgAAAus"]
[Tue Jul 21 07:24:59.252730 2026] [security2:error] [pid 230252:tid 230391] [client 74.249.245.134:5566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/xda.php"] [unique_id "al9I-00Dwhk5-Z44XrpOPwAAAqA"]
[Tue Jul 21 07:24:59.260020 2026] [security2:error] [pid 230252:tid 230351] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9I-00Dwhk5-Z44XrpOQAACr2A"]
[Tue Jul 21 07:24:59.260245 2026] [security2:error] [pid 230252:tid 230406] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9I-00Dwhk5-Z44XrpOQAACr2A"]
[Tue Jul 21 07:24:59.308951 2026] [security2:error] [pid 230252:tid 230402] [client 154.192.233.199:58634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I-00Dwhk5-Z44XrpOQQAAAqs"]
[Tue Jul 21 07:24:59.309094 2026] [security2:error] [pid 230252:tid 230402] [client 154.192.233.199:58634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I-00Dwhk5-Z44XrpOQQAAAqs"]
[Tue Jul 21 07:24:59.899413 2026] [security2:error] [pid 230252:tid 230413] [client 20.226.60.151:56874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/f35.php"] [unique_id "al9I-00Dwhk5-Z44XrpORgAAArY"]
[Tue Jul 21 07:25:00.153972 2026] [security2:error] [pid 229246:tid 229294] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I_CBMYeh5YLVG45xyqQACLS8"]
[Tue Jul 21 07:25:00.154103 2026] [security2:error] [pid 229246:tid 229401] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I_CBMYeh5YLVG45xyqQACLS8"]
[Tue Jul 21 07:25:00.325613 2026] [security2:error] [pid 230252:tid 230446] [client 20.220.225.223:45961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/ms.php"] [unique_id "al9I_E0Dwhk5-Z44XrpOSQAAAtc"]
[Tue Jul 21 07:25:00.328561 2026] [security2:error] [pid 229246:tid 229476] [client 20.220.225.223:46126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/pn.php"] [unique_id "al9I_CBMYeh5YLVG45xyqwAAAng"]
[Tue Jul 21 07:25:00.473709 2026] [security2:error] [pid 230252:tid 230430] [client 191.102.187.245:33582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "500"] [hostname "tkcorretoradeseguros.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I_E0Dwhk5-Z44XrpOSAAAAsc"]
[Tue Jul 21 07:25:00.655475 2026] [security2:error] [pid 230252:tid 230454] [client 20.226.60.151:56913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-load.php"] [unique_id "al9I_E0Dwhk5-Z44XrpOTAAAAt8"]
[Tue Jul 21 07:25:00.716586 2026] [security2:error] [pid 229246:tid 229499] [client 103.162.129.114:55900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9I_CBMYeh5YLVG45xysAAAAo8"]
[Tue Jul 21 07:25:00.716701 2026] [security2:error] [pid 229246:tid 229499] [client 103.162.129.114:55900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9I_CBMYeh5YLVG45xysAAAAo8"]
[Tue Jul 21 07:25:00.810753 2026] [security2:error] [pid 230252:tid 230385] [client 82.102.28.107:38000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9I_E0Dwhk5-Z44XrpOTQAAApo"]
[Tue Jul 21 07:25:00.810854 2026] [security2:error] [pid 230252:tid 230385] [client 82.102.28.107:38000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9I_E0Dwhk5-Z44XrpOTQAAApo"]
[Tue Jul 21 07:25:00.852594 2026] [security2:error] [pid 229246:tid 229400] [client 168.119.123.75:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9I_CBMYeh5YLVG45xyswACLDw"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:25:01.030302 2026] [proxy:error] [pid 229246:tid 229497] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:01.030379 2026] [proxy_http:error] [pid 229246:tid 229497] [client 20.151.10.161:65466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:01.030941 2026] [proxy:error] [pid 229246:tid 229497] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:01.030966 2026] [proxy_http:error] [pid 229246:tid 229497] [client 20.151.10.161:65466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:01.124354 2026] [security2:error] [pid 230252:tid 230462] [client 74.249.245.134:43405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/init.php"] [unique_id "al9I_U0Dwhk5-Z44XrpOUQAAAuc"]
[Tue Jul 21 07:25:01.242871 2026] [security2:error] [pid 230252:tid 230459] [client 117.251.86.144:44012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9I_U0Dwhk5-Z44XrpOUwAAAuQ"]
[Tue Jul 21 07:25:01.243035 2026] [security2:error] [pid 230252:tid 230459] [client 117.251.86.144:44012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9I_U0Dwhk5-Z44XrpOUwAAAuQ"]
[Tue Jul 21 07:25:01.284394 2026] [security2:error] [pid 230252:tid 230425] [client 74.249.245.134:54346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/shell.php"] [unique_id "al9I_U0Dwhk5-Z44XrpOVQAAAsI"]
[Tue Jul 21 07:25:01.348533 2026] [security2:error] [pid 229246:tid 229358] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I_SBMYeh5YLVG45xyuwACJ28"]
[Tue Jul 21 07:25:01.348703 2026] [security2:error] [pid 229246:tid 229395] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I_SBMYeh5YLVG45xyuwACJ28"]
[Tue Jul 21 07:25:01.386958 2026] [security2:error] [pid 229246:tid 229391] [client 168.119.123.75:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9I_SBMYeh5YLVG45xyvAACI3M"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:25:01.773191 2026] [security2:error] [pid 230252:tid 230409] [client 62.102.148.164:37494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9I_U0Dwhk5-Z44XrpOXQAAArI"]
[Tue Jul 21 07:25:01.773298 2026] [security2:error] [pid 230252:tid 230409] [client 62.102.148.164:37494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9I_U0Dwhk5-Z44XrpOXQAAArI"]
[Tue Jul 21 07:25:01.926706 2026] [security2:error] [pid 230252:tid 230337] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9I_U0Dwhk5-Z44XrpOXgADDlI"]
[Tue Jul 21 07:25:01.926924 2026] [security2:error] [pid 230252:tid 230501] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9I_U0Dwhk5-Z44XrpOXgADDlI"]
[Tue Jul 21 07:25:02.182375 2026] [security2:error] [pid 230252:tid 230363] [remote 104.207.32.246:9899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.32.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9I_U0Dwhk5-Z44XrpOTgADA2w"]
[Tue Jul 21 07:25:02.843254 2026] [security2:error] [pid 230252:tid 230460] [client 20.226.60.151:63301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/xyn.php"] [unique_id "al9I_k0Dwhk5-Z44XrpObAAAAuU"]
[Tue Jul 21 07:25:02.931489 2026] [security2:error] [pid 230252:tid 230345] [remote 41.76.214.143:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/wp-login.php"] [unique_id "al9I_k0Dwhk5-Z44XrpObQAC91o"], referer: http://assumaocontrole.com/
[Tue Jul 21 07:25:03.061446 2026] [ssl:error] [pid 230252:tid 230439] [client 109.53.56.127:60818] AH02032: Hostname www.quattrotech.com.br provided via SNI and hostname open.spotify.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue Jul 21 07:25:03.266061 2026] [security2:error] [pid 230252:tid 230491] [client 20.151.10.161:63651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9I_00Dwhk5-Z44XrpOcAAAAwQ"]
[Tue Jul 21 07:25:03.284231 2026] [ssl:error] [pid 230252:tid 230485] [client 2.194.133.19:42880] AH02032: Hostname www.quattrotech.com.br provided via SNI and hostname open.spotify.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue Jul 21 07:25:03.347590 2026] [security2:error] [pid 230252:tid 230454] [client 74.249.245.134:54344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/3.php"] [unique_id "al9I_00Dwhk5-Z44XrpOdgAAAt8"]
[Tue Jul 21 07:25:03.483896 2026] [security2:error] [pid 230252:tid 230511] [client 20.151.10.161:26463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9I_00Dwhk5-Z44XrpOeAAAAxg"]
[Tue Jul 21 07:25:03.503067 2026] [security2:error] [pid 230252:tid 230381] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9I_00Dwhk5-Z44XrpOeQAC1H4"]
[Tue Jul 21 07:25:03.503275 2026] [security2:error] [pid 230252:tid 230443] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9I_00Dwhk5-Z44XrpOeQAC1H4"]
[Tue Jul 21 07:25:04.297464 2026] [security2:error] [pid 230252:tid 230300] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JAE0Dwhk5-Z44XrpOjgADEC4"]
[Tue Jul 21 07:25:04.297583 2026] [security2:error] [pid 230252:tid 230503] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JAE0Dwhk5-Z44XrpOjgADEC4"]
[Tue Jul 21 07:25:04.569773 2026] [security2:error] [pid 230252:tid 230502] [client 136.144.33.241:25459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JAE0Dwhk5-Z44XrpOkwAAAw8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:25:04.586373 2026] [security2:error] [pid 230252:tid 230433] [client 103.106.20.201:59537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JAE0Dwhk5-Z44XrpOlwAAAso"]
[Tue Jul 21 07:25:04.586525 2026] [security2:error] [pid 230252:tid 230433] [client 103.106.20.201:59537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JAE0Dwhk5-Z44XrpOlwAAAso"]
[Tue Jul 21 07:25:04.835334 2026] [security2:error] [pid 229246:tid 229379] [client 109.248.148.246:32806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9JACBMYeh5YLVG45xy2AAAAhc"]
[Tue Jul 21 07:25:04.835419 2026] [security2:error] [pid 229246:tid 229379] [client 109.248.148.246:32806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9JACBMYeh5YLVG45xy2AAAAhc"]
[Tue Jul 21 07:25:04.873585 2026] [security2:error] [pid 230252:tid 230401] [client 103.174.34.15:56897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JAE0Dwhk5-Z44XrpOnAAAAqo"]
[Tue Jul 21 07:25:04.873724 2026] [security2:error] [pid 230252:tid 230401] [client 103.174.34.15:56897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JAE0Dwhk5-Z44XrpOnAAAAqo"]
[Tue Jul 21 07:25:05.018279 2026] [authz_core:error] [pid 229246:tid 229439] [client 74.249.245.134:53030] AH01630: client denied by server configuration: /home4/drjoao27/public_html/php.ini
[Tue Jul 21 07:25:05.030445 2026] [security2:error] [pid 230252:tid 230452] [client 20.151.10.161:26510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp.php"] [unique_id "al9JAU0Dwhk5-Z44XrpOngAAAt0"]
[Tue Jul 21 07:25:05.120064 2026] [security2:error] [pid 229246:tid 229435] [client 20.151.10.161:63696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/adminfuns.php"] [unique_id "al9JASBMYeh5YLVG45xy3QAAAk8"]
[Tue Jul 21 07:25:05.170646 2026] [security2:error] [pid 229246:tid 229482] [client 74.249.245.134:53030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/settings.php"] [unique_id "al9JASBMYeh5YLVG45xy3gAAAn4"]
[Tue Jul 21 07:25:05.262173 2026] [security2:error] [pid 230252:tid 230410] [client 82.102.28.107:39862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JAU0Dwhk5-Z44XrpOoAAAArM"]
[Tue Jul 21 07:25:05.262275 2026] [security2:error] [pid 230252:tid 230410] [client 82.102.28.107:39862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JAU0Dwhk5-Z44XrpOoAAAArM"]
[Tue Jul 21 07:25:05.316777 2026] [security2:error] [pid 230252:tid 230373] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JAU0Dwhk5-Z44XrpOoQAC0nY"]
[Tue Jul 21 07:25:05.316994 2026] [security2:error] [pid 230252:tid 230441] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JAU0Dwhk5-Z44XrpOoQAC0nY"]
[Tue Jul 21 07:25:05.324596 2026] [proxy:error] [pid 230252:tid 230509] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:05.324649 2026] [proxy_http:error] [pid 230252:tid 230509] [client 185.93.89.147:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:05.325245 2026] [proxy:error] [pid 230252:tid 230509] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:05.325274 2026] [proxy_http:error] [pid 230252:tid 230509] [client 185.93.89.147:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:05.726067 2026] [security2:error] [pid 230252:tid 230453] [client 74.249.245.134:54347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/mds.php"] [unique_id "al9JAU0Dwhk5-Z44XrpOqAAAAt4"]
[Tue Jul 21 07:25:06.132065 2026] [security2:error] [pid 230252:tid 230444] [client 20.151.10.161:26469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/abcd.php"] [unique_id "al9JAk0Dwhk5-Z44XrpOrwAAAtU"]
[Tue Jul 21 07:25:06.169708 2026] [security2:error] [pid 229246:tid 229496] [client 45.251.232.145:60275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JAiBMYeh5YLVG45xy6gAAAow"]
[Tue Jul 21 07:25:06.169909 2026] [security2:error] [pid 229246:tid 229496] [client 45.251.232.145:60275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JAiBMYeh5YLVG45xy6gAAAow"]
[Tue Jul 21 07:25:06.268702 2026] [security2:error] [pid 230252:tid 230462] [client 91.92.47.101:50620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/wp-config.php"] [unique_id "al9JAk0Dwhk5-Z44XrpOsgAAAuc"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:25:06.269118 2026] [security2:error] [pid 230252:tid 230384] [client 91.92.47.101:50622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/phpinfo.php"] [unique_id "al9JAk0Dwhk5-Z44XrpOtAAAApk"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:25:06.269380 2026] [security2:error] [pid 230252:tid 230404] [client 91.92.47.101:50606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/config.php"] [unique_id "al9JAk0Dwhk5-Z44XrpOswAAAq0"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:25:06.286984 2026] [security2:error] [pid 230252:tid 230454] [client 175.45.70.82:63413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JAk0Dwhk5-Z44XrpOtgAAAt8"]
[Tue Jul 21 07:25:06.287086 2026] [security2:error] [pid 230252:tid 230454] [client 175.45.70.82:63413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JAk0Dwhk5-Z44XrpOtgAAAt8"]
[Tue Jul 21 07:25:06.296330 2026] [security2:error] [pid 229246:tid 229488] [client 74.7.241.192:41040] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.a09.arcoll.com.br"] [uri "/public/robots.txt"] [unique_id "al9JAiBMYeh5YLVG45xy6wAChAc"]
[Tue Jul 21 07:25:06.322070 2026] [security2:error] [pid 229246:tid 229402] [client 74.249.245.134:5542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/archive.php"] [unique_id "al9JAiBMYeh5YLVG45xy7QAAAi4"]
[Tue Jul 21 07:25:06.468986 2026] [security2:error] [pid 230252:tid 230405] [client 91.92.47.101:50652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "look.dealspark.com.br"] [uri "/.env"] [unique_id "al9JAk0Dwhk5-Z44XrpOwQAAAq4"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:25:06.479846 2026] [security2:error] [pid 230252:tid 230451] [client 91.92.47.101:50624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/info.php"] [unique_id "al9JAk0Dwhk5-Z44XrpOwgAAAtw"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:25:06.699587 2026] [autoindex:error] [pid 230252:tid 230399] [client 20.226.60.151:56942] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:25:06.913073 2026] [security2:error] [pid 230252:tid 230432] [client 216.73.160.190:49393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/wp-login.php"] [unique_id "al9JAk0Dwhk5-Z44XrpO1AAAAsk"]
[Tue Jul 21 07:25:06.918474 2026] [security2:error] [pid 229246:tid 229406] [client 20.151.10.161:49034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/seiso.php"] [unique_id "al9JAiBMYeh5YLVG45xy9wAAAjI"]
[Tue Jul 21 07:25:07.026983 2026] [security2:error] [pid 229246:tid 229285] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JAyBMYeh5YLVG45xy-gACSyY"]
[Tue Jul 21 07:25:07.027128 2026] [security2:error] [pid 229246:tid 229431] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JAyBMYeh5YLVG45xy-gACSyY"]
[Tue Jul 21 07:25:07.254380 2026] [autoindex:error] [pid 230252:tid 230429] [client 20.226.60.151:56942] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:25:07.275609 2026] [security2:error] [pid 229246:tid 229385] [client 154.192.233.199:60453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JAyBMYeh5YLVG45xy-wAAAh0"]
[Tue Jul 21 07:25:07.275739 2026] [security2:error] [pid 229246:tid 229385] [client 154.192.233.199:60453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JAyBMYeh5YLVG45xy-wAAAh0"]
[Tue Jul 21 07:25:07.315714 2026] [security2:error] [pid 230252:tid 230441] [client 20.151.10.161:26528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/a1.php"] [unique_id "al9JA00Dwhk5-Z44XrpO2QAAAtI"]
[Tue Jul 21 07:25:07.615141 2026] [security2:error] [pid 230252:tid 230495] [client 20.151.10.161:65522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/goods.php"] [unique_id "al9JA00Dwhk5-Z44XrpO3gAAAwg"]
[Tue Jul 21 07:25:07.730417 2026] [security2:error] [pid 229246:tid 229446] [client 103.121.156.110:53766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9JAyBMYeh5YLVG45xzAgAAAlo"]
[Tue Jul 21 07:25:07.730577 2026] [security2:error] [pid 229246:tid 229446] [client 103.121.156.110:53766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9JAyBMYeh5YLVG45xzAgAAAlo"]
[Tue Jul 21 07:25:07.851079 2026] [security2:error] [pid 230252:tid 230499] [client 20.226.60.151:63331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/ccc.php"] [unique_id "al9JA00Dwhk5-Z44XrpO4AAAAww"]
[Tue Jul 21 07:25:08.077866 2026] [security2:error] [pid 229246:tid 229429] [client 74.249.245.134:5515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/amax.php"] [unique_id "al9JBCBMYeh5YLVG45xzBgAAAkk"]
[Tue Jul 21 07:25:08.161470 2026] [security2:error] [pid 230252:tid 230474] [client 213.152.162.104:36528] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JBE0Dwhk5-Z44XrpO6QAAAvM"]
[Tue Jul 21 07:25:08.161573 2026] [security2:error] [pid 230252:tid 230474] [client 213.152.162.104:36528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JBE0Dwhk5-Z44XrpO6QAAAvM"]
[Tue Jul 21 07:25:08.311756 2026] [security2:error] [pid 230252:tid 230498] [client 20.151.10.161:26536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9JBE0Dwhk5-Z44XrpO7AAAAws"]
[Tue Jul 21 07:25:08.945985 2026] [security2:error] [pid 229246:tid 229398] [client 74.249.245.134:5518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/moon.php"] [unique_id "al9JBCBMYeh5YLVG45xzEAAAAio"]
[Tue Jul 21 07:25:09.019991 2026] [security2:error] [pid 230252:tid 230479] [client 20.226.60.151:56871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/w.php"] [unique_id "al9JBU0Dwhk5-Z44XrpO9gAAAvg"]
[Tue Jul 21 07:25:09.280089 2026] [security2:error] [pid 230252:tid 230398] [client 20.151.10.161:49085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/155.php"] [unique_id "al9JBU0Dwhk5-Z44XrpO-AAAAqc"]
[Tue Jul 21 07:25:09.430210 2026] [security2:error] [pid 229246:tid 229433] [client 62.102.148.164:53424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JBSBMYeh5YLVG45xzFwAAAk0"]
[Tue Jul 21 07:25:09.430306 2026] [security2:error] [pid 229246:tid 229433] [client 62.102.148.164:53424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JBSBMYeh5YLVG45xzFwAAAk0"]
[Tue Jul 21 07:25:09.523995 2026] [security2:error] [pid 229246:tid 229452] [client 139.135.44.145:54031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JBSBMYeh5YLVG45xzGQAAAmA"]
[Tue Jul 21 07:25:09.524099 2026] [security2:error] [pid 229246:tid 229452] [client 139.135.44.145:54031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JBSBMYeh5YLVG45xzGQAAAmA"]
[Tue Jul 21 07:25:09.581412 2026] [security2:error] [pid 230252:tid 230440] [client 74.249.245.134:54380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/ws83.php"] [unique_id "al9JBU0Dwhk5-Z44XrpO_AAAAtE"]
[Tue Jul 21 07:25:09.781727 2026] [security2:error] [pid 230252:tid 230356] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JBU0Dwhk5-Z44XrpO_QACtGU"]
[Tue Jul 21 07:25:09.781977 2026] [security2:error] [pid 230252:tid 230411] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JBU0Dwhk5-Z44XrpO_QACtGU"]
[Tue Jul 21 07:25:09.951236 2026] [security2:error] [pid 229246:tid 229479] [client 20.151.10.161:65445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/ms-edit.php"] [unique_id "al9JBSBMYeh5YLVG45xzIAAAAns"]
[Tue Jul 21 07:25:10.089666 2026] [security2:error] [pid 229246:tid 229402] [client 20.151.10.161:26402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9JBiBMYeh5YLVG45xzJAAAAi4"]
[Tue Jul 21 07:25:10.377960 2026] [security2:error] [pid 229246:tid 229330] [remote 102.134.101.35:34782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "polycellassistencia.com.ocsdbodyboarding.com.br"] [uri "/wp-login.php"] [unique_id "al9JBiBMYeh5YLVG45xzKgACLVM"]
[Tue Jul 21 07:25:10.698471 2026] [security2:error] [pid 229246:tid 229313] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JBiBMYeh5YLVG45xzLwACjkI"]
[Tue Jul 21 07:25:10.698657 2026] [security2:error] [pid 229246:tid 229498] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JBiBMYeh5YLVG45xzLwACjkI"]
[Tue Jul 21 07:25:10.842958 2026] [security2:error] [pid 229246:tid 229391] [client 74.249.245.134:54341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/CDX1.php"] [unique_id "al9JBiBMYeh5YLVG45xzMQAAAiM"]
[Tue Jul 21 07:25:10.957390 2026] [security2:error] [pid 230252:tid 230413] [client 136.144.33.28:32563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JBk0Dwhk5-Z44XrpPAwAAArY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:25:11.101653 2026] [security2:error] [pid 230252:tid 230485] [client 109.248.148.246:44068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JB00Dwhk5-Z44XrpPBgAAAv4"]
[Tue Jul 21 07:25:11.101756 2026] [security2:error] [pid 230252:tid 230485] [client 109.248.148.246:44068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JB00Dwhk5-Z44XrpPBgAAAv4"]
[Tue Jul 21 07:25:11.308651 2026] [security2:error] [pid 230252:tid 230410] [client 103.162.129.114:56372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JB00Dwhk5-Z44XrpPCAAAArM"]
[Tue Jul 21 07:25:11.308776 2026] [security2:error] [pid 230252:tid 230410] [client 103.162.129.114:56372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JB00Dwhk5-Z44XrpPCAAAArM"]
[Tue Jul 21 07:25:11.432480 2026] [security2:error] [pid 229246:tid 229446] [client 20.226.60.151:54469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/ss.php"] [unique_id "al9JByBMYeh5YLVG45xzNwAAAlo"]
[Tue Jul 21 07:25:11.669870 2026] [security2:error] [pid 230252:tid 230417] [client 20.151.10.161:63697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/222.php"] [unique_id "al9JB00Dwhk5-Z44XrpPDAAAAro"]
[Tue Jul 21 07:25:11.686369 2026] [security2:error] [pid 229246:tid 229429] [client 109.248.148.246:44054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9JByBMYeh5YLVG45xzPQAAAkk"]
[Tue Jul 21 07:25:11.686487 2026] [security2:error] [pid 229246:tid 229429] [client 109.248.148.246:44054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9JByBMYeh5YLVG45xzPQAAAkk"]
[Tue Jul 21 07:25:11.850464 2026] [security2:error] [pid 230252:tid 230353] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JB00Dwhk5-Z44XrpPEAAC02I"]
[Tue Jul 21 07:25:11.850659 2026] [security2:error] [pid 230252:tid 230442] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JB00Dwhk5-Z44XrpPEAAC02I"]
[Tue Jul 21 07:25:12.020067 2026] [security2:error] [pid 230252:tid 230489] [client 117.251.86.144:45904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JCE0Dwhk5-Z44XrpPEQAAAwI"]
[Tue Jul 21 07:25:12.020248 2026] [security2:error] [pid 230252:tid 230489] [client 117.251.86.144:45904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JCE0Dwhk5-Z44XrpPEQAAAwI"]
[Tue Jul 21 07:25:12.180495 2026] [security2:error] [pid 230252:tid 230419] [client 20.151.10.161:26464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/gettest.php"] [unique_id "al9JCE0Dwhk5-Z44XrpPFAAAArw"]
[Tue Jul 21 07:25:12.318406 2026] [security2:error] [pid 230252:tid 230450] [client 20.226.60.151:62347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9JCE0Dwhk5-Z44XrpPFQAAAts"]
[Tue Jul 21 07:25:12.410569 2026] [security2:error] [pid 229246:tid 229378] [client 74.249.245.134:54348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/inputs.php"] [unique_id "al9JCCBMYeh5YLVG45xzRwAAAhY"]
[Tue Jul 21 07:25:12.933716 2026] [security2:error] [pid 229246:tid 229500] [client 20.151.10.161:63735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9JCCBMYeh5YLVG45xzUAAAApA"]
[Tue Jul 21 07:25:12.985000 2026] [security2:error] [pid 229246:tid 229278] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JCCBMYeh5YLVG45xzUQACKx8"]
[Tue Jul 21 07:25:12.985188 2026] [security2:error] [pid 229246:tid 229399] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JCCBMYeh5YLVG45xzUQACKx8"]
[Tue Jul 21 07:25:13.041593 2026] [security2:error] [pid 230252:tid 230295] [remote 68.178.160.25:60046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "loopfinancas.com"] [uri "/wp-login.php"] [unique_id "al9JCU0Dwhk5-Z44XrpPGAADBik"]
[Tue Jul 21 07:25:13.641424 2026] [security2:error] [pid 229246:tid 229420] [client 20.226.60.151:54520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/min.php"] [unique_id "al9JCSBMYeh5YLVG45xzXQAAAkA"]
[Tue Jul 21 07:25:13.981131 2026] [proxy:error] [pid 229246:tid 229497] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:13.981215 2026] [proxy_http:error] [pid 229246:tid 229497] [client 20.151.10.161:63706] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:13.981805 2026] [proxy:error] [pid 229246:tid 229497] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:13.981838 2026] [proxy_http:error] [pid 229246:tid 229497] [client 20.151.10.161:63706] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:14.045671 2026] [security2:error] [pid 230252:tid 230399] [client 74.249.245.134:5531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/ms-edit.php"] [unique_id "al9JCk0Dwhk5-Z44XrpPIAAAAqg"]
[Tue Jul 21 07:25:14.100655 2026] [security2:error] [pid 229246:tid 229377] [client 20.226.60.151:56938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/FWAZ.php"] [unique_id "al9JCiBMYeh5YLVG45xzZgAAAhU"]
[Tue Jul 21 07:25:14.227895 2026] [security2:error] [pid 229246:tid 229339] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JCiBMYeh5YLVG45xzaQACcFw"]
[Tue Jul 21 07:25:14.228051 2026] [security2:error] [pid 229246:tid 229468] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JCiBMYeh5YLVG45xzaQACcFw"]
[Tue Jul 21 07:25:14.747704 2026] [security2:error] [pid 229246:tid 229493] [client 74.249.245.134:54377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/simple.php"] [unique_id "al9JCiBMYeh5YLVG45xzbQAAAok"]
[Tue Jul 21 07:25:14.838789 2026] [security2:error] [pid 230252:tid 230382] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JCk0Dwhk5-Z44XrpPKQADF38"]
[Tue Jul 21 07:25:14.839037 2026] [security2:error] [pid 230252:tid 230510] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JCk0Dwhk5-Z44XrpPKQADF38"]
[Tue Jul 21 07:25:14.841006 2026] [security2:error] [pid 230252:tid 230477] [client 20.220.225.223:46011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-wpbak.php"] [unique_id "al9JCk0Dwhk5-Z44XrpPKgAAAvY"]
[Tue Jul 21 07:25:15.314633 2026] [security2:error] [pid 229246:tid 229423] [client 103.106.20.201:60137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JCyBMYeh5YLVG45xzrwAAAkM"]
[Tue Jul 21 07:25:15.314748 2026] [security2:error] [pid 229246:tid 229423] [client 103.106.20.201:60137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JCyBMYeh5YLVG45xzrwAAAkM"]
[Tue Jul 21 07:25:15.326368 2026] [security2:error] [pid 229246:tid 229492] [client 93.123.109.101:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.chefiabarbearia.com.br"] [uri "/___proxy_subdomain_cpcalendars/.svn/wc.db"] [unique_id "al9JCyBMYeh5YLVG45xzsQAAAog"]
[Tue Jul 21 07:25:15.505657 2026] [security2:error] [pid 230252:tid 230389] [client 20.151.10.161:65467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9JC00Dwhk5-Z44XrpPLAAAAp4"]
[Tue Jul 21 07:25:15.635163 2026] [security2:error] [pid 229246:tid 229379] [client 109.248.148.246:54062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JCyBMYeh5YLVG45xzswAAAhc"]
[Tue Jul 21 07:25:15.635254 2026] [security2:error] [pid 229246:tid 229379] [client 109.248.148.246:54062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JCyBMYeh5YLVG45xzswAAAhc"]
[Tue Jul 21 07:25:15.682002 2026] [security2:error] [pid 230252:tid 230485] [client 74.249.245.134:5522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/404.php"] [unique_id "al9JC00Dwhk5-Z44XrpPLQAAAv4"]
[Tue Jul 21 07:25:15.686627 2026] [security2:error] [pid 229246:tid 229413] [client 103.174.34.15:57370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JCyBMYeh5YLVG45xztAAAAjk"]
[Tue Jul 21 07:25:15.686775 2026] [security2:error] [pid 229246:tid 229413] [client 103.174.34.15:57370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JCyBMYeh5YLVG45xztAAAAjk"]
[Tue Jul 21 07:25:15.737958 2026] [security2:error] [pid 230252:tid 230487] [client 213.152.162.104:38082] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9JC00Dwhk5-Z44XrpPLgAAAwA"]
[Tue Jul 21 07:25:15.738097 2026] [security2:error] [pid 230252:tid 230487] [client 213.152.162.104:38082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9JC00Dwhk5-Z44XrpPLgAAAwA"]
[Tue Jul 21 07:25:16.072515 2026] [security2:error] [pid 229246:tid 229305] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JDCBMYeh5YLVG45xz3QACbjo"]
[Tue Jul 21 07:25:16.072710 2026] [security2:error] [pid 229246:tid 229466] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JDCBMYeh5YLVG45xz3QACbjo"]
[Tue Jul 21 07:25:16.397943 2026] [security2:error] [pid 230252:tid 230397] [client 20.226.60.151:56901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/miru1.php"] [unique_id "al9JDE0Dwhk5-Z44XrpPMgAAAqY"]
[Tue Jul 21 07:25:16.652849 2026] [security2:error] [pid 229246:tid 229461] [client 45.251.232.145:60794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JDCBMYeh5YLVG45xz5wAAAmk"]
[Tue Jul 21 07:25:16.652974 2026] [security2:error] [pid 229246:tid 229461] [client 45.251.232.145:60794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JDCBMYeh5YLVG45xz5wAAAmk"]
[Tue Jul 21 07:25:16.657842 2026] [proxy:error] [pid 230252:tid 230437] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:16.657898 2026] [proxy_http:error] [pid 230252:tid 230437] [client 20.151.10.161:63686] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:16.658502 2026] [proxy:error] [pid 230252:tid 230437] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:16.658525 2026] [proxy_http:error] [pid 230252:tid 230437] [client 20.151.10.161:63686] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:16.809926 2026] [security2:error] [pid 230252:tid 230511] [client 20.151.10.161:26376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/simple.php"] [unique_id "al9JDE0Dwhk5-Z44XrpPNQAAAxg"]
[Tue Jul 21 07:25:16.838339 2026] [security2:error] [pid 229246:tid 229385] [client 193.36.225.54:38303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JDCBMYeh5YLVG45xz6AAAAh0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:25:16.891321 2026] [security2:error] [pid 229246:tid 229390] [client 175.45.70.82:63925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JDCBMYeh5YLVG45xz6QAAAiI"]
[Tue Jul 21 07:25:16.891429 2026] [security2:error] [pid 229246:tid 229390] [client 175.45.70.82:63925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JDCBMYeh5YLVG45xz6QAAAiI"]
[Tue Jul 21 07:25:17.065115 2026] [security2:error] [pid 230252:tid 230456] [client 62.102.148.164:54670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JDU0Dwhk5-Z44XrpPOAAAAuE"]
[Tue Jul 21 07:25:17.065216 2026] [security2:error] [pid 230252:tid 230456] [client 62.102.148.164:54670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JDU0Dwhk5-Z44XrpPOAAAAuE"]
[Tue Jul 21 07:25:17.116532 2026] [security2:error] [pid 230252:tid 230439] [client 74.249.245.134:5541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/file3.php"] [unique_id "al9JDU0Dwhk5-Z44XrpPOQAAAtA"]
[Tue Jul 21 07:25:17.428561 2026] [security2:error] [pid 230252:tid 230467] [client 20.220.225.223:45998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/dr.php"] [unique_id "al9JDU0Dwhk5-Z44XrpPPAAAAuw"]
[Tue Jul 21 07:25:17.431224 2026] [security2:error] [pid 230252:tid 230454] [client 20.151.10.161:26388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/xxx.php"] [unique_id "al9JDU0Dwhk5-Z44XrpPPQAAAt8"]
[Tue Jul 21 07:25:17.720650 2026] [security2:error] [pid 230252:tid 230335] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JDU0Dwhk5-Z44XrpPRAACwlA"]
[Tue Jul 21 07:25:17.720820 2026] [security2:error] [pid 230252:tid 230425] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JDU0Dwhk5-Z44XrpPRAACwlA"]
[Tue Jul 21 07:25:17.843877 2026] [security2:error] [pid 229246:tid 229377] [client 154.192.233.199:59848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JDSBMYeh5YLVG45xz_QAAAhU"]
[Tue Jul 21 07:25:17.844007 2026] [security2:error] [pid 229246:tid 229377] [client 154.192.233.199:59848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JDSBMYeh5YLVG45xz_QAAAhU"]
[Tue Jul 21 07:25:17.916045 2026] [security2:error] [pid 230252:tid 230451] [client 20.151.10.161:26467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/hypo.php"] [unique_id "al9JDU0Dwhk5-Z44XrpPRQAAAtw"]
[Tue Jul 21 07:25:18.107389 2026] [security2:error] [pid 229246:tid 229478] [client 93.123.109.101:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.chefiabarbearia.com.br"] [uri "/___proxy_subdomain_cpcalendars/.svn/wc.db"] [unique_id "al9JDiBMYeh5YLVG45x0AgAAAno"]
[Tue Jul 21 07:25:18.116399 2026] [security2:error] [pid 230252:tid 230396] [client 74.249.245.134:5548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/wp-mail.php"] [unique_id "al9JDk0Dwhk5-Z44XrpPSgAAAqU"]
[Tue Jul 21 07:25:18.197071 2026] [security2:error] [pid 229246:tid 229458] [client 82.102.28.107:40042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9JDiBMYeh5YLVG45x0AwAAAmY"]
[Tue Jul 21 07:25:18.197207 2026] [security2:error] [pid 229246:tid 229458] [client 82.102.28.107:40042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9JDiBMYeh5YLVG45x0AwAAAmY"]
[Tue Jul 21 07:25:18.367740 2026] [security2:error] [pid 230252:tid 230494] [client 103.121.156.110:53994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9JDk0Dwhk5-Z44XrpPSwAAAwc"]
[Tue Jul 21 07:25:18.367888 2026] [security2:error] [pid 230252:tid 230494] [client 103.121.156.110:53994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9JDk0Dwhk5-Z44XrpPSwAAAwc"]
[Tue Jul 21 07:25:18.592849 2026] [security2:error] [pid 229246:tid 229379] [client 93.123.109.101:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.chefiabarbearia.com.br"] [uri "/___proxy_subdomain_cpcalendars/.svn/entries"] [unique_id "al9JDiBMYeh5YLVG45x0CwAAAhc"]
[Tue Jul 21 07:25:18.595442 2026] [proxy:error] [pid 230252:tid 230406] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:18.595505 2026] [proxy_http:error] [pid 230252:tid 230406] [client 20.151.10.161:65408] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:18.595970 2026] [proxy:error] [pid 230252:tid 230406] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:18.596002 2026] [proxy_http:error] [pid 230252:tid 230406] [client 20.151.10.161:65408] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:18.637246 2026] [security2:error] [pid 229246:tid 229439] [client 20.226.60.151:56954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/aa.php"] [unique_id "al9JDiBMYeh5YLVG45x0DAAAAlM"]
[Tue Jul 21 07:25:19.092671 2026] [security2:error] [pid 230252:tid 230414] [client 20.220.225.223:46082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/2x.php"] [unique_id "al9JD00Dwhk5-Z44XrpPVQAAArc"]
[Tue Jul 21 07:25:19.288277 2026] [security2:error] [pid 229246:tid 229427] [client 20.226.60.151:56900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/122.php"] [unique_id "al9JDyBMYeh5YLVG45x0HwAAAkc"]
[Tue Jul 21 07:25:19.425718 2026] [security2:error] [pid 229246:tid 229409] [client 74.249.245.134:54355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/about.php"] [unique_id "al9JDyBMYeh5YLVG45x0IgAAAjU"]
[Tue Jul 21 07:25:19.505621 2026] [security2:error] [pid 230252:tid 230316] [remote 13.159.147.98:34444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.147.159.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9JDk0Dwhk5-Z44XrpPTgADDz4"]
[Tue Jul 21 07:25:19.519017 2026] [core:alert] [pid 229246:tid 229488] [client 57.141.18.75:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:25:20.163275 2026] [security2:error] [pid 230252:tid 230456] [client 20.151.10.161:26441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/chosen.php"] [unique_id "al9JEE0Dwhk5-Z44XrpPZAAAAuE"]
[Tue Jul 21 07:25:20.265784 2026] [security2:error] [pid 230252:tid 230486] [client 139.135.44.145:54836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JEE0Dwhk5-Z44XrpPZQAAAv8"]
[Tue Jul 21 07:25:20.266524 2026] [security2:error] [pid 230252:tid 230486] [client 139.135.44.145:54836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JEE0Dwhk5-Z44XrpPZQAAAv8"]
[Tue Jul 21 07:25:20.337367 2026] [security2:error] [pid 230252:tid 230366] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JEE0Dwhk5-Z44XrpPZgACmm8"]
[Tue Jul 21 07:25:20.337518 2026] [security2:error] [pid 230252:tid 230385] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JEE0Dwhk5-Z44XrpPZgACmm8"]
[Tue Jul 21 07:25:20.375501 2026] [security2:error] [pid 230252:tid 230430] [client 20.226.60.151:56869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/get.php"] [unique_id "al9JEE0Dwhk5-Z44XrpPZwAAAsc"]
[Tue Jul 21 07:25:20.558869 2026] [security2:error] [pid 230252:tid 230454] [client 74.249.245.134:5525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/adminfuns.php"] [unique_id "al9JEE0Dwhk5-Z44XrpPaQAAAt8"]
[Tue Jul 21 07:25:20.704150 2026] [security2:error] [pid 230252:tid 230458] [client 183.83.233.92:61505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.233.83.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "governess.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JEE0Dwhk5-Z44XrpPaAAAAuM"]
[Tue Jul 21 07:25:20.704352 2026] [security2:error] [pid 230252:tid 230458] [client 183.83.233.92:61505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "governess.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JEE0Dwhk5-Z44XrpPaAAAAuM"]
[Tue Jul 21 07:25:20.793132 2026] [security2:error] [pid 230252:tid 230436] [client 20.151.10.161:63618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/raw.php"] [unique_id "al9JEE0Dwhk5-Z44XrpPbgAAAs0"]
[Tue Jul 21 07:25:21.002474 2026] [security2:error] [pid 229246:tid 229499] [client 20.220.225.223:46101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/kq1.php"] [unique_id "al9JESBMYeh5YLVG45x0MQAAAo8"]
[Tue Jul 21 07:25:21.169907 2026] [security2:error] [pid 230252:tid 230388] [client 20.226.60.151:56887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/as.php"] [unique_id "al9JEU0Dwhk5-Z44XrpPbwAAAp0"]
[Tue Jul 21 07:25:21.197827 2026] [security2:error] [pid 229246:tid 229300] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JESBMYeh5YLVG45x0NgACVjU"]
[Tue Jul 21 07:25:21.197958 2026] [security2:error] [pid 229246:tid 229442] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JESBMYeh5YLVG45x0NgACVjU"]
[Tue Jul 21 07:25:21.828521 2026] [security2:error] [pid 230252:tid 230493] [client 103.162.129.114:56829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JEU0Dwhk5-Z44XrpPdAAAAwY"]
[Tue Jul 21 07:25:21.828671 2026] [security2:error] [pid 230252:tid 230493] [client 103.162.129.114:56829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JEU0Dwhk5-Z44XrpPdAAAAwY"]
[Tue Jul 21 07:25:21.841960 2026] [security2:error] [pid 230252:tid 230438] [client 20.226.60.151:56927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/ccou.php"] [unique_id "al9JEU0Dwhk5-Z44XrpPdQAAAs8"]
[Tue Jul 21 07:25:21.916346 2026] [security2:error] [pid 229246:tid 229380] [client 20.151.10.161:48967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/ppp.php"] [unique_id "al9JESBMYeh5YLVG45x0PAAAAhg"]
[Tue Jul 21 07:25:22.025881 2026] [security2:error] [pid 230252:tid 230260] [remote 68.178.160.25:37868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "goldentrips40.com"] [uri "/wp-login.php"] [unique_id "al9JEk0Dwhk5-Z44XrpPdwAC3AY"]
[Tue Jul 21 07:25:22.173486 2026] [security2:error] [pid 230252:tid 230442] [client 193.36.225.10:21677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JEk0Dwhk5-Z44XrpPdgAAAtM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:25:22.467988 2026] [security2:error] [pid 229246:tid 229318] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JEiBMYeh5YLVG45x0RAACckc"]
[Tue Jul 21 07:25:22.468146 2026] [security2:error] [pid 229246:tid 229470] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JEiBMYeh5YLVG45x0RAACckc"]
[Tue Jul 21 07:25:22.497487 2026] [security2:error] [pid 229246:tid 229396] [client 74.249.245.134:54371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/php8.php"] [unique_id "al9JEiBMYeh5YLVG45x0RQAAAig"]
[Tue Jul 21 07:25:22.692909 2026] [security2:error] [pid 229246:tid 229452] [client 20.151.10.161:26461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/als.php"] [unique_id "al9JEiBMYeh5YLVG45x0SgAAAmA"]
[Tue Jul 21 07:25:22.700798 2026] [security2:error] [pid 230252:tid 230434] [client 20.151.10.161:65420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/abcd.php"] [unique_id "al9JEk0Dwhk5-Z44XrpPegAAAss"]
[Tue Jul 21 07:25:22.769120 2026] [security2:error] [pid 230252:tid 230420] [client 117.251.86.144:37198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JEk0Dwhk5-Z44XrpPfQAAAr0"]
[Tue Jul 21 07:25:22.769293 2026] [security2:error] [pid 230252:tid 230420] [client 117.251.86.144:37198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JEk0Dwhk5-Z44XrpPfQAAAr0"]
[Tue Jul 21 07:25:22.791573 2026] [proxy:error] [pid 229246:tid 229248] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:22.791602 2026] [proxy_http:error] [pid 229246:tid 229248] [remote 93.123.109.101:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:22.792047 2026] [proxy:error] [pid 229246:tid 229248] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:22.792067 2026] [proxy_http:error] [pid 229246:tid 229248] [remote 93.123.109.101:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:23.394800 2026] [security2:error] [pid 229246:tid 229414] [client 20.226.60.151:56852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/w3lls.php"] [unique_id "al9JEyBMYeh5YLVG45x0WgAAAjo"]
[Tue Jul 21 07:25:23.866054 2026] [security2:error] [pid 229246:tid 229317] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JEyBMYeh5YLVG45x0YQACQUY"]
[Tue Jul 21 07:25:23.866240 2026] [security2:error] [pid 229246:tid 229421] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JEyBMYeh5YLVG45x0YQACQUY"]
[Tue Jul 21 07:25:24.158146 2026] [security2:error] [pid 230252:tid 230462] [client 20.151.10.161:26521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/pol.php"] [unique_id "al9JFE0Dwhk5-Z44XrpPkwAAAuc"]
[Tue Jul 21 07:25:24.670922 2026] [security2:error] [pid 230252:tid 230423] [client 74.249.245.134:5543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/info.php"] [unique_id "al9JFE0Dwhk5-Z44XrpPlgAAAsA"]
[Tue Jul 21 07:25:24.693598 2026] [security2:error] [pid 230252:tid 230458] [client 20.151.10.161:63693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/a1.php"] [unique_id "al9JFE0Dwhk5-Z44XrpPlwAAAuM"]
[Tue Jul 21 07:25:24.695536 2026] [security2:error] [pid 230252:tid 230415] [client 20.226.60.151:54480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9JFE0Dwhk5-Z44XrpPmAAAArg"]
[Tue Jul 21 07:25:24.714029 2026] [security2:error] [pid 229246:tid 229444] [client 109.248.148.246:60164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9JFCBMYeh5YLVG45x0aAAAAlg"]
[Tue Jul 21 07:25:24.714118 2026] [security2:error] [pid 229246:tid 229444] [client 109.248.148.246:60164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9JFCBMYeh5YLVG45x0aAAAAlg"]
[Tue Jul 21 07:25:24.858969 2026] [security2:error] [pid 230252:tid 230342] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JFE0Dwhk5-Z44XrpPmgAC21c"]
[Tue Jul 21 07:25:24.859269 2026] [security2:error] [pid 230252:tid 230450] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JFE0Dwhk5-Z44XrpPmgAC21c"]
[Tue Jul 21 07:25:24.914359 2026] [security2:error] [pid 230252:tid 230479] [client 20.151.10.161:49033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/201.php"] [unique_id "al9JFE0Dwhk5-Z44XrpPnAAAAvg"]
[Tue Jul 21 07:25:25.371661 2026] [security2:error] [pid 230252:tid 230493] [client 20.52.136.55:1755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/jp.php"] [unique_id "al9JFU0Dwhk5-Z44XrpPngAAAwY"]
[Tue Jul 21 07:25:25.378090 2026] [security2:error] [pid 229246:tid 229311] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JFSBMYeh5YLVG45x0cQACXUA"]
[Tue Jul 21 07:25:25.378233 2026] [security2:error] [pid 229246:tid 229449] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JFSBMYeh5YLVG45x0cQACXUA"]
[Tue Jul 21 07:25:25.400228 2026] [security2:error] [pid 230252:tid 230438] [client 20.226.60.151:56910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/test1.php"] [unique_id "al9JFU0Dwhk5-Z44XrpPnwAAAs8"]
[Tue Jul 21 07:25:25.743895 2026] [security2:error] [pid 230252:tid 230386] [client 109.248.148.246:60204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9JFU0Dwhk5-Z44XrpPpAAAAps"]
[Tue Jul 21 07:25:25.743979 2026] [security2:error] [pid 230252:tid 230386] [client 109.248.148.246:60204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9JFU0Dwhk5-Z44XrpPpAAAAps"]
[Tue Jul 21 07:25:26.023539 2026] [security2:error] [pid 230252:tid 230501] [client 103.106.20.201:60703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JFk0Dwhk5-Z44XrpPpwAAAw4"]
[Tue Jul 21 07:25:26.023682 2026] [security2:error] [pid 230252:tid 230501] [client 103.106.20.201:60703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JFk0Dwhk5-Z44XrpPpwAAAw4"]
[Tue Jul 21 07:25:26.383755 2026] [security2:error] [pid 230252:tid 230440] [client 103.174.34.15:57846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JFk0Dwhk5-Z44XrpPqgAAAtE"]
[Tue Jul 21 07:25:26.383956 2026] [security2:error] [pid 230252:tid 230440] [client 103.174.34.15:57846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JFk0Dwhk5-Z44XrpPqgAAAtE"]
[Tue Jul 21 07:25:26.595460 2026] [security2:error] [pid 229246:tid 229452] [client 20.151.10.161:63709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9JFiBMYeh5YLVG45x0fgAAAmA"]
[Tue Jul 21 07:25:26.597256 2026] [security2:error] [pid 229246:tid 229458] [client 74.249.245.134:54373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/edit.php"] [unique_id "al9JFiBMYeh5YLVG45x0fwAAAmY"]
[Tue Jul 21 07:25:26.817160 2026] [security2:error] [pid 229246:tid 229253] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JFiBMYeh5YLVG45x0gQACKwY"]
[Tue Jul 21 07:25:26.817327 2026] [security2:error] [pid 229246:tid 229399] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JFiBMYeh5YLVG45x0gQACKwY"]
[Tue Jul 21 07:25:27.014766 2026] [security2:error] [pid 229246:tid 229455] [client 136.144.33.54:50309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JFyBMYeh5YLVG45x0hAAAAmM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:25:27.119503 2026] [security2:error] [pid 230252:tid 230420] [client 45.251.232.145:61315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JF00Dwhk5-Z44XrpPuQAAAr0"]
[Tue Jul 21 07:25:27.119586 2026] [security2:error] [pid 230252:tid 230420] [client 45.251.232.145:61315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JF00Dwhk5-Z44XrpPuQAAAr0"]
[Tue Jul 21 07:25:27.386023 2026] [security2:error] [pid 229246:tid 229402] [client 152.59.154.239:62640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JFSBMYeh5YLVG45x0cgAAAi4"]
[Tue Jul 21 07:25:27.669264 2026] [security2:error] [pid 230252:tid 230474] [client 175.45.70.82:64433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JF00Dwhk5-Z44XrpPwAAAAvM"]
[Tue Jul 21 07:25:27.669431 2026] [security2:error] [pid 230252:tid 230474] [client 175.45.70.82:64433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JF00Dwhk5-Z44XrpPwAAAAvM"]
[Tue Jul 21 07:25:27.949862 2026] [proxy:error] [pid 230252:tid 230285] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:27.949914 2026] [proxy_http:error] [pid 230252:tid 230285] [remote 93.123.109.101:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:27.950510 2026] [proxy:error] [pid 230252:tid 230285] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:27.950532 2026] [proxy_http:error] [pid 230252:tid 230285] [remote 93.123.109.101:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:28.012280 2026] [security2:error] [pid 230252:tid 230476] [client 20.151.10.161:26322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/file5.php"] [unique_id "al9JGE0Dwhk5-Z44XrpPwwAAAvU"]
[Tue Jul 21 07:25:28.032486 2026] [security2:error] [pid 230252:tid 230296] [remote 20.153.140.50:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9JGE0Dwhk5-Z44XrpPxAAC4yo"]
[Tue Jul 21 07:25:28.142304 2026] [security2:error] [pid 230252:tid 230438] [client 74.249.245.134:17423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/166.php"] [unique_id "al9JGE0Dwhk5-Z44XrpPxQAAAs8"]
[Tue Jul 21 07:25:28.155596 2026] [security2:error] [pid 230252:tid 230331] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JGE0Dwhk5-Z44XrpPxgACp0w"]
[Tue Jul 21 07:25:28.155738 2026] [security2:error] [pid 230252:tid 230398] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JGE0Dwhk5-Z44XrpPxgACp0w"]
[Tue Jul 21 07:25:28.164545 2026] [security2:error] [pid 230252:tid 230264] [remote 156.59.198.136:34236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "issima.net.br"] [uri "/equestre/brasao/brasao-azul-e-branco.pdf"] [unique_id "al9JGE0Dwhk5-Z44XrpPyAACpQo"]
[Tue Jul 21 07:25:28.166246 2026] [security2:error] [pid 230252:tid 230386] [client 62.102.148.164:43912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9JGE0Dwhk5-Z44XrpPyQAAAps"]
[Tue Jul 21 07:25:28.166321 2026] [security2:error] [pid 230252:tid 230386] [client 62.102.148.164:43912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9JGE0Dwhk5-Z44XrpPyQAAAps"]
[Tue Jul 21 07:25:28.508940 2026] [security2:error] [pid 230252:tid 230435] [client 154.192.233.199:59886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JGE0Dwhk5-Z44XrpPzgAAAsw"]
[Tue Jul 21 07:25:28.509121 2026] [security2:error] [pid 230252:tid 230435] [client 154.192.233.199:59886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JGE0Dwhk5-Z44XrpPzgAAAsw"]
[Tue Jul 21 07:25:28.574545 2026] [security2:error] [pid 230252:tid 230468] [client 20.226.60.151:56840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/database.php"] [unique_id "al9JGE0Dwhk5-Z44XrpPzwAAAu0"]
[Tue Jul 21 07:25:28.741330 2026] [security2:error] [pid 229246:tid 229450] [client 20.220.225.223:45991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/zzz.php"] [unique_id "al9JGCBMYeh5YLVG45x0kQAAAl4"]
[Tue Jul 21 07:25:28.747304 2026] [security2:error] [pid 229246:tid 229431] [client 20.151.10.161:49125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/ops.php"] [unique_id "al9JGCBMYeh5YLVG45x0kgAAAks"]
[Tue Jul 21 07:25:29.194824 2026] [security2:error] [pid 229246:tid 229468] [client 109.248.148.246:59096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9JGSBMYeh5YLVG45x0mAAAAnA"]
[Tue Jul 21 07:25:29.194957 2026] [security2:error] [pid 229246:tid 229468] [client 109.248.148.246:59096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9JGSBMYeh5YLVG45x0mAAAAnA"]
[Tue Jul 21 07:25:29.577902 2026] [security2:error] [pid 229246:tid 229261] [remote 132.148.72.88:50676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vinicius-schneider.com"] [uri "/wp-login.php"] [unique_id "al9JGSBMYeh5YLVG45x0ngACaw4"]
[Tue Jul 21 07:25:30.085189 2026] [security2:error] [pid 230252:tid 230456] [client 20.151.10.161:49138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/ingfo.php"] [unique_id "al9JGk0Dwhk5-Z44XrpP3AAAAuE"]
[Tue Jul 21 07:25:30.104460 2026] [security2:error] [pid 229246:tid 229483] [client 20.151.10.161:26462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9JGiBMYeh5YLVG45x0pAAAAn8"]
[Tue Jul 21 07:25:30.255564 2026] [security2:error] [pid 229246:tid 229305] [remote 160.187.68.132:45798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "santotchay.com"] [uri "/wp-login.php"] [unique_id "al9JGiBMYeh5YLVG45x0pgAChzo"]
[Tue Jul 21 07:25:30.669685 2026] [security2:error] [pid 229246:tid 229470] [client 20.151.10.161:65479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9JGiBMYeh5YLVG45x0rQAAAnI"]
[Tue Jul 21 07:25:30.868870 2026] [security2:error] [pid 229246:tid 229452] [client 74.249.245.134:54359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/8.php"] [unique_id "al9JGiBMYeh5YLVG45x0rwAAAmA"]
[Tue Jul 21 07:25:30.876511 2026] [security2:error] [pid 229246:tid 229270] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JGiBMYeh5YLVG45x0sAACZhc"]
[Tue Jul 21 07:25:30.876631 2026] [security2:error] [pid 229246:tid 229458] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JGiBMYeh5YLVG45x0sAACZhc"]
[Tue Jul 21 07:25:31.140280 2026] [security2:error] [pid 230252:tid 230430] [client 139.135.44.145:53688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JG00Dwhk5-Z44XrpP6gAAAsc"]
[Tue Jul 21 07:25:31.140879 2026] [security2:error] [pid 230252:tid 230430] [client 139.135.44.145:53688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JG00Dwhk5-Z44XrpP6gAAAsc"]
[Tue Jul 21 07:25:31.270079 2026] [security2:error] [pid 230252:tid 230437] [client 136.144.33.106:61685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JG00Dwhk5-Z44XrpP6QAAAs4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:25:31.351491 2026] [core:error] [pid 230252:tid 230345] [remote 40.77.167.20:9761] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:25:31.351509 2026] [core:error] [pid 230252:tid 230345] [remote 40.77.167.20:9761] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:25:31.574148 2026] [security2:error] [pid 230252:tid 230496] [client 20.220.225.223:46130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wicked.php"] [unique_id "al9JG00Dwhk5-Z44XrpP7QAAAwk"]
[Tue Jul 21 07:25:31.595146 2026] [security2:error] [pid 229246:tid 229427] [client 20.151.10.161:49040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/error_log.php"] [unique_id "al9JGyBMYeh5YLVG45x0uwAAAkc"]
[Tue Jul 21 07:25:31.714438 2026] [security2:error] [pid 229246:tid 229356] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JGyBMYeh5YLVG45x0vAACK20"]
[Tue Jul 21 07:25:31.714639 2026] [security2:error] [pid 229246:tid 229399] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JGyBMYeh5YLVG45x0vAACK20"]
[Tue Jul 21 07:25:31.828736 2026] [security2:error] [pid 230252:tid 230438] [client 20.226.60.151:63340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/file.php"] [unique_id "al9JG00Dwhk5-Z44XrpP8QAAAs8"]
[Tue Jul 21 07:25:32.169901 2026] [security2:error] [pid 229246:tid 229415] [client 20.151.10.161:48594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/xenon1337.php"] [unique_id "al9JHCBMYeh5YLVG45x0wgAAAjs"]
[Tue Jul 21 07:25:32.437024 2026] [security2:error] [pid 229246:tid 229492] [client 103.162.129.114:57287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JHCBMYeh5YLVG45x0wwAAAog"]
[Tue Jul 21 07:25:32.437177 2026] [security2:error] [pid 229246:tid 229492] [client 103.162.129.114:57287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JHCBMYeh5YLVG45x0wwAAAog"]
[Tue Jul 21 07:25:32.685806 2026] [security2:error] [pid 229246:tid 229461] [client 20.151.10.161:26548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/file.php"] [unique_id "al9JHCBMYeh5YLVG45x0xgAAAmk"]
[Tue Jul 21 07:25:32.798333 2026] [security2:error] [pid 229246:tid 229441] [client 74.249.245.134:54357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/ws38.php"] [unique_id "al9JHCBMYeh5YLVG45x0yAAAAlU"]
[Tue Jul 21 07:25:32.813691 2026] [security2:error] [pid 229246:tid 229490] [client 20.151.10.161:49075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/test11.php"] [unique_id "al9JHCBMYeh5YLVG45x0yQAAAoY"]
[Tue Jul 21 07:25:32.829663 2026] [security2:error] [pid 230252:tid 230401] [client 20.226.60.151:63307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/file.php"] [unique_id "al9JHE0Dwhk5-Z44XrpQBgAAAqo"]
[Tue Jul 21 07:25:33.122378 2026] [security2:error] [pid 229246:tid 229362] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JHSBMYeh5YLVG45x0zQACjXM"]
[Tue Jul 21 07:25:33.122524 2026] [security2:error] [pid 229246:tid 229497] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JHSBMYeh5YLVG45x0zQACjXM"]
[Tue Jul 21 07:25:33.239302 2026] [security2:error] [pid 230252:tid 230444] [client 62.102.148.164:43926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9JHU0Dwhk5-Z44XrpQDgAAAtU"]
[Tue Jul 21 07:25:33.239384 2026] [security2:error] [pid 230252:tid 230444] [client 62.102.148.164:43926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9JHU0Dwhk5-Z44XrpQDgAAAtU"]
[Tue Jul 21 07:25:33.262621 2026] [security2:error] [pid 229246:tid 229361] [remote 57.141.18.78:26390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9JGyBMYeh5YLVG45x0tQACNHI"]
[Tue Jul 21 07:25:33.391314 2026] [security2:error] [pid 230252:tid 230484] [client 20.226.60.151:63338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/777.php"] [unique_id "al9JHU0Dwhk5-Z44XrpQFQAAAv0"]
[Tue Jul 21 07:25:33.406226 2026] [security2:error] [pid 230252:tid 230328] [remote 49.12.216.176:34622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.216.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "limaradiologiadigital.com.br"] [uri "/wp-login.php"] [unique_id "al9JHU0Dwhk5-Z44XrpQFgACpkk"]
[Tue Jul 21 07:25:33.408178 2026] [security2:error] [pid 230252:tid 230441] [client 117.251.86.144:45798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JHU0Dwhk5-Z44XrpQFwAAAtI"]
[Tue Jul 21 07:25:33.408295 2026] [security2:error] [pid 230252:tid 230441] [client 117.251.86.144:45798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JHU0Dwhk5-Z44XrpQFwAAAtI"]
[Tue Jul 21 07:25:33.414777 2026] [security2:error] [pid 230252:tid 230474] [client 20.151.10.161:49109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/koala.php"] [unique_id "al9JHU0Dwhk5-Z44XrpQGAAAAvM"]
[Tue Jul 21 07:25:33.469758 2026] [proxy:error] [pid 229246:tid 229447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:33.469793 2026] [proxy_http:error] [pid 229246:tid 229447] [client 198.235.24.89:62214] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:33.470444 2026] [proxy:error] [pid 229246:tid 229447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:33.470471 2026] [proxy_http:error] [pid 229246:tid 229447] [client 198.235.24.89:62214] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:33.495791 2026] [security2:error] [pid 230252:tid 230388] [client 20.151.10.161:26348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/cfile.php"] [unique_id "al9JHU0Dwhk5-Z44XrpQGQAAAp0"]
[Tue Jul 21 07:25:33.541421 2026] [security2:error] [pid 230252:tid 230479] [client 20.226.60.151:54546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9JHU0Dwhk5-Z44XrpQGgAAAvg"]
[Tue Jul 21 07:25:33.727704 2026] [security2:error] [pid 229246:tid 229462] [client 20.151.10.161:63057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-content/BypassBest.php"] [unique_id "al9JHSBMYeh5YLVG45x00gAAAmo"]
[Tue Jul 21 07:25:33.893082 2026] [security2:error] [pid 229246:tid 229333] [remote 147.50.252.213:42154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9JHSBMYeh5YLVG45x01AACTlY"]
[Tue Jul 21 07:25:34.112342 2026] [autoindex:error] [pid 230252:tid 230440] [client 40.223.127.214:0] AH01276: Cannot serve directory /home2/inlaud99/distribuidorasja.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:25:34.280951 2026] [security2:error] [pid 230252:tid 230478] [client 20.151.10.161:26558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/class-wp.php"] [unique_id "al9JHk0Dwhk5-Z44XrpQKQAAAvc"]
[Tue Jul 21 07:25:34.365253 2026] [security2:error] [pid 230252:tid 230458] [client 20.226.60.151:56841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/ssixta.php"] [unique_id "al9JHk0Dwhk5-Z44XrpQLAAAAuM"]
[Tue Jul 21 07:25:34.494429 2026] [security2:error] [pid 230252:tid 230352] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JHk0Dwhk5-Z44XrpQLgADD2E"]
[Tue Jul 21 07:25:34.494557 2026] [security2:error] [pid 230252:tid 230502] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JHk0Dwhk5-Z44XrpQLgADD2E"]
[Tue Jul 21 07:25:34.684457 2026] [security2:error] [pid 229246:tid 229400] [client 74.249.245.134:17435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/a7.php"] [unique_id "al9JHiBMYeh5YLVG45x02wAAAiw"]
[Tue Jul 21 07:25:34.830603 2026] [security2:error] [pid 230252:tid 230420] [client 20.151.10.161:48578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/mac.php"] [unique_id "al9JHk0Dwhk5-Z44XrpQNQAAAr0"]
[Tue Jul 21 07:25:34.934229 2026] [proxy:error] [pid 230252:tid 230488] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:34.934288 2026] [proxy_http:error] [pid 230252:tid 230488] [client 93.123.109.101:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:34.934883 2026] [proxy:error] [pid 230252:tid 230488] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:34.934909 2026] [proxy_http:error] [pid 230252:tid 230488] [client 93.123.109.101:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:35.002952 2026] [security2:error] [pid 230252:tid 230461] [client 209.141.34.121:49280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "patriciaressignificar.com.br"] [uri "/"] [unique_id "al9JH00Dwhk5-Z44XrpQOgAAAuY"]
[Tue Jul 21 07:25:35.010280 2026] [security2:error] [pid 230252:tid 230444] [client 20.151.10.161:26491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/admin.php"] [unique_id "al9JH00Dwhk5-Z44XrpQOwAAAtU"]
[Tue Jul 21 07:25:35.119053 2026] [security2:error] [pid 229246:tid 229457] [client 37.140.223.69:23707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JHyBMYeh5YLVG45x04gAAAmU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:25:35.371829 2026] [security2:error] [pid 229246:tid 229279] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JHyBMYeh5YLVG45x06AACPSA"]
[Tue Jul 21 07:25:35.372020 2026] [security2:error] [pid 229246:tid 229417] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JHyBMYeh5YLVG45x06AACPSA"]
[Tue Jul 21 07:25:35.514755 2026] [security2:error] [pid 229246:tid 229438] [client 209.141.34.121:49347] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "patriciaressignificar.com.br"] [uri "/"] [unique_id "al9JHyBMYeh5YLVG45x06QAAAlI"]
[Tue Jul 21 07:25:35.692993 2026] [security2:error] [pid 229246:tid 229389] [client 20.226.60.151:54497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9JHyBMYeh5YLVG45x06gAAAiE"]
[Tue Jul 21 07:25:35.850773 2026] [security2:error] [pid 229246:tid 229503] [client 20.226.60.151:56958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/1c.php"] [unique_id "al9JHyBMYeh5YLVG45x07wAAApM"]
[Tue Jul 21 07:25:35.949064 2026] [security2:error] [pid 230252:tid 230476] [client 74.249.245.134:5516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/classsmtps.php"] [unique_id "al9JH00Dwhk5-Z44XrpQRAAAAvU"]
[Tue Jul 21 07:25:36.083167 2026] [security2:error] [pid 230252:tid 230361] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JIE0Dwhk5-Z44XrpQRgACzmo"]
[Tue Jul 21 07:25:36.083308 2026] [security2:error] [pid 230252:tid 230437] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JIE0Dwhk5-Z44XrpQRgACzmo"]
[Tue Jul 21 07:25:36.306934 2026] [security2:error] [pid 230252:tid 230386] [client 20.226.60.151:56919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/test2.php"] [unique_id "al9JIE0Dwhk5-Z44XrpQSQAAAps"]
[Tue Jul 21 07:25:36.341835 2026] [proxy:error] [pid 229246:tid 229378] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:36.341910 2026] [proxy_http:error] [pid 229246:tid 229378] [client 20.151.10.161:65495] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:36.342616 2026] [proxy:error] [pid 229246:tid 229378] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:36.342653 2026] [proxy_http:error] [pid 229246:tid 229378] [client 20.151.10.161:65495] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:36.870012 2026] [security2:error] [pid 229246:tid 229495] [client 103.106.20.201:61276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JICBMYeh5YLVG45x0-wAAAos"]
[Tue Jul 21 07:25:36.870160 2026] [security2:error] [pid 229246:tid 229495] [client 103.106.20.201:61276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JICBMYeh5YLVG45x0-wAAAos"]
[Tue Jul 21 07:25:36.942939 2026] [security2:error] [pid 229246:tid 229466] [client 74.249.245.134:5532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/rip.php"] [unique_id "al9JICBMYeh5YLVG45x0_AAAAm4"]
[Tue Jul 21 07:25:37.207907 2026] [security2:error] [pid 230252:tid 230494] [client 103.174.34.15:58327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JIU0Dwhk5-Z44XrpQUQAAAwc"]
[Tue Jul 21 07:25:37.208035 2026] [security2:error] [pid 230252:tid 230494] [client 103.174.34.15:58327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JIU0Dwhk5-Z44XrpQUQAAAwc"]
[Tue Jul 21 07:25:37.565416 2026] [security2:error] [pid 230252:tid 230302] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JIU0Dwhk5-Z44XrpQVAACpTA"]
[Tue Jul 21 07:25:37.565554 2026] [security2:error] [pid 230252:tid 230396] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JIU0Dwhk5-Z44XrpQVAACpTA"]
[Tue Jul 21 07:25:37.588784 2026] [security2:error] [pid 229246:tid 229500] [client 45.251.232.145:61841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JISBMYeh5YLVG45x1CAAAApA"]
[Tue Jul 21 07:25:37.588889 2026] [security2:error] [pid 229246:tid 229500] [client 45.251.232.145:61841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JISBMYeh5YLVG45x1CAAAApA"]
[Tue Jul 21 07:25:37.610936 2026] [security2:error] [pid 229246:tid 229425] [client 20.226.60.151:56855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/buy.php"] [unique_id "al9JISBMYeh5YLVG45x1CQAAAkU"]
[Tue Jul 21 07:25:37.626191 2026] [security2:error] [pid 230252:tid 230397] [client 59.96.220.140:60011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JIU0Dwhk5-Z44XrpQVgAAAqY"]
[Tue Jul 21 07:25:37.626404 2026] [security2:error] [pid 230252:tid 230397] [client 59.96.220.140:60011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JIU0Dwhk5-Z44XrpQVgAAAqY"]
[Tue Jul 21 07:25:37.951704 2026] [security2:error] [pid 230252:tid 230438] [client 173.239.214.239:28185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.214.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dener.design"] [uri "/wp-login.php"] [unique_id "al9JIE0Dwhk5-Z44XrpQTQAAAs8"]
[Tue Jul 21 07:25:38.198375 2026] [security2:error] [pid 229246:tid 229308] [remote 41.186.86.12:62680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supremaservices.net"] [uri "/xmlrpc.php"] [unique_id "al9JIiBMYeh5YLVG45x1DwACRj0"]
[Tue Jul 21 07:25:38.198513 2026] [security2:error] [pid 229246:tid 229426] [client 41.186.86.12:62680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "supremaservices.net"] [uri "/xmlrpc.php"] [unique_id "al9JIiBMYeh5YLVG45x1DwACRj0"]
[Tue Jul 21 07:25:38.400613 2026] [security2:error] [pid 230252:tid 230505] [client 175.45.70.82:64965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JIk0Dwhk5-Z44XrpQZQAAAxI"]
[Tue Jul 21 07:25:38.400759 2026] [security2:error] [pid 230252:tid 230505] [client 175.45.70.82:64965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JIk0Dwhk5-Z44XrpQZQAAAxI"]
[Tue Jul 21 07:25:38.425716 2026] [security2:error] [pid 229246:tid 229454] [client 20.151.10.161:63671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/simple.php"] [unique_id "al9JIiBMYeh5YLVG45x1FQAAAmI"]
[Tue Jul 21 07:25:38.559770 2026] [security2:error] [pid 229246:tid 229400] [client 74.249.245.134:17416] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/1.php"] [unique_id "al9JIiBMYeh5YLVG45x1FwAAAiw"]
[Tue Jul 21 07:25:38.559935 2026] [security2:error] [pid 229246:tid 229400] [client 74.249.245.134:17416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/1.php"] [unique_id "al9JIiBMYeh5YLVG45x1FwAAAiw"]
[Tue Jul 21 07:25:38.567521 2026] [security2:error] [pid 230252:tid 230497] [client 20.151.10.161:49107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9JIk0Dwhk5-Z44XrpQZgAAAwo"]
[Tue Jul 21 07:25:38.665741 2026] [security2:error] [pid 229246:tid 229286] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JIiBMYeh5YLVG45x1GQACayc"]
[Tue Jul 21 07:25:38.665914 2026] [security2:error] [pid 229246:tid 229463] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JIiBMYeh5YLVG45x1GQACayc"]
[Tue Jul 21 07:25:39.253484 2026] [security2:error] [pid 229246:tid 229282] [remote 41.186.86.12:2188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/wp-login.php"] [unique_id "al9JIyBMYeh5YLVG45x1HQACiSM"]
[Tue Jul 21 07:25:39.379883 2026] [security2:error] [pid 230252:tid 230450] [client 20.226.60.151:63309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/ssend.php"] [unique_id "al9JI00Dwhk5-Z44XrpQbAAAAts"]
[Tue Jul 21 07:25:39.610315 2026] [security2:error] [pid 229246:tid 229405] [client 20.226.60.151:61071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9JIyBMYeh5YLVG45x1IAAAAjE"]
[Tue Jul 21 07:25:39.731403 2026] [security2:error] [pid 229246:tid 229446] [client 87.58.197.194:54970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.63.71"] [uri "/.env"] [unique_id "al9JIyBMYeh5YLVG45x1IgAAAlo"]
[Tue Jul 21 07:25:40.160990 2026] [security2:error] [pid 230252:tid 230487] [client 20.151.10.161:49136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wefile.php"] [unique_id "al9JJE0Dwhk5-Z44XrpQgAAAAwA"]
[Tue Jul 21 07:25:40.282722 2026] [security2:error] [pid 230252:tid 230398] [client 154.192.233.199:58924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JJE0Dwhk5-Z44XrpQgQAAAqc"]
[Tue Jul 21 07:25:40.282857 2026] [security2:error] [pid 230252:tid 230398] [client 154.192.233.199:58924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JJE0Dwhk5-Z44XrpQgQAAAqc"]
[Tue Jul 21 07:25:40.372640 2026] [security2:error] [pid 230252:tid 230413] [client 193.36.225.10:36559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JJE0Dwhk5-Z44XrpQhAAAArY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:25:40.403902 2026] [security2:error] [pid 230252:tid 230410] [client 20.151.10.161:63634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/xxx.php"] [unique_id "al9JJE0Dwhk5-Z44XrpQhgAAArM"]
[Tue Jul 21 07:25:40.641926 2026] [security2:error] [pid 230252:tid 230488] [client 20.151.10.161:26406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/aa2.php"] [unique_id "al9JJE0Dwhk5-Z44XrpQjgAAAwE"]
[Tue Jul 21 07:25:40.653154 2026] [security2:error] [pid 230252:tid 230461] [client 74.249.245.134:54374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/chosen.php"] [unique_id "al9JJE0Dwhk5-Z44XrpQjwAAAuY"]
[Tue Jul 21 07:25:40.767076 2026] [security2:error] [pid 229246:tid 229501] [client 45.8.19.158:24349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lotfiimplantes.com.br"] [uri "/wp-login.php"] [unique_id "al9JJCBMYeh5YLVG45x1KgAAApE"]
[Tue Jul 21 07:25:40.769882 2026] [security2:error] [pid 230252:tid 230429] [client 45.8.19.188:59571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lotfiimplantes.com.br"] [uri "/wp-login.php"] [unique_id "al9JJE0Dwhk5-Z44XrpQkAAAAsY"]
[Tue Jul 21 07:25:40.972270 2026] [security2:error] [pid 230252:tid 230426] [client 20.226.60.151:63325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/item.php"] [unique_id "al9JJE0Dwhk5-Z44XrpQlAAAAsM"]
[Tue Jul 21 07:25:41.369687 2026] [security2:error] [pid 230252:tid 230329] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JJU0Dwhk5-Z44XrpQlgADBEo"]
[Tue Jul 21 07:25:41.369890 2026] [security2:error] [pid 230252:tid 230491] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JJU0Dwhk5-Z44XrpQlgADBEo"]
[Tue Jul 21 07:25:41.972598 2026] [security2:error] [pid 230252:tid 230493] [client 117.195.76.197:64208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.76.195.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grupogradiente.com"] [uri "/xmlrpc.php"] [unique_id "al9JI00Dwhk5-Z44XrpQeAAAAwY"]
[Tue Jul 21 07:25:41.972772 2026] [security2:error] [pid 230252:tid 230493] [client 117.195.76.197:64208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grupogradiente.com"] [uri "/xmlrpc.php"] [unique_id "al9JI00Dwhk5-Z44XrpQeAAAAwY"]
[Tue Jul 21 07:25:42.075742 2026] [security2:error] [pid 229246:tid 229440] [client 20.226.60.151:56945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/ss.php"] [unique_id "al9JJiBMYeh5YLVG45x1OgAAAlQ"]
[Tue Jul 21 07:25:42.220026 2026] [security2:error] [pid 230252:tid 230336] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JJk0Dwhk5-Z44XrpQoQACsVE"]
[Tue Jul 21 07:25:42.220210 2026] [security2:error] [pid 230252:tid 230408] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JJk0Dwhk5-Z44XrpQoQACsVE"]
[Tue Jul 21 07:25:42.306661 2026] [security2:error] [pid 229246:tid 229415] [client 74.249.245.134:17464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/css.php"] [unique_id "al9JJiBMYeh5YLVG45x1PwAAAjs"]
[Tue Jul 21 07:25:42.367548 2026] [security2:error] [pid 229246:tid 229448] [client 20.151.10.161:65474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/hypo.php"] [unique_id "al9JJiBMYeh5YLVG45x1QAAAAlw"]
[Tue Jul 21 07:25:42.519625 2026] [security2:error] [pid 230252:tid 230496] [client 139.135.44.145:54558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JJk0Dwhk5-Z44XrpQrQAAAwk"]
[Tue Jul 21 07:25:42.519757 2026] [security2:error] [pid 230252:tid 230496] [client 139.135.44.145:54558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JJk0Dwhk5-Z44XrpQrQAAAwk"]
[Tue Jul 21 07:25:42.818095 2026] [security2:error] [pid 230252:tid 230410] [client 74.7.241.178:42894] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.cownnex.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9JJk0Dwhk5-Z44XrpQrwACszQ"]
[Tue Jul 21 07:25:42.846461 2026] [proxy:error] [pid 230252:tid 230394] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:42.846537 2026] [proxy_http:error] [pid 230252:tid 230394] [client 20.151.10.161:49110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:42.847110 2026] [proxy:error] [pid 230252:tid 230394] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:42.847147 2026] [proxy_http:error] [pid 230252:tid 230394] [client 20.151.10.161:49110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:42.926552 2026] [security2:error] [pid 230252:tid 230434] [client 103.162.129.114:57801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JJk0Dwhk5-Z44XrpQsgAAAss"]
[Tue Jul 21 07:25:42.926711 2026] [security2:error] [pid 230252:tid 230434] [client 103.162.129.114:57801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JJk0Dwhk5-Z44XrpQsgAAAss"]
[Tue Jul 21 07:25:42.977684 2026] [security2:error] [pid 230252:tid 230403] [client 20.226.60.151:63330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/hypo.php"] [unique_id "al9JJk0Dwhk5-Z44XrpQswAAAqw"]
[Tue Jul 21 07:25:43.231166 2026] [security2:error] [pid 229246:tid 229264] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9JJyBMYeh5YLVG45x1TAACSxE"]
[Tue Jul 21 07:25:43.247770 2026] [security2:error] [pid 229246:tid 229330] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9JJyBMYeh5YLVG45x1TQACalM"]
[Tue Jul 21 07:25:43.262844 2026] [security2:error] [pid 229246:tid 229304] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/sql.php"] [unique_id "al9JJyBMYeh5YLVG45x1TgACIzk"]
[Tue Jul 21 07:25:43.303435 2026] [security2:error] [pid 229246:tid 229256] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/1index.php"] [unique_id "al9JJyBMYeh5YLVG45x1TwACcwk"]
[Tue Jul 21 07:25:43.319922 2026] [security2:error] [pid 229246:tid 229310] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/reop1.php"] [unique_id "al9JJyBMYeh5YLVG45x1UAACNz8"]
[Tue Jul 21 07:25:43.328512 2026] [autoindex:error] [pid 229246:tid 229324] [remote 74.7.242.62:35738] AH01276: Cannot serve directory /home2/luc15241/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:25:43.335560 2026] [security2:error] [pid 229246:tid 229352] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/trusj18.php"] [unique_id "al9JJyBMYeh5YLVG45x1UgACRmk"]
[Tue Jul 21 07:25:43.350494 2026] [security2:error] [pid 229246:tid 229360] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/trusj15.php"] [unique_id "al9JJyBMYeh5YLVG45x1UwACGnE"]
[Tue Jul 21 07:25:43.367173 2026] [security2:error] [pid 229246:tid 229299] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/rft8.php"] [unique_id "al9JJyBMYeh5YLVG45x1VAACcTQ"]
[Tue Jul 21 07:25:43.381724 2026] [security2:error] [pid 229246:tid 229326] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/ai.php"] [unique_id "al9JJyBMYeh5YLVG45x1VQACcE8"]
[Tue Jul 21 07:25:43.438822 2026] [security2:error] [pid 229246:tid 229284] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/fx.php"] [unique_id "al9JJyBMYeh5YLVG45x1VgACTiU"]
[Tue Jul 21 07:25:43.486991 2026] [security2:error] [pid 229246:tid 229328] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/xxx.php"] [unique_id "al9JJyBMYeh5YLVG45x1WAACj1E"]
[Tue Jul 21 07:25:43.495230 2026] [security2:error] [pid 229246:tid 229400] [client 20.226.60.151:56859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/users.php"] [unique_id "al9JJyBMYeh5YLVG45x1WQAAAiw"]
[Tue Jul 21 07:25:43.522137 2026] [security2:error] [pid 229246:tid 229314] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/dropdown.php"] [unique_id "al9JJyBMYeh5YLVG45x1WgACJEM"]
[Tue Jul 21 07:25:43.537204 2026] [security2:error] [pid 229246:tid 229247] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/file11.php"] [unique_id "al9JJyBMYeh5YLVG45x1WwACLwA"]
[Tue Jul 21 07:25:43.553052 2026] [security2:error] [pid 229246:tid 229277] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/png.php"] [unique_id "al9JJyBMYeh5YLVG45x1XAACax4"]
[Tue Jul 21 07:25:43.567916 2026] [security2:error] [pid 229246:tid 229312] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-slss.php"] [unique_id "al9JJyBMYeh5YLVG45x1XQACSEE"]
[Tue Jul 21 07:25:43.582160 2026] [security2:error] [pid 229246:tid 229327] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/ah25.php"] [unique_id "al9JJyBMYeh5YLVG45x1XgACGVA"]
[Tue Jul 21 07:25:43.597085 2026] [security2:error] [pid 229246:tid 229261] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/ccou.php"] [unique_id "al9JJyBMYeh5YLVG45x1XwACjA4"]
[Tue Jul 21 07:25:43.632690 2026] [security2:error] [pid 229246:tid 229378] [client 87.58.197.194:34862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.63.71"] [uri "/.env"] [unique_id "al9JJyBMYeh5YLVG45x1YwAAAhY"]
[Tue Jul 21 07:25:43.640826 2026] [security2:error] [pid 229246:tid 229265] [remote 20.206.67.15:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/1.php"] [unique_id "al9JJyBMYeh5YLVG45x1ZAACWBI"]
[Tue Jul 21 07:25:43.640904 2026] [security2:error] [pid 229246:tid 229265] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/1.php"] [unique_id "al9JJyBMYeh5YLVG45x1ZAACWBI"]
[Tue Jul 21 07:25:43.674471 2026] [security2:error] [pid 229246:tid 229350] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/900.php"] [unique_id "al9JJyBMYeh5YLVG45x1ZgACfGc"]
[Tue Jul 21 07:25:43.679605 2026] [security2:error] [pid 229246:tid 229305] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JJyBMYeh5YLVG45x1ZwACdzo"]
[Tue Jul 21 07:25:43.679714 2026] [security2:error] [pid 229246:tid 229475] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JJyBMYeh5YLVG45x1ZwACdzo"]
[Tue Jul 21 07:25:43.689147 2026] [security2:error] [pid 229246:tid 229266] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/file59.php"] [unique_id "al9JJyBMYeh5YLVG45x1aAACVhM"]
[Tue Jul 21 07:25:43.754662 2026] [security2:error] [pid 229246:tid 229251] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/amxloxxr.php"] [unique_id "al9JJyBMYeh5YLVG45x1aQACFQQ"]
[Tue Jul 21 07:25:43.812408 2026] [security2:error] [pid 229246:tid 229302] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/aboutc.php"] [unique_id "al9JJyBMYeh5YLVG45x1agAChzc"]
[Tue Jul 21 07:25:43.827320 2026] [security2:error] [pid 229246:tid 229303] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/bless18.php"] [unique_id "al9JJyBMYeh5YLVG45x1awACMTg"]
[Tue Jul 21 07:25:43.841648 2026] [security2:error] [pid 229246:tid 229270] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/crgio.php"] [unique_id "al9JJyBMYeh5YLVG45x1bAACPhc"]
[Tue Jul 21 07:25:43.856267 2026] [security2:error] [pid 229246:tid 229309] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-act.php"] [unique_id "al9JJyBMYeh5YLVG45x1bQACPT4"]
[Tue Jul 21 07:25:43.875826 2026] [security2:error] [pid 229246:tid 229294] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/new4.php"] [unique_id "al9JJyBMYeh5YLVG45x1bwACfy8"]
[Tue Jul 21 07:25:43.891242 2026] [security2:error] [pid 229246:tid 229257] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-the.php"] [unique_id "al9JJyBMYeh5YLVG45x1cQACewo"]
[Tue Jul 21 07:25:43.891737 2026] [security2:error] [pid 229246:tid 229484] [client 117.195.76.197:64248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.76.195.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grupogradiente.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JJyBMYeh5YLVG45x1cgAAAoA"]
[Tue Jul 21 07:25:43.891846 2026] [security2:error] [pid 229246:tid 229484] [client 117.195.76.197:64248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grupogradiente.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JJyBMYeh5YLVG45x1cgAAAoA"]
[Tue Jul 21 07:25:43.909370 2026] [security2:error] [pid 229246:tid 229351] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/atkno.php"] [unique_id "al9JJyBMYeh5YLVG45x1cwACgmg"]
[Tue Jul 21 07:25:43.932660 2026] [security2:error] [pid 229246:tid 229339] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/mass.php"] [unique_id "al9JJyBMYeh5YLVG45x1dAACOFw"]
[Tue Jul 21 07:25:43.966564 2026] [security2:error] [pid 230252:tid 230474] [client 20.226.60.151:56932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/177.php"] [unique_id "al9JJ00Dwhk5-Z44XrpQwwAAAvM"]
[Tue Jul 21 07:25:43.972568 2026] [security2:error] [pid 229246:tid 229356] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wefile.php"] [unique_id "al9JJyBMYeh5YLVG45x1dQACKm0"]
[Tue Jul 21 07:25:43.993202 2026] [security2:error] [pid 229246:tid 229319] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/min.php"] [unique_id "al9JJyBMYeh5YLVG45x1dgACF0g"]
[Tue Jul 21 07:25:44.059672 2026] [security2:error] [pid 229246:tid 229357] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/sid3.php"] [unique_id "al9JKCBMYeh5YLVG45x1dwACdm4"]
[Tue Jul 21 07:25:44.074351 2026] [security2:error] [pid 229246:tid 229274] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/fileas.php"] [unique_id "al9JKCBMYeh5YLVG45x1eAACFBs"]
[Tue Jul 21 07:25:44.092141 2026] [security2:error] [pid 229246:tid 229342] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/bless24.php"] [unique_id "al9JKCBMYeh5YLVG45x1eQACIV8"]
[Tue Jul 21 07:25:44.116651 2026] [security2:error] [pid 229246:tid 229363] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/fun.php"] [unique_id "al9JKCBMYeh5YLVG45x1egACkXQ"]
[Tue Jul 21 07:25:44.141652 2026] [security2:error] [pid 229246:tid 229307] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/drykl.php"] [unique_id "al9JKCBMYeh5YLVG45x1fQACYDw"]
[Tue Jul 21 07:25:44.159726 2026] [security2:error] [pid 229246:tid 229354] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "al9JKCBMYeh5YLVG45x1fgAChWs"]
[Tue Jul 21 07:25:44.173444 2026] [security2:error] [pid 229246:tid 229298] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/mifta.php"] [unique_id "al9JKCBMYeh5YLVG45x1gAACVzM"]
[Tue Jul 21 07:25:44.209896 2026] [security2:error] [pid 229246:tid 229329] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/class-t.api.php"] [unique_id "al9JKCBMYeh5YLVG45x1gQACQ1I"]
[Tue Jul 21 07:25:44.247204 2026] [proxy:error] [pid 230252:tid 230402] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:44.247266 2026] [proxy_http:error] [pid 230252:tid 230402] [client 93.123.109.101:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:44.247899 2026] [proxy:error] [pid 230252:tid 230402] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:44.247932 2026] [proxy_http:error] [pid 230252:tid 230402] [client 93.123.109.101:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:44.251805 2026] [security2:error] [pid 229246:tid 229503] [client 62.102.148.164:46774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9JKCBMYeh5YLVG45x1hQAAApM"]
[Tue Jul 21 07:25:44.251913 2026] [security2:error] [pid 229246:tid 229503] [client 62.102.148.164:46774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9JKCBMYeh5YLVG45x1hQAAApM"]
[Tue Jul 21 07:25:44.288282 2026] [security2:error] [pid 230252:tid 230444] [client 117.251.86.144:40300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JKE0Dwhk5-Z44XrpQzQAAAtU"]
[Tue Jul 21 07:25:44.288404 2026] [security2:error] [pid 230252:tid 230444] [client 117.251.86.144:40300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JKE0Dwhk5-Z44XrpQzQAAAtU"]
[Tue Jul 21 07:25:44.309979 2026] [security2:error] [pid 229246:tid 229315] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/vgtyu.php"] [unique_id "al9JKCBMYeh5YLVG45x1iAACR0Q"]
[Tue Jul 21 07:25:44.365836 2026] [security2:error] [pid 229246:tid 229333] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/atomlib.php"] [unique_id "al9JKCBMYeh5YLVG45x1igACY1Y"]
[Tue Jul 21 07:25:44.398131 2026] [security2:error] [pid 229246:tid 229295] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-access.php"] [unique_id "al9JKCBMYeh5YLVG45x1iwACSjA"]
[Tue Jul 21 07:25:44.417181 2026] [security2:error] [pid 229246:tid 229281] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-update.php"] [unique_id "al9JKCBMYeh5YLVG45x1jAACLiI"]
[Tue Jul 21 07:25:44.450000 2026] [security2:error] [pid 230252:tid 230378] [remote 64.225.121.94:59642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pousadanaturalis.com.br"] [uri "/wp-login.php"] [unique_id "al9JKE0Dwhk5-Z44XrpQ0QACsns"]
[Tue Jul 21 07:25:44.451988 2026] [security2:error] [pid 229246:tid 229287] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/erty.php"] [unique_id "al9JKCBMYeh5YLVG45x1jgACSSg"]
[Tue Jul 21 07:25:44.485939 2026] [proxy:error] [pid 229246:tid 229436] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:44.486015 2026] [proxy_http:error] [pid 229246:tid 229436] [client 20.151.10.161:63632] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:44.486769 2026] [proxy:error] [pid 229246:tid 229436] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:44.486810 2026] [proxy_http:error] [pid 229246:tid 229436] [client 20.151.10.161:63632] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:44.493531 2026] [security2:error] [pid 229246:tid 229332] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "al9JKCBMYeh5YLVG45x1kAACi1U"]
[Tue Jul 21 07:25:44.508527 2026] [security2:error] [pid 229246:tid 229368] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/like.php"] [unique_id "al9JKCBMYeh5YLVG45x1kwACO3k"]
[Tue Jul 21 07:25:44.512364 2026] [security2:error] [pid 230252:tid 230500] [client 20.226.60.151:54536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/albin.php"] [unique_id "al9JKE0Dwhk5-Z44XrpQ0wAAAw0"]
[Tue Jul 21 07:25:44.535676 2026] [security2:error] [pid 229246:tid 229340] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/bless5.php"] [unique_id "al9JKCBMYeh5YLVG45x1lQACXF0"]
[Tue Jul 21 07:25:44.592887 2026] [security2:error] [pid 229246:tid 229347] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/t.php"] [unique_id "al9JKCBMYeh5YLVG45x1lgACiGQ"]
[Tue Jul 21 07:25:44.608273 2026] [security2:error] [pid 229246:tid 229271] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/xoot.php"] [unique_id "al9JKCBMYeh5YLVG45x1lwACOhg"]
[Tue Jul 21 07:25:44.622725 2026] [security2:error] [pid 229246:tid 229276] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/xqq.php"] [unique_id "al9JKCBMYeh5YLVG45x1mAACdR0"]
[Tue Jul 21 07:25:44.636863 2026] [security2:error] [pid 229246:tid 229373] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-load.php"] [unique_id "al9JKCBMYeh5YLVG45x1mQACQH4"]
[Tue Jul 21 07:25:44.651700 2026] [security2:error] [pid 229246:tid 229292] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/x.php"] [unique_id "al9JKCBMYeh5YLVG45x1mgACPC0"]
[Tue Jul 21 07:25:44.669277 2026] [security2:error] [pid 229246:tid 229279] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/i.php"] [unique_id "al9JKCBMYeh5YLVG45x1mwACaSA"]
[Tue Jul 21 07:25:44.679288 2026] [security2:error] [pid 230252:tid 230506] [client 74.249.245.134:5528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/php.php"] [unique_id "al9JKE0Dwhk5-Z44XrpQ1QAAAxM"]
[Tue Jul 21 07:25:44.725754 2026] [security2:error] [pid 229246:tid 229365] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/ms-edit.php"] [unique_id "al9JKCBMYeh5YLVG45x1oAACkHY"]
[Tue Jul 21 07:25:44.742095 2026] [security2:error] [pid 229246:tid 229341] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/v2.php"] [unique_id "al9JKCBMYeh5YLVG45x1oQACNF4"]
[Tue Jul 21 07:25:44.758058 2026] [security2:error] [pid 229246:tid 229258] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/new.php"] [unique_id "al9JKCBMYeh5YLVG45x1ogACSws"]
[Tue Jul 21 07:25:44.779578 2026] [security2:error] [pid 229246:tid 229493] [client 152.59.154.239:63189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JKCBMYeh5YLVG45x1nwAAAok"]
[Tue Jul 21 07:25:44.808630 2026] [security2:error] [pid 229246:tid 229306] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-admin/network/edit.php"] [unique_id "al9JKCBMYeh5YLVG45x1pAACWzs"]
[Tue Jul 21 07:25:44.816532 2026] [security2:error] [pid 230252:tid 230422] [client 20.226.60.151:62357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/config.php"] [unique_id "al9JKE0Dwhk5-Z44XrpQ2wAAAr8"]
[Tue Jul 21 07:25:44.840136 2026] [security2:error] [pid 229246:tid 229323] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/pouhg.php"] [unique_id "al9JKCBMYeh5YLVG45x1pQACakw"]
[Tue Jul 21 07:25:44.854921 2026] [security2:error] [pid 229246:tid 229369] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/cilus.php"] [unique_id "al9JKCBMYeh5YLVG45x1pwACRXo"]
[Tue Jul 21 07:25:44.953265 2026] [security2:error] [pid 229246:tid 229300] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/file4.php"] [unique_id "al9JKCBMYeh5YLVG45x1qAACNzU"]
[Tue Jul 21 07:25:44.984437 2026] [security2:error] [pid 229246:tid 229349] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/samll.php"] [unique_id "al9JKCBMYeh5YLVG45x1qQACQWY"]
[Tue Jul 21 07:25:45.034596 2026] [security2:error] [pid 229246:tid 229290] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/Okxob.php"] [unique_id "al9JKSBMYeh5YLVG45x1qwACMis"]
[Tue Jul 21 07:25:45.076063 2026] [security2:error] [pid 229246:tid 229331] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JKSBMYeh5YLVG45x1rQACc1Q"]
[Tue Jul 21 07:25:45.076249 2026] [security2:error] [pid 229246:tid 229471] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JKSBMYeh5YLVG45x1rQACc1Q"]
[Tue Jul 21 07:25:45.139371 2026] [security2:error] [pid 229246:tid 229275] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/ok.php"] [unique_id "al9JKSBMYeh5YLVG45x1rgACjRw"]
[Tue Jul 21 07:25:45.154549 2026] [security2:error] [pid 229246:tid 229308] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wuasr.php"] [unique_id "al9JKSBMYeh5YLVG45x1rwACKT0"]
[Tue Jul 21 07:25:45.169279 2026] [security2:error] [pid 229246:tid 229249] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/bless11.php"] [unique_id "al9JKSBMYeh5YLVG45x1sQACGgI"]
[Tue Jul 21 07:25:45.216339 2026] [security2:error] [pid 229246:tid 229269] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-block.php"] [unique_id "al9JKSBMYeh5YLVG45x1tAACYhY"]
[Tue Jul 21 07:25:45.245215 2026] [security2:error] [pid 229246:tid 229272] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/aevly.php"] [unique_id "al9JKSBMYeh5YLVG45x1tgACaxk"]
[Tue Jul 21 07:25:45.271824 2026] [security2:error] [pid 229246:tid 229248] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/hello.php"] [unique_id "al9JKSBMYeh5YLVG45x1twACjAE"]
[Tue Jul 21 07:25:45.282684 2026] [security2:error] [pid 229246:tid 229378] [client 20.226.60.151:56843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/gettest.php"] [unique_id "al9JKSBMYeh5YLVG45x1uAAAAhY"]
[Tue Jul 21 07:25:45.325589 2026] [security2:error] [pid 229246:tid 229286] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-links-opml.php"] [unique_id "al9JKSBMYeh5YLVG45x1uQACWSc"]
[Tue Jul 21 07:25:45.346528 2026] [security2:error] [pid 229246:tid 229285] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/forbidals.php"] [unique_id "al9JKSBMYeh5YLVG45x1ugACVSY"]
[Tue Jul 21 07:25:45.363233 2026] [security2:error] [pid 229246:tid 229336] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/file30.php"] [unique_id "al9JKSBMYeh5YLVG45x1uwACZVk"]
[Tue Jul 21 07:25:45.377760 2026] [security2:error] [pid 229246:tid 229337] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/xda.php"] [unique_id "al9JKSBMYeh5YLVG45x1vAACfFo"]
[Tue Jul 21 07:25:45.390776 2026] [security2:error] [pid 230252:tid 230511] [client 34.148.166.21:50952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.166.148.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lp.oticapersona.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JKU0Dwhk5-Z44XrpQ5AAAAxg"]
[Tue Jul 21 07:25:45.390899 2026] [security2:error] [pid 230252:tid 230511] [client 34.148.166.21:50952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lp.oticapersona.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JKU0Dwhk5-Z44XrpQ5AAAAxg"]
[Tue Jul 21 07:25:45.393001 2026] [security2:error] [pid 229246:tid 229282] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/z.php"] [unique_id "al9JKSBMYeh5YLVG45x1vQACdyM"]
[Tue Jul 21 07:25:45.409534 2026] [security2:error] [pid 229246:tid 229263] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/b.php"] [unique_id "al9JKSBMYeh5YLVG45x1vgACVhA"]
[Tue Jul 21 07:25:45.425254 2026] [security2:error] [pid 229246:tid 229353] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/edit.php"] [unique_id "al9JKSBMYeh5YLVG45x1vwACbWo"]
[Tue Jul 21 07:25:45.460174 2026] [security2:error] [pid 229246:tid 229293] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/app.php"] [unique_id "al9JKSBMYeh5YLVG45x1wAACgS4"]
[Tue Jul 21 07:25:45.467788 2026] [security2:error] [pid 230252:tid 230417] [client 74.7.228.53:53696] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.emulti.agendaclique.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9JKU0Dwhk5-Z44XrpQ5gACumU"]
[Tue Jul 21 07:25:45.470112 2026] [proxy:error] [pid 230252:tid 230472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:45.470155 2026] [proxy_http:error] [pid 230252:tid 230472] [client 20.151.10.161:49035] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:45.470704 2026] [proxy:error] [pid 230252:tid 230472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:45.470726 2026] [proxy_http:error] [pid 230252:tid 230472] [client 20.151.10.161:49035] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:45.499493 2026] [security2:error] [pid 229246:tid 229289] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-png.php"] [unique_id "al9JKSBMYeh5YLVG45x1wgACeio"]
[Tue Jul 21 07:25:45.516787 2026] [security2:error] [pid 230252:tid 230478] [client 20.151.10.161:63723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/chosen.php"] [unique_id "al9JKU0Dwhk5-Z44XrpQ6AAAAvc"]
[Tue Jul 21 07:25:45.517591 2026] [security2:error] [pid 229246:tid 229317] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/lib.php"] [unique_id "al9JKSBMYeh5YLVG45x1wwACh0Y"]
[Tue Jul 21 07:25:45.532375 2026] [security2:error] [pid 229246:tid 229316] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/sys.php"] [unique_id "al9JKSBMYeh5YLVG45x1xQACMUU"]
[Tue Jul 21 07:25:45.549225 2026] [security2:error] [pid 229246:tid 229288] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/la.php"] [unique_id "al9JKSBMYeh5YLVG45x1xwACWik"]
[Tue Jul 21 07:25:45.550568 2026] [security2:error] [pid 229246:tid 229364] [remote 68.178.160.25:53398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/wp-login.php"] [unique_id "al9JKSBMYeh5YLVG45x1xgACdHU"]
[Tue Jul 21 07:25:45.615543 2026] [security2:error] [pid 229246:tid 229370] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/tires.php"] [unique_id "al9JKSBMYeh5YLVG45x1yAACXXs"]
[Tue Jul 21 07:25:45.729545 2026] [security2:error] [pid 229246:tid 229321] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/lv.php"] [unique_id "al9JKSBMYeh5YLVG45x1ygACPUo"]
[Tue Jul 21 07:25:45.769000 2026] [security2:error] [pid 229246:tid 229344] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/myfile.php"] [unique_id "al9JKSBMYeh5YLVG45x1zAACf2E"]
[Tue Jul 21 07:25:45.783873 2026] [security2:error] [pid 229246:tid 229479] [client 82.102.28.107:53186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9JKSBMYeh5YLVG45x1zQAAAns"]
[Tue Jul 21 07:25:45.783976 2026] [security2:error] [pid 229246:tid 229479] [client 82.102.28.107:53186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9JKSBMYeh5YLVG45x1zQAAAns"]
[Tue Jul 21 07:25:45.795894 2026] [security2:error] [pid 229246:tid 229260] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/06.php"] [unique_id "al9JKSBMYeh5YLVG45x1zgACgA0"]
[Tue Jul 21 07:25:45.820242 2026] [security2:error] [pid 229246:tid 229366] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/fs.php"] [unique_id "al9JKSBMYeh5YLVG45x1zwACHHc"]
[Tue Jul 21 07:25:45.835589 2026] [security2:error] [pid 229246:tid 229325] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/asasx.php"] [unique_id "al9JKSBMYeh5YLVG45x10AACgk4"]
[Tue Jul 21 07:25:45.859960 2026] [security2:error] [pid 229246:tid 229268] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-kd4xalrg7m.php"] [unique_id "al9JKSBMYeh5YLVG45x10QACRBU"]
[Tue Jul 21 07:25:45.884157 2026] [security2:error] [pid 229246:tid 229311] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-good.php"] [unique_id "al9JKSBMYeh5YLVG45x10gACKEA"]
[Tue Jul 21 07:25:45.899006 2026] [security2:error] [pid 229246:tid 229338] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/scxy.php"] [unique_id "al9JKSBMYeh5YLVG45x10wACOFs"]
[Tue Jul 21 07:25:45.940917 2026] [security2:error] [pid 229246:tid 229346] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wmore1.php"] [unique_id "al9JKSBMYeh5YLVG45x11AACKmM"]
[Tue Jul 21 07:25:45.944482 2026] [security2:error] [pid 230252:tid 230254] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JKU0Dwhk5-Z44XrpQ7gACrAA"]
[Tue Jul 21 07:25:45.944589 2026] [security2:error] [pid 230252:tid 230403] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JKU0Dwhk5-Z44XrpQ7gACrAA"]
[Tue Jul 21 07:25:45.954937 2026] [security2:error] [pid 229246:tid 229374] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/like.php"] [unique_id "al9JKSBMYeh5YLVG45x11QACF38"]
[Tue Jul 21 07:25:46.053354 2026] [security2:error] [pid 229246:tid 229250] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/x.php"] [unique_id "al9JKiBMYeh5YLVG45x11gACFAM"]
[Tue Jul 21 07:25:46.072055 2026] [security2:error] [pid 229246:tid 229348] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/xa.php"] [unique_id "al9JKiBMYeh5YLVG45x11wACIWU"]
[Tue Jul 21 07:25:46.095381 2026] [security2:error] [pid 229246:tid 229291] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/kolda.php"] [unique_id "al9JKiBMYeh5YLVG45x12AACYCw"]
[Tue Jul 21 07:25:46.110516 2026] [security2:error] [pid 229246:tid 229253] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-aothait.php"] [unique_id "al9JKiBMYeh5YLVG45x12QACTAY"]
[Tue Jul 21 07:25:46.123112 2026] [security2:error] [pid 229246:tid 229264] [remote 160.187.68.132:54358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9JKiBMYeh5YLVG45x12wACNhE"]
[Tue Jul 21 07:25:46.125806 2026] [security2:error] [pid 229246:tid 229330] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/ftde.php"] [unique_id "al9JKiBMYeh5YLVG45x13AACV1M"]
[Tue Jul 21 07:25:46.163844 2026] [security2:error] [pid 229246:tid 229304] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/vx.php"] [unique_id "al9JKiBMYeh5YLVG45x13QACUzk"]
[Tue Jul 21 07:25:46.195828 2026] [security2:error] [pid 229246:tid 229256] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/a5.php"] [unique_id "al9JKiBMYeh5YLVG45x13gACfQk"]
[Tue Jul 21 07:25:46.226869 2026] [security2:error] [pid 229246:tid 229310] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-sing.php"] [unique_id "al9JKiBMYeh5YLVG45x13wACkz8"]
[Tue Jul 21 07:25:46.243653 2026] [security2:error] [pid 229246:tid 229297] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/database.php"] [unique_id "al9JKiBMYeh5YLVG45x14QACTzI"]
[Tue Jul 21 07:25:46.254414 2026] [security2:error] [pid 230252:tid 230414] [client 136.144.33.241:40555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JKU0Dwhk5-Z44XrpQ4AAAArc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:25:46.263079 2026] [security2:error] [pid 229246:tid 229352] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/explorer/index_.php"] [unique_id "al9JKiBMYeh5YLVG45x14wACM2k"]
[Tue Jul 21 07:25:46.279339 2026] [security2:error] [pid 229246:tid 229360] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-at.php"] [unique_id "al9JKiBMYeh5YLVG45x15AACK3E"]
[Tue Jul 21 07:25:46.308090 2026] [security2:error] [pid 229246:tid 229299] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-wz.php"] [unique_id "al9JKiBMYeh5YLVG45x15QACIDQ"]
[Tue Jul 21 07:25:46.330542 2026] [security2:error] [pid 229246:tid 229326] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-ver.php"] [unique_id "al9JKiBMYeh5YLVG45x15wACYU8"]
[Tue Jul 21 07:25:46.346950 2026] [security2:error] [pid 229246:tid 229284] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp5.php"] [unique_id "al9JKiBMYeh5YLVG45x16AACSiU"]
[Tue Jul 21 07:25:46.357991 2026] [security2:error] [pid 229246:tid 229402] [client 20.226.60.151:56953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/min.php"] [unique_id "al9JKiBMYeh5YLVG45x16QAAAi4"]
[Tue Jul 21 07:25:46.362787 2026] [security2:error] [pid 229246:tid 229328] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-pp.php"] [unique_id "al9JKiBMYeh5YLVG45x16gACSVE"]
[Tue Jul 21 07:25:46.379284 2026] [security2:error] [pid 229246:tid 229314] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/w3lls.php"] [unique_id "al9JKiBMYeh5YLVG45x16wACZEM"]
[Tue Jul 21 07:25:46.395652 2026] [security2:error] [pid 229246:tid 229247] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/sbhu.php"] [unique_id "al9JKiBMYeh5YLVG45x17AACVAA"]
[Tue Jul 21 07:25:46.454489 2026] [security2:error] [pid 229246:tid 229277] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "al9JKiBMYeh5YLVG45x17QACUB4"]
[Tue Jul 21 07:25:46.484524 2026] [security2:error] [pid 229246:tid 229312] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/favicon.php"] [unique_id "al9JKiBMYeh5YLVG45x18AACTUE"]
[Tue Jul 21 07:25:46.502455 2026] [security2:error] [pid 229246:tid 229327] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/txets.php"] [unique_id "al9JKiBMYeh5YLVG45x18gACJlA"]
[Tue Jul 21 07:25:46.518926 2026] [security2:error] [pid 229246:tid 229261] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-su.php"] [unique_id "al9JKiBMYeh5YLVG45x18wACdQ4"]
[Tue Jul 21 07:25:46.522045 2026] [security2:error] [pid 230252:tid 230436] [client 20.52.136.55:1559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/classwithtostring.php"] [unique_id "al9JKk0Dwhk5-Z44XrpQ9gAAAs0"]
[Tue Jul 21 07:25:46.559353 2026] [security2:error] [pid 229246:tid 229265] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/ff.php"] [unique_id "al9JKiBMYeh5YLVG45x19AACbxI"]
[Tue Jul 21 07:25:46.617066 2026] [security2:error] [pid 229246:tid 229350] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/reze.php"] [unique_id "al9JKiBMYeh5YLVG45x1-AACkGc"]
[Tue Jul 21 07:25:46.617423 2026] [security2:error] [pid 229246:tid 229466] [client 74.249.245.134:54354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/aa.php"] [unique_id "al9JKiBMYeh5YLVG45x1-QAAAm4"]
[Tue Jul 21 07:25:46.635888 2026] [security2:error] [pid 229246:tid 229305] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/666.php"] [unique_id "al9JKiBMYeh5YLVG45x1-gACXjo"]
[Tue Jul 21 07:25:46.657198 2026] [security2:error] [pid 229246:tid 229266] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wehrman.php"] [unique_id "al9JKiBMYeh5YLVG45x1-wACMBM"]
[Tue Jul 21 07:25:46.687483 2026] [security2:error] [pid 229246:tid 229251] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-conflg.php"] [unique_id "al9JKiBMYeh5YLVG45x1_QACSwQ"]
[Tue Jul 21 07:25:46.701822 2026] [security2:error] [pid 229246:tid 229302] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/ff1.php"] [unique_id "al9JKiBMYeh5YLVG45x1_gACiTc"]
[Tue Jul 21 07:25:46.725374 2026] [security2:error] [pid 229246:tid 229303] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/fff.php"] [unique_id "al9JKiBMYeh5YLVG45x1_wACWzg"]
[Tue Jul 21 07:25:46.749615 2026] [security2:error] [pid 229246:tid 229270] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/amax.php"] [unique_id "al9JKiBMYeh5YLVG45x2AAACRRc"]
[Tue Jul 21 07:25:46.770253 2026] [security2:error] [pid 229246:tid 229257] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-firewall.php"] [unique_id "al9JKiBMYeh5YLVG45x2BAACjQo"]
[Tue Jul 21 07:25:46.785684 2026] [security2:error] [pid 230252:tid 230339] [remote 216.73.217.141:32201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vaporclube.com.br"] [uri "/campinas.php"] [unique_id "al9JKk0Dwhk5-Z44XrpQ-AACz1Q"]
[Tue Jul 21 07:25:46.805685 2026] [security2:error] [pid 229246:tid 229355] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/appt.php"] [unique_id "al9JKiBMYeh5YLVG45x2BgACYmw"]
[Tue Jul 21 07:25:46.821684 2026] [security2:error] [pid 229246:tid 229351] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-thi.php"] [unique_id "al9JKiBMYeh5YLVG45x2BwACj2g"]
[Tue Jul 21 07:25:46.832945 2026] [security2:error] [pid 230252:tid 230371] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JKk0Dwhk5-Z44XrpQ-gACzHQ"]
[Tue Jul 21 07:25:46.833107 2026] [security2:error] [pid 230252:tid 230435] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JKk0Dwhk5-Z44XrpQ-gACzHQ"]
[Tue Jul 21 07:25:46.843948 2026] [security2:error] [pid 229246:tid 229356] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/jj.php"] [unique_id "al9JKiBMYeh5YLVG45x2CQACcG0"]
[Tue Jul 21 07:25:46.861782 2026] [security2:error] [pid 229246:tid 229319] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/333.php"] [unique_id "al9JKiBMYeh5YLVG45x2CgACI0g"]
[Tue Jul 21 07:25:46.933761 2026] [security2:error] [pid 229246:tid 229280] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/albin.php"] [unique_id "al9JKiBMYeh5YLVG45x2DAACjCE"]
[Tue Jul 21 07:25:46.944621 2026] [security2:error] [pid 230252:tid 230322] [remote 216.73.217.141:32201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vaporclube.com.br"] [uri "/termos.php"] [unique_id "al9JKk0Dwhk5-Z44XrpQ-QACz0Q"]
[Tue Jul 21 07:25:46.958148 2026] [security2:error] [pid 229246:tid 229357] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/66.php"] [unique_id "al9JKiBMYeh5YLVG45x2DQACaG4"]
[Tue Jul 21 07:25:47.003153 2026] [security2:error] [pid 229246:tid 229274] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/motu.php"] [unique_id "al9JKyBMYeh5YLVG45x2DgACVRs"]
[Tue Jul 21 07:25:47.020844 2026] [security2:error] [pid 229246:tid 229342] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/kj.php"] [unique_id "al9JKyBMYeh5YLVG45x2DwACZV8"]
[Tue Jul 21 07:25:47.036397 2026] [security2:error] [pid 229246:tid 229363] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp4.php"] [unique_id "al9JKyBMYeh5YLVG45x2EAACfHQ"]
[Tue Jul 21 07:25:47.053058 2026] [security2:error] [pid 229246:tid 229307] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/file61.php"] [unique_id "al9JKyBMYeh5YLVG45x2EQACVjw"]
[Tue Jul 21 07:25:47.069143 2026] [security2:error] [pid 229246:tid 229320] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp.php"] [unique_id "al9JKyBMYeh5YLVG45x2EgACgUk"]
[Tue Jul 21 07:25:47.117160 2026] [security2:error] [pid 229246:tid 229354] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-trackback.php"] [unique_id "al9JKyBMYeh5YLVG45x2EwACems"]
[Tue Jul 21 07:25:47.117933 2026] [security2:error] [pid 230252:tid 230388] [client 20.151.10.161:49084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9JK00Dwhk5-Z44XrpQ_wAAAp0"]
[Tue Jul 21 07:25:47.175688 2026] [security2:error] [pid 229246:tid 229298] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/db.php"] [unique_id "al9JKyBMYeh5YLVG45x2FAACMTM"]
[Tue Jul 21 07:25:47.194582 2026] [proxy:error] [pid 229246:tid 229446] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:47.194635 2026] [proxy_http:error] [pid 229246:tid 229446] [client 20.151.10.161:65516] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:47.195250 2026] [proxy:error] [pid 229246:tid 229446] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:47.195274 2026] [proxy_http:error] [pid 229246:tid 229446] [client 20.151.10.161:65516] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:47.280486 2026] [security2:error] [pid 229246:tid 229361] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/NewFile.php"] [unique_id "al9JKyBMYeh5YLVG45x2GAACknI"]
[Tue Jul 21 07:25:47.296888 2026] [security2:error] [pid 229246:tid 229283] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/xxx.php"] [unique_id "al9JKyBMYeh5YLVG45x2GgACUiQ"]
[Tue Jul 21 07:25:47.312261 2026] [security2:error] [pid 229246:tid 229295] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/ms.php"] [unique_id "al9JKyBMYeh5YLVG45x2HAACfzA"]
[Tue Jul 21 07:25:47.330518 2026] [security2:error] [pid 229246:tid 229281] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/mini.php"] [unique_id "al9JKyBMYeh5YLVG45x2HgACgCI"]
[Tue Jul 21 07:25:47.346615 2026] [security2:error] [pid 229246:tid 229287] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/first.php"] [unique_id "al9JKyBMYeh5YLVG45x2HwACRCg"]
[Tue Jul 21 07:25:47.378998 2026] [security2:error] [pid 229246:tid 229368] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/0okj.php"] [unique_id "al9JKyBMYeh5YLVG45x2IQACJXk"]
[Tue Jul 21 07:25:47.395456 2026] [security2:error] [pid 229246:tid 229340] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/grsiuk.php"] [unique_id "al9JKyBMYeh5YLVG45x2IgACOF0"]
[Tue Jul 21 07:25:47.418639 2026] [security2:error] [pid 229246:tid 229347] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/shell20211028.php"] [unique_id "al9JKyBMYeh5YLVG45x2IwACF2Q"]
[Tue Jul 21 07:25:47.448430 2026] [security2:error] [pid 229246:tid 229271] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/revealability.php"] [unique_id "al9JKyBMYeh5YLVG45x2JAACJxg"]
[Tue Jul 21 07:25:47.518822 2026] [security2:error] [pid 229246:tid 229276] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/btx25.php"] [unique_id "al9JKyBMYeh5YLVG45x2JQACdh0"]
[Tue Jul 21 07:25:47.528140 2026] [security2:error] [pid 229246:tid 229428] [client 103.106.20.201:61835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JKyBMYeh5YLVG45x2JgAAAkg"]
[Tue Jul 21 07:25:47.528254 2026] [security2:error] [pid 229246:tid 229428] [client 103.106.20.201:61835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JKyBMYeh5YLVG45x2JgAAAkg"]
[Tue Jul 21 07:25:47.554706 2026] [security2:error] [pid 229246:tid 229359] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/bthil.php"] [unique_id "al9JKyBMYeh5YLVG45x2JwACFHA"]
[Tue Jul 21 07:25:47.601723 2026] [security2:error] [pid 229246:tid 229345] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/hplfuns.php"] [unique_id "al9JKyBMYeh5YLVG45x2KgACkWI"]
[Tue Jul 21 07:25:47.625209 2026] [security2:error] [pid 229246:tid 229279] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/error.php"] [unique_id "al9JKyBMYeh5YLVG45x2LAACTCA"]
[Tue Jul 21 07:25:47.658199 2026] [security2:error] [pid 229246:tid 229335] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/edit.php"] [unique_id "al9JKyBMYeh5YLVG45x2LQACNlg"]
[Tue Jul 21 07:25:47.664277 2026] [security2:error] [pid 230252:tid 230506] [client 20.226.60.151:56898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/dvjul.php"] [unique_id "al9JK00Dwhk5-Z44XrpRBQAAAxM"]
[Tue Jul 21 07:25:47.723227 2026] [security2:error] [pid 229246:tid 229365] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/pass4.php"] [unique_id "al9JKyBMYeh5YLVG45x2LgACV3Y"]
[Tue Jul 21 07:25:47.739499 2026] [security2:error] [pid 229246:tid 229341] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/sadcut1.php"] [unique_id "al9JKyBMYeh5YLVG45x2LwACU14"]
[Tue Jul 21 07:25:47.769888 2026] [security2:error] [pid 229246:tid 229343] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/bgymj.php"] [unique_id "al9JKyBMYeh5YLVG45x2MAACZmA"]
[Tue Jul 21 07:25:47.812541 2026] [security2:error] [pid 229246:tid 229306] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/yas.php"] [unique_id "al9JKyBMYeh5YLVG45x2MgACMzs"]
[Tue Jul 21 07:25:47.852401 2026] [security2:error] [pid 229246:tid 229369] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/dx.php"] [unique_id "al9JKyBMYeh5YLVG45x2NAACP3o"]
[Tue Jul 21 07:25:47.883487 2026] [security2:error] [pid 229246:tid 229300] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/yellow.php"] [unique_id "al9JKyBMYeh5YLVG45x2NQACYzU"]
[Tue Jul 21 07:25:47.918878 2026] [security2:error] [pid 229246:tid 229349] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-der.php"] [unique_id "al9JKyBMYeh5YLVG45x2NgACHmY"]
[Tue Jul 21 07:25:47.986510 2026] [security2:error] [pid 230252:tid 230409] [client 103.174.34.15:58802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JK00Dwhk5-Z44XrpRCgAAArI"]
[Tue Jul 21 07:25:47.986604 2026] [security2:error] [pid 230252:tid 230409] [client 103.174.34.15:58802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JK00Dwhk5-Z44XrpRCgAAArI"]
[Tue Jul 21 07:25:48.062142 2026] [security2:error] [pid 230252:tid 230473] [client 45.251.232.145:62364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JLE0Dwhk5-Z44XrpRCwAAAvI"]
[Tue Jul 21 07:25:48.062257 2026] [security2:error] [pid 230252:tid 230473] [client 45.251.232.145:62364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JLE0Dwhk5-Z44XrpRCwAAAvI"]
[Tue Jul 21 07:25:48.161998 2026] [security2:error] [pid 229246:tid 229275] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/lala.php"] [unique_id "al9JLCBMYeh5YLVG45x2OQACYRw"]
[Tue Jul 21 07:25:48.189235 2026] [security2:error] [pid 229246:tid 229308] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/aa.php"] [unique_id "al9JLCBMYeh5YLVG45x2OgACOT0"]
[Tue Jul 21 07:25:48.314771 2026] [security2:error] [pid 230252:tid 230382] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JLE0Dwhk5-Z44XrpRDQACpn8"]
[Tue Jul 21 07:25:48.314913 2026] [security2:error] [pid 230252:tid 230397] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JLE0Dwhk5-Z44XrpRDQACpn8"]
[Tue Jul 21 07:25:48.348631 2026] [security2:error] [pid 230252:tid 230492] [client 20.151.10.161:63627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/file5.php"] [unique_id "al9JLE0Dwhk5-Z44XrpRDgAAAwU"]
[Tue Jul 21 07:25:48.832627 2026] [security2:error] [pid 229246:tid 229378] [client 59.96.220.140:60444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JLCBMYeh5YLVG45x2QgAAAhY"]
[Tue Jul 21 07:25:48.832781 2026] [security2:error] [pid 229246:tid 229378] [client 59.96.220.140:60444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JLCBMYeh5YLVG45x2QgAAAhY"]
[Tue Jul 21 07:25:48.840836 2026] [security2:error] [pid 229246:tid 229492] [client 74.249.245.134:5534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/bolt.php"] [unique_id "al9JLCBMYeh5YLVG45x2QwAAAog"]
[Tue Jul 21 07:25:48.925314 2026] [security2:error] [pid 230252:tid 230404] [client 20.151.10.161:49074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/2P.php"] [unique_id "al9JLE0Dwhk5-Z44XrpREgAAAq0"]
[Tue Jul 21 07:25:49.177892 2026] [security2:error] [pid 229246:tid 229433] [client 175.45.70.82:65484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JLSBMYeh5YLVG45x2SQAAAk0"]
[Tue Jul 21 07:25:49.178047 2026] [security2:error] [pid 229246:tid 229433] [client 175.45.70.82:65484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JLSBMYeh5YLVG45x2SQAAAk0"]
[Tue Jul 21 07:25:49.207030 2026] [security2:error] [pid 230252:tid 230301] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JLU0Dwhk5-Z44XrpRFAAC4S8"]
[Tue Jul 21 07:25:49.207163 2026] [security2:error] [pid 230252:tid 230456] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JLU0Dwhk5-Z44XrpRFAAC4S8"]
[Tue Jul 21 07:25:49.394664 2026] [access_compat:error] [pid 230252:tid 230505] [client 162.241.63.68:31764] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:25:49.843500 2026] [security2:error] [pid 230252:tid 230453] [client 136.144.33.215:45661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JLU0Dwhk5-Z44XrpRGQAAAt4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:25:49.989893 2026] [security2:error] [pid 229246:tid 229497] [client 154.192.233.199:59349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JLSBMYeh5YLVG45x2WQAAAo0"]
[Tue Jul 21 07:25:49.990021 2026] [security2:error] [pid 229246:tid 229497] [client 154.192.233.199:59349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JLSBMYeh5YLVG45x2WQAAAo0"]
[Tue Jul 21 07:25:50.001224 2026] [security2:error] [pid 229246:tid 229445] [client 20.151.10.161:49144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/.well-known/about.php"] [unique_id "al9JLiBMYeh5YLVG45x2WwAAAlk"]
[Tue Jul 21 07:25:50.028417 2026] [security2:error] [pid 229246:tid 229293] [remote 5.252.52.249:49314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/wp-login.php"] [unique_id "al9JLiBMYeh5YLVG45x2XAACIy4"]
[Tue Jul 21 07:25:50.056821 2026] [security2:error] [pid 229246:tid 229475] [client 20.151.10.161:63624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/file.php"] [unique_id "al9JLiBMYeh5YLVG45x2XQAAAnc"]
[Tue Jul 21 07:25:50.141643 2026] [security2:error] [pid 230252:tid 230511] [client 185.198.240.89:31077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "voweltravel.com.br"] [uri "/wp-login.php"] [unique_id "al9JLU0Dwhk5-Z44XrpRFQAAAxg"]
[Tue Jul 21 07:25:50.454632 2026] [security2:error] [pid 230252:tid 230504] [client 74.249.245.134:47152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/403.php"] [unique_id "al9JLk0Dwhk5-Z44XrpRJwAAAxE"]
[Tue Jul 21 07:25:50.498286 2026] [security2:error] [pid 230252:tid 230436] [client 20.226.60.151:63352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/biufile.php"] [unique_id "al9JLk0Dwhk5-Z44XrpRKQAAAs0"]
[Tue Jul 21 07:25:50.537415 2026] [security2:error] [pid 230252:tid 230482] [client 213.152.162.104:48774] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9JLk0Dwhk5-Z44XrpRIAAAAvs"]
[Tue Jul 21 07:25:50.537550 2026] [security2:error] [pid 230252:tid 230482] [client 213.152.162.104:48774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9JLk0Dwhk5-Z44XrpRIAAAAvs"]
[Tue Jul 21 07:25:51.077367 2026] [security2:error] [pid 230252:tid 230477] [client 62.102.148.164:53642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9JL00Dwhk5-Z44XrpRNAAAAvY"]
[Tue Jul 21 07:25:51.077458 2026] [security2:error] [pid 230252:tid 230477] [client 62.102.148.164:53642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9JL00Dwhk5-Z44XrpRNAAAAvY"]
[Tue Jul 21 07:25:51.131755 2026] [security2:error] [pid 230252:tid 230469] [client 20.151.10.161:49080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9JL00Dwhk5-Z44XrpRNQAAAu4"]
[Tue Jul 21 07:25:51.186720 2026] [proxy:error] [pid 230252:tid 230437] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:51.186789 2026] [proxy_http:error] [pid 230252:tid 230437] [client 93.123.109.101:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:51.187444 2026] [proxy:error] [pid 230252:tid 230437] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:51.187480 2026] [proxy_http:error] [pid 230252:tid 230437] [client 93.123.109.101:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:51.519015 2026] [security2:error] [pid 230252:tid 230503] [client 74.249.245.134:54395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/x.php"] [unique_id "al9JL00Dwhk5-Z44XrpROAAAAxA"]
[Tue Jul 21 07:25:51.606690 2026] [security2:error] [pid 230252:tid 230400] [client 20.151.10.161:65469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/aa2.php"] [unique_id "al9JL00Dwhk5-Z44XrpROwAAAqk"]
[Tue Jul 21 07:25:51.889249 2026] [security2:error] [pid 230252:tid 230499] [client 20.151.10.161:49097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/bob.php"] [unique_id "al9JL00Dwhk5-Z44XrpRPgAAAww"]
[Tue Jul 21 07:25:51.898069 2026] [security2:error] [pid 230252:tid 230307] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JL00Dwhk5-Z44XrpRPwACyjU"]
[Tue Jul 21 07:25:51.898227 2026] [security2:error] [pid 230252:tid 230433] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JL00Dwhk5-Z44XrpRPwACyjU"]
[Tue Jul 21 07:25:52.328833 2026] [security2:error] [pid 230252:tid 230472] [client 20.226.60.151:56875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/av.php"] [unique_id "al9JME0Dwhk5-Z44XrpRQQAAAvE"]
[Tue Jul 21 07:25:52.644634 2026] [security2:error] [pid 230252:tid 230420] [client 20.151.10.161:65521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/ccou.php"] [unique_id "al9JME0Dwhk5-Z44XrpRRwAAAr0"]
[Tue Jul 21 07:25:52.747999 2026] [security2:error] [pid 230252:tid 230343] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JME0Dwhk5-Z44XrpRSAACy1g"]
[Tue Jul 21 07:25:52.748137 2026] [security2:error] [pid 230252:tid 230434] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JME0Dwhk5-Z44XrpRSAACy1g"]
[Tue Jul 21 07:25:52.753429 2026] [proxy:error] [pid 230252:tid 230439] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:52.753481 2026] [proxy_http:error] [pid 230252:tid 230439] [client 20.151.10.161:49042] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:52.754277 2026] [proxy:error] [pid 230252:tid 230439] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:52.754306 2026] [proxy_http:error] [pid 230252:tid 230439] [client 20.151.10.161:49042] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:53.202302 2026] [security2:error] [pid 230252:tid 230456] [client 139.135.44.145:53395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JMU0Dwhk5-Z44XrpRUwAAAuE"]
[Tue Jul 21 07:25:53.202384 2026] [security2:error] [pid 230252:tid 230456] [client 139.135.44.145:53395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JMU0Dwhk5-Z44XrpRUwAAAuE"]
[Tue Jul 21 07:25:53.252757 2026] [security2:error] [pid 230252:tid 230446] [client 74.249.245.134:5560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/jga.php"] [unique_id "al9JMU0Dwhk5-Z44XrpRVAAAAtc"]
[Tue Jul 21 07:25:53.285287 2026] [security2:error] [pid 230252:tid 230283] [remote 102.134.101.35:59704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9JMU0Dwhk5-Z44XrpRVgADAR0"]
[Tue Jul 21 07:25:53.400911 2026] [security2:error] [pid 230252:tid 230419] [client 103.162.129.114:58281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JMU0Dwhk5-Z44XrpRWAAAArw"]
[Tue Jul 21 07:25:53.401075 2026] [security2:error] [pid 230252:tid 230419] [client 103.162.129.114:58281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JMU0Dwhk5-Z44XrpRWAAAArw"]
[Tue Jul 21 07:25:53.471279 2026] [security2:error] [pid 230252:tid 230342] [remote 42.200.84.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onkosclinica.com"] [uri "/wp-login.php"] [unique_id "al9JMU0Dwhk5-Z44XrpRXAACxVc"]
[Tue Jul 21 07:25:53.582163 2026] [security2:error] [pid 230252:tid 230484] [client 20.151.10.161:65423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/dr.php"] [unique_id "al9JMU0Dwhk5-Z44XrpRXQAAAv0"]
[Tue Jul 21 07:25:53.628706 2026] [proxy:error] [pid 230252:tid 230385] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:53.628778 2026] [proxy_http:error] [pid 230252:tid 230385] [client 20.151.10.161:49137] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:53.629271 2026] [proxy:error] [pid 230252:tid 230385] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:53.629301 2026] [proxy_http:error] [pid 230252:tid 230385] [client 20.151.10.161:49137] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:53.630560 2026] [security2:error] [pid 230252:tid 230477] [client 20.226.60.151:56850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/coffexium.php"] [unique_id "al9JMU0Dwhk5-Z44XrpRYAAAAvY"]
[Tue Jul 21 07:25:53.714594 2026] [security2:error] [pid 230252:tid 230451] [client 20.151.10.161:26439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/ccou.php"] [unique_id "al9JMU0Dwhk5-Z44XrpRZQAAAtw"]
[Tue Jul 21 07:25:54.247451 2026] [security2:error] [pid 230252:tid 230258] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JMk0Dwhk5-Z44XrpRdAACvQQ"]
[Tue Jul 21 07:25:54.247591 2026] [security2:error] [pid 230252:tid 230420] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JMk0Dwhk5-Z44XrpRdAACvQQ"]
[Tue Jul 21 07:25:54.767668 2026] [security2:error] [pid 230252:tid 230394] [client 193.36.225.55:56717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JMk0Dwhk5-Z44XrpRfQAAAqM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:25:54.810130 2026] [security2:error] [pid 229246:tid 229462] [client 20.226.60.151:56876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/core.php"] [unique_id "al9JMiBMYeh5YLVG45x2jQAAAmo"]
[Tue Jul 21 07:25:54.947207 2026] [security2:error] [pid 230252:tid 230387] [client 74.7.241.158:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.lp.mannucarvalho.com"] [uri "/robots.txt"] [unique_id "al9JMk0Dwhk5-Z44XrpRggAAApw"]
[Tue Jul 21 07:25:54.948671 2026] [security2:error] [pid 230252:tid 230477] [client 74.7.241.158:34626] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.lp.mannucarvalho.com"] [uri "/robots.txt"] [unique_id "al9JMk0Dwhk5-Z44XrpRgAAC9h8"]
[Tue Jul 21 07:25:55.071939 2026] [security2:error] [pid 229246:tid 229467] [client 117.251.86.144:50158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JMyBMYeh5YLVG45x2kgAAAm8"]
[Tue Jul 21 07:25:55.072042 2026] [security2:error] [pid 229246:tid 229467] [client 117.251.86.144:50158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JMyBMYeh5YLVG45x2kgAAAm8"]
[Tue Jul 21 07:25:55.086941 2026] [security2:error] [pid 230252:tid 230487] [client 74.249.245.134:59758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/api.php"] [unique_id "al9JM00Dwhk5-Z44XrpRiAAAAwA"]
[Tue Jul 21 07:25:55.132559 2026] [security2:error] [pid 230252:tid 230500] [client 74.7.241.158:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.lp.mannucarvalho.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al9JM00Dwhk5-Z44XrpRhwAAAw0"], referer: https://www.lp.mannucarvalho.com/robots.txt
[Tue Jul 21 07:25:55.133403 2026] [security2:error] [pid 230252:tid 230400] [client 74.7.241.158:34626] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.lp.mannucarvalho.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al9JM00Dwhk5-Z44XrpRhQACqSo"], referer: https://www.lp.mannucarvalho.com/robots.txt
[Tue Jul 21 07:25:55.145440 2026] [security2:error] [pid 230252:tid 230449] [client 74.249.245.134:54356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/k.php"] [unique_id "al9JM00Dwhk5-Z44XrpRiQAAAto"]
[Tue Jul 21 07:25:55.358347 2026] [security2:error] [pid 230252:tid 230506] [client 20.226.60.151:54527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/cilus.php"] [unique_id "al9JM00Dwhk5-Z44XrpRjAAAAxM"]
[Tue Jul 21 07:25:55.581783 2026] [security2:error] [pid 230252:tid 230501] [client 20.151.10.161:63690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/file31.php"] [unique_id "al9JM00Dwhk5-Z44XrpRjwAAAw4"]
[Tue Jul 21 07:25:55.742767 2026] [security2:error] [pid 230252:tid 230467] [client 185.251.19.76:55043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9JM00Dwhk5-Z44XrpRlAAAAuw"]
[Tue Jul 21 07:25:55.938071 2026] [security2:error] [pid 230252:tid 230396] [client 20.52.136.55:1540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/bless.php"] [unique_id "al9JM00Dwhk5-Z44XrpRmgAAAqU"]
[Tue Jul 21 07:25:55.990498 2026] [security2:error] [pid 230252:tid 230455] [client 136.144.42.179:57497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.42.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9JM00Dwhk5-Z44XrpRnAAAAuA"]
[Tue Jul 21 07:25:56.088198 2026] [security2:error] [pid 230252:tid 230415] [client 20.226.60.151:56903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/als.php"] [unique_id "al9JNE0Dwhk5-Z44XrpRnQAAArg"]
[Tue Jul 21 07:25:56.093972 2026] [security2:error] [pid 230252:tid 230461] [client 74.249.245.134:17457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/vx.php"] [unique_id "al9JNE0Dwhk5-Z44XrpRngAAAuY"]
[Tue Jul 21 07:25:56.186538 2026] [security2:error] [pid 230252:tid 230325] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JNE0Dwhk5-Z44XrpRoAACy0Y"]
[Tue Jul 21 07:25:56.186666 2026] [security2:error] [pid 230252:tid 230434] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JNE0Dwhk5-Z44XrpRoAACy0Y"]
[Tue Jul 21 07:25:56.404669 2026] [security2:error] [pid 230252:tid 230406] [client 20.151.10.161:49051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/crgio.php"] [unique_id "al9JNE0Dwhk5-Z44XrpRowAAAq8"]
[Tue Jul 21 07:25:56.524214 2026] [security2:error] [pid 230252:tid 230363] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JNE0Dwhk5-Z44XrpRpAAC3Ww"]
[Tue Jul 21 07:25:56.524357 2026] [security2:error] [pid 230252:tid 230452] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JNE0Dwhk5-Z44XrpRpAAC3Ww"]
[Tue Jul 21 07:25:56.527937 2026] [security2:error] [pid 230252:tid 230411] [client 20.151.10.161:65449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/file6.php"] [unique_id "al9JNE0Dwhk5-Z44XrpRpQAAArQ"]
[Tue Jul 21 07:25:56.618851 2026] [security2:error] [pid 230252:tid 230386] [client 152.59.154.239:63856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JNE0Dwhk5-Z44XrpRpgAAAps"]
[Tue Jul 21 07:25:56.660785 2026] [security2:error] [pid 230252:tid 230426] [client 74.249.245.134:5562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/ws77.php"] [unique_id "al9JNE0Dwhk5-Z44XrpRqAAAAsM"]
[Tue Jul 21 07:25:57.175187 2026] [security2:error] [pid 230252:tid 230494] [client 20.151.10.161:65461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/file15.php"] [unique_id "al9JNU0Dwhk5-Z44XrpRrwAAAwc"]
[Tue Jul 21 07:25:57.283181 2026] [security2:error] [pid 230252:tid 230428] [client 59.96.220.140:60890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JNU0Dwhk5-Z44XrpRsAAAAsU"]
[Tue Jul 21 07:25:57.283864 2026] [security2:error] [pid 230252:tid 230428] [client 59.96.220.140:60890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JNU0Dwhk5-Z44XrpRsAAAAsU"]
[Tue Jul 21 07:25:57.632465 2026] [security2:error] [pid 230252:tid 230368] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JNU0Dwhk5-Z44XrpRsgACynE"]
[Tue Jul 21 07:25:57.632653 2026] [security2:error] [pid 230252:tid 230433] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JNU0Dwhk5-Z44XrpRsgACynE"]
[Tue Jul 21 07:25:57.680593 2026] [security2:error] [pid 230252:tid 230410] [client 20.151.10.161:63620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/jp.php"] [unique_id "al9JNU0Dwhk5-Z44XrpRtQAAArM"]
[Tue Jul 21 07:25:57.953044 2026] [security2:error] [pid 230252:tid 230409] [client 74.249.245.134:5540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/2.php"] [unique_id "al9JNU0Dwhk5-Z44XrpRugAAArI"]
[Tue Jul 21 07:25:58.200003 2026] [security2:error] [pid 230252:tid 230492] [client 103.106.20.201:62393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRvQAAAwU"]
[Tue Jul 21 07:25:58.200142 2026] [security2:error] [pid 230252:tid 230492] [client 103.106.20.201:62393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRvQAAAwU"]
[Tue Jul 21 07:25:58.401369 2026] [security2:error] [pid 230252:tid 230429] [client 20.151.10.161:49028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/pucci.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRwAAAAsY"]
[Tue Jul 21 07:25:58.530126 2026] [security2:error] [pid 230252:tid 230474] [client 20.151.10.161:63687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/f35.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRxAAAAvM"]
[Tue Jul 21 07:25:58.584315 2026] [security2:error] [pid 230252:tid 230493] [client 45.251.232.145:62883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRxQAAAwY"]
[Tue Jul 21 07:25:58.584452 2026] [security2:error] [pid 230252:tid 230493] [client 45.251.232.145:62883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRxQAAAwY"]
[Tue Jul 21 07:25:58.668260 2026] [security2:error] [pid 230252:tid 230502] [client 4.204.201.85:3220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRxgAAAw8"]
[Tue Jul 21 07:25:58.728019 2026] [security2:error] [pid 230252:tid 230495] [client 103.174.34.15:59280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRxwAAAwg"]
[Tue Jul 21 07:25:58.728132 2026] [security2:error] [pid 230252:tid 230495] [client 103.174.34.15:59280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRxwAAAwg"]
[Tue Jul 21 07:25:58.748033 2026] [security2:error] [pid 230252:tid 230453] [client 20.226.60.151:56942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/simple.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRyAAAAt4"]
[Tue Jul 21 07:25:58.802262 2026] [security2:error] [pid 230252:tid 230511] [client 109.248.148.246:48170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRyQAAAxg"]
[Tue Jul 21 07:25:58.802355 2026] [security2:error] [pid 230252:tid 230511] [client 109.248.148.246:48170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRyQAAAxg"]
[Tue Jul 21 07:25:59.013277 2026] [security2:error] [pid 230252:tid 230484] [client 20.151.10.161:65464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-load.php"] [unique_id "al9JN00Dwhk5-Z44XrpRzgAAAv0"]
[Tue Jul 21 07:25:59.065617 2026] [security2:error] [pid 230252:tid 230274] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JN00Dwhk5-Z44XrpRzwAC-BQ"]
[Tue Jul 21 07:25:59.065753 2026] [security2:error] [pid 230252:tid 230479] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JN00Dwhk5-Z44XrpRzwAC-BQ"]
[Tue Jul 21 07:25:59.294196 2026] [security2:error] [pid 230252:tid 230469] [client 4.204.201.85:3219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9JN00Dwhk5-Z44XrpR0QAAAu4"]
[Tue Jul 21 07:25:59.444876 2026] [security2:error] [pid 230252:tid 230422] [client 20.52.136.55:1586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/storage/index.php"] [unique_id "al9JN00Dwhk5-Z44XrpR1gAAAr8"]
[Tue Jul 21 07:25:59.467350 2026] [proxy:error] [pid 230252:tid 230500] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:59.467414 2026] [proxy_http:error] [pid 230252:tid 230500] [client 20.151.10.161:63046] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:59.467869 2026] [proxy:error] [pid 230252:tid 230500] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:59.467897 2026] [proxy_http:error] [pid 230252:tid 230500] [client 20.151.10.161:63046] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:59.696692 2026] [security2:error] [pid 230252:tid 230328] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JN00Dwhk5-Z44XrpR2wACoUk"]
[Tue Jul 21 07:25:59.696867 2026] [security2:error] [pid 230252:tid 230392] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JN00Dwhk5-Z44XrpR2wACoUk"]
[Tue Jul 21 07:25:59.873227 2026] [security2:error] [pid 230252:tid 230509] [client 175.45.70.82:49612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JN00Dwhk5-Z44XrpR3QAAAxY"]
[Tue Jul 21 07:25:59.873354 2026] [security2:error] [pid 230252:tid 230509] [client 175.45.70.82:49612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JN00Dwhk5-Z44XrpR3QAAAxY"]
[Tue Jul 21 07:25:59.963772 2026] [security2:error] [pid 230252:tid 230391] [client 4.204.201.85:3297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/media.php"] [unique_id "al9JN00Dwhk5-Z44XrpR3wAAAqA"]
[Tue Jul 21 07:26:00.052000 2026] [security2:error] [pid 230252:tid 230478] [client 31.57.219.92:26488] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "murilomattos.com"] [uri "/"] [unique_id "al9JOE0Dwhk5-Z44XrpR4QAAAvc"]
[Tue Jul 21 07:26:00.218952 2026] [proxy:error] [pid 229246:tid 229383] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:26:00.219028 2026] [proxy_http:error] [pid 229246:tid 229383] [client 20.151.10.161:65525] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:26:00.219484 2026] [proxy:error] [pid 229246:tid 229383] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:26:00.219507 2026] [proxy_http:error] [pid 229246:tid 229383] [client 20.151.10.161:65525] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:26:00.265247 2026] [security2:error] [pid 230252:tid 230443] [client 20.226.60.151:56834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/init.php"] [unique_id "al9JOE0Dwhk5-Z44XrpR5gAAAtQ"]
[Tue Jul 21 07:26:00.356944 2026] [security2:error] [pid 229246:tid 229439] [client 4.204.201.85:3240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/images.php"] [unique_id "al9JOCBMYeh5YLVG45x2uAAAAlM"]
[Tue Jul 21 07:26:00.452890 2026] [security2:error] [pid 230252:tid 230403] [client 83.97.118.16:12157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.118.97.83.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.tempex.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9JOE0Dwhk5-Z44XrpR6QAAAqw"], referer: https://www.tempex.com.br/contato/
[Tue Jul 21 07:26:00.472709 2026] [proxy:error] [pid 230252:tid 230511] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:26:00.472788 2026] [proxy_http:error] [pid 230252:tid 230511] [client 20.151.10.161:48582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:26:00.473390 2026] [proxy:error] [pid 230252:tid 230511] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:26:00.473418 2026] [proxy_http:error] [pid 230252:tid 230511] [client 20.151.10.161:48582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:26:00.657856 2026] [security2:error] [pid 230252:tid 230458] [client 4.204.201.85:3209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/gecko.php"] [unique_id "al9JOE0Dwhk5-Z44XrpR7wAAAuM"]
[Tue Jul 21 07:26:00.671569 2026] [security2:error] [pid 230252:tid 230504] [client 154.192.233.199:59564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JOE0Dwhk5-Z44XrpR8AAAAxE"]
[Tue Jul 21 07:26:00.671713 2026] [security2:error] [pid 230252:tid 230504] [client 154.192.233.199:59564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JOE0Dwhk5-Z44XrpR8AAAAxE"]
[Tue Jul 21 07:26:00.798796 2026] [security2:error] [pid 230252:tid 230487] [client 136.144.33.96:24489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRwwAAAwA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:00.950677 2026] [security2:error] [pid 229246:tid 229413] [client 4.204.201.85:3287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/82.php"] [unique_id "al9JOCBMYeh5YLVG45x2wAAAAjk"]
[Tue Jul 21 07:26:00.955117 2026] [security2:error] [pid 230252:tid 230444] [client 20.220.225.223:45377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/kua.php"] [unique_id "al9JOE0Dwhk5-Z44XrpR9AAAAtU"]
[Tue Jul 21 07:26:01.043645 2026] [security2:error] [pid 230252:tid 230402] [client 74.249.245.134:5545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/asd.php"] [unique_id "al9JOU0Dwhk5-Z44XrpR9gAAAqs"]
[Tue Jul 21 07:26:01.117779 2026] [security2:error] [pid 230252:tid 230468] [client 20.151.10.161:65494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9JOU0Dwhk5-Z44XrpR-QAAAu0"]
[Tue Jul 21 07:26:01.260156 2026] [security2:error] [pid 229246:tid 229414] [client 82.102.28.107:33788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9JOSBMYeh5YLVG45x2xQAAAjo"]
[Tue Jul 21 07:26:01.260257 2026] [security2:error] [pid 229246:tid 229414] [client 82.102.28.107:33788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9JOSBMYeh5YLVG45x2xQAAAjo"]
[Tue Jul 21 07:26:01.334343 2026] [security2:error] [pid 229246:tid 229473] [client 4.204.201.85:3218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/admin.php"] [unique_id "al9JOSBMYeh5YLVG45x2xwAAAnU"]
[Tue Jul 21 07:26:01.551901 2026] [security2:error] [pid 230252:tid 230476] [client 20.226.60.151:56899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/fpwch.php"] [unique_id "al9JOU0Dwhk5-Z44XrpR-wAAAvU"]
[Tue Jul 21 07:26:01.554268 2026] [security2:error] [pid 230252:tid 230290] [remote 152.42.185.27:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.185.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JOU0Dwhk5-Z44XrpR-gACxSQ"], referer: https://covumc.com//wp-login.php
[Tue Jul 21 07:26:01.778749 2026] [security2:error] [pid 230252:tid 230506] [client 20.151.10.161:65510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-links.php"] [unique_id "al9JOU0Dwhk5-Z44XrpR_wAAAxM"]
[Tue Jul 21 07:26:01.794146 2026] [security2:error] [pid 230252:tid 230485] [client 4.204.201.85:3282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/adminner.php"] [unique_id "al9JOU0Dwhk5-Z44XrpSAAAAAv4"]
[Tue Jul 21 07:26:01.894749 2026] [security2:error] [pid 229246:tid 229476] [client 20.226.60.151:54578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/gptsh.php"] [unique_id "al9JOSBMYeh5YLVG45x2ywAAAng"]
[Tue Jul 21 07:26:02.030940 2026] [proxy:error] [pid 229246:tid 229493] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:26:02.031022 2026] [proxy_http:error] [pid 229246:tid 229493] [client 20.151.10.161:49089] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:26:02.031982 2026] [proxy:error] [pid 229246:tid 229493] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:26:02.032020 2026] [proxy_http:error] [pid 229246:tid 229493] [client 20.151.10.161:49089] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:26:02.354292 2026] [security2:error] [pid 230252:tid 230429] [client 4.204.201.85:26600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/admin.php"] [unique_id "al9JOk0Dwhk5-Z44XrpSBwAAAsY"]
[Tue Jul 21 07:26:02.438119 2026] [security2:error] [pid 230252:tid 230271] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JOk0Dwhk5-Z44XrpSCAACvRE"]
[Tue Jul 21 07:26:02.438252 2026] [security2:error] [pid 230252:tid 230420] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JOk0Dwhk5-Z44XrpSCAACvRE"]
[Tue Jul 21 07:26:02.443164 2026] [security2:error] [pid 230252:tid 230435] [client 82.102.28.107:54538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9JOk0Dwhk5-Z44XrpSCQAAAsw"]
[Tue Jul 21 07:26:02.443248 2026] [security2:error] [pid 230252:tid 230435] [client 82.102.28.107:54538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9JOk0Dwhk5-Z44XrpSCQAAAsw"]
[Tue Jul 21 07:26:02.515553 2026] [security2:error] [pid 230252:tid 230417] [client 20.226.60.151:56866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/domvf.php"] [unique_id "al9JOk0Dwhk5-Z44XrpSCwAAAro"]
[Tue Jul 21 07:26:02.748873 2026] [security2:error] [pid 230252:tid 230488] [client 4.204.201.85:3200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/k.php"] [unique_id "al9JOk0Dwhk5-Z44XrpSDgAAAwE"]
[Tue Jul 21 07:26:02.855506 2026] [security2:error] [pid 230252:tid 230496] [client 20.151.10.161:63680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/solo1.php"] [unique_id "al9JOk0Dwhk5-Z44XrpSEAAAAwk"]
[Tue Jul 21 07:26:03.102942 2026] [security2:error] [pid 230252:tid 230388] [client 4.204.201.85:3204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/blurbs.php"] [unique_id "al9JO00Dwhk5-Z44XrpSEgAAAp0"]
[Tue Jul 21 07:26:03.320545 2026] [security2:error] [pid 230252:tid 230311] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JO00Dwhk5-Z44XrpSFgACsDk"]
[Tue Jul 21 07:26:03.320684 2026] [security2:error] [pid 230252:tid 230407] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JO00Dwhk5-Z44XrpSFgACsDk"]
[Tue Jul 21 07:26:03.475528 2026] [security2:error] [pid 230252:tid 230422] [client 4.204.201.85:3273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/bajah.php"] [unique_id "al9JO00Dwhk5-Z44XrpSGAAAAr8"]
[Tue Jul 21 07:26:03.760633 2026] [security2:error] [pid 230252:tid 230477] [client 20.151.10.161:49082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-temp.php"] [unique_id "al9JO00Dwhk5-Z44XrpSHwAAAvY"]
[Tue Jul 21 07:26:04.010003 2026] [security2:error] [pid 230252:tid 230402] [client 103.162.129.114:58737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JPE0Dwhk5-Z44XrpSJQAAAqs"]
[Tue Jul 21 07:26:04.010127 2026] [security2:error] [pid 230252:tid 230402] [client 103.162.129.114:58737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JPE0Dwhk5-Z44XrpSJQAAAqs"]
[Tue Jul 21 07:26:04.183430 2026] [security2:error] [pid 229246:tid 229497] [client 4.204.201.85:3231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/a.php"] [unique_id "al9JPCBMYeh5YLVG45x23gAAAo0"]
[Tue Jul 21 07:26:04.189343 2026] [security2:error] [pid 230252:tid 230494] [client 139.135.44.145:54167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JPE0Dwhk5-Z44XrpSKwAAAwc"]
[Tue Jul 21 07:26:04.189433 2026] [security2:error] [pid 230252:tid 230494] [client 139.135.44.145:54167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JPE0Dwhk5-Z44XrpSKwAAAwc"]
[Tue Jul 21 07:26:04.283186 2026] [security2:error] [pid 229246:tid 229258] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "panel.gradiente.com"] [uri "/.git/config"] [unique_id "al9JPCBMYeh5YLVG45x25wACfAs"]
[Tue Jul 21 07:26:04.284580 2026] [security2:error] [pid 229246:tid 229369] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/rclone.conf"] [unique_id "al9JPCBMYeh5YLVG45x26AACfHo"]
[Tue Jul 21 07:26:04.285543 2026] [security2:error] [pid 229246:tid 229323] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/.aws/credentials"] [unique_id "al9JPCBMYeh5YLVG45x26gACfEw"]
[Tue Jul 21 07:26:04.285579 2026] [security2:error] [pid 229246:tid 229275] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/z9x8c7v6b5-debug-trigger-panel.gradiente.com"] [unique_id "al9JPCBMYeh5YLVG45x27AACfBw"]
[Tue Jul 21 07:26:04.296679 2026] [security2:error] [pid 230252:tid 230401] [client 74.249.245.134:5564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/default.php"] [unique_id "al9JPE0Dwhk5-Z44XrpSLwAAAqo"]
[Tue Jul 21 07:26:04.381270 2026] [security2:error] [pid 230252:tid 230436] [client 20.151.10.161:65443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/sixxis.php"] [unique_id "al9JPE0Dwhk5-Z44XrpSMQAAAs0"]
[Tue Jul 21 07:26:04.478265 2026] [security2:error] [pid 229246:tid 229391] [client 20.226.60.151:62377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp.php"] [unique_id "al9JPCBMYeh5YLVG45x27gAAAiM"]
[Tue Jul 21 07:26:04.495881 2026] [security2:error] [pid 229246:tid 229475] [client 4.204.201.85:3291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/edit.php"] [unique_id "al9JPCBMYeh5YLVG45x27wAAAnc"]
[Tue Jul 21 07:26:04.626912 2026] [security2:error] [pid 229246:tid 229331] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "panel.gradiente.com"] [uri "/graphql"] [unique_id "al9JPCBMYeh5YLVG45x28gACfFQ"]
[Tue Jul 21 07:26:04.662818 2026] [security2:error] [pid 229246:tid 229272] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/.gitconfig"] [unique_id "al9JPCBMYeh5YLVG45x29gACfBk"]
[Tue Jul 21 07:26:04.801088 2026] [security2:error] [pid 230252:tid 230415] [client 4.204.201.85:3203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/hosty.php"] [unique_id "al9JPE0Dwhk5-Z44XrpSNgAAArg"]
[Tue Jul 21 07:26:04.820801 2026] [security2:error] [pid 230252:tid 230327] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JPE0Dwhk5-Z44XrpSNwAC1Eg"]
[Tue Jul 21 07:26:04.820921 2026] [security2:error] [pid 230252:tid 230443] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JPE0Dwhk5-Z44XrpSNwAC1Eg"]
[Tue Jul 21 07:26:04.969484 2026] [security2:error] [pid 229246:tid 229336] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "panel.gradiente.com"] [uri "/api/graphql"] [unique_id "al9JPCBMYeh5YLVG45x2-wACfFk"]
[Tue Jul 21 07:26:04.991935 2026] [security2:error] [pid 229246:tid 229263] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/.env"] [unique_id "al9JPCBMYeh5YLVG45x2_QACfBA"]
[Tue Jul 21 07:26:04.992065 2026] [security2:error] [pid 229246:tid 229480] [client 34.35.143.238:47690] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/.env"] [unique_id "al9JPCBMYeh5YLVG45x2_QACfBA"]
[Tue Jul 21 07:26:05.059075 2026] [security2:error] [pid 229246:tid 229337] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/.env.example"] [unique_id "al9JPSBMYeh5YLVG45x3AQACfFo"]
[Tue Jul 21 07:26:05.180091 2026] [security2:error] [pid 230252:tid 230461] [client 4.204.201.85:3308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/k.php"] [unique_id "al9JPU0Dwhk5-Z44XrpSOQAAAuY"]
[Tue Jul 21 07:26:05.217545 2026] [security2:error] [pid 230252:tid 230488] [client 20.220.225.223:38698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9JPU0Dwhk5-Z44XrpSOgAAAwE"]
[Tue Jul 21 07:26:05.238416 2026] [security2:error] [pid 230252:tid 230394] [client 172.245.102.41:27749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JPU0Dwhk5-Z44XrpSOwAAAqM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:05.321205 2026] [security2:error] [pid 229246:tid 229316] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "panel.gradiente.com"] [uri "/v1/graphql"] [unique_id "al9JPSBMYeh5YLVG45x3BAACfEU"]
[Tue Jul 21 07:26:05.494682 2026] [security2:error] [pid 229246:tid 229366] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.env.bak"] [unique_id "al9JPSBMYeh5YLVG45x3CwACfHc"]
[Tue Jul 21 07:26:05.494699 2026] [security2:error] [pid 229246:tid 229260] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.env.backup"] [unique_id "al9JPSBMYeh5YLVG45x3DAACfA0"]
[Tue Jul 21 07:26:05.552287 2026] [security2:error] [pid 230252:tid 230411] [client 4.204.201.85:3216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/aaa.php"] [unique_id "al9JPU0Dwhk5-Z44XrpSPgAAArQ"]
[Tue Jul 21 07:26:05.802929 2026] [security2:error] [pid 230252:tid 230482] [client 74.249.245.134:54343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/gettest.php"] [unique_id "al9JPU0Dwhk5-Z44XrpSQAAAAvs"]
[Tue Jul 21 07:26:05.809947 2026] [security2:error] [pid 229246:tid 229348] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.env.old"] [unique_id "al9JPSBMYeh5YLVG45x3FAACXWU"]
[Tue Jul 21 07:26:05.860649 2026] [security2:error] [pid 230252:tid 230453] [client 117.251.86.144:44606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JPU0Dwhk5-Z44XrpSQwAAAt4"]
[Tue Jul 21 07:26:05.860744 2026] [security2:error] [pid 230252:tid 230453] [client 117.251.86.144:44606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JPU0Dwhk5-Z44XrpSQwAAAt4"]
[Tue Jul 21 07:26:05.873458 2026] [security2:error] [pid 229246:tid 229330] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/api/.env"] [unique_id "al9JPSBMYeh5YLVG45x3GQACKFM"]
[Tue Jul 21 07:26:06.156633 2026] [security2:error] [pid 229246:tid 229352] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/config/.env"] [unique_id "al9JPiBMYeh5YLVG45x3HgACG2k"]
[Tue Jul 21 07:26:06.157537 2026] [security2:error] [pid 229246:tid 229360] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/backend/.env"] [unique_id "al9JPiBMYeh5YLVG45x3HwACG3E"]
[Tue Jul 21 07:26:06.163843 2026] [security2:error] [pid 230252:tid 230408] [client 20.226.60.151:56895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/class.php"] [unique_id "al9JPk0Dwhk5-Z44XrpSRwAAArE"]
[Tue Jul 21 07:26:06.174001 2026] [security2:error] [pid 229246:tid 229324] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/serviceAccountKey.json"] [unique_id "al9JPiBMYeh5YLVG45x3JAACSE0"]
[Tue Jul 21 07:26:06.449361 2026] [security2:error] [pid 229246:tid 229426] [client 4.204.201.85:3263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/file5.php"] [unique_id "al9JPiBMYeh5YLVG45x3LAAAAkY"]
[Tue Jul 21 07:26:06.599960 2026] [authz_core:error] [pid 229246:tid 229358] [remote 34.35.143.238:47690] AH01630: client denied by server configuration: /var/www/html/.htpasswd
[Tue Jul 21 07:26:06.647537 2026] [security2:error] [pid 229246:tid 229270] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JPiBMYeh5YLVG45x3OgACHhc"]
[Tue Jul 21 07:26:06.647633 2026] [security2:error] [pid 229246:tid 229386] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JPiBMYeh5YLVG45x3OgACHhc"]
[Tue Jul 21 07:26:06.958297 2026] [security2:error] [pid 229246:tid 229294] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/.ssh/id_ed25519"] [unique_id "al9JPiBMYeh5YLVG45x3QQACfi8"]
[Tue Jul 21 07:26:06.958535 2026] [security2:error] [pid 229246:tid 229482] [client 34.35.143.238:47690] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/.ssh/id_ed25519"] [unique_id "al9JPiBMYeh5YLVG45x3QQACfi8"]
[Tue Jul 21 07:26:06.993351 2026] [security2:error] [pid 229246:tid 229267] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.ssh/id_rsa"] [unique_id "al9JPiBMYeh5YLVG45x3RAACdRQ"]
[Tue Jul 21 07:26:06.993515 2026] [security2:error] [pid 229246:tid 229339] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/docker-compose.yaml"] [unique_id "al9JPiBMYeh5YLVG45x3RQACdVw"]
[Tue Jul 21 07:26:07.002680 2026] [security2:error] [pid 229246:tid 229357] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.ssh/id_dsa"] [unique_id "al9JPyBMYeh5YLVG45x3RgACdW4"]
[Tue Jul 21 07:26:07.064564 2026] [security2:error] [pid 229246:tid 229450] [client 4.204.201.85:3293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/222.php"] [unique_id "al9JPyBMYeh5YLVG45x3SgAAAl4"]
[Tue Jul 21 07:26:07.294899 2026] [proxy:error] [pid 229246:tid 229447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:26:07.294976 2026] [proxy_http:error] [pid 229246:tid 229447] [client 20.151.10.161:49067] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:26:07.295453 2026] [proxy:error] [pid 229246:tid 229447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:26:07.295488 2026] [proxy_http:error] [pid 229246:tid 229447] [client 20.151.10.161:49067] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:26:07.295830 2026] [security2:error] [pid 229246:tid 229462] [client 20.226.60.151:54568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/rithin.php"] [unique_id "al9JPyBMYeh5YLVG45x3UQAAAmo"]
[Tue Jul 21 07:26:07.366638 2026] [security2:error] [pid 229246:tid 229281] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/id_ecdsa"] [unique_id "al9JPyBMYeh5YLVG45x3VwACHyI"]
[Tue Jul 21 07:26:07.376023 2026] [security2:error] [pid 229246:tid 229295] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/id_rsa"] [unique_id "al9JPyBMYeh5YLVG45x3WQACjzA"]
[Tue Jul 21 07:26:07.417175 2026] [security2:error] [pid 229246:tid 229315] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/id_dsa"] [unique_id "al9JPyBMYeh5YLVG45x3XAACb0Q"]
[Tue Jul 21 07:26:07.417316 2026] [security2:error] [pid 229246:tid 229254] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/key.pem"] [unique_id "al9JPyBMYeh5YLVG45x3XQACbwc"]
[Tue Jul 21 07:26:07.455150 2026] [security2:error] [pid 230252:tid 230286] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JP00Dwhk5-Z44XrpSTAAC2iA"]
[Tue Jul 21 07:26:07.455257 2026] [security2:error] [pid 230252:tid 230449] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JP00Dwhk5-Z44XrpSTAAC2iA"]
[Tue Jul 21 07:26:07.621910 2026] [security2:error] [pid 229246:tid 229400] [client 4.204.201.85:3278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/test.php"] [unique_id "al9JPyBMYeh5YLVG45x3YgAAAiw"]
[Tue Jul 21 07:26:07.658451 2026] [security2:error] [pid 229246:tid 229367] [remote 38.242.157.30:56412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9JPyBMYeh5YLVG45x3ZAACKXg"]
[Tue Jul 21 07:26:07.760933 2026] [security2:error] [pid 229246:tid 229345] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/privatekey.key"] [unique_id "al9JPyBMYeh5YLVG45x3aAACgGI"]
[Tue Jul 21 07:26:07.790823 2026] [security2:error] [pid 229246:tid 229369] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/ssl/server.key"] [unique_id "al9JPyBMYeh5YLVG45x3bAACUno"]
[Tue Jul 21 07:26:07.790958 2026] [security2:error] [pid 229246:tid 229438] [client 34.35.143.238:47690] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/ssl/server.key"] [unique_id "al9JPyBMYeh5YLVG45x3bAACUno"]
[Tue Jul 21 07:26:07.791315 2026] [security2:error] [pid 229246:tid 229323] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/ssl/localhost.key"] [unique_id "al9JPyBMYeh5YLVG45x3bQACUkw"]
[Tue Jul 21 07:26:07.809847 2026] [security2:error] [pid 229246:tid 229418] [client 20.220.225.223:38703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9JPyBMYeh5YLVG45x3cAAAAj4"]
[Tue Jul 21 07:26:07.830397 2026] [security2:error] [pid 229246:tid 229308] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/.openclaw/.env"] [unique_id "al9JPyBMYeh5YLVG45x3cQACPT0"]
[Tue Jul 21 07:26:07.830533 2026] [security2:error] [pid 229246:tid 229417] [client 34.35.143.238:47690] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/.openclaw/.env"] [unique_id "al9JPyBMYeh5YLVG45x3cQACPT0"]
[Tue Jul 21 07:26:07.941992 2026] [security2:error] [pid 229246:tid 229476] [client 59.96.220.140:61318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JPyBMYeh5YLVG45x3dgAAAng"]
[Tue Jul 21 07:26:07.942124 2026] [security2:error] [pid 229246:tid 229476] [client 59.96.220.140:61318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JPyBMYeh5YLVG45x3dgAAAng"]
[Tue Jul 21 07:26:08.004779 2026] [security2:error] [pid 229246:tid 229481] [client 4.204.201.85:3267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/aaa.php"] [unique_id "al9JQCBMYeh5YLVG45x3egAAAn0"]
[Tue Jul 21 07:26:08.083922 2026] [security2:error] [pid 229246:tid 229503] [client 20.151.10.161:65444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/2P.update.php"] [unique_id "al9JQCBMYeh5YLVG45x3fQAAApM"]
[Tue Jul 21 07:26:08.132208 2026] [security2:error] [pid 230252:tid 230323] [remote 188.164.197.230:53424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/wp-login.php"] [unique_id "al9JQE0Dwhk5-Z44XrpSUQAC2EU"]
[Tue Jul 21 07:26:08.181402 2026] [security2:error] [pid 229246:tid 229458] [client 20.226.60.151:56921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/echkm.php"] [unique_id "al9JQCBMYeh5YLVG45x3gAAAAmY"]
[Tue Jul 21 07:26:08.200087 2026] [security2:error] [pid 230252:tid 230304] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JQE0Dwhk5-Z44XrpSUgADEjI"]
[Tue Jul 21 07:26:08.200241 2026] [security2:error] [pid 230252:tid 230505] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JQE0Dwhk5-Z44XrpSUgADEjI"]
[Tue Jul 21 07:26:08.208805 2026] [security2:error] [pid 229246:tid 229455] [client 74.249.245.134:5536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/tfm.php"] [unique_id "al9JQCBMYeh5YLVG45x3gQAAAmM"]
[Tue Jul 21 07:26:08.335417 2026] [security2:error] [pid 229246:tid 229399] [client 4.204.201.85:3321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/11.php"] [unique_id "al9JQCBMYeh5YLVG45x3ggAAAis"]
[Tue Jul 21 07:26:08.433083 2026] [security2:error] [pid 229246:tid 229337] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.hermes/.env"] [unique_id "al9JQCBMYeh5YLVG45x3jQACZFo"]
[Tue Jul 21 07:26:08.778866 2026] [security2:error] [pid 229246:tid 229478] [client 152.59.154.239:64321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JQCBMYeh5YLVG45x3lAAAAno"]
[Tue Jul 21 07:26:08.782940 2026] [security2:error] [pid 229246:tid 229321] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/.claude/settings.json"] [unique_id "al9JQCBMYeh5YLVG45x3mQACfko"]
[Tue Jul 21 07:26:08.803732 2026] [security2:error] [pid 229246:tid 229407] [client 4.204.201.85:3221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/mac.php"] [unique_id "al9JQCBMYeh5YLVG45x3nAAAAjM"]
[Tue Jul 21 07:26:08.985646 2026] [security2:error] [pid 230252:tid 230437] [client 103.106.20.201:62962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JQE0Dwhk5-Z44XrpSVgAAAs4"]
[Tue Jul 21 07:26:08.985769 2026] [security2:error] [pid 230252:tid 230437] [client 103.106.20.201:62962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JQE0Dwhk5-Z44XrpSVgAAAs4"]
[Tue Jul 21 07:26:09.073579 2026] [security2:error] [pid 229246:tid 229376] [client 45.251.232.145:63399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JQSBMYeh5YLVG45x3pQAAAhQ"]
[Tue Jul 21 07:26:09.074183 2026] [security2:error] [pid 229246:tid 229376] [client 45.251.232.145:63399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JQSBMYeh5YLVG45x3pQAAAhQ"]
[Tue Jul 21 07:26:09.153255 2026] [security2:error] [pid 229246:tid 229250] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "panel.gradiente.com"] [uri "/wp-config.php.old"] [unique_id "al9JQSBMYeh5YLVG45x3qQACcgM"]
[Tue Jul 21 07:26:09.177895 2026] [security2:error] [pid 229246:tid 229374] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "panel.gradiente.com"] [uri "/wp-config.php.bak"] [unique_id "al9JQSBMYeh5YLVG45x3qwACMn8"]
[Tue Jul 21 07:26:09.187602 2026] [security2:error] [pid 229246:tid 229330] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "panel.gradiente.com"] [uri "/laravel/.env"] [unique_id "al9JQSBMYeh5YLVG45x3rgACMlM"]
[Tue Jul 21 07:26:09.214830 2026] [security2:error] [pid 229246:tid 229499] [client 4.204.201.85:3301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/chosen.php"] [unique_id "al9JQSBMYeh5YLVG45x3rwAAAo8"]
[Tue Jul 21 07:26:09.256692 2026] [security2:error] [pid 229246:tid 229264] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/.env.php.bak"] [unique_id "al9JQSBMYeh5YLVG45x3sQACQRE"]
[Tue Jul 21 07:26:09.258193 2026] [security2:error] [pid 229246:tid 229352] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/core/.env"] [unique_id "al9JQSBMYeh5YLVG45x3sgACQWk"]
[Tue Jul 21 07:26:09.260447 2026] [security2:error] [pid 229246:tid 229360] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/config/.env.php"] [unique_id "al9JQSBMYeh5YLVG45x3swACQXE"]
[Tue Jul 21 07:26:09.527134 2026] [security2:error] [pid 230252:tid 230420] [client 103.174.34.15:59756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JQU0Dwhk5-Z44XrpSWAAAAr0"]
[Tue Jul 21 07:26:09.527276 2026] [security2:error] [pid 230252:tid 230420] [client 103.174.34.15:59756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JQU0Dwhk5-Z44XrpSWAAAAr0"]
[Tue Jul 21 07:26:09.531736 2026] [security2:error] [pid 229246:tid 229256] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/auth.json"] [unique_id "al9JQSBMYeh5YLVG45x3uAACKQk"]
[Tue Jul 21 07:26:09.547914 2026] [security2:error] [pid 229246:tid 229310] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/config.php.bak"] [unique_id "al9JQSBMYeh5YLVG45x3uQACbD8"]
[Tue Jul 21 07:26:09.547929 2026] [security2:error] [pid 229246:tid 229299] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/configuration.php.bak"] [unique_id "al9JQSBMYeh5YLVG45x3ugACbDQ"]
[Tue Jul 21 07:26:09.556713 2026] [security2:error] [pid 229246:tid 229328] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/.env.swp"] [unique_id "al9JQSBMYeh5YLVG45x3vgACbFE"]
[Tue Jul 21 07:26:09.602487 2026] [security2:error] [pid 229246:tid 229314] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/web/.env"] [unique_id "al9JQSBMYeh5YLVG45x3vwACGEM"]
[Tue Jul 21 07:26:09.628562 2026] [security2:error] [pid 229246:tid 229284] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/public/.env"] [unique_id "al9JQSBMYeh5YLVG45x3wAACcSU"]
[Tue Jul 21 07:26:09.816178 2026] [security2:error] [pid 230252:tid 230467] [client 4.204.201.85:3212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/cream1.php"] [unique_id "al9JQU0Dwhk5-Z44XrpSWQAAAuw"]
[Tue Jul 21 07:26:09.845314 2026] [security2:error] [pid 229246:tid 229277] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JQSBMYeh5YLVG45x3xgACWR4"]
[Tue Jul 21 07:26:09.845443 2026] [security2:error] [pid 229246:tid 229445] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JQSBMYeh5YLVG45x3xgACWR4"]
[Tue Jul 21 07:26:09.904074 2026] [security2:error] [pid 229246:tid 229465] [client 20.52.136.55:1568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/g.php"] [unique_id "al9JQSBMYeh5YLVG45x3yAAAAm0"]
[Tue Jul 21 07:26:09.943619 2026] [security2:error] [pid 229246:tid 229485] [client 20.226.60.151:63355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/lib.php"] [unique_id "al9JQSBMYeh5YLVG45x3ywAAAoE"]
[Tue Jul 21 07:26:10.113591 2026] [security2:error] [pid 229246:tid 229294] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/bootstrap.yml"] [unique_id "al9JQiBMYeh5YLVG45x31AACUi8"]
[Tue Jul 21 07:26:10.197012 2026] [security2:error] [pid 229246:tid 229267] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/appsettings.json"] [unique_id "al9JQiBMYeh5YLVG45x31wACPRQ"]
[Tue Jul 21 07:26:10.270123 2026] [security2:error] [pid 229246:tid 229339] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JQiBMYeh5YLVG45x32AACglw"]
[Tue Jul 21 07:26:10.270298 2026] [security2:error] [pid 229246:tid 229486] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JQiBMYeh5YLVG45x32AACglw"]
[Tue Jul 21 07:26:10.425223 2026] [security2:error] [pid 230252:tid 230494] [client 193.36.225.73:53133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JQk0Dwhk5-Z44XrpSWwAAAwc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:10.427730 2026] [security2:error] [pid 229246:tid 229425] [client 47.128.20.204:32092] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.somoszeroum.com.br"] [uri "/robots.txt"] [unique_id "al9JQiBMYeh5YLVG45x33QAAAkU"]
[Tue Jul 21 07:26:10.439343 2026] [security2:error] [pid 229246:tid 229319] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/appsettings.Production.json"] [unique_id "al9JQiBMYeh5YLVG45x33gACkUg"]
[Tue Jul 21 07:26:10.439473 2026] [security2:error] [pid 229246:tid 229501] [client 34.35.143.238:47690] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/appsettings.Production.json"] [unique_id "al9JQiBMYeh5YLVG45x33gACkUg"]
[Tue Jul 21 07:26:10.451440 2026] [security2:error] [pid 229246:tid 229305] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/web.config"] [unique_id "al9JQiBMYeh5YLVG45x34QACfTo"]
[Tue Jul 21 07:26:10.515681 2026] [security2:error] [pid 230252:tid 230499] [client 175.45.70.82:50161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JQk0Dwhk5-Z44XrpSXAAAAww"]
[Tue Jul 21 07:26:10.515827 2026] [security2:error] [pid 230252:tid 230499] [client 175.45.70.82:50161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JQk0Dwhk5-Z44XrpSXAAAAww"]
[Tue Jul 21 07:26:10.890929 2026] [security2:error] [pid 229246:tid 229312] [remote 217.181.92.4:29811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.92.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9JQSBMYeh5YLVG45x3xwACVUE"]
[Tue Jul 21 07:26:11.326862 2026] [security2:error] [pid 229246:tid 229276] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/src/.env"] [unique_id "al9JQyBMYeh5YLVG45x4BQACdR0"]
[Tue Jul 21 07:26:11.327085 2026] [security2:error] [pid 229246:tid 229473] [client 34.35.143.238:47690] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/src/.env"] [unique_id "al9JQyBMYeh5YLVG45x4BQACdR0"]
[Tue Jul 21 07:26:11.341607 2026] [security2:error] [pid 229246:tid 229369] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/frontend/.env"] [unique_id "al9JQyBMYeh5YLVG45x4CQAChXo"]
[Tue Jul 21 07:26:11.361017 2026] [security2:error] [pid 229246:tid 229426] [client 154.192.233.199:58654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JQyBMYeh5YLVG45x4EAAAAkY"]
[Tue Jul 21 07:26:11.361128 2026] [security2:error] [pid 229246:tid 229426] [client 154.192.233.199:58654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JQyBMYeh5YLVG45x4EAAAAkY"]
[Tue Jul 21 07:26:11.368032 2026] [security2:error] [pid 229246:tid 229331] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/app/.env"] [unique_id "al9JQyBMYeh5YLVG45x4EQACXlQ"]
[Tue Jul 21 07:26:11.394656 2026] [security2:error] [pid 229246:tid 229448] [client 4.204.201.85:26574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/dr.php"] [unique_id "al9JQyBMYeh5YLVG45x4EgAAAlw"]
[Tue Jul 21 07:26:11.437306 2026] [security2:error] [pid 229246:tid 229451] [client 20.226.60.151:54542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/fffm.php"] [unique_id "al9JQyBMYeh5YLVG45x4FAAAAl8"]
[Tue Jul 21 07:26:11.629976 2026] [security2:error] [pid 229246:tid 229406] [client 20.52.136.55:1734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/nf.php"] [unique_id "al9JQyBMYeh5YLVG45x4GgAAAjI"]
[Tue Jul 21 07:26:11.722820 2026] [security2:error] [pid 229246:tid 229282] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/@fs/root/.env"] [unique_id "al9JQyBMYeh5YLVG45x4IAACTiM"]
[Tue Jul 21 07:26:11.722876 2026] [security2:error] [pid 229246:tid 229293] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/staging/.env"] [unique_id "al9JQyBMYeh5YLVG45x4HwACTi4"]
[Tue Jul 21 07:26:11.722948 2026] [security2:error] [pid 229246:tid 229336] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/production/.env"] [unique_id "al9JQyBMYeh5YLVG45x4HQACTlk"]
[Tue Jul 21 07:26:11.723027 2026] [security2:error] [pid 229246:tid 229263] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/@fs/.env"] [unique_id "al9JQyBMYeh5YLVG45x4IwACThA"]
[Tue Jul 21 07:26:11.723079 2026] [security2:error] [pid 229246:tid 229365] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/server/.env"] [unique_id "al9JQyBMYeh5YLVG45x4JAACTnY"]
[Tue Jul 21 07:26:11.723303 2026] [security2:error] [pid 229246:tid 229334] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.env.production.bak"] [unique_id "al9JQyBMYeh5YLVG45x4HgACTlc"]
[Tue Jul 21 07:26:11.723309 2026] [security2:error] [pid 229246:tid 229337] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.env.prod.bak"] [unique_id "al9JQyBMYeh5YLVG45x4IQACTlo"]
[Tue Jul 21 07:26:11.723704 2026] [security2:error] [pid 229246:tid 229353] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/docker/.env"] [unique_id "al9JQyBMYeh5YLVG45x4IgACTmo"]
[Tue Jul 21 07:26:11.724415 2026] [security2:error] [pid 229246:tid 229343] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/dev/.env"] [unique_id "al9JQyBMYeh5YLVG45x4JgACTmA"]
[Tue Jul 21 07:26:11.724918 2026] [security2:error] [pid 229246:tid 229317] [remote 34.35.143.238:47690] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "panel.gradiente.com"] [uri "/@fs/proc/self/environ"] [unique_id "al9JQyBMYeh5YLVG45x4JwACTkY"]
[Tue Jul 21 07:26:11.772542 2026] [security2:error] [pid 229246:tid 229409] [client 20.220.225.223:46135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/ez.php"] [unique_id "al9JQyBMYeh5YLVG45x4KAAAAjU"]
[Tue Jul 21 07:26:11.789000 2026] [security2:error] [pid 230252:tid 230500] [client 20.151.10.161:49065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9JQ00Dwhk5-Z44XrpSagAAAw0"]
[Tue Jul 21 07:26:11.867868 2026] [security2:error] [pid 229246:tid 229431] [client 4.204.201.85:3225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/x.php"] [unique_id "al9JQyBMYeh5YLVG45x4KgAAAks"]
[Tue Jul 21 07:26:11.875587 2026] [security2:error] [pid 230252:tid 230487] [client 216.73.160.34:31409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9JQ00Dwhk5-Z44XrpSbAAAAwA"]
[Tue Jul 21 07:26:11.881105 2026] [security2:error] [pid 230252:tid 230407] [client 216.73.160.177:31653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9JQ00Dwhk5-Z44XrpSawAAArA"]
[Tue Jul 21 07:26:11.883546 2026] [security2:error] [pid 230252:tid 230425] [client 216.73.160.43:50327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9JQ00Dwhk5-Z44XrpSbgAAAsI"]
[Tue Jul 21 07:26:12.127714 2026] [security2:error] [pid 230252:tid 230404] [client 20.226.60.151:56836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/login.php"] [unique_id "al9JRE0Dwhk5-Z44XrpScgAAAq0"]
[Tue Jul 21 07:26:12.422199 2026] [security2:error] [pid 230252:tid 230409] [client 4.204.201.85:3307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/155.php"] [unique_id "al9JRE0Dwhk5-Z44XrpSdQAAArI"]
[Tue Jul 21 07:26:12.441048 2026] [security2:error] [pid 230252:tid 230447] [client 74.249.245.134:54372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/ws81.php"] [unique_id "al9JRE0Dwhk5-Z44XrpSdgAAAtg"]
[Tue Jul 21 07:26:12.683028 2026] [security2:error] [pid 229246:tid 229442] [client 20.220.225.223:46142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/fz.php"] [unique_id "al9JRCBMYeh5YLVG45x4MgAAAlY"]
[Tue Jul 21 07:26:12.777128 2026] [security2:error] [pid 230252:tid 230429] [client 4.204.201.85:3288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/ops.php"] [unique_id "al9JRE0Dwhk5-Z44XrpSeAAAAsY"]
[Tue Jul 21 07:26:12.927980 2026] [security2:error] [pid 230252:tid 230262] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JRE0Dwhk5-Z44XrpSewACqgg"]
[Tue Jul 21 07:26:12.928168 2026] [security2:error] [pid 230252:tid 230401] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JRE0Dwhk5-Z44XrpSewACqgg"]
[Tue Jul 21 07:26:12.985611 2026] [security2:error] [pid 230252:tid 230256] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/values.yaml"] [unique_id "al9JRE0Dwhk5-Z44XrpSfAACogI"]
[Tue Jul 21 07:26:12.985897 2026] [security2:error] [pid 230252:tid 230393] [client 34.35.143.238:47704] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/values.yaml"] [unique_id "al9JRE0Dwhk5-Z44XrpSfAACogI"]
[Tue Jul 21 07:26:13.000682 2026] [security2:error] [pid 230252:tid 230377] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/sa.json"] [unique_id "al9JRU0Dwhk5-Z44XrpSfgACuno"]
[Tue Jul 21 07:26:13.047345 2026] [security2:error] [pid 230252:tid 230413] [client 216.73.160.174:56211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.160.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9JQ00Dwhk5-Z44XrpSbQAAArY"]
[Tue Jul 21 07:26:13.131688 2026] [security2:error] [pid 229246:tid 229418] [client 4.204.201.85:26576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/file31.php"] [unique_id "al9JRSBMYeh5YLVG45x4NwAAAj4"]
[Tue Jul 21 07:26:13.470316 2026] [security2:error] [pid 230252:tid 230254] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/config.js"] [unique_id "al9JRU0Dwhk5-Z44XrpSkQADDwA"]
[Tue Jul 21 07:26:13.672751 2026] [security2:error] [pid 229246:tid 229432] [client 4.204.201.85:3299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/file6.php"] [unique_id "al9JRSBMYeh5YLVG45x4PgAAAkw"]
[Tue Jul 21 07:26:13.786984 2026] [security2:error] [pid 229246:tid 229338] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JRSBMYeh5YLVG45x4QQACU1s"]
[Tue Jul 21 07:26:13.787135 2026] [security2:error] [pid 229246:tid 229439] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JRSBMYeh5YLVG45x4QQACU1s"]
[Tue Jul 21 07:26:13.835754 2026] [security2:error] [pid 230252:tid 230419] [client 20.226.60.151:62344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/a2.php"] [unique_id "al9JRU0Dwhk5-Z44XrpSnQAAArw"]
[Tue Jul 21 07:26:13.944773 2026] [security2:error] [pid 230252:tid 230465] [client 20.220.225.223:38680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/wander.php"] [unique_id "al9JRU0Dwhk5-Z44XrpSnwAAAuo"]
[Tue Jul 21 07:26:14.123352 2026] [security2:error] [pid 230252:tid 230460] [client 74.249.245.134:54379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/222.php"] [unique_id "al9JRk0Dwhk5-Z44XrpSpgAAAuU"]
[Tue Jul 21 07:26:14.423106 2026] [security2:error] [pid 229246:tid 229479] [client 4.204.201.85:3309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/adminfuns.php"] [unique_id "al9JRiBMYeh5YLVG45x4RwAAAns"]
[Tue Jul 21 07:26:14.432676 2026] [security2:error] [pid 229246:tid 229428] [client 20.151.10.161:63689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/a.php"] [unique_id "al9JRiBMYeh5YLVG45x4SAAAAkg"]
[Tue Jul 21 07:26:14.473398 2026] [security2:error] [pid 230252:tid 230342] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/openapi.json"] [unique_id "al9JRk0Dwhk5-Z44XrpSugAC9lc"]
[Tue Jul 21 07:26:14.473553 2026] [security2:error] [pid 230252:tid 230477] [client 34.35.143.238:47704] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/openapi.json"] [unique_id "al9JRk0Dwhk5-Z44XrpSugAC9lc"]
[Tue Jul 21 07:26:14.487399 2026] [security2:error] [pid 229246:tid 229388] [client 103.162.129.114:59197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JRiBMYeh5YLVG45x4SQAAAiA"]
[Tue Jul 21 07:26:14.487516 2026] [security2:error] [pid 229246:tid 229388] [client 103.162.129.114:59197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JRiBMYeh5YLVG45x4SQAAAiA"]
[Tue Jul 21 07:26:14.729891 2026] [security2:error] [pid 230252:tid 230453] [client 139.135.44.145:54921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JRk0Dwhk5-Z44XrpSwQAAAt4"]
[Tue Jul 21 07:26:14.729997 2026] [security2:error] [pid 230252:tid 230453] [client 139.135.44.145:54921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JRk0Dwhk5-Z44XrpSwQAAAt4"]
[Tue Jul 21 07:26:14.782448 2026] [security2:error] [pid 230252:tid 230284] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "panel.gradiente.com"] [uri "/health"] [unique_id "al9JRk0Dwhk5-Z44XrpSwwACqB4"]
[Tue Jul 21 07:26:14.790950 2026] [security2:error] [pid 230252:tid 230351] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/__env.js"] [unique_id "al9JRk0Dwhk5-Z44XrpSxAAC2mA"]
[Tue Jul 21 07:26:14.791089 2026] [security2:error] [pid 230252:tid 230449] [client 34.35.143.238:47704] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/__env.js"] [unique_id "al9JRk0Dwhk5-Z44XrpSxAAC2mA"]
[Tue Jul 21 07:26:14.841864 2026] [security2:error] [pid 230252:tid 230400] [client 4.204.201.85:3289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/goods.php"] [unique_id "al9JRk0Dwhk5-Z44XrpSxgAAAqk"]
[Tue Jul 21 07:26:14.853322 2026] [security2:error] [pid 230252:tid 230427] [client 20.226.60.151:62390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/d61.php"] [unique_id "al9JRk0Dwhk5-Z44XrpSyAAAAsQ"]
[Tue Jul 21 07:26:15.316978 2026] [security2:error] [pid 230252:tid 230398] [client 193.36.225.57:59295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JR00Dwhk5-Z44XrpS1wAAAqc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:15.365826 2026] [security2:error] [pid 230252:tid 230272] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "panel.gradiente.com"] [uri "/actuator/mappings"] [unique_id "al9JR00Dwhk5-Z44XrpS2wACxhI"]
[Tue Jul 21 07:26:15.367453 2026] [security2:error] [pid 230252:tid 230274] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/info.php"] [unique_id "al9JR00Dwhk5-Z44XrpS3AACxhQ"]
[Tue Jul 21 07:26:15.367833 2026] [security2:error] [pid 230252:tid 230278] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/phpinfo.php"] [unique_id "al9JR00Dwhk5-Z44XrpS3QACxhg"]
[Tue Jul 21 07:26:15.378797 2026] [security2:error] [pid 230252:tid 230509] [client 4.204.201.85:3284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/100.php"] [unique_id "al9JR00Dwhk5-Z44XrpS3gAAAxY"]
[Tue Jul 21 07:26:15.397028 2026] [security2:error] [pid 230252:tid 230318] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JR00Dwhk5-Z44XrpS3wADFUA"]
[Tue Jul 21 07:26:15.397168 2026] [security2:error] [pid 230252:tid 230508] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JR00Dwhk5-Z44XrpS3wADFUA"]
[Tue Jul 21 07:26:15.559407 2026] [security2:error] [pid 230252:tid 230308] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/pi.php"] [unique_id "al9JR00Dwhk5-Z44XrpS4wACvTY"]
[Tue Jul 21 07:26:15.692437 2026] [security2:error] [pid 229246:tid 229382] [client 74.249.245.134:5526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/t.php"] [unique_id "al9JRyBMYeh5YLVG45x4VgAAAho"]
[Tue Jul 21 07:26:15.745140 2026] [security2:error] [pid 230252:tid 230434] [client 4.204.201.85:3276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/about.php"] [unique_id "al9JR00Dwhk5-Z44XrpS6AAAAss"]
[Tue Jul 21 07:26:15.794071 2026] [security2:error] [pid 230252:tid 230352] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/test.php"] [unique_id "al9JR00Dwhk5-Z44XrpS6wAC4WE"]
[Tue Jul 21 07:26:15.799388 2026] [security2:error] [pid 230252:tid 230282] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/i.php"] [unique_id "al9JR00Dwhk5-Z44XrpS7wAC-Rw"]
[Tue Jul 21 07:26:15.875291 2026] [security2:error] [pid 230252:tid 230303] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/app_dev.php"] [unique_id "al9JR00Dwhk5-Z44XrpS9QAC6zE"]
[Tue Jul 21 07:26:15.924319 2026] [security2:error] [pid 230252:tid 230311] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/_ignition/health-check"] [unique_id "al9JR00Dwhk5-Z44XrpS9gADCTk"]
[Tue Jul 21 07:26:15.925100 2026] [security2:error] [pid 230252:tid 230361] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/app_dev.php/_profiler"] [unique_id "al9JR00Dwhk5-Z44XrpS9wACvGo"]
[Tue Jul 21 07:26:15.969274 2026] [security2:error] [pid 230252:tid 230269] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/_debugbar/open"] [unique_id "al9JR00Dwhk5-Z44XrpS-QAC-A8"]
[Tue Jul 21 07:26:16.047357 2026] [security2:error] [pid 229246:tid 229466] [client 4.204.201.85:3222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/about.php"] [unique_id "al9JSCBMYeh5YLVG45x4XAAAAm4"]
[Tue Jul 21 07:26:16.214439 2026] [security2:error] [pid 230252:tid 230327] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/trace.axd"] [unique_id "al9JSE0Dwhk5-Z44XrpS_AADD0g"]
[Tue Jul 21 07:26:16.214700 2026] [security2:error] [pid 230252:tid 230330] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/elmah.axd"] [unique_id "al9JSE0Dwhk5-Z44XrpS_gADD0s"]
[Tue Jul 21 07:26:16.214796 2026] [security2:error] [pid 230252:tid 230502] [client 34.35.143.238:47704] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/elmah.axd"] [unique_id "al9JSE0Dwhk5-Z44XrpS_gADD0s"]
[Tue Jul 21 07:26:16.216004 2026] [security2:error] [pid 230252:tid 230338] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/server-info"] [unique_id "al9JSE0Dwhk5-Z44XrpS_wADD1M"]
[Tue Jul 21 07:26:16.272037 2026] [security2:error] [pid 230252:tid 230460] [client 20.226.60.151:63348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/info.php"] [unique_id "al9JSE0Dwhk5-Z44XrpTBQAAAuU"]
[Tue Jul 21 07:26:16.399895 2026] [access_compat:error] [pid 230252:tid 230317] [remote 34.35.143.238:47704] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:26:16.408823 2026] [security2:error] [pid 230252:tid 230435] [client 4.204.201.85:3305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/admin.php"] [unique_id "al9JSE0Dwhk5-Z44XrpTEAAAAsw"]
[Tue Jul 21 07:26:16.444586 2026] [security2:error] [pid 230252:tid 230457] [client 20.226.60.151:54567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/dfre.php"] [unique_id "al9JSE0Dwhk5-Z44XrpTEgAAAuI"]
[Tue Jul 21 07:26:16.500939 2026] [security2:error] [pid 230252:tid 230425] [client 20.220.225.223:31185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/jga.php"] [unique_id "al9JSE0Dwhk5-Z44XrpTEwAAAsI"]
[Tue Jul 21 07:26:16.606761 2026] [security2:error] [pid 229246:tid 229467] [client 117.251.86.144:43378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JSCBMYeh5YLVG45x4YAAAAm8"]
[Tue Jul 21 07:26:16.606890 2026] [security2:error] [pid 229246:tid 229467] [client 117.251.86.144:43378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JSCBMYeh5YLVG45x4YAAAAm8"]
[Tue Jul 21 07:26:16.798746 2026] [security2:error] [pid 229246:tid 229469] [client 74.249.245.134:54358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/a.php"] [unique_id "al9JSCBMYeh5YLVG45x4YwAAAnE"]
[Tue Jul 21 07:26:16.828638 2026] [security2:error] [pid 230252:tid 230453] [client 4.204.201.85:3217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/admin.php"] [unique_id "al9JSE0Dwhk5-Z44XrpTFgAAAt4"]
[Tue Jul 21 07:26:17.122333 2026] [security2:error] [pid 229246:tid 229485] [client 20.226.60.151:56915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/11.php"] [unique_id "al9JSSBMYeh5YLVG45x4ZgAAAoE"]
[Tue Jul 21 07:26:17.221537 2026] [security2:error] [pid 230252:tid 230476] [client 4.204.201.85:3323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/themes.php"] [unique_id "al9JSU0Dwhk5-Z44XrpTGwAAAvU"]
[Tue Jul 21 07:26:17.275037 2026] [security2:error] [pid 230252:tid 230377] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JSU0Dwhk5-Z44XrpTHAACoXo"]
[Tue Jul 21 07:26:17.275214 2026] [security2:error] [pid 230252:tid 230392] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JSU0Dwhk5-Z44XrpTHAACoXo"]
[Tue Jul 21 07:26:17.494075 2026] [security2:error] [pid 230252:tid 230486] [client 74.249.245.134:54391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/a1.php"] [unique_id "al9JSU0Dwhk5-Z44XrpTHwAAAv8"]
[Tue Jul 21 07:26:17.526371 2026] [security2:error] [pid 229246:tid 229491] [client 20.220.225.223:45958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/la.php"] [unique_id "al9JSSBMYeh5YLVG45x4awAAAoc"]
[Tue Jul 21 07:26:18.079708 2026] [security2:error] [pid 229246:tid 229327] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JSiBMYeh5YLVG45x4dAACgFA"]
[Tue Jul 21 07:26:18.079898 2026] [security2:error] [pid 229246:tid 229484] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JSiBMYeh5YLVG45x4dAACgFA"]
[Tue Jul 21 07:26:18.235905 2026] [security2:error] [pid 230252:tid 230403] [client 20.220.225.223:38707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/x.php"] [unique_id "al9JSk0Dwhk5-Z44XrpTKgAAAqw"]
[Tue Jul 21 07:26:18.327593 2026] [security2:error] [pid 229246:tid 229483] [client 4.204.201.85:3268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/.well-known/about.php"] [unique_id "al9JSiBMYeh5YLVG45x4eQAAAn8"]
[Tue Jul 21 07:26:18.378464 2026] [security2:error] [pid 230252:tid 230494] [client 20.52.136.55:1776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/xda.php"] [unique_id "al9JSk0Dwhk5-Z44XrpTKwAAAwc"]
[Tue Jul 21 07:26:18.602970 2026] [security2:error] [pid 230252:tid 230386] [client 74.249.245.134:54392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/w.php"] [unique_id "al9JSk0Dwhk5-Z44XrpTLgAAAps"]
[Tue Jul 21 07:26:18.652402 2026] [security2:error] [pid 230252:tid 230358] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/.git/HEAD"] [unique_id "al9JSk0Dwhk5-Z44XrpTLwACyWc"]
[Tue Jul 21 07:26:18.652608 2026] [security2:error] [pid 230252:tid 230432] [client 34.35.143.238:58534] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com"] [uri "/.git/HEAD"] [unique_id "al9JSk0Dwhk5-Z44XrpTLwACyWc"]
[Tue Jul 21 07:26:18.694084 2026] [security2:error] [pid 230252:tid 230367] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JSk0Dwhk5-Z44XrpTPgADCXA"]
[Tue Jul 21 07:26:18.694226 2026] [security2:error] [pid 230252:tid 230496] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JSk0Dwhk5-Z44XrpTPgADCXA"]
[Tue Jul 21 07:26:18.766078 2026] [security2:error] [pid 229246:tid 229440] [client 4.204.201.85:3236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9JSiBMYeh5YLVG45x4iQAAAlQ"]
[Tue Jul 21 07:26:18.790822 2026] [security2:error] [pid 230252:tid 230433] [client 20.220.225.223:46100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/nhvoanpl.php"] [unique_id "al9JSk0Dwhk5-Z44XrpTQAAAAso"]
[Tue Jul 21 07:26:18.809149 2026] [security2:error] [pid 229246:tid 229399] [client 173.252.95.13:44922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9JSiBMYeh5YLVG45x4igAAAis"]
[Tue Jul 21 07:26:18.822280 2026] [security2:error] [pid 229246:tid 229498] [client 20.226.60.151:56832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/v2.php"] [unique_id "al9JSiBMYeh5YLVG45x4iwAAAo4"]
[Tue Jul 21 07:26:18.931438 2026] [security2:error] [pid 229246:tid 229408] [client 62.102.148.164:39222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JSiBMYeh5YLVG45x4jwAAAjQ"]
[Tue Jul 21 07:26:18.931549 2026] [security2:error] [pid 229246:tid 229408] [client 62.102.148.164:39222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JSiBMYeh5YLVG45x4jwAAAjQ"]
[Tue Jul 21 07:26:19.101424 2026] [security2:error] [pid 230252:tid 230288] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.env"] [unique_id "al9JS00Dwhk5-Z44XrpTRAADECI"]
[Tue Jul 21 07:26:19.254589 2026] [security2:error] [pid 230252:tid 230404] [client 4.204.201.85:3207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/wefile.php"] [unique_id "al9JS00Dwhk5-Z44XrpTSwAAAq0"]
[Tue Jul 21 07:26:19.320964 2026] [security2:error] [pid 230252:tid 230447] [client 82.102.28.107:59322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9JS00Dwhk5-Z44XrpTTQAAAtg"]
[Tue Jul 21 07:26:19.321059 2026] [security2:error] [pid 230252:tid 230447] [client 82.102.28.107:59322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9JS00Dwhk5-Z44XrpTTQAAAtg"]
[Tue Jul 21 07:26:19.540262 2026] [security2:error] [pid 230252:tid 230295] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "gradiente.com"] [uri "/.env.local"] [unique_id "al9JS00Dwhk5-Z44XrpTUwACzSk"]
[Tue Jul 21 07:26:19.543245 2026] [security2:error] [pid 229246:tid 229453] [client 45.251.232.145:63918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JSyBMYeh5YLVG45x4mQAAAmE"]
[Tue Jul 21 07:26:19.543385 2026] [security2:error] [pid 229246:tid 229453] [client 45.251.232.145:63918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JSyBMYeh5YLVG45x4mQAAAmE"]
[Tue Jul 21 07:26:19.596868 2026] [security2:error] [pid 230252:tid 230428] [client 103.106.20.201:63532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JS00Dwhk5-Z44XrpTVgAAAsU"]
[Tue Jul 21 07:26:19.596998 2026] [security2:error] [pid 230252:tid 230428] [client 103.106.20.201:63532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JS00Dwhk5-Z44XrpTVgAAAsU"]
[Tue Jul 21 07:26:19.621989 2026] [security2:error] [pid 230252:tid 230469] [client 74.7.228.20:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "locadoracmd.com.br"] [uri "/index.php"] [unique_id "al9JSE0Dwhk5-Z44XrpTBAAAAu4"]
[Tue Jul 21 07:26:19.624677 2026] [security2:error] [pid 230252:tid 230415] [client 4.204.201.85:3300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9JS00Dwhk5-Z44XrpTVwAAArg"]
[Tue Jul 21 07:26:19.625026 2026] [security2:error] [pid 230252:tid 230465] [client 74.7.228.20:40708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "locadoracmd.com.br"] [uri "/robots.txt"] [unique_id "al9JSE0Dwhk5-Z44XrpTAgAC6mM"]
[Tue Jul 21 07:26:19.742083 2026] [security2:error] [pid 230252:tid 230339] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.env.backup"] [unique_id "al9JS00Dwhk5-Z44XrpTWAAC91Q"]
[Tue Jul 21 07:26:19.797790 2026] [security2:error] [pid 230252:tid 230371] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/api/.env"] [unique_id "al9JS00Dwhk5-Z44XrpTWQACm3Q"]
[Tue Jul 21 07:26:19.805001 2026] [security2:error] [pid 230252:tid 230322] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/backend/.env"] [unique_id "al9JS00Dwhk5-Z44XrpTWgAC5UQ"]
[Tue Jul 21 07:26:19.819123 2026] [security2:error] [pid 230252:tid 230382] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.env.bak"] [unique_id "al9JS00Dwhk5-Z44XrpTWwAC5H8"]
[Tue Jul 21 07:26:19.822785 2026] [security2:error] [pid 230252:tid 230375] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.env.old"] [unique_id "al9JS00Dwhk5-Z44XrpTXQACw3g"]
[Tue Jul 21 07:26:19.865304 2026] [security2:error] [pid 230252:tid 230360] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "gradiente.com"] [uri "/graphql"] [unique_id "al9JS00Dwhk5-Z44XrpTXwACw2k"]
[Tue Jul 21 07:26:19.886328 2026] [security2:error] [pid 230252:tid 230441] [client 20.220.225.223:46083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/inso.php"] [unique_id "al9JS00Dwhk5-Z44XrpTYAAAAtI"]
[Tue Jul 21 07:26:19.993178 2026] [security2:error] [pid 229246:tid 229500] [client 152.59.154.239:64729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JSyBMYeh5YLVG45x4nwAAApA"]
[Tue Jul 21 07:26:20.088304 2026] [security2:error] [pid 230252:tid 230364] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/config/.env"] [unique_id "al9JTE0Dwhk5-Z44XrpTYwACsW0"]
[Tue Jul 21 07:26:20.210912 2026] [security2:error] [pid 230252:tid 230307] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "gradiente.com"] [uri "/api/graphql"] [unique_id "al9JTE0Dwhk5-Z44XrpTcgAC8zU"]
[Tue Jul 21 07:26:20.289307 2026] [security2:error] [pid 230252:tid 230504] [client 103.174.34.15:60228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JTE0Dwhk5-Z44XrpTdgAAAxE"]
[Tue Jul 21 07:26:20.289465 2026] [security2:error] [pid 230252:tid 230504] [client 103.174.34.15:60228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JTE0Dwhk5-Z44XrpTdgAAAxE"]
[Tue Jul 21 07:26:20.458809 2026] [security2:error] [pid 230252:tid 230475] [client 74.249.245.134:5561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/wp-good.php"] [unique_id "al9JTE0Dwhk5-Z44XrpTfQAAAvQ"]
[Tue Jul 21 07:26:20.503067 2026] [authz_core:error] [pid 230252:tid 230498] [client 34.35.143.238:0] AH01630: client denied by server configuration: /home2/rica0429/public_html/.htpasswd
[Tue Jul 21 07:26:20.568132 2026] [security2:error] [pid 230252:tid 230506] [client 173.252.95.3:48658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9JS00Dwhk5-Z44XrpTTgAAAxM"]
[Tue Jul 21 07:26:20.570011 2026] [security2:error] [pid 229246:tid 229386] [client 59.96.220.140:61726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JTCBMYeh5YLVG45x4qgAAAh4"]
[Tue Jul 21 07:26:20.570711 2026] [security2:error] [pid 229246:tid 229386] [client 59.96.220.140:61726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JTCBMYeh5YLVG45x4qgAAAh4"]
[Tue Jul 21 07:26:20.572685 2026] [security2:error] [pid 230252:tid 230260] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "gradiente.com"] [uri "/v1/graphql"] [unique_id "al9JTE0Dwhk5-Z44XrpThQADCgY"]
[Tue Jul 21 07:26:20.604678 2026] [security2:error] [pid 230252:tid 230461] [client 136.144.33.29:21953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JTE0Dwhk5-Z44XrpTewAAAuY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:20.617132 2026] [security2:error] [pid 229246:tid 229491] [client 4.204.201.85:3326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/wp-admin/css/colour.php"] [unique_id "al9JTCBMYeh5YLVG45x4qwAAAoc"]
[Tue Jul 21 07:26:20.642635 2026] [security2:error] [pid 230252:tid 230276] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JTE0Dwhk5-Z44XrpThgACoRY"]
[Tue Jul 21 07:26:20.642836 2026] [security2:error] [pid 230252:tid 230392] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JTE0Dwhk5-Z44XrpThgACoRY"]
[Tue Jul 21 07:26:20.656080 2026] [security2:error] [pid 230252:tid 230258] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/.svn/entries"] [unique_id "al9JTE0Dwhk5-Z44XrpTigACzQQ"]
[Tue Jul 21 07:26:20.656243 2026] [security2:error] [pid 230252:tid 230436] [client 34.35.143.238:58534] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com"] [uri "/.svn/entries"] [unique_id "al9JTE0Dwhk5-Z44XrpTigACzQQ"]
[Tue Jul 21 07:26:20.684549 2026] [security2:error] [pid 230252:tid 230403] [client 20.151.10.161:65431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/k.php"] [unique_id "al9JTE0Dwhk5-Z44XrpTjgAAAqw"]
[Tue Jul 21 07:26:20.696170 2026] [security2:error] [pid 230252:tid 230469] [client 172.236.234.62:38842] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "ns1102.hostgator.com.br"] [uri "/"] [unique_id "al9JTE0Dwhk5-Z44XrpTjwAAAu4"]
[Tue Jul 21 07:26:20.697290 2026] [security2:error] [pid 230252:tid 230284] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.ssh/id_rsa"] [unique_id "al9JTE0Dwhk5-Z44XrpTkAACzR4"]
[Tue Jul 21 07:26:20.745537 2026] [security2:error] [pid 230252:tid 230285] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.ssh/id_dsa"] [unique_id "al9JTE0Dwhk5-Z44XrpTmAACzR8"]
[Tue Jul 21 07:26:20.773949 2026] [security2:error] [pid 229246:tid 229401] [client 20.226.60.151:54489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-happy.php"] [unique_id "al9JTCBMYeh5YLVG45x4sAAAAi0"]
[Tue Jul 21 07:26:20.874282 2026] [security2:error] [pid 229246:tid 229356] [remote 165.227.132.137:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.132.227.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9JTCBMYeh5YLVG45x4swACWm0"]
[Tue Jul 21 07:26:20.876069 2026] [security2:error] [pid 229246:tid 229319] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JTCBMYeh5YLVG45x4tAACGUg"]
[Tue Jul 21 07:26:20.876209 2026] [security2:error] [pid 229246:tid 229381] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JTCBMYeh5YLVG45x4tAACGUg"]
[Tue Jul 21 07:26:21.029024 2026] [security2:error] [pid 230252:tid 230331] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/id_rsa"] [unique_id "al9JTU0Dwhk5-Z44XrpTnQACsUw"]
[Tue Jul 21 07:26:21.029046 2026] [security2:error] [pid 230252:tid 230261] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/.ssh/known_hosts"] [unique_id "al9JTU0Dwhk5-Z44XrpTnwACsQc"]
[Tue Jul 21 07:26:21.029363 2026] [security2:error] [pid 230252:tid 230408] [client 34.35.143.238:58534] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com"] [uri "/.ssh/known_hosts"] [unique_id "al9JTU0Dwhk5-Z44XrpTnwACsQc"]
[Tue Jul 21 07:26:21.107127 2026] [security2:error] [pid 230252:tid 230363] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/id_dsa"] [unique_id "al9JTU0Dwhk5-Z44XrpTpgACsWw"]
[Tue Jul 21 07:26:21.115946 2026] [security2:error] [pid 229246:tid 229396] [client 4.204.201.85:3279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/8.php"] [unique_id "al9JTSBMYeh5YLVG45x4xgAAAig"]
[Tue Jul 21 07:26:21.186808 2026] [security2:error] [pid 230252:tid 230345] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/key.pem"] [unique_id "al9JTU0Dwhk5-Z44XrpTrAACsVo"]
[Tue Jul 21 07:26:21.230164 2026] [security2:error] [pid 230252:tid 230270] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/privatekey.key"] [unique_id "al9JTU0Dwhk5-Z44XrpTrwACsRA"]
[Tue Jul 21 07:26:21.297382 2026] [security2:error] [pid 230252:tid 230446] [client 175.45.70.82:50951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JTU0Dwhk5-Z44XrpTuwAAAtc"]
[Tue Jul 21 07:26:21.297533 2026] [security2:error] [pid 230252:tid 230446] [client 175.45.70.82:50951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JTU0Dwhk5-Z44XrpTuwAAAtc"]
[Tue Jul 21 07:26:21.328483 2026] [security2:error] [pid 230252:tid 230278] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/host.key"] [unique_id "al9JTU0Dwhk5-Z44XrpTvAACsRg"]
[Tue Jul 21 07:26:21.351768 2026] [security2:error] [pid 229246:tid 229440] [client 20.226.60.151:56943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/panel.php"] [unique_id "al9JTSBMYeh5YLVG45x41QAAAlQ"]
[Tue Jul 21 07:26:21.481989 2026] [security2:error] [pid 230252:tid 230497] [client 4.204.201.85:3303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/wp-content/admin.php"] [unique_id "al9JTU0Dwhk5-Z44XrpTxAAAAwo"]
[Tue Jul 21 07:26:21.557009 2026] [security2:error] [pid 230252:tid 230328] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.openclaw/.env"] [unique_id "al9JTU0Dwhk5-Z44XrpTxgACnUk"]
[Tue Jul 21 07:26:21.638252 2026] [security2:error] [pid 230252:tid 230434] [client 173.252.95.61:57080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9JTU0Dwhk5-Z44XrpTzQAAAss"]
[Tue Jul 21 07:26:21.753230 2026] [security2:error] [pid 230252:tid 230352] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.hermes/.env"] [unique_id "al9JTU0Dwhk5-Z44XrpT0gACnWE"]
[Tue Jul 21 07:26:21.759316 2026] [security2:error] [pid 230252:tid 230280] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/.config/anthropic/credentials/default.json"] [unique_id "al9JTU0Dwhk5-Z44XrpT1AACnRo"]
[Tue Jul 21 07:26:21.759512 2026] [security2:error] [pid 230252:tid 230388] [client 34.35.143.238:58534] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com"] [uri "/.config/anthropic/credentials/default.json"] [unique_id "al9JTU0Dwhk5-Z44XrpT1AACnRo"]
[Tue Jul 21 07:26:21.904294 2026] [security2:error] [pid 230252:tid 230502] [client 20.220.225.223:48562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wpx.php"] [unique_id "al9JTU0Dwhk5-Z44XrpT2AAAAw8"]
[Tue Jul 21 07:26:21.921167 2026] [security2:error] [pid 230252:tid 230473] [client 213.152.162.104:45656] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JTU0Dwhk5-Z44XrpT2QAAAvI"]
[Tue Jul 21 07:26:21.921320 2026] [security2:error] [pid 230252:tid 230473] [client 213.152.162.104:45656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JTU0Dwhk5-Z44XrpT2QAAAvI"]
[Tue Jul 21 07:26:21.952305 2026] [security2:error] [pid 230252:tid 230282] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "gradiente.com"] [uri "/.claude.json"] [unique_id "al9JTU0Dwhk5-Z44XrpT2gAC_hw"]
[Tue Jul 21 07:26:22.017060 2026] [security2:error] [pid 230252:tid 230391] [client 154.192.233.199:58952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JTk0Dwhk5-Z44XrpT3gAAAqA"]
[Tue Jul 21 07:26:22.017201 2026] [security2:error] [pid 230252:tid 230391] [client 154.192.233.199:58952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JTk0Dwhk5-Z44XrpT3gAAAqA"]
[Tue Jul 21 07:26:22.020363 2026] [security2:error] [pid 230252:tid 230398] [client 4.204.201.85:3286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/f6.php"] [unique_id "al9JTk0Dwhk5-Z44XrpT3wAAAqc"]
[Tue Jul 21 07:26:22.117497 2026] [security2:error] [pid 230252:tid 230361] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "gradiente.com"] [uri "/wp-config.php.bak"] [unique_id "al9JTk0Dwhk5-Z44XrpT6QAC_mo"]
[Tue Jul 21 07:26:22.176321 2026] [security2:error] [pid 230252:tid 230404] [client 20.52.136.55:1558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/shell.php"] [unique_id "al9JTk0Dwhk5-Z44XrpT6gAAAq0"]
[Tue Jul 21 07:26:22.202230 2026] [security2:error] [pid 230252:tid 230302] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "gradiente.com"] [uri "/wp-config.php.old"] [unique_id "al9JTk0Dwhk5-Z44XrpT7wAC_jA"]
[Tue Jul 21 07:26:22.255317 2026] [security2:error] [pid 230252:tid 230291] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/laravel/.env"] [unique_id "al9JTk0Dwhk5-Z44XrpT8AAC_iU"]
[Tue Jul 21 07:26:22.268896 2026] [security2:error] [pid 230252:tid 230327] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/config/.env.php"] [unique_id "al9JTk0Dwhk5-Z44XrpT8QAC_kg"]
[Tue Jul 21 07:26:22.313877 2026] [security2:error] [pid 230252:tid 230330] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/.env.php.bak"] [unique_id "al9JTk0Dwhk5-Z44XrpT8gAC_ks"]
[Tue Jul 21 07:26:22.425754 2026] [security2:error] [pid 230252:tid 230498] [client 20.151.10.161:26454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/xamp.php"] [unique_id "al9JTk0Dwhk5-Z44XrpT9QAAAws"]
[Tue Jul 21 07:26:22.446109 2026] [security2:error] [pid 230252:tid 230286] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/core/.env"] [unique_id "al9JTk0Dwhk5-Z44XrpT9gACsSA"]
[Tue Jul 21 07:26:22.510745 2026] [security2:error] [pid 230252:tid 230323] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/config.php.bak"] [unique_id "al9JTk0Dwhk5-Z44XrpT9wADE0U"]
[Tue Jul 21 07:26:22.522958 2026] [security2:error] [pid 230252:tid 230326] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/auth.json"] [unique_id "al9JTk0Dwhk5-Z44XrpT-AADCkc"]
[Tue Jul 21 07:26:22.523060 2026] [security2:error] [pid 230252:tid 230497] [client 34.35.143.238:58534] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com"] [uri "/auth.json"] [unique_id "al9JTk0Dwhk5-Z44XrpT-AADCkc"]
[Tue Jul 21 07:26:22.562283 2026] [security2:error] [pid 230252:tid 230304] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/configuration.php.bak"] [unique_id "al9JTk0Dwhk5-Z44XrpT-wACqDI"]
[Tue Jul 21 07:26:22.569198 2026] [security2:error] [pid 230252:tid 230409] [client 4.204.201.85:3210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/inputs.php"] [unique_id "al9JTk0Dwhk5-Z44XrpT_AAAArI"]
[Tue Jul 21 07:26:22.633115 2026] [security2:error] [pid 230252:tid 230376] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.env.swp"] [unique_id "al9JTk0Dwhk5-Z44XrpT_gADB3k"]
[Tue Jul 21 07:26:22.656446 2026] [security2:error] [pid 230252:tid 230317] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/public/.env"] [unique_id "al9JTk0Dwhk5-Z44XrpT_wAC4T8"]
[Tue Jul 21 07:26:22.667048 2026] [security2:error] [pid 230252:tid 230262] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/web/.env"] [unique_id "al9JTk0Dwhk5-Z44XrpUAgAC4Qg"]
[Tue Jul 21 07:26:22.667669 2026] [security2:error] [pid 230252:tid 230377] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/values.yaml"] [unique_id "al9JTk0Dwhk5-Z44XrpUAwAC4Xo"]
[Tue Jul 21 07:26:22.690063 2026] [security2:error] [pid 230252:tid 230415] [client 104.192.7.114:61199] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.sistedu-mec.com"] [uri "/wp-json/batch/v1"] [unique_id "al9JTk0Dwhk5-Z44XrpUBQAAArg"]
[Tue Jul 21 07:26:22.813917 2026] [security2:error] [pid 230252:tid 230488] [client 20.220.225.223:38691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9JTk0Dwhk5-Z44XrpUCgAAAwE"]
[Tue Jul 21 07:26:22.865805 2026] [security2:error] [pid 230252:tid 230367] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "gradiente.com"] [uri "/api/settings"] [unique_id "al9JTk0Dwhk5-Z44XrpUDgAC4XA"]
[Tue Jul 21 07:26:23.100883 2026] [security2:error] [pid 230252:tid 230491] [client 4.204.201.85:3306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/inputs.php"] [unique_id "al9JT00Dwhk5-Z44XrpUGAAAAwQ"]
[Tue Jul 21 07:26:23.423433 2026] [security2:error] [pid 230252:tid 230353] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "gradiente.com"] [uri "/api/openapi.json"] [unique_id "al9JT00Dwhk5-Z44XrpUJgADF2I"]
[Tue Jul 21 07:26:23.461217 2026] [security2:error] [pid 229246:tid 229409] [client 4.204.201.85:3229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/classwithtostring.php"] [unique_id "al9JTyBMYeh5YLVG45x48gAAAjU"]
[Tue Jul 21 07:26:23.471212 2026] [security2:error] [pid 229246:tid 229286] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JTyBMYeh5YLVG45x48wACMCc"]
[Tue Jul 21 07:26:23.471404 2026] [security2:error] [pid 229246:tid 229404] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JTyBMYeh5YLVG45x48wACMCc"]
[Tue Jul 21 07:26:23.475244 2026] [security2:error] [pid 230252:tid 230468] [client 20.220.225.223:46000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/berlin.php"] [unique_id "al9JT00Dwhk5-Z44XrpUJwAAAu0"]
[Tue Jul 21 07:26:23.488530 2026] [security2:error] [pid 229246:tid 229431] [client 20.226.60.151:63353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/dex.php"] [unique_id "al9JTyBMYeh5YLVG45x49AAAAks"]
[Tue Jul 21 07:26:23.723253 2026] [security2:error] [pid 230252:tid 230490] [client 20.226.60.151:54543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/fpr4.php"] [unique_id "al9JT00Dwhk5-Z44XrpUMwAAAwM"]
[Tue Jul 21 07:26:23.741429 2026] [security2:error] [pid 230252:tid 230375] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/swagger.json"] [unique_id "al9JT00Dwhk5-Z44XrpUNAADDng"]
[Tue Jul 21 07:26:23.816725 2026] [security2:error] [pid 230252:tid 230475] [client 4.204.201.85:3226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/wp-content/themes/index.php"] [unique_id "al9JT00Dwhk5-Z44XrpUOwAAAvQ"]
[Tue Jul 21 07:26:23.998827 2026] [security2:error] [pid 230252:tid 230315] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "gradiente.com"] [uri "/actuator/configprops"] [unique_id "al9JT00Dwhk5-Z44XrpUQgADDj0"]
[Tue Jul 21 07:26:24.173781 2026] [security2:error] [pid 229246:tid 229502] [client 20.226.60.151:56839] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "arielson.com.br"] [uri "/1.php"] [unique_id "al9JUCBMYeh5YLVG45x5BwAAApI"]
[Tue Jul 21 07:26:24.173911 2026] [security2:error] [pid 229246:tid 229502] [client 20.226.60.151:56839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/1.php"] [unique_id "al9JUCBMYeh5YLVG45x5BwAAApI"]
[Tue Jul 21 07:26:24.301216 2026] [security2:error] [pid 230252:tid 230301] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/phpinfo.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUSwADDi8"]
[Tue Jul 21 07:26:24.303438 2026] [security2:error] [pid 229246:tid 229420] [client 4.204.201.85:3315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/wp-blog.php"] [unique_id "al9JUCBMYeh5YLVG45x5CQAAAkA"]
[Tue Jul 21 07:26:24.310152 2026] [security2:error] [pid 230252:tid 230255] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/i.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUTAADDgE"]
[Tue Jul 21 07:26:24.330756 2026] [security2:error] [pid 230252:tid 230316] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/pi.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUTQADDj4"]
[Tue Jul 21 07:26:24.343941 2026] [security2:error] [pid 230252:tid 230310] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/info.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUTgADDjg"]
[Tue Jul 21 07:26:24.369081 2026] [security2:error] [pid 230252:tid 230366] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUUgAC0W8"]
[Tue Jul 21 07:26:24.369224 2026] [security2:error] [pid 230252:tid 230440] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUUgAC0W8"]
[Tue Jul 21 07:26:24.374512 2026] [security2:error] [pid 230252:tid 230343] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/_profiler/open"] [unique_id "al9JUE0Dwhk5-Z44XrpUUwADDlg"]
[Tue Jul 21 07:26:24.379926 2026] [security2:error] [pid 230252:tid 230283] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/test.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUVAADDh0"]
[Tue Jul 21 07:26:24.390579 2026] [security2:error] [pid 230252:tid 230260] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/app_dev.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUVQADDgY"]
[Tue Jul 21 07:26:24.489048 2026] [security2:error] [pid 230252:tid 230494] [client 20.220.225.223:45978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/billur.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUVwAAAwc"]
[Tue Jul 21 07:26:24.689214 2026] [security2:error] [pid 230252:tid 230258] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/app_dev.php/_profiler"] [unique_id "al9JUE0Dwhk5-Z44XrpUWAADGAQ"]
[Tue Jul 21 07:26:24.709782 2026] [security2:error] [pid 230252:tid 230342] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "gradiente.com"] [uri "/elmah.axd"] [unique_id "al9JUE0Dwhk5-Z44XrpUXQADGFc"]
[Tue Jul 21 07:26:24.713242 2026] [security2:error] [pid 230252:tid 230365] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/_debugbar/open"] [unique_id "al9JUE0Dwhk5-Z44XrpUXwADGG4"]
[Tue Jul 21 07:26:24.732198 2026] [access_compat:error] [pid 230252:tid 230268] [remote 34.35.143.238:58534] AH01797: client denied by server configuration: proxy:https://127.0.0.1:8443/server-status
[Tue Jul 21 07:26:24.740534 2026] [security2:error] [pid 230252:tid 230351] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/server-info"] [unique_id "al9JUE0Dwhk5-Z44XrpUaQADGGA"]
[Tue Jul 21 07:26:24.817943 2026] [security2:error] [pid 230252:tid 230460] [client 213.152.162.104:55572] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUbgAAAuU"]
[Tue Jul 21 07:26:24.818063 2026] [security2:error] [pid 230252:tid 230460] [client 213.152.162.104:55572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUbgAAAuU"]
[Tue Jul 21 07:26:24.873546 2026] [security2:error] [pid 229246:tid 229396] [client 20.151.10.161:26326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/bless.php"] [unique_id "al9JUCBMYeh5YLVG45x5EQAAAig"]
[Tue Jul 21 07:26:24.918242 2026] [security2:error] [pid 230252:tid 230385] [client 20.151.10.161:65419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/w.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUdgAAApo"]
[Tue Jul 21 07:26:24.983164 2026] [security2:error] [pid 229246:tid 229418] [client 103.162.129.114:59651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JUCBMYeh5YLVG45x5FAAAAj4"]
[Tue Jul 21 07:26:24.983322 2026] [security2:error] [pid 229246:tid 229418] [client 103.162.129.114:59651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JUCBMYeh5YLVG45x5FAAAAj4"]
[Tue Jul 21 07:26:24.990904 2026] [security2:error] [pid 230252:tid 230502] [client 4.204.201.85:3258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/wp-content/admin.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUdwAAAw8"]
[Tue Jul 21 07:26:25.266885 2026] [security2:error] [pid 229246:tid 229414] [client 74.249.245.134:62860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/.info.php"] [unique_id "al9JUSBMYeh5YLVG45x5HAAAAjo"]
[Tue Jul 21 07:26:25.349039 2026] [security2:error] [pid 229246:tid 229428] [client 213.152.162.104:45664] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9JUSBMYeh5YLVG45x5HgAAAkg"]
[Tue Jul 21 07:26:25.349186 2026] [security2:error] [pid 229246:tid 229428] [client 213.152.162.104:45664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9JUSBMYeh5YLVG45x5HgAAAkg"]
[Tue Jul 21 07:26:25.557801 2026] [security2:error] [pid 230252:tid 230482] [client 139.135.44.145:53798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JUU0Dwhk5-Z44XrpUggAAAvs"]
[Tue Jul 21 07:26:25.557931 2026] [security2:error] [pid 230252:tid 230482] [client 139.135.44.145:53798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JUU0Dwhk5-Z44XrpUggAAAvs"]
[Tue Jul 21 07:26:25.615306 2026] [security2:error] [pid 230252:tid 230411] [client 4.204.201.85:3249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/ms-edit.php"] [unique_id "al9JUU0Dwhk5-Z44XrpUgwAAArQ"]
[Tue Jul 21 07:26:25.699424 2026] [core:alert] [pid 230252:tid 230486] [client 57.141.18.50:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:26:25.798026 2026] [security2:error] [pid 230252:tid 230500] [client 74.7.230.49:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "drguedes.com.br"] [uri "/index.php"] [unique_id "al9JUU0Dwhk5-Z44XrpUfwAAAw0"]
[Tue Jul 21 07:26:25.799756 2026] [security2:error] [pid 230252:tid 230455] [client 74.7.230.49:57580] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "drguedes.com.br"] [uri "/robots.txt"] [unique_id "al9JUU0Dwhk5-Z44XrpUfQAC4Cs"]
[Tue Jul 21 07:26:25.819296 2026] [security2:error] [pid 230252:tid 230492] [client 20.151.10.161:26392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/file46.php"] [unique_id "al9JUU0Dwhk5-Z44XrpUjAAAAwU"]
[Tue Jul 21 07:26:25.926435 2026] [security2:error] [pid 230252:tid 230399] [client 20.220.225.223:45415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/mimpi.php"] [unique_id "al9JUU0Dwhk5-Z44XrpUkAAAAqg"]
[Tue Jul 21 07:26:25.942297 2026] [security2:error] [pid 230252:tid 230350] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JUU0Dwhk5-Z44XrpUkQAC3F8"]
[Tue Jul 21 07:26:25.942415 2026] [security2:error] [pid 230252:tid 230451] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JUU0Dwhk5-Z44XrpUkQAC3F8"]
[Tue Jul 21 07:26:26.112569 2026] [security2:error] [pid 229246:tid 229425] [client 173.252.95.2:51454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9JUCBMYeh5YLVG45x5EwAAAkU"]
[Tue Jul 21 07:26:26.210891 2026] [security2:error] [pid 229246:tid 229382] [client 4.204.201.85:3313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/cgi-bin/index.php"] [unique_id "al9JUiBMYeh5YLVG45x5KAAAAho"]
[Tue Jul 21 07:26:26.221241 2026] [security2:error] [pid 229246:tid 229376] [client 20.52.136.55:1746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/3.php"] [unique_id "al9JUiBMYeh5YLVG45x5KQAAAhQ"]
[Tue Jul 21 07:26:26.533560 2026] [security2:error] [pid 229246:tid 229470] [client 20.220.225.223:31181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/ee.php"] [unique_id "al9JUiBMYeh5YLVG45x5KwAAAnI"]
[Tue Jul 21 07:26:26.776286 2026] [security2:error] [pid 230252:tid 230386] [client 20.226.60.151:62352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/ms.php"] [unique_id "al9JUk0Dwhk5-Z44XrpUoAAAAps"]
[Tue Jul 21 07:26:26.847359 2026] [security2:error] [pid 230252:tid 230511] [client 109.248.148.246:36492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9JUk0Dwhk5-Z44XrpUpgAAAxg"]
[Tue Jul 21 07:26:26.847488 2026] [security2:error] [pid 230252:tid 230511] [client 109.248.148.246:36492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9JUk0Dwhk5-Z44XrpUpgAAAxg"]
[Tue Jul 21 07:26:26.949998 2026] [security2:error] [pid 229246:tid 229390] [client 4.204.201.85:3283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/BDKR28WP.php"] [unique_id "al9JUiBMYeh5YLVG45x5LwAAAiI"]
[Tue Jul 21 07:26:26.962825 2026] [security2:error] [pid 229246:tid 229421] [client 136.144.33.215:56589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JUSBMYeh5YLVG45x5JAAAAkE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:27.186565 2026] [security2:error] [pid 230252:tid 230417] [client 117.251.86.144:52440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JU00Dwhk5-Z44XrpUrAAAAro"]
[Tue Jul 21 07:26:27.186694 2026] [security2:error] [pid 230252:tid 230417] [client 117.251.86.144:52440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JU00Dwhk5-Z44XrpUrAAAAro"]
[Tue Jul 21 07:26:27.827025 2026] [security2:error] [pid 230252:tid 230263] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JU00Dwhk5-Z44XrpUugACqAk"]
[Tue Jul 21 07:26:27.827179 2026] [security2:error] [pid 230252:tid 230399] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JU00Dwhk5-Z44XrpUugACqAk"]
[Tue Jul 21 07:26:27.909281 2026] [security2:error] [pid 230252:tid 230392] [client 62.102.148.164:39928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JU00Dwhk5-Z44XrpUuwAAAqE"]
[Tue Jul 21 07:26:27.909416 2026] [security2:error] [pid 230252:tid 230392] [client 62.102.148.164:39928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JU00Dwhk5-Z44XrpUuwAAAqE"]
[Tue Jul 21 07:26:28.225673 2026] [security2:error] [pid 230252:tid 230434] [client 4.204.201.85:26591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/abcd.php"] [unique_id "al9JVE0Dwhk5-Z44XrpUwwAAAss"]
[Tue Jul 21 07:26:28.394663 2026] [security2:error] [pid 230252:tid 230420] [client 147.93.168.177:55621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.168.93.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "coroneldimas.mg"] [uri "/wp-login.php"] [unique_id "al9JVE0Dwhk5-Z44XrpUyAAAAr0"]
[Tue Jul 21 07:26:28.821078 2026] [security2:error] [pid 229246:tid 229484] [client 4.204.201.85:3241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/file15.php"] [unique_id "al9JVCBMYeh5YLVG45x5RQAAAoA"]
[Tue Jul 21 07:26:28.835978 2026] [security2:error] [pid 229246:tid 229386] [client 20.151.10.161:26373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/eee.php"] [unique_id "al9JVCBMYeh5YLVG45x5RgAAAh4"]
[Tue Jul 21 07:26:29.039410 2026] [security2:error] [pid 229246:tid 229253] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JVSBMYeh5YLVG45x5SAACkgY"]
[Tue Jul 21 07:26:29.039581 2026] [security2:error] [pid 229246:tid 229502] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JVSBMYeh5YLVG45x5SAACkgY"]
[Tue Jul 21 07:26:29.154557 2026] [autoindex:error] [pid 229246:tid 229403] [client 20.226.60.151:62359] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:26:29.250802 2026] [security2:error] [pid 230252:tid 230459] [client 20.226.60.151:54558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/file88.php"] [unique_id "al9JVU0Dwhk5-Z44XrpUzgAAAuQ"]
[Tue Jul 21 07:26:29.297683 2026] [security2:error] [pid 229246:tid 229256] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JVSBMYeh5YLVG45x5SwACdgk"]
[Tue Jul 21 07:26:29.297848 2026] [security2:error] [pid 229246:tid 229474] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JVSBMYeh5YLVG45x5SwACdgk"]
[Tue Jul 21 07:26:29.371989 2026] [security2:error] [pid 229246:tid 229486] [client 4.204.201.85:3318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/jp.php"] [unique_id "al9JVSBMYeh5YLVG45x5TgAAAoI"]
[Tue Jul 21 07:26:29.544278 2026] [security2:error] [pid 230252:tid 230449] [client 20.220.225.223:31183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/blue.php"] [unique_id "al9JVU0Dwhk5-Z44XrpU1QAAAto"]
[Tue Jul 21 07:26:29.837679 2026] [security2:error] [pid 230252:tid 230508] [client 4.204.201.85:3235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/f35.php"] [unique_id "al9JVU0Dwhk5-Z44XrpU2AAAAxU"]
[Tue Jul 21 07:26:30.004974 2026] [security2:error] [pid 229246:tid 229424] [client 45.251.232.145:64435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JViBMYeh5YLVG45x5UwAAAkQ"]
[Tue Jul 21 07:26:30.005099 2026] [security2:error] [pid 229246:tid 229424] [client 45.251.232.145:64435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JViBMYeh5YLVG45x5UwAAAkQ"]
[Tue Jul 21 07:26:30.102865 2026] [security2:error] [pid 229246:tid 229436] [client 20.52.136.55:1750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/mds.php"] [unique_id "al9JViBMYeh5YLVG45x5VQAAAlA"]
[Tue Jul 21 07:26:30.282892 2026] [security2:error] [pid 230252:tid 230392] [client 4.204.201.85:3213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/wp-load.php"] [unique_id "al9JVk0Dwhk5-Z44XrpU3gAAAqE"]
[Tue Jul 21 07:26:30.286441 2026] [security2:error] [pid 229246:tid 229501] [client 103.106.20.201:64096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JViBMYeh5YLVG45x5VwAAApE"]
[Tue Jul 21 07:26:30.286534 2026] [security2:error] [pid 229246:tid 229501] [client 103.106.20.201:64096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JViBMYeh5YLVG45x5VwAAApE"]
[Tue Jul 21 07:26:30.605445 2026] [security2:error] [pid 230252:tid 230434] [client 20.151.10.161:65497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/insc.php"] [unique_id "al9JVk0Dwhk5-Z44XrpU4gAAAss"]
[Tue Jul 21 07:26:30.859692 2026] [security2:error] [pid 230252:tid 230391] [client 20.220.225.223:31182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/wp-signup.php"] [unique_id "al9JVk0Dwhk5-Z44XrpU5wAAAqA"]
[Tue Jul 21 07:26:30.899434 2026] [security2:error] [pid 230252:tid 230398] [client 74.249.245.134:54375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/item.php"] [unique_id "al9JVk0Dwhk5-Z44XrpU6QAAAqc"]
[Tue Jul 21 07:26:30.928284 2026] [security2:error] [pid 230252:tid 230443] [client 4.204.201.85:3262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/xyn.php"] [unique_id "al9JVk0Dwhk5-Z44XrpU6wAAAtQ"]
[Tue Jul 21 07:26:31.052368 2026] [security2:error] [pid 229246:tid 229426] [client 20.220.225.223:48565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/dp.php"] [unique_id "al9JVyBMYeh5YLVG45x5XwAAAkY"]
[Tue Jul 21 07:26:31.100297 2026] [security2:error] [pid 230252:tid 230494] [client 103.174.34.15:60703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JV00Dwhk5-Z44XrpU7gAAAwc"]
[Tue Jul 21 07:26:31.100412 2026] [security2:error] [pid 230252:tid 230494] [client 103.174.34.15:60703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JV00Dwhk5-Z44XrpU7gAAAwc"]
[Tue Jul 21 07:26:31.172353 2026] [security2:error] [pid 230252:tid 230477] [client 136.144.33.104:51253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JV00Dwhk5-Z44XrpU8AAAAvY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:31.291010 2026] [security2:error] [pid 230252:tid 230399] [client 152.59.154.239:65149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JV00Dwhk5-Z44XrpU8QAAAqg"]
[Tue Jul 21 07:26:31.356899 2026] [security2:error] [pid 229246:tid 229408] [client 20.226.60.151:63341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/memberfuns.php"] [unique_id "al9JVyBMYeh5YLVG45x5YQAAAjQ"]
[Tue Jul 21 07:26:31.371743 2026] [security2:error] [pid 230252:tid 230281] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JV00Dwhk5-Z44XrpU8gACths"]
[Tue Jul 21 07:26:31.371911 2026] [security2:error] [pid 230252:tid 230413] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JV00Dwhk5-Z44XrpU8gACths"]
[Tue Jul 21 07:26:31.447648 2026] [security2:error] [pid 230252:tid 230462] [client 20.226.60.151:63337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/0.php"] [unique_id "al9JV00Dwhk5-Z44XrpU8wAAAuc"]
[Tue Jul 21 07:26:31.557881 2026] [security2:error] [pid 230252:tid 230511] [client 20.151.10.161:26381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/file25.php"] [unique_id "al9JV00Dwhk5-Z44XrpU-gAAAxg"]
[Tue Jul 21 07:26:31.841751 2026] [security2:error] [pid 230252:tid 230392] [client 20.226.60.151:63321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/BDKR28.php"] [unique_id "al9JV00Dwhk5-Z44XrpVDwAAAqE"]
[Tue Jul 21 07:26:31.950227 2026] [security2:error] [pid 230252:tid 230374] [remote 104.207.32.246:56793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.32.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9JV00Dwhk5-Z44XrpVEQACv3c"]
[Tue Jul 21 07:26:32.101739 2026] [security2:error] [pid 229246:tid 229439] [client 175.45.70.82:51559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JWCBMYeh5YLVG45x5awAAAlM"]
[Tue Jul 21 07:26:32.101879 2026] [security2:error] [pid 229246:tid 229439] [client 175.45.70.82:51559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JWCBMYeh5YLVG45x5awAAAlM"]
[Tue Jul 21 07:26:32.179178 2026] [security2:error] [pid 230252:tid 230346] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/wp-login.php"] [unique_id "al9JWE0Dwhk5-Z44XrpVEwACu1s"], referer: https://gradiente.com/login
[Tue Jul 21 07:26:32.190669 2026] [security2:error] [pid 230252:tid 230480] [client 4.204.201.85:26567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/ccc.php"] [unique_id "al9JWE0Dwhk5-Z44XrpVGAAAAvk"]
[Tue Jul 21 07:26:32.276150 2026] [security2:error] [pid 230252:tid 230426] [client 20.64.106.39:51650] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "162.241.63.69"] [uri "/index.cgi"] [unique_id "al9JWE0Dwhk5-Z44XrpVGQAAAsM"]
[Tue Jul 21 07:26:32.477539 2026] [security2:error] [pid 229246:tid 229412] [client 4.204.201.85:26583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/w.php"] [unique_id "al9JWCBMYeh5YLVG45x5bQAAAjg"]
[Tue Jul 21 07:26:32.503210 2026] [security2:error] [pid 230252:tid 230254] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/wp-login.php"] [unique_id "al9JWE0Dwhk5-Z44XrpVGwACnAA"], referer: https://gradiente.com/wp-admin/
[Tue Jul 21 07:26:32.503335 2026] [security2:error] [pid 230252:tid 230295] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/wp-login.php"] [unique_id "al9JWE0Dwhk5-Z44XrpVHAACnCk"], referer: https://gradiente.com/wp-admin/
[Tue Jul 21 07:26:32.531830 2026] [security2:error] [pid 229246:tid 229404] [client 20.226.60.151:62383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/green1.php"] [unique_id "al9JWCBMYeh5YLVG45x5cQAAAjA"]
[Tue Jul 21 07:26:32.627419 2026] [security2:error] [pid 230252:tid 230458] [client 20.151.10.161:26357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/file48.php"] [unique_id "al9JWE0Dwhk5-Z44XrpVHgAAAuM"]
[Tue Jul 21 07:26:32.669570 2026] [security2:error] [pid 229246:tid 229376] [client 154.192.233.199:59628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JWCBMYeh5YLVG45x5cwAAAhQ"]
[Tue Jul 21 07:26:32.669697 2026] [security2:error] [pid 229246:tid 229376] [client 154.192.233.199:59628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JWCBMYeh5YLVG45x5cwAAAhQ"]
[Tue Jul 21 07:26:32.716820 2026] [security2:error] [pid 230252:tid 230443] [client 74.249.245.134:17441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/albin.php"] [unique_id "al9JWE0Dwhk5-Z44XrpVIQAAAtQ"]
[Tue Jul 21 07:26:32.830441 2026] [security2:error] [pid 230252:tid 230385] [client 4.204.201.85:3205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9JWE0Dwhk5-Z44XrpVIwAAApo"]
[Tue Jul 21 07:26:33.319510 2026] [security2:error] [pid 230252:tid 230433] [client 4.204.201.85:3281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/FWAZ.php"] [unique_id "al9JWU0Dwhk5-Z44XrpVJgAAAso"]
[Tue Jul 21 07:26:33.321982 2026] [security2:error] [pid 229246:tid 229460] [client 213.152.162.104:52528] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JWSBMYeh5YLVG45x5eQAAAmg"]
[Tue Jul 21 07:26:33.322119 2026] [security2:error] [pid 229246:tid 229460] [client 213.152.162.104:52528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JWSBMYeh5YLVG45x5eQAAAmg"]
[Tue Jul 21 07:26:33.371473 2026] [security2:error] [pid 229246:tid 229475] [client 65.111.28.184:52781] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "giliniservices.com.br"] [uri "/"] [unique_id "al9JWSBMYeh5YLVG45x5egAAAnc"]
[Tue Jul 21 07:26:33.553428 2026] [security2:error] [pid 229246:tid 229491] [client 20.151.10.161:65455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9JWSBMYeh5YLVG45x5fwAAAoc"]
[Tue Jul 21 07:26:33.621419 2026] [security2:error] [pid 229246:tid 229445] [client 65.111.28.184:52781] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "giliniservices.com.br"] [uri "/"] [unique_id "al9JWSBMYeh5YLVG45x5gAAAAlk"]
[Tue Jul 21 07:26:33.640513 2026] [security2:error] [pid 230252:tid 230419] [client 4.204.201.85:3295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/miru1.php"] [unique_id "al9JWU0Dwhk5-Z44XrpVKQAAArw"]
[Tue Jul 21 07:26:33.651072 2026] [security2:error] [pid 229246:tid 229393] [client 20.151.10.161:26535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/file6.php"] [unique_id "al9JWSBMYeh5YLVG45x5gQAAAiU"]
[Tue Jul 21 07:26:33.770965 2026] [security2:error] [pid 230252:tid 230487] [client 20.226.60.151:56858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/nc4.php"] [unique_id "al9JWU0Dwhk5-Z44XrpVKwAAAwA"]
[Tue Jul 21 07:26:33.882061 2026] [security2:error] [pid 230252:tid 230382] [remote 38.242.157.30:47242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/wp-login.php"] [unique_id "al9JWU0Dwhk5-Z44XrpVLAADDX8"]
[Tue Jul 21 07:26:33.912919 2026] [security2:error] [pid 230252:tid 230360] [remote 47.128.56.33:50176] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dscbrasil.com.br"] [uri "/inicial"] [unique_id "al9JWU0Dwhk5-Z44XrpVLQAC8mk"]
[Tue Jul 21 07:26:33.918825 2026] [security2:error] [pid 230252:tid 230506] [client 20.220.225.223:31189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/csa.php"] [unique_id "al9JWU0Dwhk5-Z44XrpVLgAAAxM"]
[Tue Jul 21 07:26:34.019582 2026] [security2:error] [pid 230252:tid 230364] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JWk0Dwhk5-Z44XrpVLwACzG0"]
[Tue Jul 21 07:26:34.019734 2026] [security2:error] [pid 230252:tid 230435] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JWk0Dwhk5-Z44XrpVLwACzG0"]
[Tue Jul 21 07:26:34.123588 2026] [security2:error] [pid 229246:tid 229451] [client 65.111.28.184:52781] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9JWiBMYeh5YLVG45x5hgAAAl8"]
[Tue Jul 21 07:26:34.262122 2026] [security2:error] [pid 230252:tid 230498] [client 4.204.201.85:3324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/aa.php"] [unique_id "al9JWk0Dwhk5-Z44XrpVMQAAAws"]
[Tue Jul 21 07:26:34.428362 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:26448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/a2.php"] [unique_id "al9JWiBMYeh5YLVG45x5iAAAAlo"]
[Tue Jul 21 07:26:34.479364 2026] [security2:error] [pid 230252:tid 230453] [client 109.248.148.246:40258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9JWk0Dwhk5-Z44XrpVMgAAAt4"]
[Tue Jul 21 07:26:34.479507 2026] [security2:error] [pid 230252:tid 230453] [client 109.248.148.246:40258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9JWk0Dwhk5-Z44XrpVMgAAAt4"]
[Tue Jul 21 07:26:34.634431 2026] [security2:error] [pid 229246:tid 229443] [client 65.111.28.184:39051] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "giliniservices.com.br"] [uri "/"] [unique_id "al9JWiBMYeh5YLVG45x5jAAAAlc"]
[Tue Jul 21 07:26:34.681067 2026] [security2:error] [pid 229246:tid 229423] [client 20.226.60.151:56861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/a1.php"] [unique_id "al9JWiBMYeh5YLVG45x5jwAAAkM"]
[Tue Jul 21 07:26:34.734452 2026] [security2:error] [pid 229246:tid 229424] [client 4.204.201.85:3266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/122.php"] [unique_id "al9JWiBMYeh5YLVG45x5kAAAAkQ"]
[Tue Jul 21 07:26:34.869541 2026] [security2:error] [pid 230252:tid 230313] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JWk0Dwhk5-Z44XrpVOAAC2Ds"]
[Tue Jul 21 07:26:34.869678 2026] [security2:error] [pid 230252:tid 230447] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JWk0Dwhk5-Z44XrpVOAAC2Ds"]
[Tue Jul 21 07:26:34.887718 2026] [security2:error] [pid 229246:tid 229399] [client 65.111.28.184:39051] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9JWiBMYeh5YLVG45x5kQAAAis"]
[Tue Jul 21 07:26:34.891375 2026] [security2:error] [pid 229246:tid 229441] [client 20.220.225.223:46002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/bootstrap.php"] [unique_id "al9JWiBMYeh5YLVG45x5kgAAAlU"]
[Tue Jul 21 07:26:34.966217 2026] [security2:error] [pid 229246:tid 229319] [remote 18.61.192.253:49282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rqracademy.com"] [uri "/wp-login.php"] [unique_id "al9JWiBMYeh5YLVG45x5kwACkUg"]
[Tue Jul 21 07:26:34.997153 2026] [security2:error] [pid 230252:tid 230483] [client 20.151.10.161:26422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/file15.php"] [unique_id "al9JWk0Dwhk5-Z44XrpVOgAAAvw"]
[Tue Jul 21 07:26:35.173024 2026] [security2:error] [pid 229246:tid 229473] [client 20.226.60.151:56911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/eee.php"] [unique_id "al9JWyBMYeh5YLVG45x5mAAAAnU"]
[Tue Jul 21 07:26:35.394113 2026] [security2:error] [pid 229246:tid 229426] [client 65.111.28.184:59419] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9JWyBMYeh5YLVG45x5mwAAAkY"]
[Tue Jul 21 07:26:35.541738 2026] [security2:error] [pid 230252:tid 230410] [client 103.162.129.114:60111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JW00Dwhk5-Z44XrpVPwAAArM"]
[Tue Jul 21 07:26:35.541888 2026] [security2:error] [pid 230252:tid 230410] [client 103.162.129.114:60111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JW00Dwhk5-Z44XrpVPwAAArM"]
[Tue Jul 21 07:26:35.592760 2026] [security2:error] [pid 229246:tid 229481] [client 4.204.201.85:3292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/get.php"] [unique_id "al9JWyBMYeh5YLVG45x5ngAAAn0"]
[Tue Jul 21 07:26:35.627858 2026] [security2:error] [pid 229246:tid 229425] [client 45.227.253.15:36264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.253.227.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.clubelaser.com.br"] [uri "/index.php/jk"] [unique_id "al9JWyBMYeh5YLVG45x5oAAAAkU"]
[Tue Jul 21 07:26:35.638261 2026] [security2:error] [pid 229246:tid 229407] [client 20.226.60.151:63304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-aothait.php"] [unique_id "al9JWyBMYeh5YLVG45x5oQAAAjM"]
[Tue Jul 21 07:26:35.902079 2026] [security2:error] [pid 229246:tid 229412] [client 65.111.28.184:42817] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9JWyBMYeh5YLVG45x5pQAAAjg"]
[Tue Jul 21 07:26:35.905160 2026] [security2:error] [pid 230252:tid 230420] [client 20.151.10.161:26429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/jp.php"] [unique_id "al9JW00Dwhk5-Z44XrpVQQAAAr0"]
[Tue Jul 21 07:26:35.908081 2026] [security2:error] [pid 230252:tid 230508] [client 193.36.225.54:25077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JW00Dwhk5-Z44XrpVQgAAAxU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:35.991210 2026] [security2:error] [pid 229246:tid 229421] [client 213.152.162.104:52536] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9JWyBMYeh5YLVG45x5qQAAAkE"]
[Tue Jul 21 07:26:35.991323 2026] [security2:error] [pid 229246:tid 229421] [client 213.152.162.104:52536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9JWyBMYeh5YLVG45x5qQAAAkE"]
[Tue Jul 21 07:26:36.315447 2026] [security2:error] [pid 229246:tid 229380] [client 4.204.201.85:26596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/as.php"] [unique_id "al9JXCBMYeh5YLVG45x5sAAAAhg"]
[Tue Jul 21 07:26:36.334940 2026] [security2:error] [pid 229246:tid 229493] [client 139.135.44.145:54615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JXCBMYeh5YLVG45x5sQAAAok"]
[Tue Jul 21 07:26:36.339309 2026] [security2:error] [pid 229246:tid 229493] [client 139.135.44.145:54615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JXCBMYeh5YLVG45x5sQAAAok"]
[Tue Jul 21 07:26:36.402643 2026] [security2:error] [pid 230252:tid 230479] [client 20.220.225.223:46128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-editor.php"] [unique_id "al9JXE0Dwhk5-Z44XrpVRAAAAvg"]
[Tue Jul 21 07:26:36.403972 2026] [security2:error] [pid 230252:tid 230385] [client 20.226.60.151:63357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/config.json.php"] [unique_id "al9JXE0Dwhk5-Z44XrpVRQAAApo"]
[Tue Jul 21 07:26:36.410000 2026] [security2:error] [pid 230252:tid 230400] [client 65.111.28.184:15991] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9JXE0Dwhk5-Z44XrpVRgAAAqk"]
[Tue Jul 21 07:26:36.446208 2026] [security2:error] [pid 229246:tid 229500] [client 20.151.10.161:26466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/f35.php"] [unique_id "al9JXCBMYeh5YLVG45x5swAAApA"]
[Tue Jul 21 07:26:36.580468 2026] [security2:error] [pid 230252:tid 230301] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JXE0Dwhk5-Z44XrpVRwAC0i8"]
[Tue Jul 21 07:26:36.580634 2026] [security2:error] [pid 230252:tid 230441] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JXE0Dwhk5-Z44XrpVRwAC0i8"]
[Tue Jul 21 07:26:36.783307 2026] [security2:error] [pid 229246:tid 229406] [client 4.204.201.85:3232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/ccou.php"] [unique_id "al9JXCBMYeh5YLVG45x5uAAAAjI"]
[Tue Jul 21 07:26:36.801628 2026] [security2:error] [pid 229246:tid 229465] [client 20.220.225.223:31207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/min.php"] [unique_id "al9JXCBMYeh5YLVG45x5uQAAAm0"]
[Tue Jul 21 07:26:36.910039 2026] [security2:error] [pid 230252:tid 230504] [client 65.111.28.184:34019] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9JXE0Dwhk5-Z44XrpVSgAAAxE"]
[Tue Jul 21 07:26:37.020980 2026] [security2:error] [pid 230252:tid 230503] [client 74.249.245.134:17409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/alfa.php"] [unique_id "al9JXU0Dwhk5-Z44XrpVSwAAAxA"]
[Tue Jul 21 07:26:37.062572 2026] [security2:error] [pid 229246:tid 229488] [client 20.52.136.55:1578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/archive.php"] [unique_id "al9JXSBMYeh5YLVG45x5uwAAAoQ"]
[Tue Jul 21 07:26:37.065858 2026] [security2:error] [pid 230252:tid 230482] [client 82.102.28.107:39858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9JXU0Dwhk5-Z44XrpVTAAAAvs"]
[Tue Jul 21 07:26:37.065953 2026] [security2:error] [pid 230252:tid 230482] [client 82.102.28.107:39858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9JXU0Dwhk5-Z44XrpVTAAAAvs"]
[Tue Jul 21 07:26:37.215828 2026] [security2:error] [pid 230252:tid 230396] [client 20.226.60.151:63311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9JXU0Dwhk5-Z44XrpVTwAAAqU"]
[Tue Jul 21 07:26:37.380602 2026] [security2:error] [pid 229246:tid 229386] [client 20.151.10.161:26382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-load.php"] [unique_id "al9JXSBMYeh5YLVG45x5vwAAAh4"]
[Tue Jul 21 07:26:37.437203 2026] [security2:error] [pid 230252:tid 230473] [client 65.111.28.184:24971] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9JXU0Dwhk5-Z44XrpVUgAAAvI"]
[Tue Jul 21 07:26:37.482313 2026] [security2:error] [pid 230252:tid 230435] [client 20.151.10.161:63738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/u.php"] [unique_id "al9JXU0Dwhk5-Z44XrpVUwAAAsw"]
[Tue Jul 21 07:26:37.568574 2026] [security2:error] [pid 230252:tid 230497] [client 4.204.201.85:3296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/w3lls.php"] [unique_id "al9JXU0Dwhk5-Z44XrpVVQAAAwo"]
[Tue Jul 21 07:26:37.698068 2026] [security2:error] [pid 230252:tid 230467] [client 91.92.47.101:21790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/database.php"] [unique_id "al9JXU0Dwhk5-Z44XrpVWAAAAuw"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:26:37.700240 2026] [security2:error] [pid 230252:tid 230498] [client 91.92.47.101:21808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/settings.php"] [unique_id "al9JXU0Dwhk5-Z44XrpVWgAAAws"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:26:37.778952 2026] [security2:error] [pid 230252:tid 230475] [client 20.226.60.151:54479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/ccc.php"] [unique_id "al9JXU0Dwhk5-Z44XrpVXQAAAvQ"]
[Tue Jul 21 07:26:37.806478 2026] [security2:error] [pid 229246:tid 229393] [client 117.251.86.144:60640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JXSBMYeh5YLVG45x5xwAAAiU"]
[Tue Jul 21 07:26:37.806582 2026] [security2:error] [pid 229246:tid 229393] [client 117.251.86.144:60640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JXSBMYeh5YLVG45x5xwAAAiU"]
[Tue Jul 21 07:26:37.934330 2026] [security2:error] [pid 230252:tid 230409] [client 20.226.60.151:63350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/k2.php"] [unique_id "al9JXU0Dwhk5-Z44XrpVXgAAArI"]
[Tue Jul 21 07:26:37.941757 2026] [security2:error] [pid 230252:tid 230469] [client 65.111.28.184:53627] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9JXU0Dwhk5-Z44XrpVXwAAAu4"]
[Tue Jul 21 07:26:38.238756 2026] [security2:error] [pid 229246:tid 229403] [client 4.204.201.85:3228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/test1.php"] [unique_id "al9JXiBMYeh5YLVG45x5yQAAAi8"]
[Tue Jul 21 07:26:38.244769 2026] [security2:error] [pid 229246:tid 229441] [client 91.92.47.101:21822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/db.php"] [unique_id "al9JXiBMYeh5YLVG45x5zAAAAlU"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:26:38.246651 2026] [security2:error] [pid 230252:tid 230393] [client 91.92.47.101:21830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "look.dealspark.com.br"] [uri "/web.config"] [unique_id "al9JXk0Dwhk5-Z44XrpVYwAAAqI"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:26:38.248348 2026] [security2:error] [pid 229246:tid 229418] [client 91.92.47.101:21836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "look.dealspark.com.br"] [uri "/.env.bak"] [unique_id "al9JXiBMYeh5YLVG45x5zQAAAj4"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:26:38.382623 2026] [security2:error] [pid 229246:tid 229398] [client 20.220.225.223:38683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/echkm.php"] [unique_id "al9JXiBMYeh5YLVG45x50AAAAio"]
[Tue Jul 21 07:26:38.456390 2026] [security2:error] [pid 229246:tid 229456] [client 65.111.28.184:31973] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9JXiBMYeh5YLVG45x50QAAAmQ"]
[Tue Jul 21 07:26:38.473727 2026] [security2:error] [pid 230252:tid 230319] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JXk0Dwhk5-Z44XrpVaQADBEE"]
[Tue Jul 21 07:26:38.473865 2026] [security2:error] [pid 230252:tid 230491] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JXk0Dwhk5-Z44XrpVaQADBEE"]
[Tue Jul 21 07:26:38.522159 2026] [security2:error] [pid 229246:tid 229422] [client 20.226.60.151:56846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9JXiBMYeh5YLVG45x50gAAAkI"]
[Tue Jul 21 07:26:38.919914 2026] [security2:error] [pid 229246:tid 229492] [client 20.151.10.161:26468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/xwpg.php"] [unique_id "al9JXiBMYeh5YLVG45x52QAAAog"]
[Tue Jul 21 07:26:38.927518 2026] [security2:error] [pid 230252:tid 230407] [client 4.204.201.85:26619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/database.php"] [unique_id "al9JXk0Dwhk5-Z44XrpVcgAAArA"]
[Tue Jul 21 07:26:38.956457 2026] [security2:error] [pid 229246:tid 229498] [client 65.111.28.184:62995] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9JXiBMYeh5YLVG45x52wAAAo4"]
[Tue Jul 21 07:26:39.132891 2026] [security2:error] [pid 230252:tid 230503] [client 20.220.225.223:45995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/cro.php"] [unique_id "al9JX00Dwhk5-Z44XrpVdQAAAxA"]
[Tue Jul 21 07:26:39.354188 2026] [security2:error] [pid 230252:tid 230490] [client 20.104.96.117:59839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9JX00Dwhk5-Z44XrpVdgAAAwM"]
[Tue Jul 21 07:26:39.408646 2026] [security2:error] [pid 230252:tid 230505] [client 4.204.201.85:3214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/file.php"] [unique_id "al9JX00Dwhk5-Z44XrpVeAAAAxI"]
[Tue Jul 21 07:26:39.477962 2026] [security2:error] [pid 229246:tid 229430] [client 65.111.28.184:24203] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9JXyBMYeh5YLVG45x54wAAAko"]
[Tue Jul 21 07:26:39.631830 2026] [security2:error] [pid 230252:tid 230258] [remote 162.19.246.208:45822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "financasparaempreendedoras.com"] [uri "/wp-login.php"] [unique_id "al9JX00Dwhk5-Z44XrpVfAACngQ"]
[Tue Jul 21 07:26:39.752694 2026] [security2:error] [pid 229246:tid 229453] [client 74.249.245.134:54342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9JXyBMYeh5YLVG45x55wAAAmE"]
[Tue Jul 21 07:26:39.807535 2026] [security2:error] [pid 229246:tid 229416] [client 4.204.201.85:26608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/file.php"] [unique_id "al9JXyBMYeh5YLVG45x56QAAAjw"]
[Tue Jul 21 07:26:39.811784 2026] [security2:error] [pid 229246:tid 229421] [client 20.151.10.161:26428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/waf.php"] [unique_id "al9JXyBMYeh5YLVG45x56gAAAkE"]
[Tue Jul 21 07:26:39.825243 2026] [security2:error] [pid 229246:tid 229292] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JXyBMYeh5YLVG45x56wACGi0"]
[Tue Jul 21 07:26:39.825398 2026] [security2:error] [pid 229246:tid 229382] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JXyBMYeh5YLVG45x56wACGi0"]
[Tue Jul 21 07:26:39.852517 2026] [security2:error] [pid 230252:tid 230342] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JX00Dwhk5-Z44XrpVgAACtFc"]
[Tue Jul 21 07:26:39.852713 2026] [security2:error] [pid 230252:tid 230411] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JX00Dwhk5-Z44XrpVgAACtFc"]
[Tue Jul 21 07:26:39.992067 2026] [security2:error] [pid 230252:tid 230499] [client 65.111.28.184:36943] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9JX00Dwhk5-Z44XrpVhAAAAww"]
[Tue Jul 21 07:26:40.112158 2026] [security2:error] [pid 230252:tid 230409] [client 20.226.60.151:62355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9JYE0Dwhk5-Z44XrpVigAAArI"]
[Tue Jul 21 07:26:40.150870 2026] [security2:error] [pid 230252:tid 230495] [client 4.204.201.85:3238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/777.php"] [unique_id "al9JYE0Dwhk5-Z44XrpVjAAAAwg"]
[Tue Jul 21 07:26:40.270843 2026] [security2:error] [pid 229246:tid 229391] [client 20.220.225.223:46110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/cron-tab.php"] [unique_id "al9JYCBMYeh5YLVG45x58AAAAiM"]
[Tue Jul 21 07:26:40.477769 2026] [security2:error] [pid 229246:tid 229390] [client 45.251.232.145:64956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JYCBMYeh5YLVG45x59wAAAiI"]
[Tue Jul 21 07:26:40.477878 2026] [security2:error] [pid 229246:tid 229390] [client 45.251.232.145:64956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JYCBMYeh5YLVG45x59wAAAiI"]
[Tue Jul 21 07:26:40.656468 2026] [http2:info] [pid 229246:tid 229383] [client 162.158.171.29:13219] AH10180: h2_stream(229246-1130-1,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 07:26:40.662642 2026] [security2:error] [pid 229246:tid 229385] [client 4.204.201.85:3253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/ssixta.php"] [unique_id "al9JYCBMYeh5YLVG45x5-QAAAh0"]
[Tue Jul 21 07:26:40.938725 2026] [security2:error] [pid 229246:tid 229397] [client 20.226.60.151:63335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9JYCBMYeh5YLVG45x5_AAAAik"]
[Tue Jul 21 07:26:40.986316 2026] [http2:info] [pid 229246:tid 229381] [client 162.158.171.29:13219] AH10180: h2_stream(229246-1130-3,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 07:26:41.039069 2026] [security2:error] [pid 230252:tid 230458] [client 103.106.20.201:64657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JYU0Dwhk5-Z44XrpVlgAAAuM"]
[Tue Jul 21 07:26:41.039234 2026] [security2:error] [pid 230252:tid 230458] [client 103.106.20.201:64657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JYU0Dwhk5-Z44XrpVlgAAAuM"]
[Tue Jul 21 07:26:41.092581 2026] [security2:error] [pid 230252:tid 230385] [client 193.36.225.57:50567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JYE0Dwhk5-Z44XrpVlAAAApo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:41.111834 2026] [security2:error] [pid 230252:tid 230413] [client 20.151.10.161:26314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/xstelth.php"] [unique_id "al9JYU0Dwhk5-Z44XrpVmAAAArY"]
[Tue Jul 21 07:26:41.164410 2026] [security2:error] [pid 229246:tid 229476] [client 4.204.201.85:3239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/1c.php"] [unique_id "al9JYSBMYeh5YLVG45x6AAAAAng"]
[Tue Jul 21 07:26:41.320416 2026] [proxy:error] [pid 230252:tid 230345] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:26:41.320479 2026] [proxy_http:error] [pid 230252:tid 230345] [remote 198.235.24.40:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.githec.com/
[Tue Jul 21 07:26:41.321254 2026] [proxy:error] [pid 230252:tid 230345] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:26:41.321285 2026] [proxy_http:error] [pid 230252:tid 230345] [remote 198.235.24.40:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.githec.com/
[Tue Jul 21 07:26:41.340003 2026] [security2:error] [pid 229246:tid 229446] [client 74.249.245.134:5513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/av.php"] [unique_id "al9JYSBMYeh5YLVG45x6AwAAAlo"]
[Tue Jul 21 07:26:41.679543 2026] [security2:error] [pid 230252:tid 230430] [client 59.96.220.140:62639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JYU0Dwhk5-Z44XrpVpgAAAsc"]
[Tue Jul 21 07:26:41.679673 2026] [security2:error] [pid 230252:tid 230430] [client 59.96.220.140:62639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JYU0Dwhk5-Z44XrpVpgAAAsc"]
[Tue Jul 21 07:26:41.883517 2026] [security2:error] [pid 230252:tid 230497] [client 20.151.10.161:26526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-links.php"] [unique_id "al9JYU0Dwhk5-Z44XrpVrAAAAwo"]
[Tue Jul 21 07:26:41.913687 2026] [security2:error] [pid 230252:tid 230297] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JYU0Dwhk5-Z44XrpVrQAC_ys"]
[Tue Jul 21 07:26:41.913826 2026] [security2:error] [pid 230252:tid 230486] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JYU0Dwhk5-Z44XrpVrQAC_ys"]
[Tue Jul 21 07:26:41.917435 2026] [http2:info] [pid 230252:tid 230389] [client 162.158.170.64:10937] AH10180: h2_stream(230252-1310-1,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 07:26:41.987751 2026] [security2:error] [pid 230252:tid 230445] [client 20.226.60.151:63323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/for.php"] [unique_id "al9JYU0Dwhk5-Z44XrpVsAAAAtY"]
[Tue Jul 21 07:26:41.988868 2026] [security2:error] [pid 230252:tid 230467] [client 20.220.225.223:46124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/koiy.php"] [unique_id "al9JYU0Dwhk5-Z44XrpVsQAAAuw"]
[Tue Jul 21 07:26:42.064285 2026] [security2:error] [pid 230252:tid 230401] [client 4.204.201.85:3230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/test2.php"] [unique_id "al9JYk0Dwhk5-Z44XrpVsgAAAqo"]
[Tue Jul 21 07:26:42.069564 2026] [security2:error] [pid 230252:tid 230257] [remote 114.34.90.9:38428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.90.34.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9JYU0Dwhk5-Z44XrpVlwAC-AM"]
[Tue Jul 21 07:26:42.245660 2026] [http2:info] [pid 229246:tid 229456] [client 162.158.171.29:13219] AH10180: h2_stream(229246-1130-5,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 07:26:42.246639 2026] [security2:error] [pid 230252:tid 230447] [client 20.226.60.151:54508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/777.php"] [unique_id "al9JYk0Dwhk5-Z44XrpVtwAAAtg"]
[Tue Jul 21 07:26:42.296988 2026] [security2:error] [pid 230252:tid 230485] [client 45.8.17.105:43759] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/"] [unique_id "al9JYk0Dwhk5-Z44XrpVuAAAAv4"]
[Tue Jul 21 07:26:42.364484 2026] [security2:error] [pid 229246:tid 229479] [client 20.151.10.161:65470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/sss.php"] [unique_id "al9JYiBMYeh5YLVG45x6EgAAAns"]
[Tue Jul 21 07:26:42.533984 2026] [security2:error] [pid 230252:tid 230480] [client 74.249.245.134:54351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/gg.php"] [unique_id "al9JYk0Dwhk5-Z44XrpVuQAAAvk"]
[Tue Jul 21 07:26:42.560041 2026] [security2:error] [pid 230252:tid 230418] [client 4.204.201.85:26377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/buy.php"] [unique_id "al9JYk0Dwhk5-Z44XrpVuwAAArs"]
[Tue Jul 21 07:26:42.572306 2026] [http2:info] [pid 230252:tid 230465] [client 162.158.170.64:10937] AH10180: h2_stream(230252-1310-3,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 07:26:42.574007 2026] [security2:error] [pid 230252:tid 230436] [client 20.151.10.161:26438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9JYk0Dwhk5-Z44XrpVvAAAAs0"]
[Tue Jul 21 07:26:42.655407 2026] [security2:error] [pid 230252:tid 230471] [client 20.226.60.151:63349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/raw.php"] [unique_id "al9JYk0Dwhk5-Z44XrpVvQAAAvA"]
[Tue Jul 21 07:26:42.785572 2026] [security2:error] [pid 230252:tid 230452] [client 175.45.70.82:52070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JYk0Dwhk5-Z44XrpVvwAAAt0"]
[Tue Jul 21 07:26:42.785702 2026] [security2:error] [pid 230252:tid 230452] [client 175.45.70.82:52070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JYk0Dwhk5-Z44XrpVvwAAAt0"]
[Tue Jul 21 07:26:42.894248 2026] [security2:error] [pid 229246:tid 229341] [remote 173.212.252.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/wp-login.php"] [unique_id "al9JYiBMYeh5YLVG45x6GQACJ14"]
[Tue Jul 21 07:26:43.002145 2026] [security2:error] [pid 229246:tid 229482] [client 4.204.201.85:3311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/ssend.php"] [unique_id "al9JYyBMYeh5YLVG45x6HQAAAn4"]
[Tue Jul 21 07:26:43.043031 2026] [security2:error] [pid 229246:tid 229407] [client 20.220.225.223:38685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/mac.php"] [unique_id "al9JYyBMYeh5YLVG45x6HgAAAjM"]
[Tue Jul 21 07:26:43.097963 2026] [security2:error] [pid 230252:tid 230442] [client 45.8.17.144:37235] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/core.php"] [unique_id "al9JY00Dwhk5-Z44XrpVwwAAAtM"]
[Tue Jul 21 07:26:43.141166 2026] [security2:error] [pid 230252:tid 230385] [client 20.151.10.161:26522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/aaa.php"] [unique_id "al9JY00Dwhk5-Z44XrpVxQAAApo"]
[Tue Jul 21 07:26:43.402037 2026] [security2:error] [pid 230252:tid 230450] [client 154.192.233.199:60207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JY00Dwhk5-Z44XrpVyAAAAts"]
[Tue Jul 21 07:26:43.402197 2026] [security2:error] [pid 230252:tid 230450] [client 154.192.233.199:60207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JY00Dwhk5-Z44XrpVyAAAAts"]
[Tue Jul 21 07:26:43.437217 2026] [security2:error] [pid 230252:tid 230484] [client 74.249.245.134:62883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/sql.php"] [unique_id "al9JY00Dwhk5-Z44XrpVyQAAAv0"]
[Tue Jul 21 07:26:43.583046 2026] [security2:error] [pid 230252:tid 230473] [client 4.204.201.85:3257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/item.php"] [unique_id "al9JY00Dwhk5-Z44XrpVygAAAvI"]
[Tue Jul 21 07:26:43.731977 2026] [security2:error] [pid 230252:tid 230417] [client 20.52.136.55:1477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/amax.php"] [unique_id "al9JY00Dwhk5-Z44XrpVzQAAAro"]
[Tue Jul 21 07:26:43.918262 2026] [security2:error] [pid 230252:tid 230433] [client 20.104.96.117:59586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9JY00Dwhk5-Z44XrpVzgAAAso"]
[Tue Jul 21 07:26:44.121558 2026] [security2:error] [pid 230252:tid 230384] [client 152.59.154.239:49193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JYk0Dwhk5-Z44XrpVvgAAApk"]
[Tue Jul 21 07:26:44.560428 2026] [security2:error] [pid 230252:tid 230280] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JZE0Dwhk5-Z44XrpV2gAC2Bo"]
[Tue Jul 21 07:26:44.560583 2026] [security2:error] [pid 230252:tid 230447] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JZE0Dwhk5-Z44XrpV2gAC2Bo"]
[Tue Jul 21 07:26:44.562751 2026] [security2:error] [pid 230252:tid 230469] [client 4.204.201.85:3274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/ss.php"] [unique_id "al9JZE0Dwhk5-Z44XrpV2wAAAu4"]
[Tue Jul 21 07:26:44.917764 2026] [security2:error] [pid 230252:tid 230491] [client 82.102.28.107:56348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JZE0Dwhk5-Z44XrpV4wAAAwQ"]
[Tue Jul 21 07:26:44.917918 2026] [security2:error] [pid 230252:tid 230491] [client 82.102.28.107:56348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JZE0Dwhk5-Z44XrpV4wAAAwQ"]
[Tue Jul 21 07:26:44.956355 2026] [security2:error] [pid 230252:tid 230462] [client 193.36.225.67:65167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JZE0Dwhk5-Z44XrpV5AAAAuc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:45.147011 2026] [security2:error] [pid 230252:tid 230289] [remote 37.60.226.168:45352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.226.60.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fgengenharia.eng.br"] [uri "/wp-login.php"] [unique_id "al9JZU0Dwhk5-Z44XrpV5wADASM"]
[Tue Jul 21 07:26:45.279165 2026] [security2:error] [pid 229246:tid 229472] [client 45.8.17.119:33755] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "al9JZSBMYeh5YLVG45x6PwAAAnQ"]
[Tue Jul 21 07:26:45.409379 2026] [security2:error] [pid 230252:tid 230372] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JZU0Dwhk5-Z44XrpV6gACs3U"]
[Tue Jul 21 07:26:45.409618 2026] [security2:error] [pid 230252:tid 230410] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JZU0Dwhk5-Z44XrpV6gACs3U"]
[Tue Jul 21 07:26:45.538773 2026] [security2:error] [pid 229246:tid 229432] [client 20.220.225.223:46013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/hp2.php"] [unique_id "al9JZSBMYeh5YLVG45x6RQAAAkw"]
[Tue Jul 21 07:26:45.709052 2026] [security2:error] [pid 229246:tid 229443] [client 4.204.201.85:3280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/hypo.php"] [unique_id "al9JZSBMYeh5YLVG45x6SgAAAlc"]
[Tue Jul 21 07:26:45.979405 2026] [security2:error] [pid 229246:tid 229378] [client 20.226.60.151:54467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/for.php"] [unique_id "al9JZSBMYeh5YLVG45x6UQAAAhY"]
[Tue Jul 21 07:26:46.155949 2026] [security2:error] [pid 229246:tid 229496] [client 103.162.129.114:60535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JZiBMYeh5YLVG45x6VQAAAow"]
[Tue Jul 21 07:26:46.156077 2026] [security2:error] [pid 229246:tid 229496] [client 103.162.129.114:60535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JZiBMYeh5YLVG45x6VQAAAow"]
[Tue Jul 21 07:26:46.177920 2026] [security2:error] [pid 230252:tid 230440] [client 74.249.245.134:5556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/up.php"] [unique_id "al9JZk0Dwhk5-Z44XrpWBQAAAtE"]
[Tue Jul 21 07:26:46.276697 2026] [security2:error] [pid 229246:tid 229477] [client 20.151.10.161:65515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/sss.php"] [unique_id "al9JZiBMYeh5YLVG45x6WAAAAnk"]
[Tue Jul 21 07:26:46.286318 2026] [security2:error] [pid 230252:tid 230469] [client 45.8.17.121:38563] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/admin.php"] [unique_id "al9JZk0Dwhk5-Z44XrpWCAAAAu4"]
[Tue Jul 21 07:26:46.335898 2026] [security2:error] [pid 229246:tid 229481] [client 20.104.96.117:59601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/xyn.php"] [unique_id "al9JZiBMYeh5YLVG45x6WQAAAn0"]
[Tue Jul 21 07:26:46.439824 2026] [security2:error] [pid 229246:tid 229411] [client 103.174.34.15:61175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JZiBMYeh5YLVG45x6WgAAAjc"]
[Tue Jul 21 07:26:46.439995 2026] [security2:error] [pid 229246:tid 229411] [client 103.174.34.15:61175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JZiBMYeh5YLVG45x6WgAAAjc"]
[Tue Jul 21 07:26:46.490007 2026] [security2:error] [pid 230252:tid 230464] [client 213.152.162.104:58834] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JZk0Dwhk5-Z44XrpWCwAAAuk"]
[Tue Jul 21 07:26:46.490119 2026] [security2:error] [pid 230252:tid 230464] [client 213.152.162.104:58834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JZk0Dwhk5-Z44XrpWCwAAAuk"]
[Tue Jul 21 07:26:46.526566 2026] [security2:error] [pid 230252:tid 230451] [client 4.204.201.85:3319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/users.php"] [unique_id "al9JZk0Dwhk5-Z44XrpWDAAAAtw"]
[Tue Jul 21 07:26:46.918139 2026] [security2:error] [pid 229246:tid 229440] [client 4.204.201.85:26577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/177.php"] [unique_id "al9JZiBMYeh5YLVG45x6YAAAAlQ"]
[Tue Jul 21 07:26:47.011598 2026] [security2:error] [pid 229246:tid 229394] [client 74.7.230.49:48536] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "alvesmacedo.com"] [uri "/cgi-sys/404.html"] [unique_id "al9JZyBMYeh5YLVG45x6YQACJks"]
[Tue Jul 21 07:26:47.109406 2026] [security2:error] [pid 230252:tid 230294] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JZ00Dwhk5-Z44XrpWEgAC0yg"]
[Tue Jul 21 07:26:47.109601 2026] [security2:error] [pid 230252:tid 230442] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JZ00Dwhk5-Z44XrpWEgAC0yg"]
[Tue Jul 21 07:26:47.193644 2026] [security2:error] [pid 229246:tid 229499] [client 45.8.17.118:42969] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/goods.php"] [unique_id "al9JZyBMYeh5YLVG45x6ZQAAAo8"]
[Tue Jul 21 07:26:47.267602 2026] [security2:error] [pid 230252:tid 230392] [client 4.204.201.85:3260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/config.php"] [unique_id "al9JZ00Dwhk5-Z44XrpWFAAAAqE"]
[Tue Jul 21 07:26:47.276490 2026] [security2:error] [pid 229246:tid 229433] [client 139.135.44.145:53459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JZyBMYeh5YLVG45x6ZwAAAk0"]
[Tue Jul 21 07:26:47.276589 2026] [security2:error] [pid 229246:tid 229433] [client 139.135.44.145:53459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JZyBMYeh5YLVG45x6ZwAAAk0"]
[Tue Jul 21 07:26:47.560622 2026] [security2:error] [pid 229246:tid 229380] [client 20.104.96.117:59798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/patie.php"] [unique_id "al9JZyBMYeh5YLVG45x6bAAAAhg"]
[Tue Jul 21 07:26:47.787445 2026] [security2:error] [pid 230252:tid 230477] [client 4.204.201.85:3312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/gettest.php"] [unique_id "al9JZ00Dwhk5-Z44XrpWFQAAAvY"]
[Tue Jul 21 07:26:48.086692 2026] [security2:error] [pid 230252:tid 230474] [client 20.220.225.223:45403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/hp3.php"] [unique_id "al9JaE0Dwhk5-Z44XrpWGwAAAvM"]
[Tue Jul 21 07:26:48.269240 2026] [security2:error] [pid 230252:tid 230478] [client 4.204.201.85:3285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/min.php"] [unique_id "al9JaE0Dwhk5-Z44XrpWIQAAAvc"]
[Tue Jul 21 07:26:48.341993 2026] [security2:error] [pid 229246:tid 229476] [client 20.220.225.223:31168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/samll.php"] [unique_id "al9JaCBMYeh5YLVG45x6dQAAAng"]
[Tue Jul 21 07:26:48.507229 2026] [security2:error] [pid 230252:tid 230416] [client 117.251.86.144:48712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JaE0Dwhk5-Z44XrpWJgAAArk"]
[Tue Jul 21 07:26:48.507376 2026] [security2:error] [pid 230252:tid 230416] [client 117.251.86.144:48712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JaE0Dwhk5-Z44XrpWJgAAArk"]
[Tue Jul 21 07:26:48.572519 2026] [security2:error] [pid 230252:tid 230467] [client 20.104.96.117:59602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/aa.php"] [unique_id "al9JaE0Dwhk5-Z44XrpWJwAAAuw"]
[Tue Jul 21 07:26:48.600802 2026] [security2:error] [pid 229246:tid 229423] [client 4.204.201.85:26606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/dvjul.php"] [unique_id "al9JaCBMYeh5YLVG45x6ewAAAkM"]
[Tue Jul 21 07:26:48.755514 2026] [security2:error] [pid 230252:tid 230451] [client 74.249.245.134:54361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/66.php"] [unique_id "al9JaE0Dwhk5-Z44XrpWLAAAAtw"]
[Tue Jul 21 07:26:48.987957 2026] [security2:error] [pid 230252:tid 230491] [client 45.8.17.64:25723] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/edit-tags.php"] [unique_id "al9JaE0Dwhk5-Z44XrpWMgAAAwQ"]
[Tue Jul 21 07:26:49.088440 2026] [security2:error] [pid 230252:tid 230439] [client 20.226.60.151:61086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/ssla.php"] [unique_id "al9JaU0Dwhk5-Z44XrpWOAAAAtA"]
[Tue Jul 21 07:26:49.412698 2026] [security2:error] [pid 229246:tid 229456] [client 20.104.96.117:59818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/xwpg.php"] [unique_id "al9JaSBMYeh5YLVG45x6hAAAAmQ"]
[Tue Jul 21 07:26:49.641590 2026] [security2:error] [pid 230252:tid 230430] [client 20.151.10.161:65462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/c.php"] [unique_id "al9JaU0Dwhk5-Z44XrpWOgAAAsc"]
[Tue Jul 21 07:26:49.654203 2026] [security2:error] [pid 230252:tid 230306] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JaU0Dwhk5-Z44XrpWOwACnTQ"]
[Tue Jul 21 07:26:49.654327 2026] [security2:error] [pid 230252:tid 230388] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JaU0Dwhk5-Z44XrpWOwACnTQ"]
[Tue Jul 21 07:26:49.654778 2026] [security2:error] [pid 230252:tid 230484] [client 4.204.201.85:3320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/biufile.php"] [unique_id "al9JaU0Dwhk5-Z44XrpWPAAAAv0"]
[Tue Jul 21 07:26:49.660796 2026] [security2:error] [pid 230252:tid 230477] [client 213.152.162.104:42142] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9JaU0Dwhk5-Z44XrpWPQAAAvY"]
[Tue Jul 21 07:26:49.660909 2026] [security2:error] [pid 230252:tid 230477] [client 213.152.162.104:42142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9JaU0Dwhk5-Z44XrpWPQAAAvY"]
[Tue Jul 21 07:26:49.704856 2026] [security2:error] [pid 230252:tid 230374] [remote 182.77.62.24:60756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-login.php"] [unique_id "al9JaU0Dwhk5-Z44XrpWPwACy3c"]
[Tue Jul 21 07:26:49.744039 2026] [security2:error] [pid 230252:tid 230473] [client 193.36.225.73:36805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JaU0Dwhk5-Z44XrpWQwAAAvI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:49.827176 2026] [access_compat:error] [pid 230252:tid 230419] [client 162.241.63.68:57584] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:26:49.848921 2026] [security2:error] [pid 229246:tid 229303] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9JaSBMYeh5YLVG45x6iQACjDg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:26:49.861135 2026] [security2:error] [pid 229246:tid 229257] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9JaSBMYeh5YLVG45x6iwACego"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:26:49.868891 2026] [security2:error] [pid 230252:tid 230329] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9JaU0Dwhk5-Z44XrpWQAAC0ko"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:26:49.887885 2026] [security2:error] [pid 230252:tid 230288] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9JaU0Dwhk5-Z44XrpWQgAC6CI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:26:50.108522 2026] [security2:error] [pid 230252:tid 230346] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWTwAC11s"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:26:50.284962 2026] [security2:error] [pid 230252:tid 230464] [client 45.8.17.127:56373] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/filemanager.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWUQAAAuk"]
[Tue Jul 21 07:26:50.344254 2026] [security2:error] [pid 230252:tid 230254] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWUgAC6gA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:26:50.411276 2026] [security2:error] [pid 230252:tid 230480] [client 20.104.96.117:59835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/ops.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWVAAAAvk"]
[Tue Jul 21 07:26:50.429097 2026] [security2:error] [pid 230252:tid 230379] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWVQAC63w"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:26:50.434426 2026] [security2:error] [pid 230252:tid 230508] [client 4.204.201.85:3265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/av.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWVgAAAxU"]
[Tue Jul 21 07:26:50.449023 2026] [security2:error] [pid 229246:tid 229467] [client 59.96.220.140:63064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JaiBMYeh5YLVG45x6kgAAAm8"]
[Tue Jul 21 07:26:50.449160 2026] [security2:error] [pid 229246:tid 229467] [client 59.96.220.140:63064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JaiBMYeh5YLVG45x6kgAAAm8"]
[Tue Jul 21 07:26:50.460308 2026] [security2:error] [pid 230252:tid 230339] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWVwAC0VQ"]
[Tue Jul 21 07:26:50.460511 2026] [security2:error] [pid 230252:tid 230440] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWVwAC0VQ"]
[Tue Jul 21 07:26:50.467222 2026] [security2:error] [pid 230252:tid 230354] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWWAADBWM"]
[Tue Jul 21 07:26:50.467394 2026] [security2:error] [pid 230252:tid 230492] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWWAADBWM"]
[Tue Jul 21 07:26:50.511337 2026] [security2:error] [pid 230252:tid 230371] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWWgAC5nQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:26:50.531044 2026] [security2:error] [pid 229246:tid 229339] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9JaiBMYeh5YLVG45x6lgAChlw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:26:50.626310 2026] [security2:error] [pid 230252:tid 230490] [client 20.52.136.55:1594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/moon.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWWwAAAwM"]
[Tue Jul 21 07:26:50.807919 2026] [security2:error] [pid 230252:tid 230419] [client 20.226.60.151:61062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/zc-131.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWXAAAArw"]
[Tue Jul 21 07:26:51.007968 2026] [security2:error] [pid 230252:tid 230471] [client 45.251.232.145:65485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ja00Dwhk5-Z44XrpWXQAAAvA"]
[Tue Jul 21 07:26:51.008110 2026] [security2:error] [pid 230252:tid 230471] [client 45.251.232.145:65485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ja00Dwhk5-Z44XrpWXQAAAvA"]
[Tue Jul 21 07:26:51.014292 2026] [security2:error] [pid 229246:tid 229444] [client 20.220.225.223:60368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9JayBMYeh5YLVG45x6nQAAAlg"]
[Tue Jul 21 07:26:51.071694 2026] [security2:error] [pid 229246:tid 229491] [client 20.104.96.117:59787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/mac.php"] [unique_id "al9JayBMYeh5YLVG45x6ngAAAoc"]
[Tue Jul 21 07:26:51.183289 2026] [security2:error] [pid 229246:tid 229385] [client 45.8.17.136:21381] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/"] [unique_id "al9JayBMYeh5YLVG45x6nwAAAh0"]
[Tue Jul 21 07:26:51.219193 2026] [security2:error] [pid 229246:tid 229383] [client 4.204.201.85:3237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/coffexium.php"] [unique_id "al9JayBMYeh5YLVG45x6oAAAAhs"]
[Tue Jul 21 07:26:51.251931 2026] [security2:error] [pid 229246:tid 229406] [client 74.249.245.134:54381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/666.php"] [unique_id "al9JayBMYeh5YLVG45x6oQAAAjI"]
[Tue Jul 21 07:26:51.365871 2026] [security2:error] [pid 230252:tid 230382] [remote 72.167.132.114:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cromobelo.com.br"] [uri "/wp-login.php"] [unique_id "al9Ja00Dwhk5-Z44XrpWXwAC-H8"]
[Tue Jul 21 07:26:51.451550 2026] [security2:error] [pid 229246:tid 229470] [client 173.252.95.6:47944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9JayBMYeh5YLVG45x6owAAAnI"]
[Tue Jul 21 07:26:51.600750 2026] [security2:error] [pid 229246:tid 229417] [client 20.151.10.161:63710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/aa.php"] [unique_id "al9JayBMYeh5YLVG45x6pwAAAj0"]
[Tue Jul 21 07:26:51.630138 2026] [security2:error] [pid 229246:tid 229451] [client 4.204.201.85:3224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/core.php"] [unique_id "al9JayBMYeh5YLVG45x6qAAAAl8"]
[Tue Jul 21 07:26:51.778844 2026] [security2:error] [pid 229246:tid 229483] [client 20.104.96.117:59830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/mg.php"] [unique_id "al9JayBMYeh5YLVG45x6qgAAAn8"]
[Tue Jul 21 07:26:51.852385 2026] [security2:error] [pid 229246:tid 229493] [client 103.106.20.201:65254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JayBMYeh5YLVG45x6qwAAAok"]
[Tue Jul 21 07:26:51.852509 2026] [security2:error] [pid 229246:tid 229493] [client 103.106.20.201:65254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JayBMYeh5YLVG45x6qwAAAok"]
[Tue Jul 21 07:26:52.211135 2026] [security2:error] [pid 229246:tid 229456] [client 20.220.225.223:48547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/aa1.php"] [unique_id "al9JbCBMYeh5YLVG45x6sQAAAmQ"]
[Tue Jul 21 07:26:52.279362 2026] [security2:error] [pid 230252:tid 230418] [client 4.204.201.85:3233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/als.php"] [unique_id "al9JbE0Dwhk5-Z44XrpWZAAAArs"]
[Tue Jul 21 07:26:52.388675 2026] [security2:error] [pid 230252:tid 230451] [client 45.8.17.144:41915] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-config-sample.php"] [unique_id "al9JbE0Dwhk5-Z44XrpWZgAAAtw"]
[Tue Jul 21 07:26:52.414045 2026] [security2:error] [pid 230252:tid 230364] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JbE0Dwhk5-Z44XrpWZwAC2G0"]
[Tue Jul 21 07:26:52.414230 2026] [security2:error] [pid 230252:tid 230447] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JbE0Dwhk5-Z44XrpWZwAC2G0"]
[Tue Jul 21 07:26:52.579971 2026] [security2:error] [pid 230252:tid 230480] [client 4.204.201.85:3227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/simple.php"] [unique_id "al9JbE0Dwhk5-Z44XrpWagAAAvk"]
[Tue Jul 21 07:26:52.802393 2026] [security2:error] [pid 230252:tid 230499] [client 103.174.34.15:61664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JbE0Dwhk5-Z44XrpWbAAAAww"]
[Tue Jul 21 07:26:52.802529 2026] [security2:error] [pid 230252:tid 230499] [client 103.174.34.15:61664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JbE0Dwhk5-Z44XrpWbAAAAww"]
[Tue Jul 21 07:26:52.863636 2026] [security2:error] [pid 230252:tid 230406] [client 20.151.10.161:49083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/themes.php"] [unique_id "al9JbE0Dwhk5-Z44XrpWbQAAAq8"]
[Tue Jul 21 07:26:52.898807 2026] [security2:error] [pid 230252:tid 230400] [client 20.104.96.117:59614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-post-data.php"] [unique_id "al9JbE0Dwhk5-Z44XrpWbgAAAqk"]
[Tue Jul 21 07:26:52.901233 2026] [security2:error] [pid 230252:tid 230494] [client 20.151.10.161:65475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/100.php"] [unique_id "al9JbE0Dwhk5-Z44XrpWbwAAAwc"]
[Tue Jul 21 07:26:53.029377 2026] [security2:error] [pid 230252:tid 230410] [client 4.204.201.85:3215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/init.php"] [unique_id "al9JbU0Dwhk5-Z44XrpWcgAAArM"]
[Tue Jul 21 07:26:53.189775 2026] [security2:error] [pid 229246:tid 229435] [client 74.249.245.134:54376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/byp.php"] [unique_id "al9JbSBMYeh5YLVG45x6vgAAAk8"]
[Tue Jul 21 07:26:53.385919 2026] [security2:error] [pid 230252:tid 230477] [client 45.8.17.144:21349] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/enhanced-text-widget/analyst/src/403.php"] [unique_id "al9JbU0Dwhk5-Z44XrpWdQAAAvY"]
[Tue Jul 21 07:26:53.426671 2026] [security2:error] [pid 230252:tid 230420] [client 20.220.225.223:60357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9JbU0Dwhk5-Z44XrpWdgAAAr0"]
[Tue Jul 21 07:26:53.438350 2026] [security2:error] [pid 230252:tid 230466] [client 175.45.70.82:52579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JbU0Dwhk5-Z44XrpWdwAAAus"]
[Tue Jul 21 07:26:53.438470 2026] [security2:error] [pid 230252:tid 230466] [client 175.45.70.82:52579] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JbU0Dwhk5-Z44XrpWdwAAAus"]
[Tue Jul 21 07:26:53.769327 2026] [security2:error] [pid 230252:tid 230468] [client 4.204.201.85:26560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/fpwch.php"] [unique_id "al9JbU0Dwhk5-Z44XrpWfgAAAu0"]
[Tue Jul 21 07:26:53.879716 2026] [security2:error] [pid 229246:tid 229466] [client 20.104.96.117:59603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/pucci.php"] [unique_id "al9JbSBMYeh5YLVG45x6wgAAAm4"]
[Tue Jul 21 07:26:54.138845 2026] [security2:error] [pid 230252:tid 230501] [client 154.192.233.199:58783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jbk0Dwhk5-Z44XrpWgAAAAw4"]
[Tue Jul 21 07:26:54.138979 2026] [security2:error] [pid 230252:tid 230501] [client 154.192.233.199:58783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jbk0Dwhk5-Z44XrpWgAAAAw4"]
[Tue Jul 21 07:26:54.290998 2026] [security2:error] [pid 230252:tid 230511] [client 4.204.201.85:26597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/domvf.php"] [unique_id "al9Jbk0Dwhk5-Z44XrpWggAAAxg"]
[Tue Jul 21 07:26:54.291718 2026] [security2:error] [pid 230252:tid 230500] [client 152.59.154.239:49583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jbk0Dwhk5-Z44XrpWgQAAAw0"]
[Tue Jul 21 07:26:54.461365 2026] [security2:error] [pid 230252:tid 230395] [client 20.220.225.223:45975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/acew67.php"] [unique_id "al9Jbk0Dwhk5-Z44XrpWhQAAAqQ"]
[Tue Jul 21 07:26:54.589885 2026] [security2:error] [pid 230252:tid 230408] [client 45.8.17.57:20859] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "al9Jbk0Dwhk5-Z44XrpWhgAAArE"]
[Tue Jul 21 07:26:54.590421 2026] [security2:error] [pid 230252:tid 230493] [client 136.144.33.102:26809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Jbk0Dwhk5-Z44XrpWhwAAAwY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:54.970843 2026] [security2:error] [pid 230252:tid 230393] [client 4.204.201.85:26616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/wp.php"] [unique_id "al9Jbk0Dwhk5-Z44XrpWjAAAAqI"]
[Tue Jul 21 07:26:54.977944 2026] [security2:error] [pid 230252:tid 230418] [client 20.104.96.117:59781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/black.php"] [unique_id "al9Jbk0Dwhk5-Z44XrpWjQAAArs"]
[Tue Jul 21 07:26:55.077159 2026] [security2:error] [pid 230252:tid 230447] [client 20.52.136.55:1756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/ws83.php"] [unique_id "al9Jb00Dwhk5-Z44XrpWjgAAAtg"]
[Tue Jul 21 07:26:55.103487 2026] [security2:error] [pid 229246:tid 229292] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JbyBMYeh5YLVG45x61QACaC0"]
[Tue Jul 21 07:26:55.103619 2026] [security2:error] [pid 229246:tid 229460] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JbyBMYeh5YLVG45x61QACaC0"]
[Tue Jul 21 07:26:55.132040 2026] [security2:error] [pid 230252:tid 230396] [client 74.249.245.134:5563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/date.php"] [unique_id "al9Jb00Dwhk5-Z44XrpWjwAAAqU"]
[Tue Jul 21 07:26:55.436451 2026] [security2:error] [pid 229246:tid 229401] [client 20.220.225.223:38667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/abcd.php"] [unique_id "al9JbyBMYeh5YLVG45x64wAAAi0"]
[Tue Jul 21 07:26:55.546758 2026] [security2:error] [pid 230252:tid 230440] [client 213.152.162.104:42150] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Jb00Dwhk5-Z44XrpWkwAAAtE"]
[Tue Jul 21 07:26:55.546897 2026] [security2:error] [pid 230252:tid 230440] [client 213.152.162.104:42150] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Jb00Dwhk5-Z44XrpWkwAAAtE"]
[Tue Jul 21 07:26:55.546930 2026] [security2:error] [pid 230252:tid 230440] [client 213.152.162.104:42150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Jb00Dwhk5-Z44XrpWkwAAAtE"]
[Tue Jul 21 07:26:55.649346 2026] [security2:error] [pid 229246:tid 229474] [client 4.204.201.85:26579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/class.php"] [unique_id "al9JbyBMYeh5YLVG45x65wAAAnY"]
[Tue Jul 21 07:26:55.734518 2026] [security2:error] [pid 229246:tid 229432] [client 20.151.10.161:63679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/footer.php"] [unique_id "al9JbyBMYeh5YLVG45x67AAAAkw"]
[Tue Jul 21 07:26:55.742890 2026] [security2:error] [pid 229246:tid 229476] [client 20.220.225.223:53488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/wander.php"] [unique_id "al9JbyBMYeh5YLVG45x67QAAAng"]
[Tue Jul 21 07:26:56.092616 2026] [security2:error] [pid 229246:tid 229290] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JcCBMYeh5YLVG45x69wACeis"]
[Tue Jul 21 07:26:56.092789 2026] [security2:error] [pid 229246:tid 229478] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JcCBMYeh5YLVG45x69wACeis"]
[Tue Jul 21 07:26:56.100065 2026] [security2:error] [pid 229246:tid 229395] [client 20.104.96.117:59621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/zlece.php"] [unique_id "al9JcCBMYeh5YLVG45x6-AAAAic"]
[Tue Jul 21 07:26:56.225546 2026] [security2:error] [pid 229246:tid 229435] [client 4.204.201.85:3275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/echkm.php"] [unique_id "al9JcCBMYeh5YLVG45x6-wAAAk8"]
[Tue Jul 21 07:26:56.600572 2026] [security2:error] [pid 229246:tid 229467] [client 4.204.201.85:3325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/lib.php"] [unique_id "al9JcCBMYeh5YLVG45x7AQAAAm8"]
[Tue Jul 21 07:26:56.613188 2026] [security2:error] [pid 229246:tid 229439] [client 20.104.96.117:59824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/vssrs.php"] [unique_id "al9JcCBMYeh5YLVG45x7AgAAAlM"]
[Tue Jul 21 07:26:56.695056 2026] [autoindex:error] [pid 230252:tid 230496] [client 198.235.24.37:63908] AH01276: Cannot serve directory /home1/siteec36/vcacesorios.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:26:56.833677 2026] [security2:error] [pid 230252:tid 230443] [client 103.162.129.114:61184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JcE0Dwhk5-Z44XrpWlwAAAtQ"]
[Tue Jul 21 07:26:56.833821 2026] [security2:error] [pid 230252:tid 230443] [client 103.162.129.114:61184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JcE0Dwhk5-Z44XrpWlwAAAtQ"]
[Tue Jul 21 07:26:57.043706 2026] [security2:error] [pid 230252:tid 230459] [client 4.204.201.85:3277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/login.php"] [unique_id "al9JcU0Dwhk5-Z44XrpWmQAAAuQ"]
[Tue Jul 21 07:26:57.241073 2026] [security2:error] [pid 229246:tid 229499] [client 74.249.245.134:54389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/pomo.php"] [unique_id "al9JcSBMYeh5YLVG45x7CQAAAo8"]
[Tue Jul 21 07:26:57.255685 2026] [security2:error] [pid 230252:tid 230386] [client 20.220.225.223:53457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/jga.php"] [unique_id "al9JcU0Dwhk5-Z44XrpWmwAAAps"]
[Tue Jul 21 07:26:57.322180 2026] [security2:error] [pid 230252:tid 230434] [client 82.102.28.107:50200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JcU0Dwhk5-Z44XrpWnQAAAss"]
[Tue Jul 21 07:26:57.322260 2026] [security2:error] [pid 230252:tid 230434] [client 82.102.28.107:50200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JcU0Dwhk5-Z44XrpWnQAAAss"]
[Tue Jul 21 07:26:57.463871 2026] [security2:error] [pid 230252:tid 230476] [client 4.204.201.85:3327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/a2.php"] [unique_id "al9JcU0Dwhk5-Z44XrpWngAAAvU"]
[Tue Jul 21 07:26:57.658390 2026] [security2:error] [pid 230252:tid 230301] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JcU0Dwhk5-Z44XrpWnwAC8i8"]
[Tue Jul 21 07:26:57.658523 2026] [security2:error] [pid 230252:tid 230473] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JcU0Dwhk5-Z44XrpWnwAC8i8"]
[Tue Jul 21 07:26:57.739566 2026] [security2:error] [pid 229246:tid 229460] [client 20.151.10.161:63732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/users.php"] [unique_id "al9JcSBMYeh5YLVG45x7EAAAAmg"]
[Tue Jul 21 07:26:57.900634 2026] [security2:error] [pid 229246:tid 229465] [client 4.204.201.85:26376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/d61.php"] [unique_id "al9JcSBMYeh5YLVG45x7EwAAAm0"]
[Tue Jul 21 07:26:57.985146 2026] [security2:error] [pid 229246:tid 229383] [client 45.8.17.139:54341] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/"] [unique_id "al9JcSBMYeh5YLVG45x7FAAAAhs"]
[Tue Jul 21 07:26:58.070377 2026] [security2:error] [pid 230252:tid 230458] [client 139.135.44.145:54259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Jck0Dwhk5-Z44XrpWpAAAAuM"]
[Tue Jul 21 07:26:58.070512 2026] [security2:error] [pid 230252:tid 230458] [client 139.135.44.145:54259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Jck0Dwhk5-Z44XrpWpAAAAuM"]
[Tue Jul 21 07:26:58.378636 2026] [security2:error] [pid 229246:tid 229386] [client 4.204.201.85:3314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/info.php"] [unique_id "al9JciBMYeh5YLVG45x7FwAAAh4"]
[Tue Jul 21 07:26:58.450624 2026] [security2:error] [pid 230252:tid 230403] [client 136.144.33.106:21503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Jck0Dwhk5-Z44XrpWqQAAAqw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:58.751298 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:65490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/177.php"] [unique_id "al9Jck0Dwhk5-Z44XrpWqwAAAwY"]
[Tue Jul 21 07:26:58.781116 2026] [security2:error] [pid 230252:tid 230467] [client 45.8.17.108:45315] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/item.php"] [unique_id "al9Jck0Dwhk5-Z44XrpWrQAAAuw"]
[Tue Jul 21 07:26:58.853218 2026] [security2:error] [pid 230252:tid 230397] [client 20.104.96.117:59822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wicked.php"] [unique_id "al9Jck0Dwhk5-Z44XrpWrgAAAqY"]
[Tue Jul 21 07:26:59.042337 2026] [security2:error] [pid 229246:tid 229451] [client 20.220.225.223:53471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/x.php"] [unique_id "al9JcyBMYeh5YLVG45x7HQAAAl8"]
[Tue Jul 21 07:26:59.098870 2026] [security2:error] [pid 230252:tid 230462] [client 4.204.201.85:26564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/11.php"] [unique_id "al9Jc00Dwhk5-Z44XrpWswAAAuc"]
[Tue Jul 21 07:26:59.323176 2026] [security2:error] [pid 230252:tid 230395] [client 117.251.86.144:45498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Jc00Dwhk5-Z44XrpWtgAAAqQ"]
[Tue Jul 21 07:26:59.323366 2026] [security2:error] [pid 230252:tid 230395] [client 117.251.86.144:45498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Jc00Dwhk5-Z44XrpWtgAAAqQ"]
[Tue Jul 21 07:26:59.530539 2026] [security2:error] [pid 230252:tid 230423] [client 20.52.136.55:1591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/CDX1.php"] [unique_id "al9Jc00Dwhk5-Z44XrpWuQAAAsA"]
[Tue Jul 21 07:26:59.762792 2026] [security2:error] [pid 230252:tid 230400] [client 20.151.10.161:63622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/config.php"] [unique_id "al9Jc00Dwhk5-Z44XrpWvwAAAqk"]
[Tue Jul 21 07:26:59.889132 2026] [security2:error] [pid 229246:tid 229436] [client 45.8.17.135:53359] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/adminfuns.php"] [unique_id "al9JcyBMYeh5YLVG45x7JgAAAlA"]
[Tue Jul 21 07:26:59.892689 2026] [security2:error] [pid 230252:tid 230279] [remote 41.76.214.143:60422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reserveseulugar.com.br"] [uri "/wp-login.php"] [unique_id "al9Jc00Dwhk5-Z44XrpWwgACpxk"]
[Tue Jul 21 07:27:00.036500 2026] [security2:error] [pid 230252:tid 230488] [client 4.204.201.85:3255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/v2.php"] [unique_id "al9JdE0Dwhk5-Z44XrpWxAAAAwE"]
[Tue Jul 21 07:27:00.298543 2026] [security2:error] [pid 230252:tid 230443] [client 20.220.225.223:27140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9JdE0Dwhk5-Z44XrpWxgAAAtQ"]
[Tue Jul 21 07:27:00.433768 2026] [security2:error] [pid 230252:tid 230503] [client 20.151.10.161:63731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/gettest.php"] [unique_id "al9JdE0Dwhk5-Z44XrpWyAAAAxA"]
[Tue Jul 21 07:27:00.862393 2026] [security2:error] [pid 229246:tid 229430] [client 4.204.201.85:26614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/panel.php"] [unique_id "al9JdCBMYeh5YLVG45x7LgAAAko"]
[Tue Jul 21 07:27:00.921917 2026] [security2:error] [pid 229246:tid 229291] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JdCBMYeh5YLVG45x7MAACRCw"]
[Tue Jul 21 07:27:00.922144 2026] [security2:error] [pid 229246:tid 229424] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JdCBMYeh5YLVG45x7MAACRCw"]
[Tue Jul 21 07:27:00.986224 2026] [security2:error] [pid 229246:tid 229421] [client 45.8.17.107:60215] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wpx/"] [unique_id "al9JdCBMYeh5YLVG45x7MwAAAkE"]
[Tue Jul 21 07:27:00.993369 2026] [security2:error] [pid 229246:tid 229256] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JdCBMYeh5YLVG45x7NAACgwk"]
[Tue Jul 21 07:27:00.993550 2026] [security2:error] [pid 229246:tid 229487] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JdCBMYeh5YLVG45x7NAACgwk"]
[Tue Jul 21 07:27:01.116893 2026] [security2:error] [pid 229246:tid 229264] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JdSBMYeh5YLVG45x7NQACbxE"]
[Tue Jul 21 07:27:01.117048 2026] [security2:error] [pid 229246:tid 229467] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JdSBMYeh5YLVG45x7NQACbxE"]
[Tue Jul 21 07:27:01.142174 2026] [security2:error] [pid 229246:tid 229382] [client 82.102.28.107:46258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9JdSBMYeh5YLVG45x7NgAAAho"]
[Tue Jul 21 07:27:01.142291 2026] [security2:error] [pid 229246:tid 229382] [client 82.102.28.107:46258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9JdSBMYeh5YLVG45x7NgAAAho"]
[Tue Jul 21 07:27:01.302212 2026] [security2:error] [pid 230252:tid 230501] [client 4.204.201.85:26586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/dex.php"] [unique_id "al9JdU0Dwhk5-Z44XrpW0gAAAw4"]
[Tue Jul 21 07:27:01.471673 2026] [security2:error] [pid 229246:tid 229402] [client 45.251.232.145:49616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JdSBMYeh5YLVG45x7PgAAAi4"]
[Tue Jul 21 07:27:01.471789 2026] [security2:error] [pid 229246:tid 229402] [client 45.251.232.145:49616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JdSBMYeh5YLVG45x7PgAAAi4"]
[Tue Jul 21 07:27:01.490250 2026] [security2:error] [pid 229246:tid 229388] [client 213.152.162.104:41670] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9JdSBMYeh5YLVG45x7PwAAAiA"]
[Tue Jul 21 07:27:01.490341 2026] [security2:error] [pid 229246:tid 229388] [client 213.152.162.104:41670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9JdSBMYeh5YLVG45x7PwAAAiA"]
[Tue Jul 21 07:27:01.798653 2026] [security2:error] [pid 230252:tid 230276] [remote 57.141.18.82:45856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemape.xml"] [unique_id "al9JdU0Dwhk5-Z44XrpW1gACtBY"]
[Tue Jul 21 07:27:01.823286 2026] [security2:error] [pid 230252:tid 230384] [client 4.204.201.85:3264] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "bcaccj.org"] [uri "/1.php"] [unique_id "al9JdU0Dwhk5-Z44XrpW1wAAApk"]
[Tue Jul 21 07:27:01.823390 2026] [security2:error] [pid 230252:tid 230384] [client 4.204.201.85:3264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/1.php"] [unique_id "al9JdU0Dwhk5-Z44XrpW1wAAApk"]
[Tue Jul 21 07:27:02.080675 2026] [security2:error] [pid 230252:tid 230505] [client 20.151.10.161:65437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/min.php"] [unique_id "al9Jdk0Dwhk5-Z44XrpW4AAAAxI"]
[Tue Jul 21 07:27:02.090680 2026] [security2:error] [pid 230252:tid 230447] [client 45.8.17.142:61523] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/files.php"] [unique_id "al9Jdk0Dwhk5-Z44XrpW4QAAAtg"]
[Tue Jul 21 07:27:02.172198 2026] [security2:error] [pid 229246:tid 229479] [client 59.96.220.140:63496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JdiBMYeh5YLVG45x7UwAAAns"]
[Tue Jul 21 07:27:02.172328 2026] [security2:error] [pid 229246:tid 229479] [client 59.96.220.140:63496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JdiBMYeh5YLVG45x7UwAAAns"]
[Tue Jul 21 07:27:02.329359 2026] [security2:error] [pid 230252:tid 230423] [client 74.249.245.134:54349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/test1.php"] [unique_id "al9Jdk0Dwhk5-Z44XrpW5AAAAsA"]
[Tue Jul 21 07:27:02.916695 2026] [security2:error] [pid 230252:tid 230292] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Jdk0Dwhk5-Z44XrpW6wAC0yY"]
[Tue Jul 21 07:27:02.916832 2026] [security2:error] [pid 230252:tid 230442] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Jdk0Dwhk5-Z44XrpW6wAC0yY"]
[Tue Jul 21 07:27:02.964827 2026] [security2:error] [pid 229246:tid 229400] [client 136.144.33.109:60869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JdiBMYeh5YLVG45x7agAAAiw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:27:03.021067 2026] [security2:error] [pid 230252:tid 230402] [client 103.106.20.201:49701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jd00Dwhk5-Z44XrpW7QAAAqs"]
[Tue Jul 21 07:27:03.021228 2026] [security2:error] [pid 230252:tid 230402] [client 103.106.20.201:49701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jd00Dwhk5-Z44XrpW7QAAAqs"]
[Tue Jul 21 07:27:03.045706 2026] [security2:error] [pid 230252:tid 230490] [client 4.204.201.85:26622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/ms.php"] [unique_id "al9Jd00Dwhk5-Z44XrpW7gAAAwM"]
[Tue Jul 21 07:27:03.090143 2026] [security2:error] [pid 229246:tid 229430] [client 45.8.17.128:44175] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/news-portal/zdata.php"] [unique_id "al9JdyBMYeh5YLVG45x7cgAAAko"]
[Tue Jul 21 07:27:03.100574 2026] [security2:error] [pid 229246:tid 229435] [client 20.151.10.161:63705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/edorxrr.php"] [unique_id "al9JdyBMYeh5YLVG45x7dAAAAk8"]
[Tue Jul 21 07:27:03.842293 2026] [security2:error] [pid 229246:tid 229421] [client 103.174.34.15:62151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JdyBMYeh5YLVG45x7jQAAAkE"]
[Tue Jul 21 07:27:03.842614 2026] [security2:error] [pid 229246:tid 229421] [client 103.174.34.15:62151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JdyBMYeh5YLVG45x7jQAAAkE"]
[Tue Jul 21 07:27:03.887496 2026] [security2:error] [pid 230252:tid 230473] [client 45.8.17.60:63157] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/css/"] [unique_id "al9Jd00Dwhk5-Z44XrpW9wAAAvI"]
[Tue Jul 21 07:27:04.196014 2026] [security2:error] [pid 229246:tid 229392] [client 4.204.201.85:3304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/memberfuns.php"] [unique_id "al9JeCBMYeh5YLVG45x7mQAAAiQ"]
[Tue Jul 21 07:27:04.289518 2026] [security2:error] [pid 229246:tid 229415] [client 175.45.70.82:53097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JeCBMYeh5YLVG45x7ngAAAjs"]
[Tue Jul 21 07:27:04.289614 2026] [security2:error] [pid 229246:tid 229415] [client 175.45.70.82:53097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JeCBMYeh5YLVG45x7ngAAAjs"]
[Tue Jul 21 07:27:04.397383 2026] [security2:error] [pid 230252:tid 230501] [client 20.104.96.117:59588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/24.php"] [unique_id "al9JeE0Dwhk5-Z44XrpW-wAAAw4"]
[Tue Jul 21 07:27:04.566125 2026] [security2:error] [pid 230252:tid 230455] [client 20.220.225.223:46015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/bscclapb.php"] [unique_id "al9JeE0Dwhk5-Z44XrpW_AAAAuA"]
[Tue Jul 21 07:27:04.573852 2026] [security2:error] [pid 230252:tid 230424] [client 20.151.10.161:63067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/hur.php"] [unique_id "al9JeE0Dwhk5-Z44XrpW_QAAAsE"]
[Tue Jul 21 07:27:04.578290 2026] [security2:error] [pid 230252:tid 230453] [client 4.204.201.85:3274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/0.php"] [unique_id "al9JeE0Dwhk5-Z44XrpW_gAAAt4"]
[Tue Jul 21 07:27:04.644148 2026] [security2:error] [pid 229246:tid 229369] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-subscription/class-wc-subscription-diagnostics.php"] [unique_id "al9JeCBMYeh5YLVG45x7pQACgXo"]
[Tue Jul 21 07:27:04.746280 2026] [security2:error] [pid 230252:tid 230413] [client 74.249.245.134:17447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/fw.php"] [unique_id "al9JeE0Dwhk5-Z44XrpXAgAAArY"]
[Tue Jul 21 07:27:04.850655 2026] [security2:error] [pid 230252:tid 230419] [client 154.192.233.199:59679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JeE0Dwhk5-Z44XrpXAwAAArw"]
[Tue Jul 21 07:27:04.850806 2026] [security2:error] [pid 230252:tid 230419] [client 154.192.233.199:59679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JeE0Dwhk5-Z44XrpXAwAAArw"]
[Tue Jul 21 07:27:04.884525 2026] [security2:error] [pid 230252:tid 230475] [client 45.8.17.126:37605] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/classwithtostring.php"] [unique_id "al9JeE0Dwhk5-Z44XrpXBAAAAvQ"]
[Tue Jul 21 07:27:04.967097 2026] [security2:error] [pid 229246:tid 229343] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-notification/class-wc-subscription-diagnostics.php"] [unique_id "al9JeCBMYeh5YLVG45x7qQACIGA"]
[Tue Jul 21 07:27:05.180046 2026] [security2:error] [pid 229246:tid 229421] [client 109.248.148.246:52892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JeSBMYeh5YLVG45x7rgAAAkE"]
[Tue Jul 21 07:27:05.180149 2026] [security2:error] [pid 229246:tid 229421] [client 109.248.148.246:52892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JeSBMYeh5YLVG45x7rgAAAkE"]
[Tue Jul 21 07:27:05.409365 2026] [security2:error] [pid 229246:tid 229470] [client 20.220.225.223:53447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/ee.php"] [unique_id "al9JeSBMYeh5YLVG45x7sQAAAnI"]
[Tue Jul 21 07:27:05.634049 2026] [security2:error] [pid 230252:tid 230349] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JeU0Dwhk5-Z44XrpXDQAC6V4"]
[Tue Jul 21 07:27:05.634192 2026] [security2:error] [pid 230252:tid 230464] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JeU0Dwhk5-Z44XrpXDQAC6V4"]
[Tue Jul 21 07:27:05.649916 2026] [security2:error] [pid 229246:tid 229391] [client 93.108.115.148:63340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.115.108.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "homemsedutoronline.com"] [uri "/xmlrpc.php"] [unique_id "al9JeSBMYeh5YLVG45x7tQAAAiM"]
[Tue Jul 21 07:27:05.650056 2026] [security2:error] [pid 229246:tid 229391] [client 93.108.115.148:63340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "homemsedutoronline.com"] [uri "/xmlrpc.php"] [unique_id "al9JeSBMYeh5YLVG45x7tQAAAiM"]
[Tue Jul 21 07:27:05.766980 2026] [security2:error] [pid 229246:tid 229454] [client 213.152.162.104:52238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9JeSBMYeh5YLVG45x7uQAAAmI"]
[Tue Jul 21 07:27:05.767111 2026] [security2:error] [pid 229246:tid 229454] [client 213.152.162.104:52238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9JeSBMYeh5YLVG45x7uQAAAmI"]
[Tue Jul 21 07:27:05.893498 2026] [security2:error] [pid 230252:tid 230331] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woo-product-slider-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JeU0Dwhk5-Z44XrpXEwAC3Uw"]
[Tue Jul 21 07:27:05.976573 2026] [security2:error] [pid 230252:tid 230485] [client 152.59.154.239:20624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JeU0Dwhk5-Z44XrpXFAAAAv4"]
[Tue Jul 21 07:27:05.985102 2026] [security2:error] [pid 230252:tid 230408] [client 45.8.17.123:43383] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/"] [unique_id "al9JeU0Dwhk5-Z44XrpXFQAAArE"]
[Tue Jul 21 07:27:05.994145 2026] [security2:error] [pid 229246:tid 229393] [client 20.151.10.161:65492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/zoro.php"] [unique_id "al9JeSBMYeh5YLVG45x7vAAAAiU"]
[Tue Jul 21 07:27:06.207979 2026] [security2:error] [pid 229246:tid 229260] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/testimonial-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JeiBMYeh5YLVG45x7vgACbA0"]
[Tue Jul 21 07:27:06.531613 2026] [security2:error] [pid 230252:tid 230270] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/smart-show-post-pro/src/Includes/LicenseLoader.php"] [unique_id "al9Jek0Dwhk5-Z44XrpXGwACuhA"]
[Tue Jul 21 07:27:06.553829 2026] [security2:error] [pid 229246:tid 229442] [client 4.204.201.85:3302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/BDKR28.php"] [unique_id "al9JeiBMYeh5YLVG45x7xgAAAlY"]
[Tue Jul 21 07:27:06.626901 2026] [security2:error] [pid 229246:tid 229344] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JeiBMYeh5YLVG45x7xwACP2E"]
[Tue Jul 21 07:27:06.627072 2026] [security2:error] [pid 229246:tid 229419] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JeiBMYeh5YLVG45x7xwACP2E"]
[Tue Jul 21 07:27:06.843197 2026] [security2:error] [pid 229246:tid 229338] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-subscription/class-wc-subscription-diagnostics.php"] [unique_id "al9JeiBMYeh5YLVG45x7zgACW1s"]
[Tue Jul 21 07:27:06.873576 2026] [security2:error] [pid 229246:tid 229411] [client 20.151.10.161:65425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/coffexium.php"] [unique_id "al9JeiBMYeh5YLVG45x70AAAAjc"]
[Tue Jul 21 07:27:06.920413 2026] [security2:error] [pid 229246:tid 229422] [client 4.204.201.85:26585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/green1.php"] [unique_id "al9JeiBMYeh5YLVG45x70QAAAkI"]
[Tue Jul 21 07:27:06.977679 2026] [security2:error] [pid 229246:tid 229492] [client 20.52.136.55:1579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/inputs.php"] [unique_id "al9JeiBMYeh5YLVG45x70wAAAog"]
[Tue Jul 21 07:27:06.993259 2026] [security2:error] [pid 229246:tid 229449] [client 45.8.17.127:61883] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9JeiBMYeh5YLVG45x71AAAAl0"]
[Tue Jul 21 07:27:07.160868 2026] [security2:error] [pid 230252:tid 230277] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-notification/class-wc-subscription-diagnostics.php"] [unique_id "al9Je00Dwhk5-Z44XrpXIAAC1hc"]
[Tue Jul 21 07:27:07.217668 2026] [security2:error] [pid 230252:tid 230473] [client 103.162.129.114:61745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Je00Dwhk5-Z44XrpXIQAAAvI"]
[Tue Jul 21 07:27:07.217795 2026] [security2:error] [pid 230252:tid 230473] [client 103.162.129.114:61745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Je00Dwhk5-Z44XrpXIQAAAvI"]
[Tue Jul 21 07:27:07.281074 2026] [security2:error] [pid 229246:tid 229480] [client 109.248.148.246:52904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9JeyBMYeh5YLVG45x71wAAAnw"]
[Tue Jul 21 07:27:07.281249 2026] [security2:error] [pid 229246:tid 229480] [client 109.248.148.246:52904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9JeyBMYeh5YLVG45x71wAAAnw"]
[Tue Jul 21 07:27:07.464264 2026] [security2:error] [pid 229246:tid 229387] [client 20.104.96.117:64035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9JeyBMYeh5YLVG45x72wAAAh8"]
[Tue Jul 21 07:27:07.470854 2026] [security2:error] [pid 229246:tid 229402] [client 20.104.96.117:42396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/xacs.php"] [unique_id "al9JeyBMYeh5YLVG45x73AAAAi4"]
[Tue Jul 21 07:27:07.473094 2026] [security2:error] [pid 229246:tid 229330] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woo-product-slider-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JeyBMYeh5YLVG45x73QACdlM"]
[Tue Jul 21 07:27:07.487802 2026] [security2:error] [pid 229246:tid 229479] [client 4.204.201.85:26401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/nc4.php"] [unique_id "al9JeyBMYeh5YLVG45x73gAAAns"]
[Tue Jul 21 07:27:07.655203 2026] [security2:error] [pid 229246:tid 229465] [client 20.10.88.201:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "weightloss-review.shop"] [uri "/index.php"] [unique_id "al9JeyBMYeh5YLVG45x74gAAAm0"]
[Tue Jul 21 07:27:07.656332 2026] [security2:error] [pid 229246:tid 229473] [client 20.10.88.201:61441] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "weightloss-review.shop"] [uri "/robots.txt"] [unique_id "al9JeyBMYeh5YLVG45x74AAAAnU"]
[Tue Jul 21 07:27:07.726653 2026] [security2:error] [pid 230252:tid 230392] [client 193.36.225.73:28859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Je00Dwhk5-Z44XrpXJAAAAqE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:27:07.792305 2026] [security2:error] [pid 230252:tid 230278] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/testimonial-pro/src/Includes/LicenseLoader.php"] [unique_id "al9Je00Dwhk5-Z44XrpXJQADGBg"]
[Tue Jul 21 07:27:07.832877 2026] [security2:error] [pid 230252:tid 230439] [client 20.104.96.117:64059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Je00Dwhk5-Z44XrpXJwAAAtA"]
[Tue Jul 21 07:27:07.879519 2026] [security2:error] [pid 230252:tid 230425] [client 20.151.10.161:63727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/app.php"] [unique_id "al9Je00Dwhk5-Z44XrpXKQAAAsI"]
[Tue Jul 21 07:27:07.959235 2026] [security2:error] [pid 229246:tid 229380] [client 113.31.186.196:0] ModSecurity: Warning. Matched phrase "Custo" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "drajoanasiqueira.com"] [uri "/index.php"] [unique_id "al9JeiBMYeh5YLVG45x7yQAAAhg"]
[Tue Jul 21 07:27:07.984231 2026] [security2:error] [pid 230252:tid 230471] [client 4.204.201.85:26595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/a1.php"] [unique_id "al9Je00Dwhk5-Z44XrpXLAAAAvA"]
[Tue Jul 21 07:27:08.103324 2026] [security2:error] [pid 229246:tid 229297] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/smart-show-post-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JfCBMYeh5YLVG45x75gACXjI"]
[Tue Jul 21 07:27:08.140428 2026] [security2:error] [pid 230252:tid 230493] [client 20.104.96.117:64028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/media.php"] [unique_id "al9JfE0Dwhk5-Z44XrpXLwAAAwY"]
[Tue Jul 21 07:27:08.266595 2026] [security2:error] [pid 229246:tid 229360] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JfCBMYeh5YLVG45x76QACdHE"]
[Tue Jul 21 07:27:08.266728 2026] [security2:error] [pid 229246:tid 229472] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JfCBMYeh5YLVG45x76QACdHE"]
[Tue Jul 21 07:27:08.309918 2026] [security2:error] [pid 230252:tid 230447] [client 20.220.225.223:53477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/blue.php"] [unique_id "al9JfE0Dwhk5-Z44XrpXMgAAAtg"]
[Tue Jul 21 07:27:08.418293 2026] [security2:error] [pid 230252:tid 230423] [client 4.204.201.85:3244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/eee.php"] [unique_id "al9JfE0Dwhk5-Z44XrpXNgAAAsA"]
[Tue Jul 21 07:27:08.424123 2026] [security2:error] [pid 230252:tid 230257] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-subscription/class-wc-subscription-diagnostics.php"] [unique_id "al9JfE0Dwhk5-Z44XrpXNwACpAM"]
[Tue Jul 21 07:27:08.563030 2026] [security2:error] [pid 229246:tid 229451] [client 74.249.245.134:54340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/fm.php"] [unique_id "al9JfCBMYeh5YLVG45x77QAAAl8"]
[Tue Jul 21 07:27:08.616694 2026] [security2:error] [pid 229246:tid 229484] [client 20.104.96.117:64060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/images.php"] [unique_id "al9JfCBMYeh5YLVG45x77gAAAoA"]
[Tue Jul 21 07:27:08.734419 2026] [security2:error] [pid 229246:tid 229296] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-notification/class-wc-subscription-diagnostics.php"] [unique_id "al9JfCBMYeh5YLVG45x78gACZTE"]
[Tue Jul 21 07:27:08.755307 2026] [security2:error] [pid 229246:tid 229488] [client 20.151.10.161:65524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/core.php"] [unique_id "al9JfCBMYeh5YLVG45x78wAAAoQ"]
[Tue Jul 21 07:27:08.777929 2026] [security2:error] [pid 230252:tid 230398] [client 109.248.148.246:33912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JfE0Dwhk5-Z44XrpXPQAAAqc"]
[Tue Jul 21 07:27:08.778018 2026] [security2:error] [pid 230252:tid 230398] [client 109.248.148.246:33912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JfE0Dwhk5-Z44XrpXPQAAAqc"]
[Tue Jul 21 07:27:08.963680 2026] [security2:error] [pid 230252:tid 230430] [client 4.204.201.85:26379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/wp-aothait.php"] [unique_id "al9JfE0Dwhk5-Z44XrpXQQAAAsc"]
[Tue Jul 21 07:27:09.040829 2026] [security2:error] [pid 230252:tid 230495] [client 139.135.44.145:53139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JfU0Dwhk5-Z44XrpXQgAAAwg"]
[Tue Jul 21 07:27:09.053313 2026] [security2:error] [pid 230252:tid 230380] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woo-product-slider-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JfU0Dwhk5-Z44XrpXQwACrn0"]
[Tue Jul 21 07:27:09.092303 2026] [security2:error] [pid 230252:tid 230485] [client 20.104.96.117:62931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/gecko.php"] [unique_id "al9JfU0Dwhk5-Z44XrpXRQAAAv4"]
[Tue Jul 21 07:27:09.109852 2026] [security2:error] [pid 230252:tid 230495] [client 139.135.44.145:53139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JfU0Dwhk5-Z44XrpXQgAAAwg"]
[Tue Jul 21 07:27:09.188622 2026] [security2:error] [pid 230252:tid 230460] [client 45.8.17.140:55749] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/fm.php"] [unique_id "al9JfU0Dwhk5-Z44XrpXSQAAAuU"]
[Tue Jul 21 07:27:09.356829 2026] [security2:error] [pid 229246:tid 229414] [client 20.104.96.117:59793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/zildan.php"] [unique_id "al9JfSBMYeh5YLVG45x7-wAAAjo"]
[Tue Jul 21 07:27:09.365795 2026] [security2:error] [pid 229246:tid 229314] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/testimonial-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JfSBMYeh5YLVG45x7_AACTEM"]
[Tue Jul 21 07:27:09.390994 2026] [security2:error] [pid 229246:tid 229436] [client 20.220.225.223:60359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/wp-signup.php"] [unique_id "al9JfSBMYeh5YLVG45x7_QAAAlA"]
[Tue Jul 21 07:27:09.418665 2026] [security2:error] [pid 230252:tid 230468] [client 4.204.201.85:3206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/config.json.php"] [unique_id "al9JfU0Dwhk5-Z44XrpXTQAAAu0"]
[Tue Jul 21 07:27:09.534458 2026] [security2:error] [pid 230252:tid 230511] [client 20.151.10.161:49070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/dx.php"] [unique_id "al9JfU0Dwhk5-Z44XrpXUgAAAxg"]
[Tue Jul 21 07:27:09.677154 2026] [security2:error] [pid 230252:tid 230500] [client 20.104.96.117:62919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/82.php"] [unique_id "al9JfU0Dwhk5-Z44XrpXUwAAAw0"]
[Tue Jul 21 07:27:09.683397 2026] [security2:error] [pid 230252:tid 230265] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/smart-show-post-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JfU0Dwhk5-Z44XrpXVAACrws"]
[Tue Jul 21 07:27:09.757186 2026] [security2:error] [pid 230252:tid 230455] [client 74.249.245.134:9408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/ini.php"] [unique_id "al9JfU0Dwhk5-Z44XrpXVgAAAuA"]
[Tue Jul 21 07:27:09.759156 2026] [security2:error] [pid 229246:tid 229442] [client 20.151.10.161:63659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/main.php"] [unique_id "al9JfSBMYeh5YLVG45x8AQAAAlY"]
[Tue Jul 21 07:27:09.762317 2026] [security2:error] [pid 230252:tid 230424] [client 4.204.201.85:26593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9JfU0Dwhk5-Z44XrpXVwAAAsE"]
[Tue Jul 21 07:27:09.992871 2026] [security2:error] [pid 229246:tid 229304] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-subscription/class-wc-subscription-diagnostics.php"] [unique_id "al9JfSBMYeh5YLVG45x8BQACSjk"]
[Tue Jul 21 07:27:10.109172 2026] [security2:error] [pid 230252:tid 230411] [client 4.204.201.85:3209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/k2.php"] [unique_id "al9Jfk0Dwhk5-Z44XrpXXwAAArQ"]
[Tue Jul 21 07:27:10.171374 2026] [security2:error] [pid 230252:tid 230505] [client 20.52.136.55:1577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/ms-edit.php"] [unique_id "al9Jfk0Dwhk5-Z44XrpXYAAAAxI"]
[Tue Jul 21 07:27:10.202842 2026] [security2:error] [pid 230252:tid 230418] [client 20.104.96.117:62923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/admin.php"] [unique_id "al9Jfk0Dwhk5-Z44XrpXYgAAArs"]
[Tue Jul 21 07:27:10.259255 2026] [security2:error] [pid 229246:tid 229440] [client 20.220.225.223:53443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/csa.php"] [unique_id "al9JfiBMYeh5YLVG45x8CQAAAlQ"]
[Tue Jul 21 07:27:10.284655 2026] [security2:error] [pid 229246:tid 229378] [client 117.251.86.144:58858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JfiBMYeh5YLVG45x8CgAAAhY"]
[Tue Jul 21 07:27:10.285554 2026] [security2:error] [pid 229246:tid 229378] [client 117.251.86.144:58858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JfiBMYeh5YLVG45x8CgAAAhY"]
[Tue Jul 21 07:27:10.313101 2026] [security2:error] [pid 230252:tid 230328] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-notification/class-wc-subscription-diagnostics.php"] [unique_id "al9Jfk0Dwhk5-Z44XrpXZAAC_Ek"]
[Tue Jul 21 07:27:10.479094 2026] [security2:error] [pid 229246:tid 229487] [client 20.104.96.117:64025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/adminner.php"] [unique_id "al9JfiBMYeh5YLVG45x8EAAAAoM"]
[Tue Jul 21 07:27:10.481273 2026] [security2:error] [pid 230252:tid 230398] [client 45.8.17.60:27101] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/"] [unique_id "al9Jfk0Dwhk5-Z44XrpXZwAAAqc"]
[Tue Jul 21 07:27:10.622069 2026] [security2:error] [pid 229246:tid 229294] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woo-product-slider-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JfiBMYeh5YLVG45x8EQACRi8"]
[Tue Jul 21 07:27:10.724405 2026] [security2:error] [pid 230252:tid 230484] [client 4.204.201.85:26581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/uiuvs58l.php"] [unique_id "al9Jfk0Dwhk5-Z44XrpXbwAAAv0"]
[Tue Jul 21 07:27:10.840356 2026] [security2:error] [pid 230252:tid 230400] [client 20.104.96.117:5089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/admin.php"] [unique_id "al9Jfk0Dwhk5-Z44XrpXcAAAAqk"]
[Tue Jul 21 07:27:10.865575 2026] [security2:error] [pid 230252:tid 230452] [client 20.151.10.161:65481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/init.php"] [unique_id "al9Jfk0Dwhk5-Z44XrpXcQAAAt0"]
[Tue Jul 21 07:27:10.957999 2026] [security2:error] [pid 230252:tid 230308] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/testimonial-pro/src/Includes/LicenseLoader.php"] [unique_id "al9Jfk0Dwhk5-Z44XrpXcgADCDY"]
[Tue Jul 21 07:27:11.034371 2026] [security2:error] [pid 230252:tid 230503] [client 4.204.201.85:26569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/40p9ixjd.php"] [unique_id "al9Jf00Dwhk5-Z44XrpXdgAAAxA"]
[Tue Jul 21 07:27:11.082821 2026] [security2:error] [pid 230252:tid 230389] [client 20.104.96.117:59779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/csa.php"] [unique_id "al9Jf00Dwhk5-Z44XrpXdwAAAp4"]
[Tue Jul 21 07:27:11.249713 2026] [security2:error] [pid 229246:tid 229385] [client 20.220.225.223:53472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/min.php"] [unique_id "al9JfyBMYeh5YLVG45x8FwAAAh0"]
[Tue Jul 21 07:27:11.268444 2026] [security2:error] [pid 229246:tid 229257] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/smart-show-post-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JfyBMYeh5YLVG45x8GAACIgo"]
[Tue Jul 21 07:27:11.290054 2026] [security2:error] [pid 229246:tid 229465] [client 45.8.17.64:35167] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/js/widgets/"] [unique_id "al9JfyBMYeh5YLVG45x8GQAAAm0"]
[Tue Jul 21 07:27:11.306258 2026] [security2:error] [pid 229246:tid 229460] [client 20.104.96.117:62947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/k.php"] [unique_id "al9JfyBMYeh5YLVG45x8GgAAAmg"]
[Tue Jul 21 07:27:11.379396 2026] [security2:error] [pid 229246:tid 229382] [client 4.204.201.85:3211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/uiuvs58l.update.php"] [unique_id "al9JfyBMYeh5YLVG45x8GwAAAho"]
[Tue Jul 21 07:27:11.588183 2026] [security2:error] [pid 230252:tid 230372] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-subscription/class-wc-subscription-diagnostics.php"] [unique_id "al9Jf00Dwhk5-Z44XrpXegACm3U"]
[Tue Jul 21 07:27:11.623793 2026] [security2:error] [pid 229246:tid 229303] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JfyBMYeh5YLVG45x8IAACcjg"]
[Tue Jul 21 07:27:11.623933 2026] [security2:error] [pid 229246:tid 229470] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JfyBMYeh5YLVG45x8IAACcjg"]
[Tue Jul 21 07:27:11.625738 2026] [security2:error] [pid 230252:tid 230441] [client 20.104.96.117:5068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/blurbs.php"] [unique_id "al9Jf00Dwhk5-Z44XrpXewAAAtI"]
[Tue Jul 21 07:27:11.752546 2026] [security2:error] [pid 230252:tid 230282] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Jf00Dwhk5-Z44XrpXfAAC-xw"]
[Tue Jul 21 07:27:11.752878 2026] [security2:error] [pid 230252:tid 230482] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Jf00Dwhk5-Z44XrpXfAAC-xw"]
[Tue Jul 21 07:27:11.813241 2026] [security2:error] [pid 230252:tid 230458] [client 4.204.201.85:3234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/for.php"] [unique_id "al9Jf00Dwhk5-Z44XrpXfwAAAuM"]
[Tue Jul 21 07:27:11.898278 2026] [security2:error] [pid 229246:tid 229339] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-notification/class-wc-subscription-diagnostics.php"] [unique_id "al9JfyBMYeh5YLVG45x8JAACG1w"]
[Tue Jul 21 07:27:11.910677 2026] [security2:error] [pid 229246:tid 229463] [client 20.151.10.161:65452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/prekel.php"] [unique_id "al9JfyBMYeh5YLVG45x8JQAAAms"]
[Tue Jul 21 07:27:11.962262 2026] [security2:error] [pid 229246:tid 229441] [client 45.251.232.145:50139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JfyBMYeh5YLVG45x8JgAAAlU"]
[Tue Jul 21 07:27:11.962430 2026] [security2:error] [pid 229246:tid 229441] [client 45.251.232.145:50139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JfyBMYeh5YLVG45x8JgAAAlU"]
[Tue Jul 21 07:27:12.149237 2026] [security2:error] [pid 230252:tid 230450] [client 20.220.225.223:53489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/echkm.php"] [unique_id "al9JgE0Dwhk5-Z44XrpXhgAAAts"]
[Tue Jul 21 07:27:12.161406 2026] [security2:error] [pid 229246:tid 229488] [client 4.204.201.85:26605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/raw.php"] [unique_id "al9JgCBMYeh5YLVG45x8KgAAAoQ"]
[Tue Jul 21 07:27:12.189221 2026] [security2:error] [pid 230252:tid 230478] [client 45.8.17.118:64487] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/222.php"] [unique_id "al9JgE0Dwhk5-Z44XrpXhwAAAvc"]
[Tue Jul 21 07:27:12.217151 2026] [security2:error] [pid 230252:tid 230361] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woo-product-slider-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JgE0Dwhk5-Z44XrpXiAACuWo"]
[Tue Jul 21 07:27:12.255857 2026] [security2:error] [pid 230252:tid 230413] [client 20.104.96.117:5102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/bajah.php"] [unique_id "al9JgE0Dwhk5-Z44XrpXiQAAArY"]
[Tue Jul 21 07:27:12.527070 2026] [security2:error] [pid 229246:tid 229284] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/testimonial-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JgCBMYeh5YLVG45x8LQACJCU"]
[Tue Jul 21 07:27:12.717435 2026] [security2:error] [pid 229246:tid 229468] [client 20.10.88.201:22852] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "weightloss-review.shop"] [uri "/robots.txt"] [unique_id "al9JgCBMYeh5YLVG45x8LwAAAnA"]
[Tue Jul 21 07:27:12.766344 2026] [security2:error] [pid 230252:tid 230300] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JgE0Dwhk5-Z44XrpXjwACtC4"]
[Tue Jul 21 07:27:12.766477 2026] [security2:error] [pid 230252:tid 230411] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JgE0Dwhk5-Z44XrpXjwACtC4"]
[Tue Jul 21 07:27:12.807604 2026] [security2:error] [pid 230252:tid 230425] [client 20.104.96.117:62959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/a.php"] [unique_id "al9JgE0Dwhk5-Z44XrpXkAAAAsI"]
[Tue Jul 21 07:27:12.846187 2026] [security2:error] [pid 230252:tid 230302] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/smart-show-post-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JgE0Dwhk5-Z44XrpXkQAC_DA"]
[Tue Jul 21 07:27:12.957507 2026] [security2:error] [pid 230252:tid 230480] [client 20.220.225.223:53458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/mac.php"] [unique_id "al9JgE0Dwhk5-Z44XrpXkwAAAvk"]
[Tue Jul 21 07:27:13.028654 2026] [security2:error] [pid 229246:tid 229448] [client 20.151.10.161:63740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/0.php"] [unique_id "al9JgSBMYeh5YLVG45x8MwAAAlw"]
[Tue Jul 21 07:27:13.050029 2026] [security2:error] [pid 229246:tid 229485] [client 20.104.96.117:59828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/w3llscc.php"] [unique_id "al9JgSBMYeh5YLVG45x8NAAAAoE"]
[Tue Jul 21 07:27:13.070315 2026] [security2:error] [pid 230252:tid 230403] [client 20.52.136.55:1544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/simple.php"] [unique_id "al9JgU0Dwhk5-Z44XrpXlAAAAqw"]
[Tue Jul 21 07:27:13.082512 2026] [security2:error] [pid 229246:tid 229414] [client 45.8.17.135:65065] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/aaa.php"] [unique_id "al9JgSBMYeh5YLVG45x8NQAAAjo"]
[Tue Jul 21 07:27:13.154927 2026] [security2:error] [pid 229246:tid 229329] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-subscription/class-wc-subscription-diagnostics.php"] [unique_id "al9JgSBMYeh5YLVG45x8OAACUFI"]
[Tue Jul 21 07:27:13.313465 2026] [security2:error] [pid 230252:tid 230510] [client 20.104.96.117:64006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/edit.php"] [unique_id "al9JgU0Dwhk5-Z44XrpXmQAAAxc"]
[Tue Jul 21 07:27:13.339761 2026] [security2:error] [pid 230252:tid 230479] [client 103.106.20.201:50266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JgU0Dwhk5-Z44XrpXmgAAAvg"]
[Tue Jul 21 07:27:13.339902 2026] [security2:error] [pid 230252:tid 230479] [client 103.106.20.201:50266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JgU0Dwhk5-Z44XrpXmgAAAvg"]
[Tue Jul 21 07:27:13.474061 2026] [security2:error] [pid 229246:tid 229295] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-notification/class-wc-subscription-diagnostics.php"] [unique_id "al9JgSBMYeh5YLVG45x8OwACVjA"]
[Tue Jul 21 07:27:13.523508 2026] [security2:error] [pid 229246:tid 229363] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JgSBMYeh5YLVG45x8PAACd3Q"]
[Tue Jul 21 07:27:13.523686 2026] [security2:error] [pid 229246:tid 229475] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JgSBMYeh5YLVG45x8PAACd3Q"]
[Tue Jul 21 07:27:13.713283 2026] [security2:error] [pid 230252:tid 230387] [client 20.220.225.223:45973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/else1.php"] [unique_id "al9JgU0Dwhk5-Z44XrpXogAAApw"]
[Tue Jul 21 07:27:13.778354 2026] [security2:error] [pid 230252:tid 230460] [client 20.104.96.117:62950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/hosty.php"] [unique_id "al9JgU0Dwhk5-Z44XrpXowAAAuU"]
[Tue Jul 21 07:27:13.794229 2026] [security2:error] [pid 229246:tid 229361] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woo-product-slider-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JgSBMYeh5YLVG45x8SAACfnI"]
[Tue Jul 21 07:27:13.962531 2026] [security2:error] [pid 229246:tid 229462] [client 20.104.96.117:59609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wpx.php"] [unique_id "al9JgSBMYeh5YLVG45x8SgAAAmo"]
[Tue Jul 21 07:27:14.114804 2026] [security2:error] [pid 229246:tid 229313] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/testimonial-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JgiBMYeh5YLVG45x8TAACIEI"]
[Tue Jul 21 07:27:14.182520 2026] [security2:error] [pid 230252:tid 230441] [client 20.104.96.117:64000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/k.php"] [unique_id "al9Jgk0Dwhk5-Z44XrpXrgAAAtI"]
[Tue Jul 21 07:27:14.277295 2026] [security2:error] [pid 229246:tid 229385] [client 20.220.225.223:60361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/samll.php"] [unique_id "al9JgiBMYeh5YLVG45x8UAAAAh0"]
[Tue Jul 21 07:27:14.283933 2026] [security2:error] [pid 230252:tid 230461] [client 45.8.17.108:42693] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "al9Jgk0Dwhk5-Z44XrpXsAAAAuY"]
[Tue Jul 21 07:27:14.296547 2026] [security2:error] [pid 230252:tid 230444] [client 20.151.10.161:65505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/BDKR28.php"] [unique_id "al9Jgk0Dwhk5-Z44XrpXsQAAAtU"]
[Tue Jul 21 07:27:14.434582 2026] [security2:error] [pid 229246:tid 229362] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/smart-show-post-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JgiBMYeh5YLVG45x8UgACGnM"]
[Tue Jul 21 07:27:14.543145 2026] [security2:error] [pid 230252:tid 230385] [client 103.174.34.15:62635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jgk0Dwhk5-Z44XrpXtAAAApo"]
[Tue Jul 21 07:27:14.543280 2026] [security2:error] [pid 230252:tid 230385] [client 103.174.34.15:62635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jgk0Dwhk5-Z44XrpXtAAAApo"]
[Tue Jul 21 07:27:14.631557 2026] [security2:error] [pid 230252:tid 230494] [client 136.144.33.111:44713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JgE0Dwhk5-Z44XrpXigAAAwc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:27:14.713997 2026] [security2:error] [pid 230252:tid 230413] [client 20.104.96.117:59807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-css.php"] [unique_id "al9Jgk0Dwhk5-Z44XrpXuAAAArY"]
[Tue Jul 21 07:27:14.890572 2026] [security2:error] [pid 230252:tid 230447] [client 62.102.148.164:39630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Jgk0Dwhk5-Z44XrpXvgAAAtg"]
[Tue Jul 21 07:27:14.890686 2026] [security2:error] [pid 230252:tid 230447] [client 62.102.148.164:39630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Jgk0Dwhk5-Z44XrpXvgAAAtg"]
[Tue Jul 21 07:27:14.899404 2026] [security2:error] [pid 230252:tid 230425] [client 20.104.96.117:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/aaa.php"] [unique_id "al9Jgk0Dwhk5-Z44XrpXvwAAAsI"]
[Tue Jul 21 07:27:15.144699 2026] [security2:error] [pid 230252:tid 230391] [client 74.249.245.134:17424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/themes.php"] [unique_id "al9Jg00Dwhk5-Z44XrpXwQAAAqA"]
[Tue Jul 21 07:27:15.251897 2026] [security2:error] [pid 230252:tid 230501] [client 175.45.70.82:53622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jg00Dwhk5-Z44XrpXwwAAAw4"]
[Tue Jul 21 07:27:15.252008 2026] [security2:error] [pid 230252:tid 230501] [client 175.45.70.82:53622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jg00Dwhk5-Z44XrpXwwAAAw4"]
[Tue Jul 21 07:27:15.373953 2026] [security2:error] [pid 230252:tid 230490] [client 20.151.10.161:65427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/f35.update.php"] [unique_id "al9Jg00Dwhk5-Z44XrpXygAAAwM"]
[Tue Jul 21 07:27:15.389625 2026] [security2:error] [pid 230252:tid 230502] [client 45.8.17.140:56115] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/inputs.php"] [unique_id "al9Jg00Dwhk5-Z44XrpXywAAAw8"]
[Tue Jul 21 07:27:15.418974 2026] [security2:error] [pid 230252:tid 230430] [client 20.104.96.117:62962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/file5.php"] [unique_id "al9Jg00Dwhk5-Z44XrpXzAAAAsc"]
[Tue Jul 21 07:27:15.614559 2026] [security2:error] [pid 230252:tid 230446] [client 59.96.220.140:63935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Jg00Dwhk5-Z44XrpXzwAAAtc"]
[Tue Jul 21 07:27:15.615216 2026] [security2:error] [pid 230252:tid 230446] [client 59.96.220.140:63935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Jg00Dwhk5-Z44XrpXzwAAAtc"]
[Tue Jul 21 07:27:15.908510 2026] [security2:error] [pid 229246:tid 229476] [client 20.104.96.117:59837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/ho.php"] [unique_id "al9JgyBMYeh5YLVG45x8YgAAAng"]
[Tue Jul 21 07:27:16.069426 2026] [security2:error] [pid 229246:tid 229464] [client 20.104.96.117:62918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/222.php"] [unique_id "al9JhCBMYeh5YLVG45x8ZAAAAmw"]
[Tue Jul 21 07:27:16.165569 2026] [security2:error] [pid 230252:tid 230286] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JhE0Dwhk5-Z44XrpX0gACuiA"]
[Tue Jul 21 07:27:16.165799 2026] [security2:error] [pid 230252:tid 230417] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JhE0Dwhk5-Z44XrpX0gACuiA"]
[Tue Jul 21 07:27:16.255356 2026] [security2:error] [pid 229246:tid 229399] [client 20.220.225.223:53475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/abcd.php"] [unique_id "al9JhCBMYeh5YLVG45x8aAAAAis"]
[Tue Jul 21 07:27:16.289119 2026] [security2:error] [pid 229246:tid 229414] [client 45.8.17.113:34967] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/about.php"] [unique_id "al9JhCBMYeh5YLVG45x8aQAAAjo"]
[Tue Jul 21 07:27:16.400686 2026] [security2:error] [pid 229246:tid 229413] [client 20.151.10.161:63646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/f900.php"] [unique_id "al9JhCBMYeh5YLVG45x8bgAAAjk"]
[Tue Jul 21 07:27:16.485282 2026] [security2:error] [pid 229246:tid 229483] [client 20.104.96.117:64047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/test.php"] [unique_id "al9JhCBMYeh5YLVG45x8bwAAAn8"]
[Tue Jul 21 07:27:16.874168 2026] [security2:error] [pid 230252:tid 230497] [client 216.73.160.36:45077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reserveseulugar.com.br"] [uri "/wp-login.php"] [unique_id "al9Jg00Dwhk5-Z44XrpX0AAAAwo"]
[Tue Jul 21 07:27:17.116487 2026] [security2:error] [pid 230252:tid 230323] [remote 20.89.83.228:32500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.83.89.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thiagomartins.com"] [uri "/wp-login.php"] [unique_id "al9JhU0Dwhk5-Z44XrpX1wADFkU"]
[Tue Jul 21 07:27:17.139094 2026] [autoindex:error] [pid 230252:tid 230485] [client 74.7.242.47:0] AH01276: Cannot serve directory /home1/asse7722/flowwshop.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:17.161306 2026] [security2:error] [pid 229246:tid 229343] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JhSBMYeh5YLVG45x8eQACFWA"]
[Tue Jul 21 07:27:17.161449 2026] [security2:error] [pid 229246:tid 229377] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JhSBMYeh5YLVG45x8eQACFWA"]
[Tue Jul 21 07:27:17.183621 2026] [security2:error] [pid 230252:tid 230478] [client 45.8.17.118:50659] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/speculative8.php"] [unique_id "al9JhU0Dwhk5-Z44XrpX3AAAAvc"]
[Tue Jul 21 07:27:17.185759 2026] [security2:error] [pid 230252:tid 230413] [client 20.104.96.117:5106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/aaa.php"] [unique_id "al9JhU0Dwhk5-Z44XrpX3QAAArY"]
[Tue Jul 21 07:27:17.199249 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:65410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/xmrl.php"] [unique_id "al9JhU0Dwhk5-Z44XrpX3gAAAwY"]
[Tue Jul 21 07:27:17.232514 2026] [security2:error] [pid 229246:tid 229492] [client 74.7.244.61:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "flowwshop.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9JhSBMYeh5YLVG45x8ewAAAog"]
[Tue Jul 21 07:27:17.233578 2026] [security2:error] [pid 229246:tid 229440] [client 74.7.244.61:35718] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "flowwshop.com.br"] [uri "/robots.txt"] [unique_id "al9JhSBMYeh5YLVG45x8egACVGo"]
[Tue Jul 21 07:27:17.307874 2026] [security2:error] [pid 229246:tid 229467] [client 20.52.136.55:1731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/404.php"] [unique_id "al9JhSBMYeh5YLVG45x8fQAAAm8"]
[Tue Jul 21 07:27:17.530211 2026] [security2:error] [pid 229246:tid 229501] [client 20.104.96.117:59589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/xy.php"] [unique_id "al9JhSBMYeh5YLVG45x8ggAAApE"]
[Tue Jul 21 07:27:17.725632 2026] [security2:error] [pid 230252:tid 230444] [client 103.162.129.114:62187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JhU0Dwhk5-Z44XrpX4wAAAtU"]
[Tue Jul 21 07:27:17.725760 2026] [security2:error] [pid 230252:tid 230444] [client 103.162.129.114:62187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JhU0Dwhk5-Z44XrpX4wAAAtU"]
[Tue Jul 21 07:27:17.793852 2026] [security2:error] [pid 230252:tid 230447] [client 20.104.96.117:62926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/11.php"] [unique_id "al9JhU0Dwhk5-Z44XrpX5AAAAtg"]
[Tue Jul 21 07:27:18.110538 2026] [security2:error] [pid 230252:tid 230490] [client 20.151.10.161:63702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/memberfuns.php"] [unique_id "al9Jhk0Dwhk5-Z44XrpX6wAAAwM"]
[Tue Jul 21 07:27:18.165927 2026] [security2:error] [pid 230252:tid 230438] [client 20.220.225.223:53499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/xyn.php"] [unique_id "al9Jhk0Dwhk5-Z44XrpX7AAAAs8"]
[Tue Jul 21 07:27:18.188061 2026] [security2:error] [pid 230252:tid 230465] [client 45.8.17.127:65123] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/radio.php"] [unique_id "al9Jhk0Dwhk5-Z44XrpX7QAAAuo"]
[Tue Jul 21 07:27:18.306546 2026] [security2:error] [pid 230252:tid 230494] [client 152.59.154.239:50461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jhk0Dwhk5-Z44XrpX7gAAAwc"]
[Tue Jul 21 07:27:18.367158 2026] [security2:error] [pid 229246:tid 229443] [client 20.104.96.117:5085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/mac.php"] [unique_id "al9JhiBMYeh5YLVG45x8iAAAAlc"]
[Tue Jul 21 07:27:18.595912 2026] [security2:error] [pid 229246:tid 229426] [client 20.104.96.117:59615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/loader.php"] [unique_id "al9JhiBMYeh5YLVG45x8iwAAAkY"]
[Tue Jul 21 07:27:18.662363 2026] [security2:error] [pid 230252:tid 230419] [client 154.192.233.199:59752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jhk0Dwhk5-Z44XrpX9QAAArw"]
[Tue Jul 21 07:27:18.662486 2026] [security2:error] [pid 230252:tid 230419] [client 154.192.233.199:59752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jhk0Dwhk5-Z44XrpX9QAAArw"]
[Tue Jul 21 07:27:18.677948 2026] [security2:error] [pid 229246:tid 229460] [client 20.151.10.161:65471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/ms.php"] [unique_id "al9JhiBMYeh5YLVG45x8jAAAAmg"]
[Tue Jul 21 07:27:18.887759 2026] [security2:error] [pid 229246:tid 229308] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JhiBMYeh5YLVG45x8jwACGj0"]
[Tue Jul 21 07:27:18.887919 2026] [security2:error] [pid 229246:tid 229382] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JhiBMYeh5YLVG45x8jwACGj0"]
[Tue Jul 21 07:27:18.946430 2026] [security2:error] [pid 230252:tid 230467] [client 74.7.244.24:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "warleysonlacerdalope1782242261893.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9Jhk0Dwhk5-Z44XrpX-QAC7Gg"]
[Tue Jul 21 07:27:19.125410 2026] [security2:error] [pid 230252:tid 230466] [client 20.104.96.117:64050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/chosen.php"] [unique_id "al9Jh00Dwhk5-Z44XrpX-gAAAus"]
[Tue Jul 21 07:27:19.153231 2026] [security2:error] [pid 229246:tid 229383] [client 20.220.225.223:31180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/byp8.php"] [unique_id "al9JhyBMYeh5YLVG45x8kgAAAhs"]
[Tue Jul 21 07:27:19.382630 2026] [security2:error] [pid 230252:tid 230433] [client 45.8.17.58:60519] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/js/"] [unique_id "al9Jh00Dwhk5-Z44XrpYAAAAAso"]
[Tue Jul 21 07:27:19.456422 2026] [security2:error] [pid 230252:tid 230482] [client 20.151.10.161:63733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/zz.php"] [unique_id "al9Jh00Dwhk5-Z44XrpYAQAAAvs"]
[Tue Jul 21 07:27:19.789270 2026] [security2:error] [pid 229246:tid 229263] [remote 195.26.253.119:58154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.253.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/wp-login.php"] [unique_id "al9JhyBMYeh5YLVG45x8mQACeBA"]
[Tue Jul 21 07:27:19.819615 2026] [security2:error] [pid 230252:tid 230453] [client 20.104.96.117:5095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/cream1.php"] [unique_id "al9Jh00Dwhk5-Z44XrpYAwAAAt4"]
[Tue Jul 21 07:27:19.839903 2026] [security2:error] [pid 229246:tid 229472] [client 139.135.44.145:53880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JhyBMYeh5YLVG45x8mgAAAnQ"]
[Tue Jul 21 07:27:19.839996 2026] [security2:error] [pid 229246:tid 229472] [client 139.135.44.145:53880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JhyBMYeh5YLVG45x8mgAAAnQ"]
[Tue Jul 21 07:27:19.884766 2026] [security2:error] [pid 230252:tid 230491] [client 193.36.225.64:37943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Jh00Dwhk5-Z44XrpYBAAAAwQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:27:19.892804 2026] [security2:error] [pid 229246:tid 229485] [client 20.104.96.117:59598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/spadex.php"] [unique_id "al9JhyBMYeh5YLVG45x8nAAAAoE"]
[Tue Jul 21 07:27:19.908635 2026] [security2:error] [pid 230252:tid 230472] [client 20.220.225.223:55757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/byp8.php"] [unique_id "al9Jh00Dwhk5-Z44XrpYBQAAAvE"]
[Tue Jul 21 07:27:20.024713 2026] [security2:error] [pid 229246:tid 229398] [client 20.220.225.223:31188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/user.php"] [unique_id "al9JiCBMYeh5YLVG45x8ngAAAio"]
[Tue Jul 21 07:27:20.084419 2026] [security2:error] [pid 230252:tid 230409] [client 20.151.10.161:65499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/for.php"] [unique_id "al9JiE0Dwhk5-Z44XrpYCgAAArI"]
[Tue Jul 21 07:27:20.243433 2026] [security2:error] [pid 230252:tid 230384] [client 20.220.225.223:45414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/tkikikoko.php"] [unique_id "al9JiE0Dwhk5-Z44XrpYDQAAApk"]
[Tue Jul 21 07:27:20.344427 2026] [autoindex:error] [pid 230252:tid 230506] [client 20.104.96.117:62948] AH01276: Cannot serve directory /home4/forev309/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:20.482723 2026] [security2:error] [pid 230252:tid 230444] [client 45.8.17.122:63981] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/updates.php"] [unique_id "al9JiE0Dwhk5-Z44XrpYEAAAAtU"]
[Tue Jul 21 07:27:20.684180 2026] [autoindex:error] [pid 230252:tid 230395] [client 20.104.96.117:62948] AH01276: Cannot serve directory /home4/forev309/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:20.764535 2026] [security2:error] [pid 230252:tid 230416] [client 20.151.10.161:63664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/yup.php"] [unique_id "al9JiE0Dwhk5-Z44XrpYEwAAArk"]
[Tue Jul 21 07:27:20.829895 2026] [autoindex:error] [pid 230252:tid 230267] [remote 74.7.227.176:53416] AH01276: Cannot serve directory /home4/muril041/murilogermanopessagn1777322868000.0721679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:20.885679 2026] [security2:error] [pid 230252:tid 230415] [client 20.104.96.117:62948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/dr.php"] [unique_id "al9JiE0Dwhk5-Z44XrpYFQAAArg"]
[Tue Jul 21 07:27:20.907993 2026] [security2:error] [pid 229246:tid 229418] [client 20.220.225.223:55779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/user.php"] [unique_id "al9JiCBMYeh5YLVG45x8qAAAAj4"]
[Tue Jul 21 07:27:20.978766 2026] [security2:error] [pid 230252:tid 230344] [remote 103.28.36.106:41694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/wp-login.php"] [unique_id "al9JiE0Dwhk5-Z44XrpYFgACyFk"]
[Tue Jul 21 07:27:21.034064 2026] [security2:error] [pid 230252:tid 230391] [client 74.7.230.39:42188] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.murilogermanopessagn1777322868000.vaporclube.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9JiU0Dwhk5-Z44XrpYFwACoDQ"]
[Tue Jul 21 07:27:21.089500 2026] [security2:error] [pid 230252:tid 230410] [client 113.31.186.196:15794] ModSecurity: Warning. Matched phrase "Custo" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "drajoanasiqueira.com"] [uri "/"] [unique_id "al9Jek0Dwhk5-Z44XrpXHQAAArM"]
[Tue Jul 21 07:27:21.197794 2026] [security2:error] [pid 230252:tid 230418] [client 117.251.86.144:46580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JiU0Dwhk5-Z44XrpYGgAAArs"]
[Tue Jul 21 07:27:21.197930 2026] [security2:error] [pid 230252:tid 230418] [client 117.251.86.144:46580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JiU0Dwhk5-Z44XrpYGgAAArs"]
[Tue Jul 21 07:27:21.502200 2026] [security2:error] [pid 229246:tid 229378] [client 82.102.28.107:46110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9JiSBMYeh5YLVG45x8sAAAAhY"]
[Tue Jul 21 07:27:21.502288 2026] [security2:error] [pid 229246:tid 229378] [client 82.102.28.107:46110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9JiSBMYeh5YLVG45x8sAAAAhY"]
[Tue Jul 21 07:27:21.513201 2026] [security2:error] [pid 230252:tid 230430] [client 45.8.17.49:63653] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/colors/blue/"] [unique_id "al9JiU0Dwhk5-Z44XrpYHgAAAsc"]
[Tue Jul 21 07:27:21.525162 2026] [fcgid:warn] [pid 230252:tid 230508] (70014)End of file found: [client 66.132.224.231:8430] mod_fcgid: can't get data from http client
[Tue Jul 21 07:27:21.569332 2026] [security2:error] [pid 229246:tid 229466] [client 20.104.96.117:4214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/x.php"] [unique_id "al9JiSBMYeh5YLVG45x8sQAAAm4"]
[Tue Jul 21 07:27:21.587307 2026] [security2:error] [pid 230252:tid 230396] [client 20.151.10.161:63078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wpxml.php"] [unique_id "al9JiU0Dwhk5-Z44XrpYIgAAAqU"]
[Tue Jul 21 07:27:21.651635 2026] [security2:error] [pid 229246:tid 229437] [client 20.104.96.117:59829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/2x.php"] [unique_id "al9JiSBMYeh5YLVG45x8swAAAlE"]
[Tue Jul 21 07:27:21.664273 2026] [security2:error] [pid 230252:tid 230488] [client 74.249.245.134:62902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/dropdown.php"] [unique_id "al9JiU0Dwhk5-Z44XrpYJAAAAwE"]
[Tue Jul 21 07:27:22.216141 2026] [security2:error] [pid 230252:tid 230467] [client 20.104.96.117:64004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/155.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYKwAAAuw"]
[Tue Jul 21 07:27:22.232457 2026] [security2:error] [pid 230252:tid 230486] [client 20.220.225.223:45970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-Blogs.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYLAAAAv8"]
[Tue Jul 21 07:27:22.265277 2026] [security2:error] [pid 230252:tid 230346] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYLQACvFs"]
[Tue Jul 21 07:27:22.265425 2026] [security2:error] [pid 230252:tid 230419] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYLQACvFs"]
[Tue Jul 21 07:27:22.288613 2026] [security2:error] [pid 230252:tid 230468] [client 20.52.136.55:1506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/file3.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYLwAAAu0"]
[Tue Jul 21 07:27:22.361023 2026] [security2:error] [pid 230252:tid 230466] [client 20.151.10.161:63052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/fffm.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYMAAAAus"]
[Tue Jul 21 07:27:22.389832 2026] [security2:error] [pid 230252:tid 230442] [client 20.104.96.117:59782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/ctex1.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYMgAAAtM"]
[Tue Jul 21 07:27:22.396200 2026] [security2:error] [pid 230252:tid 230379] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "al9Jik0Dwhk5-Z44XrpYMwAC0nw"], referer: http://bio.deiacakes.com/wp-content/plugins/elementor/readme.txt
[Tue Jul 21 07:27:22.436832 2026] [security2:error] [pid 230252:tid 230404] [client 45.251.232.145:50655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYNQAAAq0"]
[Tue Jul 21 07:27:22.436950 2026] [security2:error] [pid 230252:tid 230404] [client 45.251.232.145:50655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYNQAAAq0"]
[Tue Jul 21 07:27:22.489280 2026] [security2:error] [pid 229246:tid 229428] [client 45.8.17.142:44681] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/theme-compat/"] [unique_id "al9JiiBMYeh5YLVG45x8uAAAAkg"]
[Tue Jul 21 07:27:22.583383 2026] [security2:error] [pid 230252:tid 230339] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYNgAC8lQ"]
[Tue Jul 21 07:27:22.583561 2026] [security2:error] [pid 230252:tid 230473] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYNgAC8lQ"]
[Tue Jul 21 07:27:22.587059 2026] [security2:error] [pid 229246:tid 229408] [client 20.220.225.223:60372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/ops.php"] [unique_id "al9JiiBMYeh5YLVG45x8vAAAAjQ"]
[Tue Jul 21 07:27:22.645580 2026] [security2:error] [pid 229246:tid 229474] [client 173.252.95.16:38856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9JiiBMYeh5YLVG45x8vgAAAnY"]
[Tue Jul 21 07:27:22.891900 2026] [security2:error] [pid 230252:tid 230500] [client 20.104.96.117:4204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/ops.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYOQAAAw0"]
[Tue Jul 21 07:27:22.914251 2026] [security2:error] [pid 229246:tid 229382] [client 20.151.10.161:63655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/gecko.php"] [unique_id "al9JiiBMYeh5YLVG45x8wgAAAho"]
[Tue Jul 21 07:27:22.957185 2026] [security2:error] [pid 229246:tid 229380] [client 82.102.28.107:57344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9JiiBMYeh5YLVG45x8wwAAAhg"]
[Tue Jul 21 07:27:22.957289 2026] [security2:error] [pid 229246:tid 229380] [client 82.102.28.107:57344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9JiiBMYeh5YLVG45x8wwAAAhg"]
[Tue Jul 21 07:27:23.229956 2026] [security2:error] [pid 230252:tid 230498] [client 20.104.96.117:64048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/file31.php"] [unique_id "al9Ji00Dwhk5-Z44XrpYPgAAAws"]
[Tue Jul 21 07:27:23.339970 2026] [security2:error] [pid 230252:tid 230463] [client 173.252.95.39:47934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Ji00Dwhk5-Z44XrpYOwAAAug"]
[Tue Jul 21 07:27:23.396909 2026] [security2:error] [pid 230252:tid 230384] [client 20.220.225.223:38716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/ops.php"] [unique_id "al9Ji00Dwhk5-Z44XrpYQgAAApk"]
[Tue Jul 21 07:27:23.486333 2026] [security2:error] [pid 229246:tid 229464] [client 20.104.96.117:59780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/edorxrr.php"] [unique_id "al9JiyBMYeh5YLVG45x8zwAAAmw"]
[Tue Jul 21 07:27:23.559992 2026] [security2:error] [pid 229246:tid 229322] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JiyBMYeh5YLVG45x80QACX0s"]
[Tue Jul 21 07:27:23.560121 2026] [security2:error] [pid 229246:tid 229451] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JiyBMYeh5YLVG45x80QACX0s"]
[Tue Jul 21 07:27:23.573926 2026] [security2:error] [pid 229246:tid 229484] [client 20.104.96.117:64001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/file6.php"] [unique_id "al9JiyBMYeh5YLVG45x80gAAAoA"]
[Tue Jul 21 07:27:23.582558 2026] [security2:error] [pid 229246:tid 229403] [client 45.8.17.73:65035] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/"] [unique_id "al9JiyBMYeh5YLVG45x80wAAAi8"]
[Tue Jul 21 07:27:23.634447 2026] [proxy:error] [pid 229246:tid 229441] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:27:23.634481 2026] [proxy_http:error] [pid 229246:tid 229441] [client 147.185.132.31:60036] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:27:23.635062 2026] [proxy:error] [pid 229246:tid 229441] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:27:23.635093 2026] [proxy_http:error] [pid 229246:tid 229441] [client 147.185.132.31:60036] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:27:23.879991 2026] [security2:error] [pid 229246:tid 229247] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wp-user-avatar/readme.txt"] [unique_id "al9JiyBMYeh5YLVG45x84AACigA"], referer: http://bio.deiacakes.com/wp-content/plugins/wp-user-avatar/readme.txt
[Tue Jul 21 07:27:23.993520 2026] [autoindex:error] [pid 229246:tid 229419] [client 20.104.96.117:62965] AH01276: Cannot serve directory /home4/forev309/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:24.071145 2026] [security2:error] [pid 229246:tid 229374] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JjCBMYeh5YLVG45x85AACd38"]
[Tue Jul 21 07:27:24.071303 2026] [security2:error] [pid 229246:tid 229475] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JjCBMYeh5YLVG45x85AACd38"]
[Tue Jul 21 07:27:24.102279 2026] [security2:error] [pid 229246:tid 229431] [client 103.106.20.201:50836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JjCBMYeh5YLVG45x85gAAAks"]
[Tue Jul 21 07:27:24.102385 2026] [security2:error] [pid 229246:tid 229431] [client 103.106.20.201:50836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JjCBMYeh5YLVG45x85gAAAks"]
[Tue Jul 21 07:27:24.104828 2026] [security2:error] [pid 229246:tid 229258] [remote 65.111.9.171:63947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.9.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9JjCBMYeh5YLVG45x85QACMQs"]
[Tue Jul 21 07:27:24.235469 2026] [security2:error] [pid 230252:tid 230451] [client 20.104.96.117:59613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/miru1.php"] [unique_id "al9JjE0Dwhk5-Z44XrpYSQAAAtw"]
[Tue Jul 21 07:27:24.269556 2026] [security2:error] [pid 229246:tid 229482] [client 20.104.96.117:62965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/adminfuns.php"] [unique_id "al9JjCBMYeh5YLVG45x86gAAAn4"]
[Tue Jul 21 07:27:24.305119 2026] [security2:error] [pid 229246:tid 229486] [client 193.36.225.64:35179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JjCBMYeh5YLVG45x86wAAAoI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:27:24.412306 2026] [core:alert] [pid 230252:tid 230429] [client 66.249.66.74:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:27:24.589069 2026] [security2:error] [pid 229246:tid 229487] [client 45.8.17.140:32835] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/languages/plugins/"] [unique_id "al9JjCBMYeh5YLVG45x87AAAAoM"]
[Tue Jul 21 07:27:24.625924 2026] [security2:error] [pid 230252:tid 230488] [client 213.152.162.104:36854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JjE0Dwhk5-Z44XrpYTwAAAwE"]
[Tue Jul 21 07:27:24.626024 2026] [security2:error] [pid 230252:tid 230488] [client 213.152.162.104:36854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JjE0Dwhk5-Z44XrpYTwAAAwE"]
[Tue Jul 21 07:27:24.629713 2026] [security2:error] [pid 229246:tid 229444] [client 20.151.10.161:63649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/a1.php"] [unique_id "al9JjCBMYeh5YLVG45x87QAAAlg"]
[Tue Jul 21 07:27:24.727622 2026] [security2:error] [pid 230252:tid 230414] [client 173.252.95.114:54308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9JjE0Dwhk5-Z44XrpYUAAAArc"]
[Tue Jul 21 07:27:24.826261 2026] [security2:error] [pid 229246:tid 229427] [client 20.220.225.223:46122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-css.php"] [unique_id "al9JjCBMYeh5YLVG45x88gAAAkc"]
[Tue Jul 21 07:27:24.865069 2026] [security2:error] [pid 229246:tid 229387] [client 20.104.96.117:62958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/goods.php"] [unique_id "al9JjCBMYeh5YLVG45x88wAAAh8"]
[Tue Jul 21 07:27:25.002765 2026] [security2:error] [pid 230252:tid 230382] [remote 45.156.129.117:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/bbpress/readme.txt"] [unique_id "al9JjU0Dwhk5-Z44XrpYUgAC-X8"], referer: http://bio.deiacakes.com/wp-content/plugins/bbpress/readme.txt
[Tue Jul 21 07:27:25.161183 2026] [security2:error] [pid 229246:tid 229477] [client 20.104.96.117:59827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/sump1.php"] [unique_id "al9JjSBMYeh5YLVG45x89wAAAnk"]
[Tue Jul 21 07:27:25.304614 2026] [security2:error] [pid 230252:tid 230494] [client 103.174.34.15:63145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JjU0Dwhk5-Z44XrpYVAAAAwc"]
[Tue Jul 21 07:27:25.304942 2026] [security2:error] [pid 230252:tid 230494] [client 103.174.34.15:63145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JjU0Dwhk5-Z44XrpYVAAAAwc"]
[Tue Jul 21 07:27:25.389601 2026] [security2:error] [pid 229246:tid 229407] [client 59.96.220.140:64387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JjSBMYeh5YLVG45x8_QAAAjM"]
[Tue Jul 21 07:27:25.389718 2026] [security2:error] [pid 229246:tid 229407] [client 59.96.220.140:64387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JjSBMYeh5YLVG45x8_QAAAjM"]
[Tue Jul 21 07:27:25.559835 2026] [security2:error] [pid 229246:tid 229473] [client 20.104.96.117:4257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/100.php"] [unique_id "al9JjSBMYeh5YLVG45x9AgAAAnU"]
[Tue Jul 21 07:27:25.587975 2026] [security2:error] [pid 230252:tid 230387] [client 45.8.17.139:27215] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/ioxi-o.php"] [unique_id "al9JjU0Dwhk5-Z44XrpYVwAAApw"]
[Tue Jul 21 07:27:25.739341 2026] [security2:error] [pid 230252:tid 230503] [client 20.220.225.223:60369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/term.php"] [unique_id "al9JjU0Dwhk5-Z44XrpYWgAAAxA"]
[Tue Jul 21 07:27:25.913758 2026] [security2:error] [pid 230252:tid 230299] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/iwp-client/readme.txt"] [unique_id "al9JjU0Dwhk5-Z44XrpYYAADES0"], referer: http://bio.deiacakes.com/wp-content/plugins/iwp-client/readme.txt
[Tue Jul 21 07:27:25.923053 2026] [security2:error] [pid 229246:tid 229421] [client 175.45.70.82:54134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JjSBMYeh5YLVG45x9BwAAAkE"]
[Tue Jul 21 07:27:25.923207 2026] [security2:error] [pid 229246:tid 229421] [client 175.45.70.82:54134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JjSBMYeh5YLVG45x9BwAAAkE"]
[Tue Jul 21 07:27:25.933507 2026] [security2:error] [pid 230252:tid 230264] [remote 151.123.177.119:59659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.177.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9JjU0Dwhk5-Z44XrpYWwACqQo"]
[Tue Jul 21 07:27:26.128622 2026] [security2:error] [pid 230252:tid 230448] [client 20.104.96.117:59812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/file5.php"] [unique_id "al9Jjk0Dwhk5-Z44XrpYYQAAAtk"]
[Tue Jul 21 07:27:26.148568 2026] [security2:error] [pid 229246:tid 229403] [client 20.104.96.117:62952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/about.php"] [unique_id "al9JjiBMYeh5YLVG45x9CAAAAi8"]
[Tue Jul 21 07:27:26.232638 2026] [security2:error] [pid 230252:tid 230467] [client 154.192.233.199:60124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jjk0Dwhk5-Z44XrpYYwAAAuw"]
[Tue Jul 21 07:27:26.232746 2026] [security2:error] [pid 230252:tid 230467] [client 154.192.233.199:60124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jjk0Dwhk5-Z44XrpYYwAAAuw"]
[Tue Jul 21 07:27:26.385829 2026] [security2:error] [pid 230252:tid 230450] [client 45.8.17.130:25467] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/IXR/"] [unique_id "al9Jjk0Dwhk5-Z44XrpYZQAAAts"]
[Tue Jul 21 07:27:26.642094 2026] [security2:error] [pid 230252:tid 230320] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wp-central/readme.txt"] [unique_id "al9Jjk0Dwhk5-Z44XrpYaQAC9EI"], referer: http://bio.deiacakes.com/wp-content/plugins/wp-central/readme.txt
[Tue Jul 21 07:27:26.740526 2026] [security2:error] [pid 230252:tid 230505] [client 20.104.96.117:5079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/about.php"] [unique_id "al9Jjk0Dwhk5-Z44XrpYawAAAxI"]
[Tue Jul 21 07:27:26.770125 2026] [security2:error] [pid 229246:tid 229283] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JjiBMYeh5YLVG45x9EwACPiQ"]
[Tue Jul 21 07:27:26.770254 2026] [security2:error] [pid 229246:tid 229418] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JjiBMYeh5YLVG45x9EwACPiQ"]
[Tue Jul 21 07:27:26.772547 2026] [security2:error] [pid 230252:tid 230444] [client 20.151.10.161:65513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/k2.php"] [unique_id "al9Jjk0Dwhk5-Z44XrpYbAAAAtU"]
[Tue Jul 21 07:27:26.842215 2026] [security2:error] [pid 229246:tid 229309] [remote 45.3.47.223:52717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.47.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9JjiBMYeh5YLVG45x9DwACOT4"]
[Tue Jul 21 07:27:27.050722 2026] [security2:error] [pid 230252:tid 230462] [client 82.102.28.107:46122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Jj00Dwhk5-Z44XrpYcgAAAuc"]
[Tue Jul 21 07:27:27.050796 2026] [security2:error] [pid 230252:tid 230462] [client 82.102.28.107:46122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Jj00Dwhk5-Z44XrpYcgAAAuc"]
[Tue Jul 21 07:27:27.379661 2026] [security2:error] [pid 230252:tid 230430] [client 20.104.96.117:64020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/admin.php"] [unique_id "al9Jj00Dwhk5-Z44XrpYdgAAAsc"]
[Tue Jul 21 07:27:27.488281 2026] [security2:error] [pid 229246:tid 229489] [client 20.220.225.223:60353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/ah25.php"] [unique_id "al9JjyBMYeh5YLVG45x9GwAAAoU"]
[Tue Jul 21 07:27:27.658250 2026] [security2:error] [pid 230252:tid 230313] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jj00Dwhk5-Z44XrpYeQAC6Ts"]
[Tue Jul 21 07:27:27.658362 2026] [security2:error] [pid 230252:tid 230464] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jj00Dwhk5-Z44XrpYeQAC6Ts"]
[Tue Jul 21 07:27:27.682618 2026] [security2:error] [pid 230252:tid 230480] [client 45.8.17.65:55421] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/404.php"] [unique_id "al9Jj00Dwhk5-Z44XrpYegAAAvk"]
[Tue Jul 21 07:27:27.797021 2026] [security2:error] [pid 230252:tid 230340] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wp-time-capsule/readme.txt"] [unique_id "al9Jj00Dwhk5-Z44XrpYewAC8FU"], referer: http://bio.deiacakes.com/wp-content/plugins/wp-time-capsule/readme.txt
[Tue Jul 21 07:27:27.853401 2026] [security2:error] [pid 230252:tid 230401] [client 20.104.96.117:64012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/admin.php"] [unique_id "al9Jj00Dwhk5-Z44XrpYfwAAAqo"]
[Tue Jul 21 07:27:28.100727 2026] [security2:error] [pid 230252:tid 230466] [client 20.151.10.161:63637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/82.php"] [unique_id "al9JkE0Dwhk5-Z44XrpYggAAAus"]
[Tue Jul 21 07:27:28.177320 2026] [security2:error] [pid 230252:tid 230503] [client 20.220.225.223:38669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/term.php"] [unique_id "al9JkE0Dwhk5-Z44XrpYgwAAAxA"]
[Tue Jul 21 07:27:28.220743 2026] [security2:error] [pid 230252:tid 230414] [client 103.162.129.114:62623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JkE0Dwhk5-Z44XrpYhAAAArc"]
[Tue Jul 21 07:27:28.220875 2026] [security2:error] [pid 230252:tid 230414] [client 103.162.129.114:62623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JkE0Dwhk5-Z44XrpYhAAAArc"]
[Tue Jul 21 07:27:28.413048 2026] [security2:error] [pid 230252:tid 230510] [client 20.104.96.117:62969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/themes.php"] [unique_id "al9JkE0Dwhk5-Z44XrpYiQAAAxc"]
[Tue Jul 21 07:27:28.493327 2026] [security2:error] [pid 229246:tid 229494] [client 193.36.225.62:35811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JkCBMYeh5YLVG45x9IAAAAoo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:27:28.621516 2026] [security2:error] [pid 229246:tid 229402] [client 20.104.96.117:59821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/0xD.php"] [unique_id "al9JkCBMYeh5YLVG45x9KAAAAi4"]
[Tue Jul 21 07:27:28.626906 2026] [security2:error] [pid 230252:tid 230467] [client 20.151.10.161:49103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/p.php"] [unique_id "al9JkE0Dwhk5-Z44XrpYjAAAAuw"]
[Tue Jul 21 07:27:28.882283 2026] [security2:error] [pid 230252:tid 230385] [client 45.8.17.61:41913] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/mah.php"] [unique_id "al9JkE0Dwhk5-Z44XrpYkgAAApo"]
[Tue Jul 21 07:27:29.044926 2026] [security2:error] [pid 229246:tid 229380] [client 20.220.225.223:45955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-explorer.php"] [unique_id "al9JkSBMYeh5YLVG45x9MQAAAhg"]
[Tue Jul 21 07:27:29.213698 2026] [security2:error] [pid 230252:tid 230366] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/fancy-product-designer/readme.txt"] [unique_id "al9JkU0Dwhk5-Z44XrpYlwADBm8"], referer: http://bio.deiacakes.com/wp-content/plugins/fancy-product-designer/readme.txt
[Tue Jul 21 07:27:29.385153 2026] [security2:error] [pid 230252:tid 230505] [client 20.220.225.223:53456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/8.php"] [unique_id "al9JkU0Dwhk5-Z44XrpYmQAAAxI"]
[Tue Jul 21 07:27:29.447154 2026] [security2:error] [pid 229246:tid 229332] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JkSBMYeh5YLVG45x9NQACIFU"]
[Tue Jul 21 07:27:29.447259 2026] [security2:error] [pid 229246:tid 229388] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JkSBMYeh5YLVG45x9NQACIFU"]
[Tue Jul 21 07:27:29.640560 2026] [security2:error] [pid 230252:tid 230426] [client 152.59.154.239:50883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JkU0Dwhk5-Z44XrpYngAAAsM"]
[Tue Jul 21 07:27:29.770044 2026] [security2:error] [pid 230252:tid 230301] [remote 45.3.36.177:17829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.36.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9JkE0Dwhk5-Z44XrpYkAADES8"]
[Tue Jul 21 07:27:29.898565 2026] [security2:error] [pid 229246:tid 229468] [client 20.151.10.161:63665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/config.json.php"] [unique_id "al9JkSBMYeh5YLVG45x9OAAAAnA"]
[Tue Jul 21 07:27:29.958122 2026] [security2:error] [pid 230252:tid 230501] [client 213.152.162.104:51286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9JkU0Dwhk5-Z44XrpYowAAAw4"]
[Tue Jul 21 07:27:29.958199 2026] [security2:error] [pid 230252:tid 230501] [client 213.152.162.104:51286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9JkU0Dwhk5-Z44XrpYowAAAw4"]
[Tue Jul 21 07:27:30.083543 2026] [security2:error] [pid 230252:tid 230502] [client 45.8.17.123:41699] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/"] [unique_id "al9Jkk0Dwhk5-Z44XrpYpAAAAw8"]
[Tue Jul 21 07:27:30.227200 2026] [security2:error] [pid 230252:tid 230438] [client 74.249.245.134:17455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/wp-links.php"] [unique_id "al9Jkk0Dwhk5-Z44XrpYpwAAAs8"]
[Tue Jul 21 07:27:30.242336 2026] [security2:error] [pid 230252:tid 230273] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/code-snippets/readme.txt"] [unique_id "al9Jkk0Dwhk5-Z44XrpYqAADARM"], referer: http://bio.deiacakes.com/wp-content/plugins/code-snippets/readme.txt
[Tue Jul 21 07:27:30.524446 2026] [autoindex:error] [pid 229246:tid 229484] [client 20.104.96.117:5062] AH01276: Cannot serve directory /home4/forev309/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:30.588658 2026] [security2:error] [pid 229246:tid 229426] [client 139.135.44.145:54704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JkiBMYeh5YLVG45x9UQAAAkY"]
[Tue Jul 21 07:27:30.588736 2026] [security2:error] [pid 229246:tid 229426] [client 139.135.44.145:54704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JkiBMYeh5YLVG45x9UQAAAkY"]
[Tue Jul 21 07:27:30.684738 2026] [security2:error] [pid 230252:tid 230405] [client 20.220.225.223:55761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/red.php"] [unique_id "al9Jkk0Dwhk5-Z44XrpYqwAAAq4"]
[Tue Jul 21 07:27:31.092530 2026] [security2:error] [pid 229246:tid 229377] [client 45.8.17.124:65269] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp.php"] [unique_id "al9JkyBMYeh5YLVG45x9kwAAAhU"]
[Tue Jul 21 07:27:31.509050 2026] [security2:error] [pid 229246:tid 229422] [client 20.220.225.223:46137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/akismet.php"] [unique_id "al9JkyBMYeh5YLVG45x9mAAAAkI"]
[Tue Jul 21 07:27:31.551756 2026] [security2:error] [pid 229246:tid 229267] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wpschoolpress/readme.txt"] [unique_id "al9JkyBMYeh5YLVG45x9nQACiRQ"], referer: http://bio.deiacakes.com/wp-content/plugins/wpschoolpress/readme.txt
[Tue Jul 21 07:27:31.746511 2026] [security2:error] [pid 230252:tid 230445] [client 117.251.86.144:39886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Jk00Dwhk5-Z44XrpYtwAAAtY"]
[Tue Jul 21 07:27:31.746647 2026] [security2:error] [pid 230252:tid 230445] [client 117.251.86.144:39886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Jk00Dwhk5-Z44XrpYtwAAAtY"]
[Tue Jul 21 07:27:31.751819 2026] [security2:error] [pid 229246:tid 229408] [client 20.52.136.55:1590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/wp-mail.php"] [unique_id "al9JkyBMYeh5YLVG45x9nwAAAjQ"]
[Tue Jul 21 07:27:31.985521 2026] [security2:error] [pid 229246:tid 229388] [client 45.8.17.135:43323] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/hello-plus/classes/ehp-sarang.php"] [unique_id "al9JkyBMYeh5YLVG45x92wAAAiA"]
[Tue Jul 21 07:27:32.175413 2026] [security2:error] [pid 229246:tid 229468] [client 20.151.10.161:63698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/fpwch.php"] [unique_id "al9JlCBMYeh5YLVG45x94AAAAnA"]
[Tue Jul 21 07:27:32.175443 2026] [security2:error] [pid 230252:tid 230436] [client 20.220.225.223:55760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/fffm.php"] [unique_id "al9JlE0Dwhk5-Z44XrpYzAAAAs0"]
[Tue Jul 21 07:27:32.257663 2026] [core:alert] [pid 230252:tid 230429] [client 57.141.18.0:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:27:32.264601 2026] [security2:error] [pid 229246:tid 229452] [client 20.104.96.117:5062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/.well-known/about.php"] [unique_id "al9JlCBMYeh5YLVG45x94wAAAmA"]
[Tue Jul 21 07:27:32.570690 2026] [security2:error] [pid 230252:tid 230258] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wordpress-database-reset/readme.txt"] [unique_id "al9JlE0Dwhk5-Z44XrpYzwACvwQ"], referer: http://bio.deiacakes.com/wp-content/plugins/wordpress-database-reset/readme.txt
[Tue Jul 21 07:27:32.687268 2026] [security2:error] [pid 230252:tid 230464] [client 62.102.148.164:54118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9JlE0Dwhk5-Z44XrpY0gAAAuk"]
[Tue Jul 21 07:27:32.687353 2026] [security2:error] [pid 230252:tid 230464] [client 62.102.148.164:54118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9JlE0Dwhk5-Z44XrpY0gAAAuk"]
[Tue Jul 21 07:27:32.740244 2026] [security2:error] [pid 229246:tid 229424] [client 20.104.96.117:59778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/fnstall.php"] [unique_id "al9JlCBMYeh5YLVG45x98AAAAkQ"]
[Tue Jul 21 07:27:32.741639 2026] [security2:error] [pid 230252:tid 230405] [client 20.220.225.223:27148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/ftde.php"] [unique_id "al9JlE0Dwhk5-Z44XrpY0wAAAq4"]
[Tue Jul 21 07:27:32.823967 2026] [security2:error] [pid 230252:tid 230370] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JlE0Dwhk5-Z44XrpY1AAC-XM"]
[Tue Jul 21 07:27:32.824111 2026] [security2:error] [pid 230252:tid 230480] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JlE0Dwhk5-Z44XrpY1AAC-XM"]
[Tue Jul 21 07:27:32.888462 2026] [security2:error] [pid 230252:tid 230395] [client 20.104.96.117:62922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9JlE0Dwhk5-Z44XrpY1QAAAqQ"]
[Tue Jul 21 07:27:32.901487 2026] [security2:error] [pid 229246:tid 229464] [client 45.251.232.145:51170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JlCBMYeh5YLVG45x9_AAAAmw"]
[Tue Jul 21 07:27:32.901655 2026] [security2:error] [pid 229246:tid 229464] [client 45.251.232.145:51170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JlCBMYeh5YLVG45x9_AAAAmw"]
[Tue Jul 21 07:27:33.085017 2026] [security2:error] [pid 230252:tid 230387] [client 45.8.17.113:36679] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentyone/content-index.php"] [unique_id "al9JlU0Dwhk5-Z44XrpY1gAAApw"]
[Tue Jul 21 07:27:33.241277 2026] [security2:error] [pid 229246:tid 229411] [client 20.104.96.117:5096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wefile.php"] [unique_id "al9JlSBMYeh5YLVG45x-EAAAAjc"]
[Tue Jul 21 07:27:33.425916 2026] [security2:error] [pid 230252:tid 230342] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JlU0Dwhk5-Z44XrpY2gACulc"]
[Tue Jul 21 07:27:33.426059 2026] [security2:error] [pid 230252:tid 230417] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JlU0Dwhk5-Z44XrpY2gACulc"]
[Tue Jul 21 07:27:33.452934 2026] [security2:error] [pid 230252:tid 230333] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/contact-form-7/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY2wACvE4"], referer: http://bio.deiacakes.com/wp-content/plugins/contact-form-7/readme.txt
[Tue Jul 21 07:27:33.497030 2026] [security2:error] [pid 230252:tid 230355] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wordfence/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY3QAC92Q"], referer: http://bio.deiacakes.com/wp-content/plugins/wordfence/readme.txt
[Tue Jul 21 07:27:33.503740 2026] [security2:error] [pid 229246:tid 229366] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/essential-addons-for-elementor-lite/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-EQACinc"], referer: http://bio.deiacakes.com/wp-content/plugins/essential-addons-for-elementor-lite/readme.txt
[Tue Jul 21 07:27:33.508172 2026] [security2:error] [pid 230252:tid 230276] [remote 45.156.129.117:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/litespeed-cache/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY3gAC9hY"], referer: http://bio.deiacakes.com/wp-content/plugins/litespeed-cache/readme.txt
[Tue Jul 21 07:27:33.519704 2026] [security2:error] [pid 229246:tid 229341] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/all-in-one-wp-migration/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-EwACFl4"], referer: http://bio.deiacakes.com/wp-content/plugins/all-in-one-wp-migration/readme.txt
[Tue Jul 21 07:27:33.538377 2026] [security2:error] [pid 230252:tid 230310] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/google-site-kit/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY3wACozg"], referer: http://bio.deiacakes.com/wp-content/plugins/google-site-kit/readme.txt
[Tue Jul 21 07:27:33.548344 2026] [security2:error] [pid 229246:tid 229326] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wordpress-seo/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-FAACfE8"], referer: http://bio.deiacakes.com/wp-content/plugins/wordpress-seo/readme.txt
[Tue Jul 21 07:27:33.561988 2026] [security2:error] [pid 230252:tid 230351] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/insert-headers-and-footers/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY4AACrWA"], referer: http://bio.deiacakes.com/wp-content/plugins/insert-headers-and-footers/readme.txt
[Tue Jul 21 07:27:33.574338 2026] [security2:error] [pid 229246:tid 229278] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/duplicate-page/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-FgACLh8"], referer: http://bio.deiacakes.com/wp-content/plugins/duplicate-page/readme.txt
[Tue Jul 21 07:27:33.575850 2026] [security2:error] [pid 230252:tid 230261] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wp-super-cache/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY4QAC0gc"], referer: http://bio.deiacakes.com/wp-content/plugins/wp-super-cache/readme.txt
[Tue Jul 21 07:27:33.579852 2026] [security2:error] [pid 230252:tid 230292] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/redirection/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY4gAC1iY"], referer: http://bio.deiacakes.com/wp-content/plugins/redirection/readme.txt
[Tue Jul 21 07:27:33.585702 2026] [security2:error] [pid 230252:tid 230290] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/woocommerce/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY4wAC5iQ"], referer: http://bio.deiacakes.com/wp-content/plugins/woocommerce/readme.txt
[Tue Jul 21 07:27:33.597246 2026] [security2:error] [pid 230252:tid 230284] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/google-analytics-for-wordpress/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY5QAC2x4"], referer: http://bio.deiacakes.com/wp-content/plugins/google-analytics-for-wordpress/readme.txt
[Tue Jul 21 07:27:33.598274 2026] [security2:error] [pid 230252:tid 230296] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/duplicator/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY5gADBCo"], referer: http://bio.deiacakes.com/wp-content/plugins/duplicator/readme.txt
[Tue Jul 21 07:27:33.604547 2026] [security2:error] [pid 229246:tid 229264] [remote 45.156.129.117:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/seo-by-rank-math/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-GAAChRE"], referer: http://bio.deiacakes.com/wp-content/plugins/seo-by-rank-math/readme.txt
[Tue Jul 21 07:27:33.617879 2026] [security2:error] [pid 230252:tid 230363] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/disable-comments/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY5wADC2w"], referer: http://bio.deiacakes.com/wp-content/plugins/disable-comments/readme.txt
[Tue Jul 21 07:27:33.640470 2026] [security2:error] [pid 229246:tid 229356] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wp-file-manager/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-HwACUW0"], referer: http://bio.deiacakes.com/wp-content/plugins/wp-file-manager/readme.txt
[Tue Jul 21 07:27:33.641471 2026] [security2:error] [pid 230252:tid 230465] [client 59.96.220.140:64840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JlU0Dwhk5-Z44XrpY6AAAAuo"]
[Tue Jul 21 07:27:33.641581 2026] [security2:error] [pid 230252:tid 230465] [client 59.96.220.140:64840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JlU0Dwhk5-Z44XrpY6AAAAuo"]
[Tue Jul 21 07:27:33.651791 2026] [security2:error] [pid 230252:tid 230500] [client 20.104.96.117:64009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9JlU0Dwhk5-Z44XrpY6QAAAw0"]
[Tue Jul 21 07:27:33.651866 2026] [security2:error] [pid 230252:tid 230365] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/w3-total-cache/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY6gADAG4"], referer: http://bio.deiacakes.com/wp-content/plugins/w3-total-cache/readme.txt
[Tue Jul 21 07:27:33.652288 2026] [security2:error] [pid 230252:tid 230349] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/better-search-replace/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY6wADAF4"], referer: http://bio.deiacakes.com/wp-content/plugins/better-search-replace/readme.txt
[Tue Jul 21 07:27:33.674316 2026] [security2:error] [pid 229246:tid 229252] [remote 45.156.129.117:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/loginizer/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-IQACagU"], referer: http://bio.deiacakes.com/wp-content/plugins/loginizer/readme.txt
[Tue Jul 21 07:27:33.675603 2026] [security2:error] [pid 230252:tid 230331] [remote 45.156.129.117:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/ewww-image-optimizer/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY7AAC0Ew"], referer: http://bio.deiacakes.com/wp-content/plugins/ewww-image-optimizer/readme.txt
[Tue Jul 21 07:27:33.679055 2026] [security2:error] [pid 230252:tid 230285] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/all-in-one-wp-security-and-firewall/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY7QAC6B8"], referer: http://bio.deiacakes.com/wp-content/plugins/all-in-one-wp-security-and-firewall/readme.txt
[Tue Jul 21 07:27:33.679590 2026] [security2:error] [pid 229246:tid 229351] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/envato-elements/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-IgACkGg"], referer: http://bio.deiacakes.com/wp-content/plugins/envato-elements/readme.txt
[Tue Jul 21 07:27:33.684931 2026] [security2:error] [pid 230252:tid 230270] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/coming-soon/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY7gAC3xA"], referer: http://bio.deiacakes.com/wp-content/plugins/coming-soon/readme.txt
[Tue Jul 21 07:27:33.687189 2026] [security2:error] [pid 230252:tid 230413] [client 20.52.136.55:1736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/about.php"] [unique_id "al9JlU0Dwhk5-Z44XrpY7wAAArY"]
[Tue Jul 21 07:27:33.757796 2026] [security2:error] [pid 229246:tid 229379] [client 193.36.225.62:38507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JlSBMYeh5YLVG45x-IwAAAhc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:27:33.782380 2026] [security2:error] [pid 229246:tid 229271] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wpforms-lite/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-TgACMhg"], referer: http://bio.deiacakes.com/wp-content/plugins/wpforms-lite/readme.txt
[Tue Jul 21 07:27:33.802679 2026] [security2:error] [pid 230252:tid 230368] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/akismet/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY8QAC4XE"], referer: http://bio.deiacakes.com/wp-content/plugins/akismet/readme.txt
[Tue Jul 21 07:27:33.847824 2026] [security2:error] [pid 229246:tid 229261] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/duplicate-post/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-UAACGw4"], referer: http://bio.deiacakes.com/wp-content/plugins/duplicate-post/readme.txt
[Tue Jul 21 07:27:33.855038 2026] [security2:error] [pid 229246:tid 229275] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/mailchimp-for-wp/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-UQACexw"], referer: http://bio.deiacakes.com/wp-content/plugins/mailchimp-for-wp/readme.txt
[Tue Jul 21 07:27:33.856227 2026] [security2:error] [pid 230252:tid 230277] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/all-in-one-seo-pack/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY8gACyRc"], referer: http://bio.deiacakes.com/wp-content/plugins/all-in-one-seo-pack/readme.txt
[Tue Jul 21 07:27:33.865666 2026] [security2:error] [pid 230252:tid 230369] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/header-footer-elementor/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY8wAC7HI"], referer: http://bio.deiacakes.com/wp-content/plugins/header-footer-elementor/readme.txt
[Tue Jul 21 07:27:33.867348 2026] [security2:error] [pid 230252:tid 230278] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wp-fastest-cache/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY9AACrxg"], referer: http://bio.deiacakes.com/wp-content/plugins/wp-fastest-cache/readme.txt
[Tue Jul 21 07:27:33.877300 2026] [security2:error] [pid 229246:tid 229305] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wps-hide-login/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-UgACGjo"], referer: http://bio.deiacakes.com/wp-content/plugins/wps-hide-login/readme.txt
[Tue Jul 21 07:27:33.880205 2026] [security2:error] [pid 230252:tid 230297] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/really-simple-ssl/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY9QAC-ys"], referer: http://bio.deiacakes.com/wp-content/plugins/really-simple-ssl/readme.txt
[Tue Jul 21 07:27:33.880479 2026] [security2:error] [pid 229246:tid 229362] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/astra-sites/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-UwACV3M"], referer: http://bio.deiacakes.com/wp-content/plugins/astra-sites/readme.txt
[Tue Jul 21 07:27:33.885618 2026] [security2:error] [pid 229246:tid 229332] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/limit-login-attempts-reloaded/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-VAACFFU"], referer: http://bio.deiacakes.com/wp-content/plugins/limit-login-attempts-reloaded/readme.txt
[Tue Jul 21 07:27:33.896691 2026] [security2:error] [pid 230252:tid 230381] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/updraftplus/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY9gAC9H4"], referer: http://bio.deiacakes.com/wp-content/plugins/updraftplus/readme.txt
[Tue Jul 21 07:27:33.903980 2026] [security2:error] [pid 230252:tid 230257] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/jetpack/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY9wACzAM"], referer: http://bio.deiacakes.com/wp-content/plugins/jetpack/readme.txt
[Tue Jul 21 07:27:33.916316 2026] [security2:error] [pid 230252:tid 230256] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/advanced-custom-fields/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY-AADEgI"], referer: http://bio.deiacakes.com/wp-content/plugins/advanced-custom-fields/readme.txt
[Tue Jul 21 07:27:33.922197 2026] [security2:error] [pid 229246:tid 229372] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/svg-support/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-VQACHH0"], referer: http://bio.deiacakes.com/wp-content/plugins/svg-support/readme.txt
[Tue Jul 21 07:27:33.937366 2026] [security2:error] [pid 230252:tid 230334] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/ultimate-addons-for-gutenberg/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY-QADE08"], referer: http://bio.deiacakes.com/wp-content/plugins/ultimate-addons-for-gutenberg/readme.txt
[Tue Jul 21 07:27:33.941467 2026] [security2:error] [pid 230252:tid 230350] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/sg-security/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY-gACy18"], referer: http://bio.deiacakes.com/wp-content/plugins/sg-security/readme.txt
[Tue Jul 21 07:27:33.957229 2026] [security2:error] [pid 230252:tid 230380] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/smart-slider-3/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY-wAC1X0"], referer: http://bio.deiacakes.com/wp-content/plugins/smart-slider-3/readme.txt
[Tue Jul 21 07:27:33.965105 2026] [security2:error] [pid 230252:tid 230272] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/redux-framework/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY_AACtBI"], referer: http://bio.deiacakes.com/wp-content/plugins/redux-framework/readme.txt
[Tue Jul 21 07:27:33.972710 2026] [security2:error] [pid 229246:tid 229292] [remote 45.156.129.117:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/autoptimize/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-VgACYi0"], referer: http://bio.deiacakes.com/wp-content/plugins/autoptimize/readme.txt
[Tue Jul 21 07:27:33.978574 2026] [security2:error] [pid 230252:tid 230266] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/hostinger/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY_gADBgw"], referer: http://bio.deiacakes.com/wp-content/plugins/hostinger/readme.txt
[Tue Jul 21 07:27:33.978785 2026] [security2:error] [pid 229246:tid 229363] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wp-optimize/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-VwACaHQ"], referer: http://bio.deiacakes.com/wp-content/plugins/wp-optimize/readme.txt
[Tue Jul 21 07:27:33.979614 2026] [security2:error] [pid 229246:tid 229295] [remote 45.156.129.117:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/better-wp-security/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-WAACSTA"], referer: http://bio.deiacakes.com/wp-content/plugins/better-wp-security/readme.txt
[Tue Jul 21 07:27:33.980113 2026] [autoindex:error] [pid 230252:tid 230473] [client 20.104.96.117:62928] AH01276: Cannot serve directory /home4/forev309/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:33.985784 2026] [security2:error] [pid 230252:tid 230321] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/complianz-gdpr/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY_wACm0M"], referer: http://bio.deiacakes.com/wp-content/plugins/complianz-gdpr/readme.txt
[Tue Jul 21 07:27:33.989060 2026] [security2:error] [pid 229246:tid 229395] [client 45.8.17.48:49051] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/admin.php"] [unique_id "al9JlSBMYeh5YLVG45x-WQAAAic"]
[Tue Jul 21 07:27:34.030149 2026] [security2:error] [pid 229246:tid 229456] [client 20.220.225.223:46112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/ace2.php"] [unique_id "al9JliBMYeh5YLVG45x-WgAAAmQ"]
[Tue Jul 21 07:27:34.219958 2026] [security2:error] [pid 229246:tid 229277] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JliBMYeh5YLVG45x-YgACHR4"]
[Tue Jul 21 07:27:34.220135 2026] [security2:error] [pid 229246:tid 229385] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JliBMYeh5YLVG45x-YgACHR4"]
[Tue Jul 21 07:27:34.344004 2026] [autoindex:error] [pid 230252:tid 230396] [client 20.104.96.117:62928] AH01276: Cannot serve directory /home4/forev309/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:34.372678 2026] [autoindex:error] [pid 229246:tid 229476] [client 192.175.111.239:38103] AH01276: Cannot serve directory /home4/ciclod61/bahtelecom.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:34.482659 2026] [security2:error] [pid 230252:tid 230408] [client 20.104.96.117:62928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Jlk0Dwhk5-Z44XrpZBgAAArE"]
[Tue Jul 21 07:27:34.616503 2026] [security2:error] [pid 229246:tid 229306] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JliBMYeh5YLVG45x-ZwACUzs"]
[Tue Jul 21 07:27:34.616639 2026] [security2:error] [pid 229246:tid 229439] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JliBMYeh5YLVG45x-ZwACUzs"]
[Tue Jul 21 07:27:34.808013 2026] [security2:error] [pid 230252:tid 230479] [client 103.106.20.201:51407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jlk0Dwhk5-Z44XrpZCwAAAvg"]
[Tue Jul 21 07:27:34.808157 2026] [security2:error] [pid 230252:tid 230479] [client 103.106.20.201:51407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jlk0Dwhk5-Z44XrpZCwAAAvg"]
[Tue Jul 21 07:27:34.817560 2026] [security2:error] [pid 229246:tid 229404] [client 20.104.96.117:64040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/8.php"] [unique_id "al9JliBMYeh5YLVG45x-agAAAjA"]
[Tue Jul 21 07:27:34.983185 2026] [security2:error] [pid 230252:tid 230328] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/kingcomposer/readme.txt"] [unique_id "al9Jlk0Dwhk5-Z44XrpZDAACq0k"], referer: http://bio.deiacakes.com/wp-content/plugins/kingcomposer/readme.txt
[Tue Jul 21 07:27:35.077517 2026] [security2:error] [pid 230252:tid 230265] [remote 157.66.26.183:44642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cdatecnologia.com.br"] [uri "/wp-login.php"] [unique_id "al9Jlk0Dwhk5-Z44XrpZAAAC4ws"]
[Tue Jul 21 07:27:35.184367 2026] [security2:error] [pid 230252:tid 230494] [client 45.8.17.108:55455] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/404.php"] [unique_id "al9Jl00Dwhk5-Z44XrpZDQAAAwc"]
[Tue Jul 21 07:27:35.188013 2026] [security2:error] [pid 230252:tid 230390] [client 20.220.225.223:60366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/yup.php"] [unique_id "al9Jl00Dwhk5-Z44XrpZDgAAAp8"]
[Tue Jul 21 07:27:35.197726 2026] [security2:error] [pid 230252:tid 230399] [client 20.104.96.117:59592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/acp.php"] [unique_id "al9Jl00Dwhk5-Z44XrpZDwAAAqg"]
[Tue Jul 21 07:27:35.249901 2026] [security2:error] [pid 230252:tid 230442] [client 20.104.96.117:5078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp-content/admin.php"] [unique_id "al9Jl00Dwhk5-Z44XrpZEgAAAtM"]
[Tue Jul 21 07:27:35.653253 2026] [security2:error] [pid 229246:tid 229434] [client 20.104.96.117:64014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/f6.php"] [unique_id "al9JlyBMYeh5YLVG45x-eQAAAk4"]
[Tue Jul 21 07:27:35.767622 2026] [security2:error] [pid 230252:tid 230314] [remote 20.84.23.222:6141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.23.84.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/wp-login.php"] [unique_id "al9Jlk0Dwhk5-Z44XrpZCgACojw"]
[Tue Jul 21 07:27:35.879530 2026] [security2:error] [pid 229246:tid 229291] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wp-video-lightbox/readme.txt"] [unique_id "al9JlyBMYeh5YLVG45x-fQACPCw"], referer: http://bio.deiacakes.com/wp-content/plugins/wp-video-lightbox/readme.txt
[Tue Jul 21 07:27:36.010225 2026] [security2:error] [pid 230252:tid 230456] [client 20.104.96.117:64051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/inputs.php"] [unique_id "al9JmE0Dwhk5-Z44XrpZGwAAAuE"]
[Tue Jul 21 07:27:36.533144 2026] [security2:error] [pid 230252:tid 230439] [client 103.174.34.15:63882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JmE0Dwhk5-Z44XrpZIgAAAtA"]
[Tue Jul 21 07:27:36.533275 2026] [security2:error] [pid 230252:tid 230439] [client 103.174.34.15:63882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JmE0Dwhk5-Z44XrpZIgAAAtA"]
[Tue Jul 21 07:27:36.582511 2026] [security2:error] [pid 229246:tid 229428] [client 20.52.136.55:1751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/adminfuns.php"] [unique_id "al9JmCBMYeh5YLVG45x-gwAAAkg"]
[Tue Jul 21 07:27:36.639861 2026] [security2:error] [pid 230252:tid 230506] [client 20.104.96.117:62945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/inputs.php"] [unique_id "al9JmE0Dwhk5-Z44XrpZIwAAAxM"]
[Tue Jul 21 07:27:36.723748 2026] [security2:error] [pid 230252:tid 230508] [client 175.45.70.82:54650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JmE0Dwhk5-Z44XrpZJAAAAxU"]
[Tue Jul 21 07:27:36.723875 2026] [security2:error] [pid 230252:tid 230508] [client 175.45.70.82:54650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JmE0Dwhk5-Z44XrpZJAAAAxU"]
[Tue Jul 21 07:27:36.788109 2026] [security2:error] [pid 230252:tid 230467] [client 154.192.233.199:58786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JmE0Dwhk5-Z44XrpZJQAAAuw"]
[Tue Jul 21 07:27:36.788232 2026] [security2:error] [pid 230252:tid 230467] [client 154.192.233.199:58786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JmE0Dwhk5-Z44XrpZJQAAAuw"]
[Tue Jul 21 07:27:37.004143 2026] [security2:error] [pid 229246:tid 229376] [client 20.104.96.117:62971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/classwithtostring.php"] [unique_id "al9JmSBMYeh5YLVG45x-jQAAAhQ"]
[Tue Jul 21 07:27:37.092673 2026] [security2:error] [pid 230252:tid 230437] [client 45.8.17.60:29563] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/file.php"] [unique_id "al9JmU0Dwhk5-Z44XrpZJwAAAs4"]
[Tue Jul 21 07:27:37.097224 2026] [security2:error] [pid 229246:tid 229276] [remote 45.156.129.117:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/optinmonster/readme.txt"] [unique_id "al9JmSBMYeh5YLVG45x-jgACXh0"], referer: http://bio.deiacakes.com/wp-content/plugins/optinmonster/readme.txt
[Tue Jul 21 07:27:37.317597 2026] [security2:error] [pid 229246:tid 229289] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JmSBMYeh5YLVG45x-kgACjio"]
[Tue Jul 21 07:27:37.317760 2026] [security2:error] [pid 229246:tid 229498] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JmSBMYeh5YLVG45x-kgACjio"]
[Tue Jul 21 07:27:37.321419 2026] [proxy:error] [pid 230252:tid 230462] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:27:37.321499 2026] [proxy_http:error] [pid 230252:tid 230462] [client 20.151.10.161:48608] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:27:37.322057 2026] [proxy:error] [pid 230252:tid 230462] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:27:37.322094 2026] [proxy_http:error] [pid 230252:tid 230462] [client 20.151.10.161:48608] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:27:37.345216 2026] [security2:error] [pid 230252:tid 230416] [client 20.104.96.117:64027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9JmU0Dwhk5-Z44XrpZLAAAArk"]
[Tue Jul 21 07:27:37.367809 2026] [security2:error] [pid 230252:tid 230468] [client 109.248.148.246:36968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9JmU0Dwhk5-Z44XrpZLQAAAu0"]
[Tue Jul 21 07:27:37.367912 2026] [security2:error] [pid 230252:tid 230468] [client 109.248.148.246:36968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9JmU0Dwhk5-Z44XrpZLQAAAu0"]
[Tue Jul 21 07:27:37.469325 2026] [security2:error] [pid 229246:tid 229296] [remote 192.249.127.213:51344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.127.249.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9JmSBMYeh5YLVG45x-lAACHDE"]
[Tue Jul 21 07:27:37.657600 2026] [security2:error] [pid 230252:tid 230511] [client 20.220.225.223:53502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/jj.php"] [unique_id "al9JmU0Dwhk5-Z44XrpZNQAAAxg"]
[Tue Jul 21 07:27:37.750583 2026] [security2:error] [pid 230252:tid 230391] [client 20.104.96.117:5081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp-blog.php"] [unique_id "al9JmU0Dwhk5-Z44XrpZNgAAAqA"]
[Tue Jul 21 07:27:37.876422 2026] [security2:error] [pid 230252:tid 230372] [remote 4.205.168.44:52088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arthromdcanada.online"] [uri "/wp-login.php"] [unique_id "al9JmU0Dwhk5-Z44XrpZOwADDHU"]
[Tue Jul 21 07:27:37.881972 2026] [security2:error] [pid 230252:tid 230395] [client 45.8.17.106:65161] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/chosen.php"] [unique_id "al9JmU0Dwhk5-Z44XrpZPAAAAqQ"]
[Tue Jul 21 07:27:37.982634 2026] [security2:error] [pid 230252:tid 230387] [client 74.249.245.134:54388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/xmrlpc.php"] [unique_id "al9JmU0Dwhk5-Z44XrpZPgAAApw"]
[Tue Jul 21 07:27:38.099019 2026] [proxy:error] [pid 230252:tid 230419] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:27:38.099118 2026] [proxy_http:error] [pid 230252:tid 230419] [client 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:27:38.100419 2026] [proxy:error] [pid 230252:tid 230419] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:27:38.100485 2026] [proxy_http:error] [pid 230252:tid 230419] [client 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:27:38.123976 2026] [autoindex:error] [pid 230252:tid 230397] [client 20.104.96.117:62920] AH01276: Cannot serve directory /home4/forev309/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:38.137300 2026] [security2:error] [pid 230252:tid 230478] [client 20.104.96.117:42407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/mosty.php"] [unique_id "al9Jmk0Dwhk5-Z44XrpZQgAAAvc"]
[Tue Jul 21 07:27:38.192205 2026] [security2:error] [pid 230252:tid 230282] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jmk0Dwhk5-Z44XrpZQwAC9hw"]
[Tue Jul 21 07:27:38.192367 2026] [security2:error] [pid 230252:tid 230477] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jmk0Dwhk5-Z44XrpZQwAC9hw"]
[Tue Jul 21 07:27:38.404126 2026] [security2:error] [pid 230252:tid 230450] [client 20.104.96.117:62920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp-content/admin.php"] [unique_id "al9Jmk0Dwhk5-Z44XrpZRQAAAts"]
[Tue Jul 21 07:27:38.705143 2026] [proxy:error] [pid 229246:tid 229415] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:27:38.705214 2026] [proxy_http:error] [pid 229246:tid 229415] [client 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:27:38.705797 2026] [proxy:error] [pid 229246:tid 229415] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:27:38.705835 2026] [proxy_http:error] [pid 229246:tid 229415] [client 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:27:38.822927 2026] [security2:error] [pid 230252:tid 230474] [client 103.162.129.114:63065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Jmk0Dwhk5-Z44XrpZSgAAAvM"]
[Tue Jul 21 07:27:38.823111 2026] [security2:error] [pid 230252:tid 230474] [client 103.162.129.114:63065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Jmk0Dwhk5-Z44XrpZSgAAAvM"]
[Tue Jul 21 07:27:38.906764 2026] [security2:error] [pid 230252:tid 230434] [client 136.144.33.107:35589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Jmk0Dwhk5-Z44XrpZTAAAAss"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:27:38.910101 2026] [security2:error] [pid 230252:tid 230505] [client 20.220.225.223:60374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/dragonshell.php"] [unique_id "al9Jmk0Dwhk5-Z44XrpZTQAAAxI"]
[Tue Jul 21 07:27:38.974637 2026] [security2:error] [pid 230252:tid 230439] [client 20.104.96.117:62912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/ms-edit.php"] [unique_id "al9Jmk0Dwhk5-Z44XrpZTgAAAtA"]
[Tue Jul 21 07:27:39.180800 2026] [security2:error] [pid 229246:tid 229442] [client 45.8.17.140:37755] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/"] [unique_id "al9JmyBMYeh5YLVG45x-sAAAAlY"]
[Tue Jul 21 07:27:39.316668 2026] [security2:error] [pid 229246:tid 229414] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9JmyBMYeh5YLVG45x-tAAAAjo"]
[Tue Jul 21 07:27:39.350226 2026] [security2:error] [pid 229246:tid 229493] [client 20.104.96.117:62915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/cgi-bin/index.php"] [unique_id "al9JmyBMYeh5YLVG45x-tQAAAok"]
[Tue Jul 21 07:27:39.673410 2026] [security2:error] [pid 230252:tid 230397] [client 20.52.136.55:1582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/php8.php"] [unique_id "al9Jm00Dwhk5-Z44XrpZWAAAAqY"]
[Tue Jul 21 07:27:39.736463 2026] [security2:error] [pid 230252:tid 230419] [client 173.252.95.25:36072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Jm00Dwhk5-Z44XrpZWQAAArw"]
[Tue Jul 21 07:27:39.861667 2026] [autoindex:error] [pid 230252:tid 230399] [client 20.104.96.117:5083] AH01276: Cannot serve directory /home4/forev309/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:39.862898 2026] [security2:error] [pid 230252:tid 230477] [client 20.220.225.223:46118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/ms.php"] [unique_id "al9Jm00Dwhk5-Z44XrpZXAAAAvY"]
[Tue Jul 21 07:27:39.881477 2026] [security2:error] [pid 230252:tid 230453] [client 20.220.225.223:53440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/wp-mt.php"] [unique_id "al9Jm00Dwhk5-Z44XrpZXQAAAt4"]
[Tue Jul 21 07:27:39.933048 2026] [security2:error] [pid 230252:tid 230465] [client 159.223.41.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jm00Dwhk5-Z44XrpZXgAAAuo"]
[Tue Jul 21 07:27:39.985753 2026] [security2:error] [pid 230252:tid 230373] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jm00Dwhk5-Z44XrpZYAAC-nY"]
[Tue Jul 21 07:27:39.985911 2026] [security2:error] [pid 230252:tid 230481] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jm00Dwhk5-Z44XrpZYAAC-nY"]
[Tue Jul 21 07:27:39.989751 2026] [security2:error] [pid 230252:tid 230393] [client 45.8.17.112:40955] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/1.php"] [unique_id "al9Jm00Dwhk5-Z44XrpZYQAAAqI"]
[Tue Jul 21 07:27:40.147678 2026] [security2:error] [pid 230252:tid 230432] [client 20.104.96.117:5083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/BDKR28WP.php"] [unique_id "al9JnE0Dwhk5-Z44XrpZZAAAAsk"]
[Tue Jul 21 07:27:40.551416 2026] [proxy:error] [pid 229246:tid 229498] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:27:40.551484 2026] [proxy_http:error] [pid 229246:tid 229498] [client 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:27:40.551945 2026] [proxy:error] [pid 229246:tid 229498] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:27:40.551971 2026] [proxy_http:error] [pid 229246:tid 229498] [client 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:27:40.791700 2026] [autoindex:error] [pid 230252:tid 230473] [client 20.104.96.117:64059] AH01276: Cannot serve directory /home4/forev309/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:40.918214 2026] [security2:error] [pid 230252:tid 230449] [client 20.220.225.223:55793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/ww.php"] [unique_id "al9JnE0Dwhk5-Z44XrpZbQAAAto"]
[Tue Jul 21 07:27:40.979032 2026] [security2:error] [pid 230252:tid 230303] [remote 45.3.53.205:49993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.53.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9Jm00Dwhk5-Z44XrpZWgACujE"]
[Tue Jul 21 07:27:41.064327 2026] [security2:error] [pid 230252:tid 230403] [client 20.220.225.223:31190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/ah25.php"] [unique_id "al9JnU0Dwhk5-Z44XrpZbwAAAqw"]
[Tue Jul 21 07:27:41.103494 2026] [autoindex:error] [pid 230252:tid 230416] [client 20.104.96.117:64059] AH01276: Cannot serve directory /home4/forev309/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:41.169463 2026] [security2:error] [pid 230252:tid 230446] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9JnU0Dwhk5-Z44XrpZdAAAAtc"]
[Tue Jul 21 07:27:41.241848 2026] [security2:error] [pid 230252:tid 230451] [client 20.104.96.117:64059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/abcd.php"] [unique_id "al9JnU0Dwhk5-Z44XrpZdQAAAtw"]
[Tue Jul 21 07:27:41.392767 2026] [security2:error] [pid 230252:tid 230431] [client 45.8.17.121:42153] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/fukasawa/inc/classes/403.php"] [unique_id "al9JnU0Dwhk5-Z44XrpZdgAAAsg"]
[Tue Jul 21 07:27:41.649254 2026] [security2:error] [pid 230252:tid 230507] [client 139.135.44.145:53567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JnU0Dwhk5-Z44XrpZegAAAxQ"]
[Tue Jul 21 07:27:41.649565 2026] [security2:error] [pid 230252:tid 230507] [client 139.135.44.145:53567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JnU0Dwhk5-Z44XrpZegAAAxQ"]
[Tue Jul 21 07:27:41.779668 2026] [security2:error] [pid 230252:tid 230387] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9JnU0Dwhk5-Z44XrpZfQAAApw"]
[Tue Jul 21 07:27:42.051968 2026] [security2:error] [pid 230252:tid 230442] [client 74.249.245.134:5544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/htaccess.php"] [unique_id "al9Jnk0Dwhk5-Z44XrpZfwAAAtM"]
[Tue Jul 21 07:27:42.377454 2026] [security2:error] [pid 230252:tid 230488] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9Jnk0Dwhk5-Z44XrpZgwAAAwE"]
[Tue Jul 21 07:27:42.419239 2026] [security2:error] [pid 230252:tid 230394] [client 20.104.96.117:62975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/file15.php"] [unique_id "al9Jnk0Dwhk5-Z44XrpZhAAAAqM"]
[Tue Jul 21 07:27:42.521213 2026] [security2:error] [pid 230252:tid 230348] [remote 132.148.72.88:49604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.bomnegociopromotora.com.br"] [uri "/wp-login.php"] [unique_id "al9JnU0Dwhk5-Z44XrpZeAACpV0"]
[Tue Jul 21 07:27:42.532299 2026] [security2:error] [pid 229246:tid 229478] [client 117.251.86.144:34044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JniBMYeh5YLVG45x-3AAAAno"]
[Tue Jul 21 07:27:42.532408 2026] [security2:error] [pid 229246:tid 229478] [client 117.251.86.144:34044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JniBMYeh5YLVG45x-3AAAAno"]
[Tue Jul 21 07:27:42.661122 2026] [security2:error] [pid 229246:tid 229464] [client 20.104.96.117:59610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/6.php"] [unique_id "al9JniBMYeh5YLVG45x-3wAAAmw"]
[Tue Jul 21 07:27:42.689622 2026] [security2:error] [pid 230252:tid 230491] [client 20.220.225.223:53478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/cron.php"] [unique_id "al9Jnk0Dwhk5-Z44XrpZiAAAAwQ"]
[Tue Jul 21 07:27:42.761121 2026] [security2:error] [pid 229246:tid 229430] [client 74.7.228.56:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9JniBMYeh5YLVG45x-5AACSnY"]
[Tue Jul 21 07:27:42.822447 2026] [security2:error] [pid 230252:tid 230424] [client 136.144.33.111:34897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Jnk0Dwhk5-Z44XrpZjAAAAsE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:27:42.968689 2026] [security2:error] [pid 230252:tid 230437] [client 152.59.154.239:15245] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jnk0Dwhk5-Z44XrpZjQAAAs4"]
[Tue Jul 21 07:27:42.968820 2026] [security2:error] [pid 230252:tid 230437] [client 152.59.154.239:15245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jnk0Dwhk5-Z44XrpZjQAAAs4"]
[Tue Jul 21 07:27:42.977144 2026] [security2:error] [pid 229246:tid 229422] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9JniBMYeh5YLVG45x-6wAAAkI"]
[Tue Jul 21 07:27:43.289919 2026] [security2:error] [pid 229246:tid 229319] [remote 46.105.28.235:49778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.28.105.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/wp-login.php"] [unique_id "al9JnyBMYeh5YLVG45x-9gACLkg"]
[Tue Jul 21 07:27:43.366321 2026] [security2:error] [pid 229246:tid 229479] [client 20.220.225.223:55754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/xxx.php"] [unique_id "al9JnyBMYeh5YLVG45x--gAAAns"]
[Tue Jul 21 07:27:43.391438 2026] [security2:error] [pid 229246:tid 229447] [client 45.251.232.145:51683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JnyBMYeh5YLVG45x--wAAAls"]
[Tue Jul 21 07:27:43.391556 2026] [security2:error] [pid 229246:tid 229447] [client 45.251.232.145:51683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JnyBMYeh5YLVG45x--wAAAls"]
[Tue Jul 21 07:27:43.411576 2026] [security2:error] [pid 229246:tid 229463] [client 74.249.245.134:17451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/readme.php"] [unique_id "al9JnyBMYeh5YLVG45x-_AAAAms"]
[Tue Jul 21 07:27:43.436522 2026] [security2:error] [pid 229246:tid 229353] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JnyBMYeh5YLVG45x-_gACG2o"]
[Tue Jul 21 07:27:43.436630 2026] [security2:error] [pid 229246:tid 229383] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JnyBMYeh5YLVG45x-_gACG2o"]
[Tue Jul 21 07:27:43.585618 2026] [security2:error] [pid 229246:tid 229441] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9JnyBMYeh5YLVG45x_AgAAAlU"]
[Tue Jul 21 07:27:43.614562 2026] [security2:error] [pid 229246:tid 229459] [client 20.104.96.117:62946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/jp.php"] [unique_id "al9JnyBMYeh5YLVG45x_AwAAAmc"]
[Tue Jul 21 07:27:43.812166 2026] [security2:error] [pid 229246:tid 229481] [client 59.96.220.140:65072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JnyBMYeh5YLVG45x_BwAAAn0"]
[Tue Jul 21 07:27:43.812828 2026] [security2:error] [pid 229246:tid 229481] [client 59.96.220.140:65072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JnyBMYeh5YLVG45x_BwAAAn0"]
[Tue Jul 21 07:27:44.136379 2026] [security2:error] [pid 229246:tid 229456] [client 20.52.136.55:1759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/info.php"] [unique_id "al9JoCBMYeh5YLVG45x_CwAAAmQ"]
[Tue Jul 21 07:27:44.192628 2026] [security2:error] [pid 229246:tid 229417] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9JoCBMYeh5YLVG45x_DAAAAj0"]
[Tue Jul 21 07:27:44.584418 2026] [security2:error] [pid 230252:tid 230415] [client 20.220.225.223:60358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/hunter.php"] [unique_id "al9JoE0Dwhk5-Z44XrpZkwAAArg"]
[Tue Jul 21 07:27:44.687240 2026] [security2:error] [pid 229246:tid 229418] [client 74.249.245.134:54350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/403.php"] [unique_id "al9JoCBMYeh5YLVG45x_GAAAAj4"]
[Tue Jul 21 07:27:44.703574 2026] [security2:error] [pid 229246:tid 229377] [client 20.104.96.117:64010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/f35.php"] [unique_id "al9JoCBMYeh5YLVG45x_GQAAAhU"]
[Tue Jul 21 07:27:44.822855 2026] [security2:error] [pid 229246:tid 229442] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9JoCBMYeh5YLVG45x_GwAAAlY"]
[Tue Jul 21 07:27:45.115295 2026] [security2:error] [pid 230252:tid 230427] [client 20.104.96.117:64021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp-load.php"] [unique_id "al9JoU0Dwhk5-Z44XrpZlwAAAsQ"]
[Tue Jul 21 07:27:45.125747 2026] [security2:error] [pid 230252:tid 230323] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JoU0Dwhk5-Z44XrpZmAADDkU"]
[Tue Jul 21 07:27:45.125877 2026] [security2:error] [pid 230252:tid 230501] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JoU0Dwhk5-Z44XrpZmAADDkU"]
[Tue Jul 21 07:27:45.187999 2026] [security2:error] [pid 229246:tid 229416] [client 109.248.148.246:39706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9JoSBMYeh5YLVG45x_IAAAAjw"]
[Tue Jul 21 07:27:45.188115 2026] [security2:error] [pid 229246:tid 229416] [client 109.248.148.246:39706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9JoSBMYeh5YLVG45x_IAAAAjw"]
[Tue Jul 21 07:27:45.202308 2026] [security2:error] [pid 230252:tid 230262] [remote 65.111.28.178:40813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9JoU0Dwhk5-Z44XrpZmwAC5wg"]
[Tue Jul 21 07:27:45.439109 2026] [security2:error] [pid 230252:tid 230422] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9JoU0Dwhk5-Z44XrpZnQAAAr8"]
[Tue Jul 21 07:27:45.477346 2026] [security2:error] [pid 230252:tid 230431] [client 20.151.10.161:48587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/bthil.php"] [unique_id "al9JoU0Dwhk5-Z44XrpZngAAAsg"]
[Tue Jul 21 07:27:45.541710 2026] [security2:error] [pid 229246:tid 229310] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JoSBMYeh5YLVG45x_JAACkD8"]
[Tue Jul 21 07:27:45.541862 2026] [security2:error] [pid 229246:tid 229500] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JoSBMYeh5YLVG45x_JAACkD8"]
[Tue Jul 21 07:27:45.555960 2026] [security2:error] [pid 229246:tid 229306] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JoSBMYeh5YLVG45x_JQACXTs"]
[Tue Jul 21 07:27:45.556147 2026] [security2:error] [pid 229246:tid 229449] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JoSBMYeh5YLVG45x_JQACXTs"]
[Tue Jul 21 07:27:45.735700 2026] [security2:error] [pid 230252:tid 230502] [client 103.106.20.201:51979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JoU0Dwhk5-Z44XrpZnwAAAw8"]
[Tue Jul 21 07:27:45.735810 2026] [security2:error] [pid 230252:tid 230502] [client 103.106.20.201:51979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JoU0Dwhk5-Z44XrpZnwAAAw8"]
[Tue Jul 21 07:27:45.740992 2026] [security2:error] [pid 230252:tid 230464] [client 74.249.245.134:62871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/max.php"] [unique_id "al9JoU0Dwhk5-Z44XrpZoAAAAuk"]
[Tue Jul 21 07:27:45.831793 2026] [security2:error] [pid 230252:tid 230460] [client 20.104.96.117:64029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/xyn.php"] [unique_id "al9JoU0Dwhk5-Z44XrpZpAAAAuU"]
[Tue Jul 21 07:27:46.022539 2026] [security2:error] [pid 230252:tid 230414] [client 20.220.225.223:55788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/we.php"] [unique_id "al9Jok0Dwhk5-Z44XrpZpQAAArc"]
[Tue Jul 21 07:27:46.050251 2026] [security2:error] [pid 230252:tid 230397] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Jok0Dwhk5-Z44XrpZpwAAAqY"]
[Tue Jul 21 07:27:46.079266 2026] [security2:error] [pid 230252:tid 230419] [client 45.8.17.144:54017] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/alera/gecko.php"] [unique_id "al9Jok0Dwhk5-Z44XrpZqQAAArw"]
[Tue Jul 21 07:27:46.312228 2026] [security2:error] [pid 230252:tid 230461] [client 20.220.225.223:38671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/8.php"] [unique_id "al9Jok0Dwhk5-Z44XrpZqgAAAuY"]
[Tue Jul 21 07:27:46.656673 2026] [security2:error] [pid 230252:tid 230498] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Jok0Dwhk5-Z44XrpZrwAAAws"]
[Tue Jul 21 07:27:46.672495 2026] [security2:error] [pid 229246:tid 229429] [client 74.249.245.134:17443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/m.php"] [unique_id "al9JoiBMYeh5YLVG45x_MAAAAkk"]
[Tue Jul 21 07:27:46.679312 2026] [autoindex:error] [pid 229246:tid 229383] [client 20.104.96.117:62913] AH01276: Cannot serve directory /home4/forev309/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:46.809901 2026] [security2:error] [pid 229246:tid 229471] [client 103.174.34.15:64515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JoiBMYeh5YLVG45x_MgAAAnM"]
[Tue Jul 21 07:27:46.810044 2026] [security2:error] [pid 229246:tid 229471] [client 103.174.34.15:64515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JoiBMYeh5YLVG45x_MgAAAnM"]
[Tue Jul 21 07:27:47.028725 2026] [security2:error] [pid 230252:tid 230478] [client 109.248.148.246:39716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZswAAAvc"]
[Tue Jul 21 07:27:47.028834 2026] [security2:error] [pid 230252:tid 230478] [client 109.248.148.246:39716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZswAAAvc"]
[Tue Jul 21 07:27:47.040731 2026] [autoindex:error] [pid 229246:tid 229392] [client 20.104.96.117:62913] AH01276: Cannot serve directory /home4/forev309/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:47.128477 2026] [security2:error] [pid 230252:tid 230434] [client 20.220.225.223:53500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/phpinfo.php1"] [unique_id "al9Jo00Dwhk5-Z44XrpZtgAAAss"]
[Tue Jul 21 07:27:47.180578 2026] [security2:error] [pid 229246:tid 229379] [client 20.104.96.117:62913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/ccc.php"] [unique_id "al9JoyBMYeh5YLVG45x_OAAAAhc"]
[Tue Jul 21 07:27:47.258654 2026] [security2:error] [pid 230252:tid 230425] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Jo00Dwhk5-Z44XrpZtwAAAsI"]
[Tue Jul 21 07:27:47.372515 2026] [security2:error] [pid 229246:tid 229314] [remote 5.182.209.54:48610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9JoyBMYeh5YLVG45x_OwACjUM"]
[Tue Jul 21 07:27:47.382274 2026] [security2:error] [pid 230252:tid 230384] [client 45.8.17.132:50505] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/so-pinyin-slugs/inc/main_json.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZugAAApk"]
[Tue Jul 21 07:27:47.433549 2026] [security2:error] [pid 230252:tid 230432] [client 154.192.233.199:60265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZvQAAAsk"]
[Tue Jul 21 07:27:47.433666 2026] [security2:error] [pid 230252:tid 230432] [client 154.192.233.199:60265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZvQAAAsk"]
[Tue Jul 21 07:27:47.437660 2026] [security2:error] [pid 230252:tid 230437] [client 175.45.70.82:55173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZvgAAAs4"]
[Tue Jul 21 07:27:47.437799 2026] [security2:error] [pid 230252:tid 230437] [client 175.45.70.82:55173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZvgAAAs4"]
[Tue Jul 21 07:27:47.655130 2026] [security2:error] [pid 230252:tid 230462] [client 20.151.10.161:48584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/7.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZxAAAAuc"]
[Tue Jul 21 07:27:47.764255 2026] [security2:error] [pid 230252:tid 230398] [client 74.249.245.134:62882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/click.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZyQAAAqc"]
[Tue Jul 21 07:27:47.859543 2026] [security2:error] [pid 230252:tid 230422] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9Jo00Dwhk5-Z44XrpZywAAAr8"]
[Tue Jul 21 07:27:47.862400 2026] [security2:error] [pid 230252:tid 230275] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZzAACyBU"]
[Tue Jul 21 07:27:47.862626 2026] [security2:error] [pid 230252:tid 230431] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZzAACyBU"]
[Tue Jul 21 07:27:47.969084 2026] [security2:error] [pid 230252:tid 230305] [remote 69.63.184.115:47360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.184.63.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZzwACxzM"]
[Tue Jul 21 07:27:47.991269 2026] [security2:error] [pid 230252:tid 230458] [client 20.104.96.117:59799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZ0AAAAuM"]
[Tue Jul 21 07:27:48.132467 2026] [security2:error] [pid 229246:tid 229399] [client 20.104.96.117:62934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/w.php"] [unique_id "al9JpCBMYeh5YLVG45x_RAAAAis"]
[Tue Jul 21 07:27:48.308764 2026] [security2:error] [pid 230252:tid 230448] [client 193.36.225.70:52577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JpE0Dwhk5-Z44XrpZ0QAAAtk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:27:48.353833 2026] [security2:error] [pid 229246:tid 229478] [client 74.7.228.42:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "construtoralagodoporto.sbbarrosadvocacia.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9JpCBMYeh5YLVG45x_RwACej0"]
[Tue Jul 21 07:27:48.382686 2026] [security2:error] [pid 229246:tid 229276] [remote 154.61.75.100:44460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/wp-login.php"] [unique_id "al9JpCBMYeh5YLVG45x_SAACGh0"]
[Tue Jul 21 07:27:48.454768 2026] [security2:error] [pid 230252:tid 230394] [client 74.249.245.134:5520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/lv.php"] [unique_id "al9JpE0Dwhk5-Z44XrpZ1wAAAqM"]
[Tue Jul 21 07:27:48.472974 2026] [security2:error] [pid 229246:tid 229454] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9JpCBMYeh5YLVG45x_SgAAAmI"]
[Tue Jul 21 07:27:48.488175 2026] [security2:error] [pid 229246:tid 229431] [client 45.8.17.118:65087] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/assets/"] [unique_id "al9JpCBMYeh5YLVG45x_SwAAAks"]
[Tue Jul 21 07:27:48.713845 2026] [security2:error] [pid 230252:tid 230329] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JpE0Dwhk5-Z44XrpZ3AAC_Eo"]
[Tue Jul 21 07:27:48.714096 2026] [security2:error] [pid 230252:tid 230483] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JpE0Dwhk5-Z44XrpZ3AAC_Eo"]
[Tue Jul 21 07:27:48.914586 2026] [autoindex:error] [pid 230252:tid 230315] [remote 74.7.227.173:0] AH01276: Cannot serve directory /home1/sbbarr09/construtoralagodoporto.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:49.078941 2026] [security2:error] [pid 230252:tid 230425] [client 20.104.96.117:64055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9JpU0Dwhk5-Z44XrpZ5AAAAsI"]
[Tue Jul 21 07:27:49.093615 2026] [security2:error] [pid 230252:tid 230423] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9JpU0Dwhk5-Z44XrpZ5QAAAsA"]
[Tue Jul 21 07:27:49.172514 2026] [security2:error] [pid 230252:tid 230387] [client 109.248.148.246:37226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JpU0Dwhk5-Z44XrpZ5gAAApw"]
[Tue Jul 21 07:27:49.172614 2026] [security2:error] [pid 230252:tid 230387] [client 109.248.148.246:37226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JpU0Dwhk5-Z44XrpZ5gAAApw"]
[Tue Jul 21 07:27:49.229550 2026] [security2:error] [pid 229246:tid 229398] [client 103.162.129.114:63496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JpSBMYeh5YLVG45x_UgAAAio"]
[Tue Jul 21 07:27:49.229756 2026] [security2:error] [pid 229246:tid 229398] [client 103.162.129.114:63496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JpSBMYeh5YLVG45x_UgAAAio"]
[Tue Jul 21 07:27:49.260885 2026] [security2:error] [pid 229246:tid 229455] [client 74.249.245.134:54367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/cong.php"] [unique_id "al9JpSBMYeh5YLVG45x_UwAAAmM"]
[Tue Jul 21 07:27:49.569865 2026] [security2:error] [pid 229246:tid 229500] [client 20.151.10.161:48577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/8.php"] [unique_id "al9JpSBMYeh5YLVG45x_WQAAApA"]
[Tue Jul 21 07:27:49.597066 2026] [security2:error] [pid 229246:tid 229410] [client 20.104.96.117:64037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/FWAZ.php"] [unique_id "al9JpSBMYeh5YLVG45x_WgAAAjY"]
[Tue Jul 21 07:27:49.717535 2026] [security2:error] [pid 230252:tid 230392] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9JpU0Dwhk5-Z44XrpZ8gAAAqE"]
[Tue Jul 21 07:27:49.766808 2026] [security2:error] [pid 230252:tid 230391] [client 74.249.245.134:54363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/brand.php"] [unique_id "al9JpU0Dwhk5-Z44XrpZ9AAAAqA"]
[Tue Jul 21 07:27:49.890274 2026] [security2:error] [pid 229246:tid 229503] [client 45.8.17.108:60315] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/hello.php"] [unique_id "al9JpSBMYeh5YLVG45x_XQAAApM"]
[Tue Jul 21 07:27:49.923506 2026] [access_compat:error] [pid 229246:tid 229437] [client 162.241.63.68:16052] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:27:49.979907 2026] [security2:error] [pid 229246:tid 229495] [client 20.220.225.223:38665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/red.php"] [unique_id "al9JpSBMYeh5YLVG45x_YgAAAos"]
[Tue Jul 21 07:27:50.100887 2026] [security2:error] [pid 230252:tid 230448] [client 20.104.96.117:62921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/miru1.php"] [unique_id "al9Jpk0Dwhk5-Z44XrpaDgAAAtk"]
[Tue Jul 21 07:27:50.298704 2026] [security2:error] [pid 230252:tid 230477] [client 74.249.245.134:54396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/atomlib.php"] [unique_id "al9Jpk0Dwhk5-Z44XrpaEgAAAvY"]
[Tue Jul 21 07:27:50.326191 2026] [security2:error] [pid 229246:tid 229388] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9JpiBMYeh5YLVG45x_ZAAAAiA"]
[Tue Jul 21 07:27:50.489101 2026] [security2:error] [pid 229246:tid 229457] [client 20.104.96.117:64047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/aa.php"] [unique_id "al9JpiBMYeh5YLVG45x_bQAAAmU"]
[Tue Jul 21 07:27:50.602485 2026] [security2:error] [pid 229246:tid 229349] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JpiBMYeh5YLVG45x_bwACL2Y"]
[Tue Jul 21 07:27:50.602603 2026] [security2:error] [pid 229246:tid 229403] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JpiBMYeh5YLVG45x_bwACL2Y"]
[Tue Jul 21 07:27:50.756776 2026] [security2:error] [pid 229246:tid 229481] [client 74.249.245.134:62855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/0x.php"] [unique_id "al9JpiBMYeh5YLVG45x_cAAAAn0"]
[Tue Jul 21 07:27:50.802766 2026] [security2:error] [pid 230252:tid 230459] [client 20.104.96.117:62973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/122.php"] [unique_id "al9Jpk0Dwhk5-Z44XrpaFQAAAuQ"]
[Tue Jul 21 07:27:51.152143 2026] [security2:error] [pid 230252:tid 230425] [client 20.104.96.117:64032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/get.php"] [unique_id "al9Jp00Dwhk5-Z44XrpaJwAAAsI"]
[Tue Jul 21 07:27:51.191492 2026] [security2:error] [pid 230252:tid 230423] [client 45.8.17.57:44371] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/maint/"] [unique_id "al9Jp00Dwhk5-Z44XrpaKAAAAsA"]
[Tue Jul 21 07:27:51.312469 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:49151] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.tempex.com.br"] [uri "/1.php"] [unique_id "al9Jp00Dwhk5-Z44XrpaKQAAAwY"]
[Tue Jul 21 07:27:51.312593 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:49151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/1.php"] [unique_id "al9Jp00Dwhk5-Z44XrpaKQAAAwY"]
[Tue Jul 21 07:27:51.338827 2026] [security2:error] [pid 230252:tid 230461] [client 20.104.96.117:42390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/qqqa.php"] [unique_id "al9Jp00Dwhk5-Z44XrpaKgAAAuY"]
[Tue Jul 21 07:27:51.455509 2026] [security2:error] [pid 230252:tid 230444] [client 74.249.245.134:17465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/buy.php"] [unique_id "al9Jp00Dwhk5-Z44XrpaLAAAAtU"]
[Tue Jul 21 07:27:51.455523 2026] [security2:error] [pid 230252:tid 230508] [client 20.104.96.117:64042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/as.php"] [unique_id "al9Jp00Dwhk5-Z44XrpaLQAAAxU"]
[Tue Jul 21 07:27:51.780472 2026] [security2:error] [pid 230252:tid 230427] [client 20.104.96.117:5115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/ccou.php"] [unique_id "al9Jp00Dwhk5-Z44XrpaMAAAAsQ"]
[Tue Jul 21 07:27:51.939124 2026] [security2:error] [pid 230252:tid 230417] [client 213.152.162.104:58510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Jp00Dwhk5-Z44XrpaNAAAAro"]
[Tue Jul 21 07:27:51.939208 2026] [security2:error] [pid 230252:tid 230417] [client 213.152.162.104:58510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Jp00Dwhk5-Z44XrpaNAAAAro"]
[Tue Jul 21 07:27:52.119638 2026] [security2:error] [pid 229246:tid 229416] [client 20.104.96.117:4257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/w3lls.php"] [unique_id "al9JqCBMYeh5YLVG45x_ggAAAjw"]
[Tue Jul 21 07:27:52.184824 2026] [security2:error] [pid 229246:tid 229398] [client 45.8.17.129:50145] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wordpress/wp-admin/maint/"] [unique_id "al9JqCBMYeh5YLVG45x_hAAAAio"]
[Tue Jul 21 07:27:52.385561 2026] [security2:error] [pid 230252:tid 230436] [client 139.135.44.145:54393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JqE0Dwhk5-Z44XrpaNwAAAs0"]
[Tue Jul 21 07:27:52.385672 2026] [security2:error] [pid 230252:tid 230436] [client 139.135.44.145:54393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JqE0Dwhk5-Z44XrpaNwAAAs0"]
[Tue Jul 21 07:27:52.532159 2026] [security2:error] [pid 229246:tid 229477] [client 74.249.245.134:5546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/sx.php"] [unique_id "al9JqCBMYeh5YLVG45x_igAAAnk"]
[Tue Jul 21 07:27:52.532615 2026] [security2:error] [pid 230252:tid 230499] [client 20.104.96.117:62949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/test1.php"] [unique_id "al9JqE0Dwhk5-Z44XrpaOQAAAww"]
[Tue Jul 21 07:27:53.090371 2026] [security2:error] [pid 229246:tid 229489] [client 20.104.96.117:5064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/database.php"] [unique_id "al9JqSBMYeh5YLVG45x_lAAAAoU"]
[Tue Jul 21 07:27:53.220430 2026] [security2:error] [pid 230252:tid 230464] [client 117.251.86.144:43774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JqU0Dwhk5-Z44XrpaQgAAAuk"]
[Tue Jul 21 07:27:53.220601 2026] [security2:error] [pid 230252:tid 230464] [client 117.251.86.144:43774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JqU0Dwhk5-Z44XrpaQgAAAuk"]
[Tue Jul 21 07:27:53.256579 2026] [security2:error] [pid 230252:tid 230438] [client 20.104.96.117:59791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/aunmc.php"] [unique_id "al9JqU0Dwhk5-Z44XrpaRAAAAs8"]
[Tue Jul 21 07:27:53.442586 2026] [security2:error] [pid 230252:tid 230469] [client 152.59.154.239:51700] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JqE0Dwhk5-Z44XrpaNgAAAu4"]
[Tue Jul 21 07:27:53.443154 2026] [security2:error] [pid 230252:tid 230469] [client 152.59.154.239:51700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JqE0Dwhk5-Z44XrpaNgAAAu4"]
[Tue Jul 21 07:27:53.443766 2026] [security2:error] [pid 230252:tid 230459] [client 109.248.148.246:40158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9JqU0Dwhk5-Z44XrpaSAAAAuQ"]
[Tue Jul 21 07:27:53.443941 2026] [security2:error] [pid 230252:tid 230459] [client 109.248.148.246:40158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9JqU0Dwhk5-Z44XrpaSAAAAuQ"]
[Tue Jul 21 07:27:53.541900 2026] [security2:error] [pid 230252:tid 230407] [client 20.104.96.117:64023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/file.php"] [unique_id "al9JqU0Dwhk5-Z44XrpaSgAAArA"]
[Tue Jul 21 07:27:53.782921 2026] [security2:error] [pid 229246:tid 229407] [client 45.8.17.125:57791] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "al9JqSBMYeh5YLVG45x_nwAAAjM"]
[Tue Jul 21 07:27:53.871182 2026] [security2:error] [pid 230252:tid 230446] [client 45.251.232.145:52208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JqU0Dwhk5-Z44XrpaTAAAAtc"]
[Tue Jul 21 07:27:53.871316 2026] [security2:error] [pid 230252:tid 230446] [client 45.251.232.145:52208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JqU0Dwhk5-Z44XrpaTAAAAtc"]
[Tue Jul 21 07:27:53.978377 2026] [security2:error] [pid 230252:tid 230363] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JqU0Dwhk5-Z44XrpaTQAComw"]
[Tue Jul 21 07:27:53.978529 2026] [security2:error] [pid 230252:tid 230393] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JqU0Dwhk5-Z44XrpaTQAComw"]
[Tue Jul 21 07:27:53.989636 2026] [security2:error] [pid 229246:tid 229459] [client 20.104.96.117:64043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/file.php"] [unique_id "al9JqSBMYeh5YLVG45x_oQAAAmc"]
[Tue Jul 21 07:27:54.007677 2026] [security2:error] [pid 230252:tid 230478] [client 20.151.10.161:49131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/100.php"] [unique_id "al9Jqk0Dwhk5-Z44XrpaTgAAAvc"]
[Tue Jul 21 07:27:54.266328 2026] [autoindex:error] [pid 230252:tid 230435] [client 71.6.134.231:39348] AH01276: Cannot serve directory /home2/uaudis29/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:54.393162 2026] [security2:error] [pid 230252:tid 230424] [client 59.96.220.140:163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Jqk0Dwhk5-Z44XrpaUwAAAsE"]
[Tue Jul 21 07:27:54.393279 2026] [security2:error] [pid 230252:tid 230424] [client 59.96.220.140:163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Jqk0Dwhk5-Z44XrpaUwAAAsE"]
[Tue Jul 21 07:27:54.402849 2026] [security2:error] [pid 229246:tid 229483] [client 20.104.96.117:62927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/777.php"] [unique_id "al9JqiBMYeh5YLVG45x_qAAAAn8"]
[Tue Jul 21 07:27:54.420087 2026] [security2:error] [pid 230252:tid 230423] [client 74.249.245.134:17454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/article.php"] [unique_id "al9Jqk0Dwhk5-Z44XrpaVAAAAsA"]
[Tue Jul 21 07:27:54.462186 2026] [security2:error] [pid 229246:tid 229451] [client 20.52.136.55:1538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/edit.php"] [unique_id "al9JqiBMYeh5YLVG45x_qgAAAl8"]
[Tue Jul 21 07:27:54.508399 2026] [security2:error] [pid 230252:tid 230384] [client 213.152.162.104:43922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Jqk0Dwhk5-Z44XrpaVwAAApk"]
[Tue Jul 21 07:27:54.508523 2026] [security2:error] [pid 230252:tid 230384] [client 213.152.162.104:43922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Jqk0Dwhk5-Z44XrpaVwAAApk"]
[Tue Jul 21 07:27:54.817827 2026] [security2:error] [pid 230252:tid 230426] [client 20.104.96.117:62917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/ssixta.php"] [unique_id "al9Jqk0Dwhk5-Z44XrpaWwAAAsM"]
[Tue Jul 21 07:27:54.892357 2026] [security2:error] [pid 230252:tid 230462] [client 20.151.10.161:49092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/about.php"] [unique_id "al9Jqk0Dwhk5-Z44XrpaXwAAAuc"]
[Tue Jul 21 07:27:55.195489 2026] [security2:error] [pid 230252:tid 230479] [client 45.8.17.61:65439] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "al9Jq00Dwhk5-Z44XrpaZwAAAvg"]
[Tue Jul 21 07:27:55.263911 2026] [security2:error] [pid 230252:tid 230460] [client 20.104.96.117:59785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/uoocf.php"] [unique_id "al9Jq00Dwhk5-Z44XrpaaAAAAuU"]
[Tue Jul 21 07:27:55.299900 2026] [security2:error] [pid 230252:tid 230503] [client 20.104.96.117:64033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/1c.php"] [unique_id "al9Jq00Dwhk5-Z44XrpaagAAAxA"]
[Tue Jul 21 07:27:55.634145 2026] [security2:error] [pid 230252:tid 230443] [client 193.36.225.66:53307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JqU0Dwhk5-Z44XrpaRQAAAtQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:27:55.713614 2026] [security2:error] [pid 230252:tid 230394] [client 20.151.10.161:48589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/admin.php"] [unique_id "al9Jq00Dwhk5-Z44XrpabwAAAqM"]
[Tue Jul 21 07:27:55.716820 2026] [security2:error] [pid 229246:tid 229329] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JqyBMYeh5YLVG45x_uwACMVI"]
[Tue Jul 21 07:27:55.717056 2026] [security2:error] [pid 229246:tid 229405] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JqyBMYeh5YLVG45x_uwACMVI"]
[Tue Jul 21 07:27:56.180762 2026] [security2:error] [pid 230252:tid 230482] [client 20.104.96.117:62925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/test2.php"] [unique_id "al9JrE0Dwhk5-Z44XrpadgAAAvs"]
[Tue Jul 21 07:27:56.257564 2026] [security2:error] [pid 230252:tid 230478] [client 20.151.10.161:49044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/edit.php"] [unique_id "al9JrE0Dwhk5-Z44XrpaewAAAvc"]
[Tue Jul 21 07:27:56.449653 2026] [security2:error] [pid 230252:tid 230297] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JrE0Dwhk5-Z44XrpaggACqSs"]
[Tue Jul 21 07:27:56.449936 2026] [security2:error] [pid 230252:tid 230400] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JrE0Dwhk5-Z44XrpaggACqSs"]
[Tue Jul 21 07:27:56.455607 2026] [security2:error] [pid 230252:tid 230494] [client 103.106.20.201:52554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JrE0Dwhk5-Z44XrpagwAAAwc"]
[Tue Jul 21 07:27:56.455773 2026] [security2:error] [pid 230252:tid 230494] [client 103.106.20.201:52554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JrE0Dwhk5-Z44XrpagwAAAwc"]
[Tue Jul 21 07:27:56.479614 2026] [security2:error] [pid 230252:tid 230493] [client 45.8.17.64:29699] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/edit.php"] [unique_id "al9JrE0Dwhk5-Z44XrpahAAAAwY"]
[Tue Jul 21 07:27:56.559052 2026] [security2:error] [pid 230252:tid 230381] [remote 51.222.168.241:30344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "jurencosmetics.com"] [uri "/product/richee-nanobtx-repair-mass-replenisher-macadamia-oil-2x-1kg/feed/"] [unique_id "al9JrE0Dwhk5-Z44XrpahQACwH4"]
[Tue Jul 21 07:27:56.559221 2026] [security2:error] [pid 230252:tid 230423] [client 51.222.168.241:30344] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jurencosmetics.com"] [uri "/product/richee-nanobtx-repair-mass-replenisher-macadamia-oil-2x-1kg/feed/"] [unique_id "al9JrE0Dwhk5-Z44XrpahQACwH4"]
[Tue Jul 21 07:27:56.589056 2026] [security2:error] [pid 230252:tid 230474] [client 74.249.245.134:5509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/bootstrap.php"] [unique_id "al9JrE0Dwhk5-Z44XrpahgAAAvM"]
[Tue Jul 21 07:27:56.764571 2026] [security2:error] [pid 230252:tid 230386] [client 20.104.96.117:59642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/iywwi.php"] [unique_id "al9JrE0Dwhk5-Z44XrpaiQAAAps"]
[Tue Jul 21 07:27:57.148061 2026] [security2:error] [pid 230252:tid 230256] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JrU0Dwhk5-Z44XrpaiwAC8AI"]
[Tue Jul 21 07:27:57.148261 2026] [security2:error] [pid 230252:tid 230471] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JrU0Dwhk5-Z44XrpaiwAC8AI"]
[Tue Jul 21 07:27:57.279755 2026] [security2:error] [pid 230252:tid 230405] [client 20.104.96.117:64041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/buy.php"] [unique_id "al9JrU0Dwhk5-Z44XrpajAAAAq4"]
[Tue Jul 21 07:27:57.290545 2026] [security2:error] [pid 229246:tid 229447] [client 45.8.17.128:25527] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/archives/"] [unique_id "al9JrSBMYeh5YLVG45x_zwAAAls"]
[Tue Jul 21 07:27:57.432111 2026] [security2:error] [pid 230252:tid 230507] [client 20.151.10.161:48616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9JrU0Dwhk5-Z44XrpajQAAAxQ"]
[Tue Jul 21 07:27:57.515992 2026] [security2:error] [pid 230252:tid 230511] [client 20.104.96.117:59784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/gqgsa.php"] [unique_id "al9JrU0Dwhk5-Z44XrpajgAAAxg"]
[Tue Jul 21 07:27:57.556629 2026] [security2:error] [pid 230252:tid 230436] [client 103.174.34.15:65009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JrU0Dwhk5-Z44XrpajwAAAs0"]
[Tue Jul 21 07:27:57.556747 2026] [security2:error] [pid 230252:tid 230436] [client 103.174.34.15:65009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JrU0Dwhk5-Z44XrpajwAAAs0"]
[Tue Jul 21 07:27:57.588198 2026] [security2:error] [pid 229246:tid 229499] [client 109.248.148.246:40170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JrSBMYeh5YLVG45x_0wAAAo8"]
[Tue Jul 21 07:27:57.588282 2026] [security2:error] [pid 229246:tid 229499] [client 109.248.148.246:40170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JrSBMYeh5YLVG45x_0wAAAo8"]
[Tue Jul 21 07:27:58.116486 2026] [security2:error] [pid 229246:tid 229412] [client 175.45.70.82:55689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JriBMYeh5YLVG45x_4AAAAjg"]
[Tue Jul 21 07:27:58.116607 2026] [security2:error] [pid 229246:tid 229412] [client 175.45.70.82:55689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JriBMYeh5YLVG45x_4AAAAjg"]
[Tue Jul 21 07:27:58.133200 2026] [security2:error] [pid 229246:tid 229450] [client 154.192.233.199:59825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JriBMYeh5YLVG45x_4QAAAl4"]
[Tue Jul 21 07:27:58.133347 2026] [security2:error] [pid 229246:tid 229450] [client 154.192.233.199:59825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JriBMYeh5YLVG45x_4QAAAl4"]
[Tue Jul 21 07:27:58.308123 2026] [security2:error] [pid 230252:tid 230389] [client 20.151.10.161:49102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/f6.php"] [unique_id "al9Jrk0Dwhk5-Z44XrpamwAAAp4"]
[Tue Jul 21 07:27:58.402280 2026] [security2:error] [pid 230252:tid 230350] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Jrk0Dwhk5-Z44XrpanQACo18"]
[Tue Jul 21 07:27:58.402467 2026] [security2:error] [pid 230252:tid 230394] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Jrk0Dwhk5-Z44XrpanQACo18"]
[Tue Jul 21 07:27:58.599203 2026] [security2:error] [pid 229246:tid 229456] [client 45.8.17.118:57269] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/includes/"] [unique_id "al9JriBMYeh5YLVG45x_6QAAAmQ"]
[Tue Jul 21 07:27:58.907319 2026] [security2:error] [pid 230252:tid 230491] [client 20.104.96.117:59618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/elbzl.php"] [unique_id "al9Jrk0Dwhk5-Z44XrpaowAAAwQ"]
[Tue Jul 21 07:27:59.201040 2026] [security2:error] [pid 230252:tid 230463] [client 82.102.28.107:39932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Jr00Dwhk5-Z44XrpaqAAAAug"]
[Tue Jul 21 07:27:59.201154 2026] [security2:error] [pid 230252:tid 230463] [client 82.102.28.107:39932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Jr00Dwhk5-Z44XrpaqAAAAug"]
[Tue Jul 21 07:27:59.230969 2026] [security2:error] [pid 230252:tid 230280] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jr00Dwhk5-Z44XrpaqQACqRo"]
[Tue Jul 21 07:27:59.231149 2026] [security2:error] [pid 230252:tid 230400] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jr00Dwhk5-Z44XrpaqQACqRo"]
[Tue Jul 21 07:27:59.281442 2026] [security2:error] [pid 230252:tid 230487] [client 182.9.35.66:9362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.35.9.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giliniservices.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jr00Dwhk5-Z44XrpaqgAAAwA"]
[Tue Jul 21 07:27:59.281609 2026] [security2:error] [pid 230252:tid 230487] [client 182.9.35.66:9362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giliniservices.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jr00Dwhk5-Z44XrpaqgAAAwA"]
[Tue Jul 21 07:27:59.399051 2026] [security2:error] [pid 230252:tid 230467] [client 20.104.96.117:62943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/ssend.php"] [unique_id "al9Jr00Dwhk5-Z44XrpargAAAuw"]
[Tue Jul 21 07:27:59.464501 2026] [security2:error] [pid 230252:tid 230427] [client 20.104.96.117:59627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/adjig.php"] [unique_id "al9Jr00Dwhk5-Z44XrpasAAAAsQ"]
[Tue Jul 21 07:27:59.582623 2026] [security2:error] [pid 230252:tid 230473] [client 45.8.17.148:56255] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/x.php"] [unique_id "al9Jr00Dwhk5-Z44XrpatAAAAvI"]
[Tue Jul 21 07:27:59.614046 2026] [security2:error] [pid 230252:tid 230401] [client 20.151.10.161:49130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/inputs.php"] [unique_id "al9Jr00Dwhk5-Z44XrpatgAAAqo"]
[Tue Jul 21 07:27:59.636535 2026] [security2:error] [pid 230252:tid 230385] [client 20.220.225.223:38710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/fffm.php"] [unique_id "al9Jr00Dwhk5-Z44XrpauAAAApo"]
[Tue Jul 21 07:27:59.710233 2026] [security2:error] [pid 230252:tid 230455] [client 103.162.129.114:63936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Jr00Dwhk5-Z44XrpavAAAAuA"]
[Tue Jul 21 07:27:59.710381 2026] [security2:error] [pid 230252:tid 230455] [client 103.162.129.114:63936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Jr00Dwhk5-Z44XrpavAAAAuA"]
[Tue Jul 21 07:28:00.134682 2026] [security2:error] [pid 230252:tid 230443] [client 20.104.96.117:59783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/byp.php"] [unique_id "al9JsE0Dwhk5-Z44XrpaxQAAAtQ"]
[Tue Jul 21 07:28:00.408870 2026] [security2:error] [pid 230252:tid 230445] [client 136.144.33.29:48215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JsE0Dwhk5-Z44XrpaxgAAAtY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:00.474879 2026] [security2:error] [pid 230252:tid 230466] [client 213.152.162.104:39054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JsE0Dwhk5-Z44XrpaygAAAus"]
[Tue Jul 21 07:28:00.474978 2026] [security2:error] [pid 230252:tid 230466] [client 213.152.162.104:39054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JsE0Dwhk5-Z44XrpaygAAAus"]
[Tue Jul 21 07:28:00.490157 2026] [security2:error] [pid 230252:tid 230357] [remote 173.252.95.3:38258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9JsE0Dwhk5-Z44XrpaywAC-mY"]
[Tue Jul 21 07:28:00.630170 2026] [security2:error] [pid 230252:tid 230435] [client 20.151.10.161:49140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/av.php"] [unique_id "al9JsE0Dwhk5-Z44XrpazwAAAsw"]
[Tue Jul 21 07:28:00.670204 2026] [security2:error] [pid 230252:tid 230475] [client 20.104.96.117:59607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9JsE0Dwhk5-Z44Xrpa0AAAAvQ"]
[Tue Jul 21 07:28:00.889243 2026] [security2:error] [pid 230252:tid 230384] [client 45.8.17.122:28315] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "al9JsE0Dwhk5-Z44Xrpa0gAAApk"]
[Tue Jul 21 07:28:01.118979 2026] [security2:error] [pid 230252:tid 230415] [client 20.104.96.117:64062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/item.php"] [unique_id "al9JsU0Dwhk5-Z44Xrpa1AAAArg"]
[Tue Jul 21 07:28:01.235619 2026] [security2:error] [pid 230252:tid 230271] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JsU0Dwhk5-Z44Xrpa1QACwxE"]
[Tue Jul 21 07:28:01.235752 2026] [security2:error] [pid 230252:tid 230426] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JsU0Dwhk5-Z44Xrpa1QACwxE"]
[Tue Jul 21 07:28:01.304942 2026] [security2:error] [pid 230252:tid 230430] [client 20.197.195.24:12386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9JsU0Dwhk5-Z44Xrpa2AAAAsc"]
[Tue Jul 21 07:28:01.333101 2026] [security2:error] [pid 230252:tid 230453] [client 74.249.245.134:5557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/config-backup.php"] [unique_id "al9JsU0Dwhk5-Z44Xrpa2wAAAt4"]
[Tue Jul 21 07:28:01.795720 2026] [security2:error] [pid 230252:tid 230442] [client 20.104.96.117:59612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/classwithtostring.php"] [unique_id "al9JsU0Dwhk5-Z44Xrpa4wAAAtM"]
[Tue Jul 21 07:28:02.000053 2026] [security2:error] [pid 229246:tid 229474] [client 45.8.17.105:54773] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/colors/light/"] [unique_id "al9JsSBMYeh5YLVG45yACwAAAnY"]
[Tue Jul 21 07:28:02.186399 2026] [security2:error] [pid 230252:tid 230443] [client 20.104.96.117:5090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/ss.php"] [unique_id "al9Jsk0Dwhk5-Z44Xrpa5gAAAtQ"]
[Tue Jul 21 07:28:02.449419 2026] [security2:error] [pid 230252:tid 230485] [client 159.69.158.189:53516] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9Jsk0Dwhk5-Z44Xrpa6wAAAv4"], referer: https://artetoner.com.br
[Tue Jul 21 07:28:02.671770 2026] [security2:error] [pid 229246:tid 229359] [remote 104.207.56.32:24889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.56.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9JsiBMYeh5YLVG45yAEQACe3A"]
[Tue Jul 21 07:28:02.992801 2026] [security2:error] [pid 229246:tid 229379] [client 45.8.17.110:47869] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin.php"] [unique_id "al9JsiBMYeh5YLVG45yAFwAAAhc"]
[Tue Jul 21 07:28:03.309099 2026] [security2:error] [pid 229246:tid 229403] [client 20.220.225.223:31109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/ftde.php"] [unique_id "al9JsyBMYeh5YLVG45yAHQAAAi8"]
[Tue Jul 21 07:28:03.374208 2026] [security2:error] [pid 230252:tid 230452] [client 139.135.44.145:53310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Js00Dwhk5-Z44Xrpa9AAAAt0"]
[Tue Jul 21 07:28:03.374374 2026] [security2:error] [pid 230252:tid 230452] [client 139.135.44.145:53310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Js00Dwhk5-Z44Xrpa9AAAAt0"]
[Tue Jul 21 07:28:03.395486 2026] [security2:error] [pid 229246:tid 229459] [client 20.220.225.223:62115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9JsyBMYeh5YLVG45yAHgAAAmc"]
[Tue Jul 21 07:28:03.399231 2026] [security2:error] [pid 229246:tid 229466] [client 20.104.96.117:59591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/root.php"] [unique_id "al9JsyBMYeh5YLVG45yAHwAAAm4"]
[Tue Jul 21 07:28:03.553976 2026] [security2:error] [pid 229246:tid 229481] [client 20.52.136.55:1570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/166.php"] [unique_id "al9JsyBMYeh5YLVG45yAIAAAAn0"]
[Tue Jul 21 07:28:03.642952 2026] [security2:error] [pid 229246:tid 229460] [client 152.59.154.239:52127] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JsyBMYeh5YLVG45yAJgAAAmg"]
[Tue Jul 21 07:28:03.643063 2026] [security2:error] [pid 229246:tid 229460] [client 152.59.154.239:52127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JsyBMYeh5YLVG45yAJgAAAmg"]
[Tue Jul 21 07:28:03.753740 2026] [security2:error] [pid 230252:tid 230384] [client 20.151.10.161:49111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/classwithtostring.php"] [unique_id "al9Js00Dwhk5-Z44Xrpa9wAAApk"]
[Tue Jul 21 07:28:03.995047 2026] [security2:error] [pid 230252:tid 230493] [client 45.8.17.116:41129] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wa/"] [unique_id "al9Js00Dwhk5-Z44Xrpa-AAAAwY"]
[Tue Jul 21 07:28:04.154200 2026] [security2:error] [pid 229246:tid 229425] [client 117.251.86.144:56154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JtCBMYeh5YLVG45yAKQAAAkU"]
[Tue Jul 21 07:28:04.154320 2026] [security2:error] [pid 229246:tid 229425] [client 117.251.86.144:56154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JtCBMYeh5YLVG45yAKQAAAkU"]
[Tue Jul 21 07:28:04.219581 2026] [autoindex:error] [pid 230252:tid 230398] [client 43.134.38.171:51802] AH01276: Cannot serve directory /home3/lianem44/ubaloc.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:04.424474 2026] [security2:error] [pid 230252:tid 230400] [client 45.251.232.145:52731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JtE0Dwhk5-Z44Xrpa_gAAAqk"]
[Tue Jul 21 07:28:04.424609 2026] [security2:error] [pid 230252:tid 230400] [client 45.251.232.145:52731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JtE0Dwhk5-Z44Xrpa_gAAAqk"]
[Tue Jul 21 07:28:04.451118 2026] [security2:error] [pid 230252:tid 230484] [client 20.104.96.117:62953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/hypo.php"] [unique_id "al9JtE0Dwhk5-Z44Xrpa_wAAAv0"]
[Tue Jul 21 07:28:04.519593 2026] [security2:error] [pid 230252:tid 230311] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JtE0Dwhk5-Z44XrpbAQACqjk"]
[Tue Jul 21 07:28:04.519776 2026] [security2:error] [pid 230252:tid 230401] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JtE0Dwhk5-Z44XrpbAQACqjk"]
[Tue Jul 21 07:28:04.611940 2026] [security2:error] [pid 230252:tid 230405] [client 20.220.225.223:38711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/yup.php"] [unique_id "al9JtE0Dwhk5-Z44XrpbAgAAAq4"]
[Tue Jul 21 07:28:04.619822 2026] [security2:error] [pid 230252:tid 230373] [remote 103.221.220.62:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "androapkmod.com"] [uri "/api/.env"] [unique_id "al9JtE0Dwhk5-Z44XrpbAwADCHY"]
[Tue Jul 21 07:28:04.635014 2026] [security2:error] [pid 230252:tid 230295] [remote 103.221.220.62:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "androapkmod.com"] [uri "/member/.env"] [unique_id "al9JtE0Dwhk5-Z44XrpbBAACoSk"]
[Tue Jul 21 07:28:04.635062 2026] [security2:error] [pid 230252:tid 230303] [remote 103.221.220.62:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "androapkmod.com"] [uri "/bank/.env"] [unique_id "al9JtE0Dwhk5-Z44XrpbBQACzTE"]
[Tue Jul 21 07:28:04.644165 2026] [security2:error] [pid 230252:tid 230286] [remote 103.221.220.62:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "androapkmod.com"] [uri "/backend/.env"] [unique_id "al9JtE0Dwhk5-Z44XrpbBwACvSA"]
[Tue Jul 21 07:28:04.742144 2026] [security2:error] [pid 230252:tid 230293] [remote 103.221.220.62:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "androapkmod.com"] [uri "/new/.env"] [unique_id "al9JtE0Dwhk5-Z44XrpbDAACuic"]
[Tue Jul 21 07:28:05.000847 2026] [security2:error] [pid 230252:tid 230397] [client 20.197.195.24:12406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9JtU0Dwhk5-Z44XrpbEQAAAqY"]
[Tue Jul 21 07:28:05.285637 2026] [security2:error] [pid 230252:tid 230466] [client 45.8.17.113:43343] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-file.php"] [unique_id "al9JtU0Dwhk5-Z44XrpbFwAAAus"]
[Tue Jul 21 07:28:05.336223 2026] [security2:error] [pid 230252:tid 230501] [client 20.151.10.161:49135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9JtU0Dwhk5-Z44XrpbGAAAAw4"]
[Tue Jul 21 07:28:05.441518 2026] [security2:error] [pid 230252:tid 230322] [remote 103.221.220.62:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "androapkmod.com"] [uri "/core/.env"] [unique_id "al9JtU0Dwhk5-Z44XrpbGQAC4UQ"]
[Tue Jul 21 07:28:05.830522 2026] [security2:error] [pid 230252:tid 230384] [client 109.248.148.246:42494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JtU0Dwhk5-Z44XrpbHgAAApk"]
[Tue Jul 21 07:28:05.830626 2026] [security2:error] [pid 230252:tid 230384] [client 109.248.148.246:42494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JtU0Dwhk5-Z44XrpbHgAAApk"]
[Tue Jul 21 07:28:05.834596 2026] [security2:error] [pid 230252:tid 230259] [remote 103.221.220.62:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "androapkmod.com"] [uri "/.env"] [unique_id "al9JtU0Dwhk5-Z44XrpbHwAC7wU"]
[Tue Jul 21 07:28:06.074915 2026] [security2:error] [pid 229246:tid 229438] [client 20.104.96.117:64058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/users.php"] [unique_id "al9JtiBMYeh5YLVG45yAOAAAAlI"]
[Tue Jul 21 07:28:06.079465 2026] [security2:error] [pid 230252:tid 230426] [client 20.197.195.24:12365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/media.php"] [unique_id "al9Jtk0Dwhk5-Z44XrpbJAAAAsM"]
[Tue Jul 21 07:28:06.142388 2026] [security2:error] [pid 230252:tid 230262] [remote 103.221.220.62:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "androapkmod.com"] [uri "/app/.env"] [unique_id "al9Jtk0Dwhk5-Z44XrpbJQACrQg"]
[Tue Jul 21 07:28:06.259252 2026] [security2:error] [pid 230252:tid 230347] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Jtk0Dwhk5-Z44XrpbKAACm1w"]
[Tue Jul 21 07:28:06.259441 2026] [security2:error] [pid 230252:tid 230386] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Jtk0Dwhk5-Z44XrpbKAACm1w"]
[Tue Jul 21 07:28:06.385190 2026] [security2:error] [pid 229246:tid 229418] [client 45.8.17.127:50705] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/info.php"] [unique_id "al9JtiBMYeh5YLVG45yAPQAAAj4"]
[Tue Jul 21 07:28:06.706669 2026] [security2:error] [pid 230252:tid 230436] [client 20.151.10.161:49079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-blog.php"] [unique_id "al9Jtk0Dwhk5-Z44XrpbMAAAAs0"]
[Tue Jul 21 07:28:06.773315 2026] [security2:error] [pid 230252:tid 230464] [client 20.104.96.117:59786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/sym403.php"] [unique_id "al9Jtk0Dwhk5-Z44XrpbMwAAAuk"]
[Tue Jul 21 07:28:07.039826 2026] [security2:error] [pid 230252:tid 230451] [client 59.96.220.140:49605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Jt00Dwhk5-Z44XrpbOAAAAtw"]
[Tue Jul 21 07:28:07.040026 2026] [security2:error] [pid 230252:tid 230451] [client 59.96.220.140:49605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Jt00Dwhk5-Z44XrpbOAAAAtw"]
[Tue Jul 21 07:28:07.121866 2026] [security2:error] [pid 229246:tid 229484] [client 74.249.245.134:62884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/goods.php"] [unique_id "al9JtyBMYeh5YLVG45yAQwAAAoA"]
[Tue Jul 21 07:28:07.181089 2026] [security2:error] [pid 229246:tid 229385] [client 103.106.20.201:53119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JtyBMYeh5YLVG45yARQAAAh0"]
[Tue Jul 21 07:28:07.181230 2026] [security2:error] [pid 229246:tid 229385] [client 103.106.20.201:53119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JtyBMYeh5YLVG45yARQAAAh0"]
[Tue Jul 21 07:28:07.202112 2026] [security2:error] [pid 229246:tid 229408] [client 20.220.225.223:38690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/jj.php"] [unique_id "al9JtyBMYeh5YLVG45yARgAAAjQ"]
[Tue Jul 21 07:28:07.212956 2026] [proxy:error] [pid 230252:tid 230438] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:07.213022 2026] [proxy_http:error] [pid 230252:tid 230438] [client 20.151.10.161:49062] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:07.213660 2026] [proxy:error] [pid 230252:tid 230438] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:07.213690 2026] [proxy_http:error] [pid 230252:tid 230438] [client 20.151.10.161:49062] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:07.281512 2026] [security2:error] [pid 230252:tid 230419] [client 45.8.17.63:32745] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/ID3/"] [unique_id "al9Jt00Dwhk5-Z44XrpbQAAAArw"]
[Tue Jul 21 07:28:07.359292 2026] [security2:error] [pid 230252:tid 230275] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Jt00Dwhk5-Z44XrpbQgADAxU"]
[Tue Jul 21 07:28:07.359437 2026] [security2:error] [pid 230252:tid 230490] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Jt00Dwhk5-Z44XrpbQgADAxU"]
[Tue Jul 21 07:28:07.850576 2026] [security2:error] [pid 230252:tid 230410] [client 20.104.96.117:62970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/177.php"] [unique_id "al9Jt00Dwhk5-Z44XrpbSAAAArM"]
[Tue Jul 21 07:28:08.121942 2026] [security2:error] [pid 230252:tid 230306] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbSgADEzQ"]
[Tue Jul 21 07:28:08.122181 2026] [security2:error] [pid 230252:tid 230506] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbSgADEzQ"]
[Tue Jul 21 07:28:08.258442 2026] [security2:error] [pid 230252:tid 230456] [client 103.174.34.15:65499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbTgAAAuE"]
[Tue Jul 21 07:28:08.258576 2026] [security2:error] [pid 230252:tid 230456] [client 103.174.34.15:65499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbTgAAAuE"]
[Tue Jul 21 07:28:08.337384 2026] [security2:error] [pid 230252:tid 230428] [client 20.151.10.161:49126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbUgAAAsU"]
[Tue Jul 21 07:28:08.389369 2026] [security2:error] [pid 230252:tid 230404] [client 45.8.17.121:44965] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/index/function.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbVAAAAq0"]
[Tue Jul 21 07:28:08.405651 2026] [security2:error] [pid 230252:tid 230462] [client 74.249.245.134:5519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/init.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbVQAAAuc"]
[Tue Jul 21 07:28:08.679766 2026] [security2:error] [pid 230252:tid 230367] [remote 20.84.23.223:5448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.23.84.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/wp-login.php"] [unique_id "al9Jt00Dwhk5-Z44XrpbRgADBXA"]
[Tue Jul 21 07:28:08.831736 2026] [security2:error] [pid 230252:tid 230494] [client 154.192.233.199:59149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbWQAAAwc"]
[Tue Jul 21 07:28:08.831882 2026] [security2:error] [pid 230252:tid 230494] [client 154.192.233.199:59149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbWQAAAwc"]
[Tue Jul 21 07:28:08.847319 2026] [security2:error] [pid 230252:tid 230488] [client 175.45.70.82:56205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbWgAAAwE"]
[Tue Jul 21 07:28:08.847439 2026] [security2:error] [pid 230252:tid 230488] [client 175.45.70.82:56205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbWgAAAwE"]
[Tue Jul 21 07:28:08.849784 2026] [security2:error] [pid 230252:tid 230509] [client 20.104.96.117:62940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/config.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbWwAAAxY"]
[Tue Jul 21 07:28:08.938620 2026] [security2:error] [pid 230252:tid 230344] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbXgACtlk"]
[Tue Jul 21 07:28:08.938764 2026] [security2:error] [pid 230252:tid 230413] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbXgACtlk"]
[Tue Jul 21 07:28:09.205149 2026] [security2:error] [pid 230252:tid 230455] [client 20.197.195.24:12413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/images.php"] [unique_id "al9JuU0Dwhk5-Z44XrpbYQAAAuA"]
[Tue Jul 21 07:28:09.260622 2026] [security2:error] [pid 230252:tid 230510] [client 20.104.96.117:5109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/gettest.php"] [unique_id "al9JuU0Dwhk5-Z44XrpbYgAAAxc"]
[Tue Jul 21 07:28:09.300923 2026] [security2:error] [pid 229246:tid 229407] [client 136.144.33.98:34455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JuSBMYeh5YLVG45yAXgAAAjM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:09.586844 2026] [security2:error] [pid 230252:tid 230447] [client 45.8.17.147:42883] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/upgrade/"] [unique_id "al9JuU0Dwhk5-Z44XrpbZwAAAtg"]
[Tue Jul 21 07:28:09.667677 2026] [security2:error] [pid 229246:tid 229403] [client 20.104.96.117:62954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/min.php"] [unique_id "al9JuSBMYeh5YLVG45yAYgAAAi8"]
[Tue Jul 21 07:28:09.681246 2026] [security2:error] [pid 230252:tid 230408] [client 20.151.10.161:49083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/adminfuns.php"] [unique_id "al9JuU0Dwhk5-Z44XrpbaQAAArE"]
[Tue Jul 21 07:28:09.748498 2026] [security2:error] [pid 230252:tid 230316] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JuU0Dwhk5-Z44XrpbagACrj4"]
[Tue Jul 21 07:28:09.748668 2026] [security2:error] [pid 230252:tid 230405] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JuU0Dwhk5-Z44XrpbagACrj4"]
[Tue Jul 21 07:28:10.009398 2026] [security2:error] [pid 230252:tid 230394] [client 20.104.96.117:5094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/dvjul.php"] [unique_id "al9Juk0Dwhk5-Z44XrpbbgAAAqM"]
[Tue Jul 21 07:28:10.137665 2026] [security2:error] [pid 229246:tid 229436] [client 82.102.28.107:58740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9JuiBMYeh5YLVG45yAaAAAAlA"]
[Tue Jul 21 07:28:10.137777 2026] [security2:error] [pid 229246:tid 229436] [client 82.102.28.107:58740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9JuiBMYeh5YLVG45yAaAAAAlA"]
[Tue Jul 21 07:28:10.220036 2026] [security2:error] [pid 230252:tid 230454] [client 20.220.225.223:31170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/dragonshell.php"] [unique_id "al9Juk0Dwhk5-Z44XrpbbwAAAt8"]
[Tue Jul 21 07:28:10.287967 2026] [security2:error] [pid 230252:tid 230477] [client 103.162.129.114:64374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Juk0Dwhk5-Z44XrpbcQAAAvY"]
[Tue Jul 21 07:28:10.288087 2026] [security2:error] [pid 230252:tid 230477] [client 103.162.129.114:64374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Juk0Dwhk5-Z44XrpbcQAAAvY"]
[Tue Jul 21 07:28:10.533441 2026] [security2:error] [pid 229246:tid 229426] [client 20.104.96.117:62936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/biufile.php"] [unique_id "al9JuiBMYeh5YLVG45yAbwAAAkY"]
[Tue Jul 21 07:28:10.608553 2026] [proxy:error] [pid 230252:tid 230500] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:10.608629 2026] [proxy_http:error] [pid 230252:tid 230500] [client 74.249.245.134:54365] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:10.609144 2026] [proxy:error] [pid 230252:tid 230500] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:10.609173 2026] [proxy_http:error] [pid 230252:tid 230500] [client 74.249.245.134:54365] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:10.785083 2026] [security2:error] [pid 230252:tid 230452] [client 45.8.17.110:50193] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/edit-tags.php"] [unique_id "al9Juk0Dwhk5-Z44XrpbdAAAAt0"]
[Tue Jul 21 07:28:10.792844 2026] [security2:error] [pid 230252:tid 230319] [remote 207.180.241.245:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Juk0Dwhk5-Z44XrpbdQAC5EE"], referer: http://assumaocontrole.com/
[Tue Jul 21 07:28:10.902832 2026] [security2:error] [pid 229246:tid 229414] [client 20.104.96.117:62935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/av.php"] [unique_id "al9JuiBMYeh5YLVG45yAdAAAAjo"]
[Tue Jul 21 07:28:11.248003 2026] [security2:error] [pid 230252:tid 230398] [client 20.151.10.161:49116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/goods.php"] [unique_id "al9Ju00Dwhk5-Z44XrpbfQAAAqc"]
[Tue Jul 21 07:28:11.330448 2026] [security2:error] [pid 230252:tid 230444] [client 20.104.96.117:64005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/coffexium.php"] [unique_id "al9Ju00Dwhk5-Z44XrpbfwAAAtU"]
[Tue Jul 21 07:28:11.641787 2026] [security2:error] [pid 230252:tid 230268] [remote 54.39.0.165:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "marketingderua.com.br"] [uri "/como-funciona-a-programacao-de-conteudo-em-telas-de-ooh/"] [unique_id "al9Ju00Dwhk5-Z44XrpbhwADCA4"]
[Tue Jul 21 07:28:11.641950 2026] [security2:error] [pid 230252:tid 230495] [client 54.39.0.165:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "marketingderua.com.br"] [uri "/como-funciona-a-programacao-de-conteudo-em-telas-de-ooh/"] [unique_id "al9Ju00Dwhk5-Z44XrpbhwADCA4"]
[Tue Jul 21 07:28:11.647190 2026] [security2:error] [pid 230252:tid 230436] [client 20.104.96.117:64049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/core.php"] [unique_id "al9Ju00Dwhk5-Z44XrpbiAAAAs0"]
[Tue Jul 21 07:28:11.876111 2026] [security2:error] [pid 230252:tid 230255] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ju00Dwhk5-Z44XrpbjAADFwE"]
[Tue Jul 21 07:28:11.876246 2026] [security2:error] [pid 230252:tid 230510] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ju00Dwhk5-Z44XrpbjAADFwE"]
[Tue Jul 21 07:28:11.986394 2026] [security2:error] [pid 230252:tid 230503] [client 45.8.17.73:59357] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/log.php"] [unique_id "al9Ju00Dwhk5-Z44XrpbjQAAAxA"]
[Tue Jul 21 07:28:12.034481 2026] [security2:error] [pid 230252:tid 230405] [client 20.104.96.117:64019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/als.php"] [unique_id "al9JvE0Dwhk5-Z44XrpbjgAAAq4"]
[Tue Jul 21 07:28:12.101963 2026] [security2:error] [pid 230252:tid 230394] [client 20.151.10.161:49036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/ms-edit.php"] [unique_id "al9JvE0Dwhk5-Z44XrpbkgAAAqM"]
[Tue Jul 21 07:28:12.193665 2026] [proxy:error] [pid 230252:tid 230399] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:12.193748 2026] [proxy_http:error] [pid 230252:tid 230399] [client 74.249.245.134:62861] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:12.194896 2026] [proxy:error] [pid 230252:tid 230399] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:12.194952 2026] [proxy_http:error] [pid 230252:tid 230399] [client 74.249.245.134:62861] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:12.261709 2026] [security2:error] [pid 230252:tid 230477] [client 20.104.96.117:59817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/v543.php"] [unique_id "al9JvE0Dwhk5-Z44XrpblwAAAvY"]
[Tue Jul 21 07:28:12.421803 2026] [security2:error] [pid 230252:tid 230390] [client 20.104.96.117:62939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/simple.php"] [unique_id "al9JvE0Dwhk5-Z44XrpbmgAAAp8"]
[Tue Jul 21 07:28:12.791933 2026] [security2:error] [pid 230252:tid 230428] [client 20.104.96.117:64008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/init.php"] [unique_id "al9JvE0Dwhk5-Z44XrpbowAAAsU"]
[Tue Jul 21 07:28:12.933549 2026] [security2:error] [pid 230252:tid 230462] [client 74.249.245.134:54382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/settings.php"] [unique_id "al9JvE0Dwhk5-Z44XrpbpQAAAuc"]
[Tue Jul 21 07:28:13.166189 2026] [security2:error] [pid 230252:tid 230453] [client 20.104.96.117:64024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/fpwch.php"] [unique_id "al9JvU0Dwhk5-Z44XrpbqQAAAt4"]
[Tue Jul 21 07:28:13.180343 2026] [security2:error] [pid 229246:tid 229455] [client 45.8.17.64:61063] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/bless.php"] [unique_id "al9JvSBMYeh5YLVG45yAiwAAAmM"]
[Tue Jul 21 07:28:13.213093 2026] [security2:error] [pid 230252:tid 230444] [client 173.252.95.25:39386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9JvU0Dwhk5-Z44XrpbqgAAAtU"]
[Tue Jul 21 07:28:13.277889 2026] [security2:error] [pid 229246:tid 229367] [remote 192.241.143.148:40672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9JvSBMYeh5YLVG45yAjAACHXg"]
[Tue Jul 21 07:28:13.479094 2026] [security2:error] [pid 229246:tid 229423] [client 20.197.195.24:12380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/gecko.php"] [unique_id "al9JvSBMYeh5YLVG45yAjgAAAkM"]
[Tue Jul 21 07:28:13.580758 2026] [security2:error] [pid 229246:tid 229454] [client 20.104.96.117:62924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/domvf.php"] [unique_id "al9JvSBMYeh5YLVG45yAkgAAAmI"]
[Tue Jul 21 07:28:13.594568 2026] [security2:error] [pid 230252:tid 230395] [client 20.220.225.223:38705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/wp-mt.php"] [unique_id "al9JvU0Dwhk5-Z44XrpbrAAAAqQ"]
[Tue Jul 21 07:28:13.594863 2026] [security2:error] [pid 230252:tid 230484] [client 20.151.10.161:48634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/222.php"] [unique_id "al9JvU0Dwhk5-Z44XrpbrQAAAv0"]
[Tue Jul 21 07:28:13.871326 2026] [security2:error] [pid 230252:tid 230420] [client 20.104.96.117:64063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp.php"] [unique_id "al9JvU0Dwhk5-Z44XrpbsAAAAr0"]
[Tue Jul 21 07:28:13.987651 2026] [security2:error] [pid 229246:tid 229427] [client 74.249.245.134:17470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/g.php"] [unique_id "al9JvSBMYeh5YLVG45yAlgAAAkc"]
[Tue Jul 21 07:28:13.993144 2026] [security2:error] [pid 230252:tid 230511] [client 45.8.17.118:57999] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Text/"] [unique_id "al9JvU0Dwhk5-Z44XrpbswAAAxg"]
[Tue Jul 21 07:28:14.274755 2026] [security2:error] [pid 229246:tid 229503] [client 20.104.96.117:64038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/class.php"] [unique_id "al9JviBMYeh5YLVG45yAnAAAApM"]
[Tue Jul 21 07:28:14.417285 2026] [security2:error] [pid 230252:tid 230498] [client 152.59.154.239:52547] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jvk0Dwhk5-Z44XrpbwAAAAws"]
[Tue Jul 21 07:28:14.417419 2026] [security2:error] [pid 230252:tid 230498] [client 152.59.154.239:52547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jvk0Dwhk5-Z44XrpbwAAAAws"]
[Tue Jul 21 07:28:14.420098 2026] [security2:error] [pid 229246:tid 229500] [client 139.135.44.145:54093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JviBMYeh5YLVG45yAnQAAApA"]
[Tue Jul 21 07:28:14.420549 2026] [security2:error] [pid 229246:tid 229500] [client 139.135.44.145:54093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JviBMYeh5YLVG45yAnQAAApA"]
[Tue Jul 21 07:28:14.609836 2026] [security2:error] [pid 230252:tid 230399] [client 20.52.136.55:1580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/8.php"] [unique_id "al9Jvk0Dwhk5-Z44XrpbwwAAAqg"]
[Tue Jul 21 07:28:14.791116 2026] [security2:error] [pid 229246:tid 229392] [client 74.249.245.134:5527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/403.php"] [unique_id "al9JviBMYeh5YLVG45yAogAAAiQ"]
[Tue Jul 21 07:28:14.860003 2026] [security2:error] [pid 230252:tid 230501] [client 20.104.96.117:5060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/echkm.php"] [unique_id "al9Jvk0Dwhk5-Z44XrpbygAAAw4"]
[Tue Jul 21 07:28:14.860675 2026] [security2:error] [pid 230252:tid 230408] [client 45.251.232.145:53253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jvk0Dwhk5-Z44XrpbywAAArE"]
[Tue Jul 21 07:28:14.860757 2026] [security2:error] [pid 230252:tid 230408] [client 45.251.232.145:53253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jvk0Dwhk5-Z44XrpbywAAArE"]
[Tue Jul 21 07:28:14.861639 2026] [security2:error] [pid 230252:tid 230510] [client 117.251.86.144:40562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Jvk0Dwhk5-Z44XrpbzAAAAxc"]
[Tue Jul 21 07:28:14.861777 2026] [security2:error] [pid 230252:tid 230510] [client 117.251.86.144:40562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Jvk0Dwhk5-Z44XrpbzAAAAxc"]
[Tue Jul 21 07:28:15.192312 2026] [security2:error] [pid 229246:tid 229354] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JvyBMYeh5YLVG45yAqQACJ2s"]
[Tue Jul 21 07:28:15.192470 2026] [security2:error] [pid 229246:tid 229395] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JvyBMYeh5YLVG45yAqQACJ2s"]
[Tue Jul 21 07:28:15.227941 2026] [security2:error] [pid 230252:tid 230426] [client 20.104.96.117:62968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/lib.php"] [unique_id "al9Jv00Dwhk5-Z44Xrpb1AAAAsM"]
[Tue Jul 21 07:28:15.284227 2026] [security2:error] [pid 230252:tid 230476] [client 74.7.230.14:56288] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.teste.inonebrasil.com.br"] [uri "/index.php"] [unique_id "al9Jv00Dwhk5-Z44Xrpb1QAC9RQ"]
[Tue Jul 21 07:28:15.383277 2026] [security2:error] [pid 229246:tid 229459] [client 45.8.17.137:28413] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/languages/themes/"] [unique_id "al9JvyBMYeh5YLVG45yArAAAAmc"]
[Tue Jul 21 07:28:15.525284 2026] [security2:error] [pid 230252:tid 230411] [client 20.151.10.161:49041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9Jv00Dwhk5-Z44Xrpb1gAAArQ"]
[Tue Jul 21 07:28:15.543780 2026] [security2:error] [pid 230252:tid 230453] [client 74.249.245.134:54339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/api.php"] [unique_id "al9Jv00Dwhk5-Z44Xrpb1wAAAt4"]
[Tue Jul 21 07:28:15.567779 2026] [security2:error] [pid 230252:tid 230398] [client 20.104.96.117:62942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/login.php"] [unique_id "al9Jv00Dwhk5-Z44Xrpb2AAAAqc"]
[Tue Jul 21 07:28:15.671318 2026] [security2:error] [pid 229246:tid 229489] [client 59.96.220.140:50064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JvyBMYeh5YLVG45yArwAAAoU"]
[Tue Jul 21 07:28:15.672494 2026] [security2:error] [pid 229246:tid 229489] [client 59.96.220.140:50064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JvyBMYeh5YLVG45yArwAAAoU"]
[Tue Jul 21 07:28:15.682989 2026] [security2:error] [pid 230252:tid 230507] [client 66.42.61.105:37858] ModSecurity: Access denied with code 406 (phase 1). Match of "rx (^/administrator/)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "63"] [id "331216"] [rev "2"] [msg "Atomicorp.com WAF Rules: Wordpress DOS Attack Dropped"] [severity "CRITICAL"] [hostname "cotidianorural.com.br"] [uri "/wp-load.php"] [unique_id "al9Jv00Dwhk5-Z44Xrpb3QAAAxQ"]
[Tue Jul 21 07:28:15.707432 2026] [security2:error] [pid 230252:tid 230467] [client 193.36.225.61:54275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Jvk0Dwhk5-Z44XrpbwQAAAuw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:15.852012 2026] [security2:error] [pid 230252:tid 230508] [client 20.197.195.24:12297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/82.php"] [unique_id "al9Jv00Dwhk5-Z44Xrpb3gAAAxU"]
[Tue Jul 21 07:28:15.936546 2026] [security2:error] [pid 229246:tid 229436] [client 20.104.96.117:5061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/a2.php"] [unique_id "al9JvyBMYeh5YLVG45yAsgAAAlA"]
[Tue Jul 21 07:28:16.080752 2026] [proxy:error] [pid 229246:tid 229488] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:16.080837 2026] [proxy_http:error] [pid 229246:tid 229488] [client 20.151.10.161:49139] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:16.081300 2026] [proxy:error] [pid 229246:tid 229488] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:16.081327 2026] [proxy_http:error] [pid 229246:tid 229488] [client 20.151.10.161:49139] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:16.081962 2026] [proxy:error] [pid 230252:tid 230464] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:16.082008 2026] [proxy_http:error] [pid 230252:tid 230464] [client 74.249.245.134:54378] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:16.082437 2026] [proxy:error] [pid 230252:tid 230464] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:16.082459 2026] [proxy_http:error] [pid 230252:tid 230464] [client 74.249.245.134:54378] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:16.203341 2026] [security2:error] [pid 229246:tid 229451] [client 20.220.225.223:62134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9JwCBMYeh5YLVG45yAuAAAAl8"]
[Tue Jul 21 07:28:16.352378 2026] [security2:error] [pid 230252:tid 230503] [client 20.104.96.117:5075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/d61.php"] [unique_id "al9JwE0Dwhk5-Z44Xrpb5gAAAxA"]
[Tue Jul 21 07:28:16.392135 2026] [security2:error] [pid 230252:tid 230407] [client 45.8.17.110:60631] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/file-upload-types/assets/css/403.php"] [unique_id "al9JwE0Dwhk5-Z44Xrpb5wAAArA"]
[Tue Jul 21 07:28:16.730058 2026] [security2:error] [pid 229246:tid 229501] [client 20.104.96.117:5111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/info.php"] [unique_id "al9JwCBMYeh5YLVG45yAwQAAApE"]
[Tue Jul 21 07:28:16.865947 2026] [security2:error] [pid 230252:tid 230261] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JwE0Dwhk5-Z44Xrpb7AAC1Ac"]
[Tue Jul 21 07:28:16.866103 2026] [security2:error] [pid 230252:tid 230443] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JwE0Dwhk5-Z44Xrpb7AAC1Ac"]
[Tue Jul 21 07:28:16.880567 2026] [security2:error] [pid 230252:tid 230449] [client 20.220.225.223:38674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/ww.php"] [unique_id "al9JwE0Dwhk5-Z44Xrpb7QAAAto"]
[Tue Jul 21 07:28:16.977853 2026] [security2:error] [pid 230252:tid 230477] [client 20.104.96.117:59643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/sixxis.php"] [unique_id "al9JwE0Dwhk5-Z44Xrpb7wAAAvY"]
[Tue Jul 21 07:28:17.080114 2026] [security2:error] [pid 230252:tid 230414] [client 20.104.96.117:4172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/11.php"] [unique_id "al9JwU0Dwhk5-Z44Xrpb8AAAArc"]
[Tue Jul 21 07:28:17.279334 2026] [security2:error] [pid 230252:tid 230493] [client 45.8.17.122:36799] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/autoload_classmap.php"] [unique_id "al9JwU0Dwhk5-Z44Xrpb9AAAAwY"]
[Tue Jul 21 07:28:17.525947 2026] [security2:error] [pid 229246:tid 229418] [client 20.104.96.117:5073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/v2.php"] [unique_id "al9JwSBMYeh5YLVG45yAxwAAAj4"]
[Tue Jul 21 07:28:17.803871 2026] [security2:error] [pid 229246:tid 229475] [client 20.151.10.161:49060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9JwSBMYeh5YLVG45yAywAAAnc"]
[Tue Jul 21 07:28:17.842876 2026] [security2:error] [pid 230252:tid 230466] [client 103.106.20.201:53688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JwU0Dwhk5-Z44XrpcAgAAAus"]
[Tue Jul 21 07:28:17.843007 2026] [security2:error] [pid 230252:tid 230466] [client 103.106.20.201:53688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JwU0Dwhk5-Z44XrpcAgAAAus"]
[Tue Jul 21 07:28:17.992486 2026] [security2:error] [pid 230252:tid 230505] [client 20.197.195.24:12356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/admin.php"] [unique_id "al9JwU0Dwhk5-Z44XrpcAwAAAxI"]
[Tue Jul 21 07:28:17.994905 2026] [security2:error] [pid 230252:tid 230511] [client 20.104.96.117:5087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/panel.php"] [unique_id "al9JwU0Dwhk5-Z44XrpcBAAAAxg"]
[Tue Jul 21 07:28:18.253455 2026] [security2:error] [pid 230252:tid 230376] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Jwk0Dwhk5-Z44XrpcCgACz3k"]
[Tue Jul 21 07:28:18.253688 2026] [security2:error] [pid 230252:tid 230438] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Jwk0Dwhk5-Z44XrpcCgACz3k"]
[Tue Jul 21 07:28:18.254642 2026] [proxy:error] [pid 229246:tid 229408] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:18.254696 2026] [proxy_http:error] [pid 229246:tid 229408] [client 198.235.24.104:61054] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:18.255471 2026] [proxy:error] [pid 229246:tid 229408] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:18.255504 2026] [proxy_http:error] [pid 229246:tid 229408] [client 198.235.24.104:61054] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:18.393217 2026] [security2:error] [pid 230252:tid 230478] [client 20.104.96.117:5066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/dex.php"] [unique_id "al9Jwk0Dwhk5-Z44XrpcDwAAAvc"]
[Tue Jul 21 07:28:18.485754 2026] [security2:error] [pid 230252:tid 230495] [client 45.8.17.146:59169] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/bolt.php"] [unique_id "al9Jwk0Dwhk5-Z44XrpcEQAAAwg"]
[Tue Jul 21 07:28:18.665219 2026] [security2:error] [pid 230252:tid 230375] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Jwk0Dwhk5-Z44XrpcEgADB3g"]
[Tue Jul 21 07:28:18.665424 2026] [security2:error] [pid 230252:tid 230494] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Jwk0Dwhk5-Z44XrpcEgADB3g"]
[Tue Jul 21 07:28:18.694531 2026] [security2:error] [pid 230252:tid 230392] [client 20.104.96.117:5056] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "foreverconfidence.com"] [uri "/1.php"] [unique_id "al9Jwk0Dwhk5-Z44XrpcEwAAAqE"]
[Tue Jul 21 07:28:18.694646 2026] [security2:error] [pid 230252:tid 230392] [client 20.104.96.117:5056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/1.php"] [unique_id "al9Jwk0Dwhk5-Z44XrpcEwAAAqE"]
[Tue Jul 21 07:28:18.875162 2026] [security2:error] [pid 230252:tid 230389] [client 20.197.195.24:12376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/adminner.php"] [unique_id "al9Jwk0Dwhk5-Z44XrpcFgAAAp4"]
[Tue Jul 21 07:28:18.955825 2026] [security2:error] [pid 230252:tid 230408] [client 20.104.96.117:59623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/ip.php"] [unique_id "al9Jwk0Dwhk5-Z44XrpcFwAAArE"]
[Tue Jul 21 07:28:19.084338 2026] [security2:error] [pid 230252:tid 230439] [client 20.220.225.223:31187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/cron.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcGwAAAtA"]
[Tue Jul 21 07:28:19.140132 2026] [security2:error] [pid 230252:tid 230472] [client 103.174.34.15:49610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcIgAAAvE"]
[Tue Jul 21 07:28:19.140264 2026] [security2:error] [pid 230252:tid 230472] [client 103.174.34.15:49610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcIgAAAvE"]
[Tue Jul 21 07:28:19.146711 2026] [security2:error] [pid 230252:tid 230404] [client 20.104.96.117:5072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/ms.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcIwAAAq0"]
[Tue Jul 21 07:28:19.470665 2026] [security2:error] [pid 230252:tid 230396] [client 136.144.33.96:46219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcKAAAAqU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:19.503729 2026] [security2:error] [pid 230252:tid 230297] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcKQACzis"]
[Tue Jul 21 07:28:19.503912 2026] [security2:error] [pid 230252:tid 230437] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcKQACzis"]
[Tue Jul 21 07:28:19.505053 2026] [proxy:error] [pid 229246:tid 229474] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:19.505123 2026] [proxy_http:error] [pid 229246:tid 229474] [client 20.151.10.161:49077] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:19.505778 2026] [proxy:error] [pid 229246:tid 229474] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:19.505808 2026] [proxy_http:error] [pid 229246:tid 229474] [client 20.151.10.161:49077] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:19.520736 2026] [security2:error] [pid 229246:tid 229454] [client 74.7.244.9:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "oscardemattos1745866142707.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9JwyBMYeh5YLVG45yA2QACYkc"]
[Tue Jul 21 07:28:19.528288 2026] [security2:error] [pid 230252:tid 230454] [client 154.192.233.199:59142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcKgAAAt8"]
[Tue Jul 21 07:28:19.528457 2026] [security2:error] [pid 230252:tid 230454] [client 154.192.233.199:59142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcKgAAAt8"]
[Tue Jul 21 07:28:19.554683 2026] [security2:error] [pid 229246:tid 229477] [client 20.197.195.24:12366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/admin.php"] [unique_id "al9JwyBMYeh5YLVG45yA2gAAAnk"]
[Tue Jul 21 07:28:19.555530 2026] [security2:error] [pid 230252:tid 230508] [client 20.220.225.223:62874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/dp.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcKwAAAxU"]
[Tue Jul 21 07:28:19.606018 2026] [security2:error] [pid 230252:tid 230477] [client 175.45.70.82:56720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcLAAAAvY"]
[Tue Jul 21 07:28:19.606185 2026] [security2:error] [pid 230252:tid 230477] [client 175.45.70.82:56720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcLAAAAvY"]
[Tue Jul 21 07:28:19.690941 2026] [autoindex:error] [pid 229246:tid 229390] [client 20.104.96.117:64056] AH01276: Cannot serve directory /home4/forev309/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:19.737778 2026] [security2:error] [pid 229246:tid 229268] [remote 152.42.137.70:46766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.137.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedrocromo.com.br"] [uri "/wp-login.php"] [unique_id "al9JwyBMYeh5YLVG45yA3QACLBU"]
[Tue Jul 21 07:28:19.747663 2026] [security2:error] [pid 229246:tid 229502] [client 62.102.148.164:47580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9JwyBMYeh5YLVG45yA3gAAApI"]
[Tue Jul 21 07:28:19.747734 2026] [security2:error] [pid 229246:tid 229502] [client 62.102.148.164:47580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9JwyBMYeh5YLVG45yA3gAAApI"]
[Tue Jul 21 07:28:19.875767 2026] [security2:error] [pid 230252:tid 230417] [client 20.197.195.24:12288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/k.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcLwAAAro"]
[Tue Jul 21 07:28:19.968585 2026] [security2:error] [pid 229246:tid 229500] [client 20.104.96.117:64056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/memberfuns.php"] [unique_id "al9JwyBMYeh5YLVG45yA4QAAApA"]
[Tue Jul 21 07:28:19.993737 2026] [security2:error] [pid 229246:tid 229479] [client 20.197.195.24:12369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/blurbs.php"] [unique_id "al9JwyBMYeh5YLVG45yA4gAAAns"]
[Tue Jul 21 07:28:20.082573 2026] [security2:error] [pid 230252:tid 230503] [client 45.8.17.146:22407] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/maint/chosen.php"] [unique_id "al9JxE0Dwhk5-Z44XrpcMQAAAxA"]
[Tue Jul 21 07:28:20.130863 2026] [security2:error] [pid 229246:tid 229499] [client 213.152.162.104:49150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9JxCBMYeh5YLVG45yA4wAAAo8"]
[Tue Jul 21 07:28:20.130958 2026] [security2:error] [pid 229246:tid 229499] [client 213.152.162.104:49150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9JxCBMYeh5YLVG45yA4wAAAo8"]
[Tue Jul 21 07:28:20.265615 2026] [security2:error] [pid 229246:tid 229323] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JxCBMYeh5YLVG45yA5QACW0w"]
[Tue Jul 21 07:28:20.265884 2026] [security2:error] [pid 229246:tid 229447] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JxCBMYeh5YLVG45yA5QACW0w"]
[Tue Jul 21 07:28:20.383902 2026] [security2:error] [pid 229246:tid 229459] [client 20.197.195.24:12360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/bajah.php"] [unique_id "al9JxCBMYeh5YLVG45yA7AAAAmc"]
[Tue Jul 21 07:28:20.405649 2026] [security2:error] [pid 230252:tid 230394] [client 20.104.96.117:4166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/0.php"] [unique_id "al9JxE0Dwhk5-Z44XrpcMwAAAqM"]
[Tue Jul 21 07:28:20.772349 2026] [security2:error] [pid 230252:tid 230448] [client 103.162.129.114:64814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JxE0Dwhk5-Z44XrpcNAAAAtk"]
[Tue Jul 21 07:28:20.772529 2026] [security2:error] [pid 230252:tid 230448] [client 103.162.129.114:64814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JxE0Dwhk5-Z44XrpcNAAAAtk"]
[Tue Jul 21 07:28:20.856757 2026] [proxy:error] [pid 229246:tid 229425] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:20.856846 2026] [proxy_http:error] [pid 229246:tid 229425] [client 20.151.10.161:49091] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:20.857407 2026] [proxy:error] [pid 229246:tid 229425] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:20.857438 2026] [proxy_http:error] [pid 229246:tid 229425] [client 20.151.10.161:49091] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:20.943322 2026] [security2:error] [pid 229246:tid 229456] [client 20.104.96.117:62960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/BDKR28.php"] [unique_id "al9JxCBMYeh5YLVG45yA9gAAAmQ"]
[Tue Jul 21 07:28:20.975022 2026] [security2:error] [pid 230252:tid 230392] [client 20.197.195.24:12305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/a.php"] [unique_id "al9JxE0Dwhk5-Z44XrpcNgAAAqE"]
[Tue Jul 21 07:28:21.059094 2026] [security2:error] [pid 230252:tid 230443] [client 20.197.195.24:12327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/edit.php"] [unique_id "al9JxU0Dwhk5-Z44XrpcNwAAAtQ"]
[Tue Jul 21 07:28:21.108763 2026] [security2:error] [pid 230252:tid 230449] [client 20.197.195.24:12396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/hosty.php"] [unique_id "al9JxU0Dwhk5-Z44XrpcOAAAAto"]
[Tue Jul 21 07:28:21.197695 2026] [security2:error] [pid 229246:tid 229378] [client 20.197.195.24:12353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/k.php"] [unique_id "al9JxSBMYeh5YLVG45yA-wAAAhY"]
[Tue Jul 21 07:28:21.305833 2026] [security2:error] [pid 230252:tid 230428] [client 20.197.195.24:12387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/aaa.php"] [unique_id "al9JxU0Dwhk5-Z44XrpcPQAAAsU"]
[Tue Jul 21 07:28:21.319188 2026] [security2:error] [pid 229246:tid 229433] [client 20.104.96.117:5082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/green1.php"] [unique_id "al9JxSBMYeh5YLVG45yA_AAAAk0"]
[Tue Jul 21 07:28:21.410395 2026] [security2:error] [pid 230252:tid 230506] [client 20.104.96.117:59585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/kq1.php"] [unique_id "al9JxU0Dwhk5-Z44XrpcQAAAAxM"]
[Tue Jul 21 07:28:21.542284 2026] [security2:error] [pid 230252:tid 230483] [client 20.220.225.223:38663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/xxx.php"] [unique_id "al9JxU0Dwhk5-Z44XrpcQQAAAvw"]
[Tue Jul 21 07:28:21.649868 2026] [security2:error] [pid 230252:tid 230463] [client 20.197.195.24:12399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/file5.php"] [unique_id "al9JxU0Dwhk5-Z44XrpcQgAAAug"]
[Tue Jul 21 07:28:21.720993 2026] [security2:error] [pid 229246:tid 229492] [client 20.104.96.117:64003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/nc4.php"] [unique_id "al9JxSBMYeh5YLVG45yBAwAAAog"]
[Tue Jul 21 07:28:21.858162 2026] [security2:error] [pid 230252:tid 230458] [client 45.8.17.116:59291] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JxU0Dwhk5-Z44XrpcQwAAAuM"]
[Tue Jul 21 07:28:21.892431 2026] [security2:error] [pid 229246:tid 229424] [client 20.151.10.161:49142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp.php"] [unique_id "al9JxSBMYeh5YLVG45yBCwAAAkQ"]
[Tue Jul 21 07:28:21.946764 2026] [security2:error] [pid 229246:tid 229480] [client 20.197.195.24:12375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/222.php"] [unique_id "al9JxSBMYeh5YLVG45yBDQAAAnw"]
[Tue Jul 21 07:28:22.067508 2026] [autoindex:error] [pid 229246:tid 229256] [remote 74.7.242.41:59998] AH01276: Cannot serve directory /home2/prove728/valordistribuidora.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:22.111742 2026] [security2:error] [pid 230252:tid 230461] [client 74.7.228.56:35116] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "valordistribuidora.provendasatacado.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9Jxk0Dwhk5-Z44XrpcRwAC5hk"]
[Tue Jul 21 07:28:22.119759 2026] [security2:error] [pid 230252:tid 230437] [client 20.104.96.117:4197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/a1.php"] [unique_id "al9Jxk0Dwhk5-Z44XrpcSAAAAs4"]
[Tue Jul 21 07:28:22.206300 2026] [security2:error] [pid 230252:tid 230403] [client 20.197.195.24:12367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/test.php"] [unique_id "al9Jxk0Dwhk5-Z44XrpcSgAAAqw"]
[Tue Jul 21 07:28:22.413517 2026] [security2:error] [pid 230252:tid 230455] [client 20.104.96.117:62937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/eee.php"] [unique_id "al9Jxk0Dwhk5-Z44XrpcTAAAAuA"]
[Tue Jul 21 07:28:22.476417 2026] [security2:error] [pid 230252:tid 230307] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jxk0Dwhk5-Z44XrpcUQACpzU"]
[Tue Jul 21 07:28:22.476589 2026] [security2:error] [pid 230252:tid 230398] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jxk0Dwhk5-Z44XrpcUQACpzU"]
[Tue Jul 21 07:28:22.507139 2026] [security2:error] [pid 230252:tid 230395] [client 20.197.195.24:12302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/aaa.php"] [unique_id "al9Jxk0Dwhk5-Z44XrpcVAAAAqQ"]
[Tue Jul 21 07:28:22.606113 2026] [security2:error] [pid 230252:tid 230469] [client 20.197.195.24:12377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/11.php"] [unique_id "al9Jxk0Dwhk5-Z44XrpcVgAAAu4"]
[Tue Jul 21 07:28:22.610866 2026] [security2:error] [pid 230252:tid 230380] [remote 173.252.95.57:41090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9Jxk0Dwhk5-Z44XrpcVwAC030"]
[Tue Jul 21 07:28:22.796635 2026] [security2:error] [pid 230252:tid 230392] [client 45.8.17.141:60433] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/worksec.php"] [unique_id "al9Jxk0Dwhk5-Z44XrpcXAAAAqE"]
[Tue Jul 21 07:28:22.923679 2026] [security2:error] [pid 230252:tid 230443] [client 20.104.96.117:4175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp-aothait.php"] [unique_id "al9Jxk0Dwhk5-Z44XrpcXwAAAtQ"]
[Tue Jul 21 07:28:22.936988 2026] [security2:error] [pid 230252:tid 230449] [client 20.197.195.24:12368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/mac.php"] [unique_id "al9Jxk0Dwhk5-Z44XrpcYgAAAto"]
[Tue Jul 21 07:28:23.044329 2026] [security2:error] [pid 229246:tid 229380] [client 82.102.28.107:56928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9JxyBMYeh5YLVG45yBHAAAAhg"]
[Tue Jul 21 07:28:23.044406 2026] [security2:error] [pid 229246:tid 229380] [client 82.102.28.107:56928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9JxyBMYeh5YLVG45yBHAAAAhg"]
[Tue Jul 21 07:28:23.090224 2026] [security2:error] [pid 230252:tid 230462] [client 20.151.10.161:49133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/abcd.php"] [unique_id "al9Jx00Dwhk5-Z44XrpcaQAAAuc"]
[Tue Jul 21 07:28:23.095960 2026] [security2:error] [pid 230252:tid 230384] [client 20.104.96.117:59631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9Jx00Dwhk5-Z44XrpcagAAApk"]
[Tue Jul 21 07:28:23.133137 2026] [security2:error] [pid 230252:tid 230463] [client 20.197.195.24:12299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/chosen.php"] [unique_id "al9Jx00Dwhk5-Z44XrpcawAAAug"]
[Tue Jul 21 07:28:23.211281 2026] [security2:error] [pid 230252:tid 230386] [client 20.104.96.117:64052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/config.json.php"] [unique_id "al9Jx00Dwhk5-Z44XrpcbAAAAps"]
[Tue Jul 21 07:28:23.561385 2026] [security2:error] [pid 230252:tid 230418] [client 20.197.195.24:12343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/cream1.php"] [unique_id "al9Jx00Dwhk5-Z44XrpccgAAArs"]
[Tue Jul 21 07:28:23.605297 2026] [security2:error] [pid 230252:tid 230403] [client 20.104.96.117:64022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9Jx00Dwhk5-Z44XrpccwAAAqw"]
[Tue Jul 21 07:28:23.949396 2026] [security2:error] [pid 230252:tid 230455] [client 20.104.96.117:4182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/k2.php"] [unique_id "al9Jx00Dwhk5-Z44XrpcdQAAAuA"]
[Tue Jul 21 07:28:24.024440 2026] [security2:error] [pid 230252:tid 230417] [client 20.104.96.117:59646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/h02ugyh.php"] [unique_id "al9JyE0Dwhk5-Z44XrpcdgAAAro"]
[Tue Jul 21 07:28:24.039203 2026] [autoindex:error] [pid 230252:tid 230485] [client 20.197.195.24:12293] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:24.044282 2026] [security2:error] [pid 229246:tid 229384] [client 20.151.10.161:49117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/a1.php"] [unique_id "al9JyCBMYeh5YLVG45yBIwAAAhw"]
[Tue Jul 21 07:28:24.078845 2026] [autoindex:error] [pid 230252:tid 230438] [client 20.197.195.24:12293] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:24.088839 2026] [security2:error] [pid 229246:tid 229407] [client 45.8.17.148:21661] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content.php"] [unique_id "al9JyCBMYeh5YLVG45yBJAAAAjM"]
[Tue Jul 21 07:28:24.097594 2026] [security2:error] [pid 230252:tid 230398] [client 20.197.195.24:12293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/dr.php"] [unique_id "al9JyE0Dwhk5-Z44XrpcewAAAqc"]
[Tue Jul 21 07:28:24.352943 2026] [security2:error] [pid 229246:tid 229467] [client 193.36.225.54:58565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JyCBMYeh5YLVG45yBKQAAAm8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:24.700494 2026] [security2:error] [pid 229246:tid 229488] [client 20.104.96.117:62929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/uiuvs58l.php"] [unique_id "al9JyCBMYeh5YLVG45yBLwAAAoQ"]
[Tue Jul 21 07:28:24.826572 2026] [security2:error] [pid 229246:tid 229426] [client 20.197.195.24:12320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/x.php"] [unique_id "al9JyCBMYeh5YLVG45yBMQAAAkY"]
[Tue Jul 21 07:28:25.087450 2026] [security2:error] [pid 229246:tid 229460] [client 45.8.17.131:59857] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/chosen.php"] [unique_id "al9JySBMYeh5YLVG45yBNAAAAmg"]
[Tue Jul 21 07:28:25.095329 2026] [security2:error] [pid 229246:tid 229450] [client 139.135.44.145:54891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JySBMYeh5YLVG45yBNQAAAl4"]
[Tue Jul 21 07:28:25.095425 2026] [security2:error] [pid 229246:tid 229450] [client 139.135.44.145:54891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JySBMYeh5YLVG45yBNQAAAl4"]
[Tue Jul 21 07:28:25.235901 2026] [security2:error] [pid 229246:tid 229433] [client 20.104.96.117:5092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/40p9ixjd.php"] [unique_id "al9JySBMYeh5YLVG45yBOwAAAk0"]
[Tue Jul 21 07:28:25.298109 2026] [security2:error] [pid 229246:tid 229491] [client 20.151.10.161:49118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9JySBMYeh5YLVG45yBPAAAAoc"]
[Tue Jul 21 07:28:25.302113 2026] [security2:error] [pid 230252:tid 230506] [client 20.104.96.117:42405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-temp.php"] [unique_id "al9JyU0Dwhk5-Z44XrpchwAAAxM"]
[Tue Jul 21 07:28:25.343860 2026] [security2:error] [pid 229246:tid 229458] [client 45.251.232.145:53769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JySBMYeh5YLVG45yBPQAAAmY"]
[Tue Jul 21 07:28:25.343975 2026] [security2:error] [pid 229246:tid 229458] [client 45.251.232.145:53769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JySBMYeh5YLVG45yBPQAAAmY"]
[Tue Jul 21 07:28:25.483384 2026] [security2:error] [pid 230252:tid 230469] [client 152.59.154.239:52971] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JyU0Dwhk5-Z44XrpciAAAAu4"]
[Tue Jul 21 07:28:25.483499 2026] [security2:error] [pid 230252:tid 230469] [client 152.59.154.239:52971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JyU0Dwhk5-Z44XrpciAAAAu4"]
[Tue Jul 21 07:28:25.575808 2026] [security2:error] [pid 229246:tid 229418] [client 20.104.96.117:5065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/uiuvs58l.update.php"] [unique_id "al9JySBMYeh5YLVG45yBQAAAAj4"]
[Tue Jul 21 07:28:25.635523 2026] [security2:error] [pid 229246:tid 229445] [client 117.251.86.144:60472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JySBMYeh5YLVG45yBQwAAAlk"]
[Tue Jul 21 07:28:25.635632 2026] [security2:error] [pid 229246:tid 229445] [client 117.251.86.144:60472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JySBMYeh5YLVG45yBQwAAAlk"]
[Tue Jul 21 07:28:25.703267 2026] [security2:error] [pid 229246:tid 229484] [client 20.197.195.24:20592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/155.php"] [unique_id "al9JySBMYeh5YLVG45yBRgAAAoA"]
[Tue Jul 21 07:28:25.779850 2026] [security2:error] [pid 230252:tid 230357] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JyU0Dwhk5-Z44XrpciwACmWY"]
[Tue Jul 21 07:28:25.779975 2026] [security2:error] [pid 230252:tid 230384] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JyU0Dwhk5-Z44XrpciwACmWY"]
[Tue Jul 21 07:28:25.951685 2026] [security2:error] [pid 229246:tid 229411] [client 20.197.195.24:20570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/ops.php"] [unique_id "al9JySBMYeh5YLVG45yBSAAAAjc"]
[Tue Jul 21 07:28:26.105511 2026] [security2:error] [pid 230252:tid 230488] [client 20.197.195.24:12393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/file31.php"] [unique_id "al9Jyk0Dwhk5-Z44XrpckAAAAwE"]
[Tue Jul 21 07:28:26.132238 2026] [security2:error] [pid 229246:tid 229284] [remote 147.135.213.27:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.hauptmann.com.br"] [uri "/robots.txt"] [unique_id "al9JyiBMYeh5YLVG45yBTgACYSU"]
[Tue Jul 21 07:28:26.132354 2026] [security2:error] [pid 229246:tid 229453] [client 147.135.213.27:0] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.hauptmann.com.br"] [uri "/robots.txt"] [unique_id "al9JyiBMYeh5YLVG45yBTgACYSU"]
[Tue Jul 21 07:28:26.194498 2026] [security2:error] [pid 229246:tid 229428] [client 20.104.96.117:4252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/for.php"] [unique_id "al9JyiBMYeh5YLVG45yBUAAAAkg"]
[Tue Jul 21 07:28:26.242920 2026] [security2:error] [pid 229246:tid 229400] [client 20.197.195.24:12407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/file6.php"] [unique_id "al9JyiBMYeh5YLVG45yBUQAAAiw"]
[Tue Jul 21 07:28:26.392100 2026] [security2:error] [pid 229246:tid 229503] [client 45.8.17.132:37681] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/tinymce/themes/about.php"] [unique_id "al9JyiBMYeh5YLVG45yBUgAAApM"]
[Tue Jul 21 07:28:26.410487 2026] [autoindex:error] [pid 230252:tid 230509] [client 20.197.195.24:12325] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:26.525341 2026] [security2:error] [pid 230252:tid 230507] [client 20.197.195.24:12325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/adminfuns.php"] [unique_id "al9Jyk0Dwhk5-Z44XrpckwAAAxQ"]
[Tue Jul 21 07:28:26.559091 2026] [security2:error] [pid 230252:tid 230439] [client 20.104.96.117:64045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/raw.php"] [unique_id "al9Jyk0Dwhk5-Z44XrpclAAAAtA"]
[Tue Jul 21 07:28:26.578527 2026] [security2:error] [pid 230252:tid 230389] [client 20.52.136.55:1735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/ws38.php"] [unique_id "al9Jyk0Dwhk5-Z44XrpclQAAAp4"]
[Tue Jul 21 07:28:26.763350 2026] [security2:error] [pid 230252:tid 230500] [client 20.104.96.117:59836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9Jyk0Dwhk5-Z44XrpcnAAAAw0"]
[Tue Jul 21 07:28:26.843127 2026] [security2:error] [pid 229246:tid 229495] [client 20.197.195.24:12415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/goods.php"] [unique_id "al9JyiBMYeh5YLVG45yBWgAAAos"]
[Tue Jul 21 07:28:26.880892 2026] [security2:error] [pid 229246:tid 229251] [remote 8.217.108.67:30818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cdatecnologia.com.br"] [uri "/wp-login.php"] [unique_id "al9JyiBMYeh5YLVG45yBWwACMgQ"]
[Tue Jul 21 07:28:27.062132 2026] [security2:error] [pid 229246:tid 229379] [client 20.197.195.24:12359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/100.php"] [unique_id "al9JyyBMYeh5YLVG45yBXAAAAhc"]
[Tue Jul 21 07:28:27.219594 2026] [security2:error] [pid 229246:tid 229468] [client 20.197.195.24:12414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/about.php"] [unique_id "al9JyyBMYeh5YLVG45yBXwAAAnA"]
[Tue Jul 21 07:28:27.280176 2026] [security2:error] [pid 229246:tid 229395] [client 20.220.225.223:8913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/old.php"] [unique_id "al9JyyBMYeh5YLVG45yBYgAAAic"]
[Tue Jul 21 07:28:27.306982 2026] [security2:error] [pid 229246:tid 229255] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JyyBMYeh5YLVG45yBYwACGwg"]
[Tue Jul 21 07:28:27.307175 2026] [security2:error] [pid 229246:tid 229383] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JyyBMYeh5YLVG45yBYwACGwg"]
[Tue Jul 21 07:28:27.404300 2026] [proxy:error] [pid 229246:tid 229467] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:27.404379 2026] [proxy_http:error] [pid 229246:tid 229467] [client 20.151.10.161:49100] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:27.404834 2026] [proxy:error] [pid 229246:tid 229467] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:27.404866 2026] [proxy_http:error] [pid 229246:tid 229467] [client 20.151.10.161:49100] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:27.686078 2026] [security2:error] [pid 230252:tid 230503] [client 45.8.17.62:25845] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/ssss/src.php"] [unique_id "al9Jy00Dwhk5-Z44XrpcowAAAxA"]
[Tue Jul 21 07:28:27.702586 2026] [security2:error] [pid 229246:tid 229436] [client 20.197.195.24:12397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/about.php"] [unique_id "al9JyyBMYeh5YLVG45yBZwAAAlA"]
[Tue Jul 21 07:28:28.169846 2026] [security2:error] [pid 230252:tid 230401] [client 20.197.195.24:12316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/admin.php"] [unique_id "al9JzE0Dwhk5-Z44XrpcqQAAAqo"]
[Tue Jul 21 07:28:28.317518 2026] [security2:error] [pid 230252:tid 230466] [client 172.245.102.45:55259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JzE0Dwhk5-Z44XrpcqAAAAus"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:28.510218 2026] [security2:error] [pid 230252:tid 230430] [client 20.197.195.24:20589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/admin.php"] [unique_id "al9JzE0Dwhk5-Z44XrpcrAAAAsc"]
[Tue Jul 21 07:28:28.542593 2026] [proxy:error] [pid 230252:tid 230502] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:28.542666 2026] [proxy_http:error] [pid 230252:tid 230502] [client 20.151.10.161:49090] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:28.543278 2026] [proxy:error] [pid 230252:tid 230502] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:28.543305 2026] [proxy_http:error] [pid 230252:tid 230502] [client 20.151.10.161:49090] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:28.631956 2026] [security2:error] [pid 229246:tid 229497] [client 103.106.20.201:54262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JzCBMYeh5YLVG45yBdAAAAo0"]
[Tue Jul 21 07:28:28.632133 2026] [security2:error] [pid 229246:tid 229497] [client 103.106.20.201:54262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JzCBMYeh5YLVG45yBdAAAAo0"]
[Tue Jul 21 07:28:28.692255 2026] [security2:error] [pid 230252:tid 230399] [client 59.96.220.140:50517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JzE0Dwhk5-Z44XrpcrwAAAqg"]
[Tue Jul 21 07:28:28.692404 2026] [security2:error] [pid 230252:tid 230399] [client 59.96.220.140:50517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JzE0Dwhk5-Z44XrpcrwAAAqg"]
[Tue Jul 21 07:28:29.177991 2026] [security2:error] [pid 230252:tid 230295] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JzU0Dwhk5-Z44XrpcuQAC7ik"]
[Tue Jul 21 07:28:29.178182 2026] [security2:error] [pid 230252:tid 230469] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JzU0Dwhk5-Z44XrpcuQAC7ik"]
[Tue Jul 21 07:28:29.290208 2026] [security2:error] [pid 230252:tid 230303] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JzU0Dwhk5-Z44XrpcvQACyDE"]
[Tue Jul 21 07:28:29.290395 2026] [security2:error] [pid 230252:tid 230431] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JzU0Dwhk5-Z44XrpcvQACyDE"]
[Tue Jul 21 07:28:29.304449 2026] [proxy:error] [pid 230252:tid 230387] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:29.304513 2026] [proxy_http:error] [pid 230252:tid 230387] [client 20.151.10.161:49104] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:29.305181 2026] [proxy:error] [pid 230252:tid 230387] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:29.305211 2026] [proxy_http:error] [pid 230252:tid 230387] [client 20.151.10.161:49104] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:29.317885 2026] [security2:error] [pid 229246:tid 229431] [client 82.102.28.107:39130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9JzSBMYeh5YLVG45yBewAAAks"]
[Tue Jul 21 07:28:29.318000 2026] [security2:error] [pid 229246:tid 229431] [client 82.102.28.107:39130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9JzSBMYeh5YLVG45yBewAAAks"]
[Tue Jul 21 07:28:29.732090 2026] [security2:error] [pid 229246:tid 229478] [client 20.104.96.117:59611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9JzSBMYeh5YLVG45yBfQAAAno"]
[Tue Jul 21 07:28:29.766620 2026] [security2:error] [pid 229246:tid 229416] [client 20.220.225.223:38657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/hunter.php"] [unique_id "al9JzSBMYeh5YLVG45yBfwAAAjw"]
[Tue Jul 21 07:28:29.785388 2026] [security2:error] [pid 230252:tid 230287] [remote 2a01:239:4db:9500::1:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "expertemrecheios.com"] [uri "/wp-login.php"] [unique_id "al9JzU0Dwhk5-Z44XrpcyAAC2CE"]
[Tue Jul 21 07:28:29.861048 2026] [security2:error] [pid 230252:tid 230461] [client 103.174.34.15:50104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JzU0Dwhk5-Z44XrpcygAAAuY"]
[Tue Jul 21 07:28:29.861165 2026] [security2:error] [pid 230252:tid 230461] [client 103.174.34.15:50104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JzU0Dwhk5-Z44XrpcygAAAuY"]
[Tue Jul 21 07:28:29.958870 2026] [security2:error] [pid 230252:tid 230438] [client 20.197.195.24:12403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/themes.php"] [unique_id "al9JzU0Dwhk5-Z44XrpcywAAAs8"]
[Tue Jul 21 07:28:30.038608 2026] [security2:error] [pid 229246:tid 229253] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JziBMYeh5YLVG45yBhgACfAY"]
[Tue Jul 21 07:28:30.038782 2026] [security2:error] [pid 229246:tid 229480] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JziBMYeh5YLVG45yBhgACfAY"]
[Tue Jul 21 07:28:30.202737 2026] [security2:error] [pid 230252:tid 230429] [client 154.192.233.199:59535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jzk0Dwhk5-Z44XrpczwAAAsY"]
[Tue Jul 21 07:28:30.202861 2026] [security2:error] [pid 230252:tid 230429] [client 154.192.233.199:59535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jzk0Dwhk5-Z44XrpczwAAAsY"]
[Tue Jul 21 07:28:30.220392 2026] [security2:error] [pid 229246:tid 229461] [client 175.45.70.82:57236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JziBMYeh5YLVG45yBiAAAAmk"]
[Tue Jul 21 07:28:30.220501 2026] [security2:error] [pid 229246:tid 229461] [client 175.45.70.82:57236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JziBMYeh5YLVG45yBiAAAAmk"]
[Tue Jul 21 07:28:30.511720 2026] [security2:error] [pid 230252:tid 230502] [client 20.104.96.117:59819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/jj.php"] [unique_id "al9Jzk0Dwhk5-Z44Xrpc0gAAAw8"]
[Tue Jul 21 07:28:30.766268 2026] [security2:error] [pid 230252:tid 230330] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jzk0Dwhk5-Z44Xrpc1gADB0s"]
[Tue Jul 21 07:28:30.766436 2026] [security2:error] [pid 230252:tid 230494] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jzk0Dwhk5-Z44Xrpc1gADB0s"]
[Tue Jul 21 07:28:30.871352 2026] [security2:error] [pid 229246:tid 229427] [client 20.220.225.223:62866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/ms-new.php"] [unique_id "al9JziBMYeh5YLVG45yBjQAAAkc"]
[Tue Jul 21 07:28:31.089655 2026] [security2:error] [pid 229246:tid 229303] [remote 20.118.34.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.34.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wso112233.php"] [unique_id "al9JzSBMYeh5YLVG45yBhAACiDg"]
[Tue Jul 21 07:28:31.132699 2026] [autoindex:error] [pid 229246:tid 229415] [client 20.197.195.24:12314] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:31.264564 2026] [security2:error] [pid 230252:tid 230397] [client 103.162.129.114:65260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Jz00Dwhk5-Z44Xrpc2QAAAqY"]
[Tue Jul 21 07:28:31.264692 2026] [security2:error] [pid 230252:tid 230397] [client 103.162.129.114:65260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Jz00Dwhk5-Z44Xrpc2QAAAqY"]
[Tue Jul 21 07:28:31.803390 2026] [security2:error] [pid 230252:tid 230467] [client 20.151.10.161:49096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9Jz00Dwhk5-Z44Xrpc4AAAAuw"]
[Tue Jul 21 07:28:32.023853 2026] [security2:error] [pid 230252:tid 230480] [client 20.104.96.117:59808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9J0E0Dwhk5-Z44Xrpc4gAAAvk"]
[Tue Jul 21 07:28:32.183132 2026] [security2:error] [pid 229246:tid 229406] [client 20.197.195.24:12314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/.well-known/about.php"] [unique_id "al9J0CBMYeh5YLVG45yBnQAAAjI"]
[Tue Jul 21 07:28:32.940332 2026] [security2:error] [pid 229246:tid 229466] [client 20.104.96.117:59605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/txets.php"] [unique_id "al9J0CBMYeh5YLVG45yBpAAAAm4"]
[Tue Jul 21 07:28:33.044851 2026] [security2:error] [pid 230252:tid 230262] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J0U0Dwhk5-Z44Xrpc_wAC2gg"]
[Tue Jul 21 07:28:33.045040 2026] [security2:error] [pid 230252:tid 230449] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J0U0Dwhk5-Z44Xrpc_wAC2gg"]
[Tue Jul 21 07:28:33.194486 2026] [security2:error] [pid 230252:tid 230323] [remote 20.75.217.64:9902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/wp-login.php"] [unique_id "al9J0U0Dwhk5-Z44XrpdAgAC3kU"]
[Tue Jul 21 07:28:33.356121 2026] [security2:error] [pid 230252:tid 230463] [client 172.245.102.45:34699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9J0U0Dwhk5-Z44XrpdBgAAAug"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:34.083484 2026] [security2:error] [pid 229246:tid 229483] [client 45.8.17.58:51455] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/files/"] [unique_id "al9J0iBMYeh5YLVG45yBvQAAAn8"]
[Tue Jul 21 07:28:34.380211 2026] [security2:error] [pid 229246:tid 229397] [client 20.151.10.161:49150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/gettest.php"] [unique_id "al9J0iBMYeh5YLVG45yBxQAAAik"]
[Tue Jul 21 07:28:34.566008 2026] [security2:error] [pid 229246:tid 229382] [client 20.104.96.117:59826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/dex.php"] [unique_id "al9J0iBMYeh5YLVG45yBywAAAho"]
[Tue Jul 21 07:28:34.697241 2026] [security2:error] [pid 230252:tid 230483] [client 20.197.195.24:12294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9J0k0Dwhk5-Z44XrpdFgAAAvw"]
[Tue Jul 21 07:28:34.805223 2026] [security2:error] [pid 230252:tid 230396] [client 105.127.11.139:42611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.11.127.105.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9J0k0Dwhk5-Z44XrpdFQAAAqU"]
[Tue Jul 21 07:28:34.805389 2026] [security2:error] [pid 230252:tid 230396] [client 105.127.11.139:42611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9J0k0Dwhk5-Z44XrpdFQAAAqU"]
[Tue Jul 21 07:28:34.888465 2026] [security2:error] [pid 229246:tid 229487] [client 45.8.17.122:64371] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/themes.php"] [unique_id "al9J0iBMYeh5YLVG45yBzwAAAoM"]
[Tue Jul 21 07:28:35.790887 2026] [security2:error] [pid 229246:tid 229411] [client 45.8.17.139:22839] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/ahax.php"] [unique_id "al9J0yBMYeh5YLVG45yB2QAAAjc"]
[Tue Jul 21 07:28:35.825800 2026] [security2:error] [pid 230252:tid 230438] [client 45.251.232.145:54283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J000Dwhk5-Z44XrpdHwAAAs8"]
[Tue Jul 21 07:28:35.825932 2026] [security2:error] [pid 230252:tid 230438] [client 45.251.232.145:54283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J000Dwhk5-Z44XrpdHwAAAs8"]
[Tue Jul 21 07:28:36.016424 2026] [security2:error] [pid 230252:tid 230451] [client 139.135.44.145:53749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J1E0Dwhk5-Z44XrpdIQAAAtw"]
[Tue Jul 21 07:28:36.016654 2026] [security2:error] [pid 230252:tid 230451] [client 139.135.44.145:53749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J1E0Dwhk5-Z44XrpdIQAAAtw"]
[Tue Jul 21 07:28:36.358669 2026] [security2:error] [pid 230252:tid 230305] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9J1E0Dwhk5-Z44XrpdJwADETM"]
[Tue Jul 21 07:28:36.358842 2026] [security2:error] [pid 230252:tid 230504] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9J1E0Dwhk5-Z44XrpdJwADETM"]
[Tue Jul 21 07:28:36.411054 2026] [security2:error] [pid 229246:tid 229385] [client 117.251.86.144:38572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9J1CBMYeh5YLVG45yB5QAAAh0"]
[Tue Jul 21 07:28:36.411175 2026] [security2:error] [pid 229246:tid 229385] [client 117.251.86.144:38572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9J1CBMYeh5YLVG45yB5QAAAh0"]
[Tue Jul 21 07:28:36.520590 2026] [security2:error] [pid 229246:tid 229400] [client 20.10.88.227:2241] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gnxinox.com.br"] [uri "/index.php"] [unique_id "al9J1CBMYeh5YLVG45yB5gAAAiw"]
[Tue Jul 21 07:28:37.009457 2026] [security2:error] [pid 230252:tid 230490] [client 152.59.154.239:32606] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J1U0Dwhk5-Z44XrpdMgAAAwM"]
[Tue Jul 21 07:28:37.011229 2026] [security2:error] [pid 230252:tid 230490] [client 152.59.154.239:32606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J1U0Dwhk5-Z44XrpdMgAAAwM"]
[Tue Jul 21 07:28:37.079496 2026] [security2:error] [pid 230252:tid 230454] [client 45.8.17.115:43119] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/images/"] [unique_id "al9J1U0Dwhk5-Z44XrpdMwAAAt8"]
[Tue Jul 21 07:28:37.341455 2026] [security2:error] [pid 230252:tid 230502] [client 193.36.225.72:22439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9J1U0Dwhk5-Z44XrpdNgAAAw8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:37.451363 2026] [security2:error] [pid 229246:tid 229457] [client 20.52.136.55:1732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/a7.php"] [unique_id "al9J1SBMYeh5YLVG45yB9AAAAmU"]
[Tue Jul 21 07:28:37.776859 2026] [security2:error] [pid 229246:tid 229459] [client 20.220.225.223:31169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/we.php"] [unique_id "al9J1SBMYeh5YLVG45yB-QAAAmc"]
[Tue Jul 21 07:28:37.782643 2026] [proxy:error] [pid 229246:tid 229466] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:37.782699 2026] [proxy_http:error] [pid 229246:tid 229466] [client 20.151.10.161:49128] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:37.783301 2026] [proxy:error] [pid 229246:tid 229466] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:37.783328 2026] [proxy_http:error] [pid 229246:tid 229466] [client 20.151.10.161:49128] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:37.861475 2026] [security2:error] [pid 229246:tid 229336] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9J1SBMYeh5YLVG45yB_wACdVk"]
[Tue Jul 21 07:28:37.861603 2026] [security2:error] [pid 229246:tid 229473] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9J1SBMYeh5YLVG45yB_wACdVk"]
[Tue Jul 21 07:28:37.914678 2026] [security2:error] [pid 229246:tid 229436] [client 20.104.96.117:59597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/xpwer1.php"] [unique_id "al9J1SBMYeh5YLVG45yCAAAAAlA"]
[Tue Jul 21 07:28:37.980829 2026] [security2:error] [pid 229246:tid 229481] [client 20.220.225.223:62114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/track.php"] [unique_id "al9J1SBMYeh5YLVG45yCAQAAAn0"]
[Tue Jul 21 07:28:38.234100 2026] [security2:error] [pid 229246:tid 229288] [remote 13.41.15.21:59338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.15.41.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9J1iBMYeh5YLVG45yCAgACLyk"]
[Tue Jul 21 07:28:38.349563 2026] [security2:error] [pid 230252:tid 230461] [client 20.197.195.24:12372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/wefile.php"] [unique_id "al9J1k0Dwhk5-Z44XrpdOgAAAuY"]
[Tue Jul 21 07:28:38.438906 2026] [security2:error] [pid 230252:tid 230398] [client 20.52.136.55:1737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/classsmtps.php"] [unique_id "al9J1k0Dwhk5-Z44XrpdPAAAAqc"]
[Tue Jul 21 07:28:38.546842 2026] [security2:error] [pid 230252:tid 230420] [client 20.10.88.227:1856] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tryhealthonline.shop"] [uri "/robots.txt"] [unique_id "al9J1k0Dwhk5-Z44XrpdPwAAAr0"]
[Tue Jul 21 07:28:38.981329 2026] [security2:error] [pid 230252:tid 230474] [client 45.8.17.73:31329] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/preformatted/"] [unique_id "al9J1k0Dwhk5-Z44XrpdRwAAAvM"]
[Tue Jul 21 07:28:39.072162 2026] [security2:error] [pid 230252:tid 230506] [client 20.52.136.55:1548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/rip.php"] [unique_id "al9J100Dwhk5-Z44XrpdSAAAAxM"]
[Tue Jul 21 07:28:39.085236 2026] [core:alert] [pid 230252:tid 230449] [client 57.141.18.27:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:28:39.313898 2026] [security2:error] [pid 229246:tid 229280] [remote 104.207.58.230:58873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9J1iBMYeh5YLVG45yCBAACiSE"]
[Tue Jul 21 07:28:39.338790 2026] [security2:error] [pid 230252:tid 230393] [client 103.106.20.201:54848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J100Dwhk5-Z44XrpdTgAAAqI"]
[Tue Jul 21 07:28:39.338954 2026] [security2:error] [pid 230252:tid 230393] [client 103.106.20.201:54848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J100Dwhk5-Z44XrpdTgAAAqI"]
[Tue Jul 21 07:28:39.452738 2026] [security2:error] [pid 230252:tid 230422] [client 20.197.195.24:12383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9J100Dwhk5-Z44XrpdTwAAAr8"]
[Tue Jul 21 07:28:39.794117 2026] [security2:error] [pid 230252:tid 230415] [client 45.8.17.103:34673] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/colors/coffee/"] [unique_id "al9J100Dwhk5-Z44XrpdVAAAArg"]
[Tue Jul 21 07:28:39.961419 2026] [security2:error] [pid 230252:tid 230344] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9J100Dwhk5-Z44XrpdVQAC7lk"]
[Tue Jul 21 07:28:39.961596 2026] [security2:error] [pid 230252:tid 230469] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9J100Dwhk5-Z44XrpdVQAC7lk"]
[Tue Jul 21 07:28:39.985739 2026] [security2:error] [pid 230252:tid 230379] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9J100Dwhk5-Z44XrpdVgACuXw"]
[Tue Jul 21 07:28:39.985894 2026] [security2:error] [pid 230252:tid 230416] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9J100Dwhk5-Z44XrpdVgACuXw"]
[Tue Jul 21 07:28:40.076660 2026] [security2:error] [pid 230252:tid 230509] [client 20.151.10.161:49029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/simple.php"] [unique_id "al9J2E0Dwhk5-Z44XrpdVwAAAxY"]
[Tue Jul 21 07:28:40.442270 2026] [security2:error] [pid 230252:tid 230490] [client 103.174.34.15:50631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J2E0Dwhk5-Z44XrpdXgAAAwM"]
[Tue Jul 21 07:28:40.442398 2026] [security2:error] [pid 230252:tid 230490] [client 103.174.34.15:50631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J2E0Dwhk5-Z44XrpdXgAAAwM"]
[Tue Jul 21 07:28:40.517288 2026] [autoindex:error] [pid 229246:tid 229501] [client 20.197.195.24:12324] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:40.577026 2026] [security2:error] [pid 230252:tid 230316] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9J2E0Dwhk5-Z44XrpdYAADCT4"]
[Tue Jul 21 07:28:40.577212 2026] [security2:error] [pid 230252:tid 230496] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9J2E0Dwhk5-Z44XrpdYAADCT4"]
[Tue Jul 21 07:28:40.777646 2026] [security2:error] [pid 230252:tid 230404] [client 59.96.220.140:50990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9J2E0Dwhk5-Z44XrpdZAAAAq0"]
[Tue Jul 21 07:28:40.777760 2026] [security2:error] [pid 230252:tid 230404] [client 59.96.220.140:50990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9J2E0Dwhk5-Z44XrpdZAAAAq0"]
[Tue Jul 21 07:28:40.852609 2026] [autoindex:error] [pid 229246:tid 229477] [client 20.197.195.24:12324] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:40.858331 2026] [security2:error] [pid 229246:tid 229427] [client 20.197.195.24:12324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9J2CBMYeh5YLVG45yCIgAAAkc"]
[Tue Jul 21 07:28:40.866466 2026] [security2:error] [pid 229246:tid 229461] [client 154.192.233.199:58664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J2CBMYeh5YLVG45yCIwAAAmk"]
[Tue Jul 21 07:28:40.866562 2026] [security2:error] [pid 229246:tid 229461] [client 154.192.233.199:58664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J2CBMYeh5YLVG45yCIwAAAmk"]
[Tue Jul 21 07:28:40.883542 2026] [security2:error] [pid 230252:tid 230425] [client 45.8.17.113:37049] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/customize/"] [unique_id "al9J2E0Dwhk5-Z44XrpdZwAAAsI"]
[Tue Jul 21 07:28:40.930843 2026] [security2:error] [pid 230252:tid 230479] [client 175.45.70.82:57763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J2E0Dwhk5-Z44XrpdaAAAAvg"]
[Tue Jul 21 07:28:40.931022 2026] [security2:error] [pid 230252:tid 230479] [client 175.45.70.82:57763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J2E0Dwhk5-Z44XrpdaAAAAvg"]
[Tue Jul 21 07:28:41.288157 2026] [security2:error] [pid 229246:tid 229298] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J2SBMYeh5YLVG45yCMAACajM"]
[Tue Jul 21 07:28:41.288375 2026] [security2:error] [pid 229246:tid 229462] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J2SBMYeh5YLVG45yCMAACajM"]
[Tue Jul 21 07:28:41.475603 2026] [security2:error] [pid 230252:tid 230474] [client 20.52.136.55:1503] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.gradiente.com"] [uri "/1.php"] [unique_id "al9J2U0Dwhk5-Z44XrpdbgAAAvM"]
[Tue Jul 21 07:28:41.475730 2026] [security2:error] [pid 230252:tid 230474] [client 20.52.136.55:1503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/1.php"] [unique_id "al9J2U0Dwhk5-Z44XrpdbgAAAvM"]
[Tue Jul 21 07:28:41.511528 2026] [security2:error] [pid 230252:tid 230449] [client 20.104.96.117:59776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/flox.php"] [unique_id "al9J2U0Dwhk5-Z44XrpdbwAAAto"]
[Tue Jul 21 07:28:41.533685 2026] [security2:error] [pid 230252:tid 230453] [client 20.104.96.117:62445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9J2U0Dwhk5-Z44XrpdcAAAAt4"]
[Tue Jul 21 07:28:41.549783 2026] [security2:error] [pid 230252:tid 230441] [client 62.102.148.164:47356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9J2U0Dwhk5-Z44XrpdcQAAAtI"]
[Tue Jul 21 07:28:41.549879 2026] [security2:error] [pid 230252:tid 230441] [client 62.102.148.164:47356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9J2U0Dwhk5-Z44XrpdcQAAAtI"]
[Tue Jul 21 07:28:41.690021 2026] [security2:error] [pid 230252:tid 230385] [client 45.8.17.141:29223] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/classwithtostring.php"] [unique_id "al9J2U0Dwhk5-Z44XrpdcgAAApo"]
[Tue Jul 21 07:28:41.736426 2026] [security2:error] [pid 230252:tid 230499] [client 103.162.129.114:49322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9J2U0Dwhk5-Z44XrpddQAAAww"]
[Tue Jul 21 07:28:41.736546 2026] [security2:error] [pid 230252:tid 230499] [client 103.162.129.114:49322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9J2U0Dwhk5-Z44XrpddQAAAww"]
[Tue Jul 21 07:28:41.810339 2026] [security2:error] [pid 230252:tid 230472] [client 20.104.96.117:62857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9J2U0Dwhk5-Z44XrpdegAAAvE"]
[Tue Jul 21 07:28:41.975750 2026] [security2:error] [pid 230252:tid 230471] [client 213.152.162.104:56846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9J2U0Dwhk5-Z44XrpdfgAAAvA"]
[Tue Jul 21 07:28:41.975865 2026] [security2:error] [pid 230252:tid 230471] [client 213.152.162.104:56846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9J2U0Dwhk5-Z44XrpdfgAAAvA"]
[Tue Jul 21 07:28:41.984667 2026] [security2:error] [pid 229246:tid 229383] [client 20.220.225.223:31204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/phpinfo.php1"] [unique_id "al9J2SBMYeh5YLVG45yCQwAAAhs"]
[Tue Jul 21 07:28:42.092221 2026] [security2:error] [pid 230252:tid 230443] [client 20.104.96.117:62908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/media.php"] [unique_id "al9J2k0Dwhk5-Z44XrpdgQAAAtQ"]
[Tue Jul 21 07:28:42.153882 2026] [security2:error] [pid 230252:tid 230454] [client 172.245.102.46:26313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9J2E0Dwhk5-Z44XrpdaQAAAt8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:42.348746 2026] [security2:error] [pid 229246:tid 229412] [client 20.197.195.24:12408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/8.php"] [unique_id "al9J2iBMYeh5YLVG45yCRQAAAjg"]
[Tue Jul 21 07:28:42.375528 2026] [security2:error] [pid 230252:tid 230448] [client 20.104.96.117:62418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/images.php"] [unique_id "al9J2k0Dwhk5-Z44XrpdggAAAtk"]
[Tue Jul 21 07:28:42.662210 2026] [security2:error] [pid 230252:tid 230401] [client 20.104.96.117:62875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/gecko.php"] [unique_id "al9J2k0Dwhk5-Z44XrpdiAAAAqo"]
[Tue Jul 21 07:28:42.689056 2026] [security2:error] [pid 230252:tid 230481] [client 74.7.175.130:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "solarisimplementos.com"] [uri "/index.php"] [unique_id "al9J2U0Dwhk5-Z44XrpdewAAAvo"]
[Tue Jul 21 07:28:42.689863 2026] [security2:error] [pid 230252:tid 230504] [client 74.7.175.130:56058] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "solarisimplementos.com"] [uri "/robots.txt"] [unique_id "al9J2U0Dwhk5-Z44XrpddgADEUI"]
[Tue Jul 21 07:28:42.761173 2026] [security2:error] [pid 230252:tid 230309] [remote 40.77.167.123:5125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/produtos-mercado.php"] [unique_id "al9J2k0Dwhk5-Z44XrpdiQAC9zc"]
[Tue Jul 21 07:28:42.943638 2026] [security2:error] [pid 230252:tid 230399] [client 20.104.96.117:62435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/82.php"] [unique_id "al9J2k0Dwhk5-Z44XrpdjQAAAqg"]
[Tue Jul 21 07:28:43.258238 2026] [security2:error] [pid 230252:tid 230449] [client 20.104.96.117:62862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/admin.php"] [unique_id "al9J200Dwhk5-Z44XrpdjwAAAto"]
[Tue Jul 21 07:28:43.479481 2026] [security2:error] [pid 230252:tid 230393] [client 20.220.225.223:8934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/2352356666.php"] [unique_id "al9J200Dwhk5-Z44XrpdlgAAAqI"]
[Tue Jul 21 07:28:43.488581 2026] [security2:error] [pid 229246:tid 229378] [client 20.197.195.24:12307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9J2yBMYeh5YLVG45yCWQAAAhY"]
[Tue Jul 21 07:28:43.503073 2026] [security2:error] [pid 229246:tid 229444] [client 20.151.10.161:48603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/xxx.php"] [unique_id "al9J2yBMYeh5YLVG45yCWgAAAlg"]
[Tue Jul 21 07:28:43.563847 2026] [security2:error] [pid 230252:tid 230472] [client 20.104.96.117:62417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/adminner.php"] [unique_id "al9J200Dwhk5-Z44XrpdmQAAAvE"]
[Tue Jul 21 07:28:43.586660 2026] [security2:error] [pid 229246:tid 229487] [client 45.8.17.110:24301] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/gallery/"] [unique_id "al9J2yBMYeh5YLVG45yCbgAAAoM"]
[Tue Jul 21 07:28:43.625090 2026] [security2:error] [pid 230252:tid 230335] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J200Dwhk5-Z44XrpdmgACmVA"]
[Tue Jul 21 07:28:43.625239 2026] [security2:error] [pid 230252:tid 230384] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J200Dwhk5-Z44XrpdmgACmVA"]
[Tue Jul 21 07:28:44.073051 2026] [security2:error] [pid 230252:tid 230509] [client 20.104.96.117:62902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/admin.php"] [unique_id "al9J3E0Dwhk5-Z44XrpdnwAAAxY"]
[Tue Jul 21 07:28:44.393040 2026] [security2:error] [pid 230252:tid 230470] [client 20.104.96.117:6293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/k.php"] [unique_id "al9J3E0Dwhk5-Z44XrpdqwAAAu8"]
[Tue Jul 21 07:28:44.442562 2026] [security2:error] [pid 229246:tid 229420] [client 20.104.96.117:59816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/popo.php"] [unique_id "al9J3CBMYeh5YLVG45yCfQAAAkA"]
[Tue Jul 21 07:28:44.469343 2026] [security2:error] [pid 230252:tid 230452] [client 20.197.195.24:12323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/f6.php"] [unique_id "al9J3E0Dwhk5-Z44XrpdrgAAAt0"]
[Tue Jul 21 07:28:44.520829 2026] [security2:error] [pid 229246:tid 229501] [client 20.151.10.161:49120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/hypo.php"] [unique_id "al9J3CBMYeh5YLVG45yCfwAAApE"]
[Tue Jul 21 07:28:44.737836 2026] [security2:error] [pid 230252:tid 230504] [client 20.104.96.117:62852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/blurbs.php"] [unique_id "al9J3E0Dwhk5-Z44XrpdswAAAxE"]
[Tue Jul 21 07:28:44.821477 2026] [security2:error] [pid 230252:tid 230424] [client 20.220.225.223:8948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/pn.php"] [unique_id "al9J3E0Dwhk5-Z44XrpdtAAAAsE"]
[Tue Jul 21 07:28:44.851560 2026] [security2:error] [pid 230252:tid 230429] [client 20.197.195.24:12357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/inputs.php"] [unique_id "al9J3E0Dwhk5-Z44XrpdtQAAAsY"]
[Tue Jul 21 07:28:45.034205 2026] [security2:error] [pid 230252:tid 230400] [client 20.104.96.117:62901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/bajah.php"] [unique_id "al9J3U0Dwhk5-Z44XrpduAAAAqk"]
[Tue Jul 21 07:28:45.074558 2026] [security2:error] [pid 230252:tid 230463] [client 20.52.136.55:1740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/chosen.php"] [unique_id "al9J3U0Dwhk5-Z44XrpduQAAAug"]
[Tue Jul 21 07:28:45.114631 2026] [security2:error] [pid 230252:tid 230486] [client 20.197.195.24:12410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/inputs.php"] [unique_id "al9J3U0Dwhk5-Z44XrpduwAAAv8"]
[Tue Jul 21 07:28:45.285333 2026] [security2:error] [pid 230252:tid 230385] [client 45.8.17.57:63385] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/js/widgets/images/"] [unique_id "al9J3U0Dwhk5-Z44XrpdvQAAApo"]
[Tue Jul 21 07:28:45.408693 2026] [security2:error] [pid 229246:tid 229492] [client 20.104.96.117:62416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/a.php"] [unique_id "al9J3SBMYeh5YLVG45yCkAAAAog"]
[Tue Jul 21 07:28:45.432576 2026] [security2:error] [pid 229246:tid 229407] [client 20.197.195.24:12289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/classwithtostring.php"] [unique_id "al9J3SBMYeh5YLVG45yCkQAAAjM"]
[Tue Jul 21 07:28:45.490355 2026] [proxy:error] [pid 230252:tid 230437] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:45.490437 2026] [proxy_http:error] [pid 230252:tid 230437] [client 20.151.10.161:49039] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:45.490775 2026] [security2:error] [pid 229246:tid 229447] [client 20.197.195.24:12318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9J3SBMYeh5YLVG45yCkwAAAls"]
[Tue Jul 21 07:28:45.491142 2026] [proxy:error] [pid 230252:tid 230437] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:45.491168 2026] [proxy_http:error] [pid 230252:tid 230437] [client 20.151.10.161:49039] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:45.613922 2026] [security2:error] [pid 229246:tid 229489] [client 20.197.195.24:12370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/wp-blog.php"] [unique_id "al9J3SBMYeh5YLVG45yClQAAAoU"]
[Tue Jul 21 07:28:45.832027 2026] [security2:error] [pid 229246:tid 229498] [client 20.10.88.227:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "solarisimplementos.com"] [uri "/index.php"] [unique_id "al9J3SBMYeh5YLVG45yCmwAAAo4"]
[Tue Jul 21 07:28:45.832906 2026] [security2:error] [pid 229246:tid 229490] [client 20.10.88.227:2244] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "solarisimplementos.com"] [uri "/robots.txt"] [unique_id "al9J3SBMYeh5YLVG45yCmQAAAoY"]
[Tue Jul 21 07:28:45.864991 2026] [autoindex:error] [pid 230252:tid 230501] [client 20.197.195.24:12306] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:45.869721 2026] [security2:error] [pid 229246:tid 229384] [client 20.104.96.117:62430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/edit.php"] [unique_id "al9J3SBMYeh5YLVG45yCnAAAAhw"]
[Tue Jul 21 07:28:45.958027 2026] [security2:error] [pid 230252:tid 230419] [client 20.197.195.24:12306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9J3U0Dwhk5-Z44XrpdxwAAArw"]
[Tue Jul 21 07:28:46.088359 2026] [security2:error] [pid 230252:tid 230422] [client 45.8.17.49:54529] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/imgareaselect/"] [unique_id "al9J3k0Dwhk5-Z44XrpdyAAAAr8"]
[Tue Jul 21 07:28:46.161261 2026] [security2:error] [pid 229246:tid 229439] [client 20.104.96.117:62905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/hosty.php"] [unique_id "al9J3iBMYeh5YLVG45yCoQAAAlM"]
[Tue Jul 21 07:28:46.197995 2026] [security2:error] [pid 230252:tid 230452] [client 20.197.195.24:12326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/ms-edit.php"] [unique_id "al9J3k0Dwhk5-Z44XrpdzQAAAt0"]
[Tue Jul 21 07:28:46.272957 2026] [security2:error] [pid 230252:tid 230401] [client 20.151.10.161:49143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/chosen.php"] [unique_id "al9J3k0Dwhk5-Z44XrpdzwAAAqo"]
[Tue Jul 21 07:28:46.300461 2026] [security2:error] [pid 229246:tid 229473] [client 45.251.232.145:54802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J3iBMYeh5YLVG45yCpAAAAnU"]
[Tue Jul 21 07:28:46.300586 2026] [security2:error] [pid 229246:tid 229473] [client 45.251.232.145:54802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J3iBMYeh5YLVG45yCpAAAAnU"]
[Tue Jul 21 07:28:46.418576 2026] [security2:error] [pid 229246:tid 229497] [client 20.220.225.223:62122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9J3iBMYeh5YLVG45yCpgAAAo0"]
[Tue Jul 21 07:28:46.521576 2026] [security2:error] [pid 229246:tid 229394] [client 20.197.195.24:12319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9J3iBMYeh5YLVG45yCqQAAAiY"]
[Tue Jul 21 07:28:46.599008 2026] [security2:error] [pid 229246:tid 229484] [client 20.104.96.117:62874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/k.php"] [unique_id "al9J3iBMYeh5YLVG45yCqwAAAoA"]
[Tue Jul 21 07:28:46.662159 2026] [security2:error] [pid 230252:tid 230468] [client 138.249.169.117:9983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.169.249.138.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-comments-post.php"] [unique_id "al9J3E0Dwhk5-Z44XrpdrwAAAu0"], referer: https://evelinemilfontadv.com/2022/04/16/hello-world/#comment-3072
[Tue Jul 21 07:28:46.662267 2026] [security2:error] [pid 230252:tid 230468] [client 138.249.169.117:9983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "evelinemilfontadv.com"] [uri "/wp-comments-post.php"] [unique_id "al9J3E0Dwhk5-Z44XrpdrwAAAu0"], referer: https://evelinemilfontadv.com/2022/04/16/hello-world/#comment-3072
[Tue Jul 21 07:28:46.761050 2026] [autoindex:error] [pid 229246:tid 229391] [client 20.197.195.24:12317] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:46.770042 2026] [security2:error] [pid 229246:tid 229395] [client 20.197.195.24:12317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9J3iBMYeh5YLVG45yCrwAAAic"]
[Tue Jul 21 07:28:46.770306 2026] [security2:error] [pid 230252:tid 230487] [client 139.135.44.145:54573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J3k0Dwhk5-Z44Xrpd1wAAAwA"]
[Tue Jul 21 07:28:46.770417 2026] [security2:error] [pid 230252:tid 230487] [client 139.135.44.145:54573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J3k0Dwhk5-Z44Xrpd1wAAAwA"]
[Tue Jul 21 07:28:46.833465 2026] [security2:error] [pid 230252:tid 230498] [client 193.36.225.58:29555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9J3k0Dwhk5-Z44Xrpd2wAAAws"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:46.884243 2026] [security2:error] [pid 229246:tid 229299] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9J3iBMYeh5YLVG45yCsQACQzQ"]
[Tue Jul 21 07:28:46.884432 2026] [security2:error] [pid 229246:tid 229423] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9J3iBMYeh5YLVG45yCsQACQzQ"]
[Tue Jul 21 07:28:46.901181 2026] [security2:error] [pid 230252:tid 230397] [client 20.104.96.117:62855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/aaa.php"] [unique_id "al9J3k0Dwhk5-Z44Xrpd3AAAAqY"]
[Tue Jul 21 07:28:46.930910 2026] [autoindex:error] [pid 229246:tid 229501] [client 20.197.195.24:12405] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:46.975353 2026] [autoindex:error] [pid 229246:tid 229461] [client 20.197.195.24:12405] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:46.982200 2026] [security2:error] [pid 230252:tid 230499] [client 45.8.17.62:38871] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "al9J3k0Dwhk5-Z44Xrpd3gAAAww"]
[Tue Jul 21 07:28:47.004415 2026] [security2:error] [pid 229246:tid 229430] [client 20.197.195.24:12405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/abcd.php"] [unique_id "al9J3yBMYeh5YLVG45yCtwAAAko"]
[Tue Jul 21 07:28:47.054823 2026] [security2:error] [pid 230252:tid 230496] [client 117.251.86.144:49588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9J300Dwhk5-Z44Xrpd4AAAAwk"]
[Tue Jul 21 07:28:47.054944 2026] [security2:error] [pid 230252:tid 230496] [client 117.251.86.144:49588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9J300Dwhk5-Z44Xrpd4AAAAwk"]
[Tue Jul 21 07:28:47.080262 2026] [proxy:error] [pid 229246:tid 229400] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:47.080338 2026] [proxy_http:error] [pid 229246:tid 229400] [client 20.151.10.161:49099] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:47.080858 2026] [proxy:error] [pid 229246:tid 229400] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:47.080881 2026] [proxy_http:error] [pid 229246:tid 229400] [client 20.151.10.161:49099] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:47.215072 2026] [security2:error] [pid 229246:tid 229425] [client 20.104.96.117:62411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/file5.php"] [unique_id "al9J3yBMYeh5YLVG45yCvgAAAkU"]
[Tue Jul 21 07:28:47.409703 2026] [security2:error] [pid 229246:tid 229457] [client 20.197.195.24:12400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/file15.php"] [unique_id "al9J3yBMYeh5YLVG45yCxwAAAmU"]
[Tue Jul 21 07:28:47.513982 2026] [security2:error] [pid 229246:tid 229502] [client 20.104.96.117:62854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/222.php"] [unique_id "al9J3yBMYeh5YLVG45yCygAAApI"]
[Tue Jul 21 07:28:47.815142 2026] [security2:error] [pid 229246:tid 229412] [client 20.104.96.117:62894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/test.php"] [unique_id "al9J3yBMYeh5YLVG45yC0AAAAjg"]
[Tue Jul 21 07:28:47.862568 2026] [security2:error] [pid 230252:tid 230419] [client 20.52.136.55:1546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/css.php"] [unique_id "al9J300Dwhk5-Z44Xrpd5AAAArw"]
[Tue Jul 21 07:28:48.096622 2026] [security2:error] [pid 229246:tid 229392] [client 45.8.17.125:42757] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/shell/"] [unique_id "al9J4CBMYeh5YLVG45yC0gAAAiQ"]
[Tue Jul 21 07:28:48.124617 2026] [security2:error] [pid 230252:tid 230470] [client 20.104.96.117:62426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/aaa.php"] [unique_id "al9J4E0Dwhk5-Z44Xrpd7QAAAu8"]
[Tue Jul 21 07:28:48.386305 2026] [security2:error] [pid 229246:tid 229350] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9J4CBMYeh5YLVG45yC1gACHGc"]
[Tue Jul 21 07:28:48.386438 2026] [security2:error] [pid 229246:tid 229384] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9J4CBMYeh5YLVG45yC1gACHGc"]
[Tue Jul 21 07:28:48.493571 2026] [security2:error] [pid 229246:tid 229402] [client 20.104.96.117:62433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/11.php"] [unique_id "al9J4CBMYeh5YLVG45yC2AAAAi4"]
[Tue Jul 21 07:28:48.535091 2026] [security2:error] [pid 230252:tid 230488] [client 20.151.10.161:49057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/als.php"] [unique_id "al9J4E0Dwhk5-Z44Xrpd_wAAAwE"]
[Tue Jul 21 07:28:48.618200 2026] [security2:error] [pid 230252:tid 230446] [client 20.104.96.117:59595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/yas.php"] [unique_id "al9J4E0Dwhk5-Z44XrpeAgAAAtc"]
[Tue Jul 21 07:28:48.711039 2026] [security2:error] [pid 230252:tid 230425] [client 20.197.195.24:20566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/jp.php"] [unique_id "al9J4E0Dwhk5-Z44XrpeAwAAAsI"]
[Tue Jul 21 07:28:48.762185 2026] [security2:error] [pid 229246:tid 229386] [client 35.196.36.160:49386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.36.196.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "protagonbh.produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9J4CBMYeh5YLVG45yC3wAAAh4"]
[Tue Jul 21 07:28:48.762288 2026] [security2:error] [pid 229246:tid 229386] [client 35.196.36.160:49386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "protagonbh.produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9J4CBMYeh5YLVG45yC3wAAAh4"]
[Tue Jul 21 07:28:48.813451 2026] [security2:error] [pid 229246:tid 229456] [client 20.104.96.117:62446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/mac.php"] [unique_id "al9J4CBMYeh5YLVG45yC5AAAAmQ"]
[Tue Jul 21 07:28:49.097452 2026] [security2:error] [pid 230252:tid 230479] [client 45.8.17.49:53349] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/mini.php"] [unique_id "al9J4U0Dwhk5-Z44XrpeBgAAAvg"]
[Tue Jul 21 07:28:49.099331 2026] [security2:error] [pid 230252:tid 230433] [client 20.104.96.117:62861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/chosen.php"] [unique_id "al9J4U0Dwhk5-Z44XrpeBwAAAso"]
[Tue Jul 21 07:28:49.190010 2026] [security2:error] [pid 230252:tid 230464] [client 20.151.10.161:49030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/pol.php"] [unique_id "al9J4U0Dwhk5-Z44XrpeDgAAAuk"]
[Tue Jul 21 07:28:49.439648 2026] [security2:error] [pid 230252:tid 230449] [client 20.197.195.24:12378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/f35.php"] [unique_id "al9J4U0Dwhk5-Z44XrpeDwAAAto"]
[Tue Jul 21 07:28:49.574492 2026] [security2:error] [pid 230252:tid 230393] [client 20.104.96.117:62415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/cream1.php"] [unique_id "al9J4U0Dwhk5-Z44XrpeFgAAAqI"]
[Tue Jul 21 07:28:49.751327 2026] [security2:error] [pid 229246:tid 229501] [client 20.151.10.161:49037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/file5.php"] [unique_id "al9J4SBMYeh5YLVG45yC8QAAApE"]
[Tue Jul 21 07:28:50.009673 2026] [security2:error] [pid 230252:tid 230474] [client 103.106.20.201:55417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J4k0Dwhk5-Z44XrpeIAAAAvM"]
[Tue Jul 21 07:28:50.009777 2026] [security2:error] [pid 230252:tid 230474] [client 103.106.20.201:55417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J4k0Dwhk5-Z44XrpeIAAAAvM"]
[Tue Jul 21 07:28:50.051255 2026] [autoindex:error] [pid 229246:tid 229398] [client 20.104.96.117:62909] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:50.091434 2026] [security2:error] [pid 230252:tid 230501] [client 45.8.17.115:48271] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/admin/function.php"] [unique_id "al9J4k0Dwhk5-Z44XrpeIQAAAw4"]
[Tue Jul 21 07:28:50.351557 2026] [access_compat:error] [pid 230252:tid 230471] [client 162.241.63.68:46212] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:28:50.361987 2026] [autoindex:error] [pid 229246:tid 229421] [client 20.104.96.117:62909] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:50.375996 2026] [security2:error] [pid 230252:tid 230448] [client 20.197.195.24:20588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/wp-load.php"] [unique_id "al9J4k0Dwhk5-Z44XrpeJgAAAtk"]
[Tue Jul 21 07:28:50.500652 2026] [security2:error] [pid 229246:tid 229485] [client 20.104.96.117:62909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/dr.php"] [unique_id "al9J4iBMYeh5YLVG45yC_gAAAoE"]
[Tue Jul 21 07:28:50.988045 2026] [security2:error] [pid 230252:tid 230464] [client 20.104.96.117:7045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/x.php"] [unique_id "al9J4k0Dwhk5-Z44XrpeNgAAAuk"]
[Tue Jul 21 07:28:51.053107 2026] [security2:error] [pid 229246:tid 229282] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9J4yBMYeh5YLVG45yDCQACkiM"]
[Tue Jul 21 07:28:51.053315 2026] [security2:error] [pid 229246:tid 229502] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9J4yBMYeh5YLVG45yDCQACkiM"]
[Tue Jul 21 07:28:51.115453 2026] [security2:error] [pid 230252:tid 230350] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeNwAC_18"]
[Tue Jul 21 07:28:51.115699 2026] [security2:error] [pid 230252:tid 230486] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeNwAC_18"]
[Tue Jul 21 07:28:51.118833 2026] [security2:error] [pid 230252:tid 230455] [client 20.151.10.161:49059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9J400Dwhk5-Z44XrpeOAAAAuA"]
[Tue Jul 21 07:28:51.166688 2026] [security2:error] [pid 229246:tid 229503] [client 103.174.34.15:51122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J4yBMYeh5YLVG45yDCgAAApM"]
[Tue Jul 21 07:28:51.166876 2026] [security2:error] [pid 229246:tid 229503] [client 103.174.34.15:51122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J4yBMYeh5YLVG45yDCgAAApM"]
[Tue Jul 21 07:28:51.185466 2026] [security2:error] [pid 230252:tid 230449] [client 213.152.162.104:59742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeOgAAAto"]
[Tue Jul 21 07:28:51.185612 2026] [security2:error] [pid 230252:tid 230449] [client 213.152.162.104:59742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeOgAAAto"]
[Tue Jul 21 07:28:51.191152 2026] [security2:error] [pid 230252:tid 230472] [client 45.8.17.136:20787] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/config.php"] [unique_id "al9J400Dwhk5-Z44XrpeOwAAAvE"]
[Tue Jul 21 07:28:51.198705 2026] [security2:error] [pid 230252:tid 230451] [client 74.7.241.144:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "luizmarceloferreirac1748361311214.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9J400Dwhk5-Z44XrpePAAC3Aw"]
[Tue Jul 21 07:28:51.229330 2026] [security2:error] [pid 230252:tid 230385] [client 141.11.107.74:60380] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.jornalbrasileiro.com.br"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "al9J400Dwhk5-Z44XrpePgAAApo"]
[Tue Jul 21 07:28:51.234220 2026] [security2:error] [pid 230252:tid 230496] [client 141.11.107.74:60384] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.jornalbrasileiro.com.br"] [uri "/___proxy_subdomain_webmail/"] [unique_id "al9J400Dwhk5-Z44XrpePwAAAwk"]
[Tue Jul 21 07:28:51.242320 2026] [security2:error] [pid 230252:tid 230402] [client 141.11.107.74:60386] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.jornalbrasileiro.com.br"] [uri "/"] [unique_id "al9J400Dwhk5-Z44XrpeQAAAAqs"]
[Tue Jul 21 07:28:51.283991 2026] [security2:error] [pid 229246:tid 229437] [client 20.197.195.24:12404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/xyn.php"] [unique_id "al9J4yBMYeh5YLVG45yDCwAAAlE"]
[Tue Jul 21 07:28:51.289559 2026] [security2:error] [pid 230252:tid 230438] [client 141.11.107.74:60419] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "autodiscover.jornalbrasileiro.com.br"] [uri "/"] [unique_id "al9J400Dwhk5-Z44XrpeQQAAAs8"]
[Tue Jul 21 07:28:51.290209 2026] [security2:error] [pid 229246:tid 229436] [client 141.11.107.74:60420] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jornalbrasileiro.com.br"] [uri "/"] [unique_id "al9J4yBMYeh5YLVG45yDDAAAAlA"]
[Tue Jul 21 07:28:51.337228 2026] [security2:error] [pid 230252:tid 230341] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeQwACplY"]
[Tue Jul 21 07:28:51.337417 2026] [security2:error] [pid 230252:tid 230397] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeQwACplY"]
[Tue Jul 21 07:28:51.419670 2026] [security2:error] [pid 230252:tid 230399] [client 59.96.220.140:51449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeRQAAAqg"]
[Tue Jul 21 07:28:51.420374 2026] [security2:error] [pid 230252:tid 230399] [client 59.96.220.140:51449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeRQAAAqg"]
[Tue Jul 21 07:28:51.428286 2026] [security2:error] [pid 230252:tid 230508] [client 20.104.96.117:62438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/155.php"] [unique_id "al9J400Dwhk5-Z44XrpeRgAAAxU"]
[Tue Jul 21 07:28:51.439184 2026] [security2:error] [pid 230252:tid 230471] [client 141.11.107.74:60528] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcontacts.jornalbrasileiro.com.br"] [uri "/___proxy_subdomain_cpcontacts/"] [unique_id "al9J400Dwhk5-Z44XrpeRwAAAvA"]
[Tue Jul 21 07:28:51.482706 2026] [security2:error] [pid 230252:tid 230461] [client 141.11.107.74:60546] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.jornalbrasileiro.com.br"] [uri "/___proxy_subdomain_webdisk/"] [unique_id "al9J400Dwhk5-Z44XrpeTQAAAuY"]
[Tue Jul 21 07:28:51.558323 2026] [security2:error] [pid 229246:tid 229470] [client 154.192.233.199:60532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J4yBMYeh5YLVG45yDEAAAAnI"]
[Tue Jul 21 07:28:51.558708 2026] [security2:error] [pid 229246:tid 229470] [client 154.192.233.199:60532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J4yBMYeh5YLVG45yDEAAAAnI"]
[Tue Jul 21 07:28:51.648196 2026] [security2:error] [pid 230252:tid 230422] [client 74.7.241.157:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.agencia.aede.com.br"] [uri "/index.php"] [unique_id "al9J400Dwhk5-Z44XrpeSwAAAr8"]
[Tue Jul 21 07:28:51.648832 2026] [security2:error] [pid 230252:tid 230386] [client 74.7.241.157:44802] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.agencia.aede.com.br"] [uri "/robots.txt"] [unique_id "al9J400Dwhk5-Z44XrpeSAACm2Y"]
[Tue Jul 21 07:28:51.662010 2026] [security2:error] [pid 230252:tid 230442] [client 136.144.33.97:38803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9J400Dwhk5-Z44XrpeTgAAAtM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:51.766551 2026] [security2:error] [pid 230252:tid 230401] [client 20.52.136.55:1587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/php.php"] [unique_id "al9J400Dwhk5-Z44XrpeUAAAAqo"]
[Tue Jul 21 07:28:51.787278 2026] [security2:error] [pid 230252:tid 230495] [client 175.45.70.82:58282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeUQAAAwg"]
[Tue Jul 21 07:28:51.787397 2026] [security2:error] [pid 230252:tid 230495] [client 175.45.70.82:58282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeUQAAAwg"]
[Tue Jul 21 07:28:51.814192 2026] [security2:error] [pid 230252:tid 230372] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeUwACvHU"]
[Tue Jul 21 07:28:51.814327 2026] [security2:error] [pid 230252:tid 230419] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeUwACvHU"]
[Tue Jul 21 07:28:51.896437 2026] [security2:error] [pid 229246:tid 229447] [client 213.152.162.104:47776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9J4yBMYeh5YLVG45yDEwAAAls"]
[Tue Jul 21 07:28:51.896606 2026] [security2:error] [pid 229246:tid 229447] [client 213.152.162.104:47776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9J4yBMYeh5YLVG45yDEwAAAls"]
[Tue Jul 21 07:28:51.950066 2026] [security2:error] [pid 229246:tid 229452] [client 20.104.96.117:62419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/ops.php"] [unique_id "al9J4yBMYeh5YLVG45yDFAAAAmA"]
[Tue Jul 21 07:28:52.192798 2026] [security2:error] [pid 230252:tid 230480] [client 45.8.17.114:49611] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/m.php"] [unique_id "al9J5E0Dwhk5-Z44XrpeVwAAAvk"]
[Tue Jul 21 07:28:52.227957 2026] [security2:error] [pid 230252:tid 230510] [client 103.162.129.114:49755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9J5E0Dwhk5-Z44XrpeWAAAAxc"]
[Tue Jul 21 07:28:52.228102 2026] [security2:error] [pid 230252:tid 230510] [client 103.162.129.114:49755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9J5E0Dwhk5-Z44XrpeWAAAAxc"]
[Tue Jul 21 07:28:52.294632 2026] [security2:error] [pid 230252:tid 230308] [remote 65.111.9.127:34371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.9.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9J5E0Dwhk5-Z44XrpeVgAC_jY"]
[Tue Jul 21 07:28:52.333396 2026] [security2:error] [pid 230252:tid 230479] [client 20.104.96.117:7098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/file31.php"] [unique_id "al9J5E0Dwhk5-Z44XrpeXAAAAvg"]
[Tue Jul 21 07:28:52.429666 2026] [security2:error] [pid 230252:tid 230455] [client 20.104.96.117:59823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/file61.php"] [unique_id "al9J5E0Dwhk5-Z44XrpeXQAAAuA"]
[Tue Jul 21 07:28:52.446136 2026] [security2:error] [pid 230252:tid 230491] [client 74.7.241.157:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agencia.aede.com.br"] [uri "/index.php"] [unique_id "al9J5E0Dwhk5-Z44XrpeWwAAAwQ"], referer: https://www.agencia.aede.com.br/robots.txt
[Tue Jul 21 07:28:52.447036 2026] [security2:error] [pid 230252:tid 230487] [client 74.7.241.157:44816] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agencia.aede.com.br"] [uri "/robots.txt"] [unique_id "al9J5E0Dwhk5-Z44XrpeWQADACU"], referer: https://www.agencia.aede.com.br/robots.txt
[Tue Jul 21 07:28:52.469163 2026] [autoindex:error] [pid 230252:tid 230451] [client 20.197.195.24:12388] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:52.536740 2026] [security2:error] [pid 230252:tid 230393] [client 20.151.10.161:49063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/file.php"] [unique_id "al9J5E0Dwhk5-Z44XrpeYAAAAqI"]
[Tue Jul 21 07:28:52.597765 2026] [autoindex:error] [pid 230252:tid 230384] [client 20.197.195.24:12388] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:52.775072 2026] [security2:error] [pid 230252:tid 230397] [client 20.104.96.117:7085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/file6.php"] [unique_id "al9J5E0Dwhk5-Z44XrpeZwAAAqY"]
[Tue Jul 21 07:28:53.027306 2026] [security2:error] [pid 230252:tid 230434] [client 20.197.195.24:12388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/ccc.php"] [unique_id "al9J5U0Dwhk5-Z44XrpeawAAAss"]
[Tue Jul 21 07:28:53.288906 2026] [security2:error] [pid 229246:tid 229386] [client 45.8.17.121:29793] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/languages/"] [unique_id "al9J5SBMYeh5YLVG45yDHAAAAh4"]
[Tue Jul 21 07:28:53.675521 2026] [autoindex:error] [pid 229246:tid 229395] [client 20.104.96.117:6212] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:53.788387 2026] [security2:error] [pid 229246:tid 229397] [client 20.197.195.24:12304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/w.php"] [unique_id "al9J5SBMYeh5YLVG45yDMgAAAik"]
[Tue Jul 21 07:28:53.950830 2026] [security2:error] [pid 229246:tid 229411] [client 20.104.96.117:6212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/adminfuns.php"] [unique_id "al9J5SBMYeh5YLVG45yDNQAAAjc"]
[Tue Jul 21 07:28:53.970404 2026] [security2:error] [pid 229246:tid 229362] [remote 103.28.36.122:36914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inovasoulfigital.com"] [uri "/wp-login.php"] [unique_id "al9J5SBMYeh5YLVG45yDNgACjXM"]
[Tue Jul 21 07:28:53.996564 2026] [security2:error] [pid 230252:tid 230458] [client 20.151.10.161:49134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/cfile.php"] [unique_id "al9J5U0Dwhk5-Z44XrpefgAAAuM"]
[Tue Jul 21 07:28:54.001213 2026] [security2:error] [pid 229246:tid 229388] [client 109.248.148.246:44320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9J5SBMYeh5YLVG45yDNwAAAiA"]
[Tue Jul 21 07:28:54.001286 2026] [security2:error] [pid 229246:tid 229388] [client 109.248.148.246:44320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9J5SBMYeh5YLVG45yDNwAAAiA"]
[Tue Jul 21 07:28:54.199050 2026] [security2:error] [pid 230252:tid 230449] [client 20.104.96.117:42385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/water.php"] [unique_id "al9J5k0Dwhk5-Z44XrpegQAAAto"]
[Tue Jul 21 07:28:54.357550 2026] [security2:error] [pid 230252:tid 230433] [client 20.197.195.24:12335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9J5k0Dwhk5-Z44XrpehAAAAso"]
[Tue Jul 21 07:28:54.662354 2026] [security2:error] [pid 229246:tid 229387] [client 20.104.96.117:62423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/goods.php"] [unique_id "al9J5iBMYeh5YLVG45yDQAAAAh8"]
[Tue Jul 21 07:28:55.062280 2026] [security2:error] [pid 229246:tid 229379] [client 20.151.10.161:48586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/class-wp.php"] [unique_id "al9J5yBMYeh5YLVG45yDRAAAAhc"]
[Tue Jul 21 07:28:55.179551 2026] [security2:error] [pid 230252:tid 230461] [client 45.8.17.142:50889] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/about.php"] [unique_id "al9J500Dwhk5-Z44XrpekAAAAuY"]
[Tue Jul 21 07:28:55.252435 2026] [security2:error] [pid 229246:tid 229383] [client 20.197.195.24:12390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/FWAZ.php"] [unique_id "al9J5yBMYeh5YLVG45yDSQAAAhs"]
[Tue Jul 21 07:28:55.328646 2026] [security2:error] [pid 229246:tid 229412] [client 20.104.96.117:62409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/100.php"] [unique_id "al9J5yBMYeh5YLVG45yDSwAAAjg"]
[Tue Jul 21 07:28:55.520280 2026] [security2:error] [pid 230252:tid 230455] [client 193.36.225.60:27203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9J500Dwhk5-Z44XrpekQAAAuA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:55.533010 2026] [security2:error] [pid 230252:tid 230416] [client 20.104.96.117:59619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/nano.php"] [unique_id "al9J500Dwhk5-Z44XrpekwAAArk"]
[Tue Jul 21 07:28:55.571259 2026] [security2:error] [pid 230252:tid 230394] [client 20.197.195.24:12348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/miru1.php"] [unique_id "al9J500Dwhk5-Z44XrpelgAAAqM"]
[Tue Jul 21 07:28:55.615284 2026] [security2:error] [pid 230252:tid 230419] [client 82.102.28.107:40602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9J500Dwhk5-Z44XrpelwAAArw"]
[Tue Jul 21 07:28:55.615367 2026] [security2:error] [pid 230252:tid 230419] [client 82.102.28.107:40602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9J500Dwhk5-Z44XrpelwAAArw"]
[Tue Jul 21 07:28:55.669474 2026] [security2:error] [pid 230252:tid 230446] [client 20.104.96.117:62867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/about.php"] [unique_id "al9J500Dwhk5-Z44XrpemAAAAtc"]
[Tue Jul 21 07:28:55.801892 2026] [security2:error] [pid 230252:tid 230458] [client 20.151.10.161:49147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/admin.php"] [unique_id "al9J500Dwhk5-Z44XrpenQAAAuM"]
[Tue Jul 21 07:28:55.898745 2026] [security2:error] [pid 230252:tid 230405] [client 20.197.195.24:12308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/aa.php"] [unique_id "al9J500Dwhk5-Z44XrpengAAAq4"]
[Tue Jul 21 07:28:56.001462 2026] [security2:error] [pid 229246:tid 229474] [client 20.104.96.117:62434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/about.php"] [unique_id "al9J6CBMYeh5YLVG45yDUQAAAnY"]
[Tue Jul 21 07:28:56.022973 2026] [security2:error] [pid 230252:tid 230449] [client 213.152.162.104:47784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9J6E0Dwhk5-Z44XrpenwAAAto"]
[Tue Jul 21 07:28:56.023093 2026] [security2:error] [pid 230252:tid 230449] [client 213.152.162.104:47784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9J6E0Dwhk5-Z44XrpenwAAAto"]
[Tue Jul 21 07:28:56.085511 2026] [security2:error] [pid 230252:tid 230472] [client 45.8.17.127:34047] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/packed.php"] [unique_id "al9J6E0Dwhk5-Z44XrpeoAAAAvE"]
[Tue Jul 21 07:28:56.372022 2026] [security2:error] [pid 230252:tid 230437] [client 20.104.96.117:62897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/admin.php"] [unique_id "al9J6E0Dwhk5-Z44XrpeogAAAs4"]
[Tue Jul 21 07:28:56.417460 2026] [security2:error] [pid 230252:tid 230415] [client 20.104.96.117:42379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/moon.php"] [unique_id "al9J6E0Dwhk5-Z44XrpepAAAArg"]
[Tue Jul 21 07:28:56.679023 2026] [security2:error] [pid 230252:tid 230446] [client 20.104.96.117:62440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/admin.php"] [unique_id "al9J6E0Dwhk5-Z44XrperAAAAtc"]
[Tue Jul 21 07:28:56.776696 2026] [security2:error] [pid 230252:tid 230473] [client 45.251.232.145:55489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J6E0Dwhk5-Z44XrpergAAAvI"]
[Tue Jul 21 07:28:56.776869 2026] [security2:error] [pid 230252:tid 230473] [client 45.251.232.145:55489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J6E0Dwhk5-Z44XrpergAAAvI"]
[Tue Jul 21 07:28:56.807570 2026] [security2:error] [pid 230252:tid 230480] [client 20.151.10.161:49093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/aa2.php"] [unique_id "al9J6E0Dwhk5-Z44XrperwAAAvk"]
[Tue Jul 21 07:28:56.978257 2026] [security2:error] [pid 230252:tid 230458] [client 20.104.96.117:62876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/themes.php"] [unique_id "al9J6E0Dwhk5-Z44XrpesAAAAuM"]
[Tue Jul 21 07:28:57.210251 2026] [security2:error] [pid 229246:tid 229483] [client 20.197.195.24:12361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/122.php"] [unique_id "al9J6SBMYeh5YLVG45yDXAAAAn8"]
[Tue Jul 21 07:28:57.267869 2026] [autoindex:error] [pid 230252:tid 230486] [client 20.104.96.117:62420] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:57.281288 2026] [security2:error] [pid 230252:tid 230449] [client 45.8.17.141:28083] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentyfive/"] [unique_id "al9J6U0Dwhk5-Z44XrpeswAAAto"]
[Tue Jul 21 07:28:57.417859 2026] [security2:error] [pid 230252:tid 230286] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9J6U0Dwhk5-Z44XrpetAADACA"]
[Tue Jul 21 07:28:57.418000 2026] [security2:error] [pid 230252:tid 230487] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9J6U0Dwhk5-Z44XrpetAADACA"]
[Tue Jul 21 07:28:57.579698 2026] [security2:error] [pid 230252:tid 230421] [client 20.197.195.24:20563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/get.php"] [unique_id "al9J6U0Dwhk5-Z44XrpeuQAAAr4"]
[Tue Jul 21 07:28:57.749015 2026] [security2:error] [pid 229246:tid 229415] [client 139.135.44.145:53495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J6SBMYeh5YLVG45yDZwAAAjs"]
[Tue Jul 21 07:28:57.749127 2026] [security2:error] [pid 229246:tid 229415] [client 139.135.44.145:53495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J6SBMYeh5YLVG45yDZwAAAjs"]
[Tue Jul 21 07:28:57.815947 2026] [security2:error] [pid 229246:tid 229450] [client 117.251.86.144:42636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9J6SBMYeh5YLVG45yDaQAAAl4"]
[Tue Jul 21 07:28:57.816084 2026] [security2:error] [pid 229246:tid 229450] [client 117.251.86.144:42636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9J6SBMYeh5YLVG45yDaQAAAl4"]
[Tue Jul 21 07:28:58.176044 2026] [security2:error] [pid 230252:tid 230451] [client 59.96.220.140:51918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9J6k0Dwhk5-Z44XrpevQAAAtw"]
[Tue Jul 21 07:28:58.176188 2026] [security2:error] [pid 230252:tid 230451] [client 59.96.220.140:51918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9J6k0Dwhk5-Z44XrpevQAAAtw"]
[Tue Jul 21 07:28:58.181803 2026] [security2:error] [pid 230252:tid 230402] [client 45.8.17.145:65535] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/enhanced-text-widget/analyst/src/403x.php"] [unique_id "al9J6k0Dwhk5-Z44XrpevgAAAqs"]
[Tue Jul 21 07:28:58.256227 2026] [security2:error] [pid 229246:tid 229381] [client 20.151.10.161:49148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/ccou.php"] [unique_id "al9J6iBMYeh5YLVG45yDbAAAAhk"]
[Tue Jul 21 07:28:58.349288 2026] [autoindex:error] [pid 229246:tid 229397] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:58.361577 2026] [security2:error] [pid 230252:tid 230399] [client 20.104.96.117:62420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/.well-known/about.php"] [unique_id "al9J6k0Dwhk5-Z44XrpexAAAAqg"]
[Tue Jul 21 07:28:58.434116 2026] [security2:error] [pid 229246:tid 229451] [client 20.104.96.117:42408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-info.php"] [unique_id "al9J6iBMYeh5YLVG45yDbwAAAl8"]
[Tue Jul 21 07:28:58.721277 2026] [security2:error] [pid 230252:tid 230416] [client 20.104.96.117:7070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9J6k0Dwhk5-Z44XrpeyQAAArk"]
[Tue Jul 21 07:28:58.736049 2026] [autoindex:error] [pid 230252:tid 230455] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:58.952209 2026] [autoindex:error] [pid 230252:tid 230446] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:58.958751 2026] [security2:error] [pid 229246:tid 229364] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9J6iBMYeh5YLVG45yDewACc3U"]
[Tue Jul 21 07:28:58.958895 2026] [security2:error] [pid 229246:tid 229471] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9J6iBMYeh5YLVG45yDewACc3U"]
[Tue Jul 21 07:28:59.031074 2026] [security2:error] [pid 229246:tid 229406] [client 20.104.96.117:7041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/wefile.php"] [unique_id "al9J6yBMYeh5YLVG45yDfAAAAjI"]
[Tue Jul 21 07:28:59.161535 2026] [autoindex:error] [pid 229246:tid 229404] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:59.340215 2026] [security2:error] [pid 229246:tid 229468] [client 20.104.96.117:62882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9J6yBMYeh5YLVG45yDgQAAAnA"]
[Tue Jul 21 07:28:59.371810 2026] [autoindex:error] [pid 230252:tid 230491] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:59.391564 2026] [security2:error] [pid 230252:tid 230498] [client 45.8.17.147:41951] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/user/upgrade/"] [unique_id "al9J600Dwhk5-Z44Xrpe9gAAAws"]
[Tue Jul 21 07:28:59.426678 2026] [security2:error] [pid 229246:tid 229487] [client 20.220.225.223:62864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/dr.php"] [unique_id "al9J6yBMYeh5YLVG45yDgwAAAoM"]
[Tue Jul 21 07:28:59.430807 2026] [security2:error] [pid 230252:tid 230506] [client 152.59.154.239:34765] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J600Dwhk5-Z44Xrpe_QAAAxM"]
[Tue Jul 21 07:28:59.430933 2026] [security2:error] [pid 230252:tid 230506] [client 152.59.154.239:34765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J600Dwhk5-Z44Xrpe_QAAAxM"]
[Tue Jul 21 07:28:59.580419 2026] [autoindex:error] [pid 230252:tid 230393] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:59.630089 2026] [security2:error] [pid 229246:tid 229502] [client 20.197.195.24:20575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/as.php"] [unique_id "al9J6yBMYeh5YLVG45yDhgAAApI"]
[Tue Jul 21 07:28:59.789198 2026] [autoindex:error] [pid 230252:tid 230433] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:59.796678 2026] [autoindex:error] [pid 230252:tid 230384] [client 20.104.96.117:62903] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:00.004460 2026] [autoindex:error] [pid 230252:tid 230411] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:00.117754 2026] [autoindex:error] [pid 230252:tid 230428] [client 20.104.96.117:62903] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:00.199276 2026] [security2:error] [pid 230252:tid 230452] [client 136.144.33.106:61999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9J7E0Dwhk5-Z44XrpfHwAAAt0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:00.255654 2026] [security2:error] [pid 230252:tid 230419] [client 20.104.96.117:62903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9J7E0Dwhk5-Z44XrpfJQAAArw"]
[Tue Jul 21 07:29:00.484640 2026] [security2:error] [pid 229246:tid 229494] [client 45.8.17.110:30535] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Text/Diff/"] [unique_id "al9J7CBMYeh5YLVG45yDkwAAAoo"]
[Tue Jul 21 07:29:00.728415 2026] [security2:error] [pid 230252:tid 230504] [client 82.102.28.107:41252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9J7E0Dwhk5-Z44XrpfOgAAAxE"]
[Tue Jul 21 07:29:00.728493 2026] [security2:error] [pid 230252:tid 230504] [client 82.102.28.107:41252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9J7E0Dwhk5-Z44XrpfOgAAAxE"]
[Tue Jul 21 07:29:00.778638 2026] [security2:error] [pid 230252:tid 230455] [client 103.106.20.201:56108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J7E0Dwhk5-Z44XrpfPgAAAuA"]
[Tue Jul 21 07:29:00.778750 2026] [security2:error] [pid 230252:tid 230455] [client 103.106.20.201:56108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J7E0Dwhk5-Z44XrpfPgAAAuA"]
[Tue Jul 21 07:29:00.792212 2026] [security2:error] [pid 229246:tid 229480] [client 20.104.96.117:62850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/8.php"] [unique_id "al9J7CBMYeh5YLVG45yDlwAAAnw"]
[Tue Jul 21 07:29:01.063655 2026] [security2:error] [pid 230252:tid 230476] [client 20.197.195.24:12411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/ccou.php"] [unique_id "al9J7U0Dwhk5-Z44XrpfTgAAAvU"]
[Tue Jul 21 07:29:01.141531 2026] [security2:error] [pid 230252:tid 230391] [client 20.104.96.117:62427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9J7U0Dwhk5-Z44XrpfUgAAAqA"]
[Tue Jul 21 07:29:01.147199 2026] [security2:error] [pid 229246:tid 229417] [client 20.151.10.161:49123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/dr.php"] [unique_id "al9J7SBMYeh5YLVG45yDngAAAj0"]
[Tue Jul 21 07:29:01.489262 2026] [security2:error] [pid 230252:tid 230452] [client 20.104.96.117:62447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/f6.php"] [unique_id "al9J7U0Dwhk5-Z44XrpfXAAAAt0"]
[Tue Jul 21 07:29:01.597101 2026] [security2:error] [pid 230252:tid 230442] [client 45.8.17.107:30661] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/"] [unique_id "al9J7U0Dwhk5-Z44XrpfXQAAAtM"]
[Tue Jul 21 07:29:01.672226 2026] [security2:error] [pid 230252:tid 230282] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9J7U0Dwhk5-Z44XrpfXgACxRw"]
[Tue Jul 21 07:29:01.672491 2026] [security2:error] [pid 230252:tid 230428] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9J7U0Dwhk5-Z44XrpfXgACxRw"]
[Tue Jul 21 07:29:01.759075 2026] [autoindex:error] [pid 230252:tid 230474] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:01.793938 2026] [security2:error] [pid 230252:tid 230467] [client 20.104.96.117:62412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/inputs.php"] [unique_id "al9J7U0Dwhk5-Z44XrpfYgAAAuw"]
[Tue Jul 21 07:29:01.947907 2026] [security2:error] [pid 230252:tid 230300] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9J7U0Dwhk5-Z44XrpfYwAC1y4"]
[Tue Jul 21 07:29:01.948048 2026] [security2:error] [pid 230252:tid 230446] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9J7U0Dwhk5-Z44XrpfYwAC1y4"]
[Tue Jul 21 07:29:01.967376 2026] [autoindex:error] [pid 230252:tid 230482] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:02.000994 2026] [security2:error] [pid 230252:tid 230503] [client 20.197.195.24:12321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/w3lls.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfaQAAAxA"]
[Tue Jul 21 07:29:02.057954 2026] [security2:error] [pid 229246:tid 229287] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9J7iBMYeh5YLVG45yDqQACaSg"]
[Tue Jul 21 07:29:02.058091 2026] [security2:error] [pid 229246:tid 229461] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9J7iBMYeh5YLVG45yDqQACaSg"]
[Tue Jul 21 07:29:02.079244 2026] [security2:error] [pid 230252:tid 230390] [client 103.174.34.15:51613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfagAAAp8"]
[Tue Jul 21 07:29:02.079328 2026] [security2:error] [pid 230252:tid 230390] [client 103.174.34.15:51613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfagAAAp8"]
[Tue Jul 21 07:29:02.102827 2026] [security2:error] [pid 230252:tid 230486] [client 20.104.96.117:7081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/inputs.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfawAAAv8"]
[Tue Jul 21 07:29:02.281661 2026] [security2:error] [pid 230252:tid 230437] [client 20.104.96.117:59811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/2000.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfdQAAAs4"]
[Tue Jul 21 07:29:02.323665 2026] [security2:error] [pid 230252:tid 230311] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfdgACrjk"]
[Tue Jul 21 07:29:02.323821 2026] [security2:error] [pid 230252:tid 230405] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfdgACrjk"]
[Tue Jul 21 07:29:02.360673 2026] [security2:error] [pid 229246:tid 229397] [client 175.45.70.82:58792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J7iBMYeh5YLVG45yDqgAAAik"]
[Tue Jul 21 07:29:02.360786 2026] [security2:error] [pid 229246:tid 229397] [client 175.45.70.82:58792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J7iBMYeh5YLVG45yDqgAAAik"]
[Tue Jul 21 07:29:02.386860 2026] [autoindex:error] [pid 230252:tid 230438] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:02.439359 2026] [security2:error] [pid 230252:tid 230432] [client 20.104.96.117:62891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/classwithtostring.php"] [unique_id "al9J7k0Dwhk5-Z44XrpffAAAAsk"]
[Tue Jul 21 07:29:02.485430 2026] [security2:error] [pid 230252:tid 230386] [client 45.8.17.131:26283] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/we.php"] [unique_id "al9J7k0Dwhk5-Z44XrpffQAAAps"]
[Tue Jul 21 07:29:02.583042 2026] [security2:error] [pid 230252:tid 230452] [client 82.102.28.107:41268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9J7k0Dwhk5-Z44XrpffwAAAt0"]
[Tue Jul 21 07:29:02.583135 2026] [security2:error] [pid 230252:tid 230452] [client 82.102.28.107:41268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9J7k0Dwhk5-Z44XrpffwAAAt0"]
[Tue Jul 21 07:29:02.596584 2026] [autoindex:error] [pid 230252:tid 230399] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:02.621840 2026] [security2:error] [pid 229246:tid 229453] [client 20.197.195.24:12381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/test1.php"] [unique_id "al9J7iBMYeh5YLVG45yDrQAAAmE"]
[Tue Jul 21 07:29:02.684006 2026] [security2:error] [pid 230252:tid 230479] [client 103.162.129.114:50214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfhQAAAvg"]
[Tue Jul 21 07:29:02.684229 2026] [security2:error] [pid 230252:tid 230479] [client 103.162.129.114:50214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfhQAAAvg"]
[Tue Jul 21 07:29:02.730958 2026] [security2:error] [pid 230252:tid 230445] [client 20.104.96.117:62432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfhwAAAtY"]
[Tue Jul 21 07:29:02.817495 2026] [autoindex:error] [pid 230252:tid 230482] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:02.931255 2026] [security2:error] [pid 230252:tid 230458] [client 204.8.96.141:39388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.96.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfiAAAAuM"]
[Tue Jul 21 07:29:02.931343 2026] [security2:error] [pid 230252:tid 230458] [client 204.8.96.141:39388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfiAAAAuM"]
[Tue Jul 21 07:29:02.942296 2026] [security2:error] [pid 230252:tid 230435] [client 20.220.225.223:62877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/2x.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfjgAAAsw"]
[Tue Jul 21 07:29:03.011108 2026] [security2:error] [pid 230252:tid 230413] [client 20.104.96.117:62444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/wp-blog.php"] [unique_id "al9J700Dwhk5-Z44XrpfjwAAArY"]
[Tue Jul 21 07:29:03.030387 2026] [autoindex:error] [pid 230252:tid 230455] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:03.044382 2026] [security2:error] [pid 230252:tid 230486] [client 20.52.136.55:1763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/aa.php"] [unique_id "al9J700Dwhk5-Z44XrpfkwAAAv8"]
[Tue Jul 21 07:29:03.235869 2026] [security2:error] [pid 230252:tid 230384] [client 213.152.162.104:45002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9J700Dwhk5-Z44XrpfmAAAApk"]
[Tue Jul 21 07:29:03.235987 2026] [security2:error] [pid 230252:tid 230384] [client 213.152.162.104:45002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9J700Dwhk5-Z44XrpfmAAAApk"]
[Tue Jul 21 07:29:03.238987 2026] [autoindex:error] [pid 230252:tid 230454] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:03.310274 2026] [autoindex:error] [pid 230252:tid 230405] [client 20.104.96.117:62859] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:03.405598 2026] [security2:error] [pid 229246:tid 229423] [client 45.146.55.205:33795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.55.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lumerah.com.br"] [uri "/wp-login.php"] [unique_id "al9J7yBMYeh5YLVG45yDsgAAAkM"]
[Tue Jul 21 07:29:03.494346 2026] [security2:error] [pid 230252:tid 230411] [client 20.197.195.24:12402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/database.php"] [unique_id "al9J700Dwhk5-Z44XrpfowAAArQ"]
[Tue Jul 21 07:29:03.593669 2026] [security2:error] [pid 230252:tid 230470] [client 45.8.17.146:60449] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/neve/assets/apps/dashboard/build/"] [unique_id "al9J700Dwhk5-Z44XrpfpgAAAu8"]
[Tue Jul 21 07:29:03.595904 2026] [security2:error] [pid 230252:tid 230484] [client 20.104.96.117:62859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9J700Dwhk5-Z44XrpfpwAAAv0"]
[Tue Jul 21 07:29:03.631941 2026] [security2:error] [pid 230252:tid 230417] [client 20.104.96.117:42370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/122.php"] [unique_id "al9J700Dwhk5-Z44XrpfqAAAAro"]
[Tue Jul 21 07:29:03.642271 2026] [security2:error] [pid 230252:tid 230448] [client 34.11.127.22:58271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.127.11.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajsdiesel.com.br.jaypi.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J700Dwhk5-Z44XrpfqQAAAtk"]
[Tue Jul 21 07:29:03.681952 2026] [security2:error] [pid 230252:tid 230452] [client 34.11.127.22:52122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.127.11.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajsdiesel.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J700Dwhk5-Z44XrpfqgAAAt0"]
[Tue Jul 21 07:29:03.827947 2026] [security2:error] [pid 230252:tid 230424] [client 172.245.102.45:22787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9J700Dwhk5-Z44XrpfsQAAAsE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:03.938823 2026] [security2:error] [pid 230252:tid 230425] [client 20.104.96.117:62413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/ms-edit.php"] [unique_id "al9J700Dwhk5-Z44XrpfswAAAsI"]
[Tue Jul 21 07:29:04.009982 2026] [security2:error] [pid 230252:tid 230403] [client 34.11.127.22:61054] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9J8E0Dwhk5-Z44XrpftAAAAqw"]
[Tue Jul 21 07:29:04.026172 2026] [autoindex:error] [pid 229246:tid 229406] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:04.060558 2026] [security2:error] [pid 230252:tid 230473] [client 34.11.127.22:57996] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br.jaypi.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9J8E0Dwhk5-Z44XrpfuAAAAvI"]
[Tue Jul 21 07:29:04.143035 2026] [security2:error] [pid 230252:tid 230435] [client 20.151.10.161:49095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/xamp.php"] [unique_id "al9J8E0Dwhk5-Z44XrpfuQAAAsw"]
[Tue Jul 21 07:29:04.211303 2026] [security2:error] [pid 230252:tid 230409] [client 20.197.195.24:12362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/file.php"] [unique_id "al9J8E0Dwhk5-Z44XrpfugAAArI"]
[Tue Jul 21 07:29:04.229447 2026] [cgid:error] [pid 230252:tid 230455] [client 82.102.18.182:0] AH01265: stderr from /home1/asse7722/public_html/cgi-bin/: attempt to invoke directory as script
[Tue Jul 21 07:29:04.244126 2026] [security2:error] [pid 229246:tid 229459] [client 20.104.96.117:62403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9J8CBMYeh5YLVG45yDuwAAAmc"]
[Tue Jul 21 07:29:04.260114 2026] [security2:error] [pid 230252:tid 230460] [client 34.11.127.22:55532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9J8E0Dwhk5-Z44XrpfvgAAAuU"]
[Tue Jul 21 07:29:04.385347 2026] [security2:error] [pid 229246:tid 229468] [client 45.8.17.128:42955] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/css/dist/"] [unique_id "al9J8CBMYeh5YLVG45yDvAAAAnA"]
[Tue Jul 21 07:29:04.387281 2026] [security2:error] [pid 230252:tid 230498] [client 34.11.127.22:59567] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br.jaypi.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9J8E0Dwhk5-Z44XrpfwgAAAws"]
[Tue Jul 21 07:29:04.547891 2026] [autoindex:error] [pid 230252:tid 230411] [client 20.104.96.117:62422] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:04.586236 2026] [security2:error] [pid 229246:tid 229412] [client 34.11.127.22:55754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9J8CBMYeh5YLVG45yDvwAAAjg"]
[Tue Jul 21 07:29:04.630514 2026] [security2:error] [pid 229246:tid 229503] [client 20.197.195.24:12412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/file.php"] [unique_id "al9J8CBMYeh5YLVG45yDwQAAApM"]
[Tue Jul 21 07:29:04.660404 2026] [security2:error] [pid 229246:tid 229466] [client 34.11.127.22:59774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br.jaypi.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9J8CBMYeh5YLVG45yDwwAAAm4"]
[Tue Jul 21 07:29:04.758910 2026] [security2:error] [pid 230252:tid 230438] [client 20.197.195.24:20496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/777.php"] [unique_id "al9J8E0Dwhk5-Z44XrpfzAAAAs8"]
[Tue Jul 21 07:29:04.830716 2026] [security2:error] [pid 230252:tid 230417] [client 20.104.96.117:62422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9J8E0Dwhk5-Z44XrpfzwAAAro"]
[Tue Jul 21 07:29:04.878734 2026] [security2:error] [pid 230252:tid 230474] [client 20.197.195.24:12296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/ssixta.php"] [unique_id "al9J8E0Dwhk5-Z44Xrpf0QAAAvM"]
[Tue Jul 21 07:29:04.879773 2026] [security2:error] [pid 230252:tid 230394] [client 34.11.127.22:56273] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9J8E0Dwhk5-Z44Xrpf0gAAAqM"]
[Tue Jul 21 07:29:04.929518 2026] [security2:error] [pid 230252:tid 230416] [client 34.11.127.22:53534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br.jaypi.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9J8E0Dwhk5-Z44Xrpf0wAAArk"]
[Tue Jul 21 07:29:04.932995 2026] [security2:error] [pid 229246:tid 229463] [client 204.8.96.141:39392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.96.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J8CBMYeh5YLVG45yDxwAAAms"]
[Tue Jul 21 07:29:04.933122 2026] [security2:error] [pid 229246:tid 229463] [client 204.8.96.141:39392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J8CBMYeh5YLVG45yDxwAAAms"]
[Tue Jul 21 07:29:05.137386 2026] [autoindex:error] [pid 230252:tid 230500] [client 20.104.96.117:62453] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:05.192381 2026] [security2:error] [pid 230252:tid 230485] [client 34.11.127.22:50295] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9J8U0Dwhk5-Z44Xrpf3AAAAv4"]
[Tue Jul 21 07:29:05.228465 2026] [security2:error] [pid 230252:tid 230497] [client 34.11.127.22:53984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br.jaypi.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9J8U0Dwhk5-Z44Xrpf3QAAAwo"]
[Tue Jul 21 07:29:05.247640 2026] [security2:error] [pid 230252:tid 230458] [client 20.197.195.24:12295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/1c.php"] [unique_id "al9J8U0Dwhk5-Z44Xrpf3gAAAuM"]
[Tue Jul 21 07:29:05.387486 2026] [security2:error] [pid 230252:tid 230390] [client 45.8.17.113:55525] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/media-text/"] [unique_id "al9J8U0Dwhk5-Z44Xrpf5QAAAp8"]
[Tue Jul 21 07:29:05.420027 2026] [autoindex:error] [pid 230252:tid 230498] [client 20.104.96.117:62453] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:05.466582 2026] [security2:error] [pid 229246:tid 229429] [client 34.11.127.22:54841] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9J8SBMYeh5YLVG45yDywAAAkk"]
[Tue Jul 21 07:29:05.473005 2026] [security2:error] [pid 230252:tid 230487] [client 34.11.127.22:51639] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br.jaypi.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9J8U0Dwhk5-Z44Xrpf6AAAAwA"]
[Tue Jul 21 07:29:05.570323 2026] [security2:error] [pid 230252:tid 230405] [client 20.104.96.117:62453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/abcd.php"] [unique_id "al9J8U0Dwhk5-Z44Xrpf6gAAAq4"]
[Tue Jul 21 07:29:05.657553 2026] [security2:error] [pid 230252:tid 230384] [client 20.197.195.24:20559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/test2.php"] [unique_id "al9J8U0Dwhk5-Z44Xrpf8AAAApk"]
[Tue Jul 21 07:29:05.757985 2026] [security2:error] [pid 229246:tid 229480] [client 20.197.195.24:20557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/buy.php"] [unique_id "al9J8SBMYeh5YLVG45yD0gAAAnw"]
[Tue Jul 21 07:29:05.788845 2026] [security2:error] [pid 229246:tid 229403] [client 91.92.47.101:49220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/php_info.php"] [unique_id "al9J8SBMYeh5YLVG45yD0wAAAi8"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:29:05.789909 2026] [security2:error] [pid 230252:tid 230432] [client 91.92.47.101:49210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/server_info.php"] [unique_id "al9J8U0Dwhk5-Z44Xrpf9AAAAsk"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:29:05.798820 2026] [security2:error] [pid 229246:tid 229384] [client 91.92.47.101:49292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/pinfo.php"] [unique_id "al9J8SBMYeh5YLVG45yD1gAAAhw"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:29:05.799442 2026] [security2:error] [pid 229246:tid 229449] [client 91.92.47.101:49238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/test.php"] [unique_id "al9J8SBMYeh5YLVG45yD2AAAAl0"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:29:05.801074 2026] [security2:error] [pid 230252:tid 230452] [client 91.92.47.101:49248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/functions.php"] [unique_id "al9J8U0Dwhk5-Z44Xrpf9gAAAt0"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:29:05.801768 2026] [security2:error] [pid 230252:tid 230493] [client 91.92.47.101:49308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/index.php"] [unique_id "al9J8U0Dwhk5-Z44Xrpf9wAAAwY"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:29:05.801789 2026] [security2:error] [pid 229246:tid 229484] [client 91.92.47.101:49216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/configuration.php"] [unique_id "al9J8SBMYeh5YLVG45yD2QAAAoA"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:29:05.802326 2026] [security2:error] [pid 230252:tid 230406] [client 91.92.47.101:49240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/portal/phpinfo.php"] [unique_id "al9J8U0Dwhk5-Z44Xrpf-AAAAq8"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:29:05.802660 2026] [security2:error] [pid 229246:tid 229394] [client 91.92.47.101:49206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/phpinfo/info.php"] [unique_id "al9J8SBMYeh5YLVG45yD3AAAAiY"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:29:05.848698 2026] [security2:error] [pid 229246:tid 229445] [client 34.11.127.22:60130] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br.jaypi.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9J8SBMYeh5YLVG45yD3gAAAlk"]
[Tue Jul 21 07:29:05.856183 2026] [security2:error] [pid 230252:tid 230477] [client 34.11.127.22:57994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9J8U0Dwhk5-Z44Xrpf-gAAAvY"]
[Tue Jul 21 07:29:05.862952 2026] [security2:error] [pid 230252:tid 230415] [client 20.104.96.117:42413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/mds.php"] [unique_id "al9J8U0Dwhk5-Z44Xrpf-wAAArg"]
[Tue Jul 21 07:29:05.869984 2026] [security2:error] [pid 230252:tid 230474] [client 20.104.96.117:62878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/file15.php"] [unique_id "al9J8U0Dwhk5-Z44Xrpf_AAAAvM"]
[Tue Jul 21 07:29:05.893618 2026] [security2:error] [pid 230252:tid 230419] [client 20.197.195.24:12344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/ssend.php"] [unique_id "al9J8U0Dwhk5-Z44XrpgAAAAArw"]
[Tue Jul 21 07:29:05.960969 2026] [security2:error] [pid 229246:tid 229456] [client 20.197.195.24:12352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/item.php"] [unique_id "al9J8SBMYeh5YLVG45yD4gAAAmQ"]
[Tue Jul 21 07:29:05.974247 2026] [security2:error] [pid 230252:tid 230411] [client 173.252.95.8:36986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9J8U0Dwhk5-Z44Xrpf-QAAArQ"]
[Tue Jul 21 07:29:06.117713 2026] [autoindex:error] [pid 230252:tid 230436] [client 186.202.163.107:36877] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/planamoveis.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:06.143033 2026] [security2:error] [pid 229246:tid 229432] [client 34.11.127.22:65146] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9J8iBMYeh5YLVG45yD4wAAAkw"]
[Tue Jul 21 07:29:06.150233 2026] [security2:error] [pid 229246:tid 229451] [client 34.11.127.22:57265] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br.jaypi.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9J8iBMYeh5YLVG45yD5gAAAl8"]
[Tue Jul 21 07:29:06.172933 2026] [security2:error] [pid 229246:tid 229491] [client 20.104.96.117:6279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/jp.php"] [unique_id "al9J8iBMYeh5YLVG45yD6AAAAoc"]
[Tue Jul 21 07:29:06.224136 2026] [security2:error] [pid 229246:tid 229493] [client 20.197.195.24:12338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/ss.php"] [unique_id "al9J8iBMYeh5YLVG45yD6QAAAok"]
[Tue Jul 21 07:29:06.397108 2026] [security2:error] [pid 229246:tid 229442] [client 34.11.127.22:54854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9J8iBMYeh5YLVG45yD9AAAAlY"]
[Tue Jul 21 07:29:06.408951 2026] [security2:error] [pid 230252:tid 230504] [client 34.11.127.22:52346] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br.jaypi.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9J8k0Dwhk5-Z44XrpgBQAAAxE"]
[Tue Jul 21 07:29:06.452617 2026] [security2:error] [pid 229246:tid 229471] [client 20.104.96.117:7047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/f35.php"] [unique_id "al9J8iBMYeh5YLVG45yD9QAAAnM"]
[Tue Jul 21 07:29:06.484764 2026] [security2:error] [pid 230252:tid 230401] [client 45.8.17.73:64059] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "al9J8k0Dwhk5-Z44XrpgBgAAAqo"]
[Tue Jul 21 07:29:06.494540 2026] [security2:error] [pid 229246:tid 229406] [client 20.197.195.24:12329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/hypo.php"] [unique_id "al9J8iBMYeh5YLVG45yD9wAAAjI"]
[Tue Jul 21 07:29:06.527682 2026] [security2:error] [pid 230252:tid 230347] [remote 157.66.26.183:60436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "franciscaco.com.br"] [uri "/wp-login.php"] [unique_id "al9J8U0Dwhk5-Z44Xrpf5AACm1w"]
[Tue Jul 21 07:29:06.643695 2026] [security2:error] [pid 229246:tid 229407] [client 20.104.96.117:59593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-blink.php"] [unique_id "al9J8iBMYeh5YLVG45yD_gAAAjM"]
[Tue Jul 21 07:29:06.675639 2026] [security2:error] [pid 229246:tid 229412] [client 34.11.127.22:64664] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9J8iBMYeh5YLVG45yD_wAAAjg"]
[Tue Jul 21 07:29:06.744304 2026] [security2:error] [pid 230252:tid 230413] [client 20.104.96.117:7084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/wp-load.php"] [unique_id "al9J8k0Dwhk5-Z44XrpgCAAAArY"]
[Tue Jul 21 07:29:06.763587 2026] [security2:error] [pid 229246:tid 229405] [client 173.252.95.39:36344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9J8iBMYeh5YLVG45yEAAAAAjE"]
[Tue Jul 21 07:29:06.766585 2026] [security2:error] [pid 229246:tid 229497] [client 204.8.96.141:39408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.96.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J8iBMYeh5YLVG45yEAQAAAo0"]
[Tue Jul 21 07:29:06.766675 2026] [security2:error] [pid 229246:tid 229497] [client 204.8.96.141:39408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J8iBMYeh5YLVG45yEAQAAAo0"]
[Tue Jul 21 07:29:06.807200 2026] [security2:error] [pid 229246:tid 229474] [client 20.197.195.24:20600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/users.php"] [unique_id "al9J8iBMYeh5YLVG45yEAgAAAnY"]
[Tue Jul 21 07:29:06.866348 2026] [autoindex:error] [pid 229246:tid 229462] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/admin/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:06.916949 2026] [security2:error] [pid 229246:tid 229502] [client 109.248.148.246:56512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9J8iBMYeh5YLVG45yECQAAApI"]
[Tue Jul 21 07:29:06.917077 2026] [security2:error] [pid 229246:tid 229502] [client 109.248.148.246:56512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9J8iBMYeh5YLVG45yECQAAApI"]
[Tue Jul 21 07:29:07.040629 2026] [security2:error] [pid 230252:tid 230507] [client 20.197.195.24:12379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/177.php"] [unique_id "al9J800Dwhk5-Z44XrpgCwAAAxQ"]
[Tue Jul 21 07:29:07.040769 2026] [security2:error] [pid 230252:tid 230435] [client 20.104.96.117:6276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/xyn.php"] [unique_id "al9J800Dwhk5-Z44XrpgDAAAAsw"]
[Tue Jul 21 07:29:07.069523 2026] [autoindex:error] [pid 230252:tid 230400] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:07.246599 2026] [security2:error] [pid 230252:tid 230391] [client 82.102.28.107:41286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9J800Dwhk5-Z44XrpgEQAAAqA"]
[Tue Jul 21 07:29:07.246692 2026] [security2:error] [pid 230252:tid 230391] [client 82.102.28.107:41286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9J800Dwhk5-Z44XrpgEQAAAqA"]
[Tue Jul 21 07:29:07.296245 2026] [security2:error] [pid 230252:tid 230503] [client 45.251.232.145:56222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J800Dwhk5-Z44XrpgFQAAAxA"]
[Tue Jul 21 07:29:07.296379 2026] [security2:error] [pid 230252:tid 230503] [client 45.251.232.145:56222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J800Dwhk5-Z44XrpgFQAAAxA"]
[Tue Jul 21 07:29:07.347275 2026] [autoindex:error] [pid 229246:tid 229413] [client 20.104.96.117:6295] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:07.394834 2026] [security2:error] [pid 230252:tid 230417] [client 45.8.17.60:62157] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/rest-api/fields/"] [unique_id "al9J800Dwhk5-Z44XrpgGAAAAro"]
[Tue Jul 21 07:29:07.516887 2026] [security2:error] [pid 229246:tid 229484] [client 20.197.195.24:20494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/config.php"] [unique_id "al9J8yBMYeh5YLVG45yEFQAAAoA"]
[Tue Jul 21 07:29:07.552222 2026] [security2:error] [pid 229246:tid 229430] [client 193.36.225.72:49927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9J8yBMYeh5YLVG45yEFwAAAko"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:07.675076 2026] [autoindex:error] [pid 229246:tid 229486] [client 20.104.96.117:6295] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:07.802789 2026] [security2:error] [pid 230252:tid 230421] [client 20.197.195.24:20571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/gettest.php"] [unique_id "al9J800Dwhk5-Z44XrpgHgAAAr4"]
[Tue Jul 21 07:29:07.812913 2026] [security2:error] [pid 229246:tid 229448] [client 20.104.96.117:6295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/ccc.php"] [unique_id "al9J8yBMYeh5YLVG45yEHgAAAlw"]
[Tue Jul 21 07:29:07.999247 2026] [security2:error] [pid 230252:tid 230382] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9J800Dwhk5-Z44XrpgIwAC-38"]
[Tue Jul 21 07:29:07.999423 2026] [security2:error] [pid 230252:tid 230482] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9J800Dwhk5-Z44XrpgIwAC-38"]
[Tue Jul 21 07:29:08.021297 2026] [security2:error] [pid 229246:tid 229399] [client 20.104.96.117:59635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/zc-208.php"] [unique_id "al9J9CBMYeh5YLVG45yEIAAAAis"]
[Tue Jul 21 07:29:08.068483 2026] [security2:error] [pid 230252:tid 230500] [client 20.197.195.24:12392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/min.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgJAAAAw0"]
[Tue Jul 21 07:29:08.157324 2026] [security2:error] [pid 230252:tid 230429] [client 20.104.96.117:62879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/w.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgKAAAAsY"]
[Tue Jul 21 07:29:08.178579 2026] [security2:error] [pid 230252:tid 230390] [client 20.197.195.24:12310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/dvjul.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgKQAAAp8"]
[Tue Jul 21 07:29:08.291367 2026] [security2:error] [pid 230252:tid 230394] [client 139.135.44.145:54344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgLAAAAqM"]
[Tue Jul 21 07:29:08.292083 2026] [security2:error] [pid 230252:tid 230394] [client 139.135.44.145:54344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgLAAAAqM"]
[Tue Jul 21 07:29:08.337935 2026] [security2:error] [pid 230252:tid 230487] [client 20.197.195.24:12371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/biufile.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgLgAAAwA"]
[Tue Jul 21 07:29:08.419227 2026] [security2:error] [pid 230252:tid 230472] [client 20.197.195.24:12337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/av.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgMAAAAvE"]
[Tue Jul 21 07:29:08.467451 2026] [security2:error] [pid 230252:tid 230455] [client 20.104.96.117:62881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgOAAAAuA"]
[Tue Jul 21 07:29:08.515286 2026] [security2:error] [pid 230252:tid 230454] [client 20.197.195.24:12347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/coffexium.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgOgAAAt8"]
[Tue Jul 21 07:29:08.581042 2026] [security2:error] [pid 230252:tid 230477] [client 45.8.17.49:27701] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentynineteen/sass/site/"] [unique_id "al9J9E0Dwhk5-Z44XrpgPQAAAvY"]
[Tue Jul 21 07:29:08.640263 2026] [security2:error] [pid 230252:tid 230399] [client 117.251.86.144:47412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgPgAAAqg"]
[Tue Jul 21 07:29:08.640453 2026] [security2:error] [pid 230252:tid 230399] [client 117.251.86.144:47412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgPgAAAqg"]
[Tue Jul 21 07:29:08.694946 2026] [security2:error] [pid 230252:tid 230386] [client 193.189.100.203:19867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.100.189.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgOwAAAps"]
[Tue Jul 21 07:29:08.695104 2026] [security2:error] [pid 230252:tid 230386] [client 193.189.100.203:19867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgOwAAAps"]
[Tue Jul 21 07:29:08.764364 2026] [security2:error] [pid 230252:tid 230445] [client 20.104.96.117:62889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/FWAZ.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgRwAAAtY"]
[Tue Jul 21 07:29:08.848377 2026] [security2:error] [pid 230252:tid 230420] [client 20.197.195.24:12298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/core.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgTQAAAr0"]
[Tue Jul 21 07:29:09.063920 2026] [security2:error] [pid 229246:tid 229395] [client 20.104.96.117:59802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/sid4.php"] [unique_id "al9J9SBMYeh5YLVG45yEKQAAAic"]
[Tue Jul 21 07:29:09.217129 2026] [security2:error] [pid 230252:tid 230394] [client 20.197.195.24:12355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/als.php"] [unique_id "al9J9U0Dwhk5-Z44XrpgVAAAAqM"]
[Tue Jul 21 07:29:09.253585 2026] [security2:error] [pid 230252:tid 230464] [client 20.104.96.117:62407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/miru1.php"] [unique_id "al9J9U0Dwhk5-Z44XrpgVQAAAuk"]
[Tue Jul 21 07:29:09.489095 2026] [security2:error] [pid 229246:tid 229457] [client 45.8.17.105:38421] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/fukasawa/inc/classes/403x.php"] [unique_id "al9J9SBMYeh5YLVG45yELgAAAmU"]
[Tue Jul 21 07:29:09.516478 2026] [security2:error] [pid 229246:tid 229357] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9J9SBMYeh5YLVG45yELwACRm4"]
[Tue Jul 21 07:29:09.516652 2026] [security2:error] [pid 229246:tid 229426] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9J9SBMYeh5YLVG45yELwACRm4"]
[Tue Jul 21 07:29:09.601393 2026] [security2:error] [pid 229246:tid 229398] [client 20.104.96.117:62869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/aa.php"] [unique_id "al9J9SBMYeh5YLVG45yEMQAAAio"]
[Tue Jul 21 07:29:09.906254 2026] [security2:error] [pid 230252:tid 230406] [client 20.104.96.117:62401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/122.php"] [unique_id "al9J9U0Dwhk5-Z44XrpgYQAAAq8"]
[Tue Jul 21 07:29:10.017643 2026] [security2:error] [pid 230252:tid 230477] [client 20.197.195.24:20500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/simple.php"] [unique_id "al9J9k0Dwhk5-Z44XrpgZAAAAvY"]
[Tue Jul 21 07:29:10.167501 2026] [security2:error] [pid 230252:tid 230386] [client 20.197.195.24:12309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/init.php"] [unique_id "al9J9k0Dwhk5-Z44XrpgZgAAAps"]
[Tue Jul 21 07:29:10.291255 2026] [security2:error] [pid 230252:tid 230446] [client 20.104.96.117:62436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/get.php"] [unique_id "al9J9k0Dwhk5-Z44XrpgaQAAAtc"]
[Tue Jul 21 07:29:10.385100 2026] [security2:error] [pid 229246:tid 229391] [client 59.96.220.140:52386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9J9iBMYeh5YLVG45yEPQAAAiM"]
[Tue Jul 21 07:29:10.385229 2026] [security2:error] [pid 229246:tid 229391] [client 59.96.220.140:52386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9J9iBMYeh5YLVG45yEPQAAAiM"]
[Tue Jul 21 07:29:10.584911 2026] [security2:error] [pid 230252:tid 230467] [client 20.104.96.117:62851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/as.php"] [unique_id "al9J9k0Dwhk5-Z44XrpgbAAAAuw"]
[Tue Jul 21 07:29:10.691590 2026] [security2:error] [pid 230252:tid 230462] [client 20.197.195.24:12385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/fpwch.php"] [unique_id "al9J9k0Dwhk5-Z44XrpgcAAAAuc"]
[Tue Jul 21 07:29:10.816987 2026] [autoindex:error] [pid 229246:tid 229498] [client 20.104.96.117:0] AH01276: Cannot serve directory /home1/hostag18/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:10.861676 2026] [security2:error] [pid 230252:tid 230491] [client 20.104.96.117:62870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/ccou.php"] [unique_id "al9J9k0Dwhk5-Z44XrpgcwAAAwQ"]
[Tue Jul 21 07:29:11.080176 2026] [security2:error] [pid 230252:tid 230400] [client 45.8.17.105:48009] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/filester/assets/css/404.php"] [unique_id "al9J900Dwhk5-Z44XrpgeQAAAqk"]
[Tue Jul 21 07:29:11.182614 2026] [security2:error] [pid 230252:tid 230501] [client 20.104.96.117:6275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/w3lls.php"] [unique_id "al9J900Dwhk5-Z44XrpgfAAAAw4"]
[Tue Jul 21 07:29:11.283397 2026] [security2:error] [pid 230252:tid 230435] [client 20.197.195.24:12315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/domvf.php"] [unique_id "al9J900Dwhk5-Z44XrpgfwAAAsw"]
[Tue Jul 21 07:29:11.474591 2026] [security2:error] [pid 229246:tid 229455] [client 62.102.148.164:48806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9J9yBMYeh5YLVG45yESAAAAmM"]
[Tue Jul 21 07:29:11.474683 2026] [security2:error] [pid 229246:tid 229455] [client 62.102.148.164:48806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9J9yBMYeh5YLVG45yESAAAAmM"]
[Tue Jul 21 07:29:11.507306 2026] [security2:error] [pid 229246:tid 229460] [client 20.104.96.117:62860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/test1.php"] [unique_id "al9J9yBMYeh5YLVG45yESQAAAmg"]
[Tue Jul 21 07:29:11.522036 2026] [security2:error] [pid 230252:tid 230486] [client 103.106.20.201:56851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J900Dwhk5-Z44XrpghQAAAv8"]
[Tue Jul 21 07:29:11.522207 2026] [security2:error] [pid 230252:tid 230486] [client 103.106.20.201:56851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J900Dwhk5-Z44XrpghQAAAv8"]
[Tue Jul 21 07:29:11.546131 2026] [security2:error] [pid 229246:tid 229402] [client 20.104.96.117:59617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wmore1.php"] [unique_id "al9J9yBMYeh5YLVG45yESgAAAi4"]
[Tue Jul 21 07:29:11.642685 2026] [security2:error] [pid 229246:tid 229403] [client 20.197.195.24:20489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/wp.php"] [unique_id "al9J9yBMYeh5YLVG45yESwAAAi8"]
[Tue Jul 21 07:29:11.789564 2026] [security2:error] [pid 230252:tid 230415] [client 20.104.96.117:62410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/database.php"] [unique_id "al9J900Dwhk5-Z44XrpgiwAAArg"]
[Tue Jul 21 07:29:11.819461 2026] [security2:error] [pid 230252:tid 230433] [client 172.245.102.44:56999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9J900Dwhk5-Z44XrpghgAAAso"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:11.962302 2026] [security2:error] [pid 229246:tid 229433] [client 20.151.10.161:49049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/bless.php"] [unique_id "al9J9yBMYeh5YLVG45yEVAAAAk0"]
[Tue Jul 21 07:29:11.999042 2026] [security2:error] [pid 230252:tid 230338] [remote 103.112.62.59:43202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.62.112.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "governess.com.br"] [uri "/wp-login.php"] [unique_id "al9J900Dwhk5-Z44XrpgjQAC9VM"]
[Tue Jul 21 07:29:12.119600 2026] [security2:error] [pid 230252:tid 230420] [client 20.104.96.117:62899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/file.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgkQAAAr0"]
[Tue Jul 21 07:29:12.163543 2026] [security2:error] [pid 230252:tid 230281] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgkgACvhs"]
[Tue Jul 21 07:29:12.163680 2026] [security2:error] [pid 230252:tid 230421] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgkgACvhs"]
[Tue Jul 21 07:29:12.183335 2026] [security2:error] [pid 230252:tid 230458] [client 45.8.17.138:62281] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/wp-conflg.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgkwAAAuM"]
[Tue Jul 21 07:29:12.386171 2026] [security2:error] [pid 230252:tid 230413] [client 20.197.195.24:20547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/class.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgmQAAArY"]
[Tue Jul 21 07:29:12.452725 2026] [security2:error] [pid 229246:tid 229399] [client 20.104.96.117:62885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/file.php"] [unique_id "al9J-CBMYeh5YLVG45yEWAAAAis"]
[Tue Jul 21 07:29:12.572130 2026] [security2:error] [pid 230252:tid 230329] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgmwACn0o"]
[Tue Jul 21 07:29:12.572287 2026] [security2:error] [pid 230252:tid 230390] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgmwACn0o"]
[Tue Jul 21 07:29:12.633193 2026] [security2:error] [pid 230252:tid 230367] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgnAADDnA"]
[Tue Jul 21 07:29:12.633336 2026] [security2:error] [pid 230252:tid 230501] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgnAADDnA"]
[Tue Jul 21 07:29:12.754578 2026] [security2:error] [pid 230252:tid 230451] [client 20.104.96.117:62895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/777.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgoAAAAtw"]
[Tue Jul 21 07:29:12.849530 2026] [security2:error] [pid 230252:tid 230370] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgoQACrnM"]
[Tue Jul 21 07:29:12.849708 2026] [security2:error] [pid 230252:tid 230405] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgoQACrnM"]
[Tue Jul 21 07:29:12.882982 2026] [security2:error] [pid 230252:tid 230452] [client 103.174.34.15:52100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgogAAAt0"]
[Tue Jul 21 07:29:12.883131 2026] [security2:error] [pid 230252:tid 230452] [client 103.174.34.15:52100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgogAAAt0"]
[Tue Jul 21 07:29:12.960702 2026] [fcgid:warn] [pid 229246:tid 229425] (70014)End of file found: [client 66.132.195.87:3924] mod_fcgid: can't get data from http client
[Tue Jul 21 07:29:12.989110 2026] [security2:error] [pid 230252:tid 230491] [client 154.192.233.199:60395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgpwAAAwQ"]
[Tue Jul 21 07:29:12.989371 2026] [security2:error] [pid 230252:tid 230491] [client 154.192.233.199:60395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgpwAAAwQ"]
[Tue Jul 21 07:29:13.074015 2026] [security2:error] [pid 230252:tid 230398] [client 175.45.70.82:59312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J-U0Dwhk5-Z44XrpgqAAAAqc"]
[Tue Jul 21 07:29:13.074172 2026] [security2:error] [pid 230252:tid 230398] [client 175.45.70.82:59312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J-U0Dwhk5-Z44XrpgqAAAAqc"]
[Tue Jul 21 07:29:13.186641 2026] [security2:error] [pid 230252:tid 230465] [client 45.8.17.127:35227] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/colors/modern/"] [unique_id "al9J-U0Dwhk5-Z44XrpgqQAAAuo"]
[Tue Jul 21 07:29:13.206310 2026] [security2:error] [pid 230252:tid 230411] [client 20.104.96.117:6294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/ssixta.php"] [unique_id "al9J-U0Dwhk5-Z44XrpgqgAAArQ"]
[Tue Jul 21 07:29:13.296646 2026] [security2:error] [pid 230252:tid 230412] [client 152.59.154.239:54669] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J9k0Dwhk5-Z44XrpgdwAAArU"]
[Tue Jul 21 07:29:13.296791 2026] [security2:error] [pid 230252:tid 230412] [client 152.59.154.239:54669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J9k0Dwhk5-Z44XrpgdwAAArU"]
[Tue Jul 21 07:29:13.302767 2026] [security2:error] [pid 230252:tid 230487] [client 103.162.129.114:50659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9J-U0Dwhk5-Z44XrpgrgAAAwA"]
[Tue Jul 21 07:29:13.302924 2026] [security2:error] [pid 230252:tid 230487] [client 103.162.129.114:50659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9J-U0Dwhk5-Z44XrpgrgAAAwA"]
[Tue Jul 21 07:29:13.312266 2026] [autoindex:error] [pid 230252:tid 230403] [client 82.102.18.182:60814] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:13.412736 2026] [security2:error] [pid 230252:tid 230476] [client 20.197.195.24:12374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/echkm.php"] [unique_id "al9J-U0Dwhk5-Z44XrpgsAAAAvU"]
[Tue Jul 21 07:29:13.728075 2026] [security2:error] [pid 230252:tid 230392] [client 20.197.195.24:20546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/lib.php"] [unique_id "al9J-U0Dwhk5-Z44XrpgtgAAAqE"]
[Tue Jul 21 07:29:13.755473 2026] [security2:error] [pid 230252:tid 230401] [client 20.104.96.117:62872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/1c.php"] [unique_id "al9J-U0Dwhk5-Z44XrpguAAAAqo"]
[Tue Jul 21 07:29:13.811598 2026] [autoindex:error] [pid 230252:tid 230453] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-content/cache/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:13.887541 2026] [security2:error] [pid 230252:tid 230316] [remote 65.111.22.132:52449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9J-U0Dwhk5-Z44XrpguwADAz4"]
[Tue Jul 21 07:29:14.011181 2026] [security2:error] [pid 230252:tid 230472] [client 20.197.195.24:12332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/login.php"] [unique_id "al9J-k0Dwhk5-Z44XrpgvwAAAvE"]
[Tue Jul 21 07:29:14.048011 2026] [autoindex:error] [pid 230252:tid 230451] [client 82.102.18.182:60814] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:14.131709 2026] [security2:error] [pid 230252:tid 230452] [client 20.104.96.117:62441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/test2.php"] [unique_id "al9J-k0Dwhk5-Z44XrpgwgAAAt0"]
[Tue Jul 21 07:29:14.245381 2026] [security2:error] [pid 230252:tid 230402] [client 20.197.195.24:20567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/a2.php"] [unique_id "al9J-k0Dwhk5-Z44XrpgwwAAAqs"]
[Tue Jul 21 07:29:14.272669 2026] [security2:error] [pid 230252:tid 230432] [client 20.151.10.161:49129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/file46.php"] [unique_id "al9J-k0Dwhk5-Z44XrpgxAAAAsk"]
[Tue Jul 21 07:29:14.285396 2026] [authz_core:error] [pid 230252:tid 230406] [client 82.102.18.182:0] AH01630: client denied by server configuration: /home1/asse7722/public_html/wp-content/plugins/akismet/
[Tue Jul 21 07:29:14.434240 2026] [security2:error] [pid 230252:tid 230483] [client 20.197.195.24:12349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/d61.php"] [unique_id "al9J-k0Dwhk5-Z44XrpgyQAAAvw"]
[Tue Jul 21 07:29:14.466120 2026] [security2:error] [pid 230252:tid 230429] [client 109.248.148.246:60922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9J-k0Dwhk5-Z44XrpgygAAAsY"]
[Tue Jul 21 07:29:14.466204 2026] [security2:error] [pid 230252:tid 230429] [client 109.248.148.246:60922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9J-k0Dwhk5-Z44XrpgygAAAsY"]
[Tue Jul 21 07:29:14.471407 2026] [security2:error] [pid 229246:tid 229441] [client 20.52.136.55:1487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/bolt.php"] [unique_id "al9J-iBMYeh5YLVG45yEbwAAAlU"]
[Tue Jul 21 07:29:14.498592 2026] [autoindex:error] [pid 230252:tid 230398] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:14.544793 2026] [security2:error] [pid 229246:tid 229379] [client 20.104.96.117:7066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/buy.php"] [unique_id "al9J-iBMYeh5YLVG45yEcgAAAhc"]
[Tue Jul 21 07:29:14.547892 2026] [security2:error] [pid 230252:tid 230439] [client 20.197.195.24:12300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/info.php"] [unique_id "al9J-k0Dwhk5-Z44Xrpg0AAAAtA"]
[Tue Jul 21 07:29:14.584450 2026] [security2:error] [pid 229246:tid 229407] [client 45.8.17.112:34911] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/maint/includes/"] [unique_id "al9J-iBMYeh5YLVG45yEcwAAAjM"]
[Tue Jul 21 07:29:14.606518 2026] [security2:error] [pid 230252:tid 230430] [client 20.197.195.24:20572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/11.php"] [unique_id "al9J-k0Dwhk5-Z44Xrpg0gAAAsc"]
[Tue Jul 21 07:29:14.705854 2026] [autoindex:error] [pid 230252:tid 230391] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:14.912823 2026] [autoindex:error] [pid 230252:tid 230438] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:14.925764 2026] [security2:error] [pid 229246:tid 229498] [client 20.197.195.24:20562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/v2.php"] [unique_id "al9J-iBMYeh5YLVG45yEdwAAAo4"]
[Tue Jul 21 07:29:14.936598 2026] [security2:error] [pid 230252:tid 230504] [client 20.104.96.117:62896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/ssend.php"] [unique_id "al9J-k0Dwhk5-Z44Xrpg3gAAAxE"]
[Tue Jul 21 07:29:15.120327 2026] [autoindex:error] [pid 230252:tid 230464] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:15.217747 2026] [security2:error] [pid 230252:tid 230459] [client 20.104.96.117:7083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/item.php"] [unique_id "al9J-00Dwhk5-Z44Xrpg5AAAAuQ"]
[Tue Jul 21 07:29:15.369710 2026] [autoindex:error] [pid 230252:tid 230501] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:15.567987 2026] [security2:error] [pid 230252:tid 230452] [client 20.104.96.117:7088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/ss.php"] [unique_id "al9J-00Dwhk5-Z44Xrpg7gAAAt0"]
[Tue Jul 21 07:29:15.573894 2026] [autoindex:error] [pid 230252:tid 230435] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:15.776936 2026] [security2:error] [pid 229246:tid 229402] [client 45.8.17.103:44311] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/comment-date/"] [unique_id "al9J-yBMYeh5YLVG45yEgwAAAi4"]
[Tue Jul 21 07:29:15.780283 2026] [autoindex:error] [pid 230252:tid 230491] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:15.879418 2026] [security2:error] [pid 230252:tid 230434] [client 20.104.96.117:62462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/hypo.php"] [unique_id "al9J-00Dwhk5-Z44Xrpg8gAAAss"]
[Tue Jul 21 07:29:15.985322 2026] [autoindex:error] [pid 230252:tid 230416] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:16.026686 2026] [security2:error] [pid 230252:tid 230505] [client 136.144.33.112:44409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9J_E0Dwhk5-Z44Xrpg9gAAAxI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:16.077623 2026] [security2:error] [pid 229246:tid 229488] [client 20.197.195.24:20549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/panel.php"] [unique_id "al9J_CBMYeh5YLVG45yEigAAAoQ"]
[Tue Jul 21 07:29:16.271190 2026] [security2:error] [pid 230252:tid 230456] [client 20.104.96.117:62424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/users.php"] [unique_id "al9J_E0Dwhk5-Z44Xrpg-wAAAuE"]
[Tue Jul 21 07:29:16.411645 2026] [security2:error] [pid 230252:tid 230320] [remote 5.182.209.54:39240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9J_E0Dwhk5-Z44XrphAQACm0I"]
[Tue Jul 21 07:29:16.524299 2026] [autoindex:error] [pid 229246:tid 229417] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:16.589775 2026] [security2:error] [pid 229246:tid 229448] [client 20.104.96.117:6244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/177.php"] [unique_id "al9J_CBMYeh5YLVG45yEjwAAAlw"]
[Tue Jul 21 07:29:16.698269 2026] [security2:error] [pid 230252:tid 230476] [client 20.151.10.161:49050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/eee.php"] [unique_id "al9J_E0Dwhk5-Z44XrphCgAAAvU"]
[Tue Jul 21 07:29:16.764402 2026] [autoindex:error] [pid 230252:tid 230442] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:16.873985 2026] [security2:error] [pid 230252:tid 230326] [remote 202.51.202.242:44436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9J_E0Dwhk5-Z44XrphDgAC0Ec"]
[Tue Jul 21 07:29:16.903136 2026] [security2:error] [pid 230252:tid 230426] [client 20.104.96.117:7054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/config.php"] [unique_id "al9J_E0Dwhk5-Z44XrphEAAAAsM"]
[Tue Jul 21 07:29:16.971467 2026] [autoindex:error] [pid 230252:tid 230498] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:17.092456 2026] [security2:error] [pid 230252:tid 230400] [client 45.8.17.126:58745] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/tinymce/skins/lightgray/"] [unique_id "al9J_U0Dwhk5-Z44XrphFgAAAqk"]
[Tue Jul 21 07:29:17.180398 2026] [autoindex:error] [pid 230252:tid 230477] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:17.201733 2026] [security2:error] [pid 230252:tid 230501] [client 20.104.96.117:7058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/gettest.php"] [unique_id "al9J_U0Dwhk5-Z44XrphGgAAAw4"]
[Tue Jul 21 07:29:17.387002 2026] [autoindex:error] [pid 230252:tid 230451] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:17.402996 2026] [security2:error] [pid 229246:tid 229411] [client 216.244.66.195:52216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "acheservicos.com.br"] [uri "/"] [unique_id "al9J_SBMYeh5YLVG45yEnAAAAjc"]
[Tue Jul 21 07:29:17.403103 2026] [security2:error] [pid 229246:tid 229411] [client 216.244.66.195:52216] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "acheservicos.com.br"] [uri "/"] [unique_id "al9J_SBMYeh5YLVG45yEnAAAAjc"]
[Tue Jul 21 07:29:17.497957 2026] [security2:error] [pid 229246:tid 229495] [client 20.104.96.117:6272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/min.php"] [unique_id "al9J_SBMYeh5YLVG45yEngAAAos"]
[Tue Jul 21 07:29:17.501484 2026] [security2:error] [pid 229246:tid 229420] [client 20.197.195.24:20550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/dex.php"] [unique_id "al9J_SBMYeh5YLVG45yEnwAAAkA"]
[Tue Jul 21 07:29:17.593137 2026] [autoindex:error] [pid 230252:tid 230406] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:17.763645 2026] [security2:error] [pid 230252:tid 230390] [client 45.251.232.145:56741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J_U0Dwhk5-Z44XrphJwAAAp8"]
[Tue Jul 21 07:29:17.763790 2026] [security2:error] [pid 230252:tid 230390] [client 45.251.232.145:56741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J_U0Dwhk5-Z44XrphJwAAAp8"]
[Tue Jul 21 07:29:17.782397 2026] [security2:error] [pid 230252:tid 230479] [client 20.104.96.117:7092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/dvjul.php"] [unique_id "al9J_U0Dwhk5-Z44XrphKAAAAvg"]
[Tue Jul 21 07:29:17.834765 2026] [autoindex:error] [pid 230252:tid 230391] [client 82.102.18.182:60814] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:17.913662 2026] [security2:error] [pid 230252:tid 230467] [client 74.7.230.22:34148] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "americajoseense.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9J_U0Dwhk5-Z44XrphLgAC7Cw"]
[Tue Jul 21 07:29:18.075746 2026] [autoindex:error] [pid 230252:tid 230458] [client 82.102.18.182:60814] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:18.076420 2026] [security2:error] [pid 230252:tid 230474] [client 20.104.96.117:6273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/biufile.php"] [unique_id "al9J_k0Dwhk5-Z44XrphMAAAAvM"]
[Tue Jul 21 07:29:18.184676 2026] [security2:error] [pid 230252:tid 230442] [client 109.248.148.246:45794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9J_k0Dwhk5-Z44XrphMwAAAtM"]
[Tue Jul 21 07:29:18.184778 2026] [security2:error] [pid 230252:tid 230442] [client 109.248.148.246:45794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9J_k0Dwhk5-Z44XrphMwAAAtM"]
[Tue Jul 21 07:29:18.192235 2026] [autoindex:error] [pid 230252:tid 230444] [client 66.132.195.87:24766] AH01276: Cannot serve directory /home4/ciclod61/homemsedutoronline.store/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:18.368153 2026] [security2:error] [pid 230252:tid 230453] [client 20.104.96.117:7078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/av.php"] [unique_id "al9J_k0Dwhk5-Z44XrphNwAAAt4"]
[Tue Jul 21 07:29:18.482475 2026] [security2:error] [pid 230252:tid 230472] [client 45.8.17.135:35543] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/widgets/chosen.php"] [unique_id "al9J_k0Dwhk5-Z44XrphOwAAAvE"]
[Tue Jul 21 07:29:18.511723 2026] [security2:error] [pid 230252:tid 230452] [client 20.197.195.24:12312] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "lirioshoppy.com.br"] [uri "/1.php"] [unique_id "al9J_k0Dwhk5-Z44XrphPAAAAt0"]
[Tue Jul 21 07:29:18.511896 2026] [security2:error] [pid 230252:tid 230452] [client 20.197.195.24:12312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/1.php"] [unique_id "al9J_k0Dwhk5-Z44XrphPAAAAt0"]
[Tue Jul 21 07:29:18.538097 2026] [security2:error] [pid 230252:tid 230432] [client 20.104.96.117:59634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/solo1.php"] [unique_id "al9J_k0Dwhk5-Z44XrphPwAAAsk"]
[Tue Jul 21 07:29:18.546120 2026] [security2:error] [pid 230252:tid 230277] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9J_k0Dwhk5-Z44XrphQgAC9hc"]
[Tue Jul 21 07:29:18.546230 2026] [security2:error] [pid 230252:tid 230477] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9J_k0Dwhk5-Z44XrphQgAC9hc"]
[Tue Jul 21 07:29:18.552043 2026] [security2:error] [pid 230252:tid 230394] [client 65.111.28.166:30567] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "lojaracompressores.com.br"] [uri "/"] [unique_id "al9J_k0Dwhk5-Z44XrphQwAAAqM"]
[Tue Jul 21 07:29:18.662905 2026] [security2:error] [pid 230252:tid 230411] [client 20.104.96.117:62404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/coffexium.php"] [unique_id "al9J_k0Dwhk5-Z44XrphSgAAArQ"]
[Tue Jul 21 07:29:18.759979 2026] [security2:error] [pid 230252:tid 230446] [client 109.248.148.246:45810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9J_k0Dwhk5-Z44XrphTAAAAtc"]
[Tue Jul 21 07:29:18.760092 2026] [security2:error] [pid 230252:tid 230446] [client 109.248.148.246:45810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9J_k0Dwhk5-Z44XrphTAAAAtc"]
[Tue Jul 21 07:29:18.803544 2026] [security2:error] [pid 230252:tid 230467] [client 65.111.28.166:30567] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "lojaracompressores.com.br"] [uri "/"] [unique_id "al9J_k0Dwhk5-Z44XrphTQAAAuw"]
[Tue Jul 21 07:29:18.920569 2026] [security2:error] [pid 230252:tid 230458] [client 20.197.195.24:12401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/ms.php"] [unique_id "al9J_k0Dwhk5-Z44XrphTgAAAuM"]
[Tue Jul 21 07:29:18.949196 2026] [security2:error] [pid 230252:tid 230438] [client 20.104.96.117:62448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/core.php"] [unique_id "al9J_k0Dwhk5-Z44XrphTwAAAs8"]
[Tue Jul 21 07:29:19.052394 2026] [security2:error] [pid 230252:tid 230444] [client 65.111.28.166:30567] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9J_00Dwhk5-Z44XrphVQAAAtU"]
[Tue Jul 21 07:29:19.074751 2026] [autoindex:error] [pid 230252:tid 230445] [client 20.197.195.24:20493] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:19.080064 2026] [security2:error] [pid 230252:tid 230431] [client 139.135.44.145:53275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J_00Dwhk5-Z44XrphWQAAAsg"]
[Tue Jul 21 07:29:19.080171 2026] [security2:error] [pid 230252:tid 230431] [client 139.135.44.145:53275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J_00Dwhk5-Z44XrphWQAAAsg"]
[Tue Jul 21 07:29:19.088317 2026] [security2:error] [pid 230252:tid 230392] [client 20.197.195.24:20493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/memberfuns.php"] [unique_id "al9J_00Dwhk5-Z44XrphWgAAAqE"]
[Tue Jul 21 07:29:19.229564 2026] [security2:error] [pid 230252:tid 230459] [client 20.104.96.117:62429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/als.php"] [unique_id "al9J_00Dwhk5-Z44XrphXQAAAuQ"]
[Tue Jul 21 07:29:19.248999 2026] [security2:error] [pid 230252:tid 230501] [client 20.197.195.24:12303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/0.php"] [unique_id "al9J_00Dwhk5-Z44XrphXwAAAw4"]
[Tue Jul 21 07:29:19.388346 2026] [security2:error] [pid 230252:tid 230483] [client 117.251.86.144:39700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9J_00Dwhk5-Z44XrphYAAAAvw"]
[Tue Jul 21 07:29:19.388471 2026] [security2:error] [pid 230252:tid 230483] [client 117.251.86.144:39700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9J_00Dwhk5-Z44XrphYAAAAvw"]
[Tue Jul 21 07:29:19.515602 2026] [security2:error] [pid 230252:tid 230470] [client 20.104.96.117:62880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/simple.php"] [unique_id "al9J_00Dwhk5-Z44XrphYgAAAu8"]
[Tue Jul 21 07:29:19.592071 2026] [security2:error] [pid 230252:tid 230464] [client 45.8.17.119:45897] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/theme-check/main.php"] [unique_id "al9J_00Dwhk5-Z44XrphZAAAAuk"]
[Tue Jul 21 07:29:19.675151 2026] [security2:error] [pid 230252:tid 230465] [client 20.197.195.24:12328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/BDKR28.php"] [unique_id "al9J_00Dwhk5-Z44XrphZgAAAuo"]
[Tue Jul 21 07:29:19.742834 2026] [security2:error] [pid 230252:tid 230429] [client 65.111.28.166:13273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaracompressores.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J_00Dwhk5-Z44XrphYwAAAsY"]
[Tue Jul 21 07:29:19.748823 2026] [security2:error] [pid 230252:tid 230476] [client 59.96.220.140:52871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9J_00Dwhk5-Z44XrphbAAAAvU"]
[Tue Jul 21 07:29:19.748929 2026] [security2:error] [pid 230252:tid 230476] [client 59.96.220.140:52871] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9J_00Dwhk5-Z44XrphbAAAAvU"]
[Tue Jul 21 07:29:19.808736 2026] [security2:error] [pid 229246:tid 229474] [client 20.104.96.117:7091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/init.php"] [unique_id "al9J_yBMYeh5YLVG45yEtQAAAnY"]
[Tue Jul 21 07:29:19.985088 2026] [security2:error] [pid 229246:tid 229487] [client 20.197.195.24:20568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/green1.php"] [unique_id "al9J_yBMYeh5YLVG45yEtgAAAoM"]
[Tue Jul 21 07:29:20.009292 2026] [security2:error] [pid 229246:tid 229294] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KACBMYeh5YLVG45yEuQACTy8"]
[Tue Jul 21 07:29:20.009440 2026] [security2:error] [pid 229246:tid 229435] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KACBMYeh5YLVG45yEuQACTy8"]
[Tue Jul 21 07:29:20.098873 2026] [security2:error] [pid 229246:tid 229401] [client 20.220.225.223:46108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KACBMYeh5YLVG45yEvgAAAi0"]
[Tue Jul 21 07:29:20.146466 2026] [security2:error] [pid 229246:tid 229477] [client 20.104.96.117:62439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/fpwch.php"] [unique_id "al9KACBMYeh5YLVG45yEvwAAAnk"]
[Tue Jul 21 07:29:20.273069 2026] [security2:error] [pid 229246:tid 229403] [client 65.111.28.166:32409] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "lojaracompressores.com.br"] [uri "/"] [unique_id "al9KACBMYeh5YLVG45yExAAAAi8"]
[Tue Jul 21 07:29:20.371744 2026] [security2:error] [pid 229246:tid 229484] [client 20.197.195.24:20596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/nc4.php"] [unique_id "al9KACBMYeh5YLVG45yEyQAAAoA"]
[Tue Jul 21 07:29:20.437699 2026] [security2:error] [pid 230252:tid 230482] [client 20.104.96.117:6302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/domvf.php"] [unique_id "al9KAE0Dwhk5-Z44XrphcAAAAvs"]
[Tue Jul 21 07:29:20.526601 2026] [security2:error] [pid 229246:tid 229430] [client 65.111.28.166:32409] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9KACBMYeh5YLVG45yEygAAAko"]
[Tue Jul 21 07:29:20.552626 2026] [security2:error] [pid 229246:tid 229378] [client 20.197.195.24:20483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/a1.php"] [unique_id "al9KACBMYeh5YLVG45yEywAAAhY"]
[Tue Jul 21 07:29:20.735598 2026] [security2:error] [pid 230252:tid 230500] [client 20.104.96.117:62406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/wp.php"] [unique_id "al9KAE0Dwhk5-Z44XrphdAAAAw0"]
[Tue Jul 21 07:29:20.853658 2026] [security2:error] [pid 230252:tid 230431] [client 20.197.195.24:20544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/eee.php"] [unique_id "al9KAE0Dwhk5-Z44XrphdwAAAsg"]
[Tue Jul 21 07:29:20.902018 2026] [autoindex:error] [pid 230252:tid 230415] [client 20.104.96.117:0] AH01276: Cannot serve directory /home1/hostag18/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:20.905482 2026] [security2:error] [pid 230252:tid 230454] [client 193.36.225.56:62371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9J_00Dwhk5-Z44XrphagAAAt8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:21.030590 2026] [security2:error] [pid 230252:tid 230459] [client 20.104.96.117:62443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/class.php"] [unique_id "al9KAU0Dwhk5-Z44XrphfgAAAuQ"]
[Tue Jul 21 07:29:21.044561 2026] [security2:error] [pid 230252:tid 230455] [client 65.111.28.166:16699] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9KAU0Dwhk5-Z44XrphfwAAAuA"]
[Tue Jul 21 07:29:21.178099 2026] [security2:error] [pid 230252:tid 230435] [client 20.104.96.117:59590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/cong.php"] [unique_id "al9KAU0Dwhk5-Z44XrphggAAAsw"]
[Tue Jul 21 07:29:21.192789 2026] [security2:error] [pid 230252:tid 230471] [client 20.197.195.24:12311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/wp-aothait.php"] [unique_id "al9KAU0Dwhk5-Z44XrphgwAAAvA"]
[Tue Jul 21 07:29:21.225450 2026] [security2:error] [pid 230252:tid 230483] [client 82.102.28.107:34868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KAU0Dwhk5-Z44XrphhAAAAvw"]
[Tue Jul 21 07:29:21.225542 2026] [security2:error] [pid 230252:tid 230483] [client 82.102.28.107:34868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KAU0Dwhk5-Z44XrphhAAAAvw"]
[Tue Jul 21 07:29:21.312529 2026] [security2:error] [pid 230252:tid 230423] [client 20.104.96.117:7086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/echkm.php"] [unique_id "al9KAU0Dwhk5-Z44XrphhgAAAsA"]
[Tue Jul 21 07:29:21.471375 2026] [security2:error] [pid 229246:tid 229386] [client 20.197.195.24:12342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/config.json.php"] [unique_id "al9KASBMYeh5YLVG45yE1AAAAh4"]
[Tue Jul 21 07:29:21.490984 2026] [security2:error] [pid 229246:tid 229399] [client 45.8.17.49:62579] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/css.php"] [unique_id "al9KASBMYeh5YLVG45yE1QAAAis"]
[Tue Jul 21 07:29:21.560587 2026] [security2:error] [pid 229246:tid 229393] [client 65.111.28.166:41811] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9KASBMYeh5YLVG45yE1wAAAiU"]
[Tue Jul 21 07:29:21.577631 2026] [security2:error] [pid 230252:tid 230511] [client 20.220.225.223:45961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KAU0Dwhk5-Z44XrphjwAAAxg"]
[Tue Jul 21 07:29:21.603855 2026] [security2:error] [pid 229246:tid 229419] [client 20.104.96.117:62442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/lib.php"] [unique_id "al9KASBMYeh5YLVG45yE2gAAAj8"]
[Tue Jul 21 07:29:21.633737 2026] [security2:error] [pid 229246:tid 229424] [client 82.102.28.107:34870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KASBMYeh5YLVG45yE2wAAAkQ"]
[Tue Jul 21 07:29:21.633842 2026] [security2:error] [pid 229246:tid 229424] [client 82.102.28.107:34870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KASBMYeh5YLVG45yE2wAAAkQ"]
[Tue Jul 21 07:29:21.880543 2026] [security2:error] [pid 229246:tid 229420] [client 20.104.96.117:6278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/login.php"] [unique_id "al9KASBMYeh5YLVG45yE3gAAAkA"]
[Tue Jul 21 07:29:22.006628 2026] [security2:error] [pid 229246:tid 229457] [client 20.197.195.24:20583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9KAiBMYeh5YLVG45yE4wAAAmU"]
[Tue Jul 21 07:29:22.174530 2026] [security2:error] [pid 229246:tid 229458] [client 20.104.96.117:62848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/a2.php"] [unique_id "al9KAiBMYeh5YLVG45yE5QAAAmY"]
[Tue Jul 21 07:29:22.210642 2026] [security2:error] [pid 230252:tid 230464] [client 152.59.154.239:55101] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KAk0Dwhk5-Z44XrphmgAAAuk"]
[Tue Jul 21 07:29:22.210800 2026] [security2:error] [pid 230252:tid 230464] [client 152.59.154.239:55101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KAk0Dwhk5-Z44XrphmgAAAuk"]
[Tue Jul 21 07:29:22.243309 2026] [security2:error] [pid 229246:tid 229377] [client 103.106.20.201:57468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KAiBMYeh5YLVG45yE5wAAAhU"]
[Tue Jul 21 07:29:22.243421 2026] [security2:error] [pid 229246:tid 229377] [client 103.106.20.201:57468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KAiBMYeh5YLVG45yE5wAAAhU"]
[Tue Jul 21 07:29:22.292897 2026] [security2:error] [pid 230252:tid 230415] [client 45.8.17.114:55295] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/admin.php"] [unique_id "al9KAk0Dwhk5-Z44XrphmwAAArg"]
[Tue Jul 21 07:29:22.404141 2026] [autoindex:error] [pid 230252:tid 230439] [client 82.102.18.182:33740] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:22.427184 2026] [security2:error] [pid 230252:tid 230507] [client 65.111.28.166:11763] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9KAk0Dwhk5-Z44XrphnwAAAxQ"]
[Tue Jul 21 07:29:22.451859 2026] [security2:error] [pid 230252:tid 230400] [client 20.104.96.117:62421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/d61.php"] [unique_id "al9KAk0Dwhk5-Z44XrphoAAAAqk"]
[Tue Jul 21 07:29:22.662775 2026] [security2:error] [pid 230252:tid 230313] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KAk0Dwhk5-Z44XrphpQAC3js"]
[Tue Jul 21 07:29:22.662912 2026] [security2:error] [pid 230252:tid 230453] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KAk0Dwhk5-Z44XrphpQAC3js"]
[Tue Jul 21 07:29:22.739515 2026] [security2:error] [pid 230252:tid 230472] [client 20.104.96.117:6236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/info.php"] [unique_id "al9KAk0Dwhk5-Z44XrphpgAAAvE"]
[Tue Jul 21 07:29:22.849501 2026] [security2:error] [pid 230252:tid 230429] [client 20.197.195.24:20597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/k2.php"] [unique_id "al9KAk0Dwhk5-Z44XrphqwAAAsY"]
[Tue Jul 21 07:29:22.851519 2026] [security2:error] [pid 229246:tid 229453] [client 74.7.241.174:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.alphafix.com.br"] [uri "/index.php"] [unique_id "al9KASBMYeh5YLVG45yE4QACYQI"]
[Tue Jul 21 07:29:22.870075 2026] [security2:error] [pid 230252:tid 230434] [client 213.152.162.104:44010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KAk0Dwhk5-Z44XrphrAAAAss"]
[Tue Jul 21 07:29:22.870182 2026] [security2:error] [pid 230252:tid 230434] [client 213.152.162.104:44010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KAk0Dwhk5-Z44XrphrAAAAss"]
[Tue Jul 21 07:29:22.931407 2026] [security2:error] [pid 229246:tid 229379] [client 65.111.28.166:15703] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9KAiBMYeh5YLVG45yE7wAAAhc"]
[Tue Jul 21 07:29:23.062620 2026] [security2:error] [pid 229246:tid 229497] [client 20.52.136.55:1575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/x.php"] [unique_id "al9KAyBMYeh5YLVG45yE8wAAAo0"]
[Tue Jul 21 07:29:23.072493 2026] [security2:error] [pid 229246:tid 229405] [client 20.104.96.117:6309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/11.php"] [unique_id "al9KAyBMYeh5YLVG45yE9AAAAjE"]
[Tue Jul 21 07:29:23.196770 2026] [autoindex:error] [pid 230252:tid 230482] [client 20.104.96.117:0] AH01276: Cannot serve directory /home1/hostag18/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:23.223470 2026] [security2:error] [pid 229246:tid 229412] [client 20.151.10.161:49081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/file25.php"] [unique_id "al9KAyBMYeh5YLVG45yE9wAAAjg"]
[Tue Jul 21 07:29:23.235264 2026] [security2:error] [pid 229246:tid 229257] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KAyBMYeh5YLVG45yE-AACcAo"]
[Tue Jul 21 07:29:23.235432 2026] [security2:error] [pid 229246:tid 229468] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KAyBMYeh5YLVG45yE-AACcAo"]
[Tue Jul 21 07:29:23.369585 2026] [security2:error] [pid 229246:tid 229321] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KAyBMYeh5YLVG45yE-gACd0o"]
[Tue Jul 21 07:29:23.369745 2026] [security2:error] [pid 229246:tid 229475] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KAyBMYeh5YLVG45yE-gACd0o"]
[Tue Jul 21 07:29:23.371259 2026] [security2:error] [pid 229246:tid 229329] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KAyBMYeh5YLVG45yE-wACGFI"]
[Tue Jul 21 07:29:23.371372 2026] [security2:error] [pid 229246:tid 229380] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KAyBMYeh5YLVG45yE-wACGFI"]
[Tue Jul 21 07:29:23.378249 2026] [security2:error] [pid 229246:tid 229406] [client 20.104.96.117:62414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/v2.php"] [unique_id "al9KAyBMYeh5YLVG45yE_QAAAjI"]
[Tue Jul 21 07:29:23.380659 2026] [security2:error] [pid 229246:tid 229401] [client 20.220.225.223:46081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/dp.php"] [unique_id "al9KAyBMYeh5YLVG45yE_gAAAi0"]
[Tue Jul 21 07:29:23.423374 2026] [security2:error] [pid 230252:tid 230439] [client 65.111.28.166:14557] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9KA00Dwhk5-Z44XrphuwAAAtA"]
[Tue Jul 21 07:29:23.486021 2026] [security2:error] [pid 229246:tid 229480] [client 20.104.96.117:59596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/public/css.php"] [unique_id "al9KAyBMYeh5YLVG45yFAwAAAnw"]
[Tue Jul 21 07:29:23.686281 2026] [security2:error] [pid 230252:tid 230455] [client 45.8.17.62:52579] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/2025/"] [unique_id "al9KA00Dwhk5-Z44XrphwAAAAuA"]
[Tue Jul 21 07:29:23.688347 2026] [security2:error] [pid 230252:tid 230501] [client 20.104.96.117:7096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/panel.php"] [unique_id "al9KA00Dwhk5-Z44XrphwQAAAw4"]
[Tue Jul 21 07:29:23.704991 2026] [security2:error] [pid 229246:tid 229416] [client 103.162.129.114:51102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KAyBMYeh5YLVG45yFBgAAAjw"]
[Tue Jul 21 07:29:23.705152 2026] [security2:error] [pid 229246:tid 229416] [client 103.162.129.114:51102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KAyBMYeh5YLVG45yFBgAAAjw"]
[Tue Jul 21 07:29:23.787923 2026] [security2:error] [pid 230252:tid 230475] [client 154.192.233.199:59274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KA00Dwhk5-Z44XrphxQAAAvQ"]
[Tue Jul 21 07:29:23.788235 2026] [security2:error] [pid 230252:tid 230475] [client 154.192.233.199:59274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KA00Dwhk5-Z44XrphxQAAAvQ"]
[Tue Jul 21 07:29:23.800156 2026] [security2:error] [pid 230252:tid 230467] [client 175.45.70.82:59819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KA00Dwhk5-Z44XrphxgAAAuw"]
[Tue Jul 21 07:29:23.800252 2026] [security2:error] [pid 230252:tid 230467] [client 175.45.70.82:59819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KA00Dwhk5-Z44XrphxgAAAuw"]
[Tue Jul 21 07:29:23.901113 2026] [security2:error] [pid 230252:tid 230472] [client 20.197.195.24:12333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9KA00Dwhk5-Z44XrphxwAAAvE"]
[Tue Jul 21 07:29:23.924409 2026] [security2:error] [pid 230252:tid 230442] [client 103.174.34.15:52595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KA00Dwhk5-Z44XrphyAAAAtM"]
[Tue Jul 21 07:29:23.924556 2026] [security2:error] [pid 230252:tid 230442] [client 103.174.34.15:52595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KA00Dwhk5-Z44XrphyAAAAtM"]
[Tue Jul 21 07:29:23.929783 2026] [security2:error] [pid 229246:tid 229414] [client 65.111.28.166:33081] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9KAyBMYeh5YLVG45yFBwAAAjo"]
[Tue Jul 21 07:29:24.004740 2026] [security2:error] [pid 230252:tid 230478] [client 20.104.96.117:7060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/dex.php"] [unique_id "al9KBE0Dwhk5-Z44XrphzAAAAvc"]
[Tue Jul 21 07:29:24.301207 2026] [security2:error] [pid 229246:tid 229408] [client 20.104.96.117:62865] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "politicabrasil.com.br"] [uri "/1.php"] [unique_id "al9KBCBMYeh5YLVG45yFDwAAAjQ"]
[Tue Jul 21 07:29:24.301322 2026] [security2:error] [pid 229246:tid 229408] [client 20.104.96.117:62865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/1.php"] [unique_id "al9KBCBMYeh5YLVG45yFDwAAAjQ"]
[Tue Jul 21 07:29:24.434180 2026] [security2:error] [pid 229246:tid 229448] [client 65.111.28.166:23631] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9KBCBMYeh5YLVG45yFEQAAAlw"]
[Tue Jul 21 07:29:24.633406 2026] [security2:error] [pid 230252:tid 230415] [client 20.104.96.117:62458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/ms.php"] [unique_id "al9KBE0Dwhk5-Z44Xrph1QAAArg"]
[Tue Jul 21 07:29:24.726060 2026] [security2:error] [pid 229246:tid 229451] [client 62.102.148.164:33452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KBCBMYeh5YLVG45yFFwAAAl8"]
[Tue Jul 21 07:29:24.726183 2026] [security2:error] [pid 229246:tid 229451] [client 62.102.148.164:33452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KBCBMYeh5YLVG45yFFwAAAl8"]
[Tue Jul 21 07:29:24.753919 2026] [security2:error] [pid 230252:tid 230426] [client 213.152.162.104:44018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9KBE0Dwhk5-Z44Xrph2AAAAsM"]
[Tue Jul 21 07:29:24.754024 2026] [security2:error] [pid 230252:tid 230426] [client 213.152.162.104:44018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9KBE0Dwhk5-Z44Xrph2AAAAsM"]
[Tue Jul 21 07:29:24.936981 2026] [security2:error] [pid 230252:tid 230404] [client 65.111.28.166:21351] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9KBE0Dwhk5-Z44Xrph2wAAAq0"]
[Tue Jul 21 07:29:24.989140 2026] [autoindex:error] [pid 230252:tid 230437] [client 20.104.96.117:62866] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:25.095473 2026] [security2:error] [pid 230252:tid 230501] [client 20.197.195.24:12346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9KBU0Dwhk5-Z44Xrph3QAAAw4"]
[Tue Jul 21 07:29:25.095896 2026] [security2:error] [pid 230252:tid 230486] [client 45.8.17.73:64209] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/comment-content/"] [unique_id "al9KBU0Dwhk5-Z44Xrph3gAAAv8"]
[Tue Jul 21 07:29:25.258205 2026] [autoindex:error] [pid 229246:tid 229377] [client 64.23.212.162:39808] AH01276: Cannot serve directory /home2/andr9968/artemcamadas.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:25.264933 2026] [security2:error] [pid 230252:tid 230477] [client 20.104.96.117:62866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/memberfuns.php"] [unique_id "al9KBU0Dwhk5-Z44Xrph4QAAAvY"]
[Tue Jul 21 07:29:25.444664 2026] [security2:error] [pid 230252:tid 230411] [client 65.111.28.166:63265] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9KBU0Dwhk5-Z44Xrph5QAAArQ"]
[Tue Jul 21 07:29:25.511206 2026] [security2:error] [pid 229246:tid 229395] [client 82.102.18.182:51092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wp-login.php"] [unique_id "al9KBSBMYeh5YLVG45yFJQAAAic"]
[Tue Jul 21 07:29:25.567697 2026] [security2:error] [pid 230252:tid 230429] [client 20.104.96.117:62898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/0.php"] [unique_id "al9KBU0Dwhk5-Z44Xrph5wAAAsY"]
[Tue Jul 21 07:29:25.756946 2026] [security2:error] [pid 230252:tid 230478] [client 20.197.195.24:12313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9KBU0Dwhk5-Z44Xrph7AAAAvc"]
[Tue Jul 21 07:29:25.782590 2026] [security2:error] [pid 229246:tid 229275] [remote 168.226.217.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.217.226.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KBSBMYeh5YLVG45yFKQACFxw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:29:25.782593 2026] [security2:error] [pid 229246:tid 229266] [remote 168.226.217.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.217.226.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KBSBMYeh5YLVG45yFKgACLBM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:29:25.782603 2026] [security2:error] [pid 230252:tid 230375] [remote 168.226.217.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.217.226.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KBU0Dwhk5-Z44Xrph7QADGHg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:29:25.845207 2026] [security2:error] [pid 229246:tid 229286] [remote 168.226.217.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.217.226.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KBSBMYeh5YLVG45yFKwACMCc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:29:25.846750 2026] [security2:error] [pid 229246:tid 229261] [remote 168.226.217.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.217.226.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KBSBMYeh5YLVG45yFLAACZw4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:29:25.859979 2026] [security2:error] [pid 229246:tid 229383] [client 20.104.96.117:7067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/BDKR28.php"] [unique_id "al9KBSBMYeh5YLVG45yFLQAAAhs"]
[Tue Jul 21 07:29:25.906325 2026] [security2:error] [pid 229246:tid 229362] [remote 168.226.217.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.217.226.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KBSBMYeh5YLVG45yFLgACVXM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:29:25.909282 2026] [security2:error] [pid 229246:tid 229273] [remote 168.226.217.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.217.226.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KBSBMYeh5YLVG45yFLwACiBo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:29:25.910526 2026] [security2:error] [pid 230252:tid 230278] [remote 168.226.217.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.217.226.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KBU0Dwhk5-Z44Xrph7wAC6hg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:29:25.965955 2026] [security2:error] [pid 230252:tid 230368] [remote 168.226.217.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.217.226.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KBU0Dwhk5-Z44Xrph8AACsXE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:29:26.006506 2026] [security2:error] [pid 229246:tid 229332] [remote 168.226.217.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.217.226.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KBiBMYeh5YLVG45yFMQACT1U"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:29:26.148862 2026] [security2:error] [pid 230252:tid 230432] [client 20.104.96.117:7043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/green1.php"] [unique_id "al9KBk0Dwhk5-Z44Xrph9QAAAsk"]
[Tue Jul 21 07:29:26.343375 2026] [security2:error] [pid 229246:tid 229493] [client 173.24.185.52:65270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KBSBMYeh5YLVG45yFIQAAAok"]
[Tue Jul 21 07:29:26.343580 2026] [security2:error] [pid 229246:tid 229493] [client 173.24.185.52:65270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KBSBMYeh5YLVG45yFIQAAAok"]
[Tue Jul 21 07:29:26.374397 2026] [autoindex:error] [pid 230252:tid 230504] [client 64.23.212.162:36412] AH01276: Cannot serve directory /home2/andr9968/artemcamadas.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:26.425114 2026] [security2:error] [pid 229246:tid 229406] [client 20.104.96.117:62853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/nc4.php"] [unique_id "al9KBiBMYeh5YLVG45yFOgAAAjI"]
[Tue Jul 21 07:29:26.484492 2026] [security2:error] [pid 229246:tid 229481] [client 45.8.17.129:52521] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/images/"] [unique_id "al9KBiBMYeh5YLVG45yFOwAAAn0"]
[Tue Jul 21 07:29:26.607736 2026] [security2:error] [pid 230252:tid 230507] [client 82.102.18.182:51102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wp-login.php"] [unique_id "al9KBk0Dwhk5-Z44Xrph-gAAAxQ"]
[Tue Jul 21 07:29:26.646377 2026] [security2:error] [pid 230252:tid 230404] [client 20.104.96.117:42274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/output.php"] [unique_id "al9KBk0Dwhk5-Z44Xrph_AAAAq0"]
[Tue Jul 21 07:29:26.765608 2026] [security2:error] [pid 230252:tid 230437] [client 20.104.96.117:6296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/a1.php"] [unique_id "al9KBk0Dwhk5-Z44Xrph_QAAAs4"]
[Tue Jul 21 07:29:26.769956 2026] [security2:error] [pid 229246:tid 229484] [client 20.151.10.161:49058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/file48.php"] [unique_id "al9KBiBMYeh5YLVG45yFQgAAAoA"]
[Tue Jul 21 07:29:26.779535 2026] [security2:error] [pid 230252:tid 230363] [remote 168.226.217.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.217.226.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KBU0Dwhk5-Z44Xrph7gAC4Ww"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:29:26.863362 2026] [security2:error] [pid 230252:tid 230471] [client 20.197.195.24:20595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/for.php"] [unique_id "al9KBk0Dwhk5-Z44XrpiAQAAAvA"]
[Tue Jul 21 07:29:26.998808 2026] [security2:error] [pid 229246:tid 229488] [client 82.102.28.107:49466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KBiBMYeh5YLVG45yFRwAAAoQ"]
[Tue Jul 21 07:29:26.998959 2026] [security2:error] [pid 229246:tid 229488] [client 82.102.28.107:49466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KBiBMYeh5YLVG45yFRwAAAoQ"]
[Tue Jul 21 07:29:27.093364 2026] [security2:error] [pid 229246:tid 229408] [client 20.104.96.117:7052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/eee.php"] [unique_id "al9KByBMYeh5YLVG45yFSwAAAjQ"]
[Tue Jul 21 07:29:27.400328 2026] [security2:error] [pid 230252:tid 230411] [client 20.104.96.117:62437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/wp-aothait.php"] [unique_id "al9KB00Dwhk5-Z44XrpiCAAAArQ"]
[Tue Jul 21 07:29:27.482804 2026] [autoindex:error] [pid 230252:tid 230429] [client 82.102.18.182:33740] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:27.758310 2026] [security2:error] [pid 229246:tid 229381] [client 20.104.96.117:6291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/config.json.php"] [unique_id "al9KByBMYeh5YLVG45yFWAAAAhk"]
[Tue Jul 21 07:29:27.777078 2026] [security2:error] [pid 230252:tid 230468] [client 20.197.195.24:20553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/raw.php"] [unique_id "al9KB00Dwhk5-Z44XrpiDwAAAu0"]
[Tue Jul 21 07:29:28.079390 2026] [security2:error] [pid 229246:tid 229377] [client 20.104.96.117:62887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9KCCBMYeh5YLVG45yFXAAAAhU"]
[Tue Jul 21 07:29:28.080040 2026] [security2:error] [pid 229246:tid 229427] [client 45.8.17.124:30231] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/options.php"] [unique_id "al9KCCBMYeh5YLVG45yFXQAAAkc"]
[Tue Jul 21 07:29:28.238423 2026] [security2:error] [pid 230252:tid 230423] [client 45.251.232.145:57270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KCE0Dwhk5-Z44XrpiEwAAAsA"]
[Tue Jul 21 07:29:28.238549 2026] [security2:error] [pid 230252:tid 230423] [client 45.251.232.145:57270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KCE0Dwhk5-Z44XrpiEwAAAsA"]
[Tue Jul 21 07:29:28.325605 2026] [security2:error] [pid 229246:tid 229459] [client 20.104.96.117:42406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-file-120.php"] [unique_id "al9KCCBMYeh5YLVG45yFZAAAAmc"]
[Tue Jul 21 07:29:28.376362 2026] [security2:error] [pid 230252:tid 230443] [client 37.140.223.68:47785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KCE0Dwhk5-Z44XrpiEgAAAtQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:28.385892 2026] [security2:error] [pid 229246:tid 229489] [client 20.104.96.117:6257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/k2.php"] [unique_id "al9KCCBMYeh5YLVG45yFZgAAAoU"]
[Tue Jul 21 07:29:28.579197 2026] [security2:error] [pid 229246:tid 229502] [client 82.102.18.182:56300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wp-login.php"] [unique_id "al9KCCBMYeh5YLVG45yFaAAAApI"]
[Tue Jul 21 07:29:28.702418 2026] [security2:error] [pid 229246:tid 229405] [client 20.104.96.117:7100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9KCCBMYeh5YLVG45yFbAAAAjE"]
[Tue Jul 21 07:29:28.763277 2026] [security2:error] [pid 230252:tid 230407] [client 47.128.44.140:32346] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "clinicaleonazevedo.com.br"] [uri "/robots.txt"] [unique_id "al9KCE0Dwhk5-Z44XrpiFQAAArA"]
[Tue Jul 21 07:29:28.783689 2026] [autoindex:error] [pid 229246:tid 229401] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:28.978575 2026] [security2:error] [pid 229246:tid 229430] [client 20.104.96.117:7053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9KCCBMYeh5YLVG45yFdgAAAko"]
[Tue Jul 21 07:29:29.077637 2026] [security2:error] [pid 230252:tid 230381] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KCU0Dwhk5-Z44XrpiGAACzH4"]
[Tue Jul 21 07:29:29.077782 2026] [security2:error] [pid 230252:tid 230435] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KCU0Dwhk5-Z44XrpiGAACzH4"]
[Tue Jul 21 07:29:29.178646 2026] [security2:error] [pid 230252:tid 230454] [client 20.104.96.117:42421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/special.php"] [unique_id "al9KCU0Dwhk5-Z44XrpiGQAAAt8"]
[Tue Jul 21 07:29:29.267530 2026] [security2:error] [pid 230252:tid 230404] [client 20.104.96.117:62431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9KCU0Dwhk5-Z44XrpiHAAAAq0"]
[Tue Jul 21 07:29:29.440095 2026] [security2:error] [pid 229246:tid 229472] [client 20.220.225.223:8944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/zzz.php"] [unique_id "al9KCSBMYeh5YLVG45yFgAAAAnQ"]
[Tue Jul 21 07:29:29.578765 2026] [security2:error] [pid 230252:tid 230471] [client 20.104.96.117:62451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/for.php"] [unique_id "al9KCU0Dwhk5-Z44XrpiIgAAAvA"]
[Tue Jul 21 07:29:29.876782 2026] [security2:error] [pid 230252:tid 230446] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9KCU0Dwhk5-Z44XrpiJwAAAtc"]
[Tue Jul 21 07:29:29.950128 2026] [security2:error] [pid 229246:tid 229381] [client 20.104.96.117:62883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/raw.php"] [unique_id "al9KCSBMYeh5YLVG45yFiQAAAhk"]
[Tue Jul 21 07:29:30.131357 2026] [security2:error] [pid 229246:tid 229478] [client 139.135.44.145:54063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KCiBMYeh5YLVG45yFjQAAAno"]
[Tue Jul 21 07:29:30.131486 2026] [security2:error] [pid 229246:tid 229478] [client 139.135.44.145:54063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KCiBMYeh5YLVG45yFjQAAAno"]
[Tue Jul 21 07:29:30.166427 2026] [security2:error] [pid 230252:tid 230478] [client 143.244.57.121:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KCk0Dwhk5-Z44XrpiKQAAAvc"]
[Tue Jul 21 07:29:30.198093 2026] [security2:error] [pid 229246:tid 229396] [client 20.104.96.117:59797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/as.php"] [unique_id "al9KCiBMYeh5YLVG45yFjgAAAig"]
[Tue Jul 21 07:29:30.238039 2026] [security2:error] [pid 230252:tid 230486] [client 117.251.86.144:36512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KCk0Dwhk5-Z44XrpiKgAAAv8"]
[Tue Jul 21 07:29:30.238177 2026] [security2:error] [pid 230252:tid 230486] [client 117.251.86.144:36512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KCk0Dwhk5-Z44XrpiKgAAAv8"]
[Tue Jul 21 07:29:30.545915 2026] [security2:error] [pid 230252:tid 230343] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KCk0Dwhk5-Z44XrpiMAAC1Vg"]
[Tue Jul 21 07:29:30.546131 2026] [security2:error] [pid 230252:tid 230444] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KCk0Dwhk5-Z44XrpiMAAC1Vg"]
[Tue Jul 21 07:29:30.613586 2026] [security2:error] [pid 229246:tid 229379] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9KCiBMYeh5YLVG45yFlwAAAhc"]
[Tue Jul 21 07:29:30.885199 2026] [security2:error] [pid 229246:tid 229492] [client 45.8.17.145:47829] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/chosen.php"] [unique_id "al9KCiBMYeh5YLVG45yFnAAAAog"]
[Tue Jul 21 07:29:30.898486 2026] [security2:error] [pid 229246:tid 229479] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9KCiBMYeh5YLVG45yFnQAAAns"]
[Tue Jul 21 07:29:31.027632 2026] [security2:error] [pid 230252:tid 230500] [client 173.239.211.139:32571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.211.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9KC00Dwhk5-Z44XrpiNAAAAw0"]
[Tue Jul 21 07:29:31.028291 2026] [security2:error] [pid 229246:tid 229377] [client 173.239.211.139:60591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.211.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9KCyBMYeh5YLVG45yFnwAAAhU"]
[Tue Jul 21 07:29:31.029827 2026] [security2:error] [pid 230252:tid 230474] [client 173.239.211.122:38649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.211.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9KC00Dwhk5-Z44XrpiMwAAAvM"]
[Tue Jul 21 07:29:31.183812 2026] [security2:error] [pid 230252:tid 230400] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9KC00Dwhk5-Z44XrpiNwAAAqk"]
[Tue Jul 21 07:29:31.221169 2026] [security2:error] [pid 230252:tid 230440] [client 59.96.220.140:53337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KC00Dwhk5-Z44XrpiOwAAAtE"]
[Tue Jul 21 07:29:31.221290 2026] [security2:error] [pid 230252:tid 230440] [client 59.96.220.140:53337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KC00Dwhk5-Z44XrpiOwAAAtE"]
[Tue Jul 21 07:29:31.487470 2026] [security2:error] [pid 230252:tid 230452] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9KC00Dwhk5-Z44XrpiQAAAAt0"]
[Tue Jul 21 07:29:31.574294 2026] [security2:error] [pid 229246:tid 229474] [client 20.104.96.117:59622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9KCyBMYeh5YLVG45yFpQAAAnY"]
[Tue Jul 21 07:29:31.773755 2026] [security2:error] [pid 229246:tid 229416] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9KCyBMYeh5YLVG45yFqwAAAjw"]
[Tue Jul 21 07:29:31.845098 2026] [security2:error] [pid 229246:tid 229403] [client 20.52.136.55:1741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/jga.php"] [unique_id "al9KCyBMYeh5YLVG45yFrAAAAi8"]
[Tue Jul 21 07:29:31.884099 2026] [security2:error] [pid 229246:tid 229378] [client 45.8.17.65:21213] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/images/as.php"] [unique_id "al9KCyBMYeh5YLVG45yFsAAAAhY"]
[Tue Jul 21 07:29:32.061247 2026] [security2:error] [pid 229246:tid 229460] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9KDCBMYeh5YLVG45yFswAAAmg"]
[Tue Jul 21 07:29:32.345974 2026] [security2:error] [pid 230252:tid 230429] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9KDE0Dwhk5-Z44XrpiQgAAAsY"]
[Tue Jul 21 07:29:32.560938 2026] [security2:error] [pid 230252:tid 230509] [client 20.151.10.161:48613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/file6.php"] [unique_id "al9KDE0Dwhk5-Z44XrpiQwAAAxY"]
[Tue Jul 21 07:29:32.630577 2026] [security2:error] [pid 229246:tid 229425] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9KDCBMYeh5YLVG45yFwgAAAkU"]
[Tue Jul 21 07:29:32.783187 2026] [security2:error] [pid 229246:tid 229442] [client 45.8.17.129:50043] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-security.php"] [unique_id "al9KDCBMYeh5YLVG45yFygAAAlY"]
[Tue Jul 21 07:29:32.914972 2026] [security2:error] [pid 229246:tid 229400] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9KDCBMYeh5YLVG45yFzwAAAiw"]
[Tue Jul 21 07:29:32.962830 2026] [security2:error] [pid 229246:tid 229437] [client 103.106.20.201:58028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDCBMYeh5YLVG45yF0AAAAlE"]
[Tue Jul 21 07:29:32.963005 2026] [security2:error] [pid 229246:tid 229437] [client 103.106.20.201:58028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDCBMYeh5YLVG45yF0AAAAlE"]
[Tue Jul 21 07:29:33.184727 2026] [security2:error] [pid 229246:tid 229373] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KDSBMYeh5YLVG45yF1QAChX4"]
[Tue Jul 21 07:29:33.184858 2026] [security2:error] [pid 229246:tid 229489] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KDSBMYeh5YLVG45yF1QAChX4"]
[Tue Jul 21 07:29:33.199559 2026] [security2:error] [pid 229246:tid 229497] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9KDSBMYeh5YLVG45yF1gAAAo0"]
[Tue Jul 21 07:29:33.309655 2026] [security2:error] [pid 229246:tid 229475] [client 20.104.96.117:59805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/w1px.php"] [unique_id "al9KDSBMYeh5YLVG45yF2AAAAnc"]
[Tue Jul 21 07:29:33.484994 2026] [security2:error] [pid 229246:tid 229406] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9KDSBMYeh5YLVG45yF3AAAAjI"]
[Tue Jul 21 07:29:33.638482 2026] [security2:error] [pid 229246:tid 229483] [client 37.140.223.68:39299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KDSBMYeh5YLVG45yF4AAAAn8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:33.719912 2026] [security2:error] [pid 229246:tid 229407] [client 152.59.154.239:55529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDSBMYeh5YLVG45yF4gAAAjM"]
[Tue Jul 21 07:29:33.720038 2026] [security2:error] [pid 229246:tid 229407] [client 152.59.154.239:55529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDSBMYeh5YLVG45yF4gAAAjM"]
[Tue Jul 21 07:29:33.720358 2026] [security2:error] [pid 230252:tid 230462] [client 20.220.225.223:8953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/wicked.php"] [unique_id "al9KDU0Dwhk5-Z44XrpiRwAAAuc"]
[Tue Jul 21 07:29:33.787607 2026] [security2:error] [pid 230252:tid 230423] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9KDU0Dwhk5-Z44XrpiSAAAAsA"]
[Tue Jul 21 07:29:33.860085 2026] [security2:error] [pid 230252:tid 230334] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDU0Dwhk5-Z44XrpiSgAC_08"]
[Tue Jul 21 07:29:33.860261 2026] [security2:error] [pid 230252:tid 230486] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDU0Dwhk5-Z44XrpiSgAC_08"]
[Tue Jul 21 07:29:33.871733 2026] [security2:error] [pid 230252:tid 230482] [client 213.152.162.104:53258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KDU0Dwhk5-Z44XrpiSwAAAvs"]
[Tue Jul 21 07:29:33.871834 2026] [security2:error] [pid 230252:tid 230482] [client 213.152.162.104:53258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KDU0Dwhk5-Z44XrpiSwAAAvs"]
[Tue Jul 21 07:29:33.931606 2026] [security2:error] [pid 230252:tid 230350] [remote 91.142.222.105:46778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roha.life"] [uri "/wp-login.php"] [unique_id "al9KDU0Dwhk5-Z44XrpiTAACz18"]
[Tue Jul 21 07:29:33.980837 2026] [security2:error] [pid 230252:tid 230386] [client 45.8.17.115:22023] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/system.php"] [unique_id "al9KDU0Dwhk5-Z44XrpiTQAAAps"]
[Tue Jul 21 07:29:33.986003 2026] [security2:error] [pid 229246:tid 229274] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KDSBMYeh5YLVG45yF5QACIRs"]
[Tue Jul 21 07:29:33.986121 2026] [security2:error] [pid 229246:tid 229389] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KDSBMYeh5YLVG45yF5QACIRs"]
[Tue Jul 21 07:29:34.016654 2026] [security2:error] [pid 229246:tid 229343] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KDiBMYeh5YLVG45yF5gACOmA"]
[Tue Jul 21 07:29:34.016776 2026] [security2:error] [pid 229246:tid 229414] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KDiBMYeh5YLVG45yF5gACOmA"]
[Tue Jul 21 07:29:34.072091 2026] [security2:error] [pid 229246:tid 229455] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9KDiBMYeh5YLVG45yF6AAAAmM"]
[Tue Jul 21 07:29:34.110197 2026] [security2:error] [pid 230252:tid 230500] [client 20.151.10.161:49145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/a2.php"] [unique_id "al9KDk0Dwhk5-Z44XrpiUAAAAw0"]
[Tue Jul 21 07:29:34.180848 2026] [security2:error] [pid 230252:tid 230508] [client 103.162.129.114:51547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KDk0Dwhk5-Z44XrpiUQAAAxU"]
[Tue Jul 21 07:29:34.180983 2026] [security2:error] [pid 230252:tid 230508] [client 103.162.129.114:51547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KDk0Dwhk5-Z44XrpiUQAAAxU"]
[Tue Jul 21 07:29:34.356331 2026] [security2:error] [pid 230252:tid 230404] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9KDk0Dwhk5-Z44XrpiVQAAAq0"]
[Tue Jul 21 07:29:34.358311 2026] [security2:error] [pid 230252:tid 230458] [client 154.192.233.199:60305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDk0Dwhk5-Z44XrpiVAAAAuM"]
[Tue Jul 21 07:29:34.358434 2026] [security2:error] [pid 230252:tid 230458] [client 154.192.233.199:60305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDk0Dwhk5-Z44XrpiVAAAAuM"]
[Tue Jul 21 07:29:34.475229 2026] [security2:error] [pid 229246:tid 229416] [client 175.45.70.82:60331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDiBMYeh5YLVG45yF8AAAAjw"]
[Tue Jul 21 07:29:34.475351 2026] [security2:error] [pid 229246:tid 229416] [client 175.45.70.82:60331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDiBMYeh5YLVG45yF8AAAAjw"]
[Tue Jul 21 07:29:34.641726 2026] [security2:error] [pid 229246:tid 229423] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9KDiBMYeh5YLVG45yF8wAAAkM"]
[Tue Jul 21 07:29:34.677977 2026] [security2:error] [pid 229246:tid 229454] [client 20.104.96.117:59594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/yawa.php"] [unique_id "al9KDiBMYeh5YLVG45yF9QAAAmI"]
[Tue Jul 21 07:29:34.686607 2026] [security2:error] [pid 229246:tid 229378] [client 103.174.34.15:53084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDiBMYeh5YLVG45yF9gAAAhY"]
[Tue Jul 21 07:29:34.686690 2026] [security2:error] [pid 229246:tid 229378] [client 103.174.34.15:53084] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDiBMYeh5YLVG45yF9gAAAhY"]
[Tue Jul 21 07:29:34.931386 2026] [security2:error] [pid 230252:tid 230393] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9KDk0Dwhk5-Z44XrpiWQAAAqI"]
[Tue Jul 21 07:29:35.072112 2026] [security2:error] [pid 230252:tid 230466] [client 20.220.225.223:46116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/old.php"] [unique_id "al9KD00Dwhk5-Z44XrpiWgAAAus"]
[Tue Jul 21 07:29:35.084992 2026] [security2:error] [pid 230252:tid 230479] [client 45.8.17.118:35933] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/header.php"] [unique_id "al9KD00Dwhk5-Z44XrpiWwAAAvg"]
[Tue Jul 21 07:29:35.390165 2026] [security2:error] [pid 229246:tid 229390] [client 82.102.28.107:40954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KDyBMYeh5YLVG45yF_wAAAiI"]
[Tue Jul 21 07:29:35.390265 2026] [security2:error] [pid 229246:tid 229390] [client 82.102.28.107:40954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KDyBMYeh5YLVG45yF_wAAAiI"]
[Tue Jul 21 07:29:35.392017 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:49132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/file15.php"] [unique_id "al9KD00Dwhk5-Z44XrpiXgAAAwY"]
[Tue Jul 21 07:29:35.481936 2026] [security2:error] [pid 230252:tid 230453] [client 173.24.185.52:49438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KD00Dwhk5-Z44XrpiXwAAAt4"]
[Tue Jul 21 07:29:35.482058 2026] [security2:error] [pid 230252:tid 230453] [client 173.24.185.52:49438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KD00Dwhk5-Z44XrpiXwAAAt4"]
[Tue Jul 21 07:29:36.097584 2026] [security2:error] [pid 229246:tid 229471] [client 45.8.17.112:52899] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/fonts/"] [unique_id "al9KECBMYeh5YLVG45yGEAAAAnM"]
[Tue Jul 21 07:29:36.159902 2026] [security2:error] [pid 229246:tid 229475] [client 20.104.96.117:59789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/js.php"] [unique_id "al9KECBMYeh5YLVG45yGEgAAAnc"]
[Tue Jul 21 07:29:36.729577 2026] [security2:error] [pid 230252:tid 230265] [remote 104.207.39.78:60793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.39.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9KD00Dwhk5-Z44XrpiYAADDAs"]
[Tue Jul 21 07:29:36.999651 2026] [security2:error] [pid 230252:tid 230507] [client 20.151.10.161:49025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/jp.php"] [unique_id "al9KEE0Dwhk5-Z44XrpicQAAAxQ"]
[Tue Jul 21 07:29:37.284586 2026] [security2:error] [pid 230252:tid 230410] [client 45.8.17.59:62495] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/colors/ocean/"] [unique_id "al9KEU0Dwhk5-Z44XrpicwAAArM"]
[Tue Jul 21 07:29:38.083847 2026] [security2:error] [pid 230252:tid 230470] [client 45.8.17.132:39409] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/a.php"] [unique_id "al9KEk0Dwhk5-Z44XrpifQAAAu8"]
[Tue Jul 21 07:29:38.350371 2026] [security2:error] [pid 230252:tid 230445] [client 136.144.33.101:31349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KEk0Dwhk5-Z44XrpifwAAAtY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:38.716562 2026] [security2:error] [pid 229246:tid 229424] [client 45.251.232.145:57796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KEiBMYeh5YLVG45yGNgAAAkQ"]
[Tue Jul 21 07:29:38.716660 2026] [security2:error] [pid 229246:tid 229424] [client 45.251.232.145:57796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KEiBMYeh5YLVG45yGNgAAAkQ"]
[Tue Jul 21 07:29:38.789878 2026] [security2:error] [pid 229246:tid 229464] [client 20.52.136.55:1566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/k.php"] [unique_id "al9KEiBMYeh5YLVG45yGNwAAAmw"]
[Tue Jul 21 07:29:39.638280 2026] [security2:error] [pid 229246:tid 229272] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KEyBMYeh5YLVG45yGQwACVBk"]
[Tue Jul 21 07:29:39.638445 2026] [security2:error] [pid 229246:tid 229440] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KEyBMYeh5YLVG45yGQwACVBk"]
[Tue Jul 21 07:29:39.956892 2026] [security2:error] [pid 229246:tid 229483] [client 20.151.10.161:49115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/f35.php"] [unique_id "al9KEyBMYeh5YLVG45yGSQAAAn8"]
[Tue Jul 21 07:29:39.996153 2026] [security2:error] [pid 229246:tid 229401] [client 45.8.17.114:60943] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "al9KEyBMYeh5YLVG45yGTQAAAi0"]
[Tue Jul 21 07:29:40.098810 2026] [security2:error] [pid 229246:tid 229328] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sandrareginaprata1781718333175.0711679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9KFCBMYeh5YLVG45yGUAACHVE"]
[Tue Jul 21 07:29:40.187007 2026] [security2:error] [pid 230252:tid 230431] [client 34.26.127.63:60289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.127.26.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "startonesite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KFE0Dwhk5-Z44XrpiiwAAAsg"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:29:40.738025 2026] [security2:error] [pid 230252:tid 230473] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sandrareginaprata1781718333175.0711679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9KFE0Dwhk5-Z44XrpilQAAAvI"]
[Tue Jul 21 07:29:40.822023 2026] [security2:error] [pid 230252:tid 230416] [client 59.96.220.140:53812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KFE0Dwhk5-Z44XrpilgAAArk"]
[Tue Jul 21 07:29:40.822129 2026] [security2:error] [pid 230252:tid 230416] [client 59.96.220.140:53812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KFE0Dwhk5-Z44XrpilgAAArk"]
[Tue Jul 21 07:29:40.850514 2026] [security2:error] [pid 229246:tid 229389] [client 117.251.86.144:35996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KFCBMYeh5YLVG45yGYgAAAiE"]
[Tue Jul 21 07:29:40.850606 2026] [security2:error] [pid 229246:tid 229389] [client 117.251.86.144:35996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KFCBMYeh5YLVG45yGYgAAAiE"]
[Tue Jul 21 07:29:40.924060 2026] [security2:error] [pid 230252:tid 230501] [client 34.26.127.63:62762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9KFE0Dwhk5-Z44XrpilwAAAw4"]
[Tue Jul 21 07:29:40.973700 2026] [security2:error] [pid 229246:tid 229469] [client 139.135.44.145:54877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KFCBMYeh5YLVG45yGYwAAAnE"]
[Tue Jul 21 07:29:40.973844 2026] [security2:error] [pid 229246:tid 229469] [client 139.135.44.145:54877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KFCBMYeh5YLVG45yGYwAAAnE"]
[Tue Jul 21 07:29:41.090846 2026] [security2:error] [pid 230252:tid 230470] [client 20.104.96.117:59600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/core.php"] [unique_id "al9KFU0Dwhk5-Z44XrpimwAAAu8"]
[Tue Jul 21 07:29:41.345541 2026] [autoindex:error] [pid 229246:tid 229421] [client 98.91.173.173:57554] AH01276: Cannot serve directory /home2/kncont40/knplay.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:41.465804 2026] [security2:error] [pid 230252:tid 230394] [client 34.26.127.63:54492] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9KFU0Dwhk5-Z44XrpingAAAqM"]
[Tue Jul 21 07:29:41.736376 2026] [security2:error] [pid 230252:tid 230449] [client 136.144.33.28:42605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KFU0Dwhk5-Z44XrpiowAAAto"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:42.051385 2026] [security2:error] [pid 229246:tid 229497] [client 109.248.148.246:37428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KFiBMYeh5YLVG45yGdQAAAo0"]
[Tue Jul 21 07:29:42.051491 2026] [security2:error] [pid 229246:tid 229497] [client 109.248.148.246:37428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KFiBMYeh5YLVG45yGdQAAAo0"]
[Tue Jul 21 07:29:42.080217 2026] [security2:error] [pid 229246:tid 229489] [client 34.26.127.63:52278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9KFiBMYeh5YLVG45yGeAAAAoU"]
[Tue Jul 21 07:29:42.286111 2026] [security2:error] [pid 230252:tid 230503] [client 45.8.17.132:61029] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Requests/src/Exception/Transport/"] [unique_id "al9KFk0Dwhk5-Z44XrpiqgAAAxA"]
[Tue Jul 21 07:29:42.300551 2026] [security2:error] [pid 230252:tid 230499] [client 62.102.148.164:44312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9KFk0Dwhk5-Z44XrpiqwAAAww"]
[Tue Jul 21 07:29:42.300624 2026] [security2:error] [pid 230252:tid 230499] [client 62.102.148.164:44312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9KFk0Dwhk5-Z44XrpiqwAAAww"]
[Tue Jul 21 07:29:42.456273 2026] [security2:error] [pid 230252:tid 230461] [client 20.151.10.161:48612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-load.php"] [unique_id "al9KFk0Dwhk5-Z44XrpirQAAAuY"]
[Tue Jul 21 07:29:42.901278 2026] [security2:error] [pid 230252:tid 230410] [client 34.26.127.63:55432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9KFk0Dwhk5-Z44XrpitAAAArM"]
[Tue Jul 21 07:29:43.129453 2026] [security2:error] [pid 230252:tid 230348] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sandrareginaprata1781718333175.0711679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9KF00Dwhk5-Z44XrpitgAC8F0"]
[Tue Jul 21 07:29:43.511683 2026] [security2:error] [pid 230252:tid 230439] [client 34.26.127.63:54778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9KF00Dwhk5-Z44XrpivAAAAtA"]
[Tue Jul 21 07:29:43.653677 2026] [security2:error] [pid 230252:tid 230456] [client 103.106.20.201:58610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KF00Dwhk5-Z44XrpivgAAAuE"]
[Tue Jul 21 07:29:43.653830 2026] [security2:error] [pid 230252:tid 230456] [client 103.106.20.201:58610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KF00Dwhk5-Z44XrpivgAAAuE"]
[Tue Jul 21 07:29:43.689856 2026] [security2:error] [pid 229246:tid 229430] [client 45.8.17.131:60993] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/network/"] [unique_id "al9KFyBMYeh5YLVG45yGjAAAAko"]
[Tue Jul 21 07:29:43.713345 2026] [security2:error] [pid 229246:tid 229346] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KFyBMYeh5YLVG45yGjgACdGM"]
[Tue Jul 21 07:29:43.713656 2026] [security2:error] [pid 229246:tid 229472] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KFyBMYeh5YLVG45yGjgACdGM"]
[Tue Jul 21 07:29:43.723177 2026] [security2:error] [pid 230252:tid 230453] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sandrareginaprata1781718333175.0711679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9KF00Dwhk5-Z44XrpivwAAAt4"]
[Tue Jul 21 07:29:44.023953 2026] [security2:error] [pid 229246:tid 229484] [client 20.151.10.161:49053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/xwpg.php"] [unique_id "al9KGCBMYeh5YLVG45yGlgAAAoA"]
[Tue Jul 21 07:29:44.039696 2026] [security2:error] [pid 229246:tid 229336] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KGCBMYeh5YLVG45yGlwACXVk"]
[Tue Jul 21 07:29:44.039876 2026] [security2:error] [pid 229246:tid 229449] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KGCBMYeh5YLVG45yGlwACXVk"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:29:44.240124 2026] [security2:error] [pid 230252:tid 230391] [client 20.220.225.223:46091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/ms-new.php"] [unique_id "al9KGE0Dwhk5-Z44XrpiyAAAAqA"]
[Tue Jul 21 07:29:44.260130 2026] [security2:error] [pid 229246:tid 229417] [client 34.26.127.63:50044] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9KGCBMYeh5YLVG45yGmwAAAj0"]
[Tue Jul 21 07:29:44.287159 2026] [security2:error] [pid 229246:tid 229490] [client 20.197.192.193:47951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KGCBMYeh5YLVG45yGnAAAAoY"]
[Tue Jul 21 07:29:44.317514 2026] [security2:error] [pid 229246:tid 229446] [client 20.197.192.193:30296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KGCBMYeh5YLVG45yGngAAAlo"]
[Tue Jul 21 07:29:44.370298 2026] [security2:error] [pid 230252:tid 230506] [client 20.197.192.193:47976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/dp.php"] [unique_id "al9KGE0Dwhk5-Z44XrpizAAAAxM"]
[Tue Jul 21 07:29:44.390786 2026] [security2:error] [pid 229246:tid 229350] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KGCBMYeh5YLVG45yGnwACQGc"]
[Tue Jul 21 07:29:44.391011 2026] [security2:error] [pid 229246:tid 229420] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KGCBMYeh5YLVG45yGnwACQGc"]
[Tue Jul 21 07:29:44.419404 2026] [security2:error] [pid 229246:tid 229478] [client 20.197.192.193:30332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/old.php"] [unique_id "al9KGCBMYeh5YLVG45yGowAAAno"]
[Tue Jul 21 07:29:44.450652 2026] [security2:error] [pid 229246:tid 229427] [client 20.197.192.193:30272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/ms-new.php"] [unique_id "al9KGCBMYeh5YLVG45yGpAAAAkc"]
[Tue Jul 21 07:29:44.494952 2026] [security2:error] [pid 229246:tid 229398] [client 20.197.192.193:47937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/track.php"] [unique_id "al9KGCBMYeh5YLVG45yGpgAAAio"]
[Tue Jul 21 07:29:44.517134 2026] [security2:error] [pid 229246:tid 229464] [client 20.197.192.193:30278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/2352356666.php"] [unique_id "al9KGCBMYeh5YLVG45yGpwAAAmw"]
[Tue Jul 21 07:29:44.552740 2026] [security2:error] [pid 229246:tid 229479] [client 20.197.192.193:47957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/pn.php"] [unique_id "al9KGCBMYeh5YLVG45yGqQAAAns"]
[Tue Jul 21 07:29:44.597860 2026] [security2:error] [pid 229246:tid 229477] [client 20.197.192.193:47992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9KGCBMYeh5YLVG45yGqgAAAnk"]
[Tue Jul 21 07:29:44.645526 2026] [security2:error] [pid 229246:tid 229502] [client 20.197.192.193:30291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/dr.php"] [unique_id "al9KGCBMYeh5YLVG45yGrgAAApI"]
[Tue Jul 21 07:29:44.723954 2026] [security2:error] [pid 229246:tid 229435] [client 20.197.192.193:47989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/2x.php"] [unique_id "al9KGCBMYeh5YLVG45yGrwAAAk8"]
[Tue Jul 21 07:29:44.785412 2026] [security2:error] [pid 229246:tid 229302] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KGCBMYeh5YLVG45yGsgACMTc"]
[Tue Jul 21 07:29:44.785543 2026] [security2:error] [pid 229246:tid 229405] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KGCBMYeh5YLVG45yGsgACMTc"]
[Tue Jul 21 07:29:44.786836 2026] [security2:error] [pid 229246:tid 229463] [client 45.8.17.123:23405] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/profile.php"] [unique_id "al9KGCBMYeh5YLVG45yGtAAAAms"]
[Tue Jul 21 07:29:44.796899 2026] [security2:error] [pid 229246:tid 229387] [client 103.162.129.114:51993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KGCBMYeh5YLVG45yGtgAAAh8"]
[Tue Jul 21 07:29:44.796999 2026] [security2:error] [pid 229246:tid 229387] [client 103.162.129.114:51993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KGCBMYeh5YLVG45yGtgAAAh8"]
[Tue Jul 21 07:29:44.857754 2026] [security2:error] [pid 230252:tid 230404] [client 20.197.192.193:57215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/kq1.php"] [unique_id "al9KGE0Dwhk5-Z44Xrpi0AAAAq0"]
[Tue Jul 21 07:29:44.897167 2026] [security2:error] [pid 229246:tid 229423] [client 152.59.154.239:55957] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KGCBMYeh5YLVG45yGtwAAAkM"]
[Tue Jul 21 07:29:44.897307 2026] [security2:error] [pid 229246:tid 229423] [client 152.59.154.239:55957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KGCBMYeh5YLVG45yGtwAAAkM"]
[Tue Jul 21 07:29:44.924460 2026] [security2:error] [pid 229246:tid 229452] [client 20.197.192.193:47975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/zzz.php"] [unique_id "al9KGCBMYeh5YLVG45yGugAAAmA"]
[Tue Jul 21 07:29:44.941322 2026] [security2:error] [pid 229246:tid 229481] [client 20.197.192.193:47977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/wicked.php"] [unique_id "al9KGCBMYeh5YLVG45yGuwAAAn0"]
[Tue Jul 21 07:29:44.956219 2026] [security2:error] [pid 229246:tid 229403] [client 20.197.192.193:47982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/edit.php"] [unique_id "al9KGCBMYeh5YLVG45yGvAAAAi8"]
[Tue Jul 21 07:29:44.967207 2026] [security2:error] [pid 229246:tid 229394] [client 20.197.192.193:30094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/kua.php"] [unique_id "al9KGCBMYeh5YLVG45yGvwAAAiY"]
[Tue Jul 21 07:29:44.973608 2026] [proxy:error] [pid 229246:tid 229455] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:29:44.973659 2026] [proxy_http:error] [pid 229246:tid 229455] [client 20.151.10.161:49033] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:29:44.974150 2026] [proxy:error] [pid 229246:tid 229455] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:29:44.974178 2026] [proxy_http:error] [pid 229246:tid 229455] [client 20.151.10.161:49033] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:29:44.981638 2026] [security2:error] [pid 229246:tid 229385] [client 20.197.192.193:30096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/ez.php"] [unique_id "al9KGCBMYeh5YLVG45yGwgAAAh0"]
[Tue Jul 21 07:29:45.000500 2026] [security2:error] [pid 229246:tid 229460] [client 20.197.192.193:30965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/fz.php"] [unique_id "al9KGCBMYeh5YLVG45yGwwAAAmg"]
[Tue Jul 21 07:29:45.004343 2026] [security2:error] [pid 229246:tid 229501] [client 34.26.127.63:54855] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9KGSBMYeh5YLVG45yGxAAAApE"]
[Tue Jul 21 07:29:45.018848 2026] [security2:error] [pid 229246:tid 229451] [client 20.197.192.193:30334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/la.php"] [unique_id "al9KGSBMYeh5YLVG45yGxQAAAl8"]
[Tue Jul 21 07:29:45.036570 2026] [security2:error] [pid 229246:tid 229416] [client 20.197.192.193:47969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9KGSBMYeh5YLVG45yGxgAAAjw"]
[Tue Jul 21 07:29:45.040027 2026] [security2:error] [pid 229246:tid 229469] [client 175.45.70.82:60830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KGSBMYeh5YLVG45yGxwAAAnE"]
[Tue Jul 21 07:29:45.040123 2026] [security2:error] [pid 229246:tid 229469] [client 175.45.70.82:60830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KGSBMYeh5YLVG45yGxwAAAnE"]
[Tue Jul 21 07:29:45.080598 2026] [security2:error] [pid 229246:tid 229378] [client 213.152.162.104:43338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KGSBMYeh5YLVG45yGyAAAAhY"]
[Tue Jul 21 07:29:45.080671 2026] [security2:error] [pid 229246:tid 229378] [client 213.152.162.104:43338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KGSBMYeh5YLVG45yGyAAAAhY"]
[Tue Jul 21 07:29:45.091985 2026] [security2:error] [pid 229246:tid 229449] [client 20.197.192.193:57189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/inso.php"] [unique_id "al9KGSBMYeh5YLVG45yGyQAAAl0"]
[Tue Jul 21 07:29:45.115801 2026] [security2:error] [pid 229246:tid 229473] [client 20.197.192.193:30139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/wpx.php"] [unique_id "al9KGSBMYeh5YLVG45yGzAAAAnU"]
[Tue Jul 21 07:29:45.140744 2026] [security2:error] [pid 229246:tid 229417] [client 20.197.192.193:30330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/berlin.php"] [unique_id "al9KGSBMYeh5YLVG45yGzQAAAj0"]
[Tue Jul 21 07:29:45.161437 2026] [security2:error] [pid 229246:tid 229284] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KGSBMYeh5YLVG45yGzgACNCU"]
[Tue Jul 21 07:29:45.161546 2026] [security2:error] [pid 229246:tid 229408] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KGSBMYeh5YLVG45yGzgACNCU"]
[Tue Jul 21 07:29:45.170642 2026] [security2:error] [pid 229246:tid 229458] [client 20.197.192.193:47979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/billur.php"] [unique_id "al9KGSBMYeh5YLVG45yGzwAAAmY"]
[Tue Jul 21 07:29:45.201100 2026] [security2:error] [pid 229246:tid 229432] [client 20.197.192.193:57173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/mimpi.php"] [unique_id "al9KGSBMYeh5YLVG45yG0AAAAkw"]
[Tue Jul 21 07:29:45.235522 2026] [security2:error] [pid 229246:tid 229398] [client 20.197.192.193:57200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/dp.php"] [unique_id "al9KGSBMYeh5YLVG45yG0gAAAio"]
[Tue Jul 21 07:29:45.250848 2026] [security2:error] [pid 229246:tid 229465] [client 20.197.192.193:30305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/bootstrap.php"] [unique_id "al9KGSBMYeh5YLVG45yG0wAAAm0"]
[Tue Jul 21 07:29:45.275275 2026] [security2:error] [pid 229246:tid 229492] [client 20.197.192.193:57180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/wp-editor.php"] [unique_id "al9KGSBMYeh5YLVG45yG1AAAAog"]
[Tue Jul 21 07:29:45.364480 2026] [security2:error] [pid 229246:tid 229435] [client 20.197.192.193:47967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/cro.php"] [unique_id "al9KGSBMYeh5YLVG45yG2AAAAk8"]
[Tue Jul 21 07:29:45.453435 2026] [security2:error] [pid 229246:tid 229387] [client 20.197.192.193:30302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/cron-tab.php"] [unique_id "al9KGSBMYeh5YLVG45yG2gAAAh8"]
[Tue Jul 21 07:29:45.465777 2026] [security2:error] [pid 229246:tid 229399] [client 109.248.148.246:37430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9KGSBMYeh5YLVG45yG2wAAAis"]
[Tue Jul 21 07:29:45.465878 2026] [security2:error] [pid 229246:tid 229399] [client 109.248.148.246:37430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9KGSBMYeh5YLVG45yG2wAAAis"]
[Tue Jul 21 07:29:45.486780 2026] [security2:error] [pid 229246:tid 229423] [client 20.197.192.193:47971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/koiy.php"] [unique_id "al9KGSBMYeh5YLVG45yG3gAAAkM"]
[Tue Jul 21 07:29:45.496697 2026] [security2:error] [pid 230252:tid 230442] [client 20.104.96.117:42403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/19.php"] [unique_id "al9KGU0Dwhk5-Z44Xrpi1QAAAtM"]
[Tue Jul 21 07:29:45.527370 2026] [security2:error] [pid 229246:tid 229481] [client 20.197.192.193:30107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/hp2.php"] [unique_id "al9KGSBMYeh5YLVG45yG4AAAAn0"]
[Tue Jul 21 07:29:45.587786 2026] [proxy:error] [pid 229246:tid 229444] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:29:45.587865 2026] [proxy_http:error] [pid 229246:tid 229444] [client 20.151.10.161:49052] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:29:45.588546 2026] [proxy:error] [pid 229246:tid 229444] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:29:45.588577 2026] [proxy_http:error] [pid 229246:tid 229444] [client 20.151.10.161:49052] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:29:45.590232 2026] [security2:error] [pid 230252:tid 230473] [client 103.174.34.15:53577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KGU0Dwhk5-Z44Xrpi1gAAAvI"]
[Tue Jul 21 07:29:45.590349 2026] [security2:error] [pid 230252:tid 230473] [client 103.174.34.15:53577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KGU0Dwhk5-Z44Xrpi1gAAAvI"]
[Tue Jul 21 07:29:45.591243 2026] [security2:error] [pid 229246:tid 229394] [client 20.197.192.193:30135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/hp3.php"] [unique_id "al9KGSBMYeh5YLVG45yG4gAAAiY"]
[Tue Jul 21 07:29:45.625370 2026] [security2:error] [pid 229246:tid 229482] [client 20.197.192.193:47834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/aa1.php"] [unique_id "al9KGSBMYeh5YLVG45yG4wAAAn4"]
[Tue Jul 21 07:29:45.674861 2026] [security2:error] [pid 229246:tid 229480] [client 20.197.192.193:30279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/acew67.php"] [unique_id "al9KGSBMYeh5YLVG45yG5AAAAnw"]
[Tue Jul 21 07:29:45.693618 2026] [security2:error] [pid 229246:tid 229402] [client 45.8.17.127:61835] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/tinymce/utils/"] [unique_id "al9KGSBMYeh5YLVG45yG5QAAAi4"]
[Tue Jul 21 07:29:45.736956 2026] [security2:error] [pid 229246:tid 229445] [client 20.197.192.193:47830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/bscclapb.php"] [unique_id "al9KGSBMYeh5YLVG45yG5gAAAlk"]
[Tue Jul 21 07:29:45.849584 2026] [security2:error] [pid 229246:tid 229455] [client 34.26.127.63:54549] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9KGSBMYeh5YLVG45yG7AAAAmM"]
[Tue Jul 21 07:29:45.861396 2026] [security2:error] [pid 229246:tid 229469] [client 20.197.192.193:30290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/else1.php"] [unique_id "al9KGSBMYeh5YLVG45yG7gAAAnE"]
[Tue Jul 21 07:29:45.881222 2026] [security2:error] [pid 229246:tid 229378] [client 20.197.192.193:57208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/tkikikoko.php"] [unique_id "al9KGSBMYeh5YLVG45yG7wAAAhY"]
[Tue Jul 21 07:29:45.906038 2026] [security2:error] [pid 229246:tid 229473] [client 20.197.192.193:47964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9KGSBMYeh5YLVG45yG8AAAAnU"]
[Tue Jul 21 07:29:45.954109 2026] [security2:error] [pid 229246:tid 229429] [client 20.197.192.193:57202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/wp-css.php"] [unique_id "al9KGSBMYeh5YLVG45yG8QAAAkk"]
[Tue Jul 21 07:29:45.993899 2026] [security2:error] [pid 230252:tid 230393] [client 20.197.192.193:30088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/wp-explorer.php"] [unique_id "al9KGU0Dwhk5-Z44Xrpi2AAAAqI"]
[Tue Jul 21 07:29:46.025370 2026] [security2:error] [pid 230252:tid 230394] [client 20.197.192.193:30286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/akismet.php"] [unique_id "al9KGk0Dwhk5-Z44Xrpi2QAAAqM"]
[Tue Jul 21 07:29:46.052974 2026] [security2:error] [pid 229246:tid 229475] [client 154.192.233.199:59035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KGiBMYeh5YLVG45yG9gAAAnc"]
[Tue Jul 21 07:29:46.052983 2026] [security2:error] [pid 229246:tid 229460] [client 173.24.185.52:50766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KGiBMYeh5YLVG45yG9wAAAmg"]
[Tue Jul 21 07:29:46.053087 2026] [security2:error] [pid 229246:tid 229460] [client 173.24.185.52:50766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KGiBMYeh5YLVG45yG9wAAAmg"]
[Tue Jul 21 07:29:46.053095 2026] [security2:error] [pid 229246:tid 229475] [client 154.192.233.199:59035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KGiBMYeh5YLVG45yG9gAAAnc"]
[Tue Jul 21 07:29:46.080034 2026] [security2:error] [pid 230252:tid 230419] [client 20.197.192.193:31170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/ace2.php"] [unique_id "al9KGk0Dwhk5-Z44Xrpi2gAAArw"]
[Tue Jul 21 07:29:46.115177 2026] [security2:error] [pid 229246:tid 229432] [client 20.197.192.193:30287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/ms.php"] [unique_id "al9KGiBMYeh5YLVG45yG-QAAAkw"]
[Tue Jul 21 07:29:46.232619 2026] [core:alert] [pid 230252:tid 230417] [client 57.141.18.13:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:29:46.405678 2026] [security2:error] [pid 230252:tid 230511] [client 20.151.10.161:49024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/waf.php"] [unique_id "al9KGk0Dwhk5-Z44Xrpi5gAAAxg"]
[Tue Jul 21 07:29:46.415964 2026] [security2:error] [pid 230252:tid 230480] [client 34.26.127.63:63268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9KGk0Dwhk5-Z44Xrpi5wAAAvk"]
[Tue Jul 21 07:29:46.457389 2026] [security2:error] [pid 229246:tid 229489] [client 193.36.225.69:28745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KGiBMYeh5YLVG45yHEgAAAoU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:47.096499 2026] [security2:error] [pid 230252:tid 230482] [client 34.26.127.63:58548] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9KG00Dwhk5-Z44Xrpi8AAAAvs"]
[Tue Jul 21 07:29:47.194901 2026] [security2:error] [pid 230252:tid 230479] [client 45.8.17.115:28135] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/block-patterns/"] [unique_id "al9KG00Dwhk5-Z44Xrpi8QAAAvg"]
[Tue Jul 21 07:29:47.205397 2026] [security2:error] [pid 229246:tid 229482] [client 62.102.148.164:44314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KGyBMYeh5YLVG45yHHgAAAn4"]
[Tue Jul 21 07:29:47.205509 2026] [security2:error] [pid 229246:tid 229482] [client 62.102.148.164:44314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KGyBMYeh5YLVG45yHHgAAAn4"]
[Tue Jul 21 07:29:47.342121 2026] [security2:error] [pid 229246:tid 229402] [client 20.151.10.161:49076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/xstelth.php"] [unique_id "al9KGyBMYeh5YLVG45yHIgAAAi4"]
[Tue Jul 21 07:29:47.665038 2026] [security2:error] [pid 229246:tid 229445] [client 34.26.127.63:52752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9KGyBMYeh5YLVG45yHJQAAAlk"]
[Tue Jul 21 07:29:47.827070 2026] [security2:error] [pid 229246:tid 229488] [client 20.151.10.161:48585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-links.php"] [unique_id "al9KGyBMYeh5YLVG45yHJgAAAoQ"]
[Tue Jul 21 07:29:47.991763 2026] [security2:error] [pid 230252:tid 230459] [client 20.104.96.117:59604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/inc.php"] [unique_id "al9KG00Dwhk5-Z44Xrpi-gAAAuQ"]
[Tue Jul 21 07:29:48.337244 2026] [security2:error] [pid 229246:tid 229449] [client 34.26.127.63:54183] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9KHCBMYeh5YLVG45yHLAAAAl0"]
[Tue Jul 21 07:29:48.586784 2026] [security2:error] [pid 230252:tid 230477] [client 45.8.17.137:46375] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentythree/patterns/template-singl-portfolio.php"] [unique_id "al9KHE0Dwhk5-Z44Xrpi_gAAAvY"]
[Tue Jul 21 07:29:48.671319 2026] [security2:error] [pid 229246:tid 229389] [client 20.220.225.223:45992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/track.php"] [unique_id "al9KHCBMYeh5YLVG45yHMwAAAiE"]
[Tue Jul 21 07:29:48.796582 2026] [security2:error] [pid 230252:tid 230407] [client 20.151.10.161:49094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9KHE0Dwhk5-Z44Xrpi_wAAArA"]
[Tue Jul 21 07:29:49.200770 2026] [security2:error] [pid 230252:tid 230417] [client 45.251.232.145:58312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KHU0Dwhk5-Z44XrpjAAAAAro"]
[Tue Jul 21 07:29:49.200910 2026] [security2:error] [pid 230252:tid 230417] [client 45.251.232.145:58312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KHU0Dwhk5-Z44XrpjAAAAAro"]
[Tue Jul 21 07:29:49.279146 2026] [security2:error] [pid 229246:tid 229283] [remote 41.186.86.12:19620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9KHSBMYeh5YLVG45yHPgACHCQ"]
[Tue Jul 21 07:29:49.802257 2026] [autoindex:error] [pid 230252:tid 230268] [remote 74.7.242.3:49918] AH01276: Cannot serve directory /home1/ofic8899/sulinex.oficialwebsite.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:49.817783 2026] [security2:error] [pid 229246:tid 229405] [client 74.7.241.149:38254] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.sulinex.oficialwebsite.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9KHSBMYeh5YLVG45yHSAACMSc"]
[Tue Jul 21 07:29:50.096040 2026] [security2:error] [pid 229246:tid 229403] [client 20.151.10.161:49086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/aaa.php"] [unique_id "al9KHiBMYeh5YLVG45yHTgAAAi8"]
[Tue Jul 21 07:29:50.143442 2026] [security2:error] [pid 230252:tid 230304] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KHk0Dwhk5-Z44XrpjDAADFTI"]
[Tue Jul 21 07:29:50.143611 2026] [security2:error] [pid 230252:tid 230508] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KHk0Dwhk5-Z44XrpjDAADFTI"]
[Tue Jul 21 07:29:50.206795 2026] [security2:error] [pid 229246:tid 229406] [client 45.8.17.59:64371] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/certificates/"] [unique_id "al9KHiBMYeh5YLVG45yHUgAAAjI"]
[Tue Jul 21 07:29:50.538723 2026] [access_compat:error] [pid 229246:tid 229448] [client 162.241.63.68:22484] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:29:50.651644 2026] [security2:error] [pid 230252:tid 230467] [client 136.144.33.107:52127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KHk0Dwhk5-Z44XrpjEwAAAuw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:51.391075 2026] [security2:error] [pid 229246:tid 229475] [client 45.8.17.115:31731] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/includes/user/"] [unique_id "al9KHyBMYeh5YLVG45yHYQAAAnc"]
[Tue Jul 21 07:29:51.492543 2026] [security2:error] [pid 230252:tid 230459] [client 59.96.220.140:54285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KH00Dwhk5-Z44XrpjHgAAAuQ"]
[Tue Jul 21 07:29:51.492694 2026] [security2:error] [pid 230252:tid 230459] [client 59.96.220.140:54285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KH00Dwhk5-Z44XrpjHgAAAuQ"]
[Tue Jul 21 07:29:51.634940 2026] [security2:error] [pid 230252:tid 230447] [client 117.251.86.144:35416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KH00Dwhk5-Z44XrpjIAAAAtg"]
[Tue Jul 21 07:29:51.635076 2026] [security2:error] [pid 230252:tid 230447] [client 117.251.86.144:35416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KH00Dwhk5-Z44XrpjIAAAAtg"]
[Tue Jul 21 07:29:51.651466 2026] [security2:error] [pid 230252:tid 230462] [client 20.104.96.117:59796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9KH00Dwhk5-Z44XrpjIQAAAuc"]
[Tue Jul 21 07:29:51.781101 2026] [security2:error] [pid 229246:tid 229496] [client 139.135.44.145:53730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KHyBMYeh5YLVG45yHbgAAAow"]
[Tue Jul 21 07:29:51.781211 2026] [security2:error] [pid 229246:tid 229496] [client 139.135.44.145:53730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KHyBMYeh5YLVG45yHbgAAAow"]
[Tue Jul 21 07:29:51.810475 2026] [security2:error] [pid 230252:tid 230267] [remote 57.141.18.60:58586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9KHk0Dwhk5-Z44XrpjFQACog0"]
[Tue Jul 21 07:29:52.526924 2026] [security2:error] [pid 229246:tid 229257] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KICBMYeh5YLVG45yHvAACawo"]
[Tue Jul 21 07:29:52.527073 2026] [security2:error] [pid 229246:tid 229463] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KICBMYeh5YLVG45yHvAACawo"]
[Tue Jul 21 07:29:52.611078 2026] [security2:error] [pid 230252:tid 230387] [client 103.186.30.230:52485] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "thiagomartins.com"] [uri "/"] [unique_id "al9KIE0Dwhk5-Z44XrpjLQAAApw"]
[Tue Jul 21 07:29:52.777399 2026] [security2:error] [pid 229246:tid 229481] [client 45.8.17.125:38275] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/66.php"] [unique_id "al9KICBMYeh5YLVG45yH1QAAAn0"]
[Tue Jul 21 07:29:53.044640 2026] [security2:error] [pid 230252:tid 230487] [client 20.52.136.55:1565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/vx.php"] [unique_id "al9KIU0Dwhk5-Z44XrpjMgAAAwA"]
[Tue Jul 21 07:29:53.632079 2026] [security2:error] [pid 229246:tid 229368] [remote 182.77.62.24:59224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/wp-login.php"] [unique_id "al9KISBMYeh5YLVG45yH7gACMXk"]
[Tue Jul 21 07:29:53.802118 2026] [security2:error] [pid 230252:tid 230470] [client 103.186.30.230:52506] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "thiagomartins.com"] [uri "/wp-json/batch/v1"] [unique_id "al9KIU0Dwhk5-Z44XrpjOQAAAu8"]
[Tue Jul 21 07:29:53.913929 2026] [security2:error] [pid 229246:tid 229305] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9KISBMYeh5YLVG45yH8wACFDo"]
[Tue Jul 21 07:29:54.185696 2026] [security2:error] [pid 230252:tid 230405] [client 45.8.17.48:36197] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/languages/autoload_classmap.php"] [unique_id "al9KIk0Dwhk5-Z44XrpjPQAAAq4"]
[Tue Jul 21 07:29:54.235565 2026] [security2:error] [pid 229246:tid 229361] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KIiBMYeh5YLVG45yIHwACR3I"]
[Tue Jul 21 07:29:54.235762 2026] [security2:error] [pid 229246:tid 229427] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KIiBMYeh5YLVG45yIHwACR3I"]
[Tue Jul 21 07:29:54.311621 2026] [security2:error] [pid 230252:tid 230458] [client 136.144.33.97:62407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KIk0Dwhk5-Z44XrpjPgAAAuM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:54.318973 2026] [security2:error] [pid 229246:tid 229389] [client 103.106.20.201:59178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KIiBMYeh5YLVG45yIJgAAAiE"]
[Tue Jul 21 07:29:54.319085 2026] [security2:error] [pid 229246:tid 229389] [client 103.106.20.201:59178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KIiBMYeh5YLVG45yIJgAAAiE"]
[Tue Jul 21 07:29:54.665461 2026] [security2:error] [pid 230252:tid 230496] [client 20.104.96.117:42404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9KIk0Dwhk5-Z44XrpjQQAAAwk"]
[Tue Jul 21 07:29:54.727693 2026] [security2:error] [pid 229246:tid 229437] [client 20.220.225.223:8928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/kua.php"] [unique_id "al9KIiBMYeh5YLVG45yILgAAAlE"]
[Tue Jul 21 07:29:54.921435 2026] [security2:error] [pid 229246:tid 229280] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KIiBMYeh5YLVG45yIMAACdiE"]
[Tue Jul 21 07:29:54.921590 2026] [security2:error] [pid 229246:tid 229474] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KIiBMYeh5YLVG45yIMAACdiE"]
[Tue Jul 21 07:29:55.033193 2026] [security2:error] [pid 230252:tid 230436] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9KI00Dwhk5-Z44XrpjRgAAAs0"]
[Tue Jul 21 07:29:55.068958 2026] [security2:error] [pid 230252:tid 230410] [client 103.162.129.114:52434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KI00Dwhk5-Z44XrpjRwAAArM"]
[Tue Jul 21 07:29:55.069129 2026] [security2:error] [pid 230252:tid 230410] [client 103.162.129.114:52434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KI00Dwhk5-Z44XrpjRwAAArM"]
[Tue Jul 21 07:29:55.178977 2026] [autoindex:error] [pid 230252:tid 230469] [client 64.69.216.78:39244] AH01276: Cannot serve directory /home2/marc8022/canelapart.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:55.470383 2026] [security2:error] [pid 230252:tid 230370] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KI00Dwhk5-Z44XrpjUQACoHM"]
[Tue Jul 21 07:29:55.470595 2026] [security2:error] [pid 230252:tid 230391] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KI00Dwhk5-Z44XrpjUQACoHM"]
[Tue Jul 21 07:29:55.474899 2026] [security2:error] [pid 230252:tid 230511] [client 103.186.30.230:52525] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "thiagomartins.com"] [uri "/"] [unique_id "al9KI00Dwhk5-Z44XrpjUgAAAxg"]
[Tue Jul 21 07:29:55.645583 2026] [security2:error] [pid 229246:tid 229267] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KIyBMYeh5YLVG45yIOwACYRQ"]
[Tue Jul 21 07:29:55.645720 2026] [security2:error] [pid 229246:tid 229453] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KIyBMYeh5YLVG45yIOwACYRQ"]
[Tue Jul 21 07:29:55.678174 2026] [security2:error] [pid 230252:tid 230443] [client 154.192.233.199:59353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KI00Dwhk5-Z44XrpjVgAAAtQ"]
[Tue Jul 21 07:29:55.678292 2026] [security2:error] [pid 230252:tid 230443] [client 154.192.233.199:59353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KI00Dwhk5-Z44XrpjVgAAAtQ"]
[Tue Jul 21 07:29:55.747849 2026] [security2:error] [pid 230252:tid 230468] [client 175.45.70.82:61339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KI00Dwhk5-Z44XrpjVwAAAu0"]
[Tue Jul 21 07:29:55.747957 2026] [security2:error] [pid 230252:tid 230468] [client 175.45.70.82:61339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KI00Dwhk5-Z44XrpjVwAAAu0"]
[Tue Jul 21 07:29:56.101114 2026] [security2:error] [pid 230252:tid 230421] [client 152.59.154.239:56338] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KJE0Dwhk5-Z44XrpjXAAAAr4"]
[Tue Jul 21 07:29:56.101262 2026] [security2:error] [pid 230252:tid 230421] [client 152.59.154.239:56338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KJE0Dwhk5-Z44XrpjXAAAAr4"]
[Tue Jul 21 07:29:56.207381 2026] [autoindex:error] [pid 229246:tid 229480] [client 64.69.216.78:39358] AH01276: Cannot serve directory /home2/marc8022/canelapart.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:56.290135 2026] [security2:error] [pid 230252:tid 230428] [client 103.174.34.15:54077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KJE0Dwhk5-Z44XrpjXwAAAsU"]
[Tue Jul 21 07:29:56.290256 2026] [security2:error] [pid 230252:tid 230428] [client 103.174.34.15:54077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KJE0Dwhk5-Z44XrpjXwAAAsU"]
[Tue Jul 21 07:29:56.497806 2026] [security2:error] [pid 230252:tid 230413] [client 45.8.17.110:37633] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/2024/"] [unique_id "al9KJE0Dwhk5-Z44XrpjYAAAArY"]
[Tue Jul 21 07:29:56.611273 2026] [security2:error] [pid 229246:tid 229401] [client 173.24.185.52:51231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KJCBMYeh5YLVG45yITQAAAi0"]
[Tue Jul 21 07:29:56.611471 2026] [security2:error] [pid 229246:tid 229401] [client 173.24.185.52:51231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KJCBMYeh5YLVG45yITQAAAi0"]
[Tue Jul 21 07:29:57.004918 2026] [security2:error] [pid 229246:tid 229412] [client 20.220.225.223:46013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/2352356666.php"] [unique_id "al9KJSBMYeh5YLVG45yIVAAAAjg"]
[Tue Jul 21 07:29:57.093637 2026] [security2:error] [pid 229246:tid 229254] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9KJSBMYeh5YLVG45yIVQACJwc"]
[Tue Jul 21 07:29:57.284520 2026] [core:error] [pid 229246:tid 229458] [client 66.249.66.69:54901] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:29:57.284543 2026] [core:error] [pid 229246:tid 229458] [client 66.249.66.69:54901] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:29:57.556617 2026] [security2:error] [pid 229246:tid 229476] [client 198.204.224.34:57912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/wp-includes/qqf65547/73/index.php"] [unique_id "al9KJSBMYeh5YLVG45yIXQAAAng"], referer: http://roanalacerda.com.br/wp-includes/qqf65547/73/index.php
[Tue Jul 21 07:29:57.754785 2026] [security2:error] [pid 229246:tid 229497] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9KJSBMYeh5YLVG45yIXgAAAo0"]
[Tue Jul 21 07:29:57.994349 2026] [security2:error] [pid 229246:tid 229492] [client 20.104.96.117:42429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/ss.php"] [unique_id "al9KJSBMYeh5YLVG45yIZgAAAog"]
[Tue Jul 21 07:29:58.035418 2026] [security2:error] [pid 229246:tid 229483] [client 198.204.224.34:57918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/re/embeds/19/index.php"] [unique_id "al9KJiBMYeh5YLVG45yIaAAAAn8"], referer: http://roanalacerda.com.br/re/embeds/19/index.php
[Tue Jul 21 07:29:58.284782 2026] [core:error] [pid 229246:tid 229463] [client 66.249.66.67:58147] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:29:58.284803 2026] [core:error] [pid 229246:tid 229463] [client 66.249.66.67:58147] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:29:58.582534 2026] [security2:error] [pid 230252:tid 230416] [client 45.8.17.117:38567] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/chosen.php"] [unique_id "al9KJk0Dwhk5-Z44XrpjdgAAArk"]
[Tue Jul 21 07:29:58.898397 2026] [security2:error] [pid 230252:tid 230436] [client 193.36.225.54:41477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KJk0Dwhk5-Z44XrpjeQAAAs0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:59.280856 2026] [security2:error] [pid 229246:tid 229480] [client 198.204.224.34:57928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/us/audits/6/index.php"] [unique_id "al9KJyBMYeh5YLVG45yIeQAAAnw"], referer: http://roanalacerda.com.br/us/audits/6/index.php
[Tue Jul 21 07:29:59.580180 2026] [security2:error] [pid 230252:tid 230458] [client 45.8.17.59:21439] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/footer.php"] [unique_id "al9KJ00Dwhk5-Z44XrpjhwAAAuM"]
[Tue Jul 21 07:29:59.606111 2026] [security2:error] [pid 230252:tid 230491] [client 198.204.224.34:57942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/us/query-content/7/index.php"] [unique_id "al9KJ00Dwhk5-Z44XrpjiAAAAwQ"], referer: http://roanalacerda.com.br/us/query-content/7/index.php
[Tue Jul 21 07:29:59.671946 2026] [security2:error] [pid 230252:tid 230472] [client 45.251.232.145:58833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KJ00Dwhk5-Z44XrpjiQAAAvE"]
[Tue Jul 21 07:29:59.672157 2026] [security2:error] [pid 230252:tid 230472] [client 45.251.232.145:58833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KJ00Dwhk5-Z44XrpjiQAAAvE"]
[Tue Jul 21 07:29:59.726530 2026] [security2:error] [pid 230252:tid 230421] [client 20.104.96.117:59809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/min.php"] [unique_id "al9KJ00Dwhk5-Z44XrpjigAAAr4"]
[Tue Jul 21 07:29:59.920967 2026] [security2:error] [pid 230252:tid 230463] [client 198.204.224.34:57948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/pro/78/index.php"] [unique_id "al9KJ00Dwhk5-Z44XrpjjwAAAug"], referer: http://roanalacerda.com.br/pro/78/index.php
[Tue Jul 21 07:29:59.982237 2026] [security2:error] [pid 230252:tid 230509] [client 82.102.28.107:39972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KJ00Dwhk5-Z44XrpjkAAAAxY"]
[Tue Jul 21 07:29:59.982364 2026] [security2:error] [pid 230252:tid 230509] [client 82.102.28.107:39972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KJ00Dwhk5-Z44XrpjkAAAAxY"]
[Tue Jul 21 07:30:00.279742 2026] [security2:error] [pid 230252:tid 230406] [client 198.204.224.34:57950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/ra/12/index.php"] [unique_id "al9KKE0Dwhk5-Z44XrpjkgAAAq8"], referer: http://roanalacerda.com.br/ra/12/index.php
[Tue Jul 21 07:30:00.628074 2026] [security2:error] [pid 230252:tid 230385] [client 198.204.224.34:57952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/Avast/98/index.php"] [unique_id "al9KKE0Dwhk5-Z44XrpjmQAAApo"], referer: http://roanalacerda.com.br/Avast/98/index.php
[Tue Jul 21 07:30:00.728318 2026] [security2:error] [pid 230252:tid 230320] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KKE0Dwhk5-Z44XrpjmwADEEI"]
[Tue Jul 21 07:30:00.728457 2026] [security2:error] [pid 230252:tid 230503] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KKE0Dwhk5-Z44XrpjmwADEEI"]
[Tue Jul 21 07:30:00.991779 2026] [security2:error] [pid 230252:tid 230387] [client 198.204.224.34:57958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/wp-includes/32/index.php"] [unique_id "al9KKE0Dwhk5-Z44XrpjnQAAApw"], referer: http://roanalacerda.com.br/wp-includes/32/index.php
[Tue Jul 21 07:30:01.157707 2026] [security2:error] [pid 230252:tid 230454] [client 74.7.175.147:51874] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.radiantus.online"] [uri "/robots.txt"] [unique_id "al9KKU0Dwhk5-Z44XrpjoQAAAt8"]
[Tue Jul 21 07:30:01.291568 2026] [security2:error] [pid 229246:tid 229459] [client 45.8.17.108:25339] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/wp-file-manager-pro/"] [unique_id "al9KKSBMYeh5YLVG45yIkwAAAmc"]
[Tue Jul 21 07:30:01.311591 2026] [security2:error] [pid 230252:tid 230467] [client 198.204.224.34:57974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/840cb/42/index.php"] [unique_id "al9KKU0Dwhk5-Z44XrpjqQAAAuw"], referer: http://roanalacerda.com.br/840cb/42/index.php
[Tue Jul 21 07:30:01.469817 2026] [security2:error] [pid 230252:tid 230384] [client 213.152.162.104:35784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9KKU0Dwhk5-Z44XrpjsQAAApk"]
[Tue Jul 21 07:30:01.469924 2026] [security2:error] [pid 230252:tid 230384] [client 213.152.162.104:35784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9KKU0Dwhk5-Z44XrpjsQAAApk"]
[Tue Jul 21 07:30:01.667200 2026] [security2:error] [pid 230252:tid 230298] [remote 116.203.133.192:38008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.133.203.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "frsadvocacia.net"] [uri "/xmlrpc.php"] [unique_id "al9KKU0Dwhk5-Z44XrpjswAC4Sw"]
[Tue Jul 21 07:30:01.667455 2026] [security2:error] [pid 230252:tid 230456] [client 116.203.133.192:38008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "frsadvocacia.net"] [uri "/xmlrpc.php"] [unique_id "al9KKU0Dwhk5-Z44XrpjswAC4Sw"]
[Tue Jul 21 07:30:01.681457 2026] [security2:error] [pid 229246:tid 229471] [client 198.204.224.34:57988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/us/10/index.php"] [unique_id "al9KKSBMYeh5YLVG45yImwAAAnM"], referer: http://roanalacerda.com.br/us/10/index.php
[Tue Jul 21 07:30:01.803492 2026] [security2:error] [pid 230252:tid 230507] [client 20.104.96.117:42372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9KKU0Dwhk5-Z44XrpjtgAAAxQ"]
[Tue Jul 21 07:30:02.388007 2026] [security2:error] [pid 230252:tid 230297] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KKk0Dwhk5-Z44XrpjvgAC0is"]
[Tue Jul 21 07:30:02.388172 2026] [security2:error] [pid 230252:tid 230441] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KKk0Dwhk5-Z44XrpjvgAC0is"]
[Tue Jul 21 07:30:02.418158 2026] [security2:error] [pid 230252:tid 230412] [client 117.251.86.144:58946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KKk0Dwhk5-Z44XrpjwAAAArU"]
[Tue Jul 21 07:30:02.418280 2026] [security2:error] [pid 230252:tid 230412] [client 117.251.86.144:58946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KKk0Dwhk5-Z44XrpjwAAAArU"]
[Tue Jul 21 07:30:02.595794 2026] [security2:error] [pid 229246:tid 229503] [client 45.8.17.126:32983] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/system_log.php"] [unique_id "al9KKiBMYeh5YLVG45yIqQAAApM"]
[Tue Jul 21 07:30:02.600679 2026] [security2:error] [pid 230252:tid 230410] [client 139.135.44.145:54541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KKk0Dwhk5-Z44XrpjxQAAArM"]
[Tue Jul 21 07:30:02.600883 2026] [security2:error] [pid 230252:tid 230410] [client 139.135.44.145:54541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KKk0Dwhk5-Z44XrpjxQAAArM"]
[Tue Jul 21 07:30:02.643275 2026] [security2:error] [pid 230252:tid 230483] [client 136.144.33.108:44581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KKk0Dwhk5-Z44XrpjxgAAAvw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:02.821265 2026] [security2:error] [pid 229246:tid 229474] [client 49.13.167.123:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9KKiBMYeh5YLVG45yIrQACdmE"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:30:03.076524 2026] [security2:error] [pid 229246:tid 229481] [client 20.104.96.117:42401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9KKyBMYeh5YLVG45yIsAAAAn0"]
[Tue Jul 21 07:30:03.155174 2026] [security2:error] [pid 230252:tid 230391] [client 59.96.220.140:54772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KK00Dwhk5-Z44Xrpj0QAAAqA"]
[Tue Jul 21 07:30:03.155315 2026] [security2:error] [pid 230252:tid 230391] [client 59.96.220.140:54772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KK00Dwhk5-Z44Xrpj0QAAAqA"]
[Tue Jul 21 07:30:03.376546 2026] [security2:error] [pid 230252:tid 230413] [client 49.13.167.123:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9KK00Dwhk5-Z44Xrpj1wACtjs"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:30:03.495825 2026] [security2:error] [pid 230252:tid 230406] [client 45.8.17.107:45325] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/separator/"] [unique_id "al9KK00Dwhk5-Z44Xrpj2AAAAq8"]
[Tue Jul 21 07:30:03.699632 2026] [security2:error] [pid 230252:tid 230444] [client 20.52.136.55:1547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/ws77.php"] [unique_id "al9KK00Dwhk5-Z44Xrpj3AAAAtU"]
[Tue Jul 21 07:30:03.792626 2026] [autoindex:error] [pid 230252:tid 230510] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:03.856769 2026] [security2:error] [pid 229246:tid 229416] [client 62.102.148.164:49796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KKyBMYeh5YLVG45yIuAAAAjw"]
[Tue Jul 21 07:30:03.856887 2026] [security2:error] [pid 229246:tid 229416] [client 62.102.148.164:49796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KKyBMYeh5YLVG45yIuAAAAjw"]
[Tue Jul 21 07:30:04.238310 2026] [autoindex:error] [pid 230252:tid 230499] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:04.380984 2026] [security2:error] [pid 229246:tid 229455] [client 185.198.240.13:23607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mbarcondicionados.com.br"] [uri "/wp-login.php"] [unique_id "al9KLCBMYeh5YLVG45yIxgAAAmM"]
[Tue Jul 21 07:30:04.515299 2026] [autoindex:error] [pid 230252:tid 230441] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:04.686523 2026] [security2:error] [pid 230252:tid 230409] [client 45.8.17.128:61707] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/mah/function.php"] [unique_id "al9KLE0Dwhk5-Z44Xrpj6AAAArI"]
[Tue Jul 21 07:30:04.745770 2026] [autoindex:error] [pid 230252:tid 230460] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:04.827781 2026] [security2:error] [pid 230252:tid 230274] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KLE0Dwhk5-Z44Xrpj7gACzxQ"]
[Tue Jul 21 07:30:04.827952 2026] [security2:error] [pid 230252:tid 230438] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KLE0Dwhk5-Z44Xrpj7gACzxQ"]
[Tue Jul 21 07:30:05.036218 2026] [autoindex:error] [pid 230252:tid 230410] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:05.068426 2026] [security2:error] [pid 229246:tid 229396] [client 103.106.20.201:59764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KLSBMYeh5YLVG45yIzgAAAig"]
[Tue Jul 21 07:30:05.068575 2026] [security2:error] [pid 229246:tid 229396] [client 103.106.20.201:59764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KLSBMYeh5YLVG45yIzgAAAig"]
[Tue Jul 21 07:30:05.103000 2026] [security2:error] [pid 230252:tid 230450] [client 20.104.96.117:42398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9KLU0Dwhk5-Z44Xrpj8wAAAts"]
[Tue Jul 21 07:30:05.332825 2026] [autoindex:error] [pid 230252:tid 230491] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:05.459778 2026] [security2:error] [pid 230252:tid 230333] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KLU0Dwhk5-Z44Xrpj-QADDk4"]
[Tue Jul 21 07:30:05.459977 2026] [security2:error] [pid 230252:tid 230501] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KLU0Dwhk5-Z44Xrpj-QADDk4"]
[Tue Jul 21 07:30:05.613135 2026] [autoindex:error] [pid 230252:tid 230486] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:05.647760 2026] [security2:error] [pid 230252:tid 230467] [client 103.162.129.114:52886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KLU0Dwhk5-Z44Xrpj_QAAAuw"]
[Tue Jul 21 07:30:05.647889 2026] [security2:error] [pid 230252:tid 230467] [client 103.162.129.114:52886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KLU0Dwhk5-Z44Xrpj_QAAAuw"]
[Tue Jul 21 07:30:05.825117 2026] [autoindex:error] [pid 230252:tid 230402] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:06.100158 2026] [security2:error] [pid 230252:tid 230452] [client 213.152.162.104:35806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9KLk0Dwhk5-Z44XrpkBwAAAt0"]
[Tue Jul 21 07:30:06.100261 2026] [security2:error] [pid 230252:tid 230452] [client 213.152.162.104:35806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9KLk0Dwhk5-Z44XrpkBwAAAt0"]
[Tue Jul 21 07:30:06.106439 2026] [security2:error] [pid 230252:tid 230312] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KLk0Dwhk5-Z44XrpkCAACojo"]
[Tue Jul 21 07:30:06.106667 2026] [security2:error] [pid 230252:tid 230393] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KLk0Dwhk5-Z44XrpkCAACojo"]
[Tue Jul 21 07:30:06.384317 2026] [security2:error] [pid 230252:tid 230441] [client 45.8.17.119:55033] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/languages/admin.php"] [unique_id "al9KLk0Dwhk5-Z44XrpkCwAAAtI"]
[Tue Jul 21 07:30:06.421423 2026] [security2:error] [pid 230252:tid 230484] [client 175.45.70.82:61847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KLk0Dwhk5-Z44XrpkDAAAAv0"]
[Tue Jul 21 07:30:06.421586 2026] [security2:error] [pid 230252:tid 230484] [client 175.45.70.82:61847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KLk0Dwhk5-Z44XrpkDAAAAv0"]
[Tue Jul 21 07:30:06.432985 2026] [security2:error] [pid 229246:tid 229274] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KLiBMYeh5YLVG45yI5AACKxs"]
[Tue Jul 21 07:30:06.433140 2026] [security2:error] [pid 229246:tid 229399] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KLiBMYeh5YLVG45yI5AACKxs"]
[Tue Jul 21 07:30:06.648739 2026] [security2:error] [pid 230252:tid 230415] [client 45.8.19.153:40887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "madeireirapiske.com.br"] [uri "/wp-login.php"] [unique_id "al9KLk0Dwhk5-Z44XrpkEAAAArg"]
[Tue Jul 21 07:30:06.794550 2026] [security2:error] [pid 230252:tid 230412] [client 3.77.67.4:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9KLk0Dwhk5-Z44XrpkFAACtUw"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:30:07.101512 2026] [security2:error] [pid 230252:tid 230511] [client 103.174.34.15:54569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KL00Dwhk5-Z44XrpkGAAAAxg"]
[Tue Jul 21 07:30:07.102086 2026] [security2:error] [pid 230252:tid 230511] [client 103.174.34.15:54569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KL00Dwhk5-Z44XrpkGAAAAxg"]
[Tue Jul 21 07:30:07.175263 2026] [security2:error] [pid 230252:tid 230396] [client 173.24.185.52:51691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KL00Dwhk5-Z44XrpkGwAAAqU"]
[Tue Jul 21 07:30:07.175375 2026] [security2:error] [pid 230252:tid 230396] [client 173.24.185.52:51691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KL00Dwhk5-Z44XrpkGwAAAqU"]
[Tue Jul 21 07:30:07.212367 2026] [security2:error] [pid 229246:tid 229479] [client 152.59.154.239:56596] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KLyBMYeh5YLVG45yI7wAAAns"]
[Tue Jul 21 07:30:07.212495 2026] [security2:error] [pid 229246:tid 229479] [client 152.59.154.239:56596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KLyBMYeh5YLVG45yI7wAAAns"]
[Tue Jul 21 07:30:07.250359 2026] [autoindex:error] [pid 230252:tid 230467] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:07.339159 2026] [security2:error] [pid 229246:tid 229394] [client 3.77.67.4:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9KLyBMYeh5YLVG45yI8wACJiM"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:30:07.397125 2026] [security2:error] [pid 230252:tid 230450] [client 154.192.233.199:59892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KL00Dwhk5-Z44XrpkHwAAAts"]
[Tue Jul 21 07:30:07.397274 2026] [security2:error] [pid 230252:tid 230450] [client 154.192.233.199:59892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KL00Dwhk5-Z44XrpkHwAAAts"]
[Tue Jul 21 07:30:07.537470 2026] [autoindex:error] [pid 230252:tid 230444] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:07.690447 2026] [security2:error] [pid 230252:tid 230385] [client 45.8.17.106:55525] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/spacer/"] [unique_id "al9KL00Dwhk5-Z44XrpkJwAAApo"]
[Tue Jul 21 07:30:07.822185 2026] [security2:error] [pid 230252:tid 230490] [client 37.140.223.68:34103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KL00Dwhk5-Z44XrpkKgAAAwM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:08.044517 2026] [autoindex:error] [pid 230252:tid 230441] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:08.124434 2026] [security2:error] [pid 229246:tid 229401] [client 20.104.96.117:59644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9KMCBMYeh5YLVG45yI-wAAAi0"]
[Tue Jul 21 07:30:08.252742 2026] [autoindex:error] [pid 230252:tid 230409] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:08.538284 2026] [autoindex:error] [pid 230252:tid 230410] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:08.755759 2026] [autoindex:error] [pid 230252:tid 230428] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:08.984170 2026] [security2:error] [pid 230252:tid 230405] [client 45.8.17.73:54573] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/certificates/chosen.php"] [unique_id "al9KME0Dwhk5-Z44XrpkPAAAAq4"]
[Tue Jul 21 07:30:09.018776 2026] [autoindex:error] [pid 230252:tid 230416] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:09.856105 2026] [security2:error] [pid 230252:tid 230481] [client 20.104.96.117:42276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/albin.php"] [unique_id "al9KMU0Dwhk5-Z44XrpkRwAAAvo"]
[Tue Jul 21 07:30:10.033129 2026] [security2:error] [pid 230252:tid 230444] [client 20.52.136.55:1595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/2.php"] [unique_id "al9KMk0Dwhk5-Z44XrpkSAAAAtU"]
[Tue Jul 21 07:30:10.087640 2026] [security2:error] [pid 230252:tid 230393] [client 45.8.17.130:51229] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/shortcode/"] [unique_id "al9KMk0Dwhk5-Z44XrpkSwAAAqI"]
[Tue Jul 21 07:30:10.204103 2026] [security2:error] [pid 230252:tid 230509] [client 45.251.232.145:59362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KMk0Dwhk5-Z44XrpkTAAAAxY"]
[Tue Jul 21 07:30:10.204257 2026] [security2:error] [pid 230252:tid 230509] [client 45.251.232.145:59362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KMk0Dwhk5-Z44XrpkTAAAAxY"]
[Tue Jul 21 07:30:10.233512 2026] [autoindex:error] [pid 230252:tid 230503] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:10.243818 2026] [security2:error] [pid 230252:tid 230287] [remote 45.79.123.44:33238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9KMk0Dwhk5-Z44XrpkTgACpyE"]
[Tue Jul 21 07:30:10.522318 2026] [core:crit] [pid 230252:tid 230430] (13)Permission denied: [client 85.204.70.92:33458] AH00529: /home3/frsadv16/public_html/cgi-bin/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home3/frsadv16/public_html/cgi-bin/' is executable
[Tue Jul 21 07:30:11.089639 2026] [security2:error] [pid 229246:tid 229399] [client 45.8.17.132:50747] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/edit-wolf.php"] [unique_id "al9KMyBMYeh5YLVG45yJHQAAAis"]
[Tue Jul 21 07:30:11.250219 2026] [security2:error] [pid 230252:tid 230495] [client 47.128.112.178:36440] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "triviaodontologia.com.br"] [uri "/robots.txt"] [unique_id "al9KM00Dwhk5-Z44XrpkWAAAAwg"]
[Tue Jul 21 07:30:11.377944 2026] [security2:error] [pid 230252:tid 230322] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KM00Dwhk5-Z44XrpkWQAC_UQ"]
[Tue Jul 21 07:30:11.378132 2026] [security2:error] [pid 230252:tid 230484] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KM00Dwhk5-Z44XrpkWQAC_UQ"]
[Tue Jul 21 07:30:11.621090 2026] [security2:error] [pid 229246:tid 229303] [remote 66.249.79.128:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sejabarbara.com.br"] [uri "/robots.txt"] [unique_id "al9KMyBMYeh5YLVG45yJKQACHTg"]
[Tue Jul 21 07:30:11.759527 2026] [security2:error] [pid 230252:tid 230389] [client 136.144.33.111:28273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KM00Dwhk5-Z44XrpkWgAAAp4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:11.929013 2026] [security2:error] [pid 230252:tid 230471] [client 109.248.148.246:59660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9KM00Dwhk5-Z44XrpkYAAAAvA"]
[Tue Jul 21 07:30:11.929137 2026] [security2:error] [pid 230252:tid 230471] [client 109.248.148.246:59660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9KM00Dwhk5-Z44XrpkYAAAAvA"]
[Tue Jul 21 07:30:12.212852 2026] [security2:error] [pid 230252:tid 230498] [client 20.104.96.117:59838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/cilus.php"] [unique_id "al9KNE0Dwhk5-Z44XrpkZgAAAws"]
[Tue Jul 21 07:30:12.260669 2026] [security2:error] [pid 230252:tid 230343] [remote 66.249.79.130:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sejabarbara.com.br"] [uri "/sindrome-do-impostor/"] [unique_id "al9KNE0Dwhk5-Z44XrpkaQAC6lg"]
[Tue Jul 21 07:30:12.290851 2026] [security2:error] [pid 230252:tid 230488] [client 45.8.17.48:65245] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/2021/10/"] [unique_id "al9KNE0Dwhk5-Z44XrpkawAAAwE"]
[Tue Jul 21 07:30:12.451158 2026] [security2:error] [pid 230252:tid 230458] [client 20.220.225.223:62897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/fz.php"] [unique_id "al9KNE0Dwhk5-Z44XrpkbgAAAuM"]
[Tue Jul 21 07:30:12.702088 2026] [security2:error] [pid 229246:tid 229268] [remote 20.153.140.50:35714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "manual.fernandohipolito.com.br"] [uri "/wp-login.php"] [unique_id "al9KNCBMYeh5YLVG45yJOgACFhU"]
[Tue Jul 21 07:30:12.766446 2026] [security2:error] [pid 229246:tid 229305] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KNCBMYeh5YLVG45yJOwACGjo"]
[Tue Jul 21 07:30:12.766573 2026] [security2:error] [pid 229246:tid 229382] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KNCBMYeh5YLVG45yJOwACGjo"]
[Tue Jul 21 07:30:13.239606 2026] [security2:error] [pid 230252:tid 230426] [client 117.251.86.144:32834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KNU0Dwhk5-Z44XrpkfQAAAsM"]
[Tue Jul 21 07:30:13.239735 2026] [security2:error] [pid 230252:tid 230426] [client 117.251.86.144:32834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KNU0Dwhk5-Z44XrpkfQAAAsM"]
[Tue Jul 21 07:30:13.321112 2026] [security2:error] [pid 230252:tid 230496] [client 62.102.148.164:39440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KNU0Dwhk5-Z44XrpkgAAAAwk"]
[Tue Jul 21 07:30:13.321215 2026] [security2:error] [pid 230252:tid 230496] [client 62.102.148.164:39440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KNU0Dwhk5-Z44XrpkgAAAAwk"]
[Tue Jul 21 07:30:13.494532 2026] [security2:error] [pid 230252:tid 230504] [client 139.135.44.145:53388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KNU0Dwhk5-Z44XrpkggAAAxE"]
[Tue Jul 21 07:30:13.494665 2026] [security2:error] [pid 230252:tid 230504] [client 139.135.44.145:53388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KNU0Dwhk5-Z44XrpkggAAAxE"]
[Tue Jul 21 07:30:13.585547 2026] [security2:error] [pid 229246:tid 229497] [client 45.8.17.117:57377] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/widgets/admin.php"] [unique_id "al9KNSBMYeh5YLVG45yJRwAAAo0"]
[Tue Jul 21 07:30:13.613649 2026] [security2:error] [pid 230252:tid 230436] [client 82.102.28.107:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9KNU0Dwhk5-Z44XrpkiAAAAs0"]
[Tue Jul 21 07:30:13.613750 2026] [security2:error] [pid 230252:tid 230436] [client 82.102.28.107:49848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9KNU0Dwhk5-Z44XrpkiAAAAs0"]
[Tue Jul 21 07:30:13.664937 2026] [security2:error] [pid 230252:tid 230404] [client 109.248.148.246:58758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KNU0Dwhk5-Z44XrpkiQAAAq0"]
[Tue Jul 21 07:30:13.665083 2026] [security2:error] [pid 230252:tid 230404] [client 109.248.148.246:58758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KNU0Dwhk5-Z44XrpkiQAAAq0"]
[Tue Jul 21 07:30:13.949542 2026] [security2:error] [pid 230252:tid 230511] [client 20.104.96.117:59587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/gptsh.php"] [unique_id "al9KNU0Dwhk5-Z44XrpkjAAAAxg"]
[Tue Jul 21 07:30:14.122219 2026] [security2:error] [pid 229246:tid 229485] [client 20.220.225.223:46094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9KNiBMYeh5YLVG45yJTgAAAoE"]
[Tue Jul 21 07:30:14.586152 2026] [security2:error] [pid 229246:tid 229477] [client 45.8.17.136:53385] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/tinymce/themes/"] [unique_id "al9KNiBMYeh5YLVG45yJWAAAAnk"]
[Tue Jul 21 07:30:14.809583 2026] [security2:error] [pid 230252:tid 230494] [client 85.204.70.92:46152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.frsadvocacia.net"] [uri "/wp-login.php"] [unique_id "al9KNk0Dwhk5-Z44XrpklAAAAwc"]
[Tue Jul 21 07:30:15.024276 2026] [autoindex:error] [pid 229246:tid 229439] [client 100.50.152.193:53401] AH01276: Cannot serve directory /home2/onfiel33/kotovicz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:15.362735 2026] [security2:error] [pid 229246:tid 229422] [client 20.220.225.223:46136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/dr.php"] [unique_id "al9KNyBMYeh5YLVG45yJZgAAAkI"]
[Tue Jul 21 07:30:15.373421 2026] [security2:error] [pid 229246:tid 229297] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KNyBMYeh5YLVG45yJaAACezI"]
[Tue Jul 21 07:30:15.373548 2026] [security2:error] [pid 229246:tid 229479] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KNyBMYeh5YLVG45yJaAACezI"]
[Tue Jul 21 07:30:15.384721 2026] [security2:error] [pid 230252:tid 230480] [client 45.8.17.105:20279] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/social-link/"] [unique_id "al9KN00Dwhk5-Z44XrpkmwAAAvk"]
[Tue Jul 21 07:30:15.420533 2026] [security2:error] [pid 230252:tid 230403] [client 136.144.33.241:34797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KN00Dwhk5-Z44XrpknAAAAqw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:15.618285 2026] [security2:error] [pid 229246:tid 229480] [client 209.141.34.121:64547] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "patriciarodriguesterapia.com.br"] [uri "/"] [unique_id "al9KNyBMYeh5YLVG45yJbQAAAnw"]
[Tue Jul 21 07:30:15.732030 2026] [security2:error] [pid 230252:tid 230475] [client 103.106.20.201:60356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KN00Dwhk5-Z44XrpkoAAAAvQ"]
[Tue Jul 21 07:30:15.732164 2026] [security2:error] [pid 230252:tid 230475] [client 103.106.20.201:60356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KN00Dwhk5-Z44XrpkoAAAAvQ"]
[Tue Jul 21 07:30:15.959338 2026] [security2:error] [pid 229246:tid 229330] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KNyBMYeh5YLVG45yJcwACc1M"]
[Tue Jul 21 07:30:15.959535 2026] [security2:error] [pid 229246:tid 229471] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KNyBMYeh5YLVG45yJcwACc1M"]
[Tue Jul 21 07:30:16.065481 2026] [security2:error] [pid 230252:tid 230425] [client 20.104.96.117:42397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/rithin.php"] [unique_id "al9KOE0Dwhk5-Z44XrpkpAAAAsI"]
[Tue Jul 21 07:30:16.123693 2026] [security2:error] [pid 230252:tid 230452] [client 103.162.129.114:53331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KOE0Dwhk5-Z44XrpkpgAAAt0"]
[Tue Jul 21 07:30:16.123869 2026] [security2:error] [pid 230252:tid 230452] [client 103.162.129.114:53331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KOE0Dwhk5-Z44XrpkpgAAAt0"]
[Tue Jul 21 07:30:16.128719 2026] [security2:error] [pid 230252:tid 230462] [client 209.141.34.121:64610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "patriciarodriguesterapia.com.br"] [uri "/"] [unique_id "al9KOE0Dwhk5-Z44XrpkpwAAAuc"]
[Tue Jul 21 07:30:16.336132 2026] [security2:error] [pid 230252:tid 230438] [client 20.151.10.161:57362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KOE0Dwhk5-Z44XrpkqgAAAs8"]
[Tue Jul 21 07:30:16.598694 2026] [security2:error] [pid 230252:tid 230506] [client 45.8.17.121:45789] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-good.php"] [unique_id "al9KOE0Dwhk5-Z44XrpkrwAAAxM"]
[Tue Jul 21 07:30:16.958466 2026] [security2:error] [pid 230252:tid 230321] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KOE0Dwhk5-Z44XrpktQACrUM"]
[Tue Jul 21 07:30:16.958666 2026] [security2:error] [pid 230252:tid 230404] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KOE0Dwhk5-Z44XrpktQACrUM"]
[Tue Jul 21 07:30:16.972986 2026] [security2:error] [pid 230252:tid 230259] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KOE0Dwhk5-Z44XrpktgACngU"]
[Tue Jul 21 07:30:16.973112 2026] [security2:error] [pid 230252:tid 230389] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KOE0Dwhk5-Z44XrpktgACngU"]
[Tue Jul 21 07:30:17.034832 2026] [security2:error] [pid 230252:tid 230468] [client 175.45.70.82:62354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KOU0Dwhk5-Z44XrpkuAAAAu0"]
[Tue Jul 21 07:30:17.034937 2026] [security2:error] [pid 230252:tid 230468] [client 175.45.70.82:62354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KOU0Dwhk5-Z44XrpkuAAAAu0"]
[Tue Jul 21 07:30:17.153882 2026] [security2:error] [pid 230252:tid 230454] [client 154.192.233.199:59875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KOU0Dwhk5-Z44XrpkugAAAt8"]
[Tue Jul 21 07:30:17.153990 2026] [security2:error] [pid 230252:tid 230454] [client 154.192.233.199:59875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KOU0Dwhk5-Z44XrpkugAAAt8"]
[Tue Jul 21 07:30:17.492455 2026] [security2:error] [pid 229246:tid 229468] [client 45.8.17.125:29797] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/elementor/css/"] [unique_id "al9KOSBMYeh5YLVG45yJhQAAAnA"]
[Tue Jul 21 07:30:17.801151 2026] [security2:error] [pid 230252:tid 230501] [client 103.174.34.15:55065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KOU0Dwhk5-Z44XrpkvgAAAw4"]
[Tue Jul 21 07:30:17.801303 2026] [security2:error] [pid 230252:tid 230501] [client 103.174.34.15:55065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KOU0Dwhk5-Z44XrpkvgAAAw4"]
[Tue Jul 21 07:30:17.844506 2026] [security2:error] [pid 229246:tid 229436] [client 173.24.185.52:52165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KOSBMYeh5YLVG45yJiAAAAlA"]
[Tue Jul 21 07:30:17.844600 2026] [security2:error] [pid 229246:tid 229436] [client 173.24.185.52:52165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KOSBMYeh5YLVG45yJiAAAAlA"]
[Tue Jul 21 07:30:18.081731 2026] [security2:error] [pid 229246:tid 229452] [client 62.102.148.164:44218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9KOiBMYeh5YLVG45yJkwAAAmA"]
[Tue Jul 21 07:30:18.081871 2026] [security2:error] [pid 229246:tid 229452] [client 62.102.148.164:44218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9KOiBMYeh5YLVG45yJkwAAAmA"]
[Tue Jul 21 07:30:18.371082 2026] [security2:error] [pid 229246:tid 229494] [client 173.252.95.39:52968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9KOiBMYeh5YLVG45yJnQAAAoo"]
[Tue Jul 21 07:30:18.386543 2026] [security2:error] [pid 229246:tid 229403] [client 45.8.17.121:24275] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/config.php"] [unique_id "al9KOiBMYeh5YLVG45yJngAAAi8"]
[Tue Jul 21 07:30:18.421187 2026] [security2:error] [pid 230252:tid 230455] [client 20.104.96.117:42290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/fffm.php"] [unique_id "al9KOk0Dwhk5-Z44XrpkwwAAAuA"]
[Tue Jul 21 07:30:18.502901 2026] [security2:error] [pid 229246:tid 229384] [client 20.220.225.223:4595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KOiBMYeh5YLVG45yJogAAAhw"]
[Tue Jul 21 07:30:19.329793 2026] [security2:error] [pid 230252:tid 230430] [client 82.102.28.107:39302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KO00Dwhk5-Z44XrpkygAAAsc"]
[Tue Jul 21 07:30:19.329893 2026] [security2:error] [pid 230252:tid 230430] [client 82.102.28.107:39302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KO00Dwhk5-Z44XrpkygAAAsc"]
[Tue Jul 21 07:30:19.400114 2026] [security2:error] [pid 229246:tid 229500] [client 114.119.144.84:48905] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tryhealth.shop"] [uri "/"] [unique_id "al9KOyBMYeh5YLVG45yJsQAAApA"], referer: https://newlyregddomains.com/2024-02-02/44
[Tue Jul 21 07:30:19.574548 2026] [security2:error] [pid 229246:tid 229396] [client 20.151.10.161:51298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KOyBMYeh5YLVG45yJtwAAAig"]
[Tue Jul 21 07:30:19.601029 2026] [security2:error] [pid 230252:tid 230500] [client 45.8.17.146:54575] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/rest-api/endpoints/"] [unique_id "al9KO00Dwhk5-Z44XrpkzgAAAw0"]
[Tue Jul 21 07:30:19.868570 2026] [proxy:error] [pid 230252:tid 230493] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:30:19.868641 2026] [proxy_http:error] [pid 230252:tid 230493] [client 195.96.139.107:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:30:19.869083 2026] [proxy:error] [pid 230252:tid 230493] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:30:19.869112 2026] [proxy_http:error] [pid 230252:tid 230493] [client 195.96.139.107:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:30:19.885025 2026] [security2:error] [pid 229246:tid 229459] [client 152.59.154.239:57203] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KOiBMYeh5YLVG45yJowAAAmc"]
[Tue Jul 21 07:30:19.885174 2026] [security2:error] [pid 229246:tid 229459] [client 152.59.154.239:57203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KOiBMYeh5YLVG45yJowAAAmc"]
[Tue Jul 21 07:30:20.115454 2026] [security2:error] [pid 229246:tid 229481] [client 136.144.33.53:54683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KPCBMYeh5YLVG45yJwAAAAn0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:20.483430 2026] [security2:error] [pid 230252:tid 230468] [client 45.8.17.122:50603] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/theme-compat/chosen.php"] [unique_id "al9KPE0Dwhk5-Z44Xrpk2gAAAu0"]
[Tue Jul 21 07:30:20.689372 2026] [security2:error] [pid 230252:tid 230414] [client 20.220.225.223:45963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/2x.php"] [unique_id "al9KPE0Dwhk5-Z44Xrpk3AAAArc"]
[Tue Jul 21 07:30:20.710327 2026] [security2:error] [pid 230252:tid 230443] [client 45.251.232.145:59881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KPE0Dwhk5-Z44Xrpk3QAAAtQ"]
[Tue Jul 21 07:30:20.710465 2026] [security2:error] [pid 230252:tid 230443] [client 45.251.232.145:59881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KPE0Dwhk5-Z44Xrpk3QAAAtQ"]
[Tue Jul 21 07:30:20.864968 2026] [security2:error] [pid 230252:tid 230421] [client 20.104.96.117:59792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/dfre.php"] [unique_id "al9KPE0Dwhk5-Z44Xrpk4QAAAr4"]
[Tue Jul 21 07:30:20.978882 2026] [security2:error] [pid 230252:tid 230488] [client 74.7.244.12:36430] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "l-attohome.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9KPE0Dwhk5-Z44Xrpk5gADAXo"]
[Tue Jul 21 07:30:21.028555 2026] [security2:error] [pid 229246:tid 229454] [client 20.151.10.161:50885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/x.php"] [unique_id "al9KPSBMYeh5YLVG45yJzAAAAmI"]
[Tue Jul 21 07:30:21.045873 2026] [security2:error] [pid 229246:tid 229399] [client 62.102.148.164:40502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9KPSBMYeh5YLVG45yJzQAAAis"]
[Tue Jul 21 07:30:21.045973 2026] [security2:error] [pid 229246:tid 229399] [client 62.102.148.164:40502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9KPSBMYeh5YLVG45yJzQAAAis"]
[Tue Jul 21 07:30:21.357659 2026] [security2:error] [pid 229246:tid 229422] [client 20.220.225.223:45981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/kq1.php"] [unique_id "al9KPSBMYeh5YLVG45yJ1QAAAkI"]
[Tue Jul 21 07:30:21.689431 2026] [security2:error] [pid 230252:tid 230446] [client 45.8.17.145:22109] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/root.php"] [unique_id "al9KPU0Dwhk5-Z44XrplMgAAAtc"]
[Tue Jul 21 07:30:21.837681 2026] [security2:error] [pid 230252:tid 230493] [client 20.206.105.145:7472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KPU0Dwhk5-Z44XrplOAAAAwY"]
[Tue Jul 21 07:30:21.985594 2026] [security2:error] [pid 229246:tid 229391] [client 20.151.10.161:50904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/j260624_13.php"] [unique_id "al9KPSBMYeh5YLVG45yJ4AAAAiM"]
[Tue Jul 21 07:30:22.043512 2026] [security2:error] [pid 230252:tid 230369] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KPk0Dwhk5-Z44XrplPwADE3I"]
[Tue Jul 21 07:30:22.043670 2026] [security2:error] [pid 230252:tid 230506] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KPk0Dwhk5-Z44XrplPwADE3I"]
[Tue Jul 21 07:30:22.368891 2026] [security2:error] [pid 229246:tid 229460] [client 20.220.225.223:46114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/zzz.php"] [unique_id "al9KPiBMYeh5YLVG45yJ5AAAAmg"]
[Tue Jul 21 07:30:22.578797 2026] [autoindex:error] [pid 230252:tid 230465] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:22.597101 2026] [security2:error] [pid 230252:tid 230467] [client 45.8.17.110:37249] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/widgets/"] [unique_id "al9KPk0Dwhk5-Z44XrplSAAAAuw"]
[Tue Jul 21 07:30:23.127694 2026] [security2:error] [pid 230252:tid 230413] [client 20.206.105.145:7777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KP00Dwhk5-Z44XrplUAAAArY"]
[Tue Jul 21 07:30:23.138993 2026] [security2:error] [pid 230252:tid 230318] [remote 34.91.119.153:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.luminabeauty.com.br"] [uri "/"] [unique_id "al9KP00Dwhk5-Z44XrplUQADDkA"]
[Tue Jul 21 07:30:23.139130 2026] [security2:error] [pid 230252:tid 230501] [client 34.91.119.153:0] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.luminabeauty.com.br"] [uri "/"] [unique_id "al9KP00Dwhk5-Z44XrplUQADDkA"]
[Tue Jul 21 07:30:23.233095 2026] [autoindex:error] [pid 230252:tid 230433] [client 175.27.171.245:50560] AH01276: Cannot serve directory /home2/onfiel33/lucaskotovicz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:23.297276 2026] [security2:error] [pid 230252:tid 230380] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KP00Dwhk5-Z44XrplUwAC430"]
[Tue Jul 21 07:30:23.297400 2026] [security2:error] [pid 230252:tid 230458] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KP00Dwhk5-Z44XrplUwAC430"]
[Tue Jul 21 07:30:23.487101 2026] [autoindex:error] [pid 230252:tid 230455] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:23.602121 2026] [security2:error] [pid 230252:tid 230494] [client 20.206.105.145:7747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/media.php"] [unique_id "al9KP00Dwhk5-Z44XrplVwAAAwc"]
[Tue Jul 21 07:30:23.691731 2026] [security2:error] [pid 229246:tid 229491] [client 20.220.225.223:46088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/wicked.php"] [unique_id "al9KPyBMYeh5YLVG45yJ9wAAAoc"]
[Tue Jul 21 07:30:23.835943 2026] [authz_core:error] [pid 230252:tid 230469] [client 85.204.70.92:33458] AH01630: client denied by server configuration: /home3/frsadv16/public_html/wp-content/plugins/akismet/
[Tue Jul 21 07:30:23.938580 2026] [security2:error] [pid 230252:tid 230456] [client 117.251.86.144:33434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KP00Dwhk5-Z44XrplWgAAAuE"]
[Tue Jul 21 07:30:23.938710 2026] [security2:error] [pid 230252:tid 230456] [client 117.251.86.144:33434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KP00Dwhk5-Z44XrplWgAAAuE"]
[Tue Jul 21 07:30:23.978609 2026] [security2:error] [pid 229246:tid 229459] [client 20.151.10.161:51319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/d62.php"] [unique_id "al9KPyBMYeh5YLVG45yJ-gAAAmc"]
[Tue Jul 21 07:30:24.048969 2026] [autoindex:error] [pid 230252:tid 230403] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:24.272536 2026] [security2:error] [pid 230252:tid 230350] [remote 4.205.168.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/wp-login.php"] [unique_id "al9KQE0Dwhk5-Z44XrplXQACwV8"]
[Tue Jul 21 07:30:24.295066 2026] [security2:error] [pid 229246:tid 229483] [client 20.220.225.223:61958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KQCBMYeh5YLVG45yKAgAAAn8"]
[Tue Jul 21 07:30:24.342975 2026] [autoindex:error] [pid 230252:tid 230510] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:24.446517 2026] [security2:error] [pid 229246:tid 229451] [client 139.135.44.145:54161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KQCBMYeh5YLVG45yKAwAAAl8"]
[Tue Jul 21 07:30:24.446643 2026] [security2:error] [pid 229246:tid 229451] [client 139.135.44.145:54161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KQCBMYeh5YLVG45yKAwAAAl8"]
[Tue Jul 21 07:30:24.457397 2026] [security2:error] [pid 230252:tid 230446] [client 20.206.105.145:54588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/images.php"] [unique_id "al9KQE0Dwhk5-Z44XrplYgAAAtc"]
[Tue Jul 21 07:30:24.549204 2026] [security2:error] [pid 230252:tid 230493] [client 20.197.192.193:44117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KQE0Dwhk5-Z44XrplZwAAAwY"]
[Tue Jul 21 07:30:24.556619 2026] [autoindex:error] [pid 230252:tid 230500] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:24.689859 2026] [security2:error] [pid 230252:tid 230396] [client 136.144.33.104:22903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KQE0Dwhk5-Z44XrplZAAAAqU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:24.742317 2026] [security2:error] [pid 229246:tid 229482] [client 20.197.192.193:40809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KQCBMYeh5YLVG45yKDQAAAn4"]
[Tue Jul 21 07:30:24.785984 2026] [security2:error] [pid 229246:tid 229492] [client 20.197.192.193:53294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/dp.php"] [unique_id "al9KQCBMYeh5YLVG45yKDwAAAog"]
[Tue Jul 21 07:30:24.786980 2026] [security2:error] [pid 230252:tid 230475] [client 45.8.17.112:61073] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/class.php"] [unique_id "al9KQE0Dwhk5-Z44XrplcAAAAvQ"]
[Tue Jul 21 07:30:24.829393 2026] [autoindex:error] [pid 230252:tid 230428] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:24.833788 2026] [security2:error] [pid 229246:tid 229494] [client 20.197.192.193:44112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/old.php"] [unique_id "al9KQCBMYeh5YLVG45yKEQAAAoo"]
[Tue Jul 21 07:30:24.859339 2026] [security2:error] [pid 229246:tid 229474] [client 20.197.192.193:44155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/ms-new.php"] [unique_id "al9KQCBMYeh5YLVG45yKEgAAAnY"]
[Tue Jul 21 07:30:24.876892 2026] [security2:error] [pid 229246:tid 229487] [client 59.96.220.140:55748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KQCBMYeh5YLVG45yKEwAAAoM"]
[Tue Jul 21 07:30:24.877715 2026] [security2:error] [pid 229246:tid 229487] [client 59.96.220.140:55748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KQCBMYeh5YLVG45yKEwAAAoM"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:30:24.936760 2026] [security2:error] [pid 230252:tid 230405] [client 20.197.192.193:40805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/track.php"] [unique_id "al9KQE0Dwhk5-Z44XrplcwAAAq4"]
[Tue Jul 21 07:30:24.962409 2026] [security2:error] [pid 230252:tid 230389] [client 20.197.192.193:40789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/2352356666.php"] [unique_id "al9KQE0Dwhk5-Z44XrpldAAAAp4"]
[Tue Jul 21 07:30:24.992799 2026] [security2:error] [pid 230252:tid 230441] [client 20.197.192.193:40817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/pn.php"] [unique_id "al9KQE0Dwhk5-Z44XrpldQAAAtI"]
[Tue Jul 21 07:30:25.011272 2026] [security2:error] [pid 230252:tid 230386] [client 20.197.192.193:40776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9KQU0Dwhk5-Z44XrpldgAAAps"]
[Tue Jul 21 07:30:25.029746 2026] [security2:error] [pid 230252:tid 230511] [client 20.197.192.193:40788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/dr.php"] [unique_id "al9KQU0Dwhk5-Z44XrpldwAAAxg"]
[Tue Jul 21 07:30:25.054142 2026] [autoindex:error] [pid 230252:tid 230465] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:25.065885 2026] [security2:error] [pid 230252:tid 230467] [client 20.220.225.223:46138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/edit.php"] [unique_id "al9KQU0Dwhk5-Z44XrplewAAAuw"]
[Tue Jul 21 07:30:25.089789 2026] [security2:error] [pid 230252:tid 230384] [client 20.197.192.193:53297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/2x.php"] [unique_id "al9KQU0Dwhk5-Z44XrplfAAAApk"]
[Tue Jul 21 07:30:25.161635 2026] [security2:error] [pid 230252:tid 230399] [client 20.151.10.161:51274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/ups.php"] [unique_id "al9KQU0Dwhk5-Z44XrplgQAAAqg"]
[Tue Jul 21 07:30:25.176085 2026] [security2:error] [pid 230252:tid 230466] [client 20.197.192.193:44098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/kq1.php"] [unique_id "al9KQU0Dwhk5-Z44XrplggAAAus"]
[Tue Jul 21 07:30:25.248191 2026] [security2:error] [pid 230252:tid 230481] [client 20.197.192.193:44145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/zzz.php"] [unique_id "al9KQU0Dwhk5-Z44XrpliAAAAvo"]
[Tue Jul 21 07:30:25.268042 2026] [security2:error] [pid 230252:tid 230483] [client 20.197.192.193:44158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/wicked.php"] [unique_id "al9KQU0Dwhk5-Z44XrpljAAAAvw"]
[Tue Jul 21 07:30:25.294902 2026] [security2:error] [pid 230252:tid 230485] [client 20.197.192.193:44107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/edit.php"] [unique_id "al9KQU0Dwhk5-Z44XrpljQAAAv4"]
[Tue Jul 21 07:30:25.327801 2026] [autoindex:error] [pid 230252:tid 230448] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:25.334249 2026] [security2:error] [pid 230252:tid 230449] [client 20.197.192.193:44156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/kua.php"] [unique_id "al9KQU0Dwhk5-Z44XrpljwAAAto"]
[Tue Jul 21 07:30:25.366618 2026] [security2:error] [pid 230252:tid 230401] [client 20.197.192.193:44101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/ez.php"] [unique_id "al9KQU0Dwhk5-Z44XrplkwAAAqo"]
[Tue Jul 21 07:30:25.369677 2026] [security2:error] [pid 230252:tid 230490] [client 20.206.105.145:7767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/adminner.php"] [unique_id "al9KQU0Dwhk5-Z44XrpllAAAAwM"]
[Tue Jul 21 07:30:25.516954 2026] [security2:error] [pid 229246:tid 229415] [client 20.197.192.193:40829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/fz.php"] [unique_id "al9KQSBMYeh5YLVG45yKHAAAAjs"]
[Tue Jul 21 07:30:25.538303 2026] [autoindex:error] [pid 230252:tid 230409] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:25.677597 2026] [security2:error] [pid 229246:tid 229385] [client 20.220.225.223:8936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/la.php"] [unique_id "al9KQSBMYeh5YLVG45yKHwAAAh0"]
[Tue Jul 21 07:30:25.726683 2026] [security2:error] [pid 229246:tid 229376] [client 20.197.192.193:40799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/la.php"] [unique_id "al9KQSBMYeh5YLVG45yKIAAAAhQ"]
[Tue Jul 21 07:30:25.745267 2026] [autoindex:error] [pid 230252:tid 230428] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:25.779389 2026] [security2:error] [pid 229246:tid 229473] [client 20.197.192.193:40814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9KQSBMYeh5YLVG45yKIQAAAnU"]
[Tue Jul 21 07:30:25.787014 2026] [security2:error] [pid 229246:tid 229428] [client 45.8.17.62:56127] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "al9KQSBMYeh5YLVG45yKIgAAAkg"]
[Tue Jul 21 07:30:25.792764 2026] [security2:error] [pid 229246:tid 229455] [client 20.197.192.193:44122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/inso.php"] [unique_id "al9KQSBMYeh5YLVG45yKIwAAAmM"]
[Tue Jul 21 07:30:25.820475 2026] [security2:error] [pid 230252:tid 230477] [client 74.7.228.30:45502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.espacofabula.com"] [uri "/index.php"] [unique_id "al9KQU0Dwhk5-Z44XrpliwAC9kY"]
[Tue Jul 21 07:30:25.832034 2026] [security2:error] [pid 229246:tid 229408] [client 20.197.192.193:44099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/wpx.php"] [unique_id "al9KQSBMYeh5YLVG45yKJgAAAjQ"]
[Tue Jul 21 07:30:25.864341 2026] [security2:error] [pid 230252:tid 230405] [client 20.197.192.193:44153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/berlin.php"] [unique_id "al9KQU0Dwhk5-Z44XrplnwAAAq4"]
[Tue Jul 21 07:30:25.872843 2026] [security2:error] [pid 229246:tid 229252] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KQSBMYeh5YLVG45yKJwACXQU"]
[Tue Jul 21 07:30:25.872984 2026] [security2:error] [pid 229246:tid 229449] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KQSBMYeh5YLVG45yKJwACXQU"]
[Tue Jul 21 07:30:25.895307 2026] [security2:error] [pid 230252:tid 230389] [client 20.197.192.193:40771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/billur.php"] [unique_id "al9KQU0Dwhk5-Z44XrploQAAAp4"]
[Tue Jul 21 07:30:25.937112 2026] [security2:error] [pid 230252:tid 230502] [client 20.197.192.193:44126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/mimpi.php"] [unique_id "al9KQU0Dwhk5-Z44XrplogAAAw8"]
[Tue Jul 21 07:30:25.956716 2026] [security2:error] [pid 230252:tid 230443] [client 20.197.192.193:40791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/dp.php"] [unique_id "al9KQU0Dwhk5-Z44XrplowAAAtQ"]
[Tue Jul 21 07:30:26.099672 2026] [security2:error] [pid 230252:tid 230484] [client 20.197.192.193:44105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/bootstrap.php"] [unique_id "al9KQk0Dwhk5-Z44XrplpgAAAv0"]
[Tue Jul 21 07:30:26.234256 2026] [security2:error] [pid 229246:tid 229500] [client 20.197.192.193:40773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/wp-editor.php"] [unique_id "al9KQiBMYeh5YLVG45yKLgAAApA"]
[Tue Jul 21 07:30:26.234635 2026] [security2:error] [pid 229246:tid 229441] [client 20.104.96.117:59814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-happy.php"] [unique_id "al9KQiBMYeh5YLVG45yKLwAAAlU"]
[Tue Jul 21 07:30:26.360358 2026] [security2:error] [pid 229246:tid 229459] [client 20.151.10.161:50929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/k.php"] [unique_id "al9KQiBMYeh5YLVG45yKMAAAAmc"]
[Tue Jul 21 07:30:26.374461 2026] [security2:error] [pid 229246:tid 229481] [client 20.197.192.193:40794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/cro.php"] [unique_id "al9KQiBMYeh5YLVG45yKMgAAAn0"]
[Tue Jul 21 07:30:26.433311 2026] [security2:error] [pid 229246:tid 229468] [client 20.197.192.193:40770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/cron-tab.php"] [unique_id "al9KQiBMYeh5YLVG45yKMwAAAnA"]
[Tue Jul 21 07:30:26.437421 2026] [security2:error] [pid 229246:tid 229409] [client 103.106.20.201:60922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KQiBMYeh5YLVG45yKNAAAAjU"]
[Tue Jul 21 07:30:26.437553 2026] [security2:error] [pid 229246:tid 229409] [client 103.106.20.201:60922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KQiBMYeh5YLVG45yKNAAAAjU"]
[Tue Jul 21 07:30:26.480342 2026] [security2:error] [pid 229246:tid 229288] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KQiBMYeh5YLVG45yKNQAChyk"]
[Tue Jul 21 07:30:26.480969 2026] [security2:error] [pid 229246:tid 229491] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KQiBMYeh5YLVG45yKNQAChyk"]
[Tue Jul 21 07:30:26.481166 2026] [security2:error] [pid 229246:tid 229496] [client 20.197.192.193:40800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/koiy.php"] [unique_id "al9KQiBMYeh5YLVG45yKNgAAAow"]
[Tue Jul 21 07:30:26.500529 2026] [security2:error] [pid 229246:tid 229489] [client 20.197.192.193:40780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/hp2.php"] [unique_id "al9KQiBMYeh5YLVG45yKNwAAAoU"]
[Tue Jul 21 07:30:26.530497 2026] [security2:error] [pid 229246:tid 229483] [client 20.197.192.193:44129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/hp3.php"] [unique_id "al9KQiBMYeh5YLVG45yKOAAAAn8"]
[Tue Jul 21 07:30:26.568315 2026] [security2:error] [pid 230252:tid 230404] [client 103.162.129.114:53776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KQk0Dwhk5-Z44XrplqAAAAq0"]
[Tue Jul 21 07:30:26.568473 2026] [security2:error] [pid 230252:tid 230404] [client 103.162.129.114:53776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KQk0Dwhk5-Z44XrplqAAAAq0"]
[Tue Jul 21 07:30:26.581013 2026] [security2:error] [pid 229246:tid 229451] [client 20.197.192.193:44102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/aa1.php"] [unique_id "al9KQiBMYeh5YLVG45yKOQAAAl8"]
[Tue Jul 21 07:30:26.597618 2026] [security2:error] [pid 229246:tid 229421] [client 20.206.105.145:7690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/admin.php"] [unique_id "al9KQiBMYeh5YLVG45yKOgAAAkE"]
[Tue Jul 21 07:30:26.632491 2026] [security2:error] [pid 229246:tid 229454] [client 20.197.192.193:44106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/acew67.php"] [unique_id "al9KQiBMYeh5YLVG45yKPgAAAmI"]
[Tue Jul 21 07:30:26.694984 2026] [security2:error] [pid 229246:tid 229387] [client 20.197.192.193:53251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/bscclapb.php"] [unique_id "al9KQiBMYeh5YLVG45yKQgAAAh8"]
[Tue Jul 21 07:30:26.729795 2026] [security2:error] [pid 229246:tid 229380] [client 20.197.192.193:40774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/else1.php"] [unique_id "al9KQiBMYeh5YLVG45yKRAAAAhg"]
[Tue Jul 21 07:30:26.747187 2026] [autoindex:error] [pid 229246:tid 229474] [client 85.204.70.92:60474] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:26.763655 2026] [security2:error] [pid 229246:tid 229472] [client 20.197.192.193:44096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/tkikikoko.php"] [unique_id "al9KQiBMYeh5YLVG45yKRwAAAnQ"]
[Tue Jul 21 07:30:26.802639 2026] [security2:error] [pid 229246:tid 229479] [client 20.197.192.193:40782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9KQiBMYeh5YLVG45yKSQAAAns"]
[Tue Jul 21 07:30:26.830731 2026] [security2:error] [pid 229246:tid 229448] [client 20.197.192.193:40825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/wp-css.php"] [unique_id "al9KQiBMYeh5YLVG45yKTQAAAlw"]
[Tue Jul 21 07:30:26.853589 2026] [security2:error] [pid 229246:tid 229397] [client 20.197.192.193:44134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/wp-explorer.php"] [unique_id "al9KQiBMYeh5YLVG45yKTgAAAik"]
[Tue Jul 21 07:30:26.878460 2026] [security2:error] [pid 229246:tid 229413] [client 20.197.192.193:44133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/akismet.php"] [unique_id "al9KQiBMYeh5YLVG45yKTwAAAjk"]
[Tue Jul 21 07:30:26.887135 2026] [security2:error] [pid 229246:tid 229393] [client 45.8.17.123:28719] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/news-portal/admins-dir.php"] [unique_id "al9KQiBMYeh5YLVG45yKUQAAAiU"]
[Tue Jul 21 07:30:26.911810 2026] [security2:error] [pid 229246:tid 229377] [client 20.151.10.161:50942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/k2.php"] [unique_id "al9KQiBMYeh5YLVG45yKUgAAAhU"]
[Tue Jul 21 07:30:26.913182 2026] [security2:error] [pid 229246:tid 229460] [client 20.197.192.193:44108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/ace2.php"] [unique_id "al9KQiBMYeh5YLVG45yKUwAAAmg"]
[Tue Jul 21 07:30:26.949077 2026] [security2:error] [pid 229246:tid 229480] [client 20.197.192.193:44149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/ms.php"] [unique_id "al9KQiBMYeh5YLVG45yKVQAAAnw"]
[Tue Jul 21 07:30:27.160573 2026] [security2:error] [pid 229246:tid 229378] [client 20.220.225.223:46015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/kua.php"] [unique_id "al9KQyBMYeh5YLVG45yKVwAAAhY"]
[Tue Jul 21 07:30:27.188668 2026] [security2:error] [pid 229246:tid 229457] [client 20.220.225.223:62871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9KQyBMYeh5YLVG45yKXgAAAmU"]
[Tue Jul 21 07:30:27.212855 2026] [autoindex:error] [pid 229246:tid 229398] [client 85.204.70.92:60474] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:27.275103 2026] [security2:error] [pid 229246:tid 229323] [remote 188.138.102.156:46806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9KQyBMYeh5YLVG45yKYQACekw"]
[Tue Jul 21 07:30:27.275270 2026] [security2:error] [pid 229246:tid 229478] [client 188.138.102.156:46806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9KQyBMYeh5YLVG45yKYQACekw"]
[Tue Jul 21 07:30:27.457891 2026] [autoindex:error] [pid 229246:tid 229493] [client 85.204.70.92:60474] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:27.546830 2026] [security2:error] [pid 229246:tid 229260] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KQyBMYeh5YLVG45yKaAACfQ0"]
[Tue Jul 21 07:30:27.547035 2026] [security2:error] [pid 229246:tid 229481] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KQyBMYeh5YLVG45yKaAACfQ0"]
[Tue Jul 21 07:30:27.585158 2026] [security2:error] [pid 229246:tid 229336] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KQyBMYeh5YLVG45yKaQACTFk"]
[Tue Jul 21 07:30:27.585936 2026] [security2:error] [pid 229246:tid 229432] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KQyBMYeh5YLVG45yKaQACTFk"]
[Tue Jul 21 07:30:27.682978 2026] [autoindex:error] [pid 229246:tid 229491] [client 85.204.70.92:60474] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:27.857879 2026] [security2:error] [pid 229246:tid 229452] [client 20.206.105.145:7730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/k.php"] [unique_id "al9KQyBMYeh5YLVG45yKdQAAAmA"]
[Tue Jul 21 07:30:27.878715 2026] [security2:error] [pid 229246:tid 229470] [client 175.45.70.82:62875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KQyBMYeh5YLVG45yKdgAAAnI"]
[Tue Jul 21 07:30:27.878851 2026] [security2:error] [pid 229246:tid 229470] [client 175.45.70.82:62875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KQyBMYeh5YLVG45yKdgAAAnI"]
[Tue Jul 21 07:30:27.973308 2026] [autoindex:error] [pid 229246:tid 229379] [client 85.204.70.92:60474] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:27.998295 2026] [security2:error] [pid 229246:tid 229484] [client 154.192.233.199:60368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KQyBMYeh5YLVG45yKegAAAoA"]
[Tue Jul 21 07:30:27.998429 2026] [security2:error] [pid 229246:tid 229484] [client 154.192.233.199:60368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KQyBMYeh5YLVG45yKegAAAoA"]
[Tue Jul 21 07:30:28.163274 2026] [security2:error] [pid 229246:tid 229454] [client 103.76.88.36:64157] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adsul.focsmart.com.br"] [uri "/.env"] [unique_id "al9KRCBMYeh5YLVG45yKfAAAAmI"]
[Tue Jul 21 07:30:28.184390 2026] [security2:error] [pid 229246:tid 229387] [client 85.208.96.202:34686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "vivaconcierge.com.br"] [uri "/en/_detalhes/gerador/"] [unique_id "al9KRCBMYeh5YLVG45yKfgAAAh8"]
[Tue Jul 21 07:30:28.184533 2026] [security2:error] [pid 229246:tid 229387] [client 85.208.96.202:34686] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "vivaconcierge.com.br"] [uri "/en/_detalhes/gerador/"] [unique_id "al9KRCBMYeh5YLVG45yKfgAAAh8"]
[Tue Jul 21 07:30:28.186237 2026] [security2:error] [pid 229246:tid 229380] [client 45.8.17.57:65501] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/js/chosen.php"] [unique_id "al9KRCBMYeh5YLVG45yKfwAAAhg"]
[Tue Jul 21 07:30:28.250374 2026] [autoindex:error] [pid 229246:tid 229416] [client 85.204.70.92:60474] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:28.303280 2026] [autoindex:error] [pid 229246:tid 229494] [client 198.235.24.15:62682] AH01276: Cannot serve directory /home2/cla35313/reidocouro.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:28.330236 2026] [security2:error] [pid 229246:tid 229381] [client 20.151.10.161:50892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/k3.php"] [unique_id "al9KRCBMYeh5YLVG45yKiQAAAhk"]
[Tue Jul 21 07:30:28.504121 2026] [security2:error] [pid 229246:tid 229487] [client 173.24.185.52:52635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KRCBMYeh5YLVG45yKkAAAAoM"]
[Tue Jul 21 07:30:28.504250 2026] [security2:error] [pid 229246:tid 229487] [client 173.24.185.52:52635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KRCBMYeh5YLVG45yKkAAAAoM"]
[Tue Jul 21 07:30:28.560086 2026] [security2:error] [pid 229246:tid 229498] [client 103.174.34.15:55552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KRCBMYeh5YLVG45yKkwAAAo4"]
[Tue Jul 21 07:30:28.560216 2026] [security2:error] [pid 229246:tid 229498] [client 103.174.34.15:55552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KRCBMYeh5YLVG45yKkwAAAo4"]
[Tue Jul 21 07:30:28.570519 2026] [autoindex:error] [pid 229246:tid 229428] [client 85.204.70.92:60474] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:28.781474 2026] [security2:error] [pid 229246:tid 229478] [client 20.220.225.223:45959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/ez.php"] [unique_id "al9KRCBMYeh5YLVG45yKmwAAAno"]
[Tue Jul 21 07:30:28.898328 2026] [security2:error] [pid 229246:tid 229500] [client 20.151.10.161:51303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/k4.php"] [unique_id "al9KRCBMYeh5YLVG45yKnQAAApA"]
[Tue Jul 21 07:30:28.976927 2026] [autoindex:error] [pid 229246:tid 229441] [client 85.204.70.92:60474] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:29.077643 2026] [security2:error] [pid 229246:tid 229481] [client 82.102.28.107:51058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9KRSBMYeh5YLVG45yKoQAAAn0"]
[Tue Jul 21 07:30:29.077747 2026] [security2:error] [pid 229246:tid 229481] [client 82.102.28.107:51058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9KRSBMYeh5YLVG45yKoQAAAn0"]
[Tue Jul 21 07:30:29.102389 2026] [security2:error] [pid 229246:tid 229462] [client 74.7.230.11:59320] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "havoy.com.br"] [uri "/index.php"] [unique_id "al9KQyBMYeh5YLVG45yKZAACal0"]
[Tue Jul 21 07:30:29.139021 2026] [security2:error] [pid 229246:tid 229409] [client 62.102.148.164:40518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KRSBMYeh5YLVG45yKowAAAjU"]
[Tue Jul 21 07:30:29.139155 2026] [security2:error] [pid 229246:tid 229409] [client 62.102.148.164:40518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KRSBMYeh5YLVG45yKowAAAjU"]
[Tue Jul 21 07:30:29.207596 2026] [security2:error] [pid 229246:tid 229491] [client 20.206.105.145:7481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/x.php"] [unique_id "al9KRSBMYeh5YLVG45yKpgAAAoc"]
[Tue Jul 21 07:30:29.326609 2026] [security2:error] [pid 229246:tid 229356] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KRSBMYeh5YLVG45yKsAACi20"]
[Tue Jul 21 07:30:29.326834 2026] [security2:error] [pid 229246:tid 229495] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KRSBMYeh5YLVG45yKsAACi20"]
[Tue Jul 21 07:30:29.386334 2026] [security2:error] [pid 229246:tid 229484] [client 213.152.162.104:57898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9KRSBMYeh5YLVG45yKsgAAAoA"]
[Tue Jul 21 07:30:29.386484 2026] [security2:error] [pid 229246:tid 229484] [client 213.152.162.104:57898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9KRSBMYeh5YLVG45yKsgAAAoA"]
[Tue Jul 21 07:30:29.725529 2026] [security2:error] [pid 229246:tid 229408] [client 152.59.154.239:57641] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KRSBMYeh5YLVG45yKvAAAAjQ"]
[Tue Jul 21 07:30:29.725665 2026] [security2:error] [pid 229246:tid 229408] [client 152.59.154.239:57641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KRSBMYeh5YLVG45yKvAAAAjQ"]
[Tue Jul 21 07:30:29.837771 2026] [security2:error] [pid 229246:tid 229405] [client 20.151.10.161:57365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/k5.php"] [unique_id "al9KRSBMYeh5YLVG45yKxgAAAjE"]
[Tue Jul 21 07:30:29.883299 2026] [security2:error] [pid 229246:tid 229404] [client 45.8.17.60:63043] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/classwithtostring.php"] [unique_id "al9KRSBMYeh5YLVG45yKxwAAAjA"]
[Tue Jul 21 07:30:30.140258 2026] [security2:error] [pid 229246:tid 229498] [client 20.206.105.145:7698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wss.php"] [unique_id "al9KRiBMYeh5YLVG45yKywAAAo4"]
[Tue Jul 21 07:30:30.186664 2026] [security2:error] [pid 229246:tid 229425] [client 20.104.96.117:59820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/fpr4.php"] [unique_id "al9KRiBMYeh5YLVG45yKzAAAAkU"]
[Tue Jul 21 07:30:30.375230 2026] [security2:error] [pid 229246:tid 229431] [client 136.144.33.98:30013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KRiBMYeh5YLVG45yK1gAAAks"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:30.659986 2026] [security2:error] [pid 229246:tid 229432] [client 20.206.105.145:7475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/ty.php"] [unique_id "al9KRiBMYeh5YLVG45yK2wAAAkw"]
[Tue Jul 21 07:30:30.814305 2026] [security2:error] [pid 229246:tid 229491] [client 20.206.105.145:7731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/155.php"] [unique_id "al9KRiBMYeh5YLVG45yK4QAAAoc"]
[Tue Jul 21 07:30:30.833200 2026] [security2:error] [pid 229246:tid 229400] [client 82.102.28.107:35664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9KRiBMYeh5YLVG45yK4gAAAiw"]
[Tue Jul 21 07:30:30.833306 2026] [security2:error] [pid 229246:tid 229400] [client 82.102.28.107:35664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9KRiBMYeh5YLVG45yK4gAAAiw"]
[Tue Jul 21 07:30:30.838822 2026] [security2:error] [pid 229246:tid 229490] [client 20.52.136.55:1557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/default.php"] [unique_id "al9KRiBMYeh5YLVG45yK4wAAAoY"]
[Tue Jul 21 07:30:30.898136 2026] [security2:error] [pid 229246:tid 229439] [client 20.206.105.145:7451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/ops.php"] [unique_id "al9KRiBMYeh5YLVG45yK5QAAAlM"]
[Tue Jul 21 07:30:31.018043 2026] [security2:error] [pid 229246:tid 229492] [client 20.206.105.145:54554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/ingfo.php"] [unique_id "al9KRyBMYeh5YLVG45yK6wAAAog"]
[Tue Jul 21 07:30:31.146326 2026] [security2:error] [pid 229246:tid 229335] [remote 173.252.95.21:60628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9KRyBMYeh5YLVG45yK9AACF1g"]
[Tue Jul 21 07:30:31.165243 2026] [security2:error] [pid 229246:tid 229377] [client 45.251.232.145:60402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KRyBMYeh5YLVG45yK9gAAAhU"]
[Tue Jul 21 07:30:31.165348 2026] [security2:error] [pid 229246:tid 229377] [client 45.251.232.145:60402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KRyBMYeh5YLVG45yK9gAAAhU"]
[Tue Jul 21 07:30:31.193881 2026] [security2:error] [pid 229246:tid 229389] [client 20.151.10.161:50895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/w.php"] [unique_id "al9KRyBMYeh5YLVG45yK9wAAAiE"]
[Tue Jul 21 07:30:31.349371 2026] [security2:error] [pid 229246:tid 229405] [client 20.206.105.145:7383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/error_log.php"] [unique_id "al9KRyBMYeh5YLVG45yK_gAAAjE"]
[Tue Jul 21 07:30:31.387488 2026] [security2:error] [pid 229246:tid 229445] [client 45.8.17.116:58213] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentytwo/templates/"] [unique_id "al9KRyBMYeh5YLVG45yK_wAAAlk"]
[Tue Jul 21 07:30:31.551739 2026] [security2:error] [pid 229246:tid 229394] [client 20.220.225.223:54508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/dp.php"] [unique_id "al9KRyBMYeh5YLVG45yLBQAAAiY"]
[Tue Jul 21 07:30:31.597547 2026] [security2:error] [pid 229246:tid 229425] [client 109.248.148.246:52752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9KRyBMYeh5YLVG45yLCgAAAkU"]
[Tue Jul 21 07:30:31.597681 2026] [security2:error] [pid 229246:tid 229425] [client 109.248.148.246:52752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9KRyBMYeh5YLVG45yLCgAAAkU"]
[Tue Jul 21 07:30:32.273624 2026] [security2:error] [pid 229246:tid 229490] [client 20.206.105.145:7750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/ok.php"] [unique_id "al9KSCBMYeh5YLVG45yLHAAAAoY"]
[Tue Jul 21 07:30:32.488903 2026] [security2:error] [pid 229246:tid 229452] [client 45.8.17.106:27901] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Requests/src/Utility/"] [unique_id "al9KSCBMYeh5YLVG45yLJAAAAmA"]
[Tue Jul 21 07:30:32.661855 2026] [security2:error] [pid 229246:tid 229256] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KSCBMYeh5YLVG45yLKAACiAk"]
[Tue Jul 21 07:30:32.662057 2026] [security2:error] [pid 229246:tid 229492] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KSCBMYeh5YLVG45yLKAACiAk"]
[Tue Jul 21 07:30:33.141082 2026] [security2:error] [pid 229246:tid 229465] [client 20.151.10.161:50935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/fpwch.php"] [unique_id "al9KSSBMYeh5YLVG45yLNwAAAm0"]
[Tue Jul 21 07:30:33.162258 2026] [security2:error] [pid 229246:tid 229418] [client 20.206.105.145:7708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/mac.php"] [unique_id "al9KSSBMYeh5YLVG45yLOQAAAj4"]
[Tue Jul 21 07:30:33.238040 2026] [security2:error] [pid 229246:tid 229319] [remote 103.112.62.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.62.112.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naldoinvest.com.br"] [uri "/wp-login.php"] [unique_id "al9KSSBMYeh5YLVG45yLOgACF0g"]
[Tue Jul 21 07:30:33.495987 2026] [security2:error] [pid 229246:tid 229500] [client 45.8.17.105:52937] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/sodium_compat/src/Core/"] [unique_id "al9KSSBMYeh5YLVG45yLQQAAApA"]
[Tue Jul 21 07:30:33.629476 2026] [security2:error] [pid 229246:tid 229411] [client 20.151.10.161:57454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/w2025.php"] [unique_id "al9KSSBMYeh5YLVG45yLRQAAAjc"]
[Tue Jul 21 07:30:33.657939 2026] [security2:error] [pid 229246:tid 229491] [client 20.220.225.223:45971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/fz.php"] [unique_id "al9KSSBMYeh5YLVG45yLRwAAAoc"]
[Tue Jul 21 07:30:33.681094 2026] [security2:error] [pid 229246:tid 229481] [client 20.220.225.223:62848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/inso.php"] [unique_id "al9KSSBMYeh5YLVG45yLSAAAAn0"]
[Tue Jul 21 07:30:33.808395 2026] [security2:error] [pid 229246:tid 229439] [client 20.206.105.145:7686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wefile.php"] [unique_id "al9KSSBMYeh5YLVG45yLSwAAAlM"]
[Tue Jul 21 07:30:33.845183 2026] [security2:error] [pid 229246:tid 229341] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KSSBMYeh5YLVG45yLTAACNV4"]
[Tue Jul 21 07:30:33.845434 2026] [security2:error] [pid 229246:tid 229409] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KSSBMYeh5YLVG45yLTAACNV4"]
[Tue Jul 21 07:30:33.924400 2026] [security2:error] [pid 229246:tid 229483] [client 20.104.96.117:42392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/file88.php"] [unique_id "al9KSSBMYeh5YLVG45yLTgAAAn8"]
[Tue Jul 21 07:30:34.055475 2026] [security2:error] [pid 229246:tid 229426] [client 59.96.220.140:56227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KSiBMYeh5YLVG45yLUgAAAkY"]
[Tue Jul 21 07:30:34.055631 2026] [security2:error] [pid 229246:tid 229426] [client 59.96.220.140:56227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KSiBMYeh5YLVG45yLUgAAAkY"]
[Tue Jul 21 07:30:34.160187 2026] [autoindex:error] [pid 229246:tid 229448] [client 85.204.70.92:60474] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:34.453150 2026] [security2:error] [pid 229246:tid 229494] [client 20.206.105.145:7426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9KSiBMYeh5YLVG45yLYAAAAoo"]
[Tue Jul 21 07:30:34.651839 2026] [security2:error] [pid 229246:tid 229477] [client 117.251.86.144:35788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KSiBMYeh5YLVG45yLaAAAAnk"]
[Tue Jul 21 07:30:34.651936 2026] [security2:error] [pid 229246:tid 229477] [client 117.251.86.144:35788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KSiBMYeh5YLVG45yLaAAAAnk"]
[Tue Jul 21 07:30:34.686943 2026] [security2:error] [pid 229246:tid 229498] [client 45.8.17.123:48109] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/lock360.php"] [unique_id "al9KSiBMYeh5YLVG45yLagAAAo4"]
[Tue Jul 21 07:30:34.990636 2026] [security2:error] [pid 229246:tid 229398] [client 193.36.225.55:64263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KSiBMYeh5YLVG45yLdAAAAio"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:35.055087 2026] [autoindex:error] [pid 229246:tid 229411] [client 20.206.105.145:7697] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:35.113142 2026] [autoindex:error] [pid 229246:tid 229423] [client 20.206.105.145:7697] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:35.118435 2026] [security2:error] [pid 229246:tid 229489] [client 20.206.105.145:7697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9KSyBMYeh5YLVG45yLfQAAAoU"]
[Tue Jul 21 07:30:35.436715 2026] [security2:error] [pid 229246:tid 229503] [client 20.220.225.223:46126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/la.php"] [unique_id "al9KSyBMYeh5YLVG45yLjQAAApM"]
[Tue Jul 21 07:30:35.689453 2026] [security2:error] [pid 229246:tid 229389] [client 45.8.17.138:23423] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/fonts/wp-conflg.php"] [unique_id "al9KSyBMYeh5YLVG45yLmAAAAiE"]
[Tue Jul 21 07:30:35.695500 2026] [security2:error] [pid 229246:tid 229460] [client 20.151.10.161:51307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/scxy.php"] [unique_id "al9KSyBMYeh5YLVG45yLmQAAAmg"]
[Tue Jul 21 07:30:36.110167 2026] [security2:error] [pid 229246:tid 229465] [client 74.7.230.58:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "luizanonato1755732317052.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9KTCBMYeh5YLVG45yLpQACbR0"]
[Tue Jul 21 07:30:36.432873 2026] [security2:error] [pid 229246:tid 229278] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KTCBMYeh5YLVG45yLrwACeh8"]
[Tue Jul 21 07:30:36.433067 2026] [security2:error] [pid 229246:tid 229478] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KTCBMYeh5YLVG45yLrwACeh8"]
[Tue Jul 21 07:30:36.616572 2026] [security2:error] [pid 229246:tid 229407] [client 20.206.105.145:7720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/like.php"] [unique_id "al9KTCBMYeh5YLVG45yLwwAAAjM"]
[Tue Jul 21 07:30:36.744382 2026] [security2:error] [pid 229246:tid 229421] [client 20.104.96.117:59616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/ccc.php"] [unique_id "al9KTCBMYeh5YLVG45yLyQAAAkE"]
[Tue Jul 21 07:30:36.978639 2026] [security2:error] [pid 229246:tid 229295] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTCBMYeh5YLVG45yL0gACRjA"]
[Tue Jul 21 07:30:36.978807 2026] [security2:error] [pid 229246:tid 229426] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTCBMYeh5YLVG45yL0gACRjA"]
[Tue Jul 21 07:30:36.998647 2026] [security2:error] [pid 229246:tid 229493] [client 45.8.17.58:29269] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentythree/patterns/"] [unique_id "al9KTCBMYeh5YLVG45yL0wAAAok"]
[Tue Jul 21 07:30:37.044555 2026] [security2:error] [pid 229246:tid 229385] [client 122.186.204.214:53565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KTSBMYeh5YLVG45yL1AAAAh0"]
[Tue Jul 21 07:30:37.044740 2026] [security2:error] [pid 229246:tid 229385] [client 122.186.204.214:53565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KTSBMYeh5YLVG45yL1AAAAh0"]
[Tue Jul 21 07:30:37.187841 2026] [security2:error] [pid 229246:tid 229500] [client 20.206.105.145:7425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/.well-known/about.php"] [unique_id "al9KTSBMYeh5YLVG45yL2wAAApA"]
[Tue Jul 21 07:30:37.223325 2026] [security2:error] [pid 229246:tid 229440] [client 103.106.20.201:61494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTSBMYeh5YLVG45yL6QAAAlQ"]
[Tue Jul 21 07:30:37.223449 2026] [security2:error] [pid 229246:tid 229440] [client 103.106.20.201:61494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTSBMYeh5YLVG45yL6QAAAlQ"]
[Tue Jul 21 07:30:37.283607 2026] [security2:error] [pid 229246:tid 229312] [remote 157.66.26.183:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9KTSBMYeh5YLVG45yL8QACg0E"]
[Tue Jul 21 07:30:37.312762 2026] [security2:error] [pid 229246:tid 229405] [client 74.7.175.176:57678] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.nrfilmes.com"] [uri "/robots.txt"] [unique_id "al9KTSBMYeh5YLVG45yL8gACMW8"]
[Tue Jul 21 07:30:37.316237 2026] [security2:error] [pid 229246:tid 229441] [client 103.162.129.114:54221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KTSBMYeh5YLVG45yL8wAAAlU"]
[Tue Jul 21 07:30:37.316345 2026] [security2:error] [pid 229246:tid 229441] [client 103.162.129.114:54221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KTSBMYeh5YLVG45yL8wAAAlU"]
[Tue Jul 21 07:30:37.633909 2026] [security2:error] [pid 229246:tid 229423] [client 20.206.105.145:7483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9KTSBMYeh5YLVG45yL-wAAAkM"]
[Tue Jul 21 07:30:37.937999 2026] [security2:error] [pid 229246:tid 229421] [client 85.204.70.92:45742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.frsadvocacia.net"] [uri "/wp-login.php"] [unique_id "al9KTSBMYeh5YLVG45yMCwAAAkE"]
[Tue Jul 21 07:30:38.085364 2026] [security2:error] [pid 229246:tid 229450] [client 45.8.17.108:48101] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/js/widgets/admin.php"] [unique_id "al9KTiBMYeh5YLVG45yMEQAAAl4"]
[Tue Jul 21 07:30:38.104187 2026] [security2:error] [pid 229246:tid 229493] [client 20.104.96.117:42430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/777.php"] [unique_id "al9KTiBMYeh5YLVG45yMEgAAAok"]
[Tue Jul 21 07:30:38.131776 2026] [security2:error] [pid 229246:tid 229479] [client 20.151.10.161:58044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/FWAZ.php"] [unique_id "al9KTiBMYeh5YLVG45yMFQAAAns"]
[Tue Jul 21 07:30:38.155993 2026] [security2:error] [pid 229246:tid 229354] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KTiBMYeh5YLVG45yMFwACSGs"]
[Tue Jul 21 07:30:38.156136 2026] [security2:error] [pid 229246:tid 229428] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KTiBMYeh5YLVG45yMFwACSGs"]
[Tue Jul 21 07:30:38.214862 2026] [security2:error] [pid 229246:tid 229256] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KTiBMYeh5YLVG45yMGgACVgk"]
[Tue Jul 21 07:30:38.278222 2026] [autoindex:error] [pid 229246:tid 229480] [client 20.206.105.145:54577] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:38.471475 2026] [security2:error] [pid 229246:tid 229401] [client 20.220.225.223:45383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9KTiBMYeh5YLVG45yMKAAAAi0"]
[Tue Jul 21 07:30:38.558978 2026] [security2:error] [pid 229246:tid 229451] [client 175.45.70.82:63390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTiBMYeh5YLVG45yMLgAAAl8"]
[Tue Jul 21 07:30:38.559122 2026] [security2:error] [pid 229246:tid 229451] [client 175.45.70.82:63390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTiBMYeh5YLVG45yMLgAAAl8"]
[Tue Jul 21 07:30:38.566432 2026] [security2:error] [pid 229246:tid 229332] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KTiBMYeh5YLVG45yMLwACFVU"]
[Tue Jul 21 07:30:38.566616 2026] [security2:error] [pid 229246:tid 229377] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KTiBMYeh5YLVG45yMLwACFVU"]
[Tue Jul 21 07:30:38.726136 2026] [autoindex:error] [pid 229246:tid 229447] [client 20.206.105.145:54577] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:38.731853 2026] [security2:error] [pid 229246:tid 229477] [client 20.206.105.145:54577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/pucci.php"] [unique_id "al9KTiBMYeh5YLVG45yMQwAAAnk"]
[Tue Jul 21 07:30:38.816441 2026] [security2:error] [pid 229246:tid 229385] [client 154.192.233.199:59536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTiBMYeh5YLVG45yMSQAAAh0"]
[Tue Jul 21 07:30:38.816592 2026] [security2:error] [pid 229246:tid 229385] [client 154.192.233.199:59536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTiBMYeh5YLVG45yMSQAAAh0"]
[Tue Jul 21 07:30:38.847620 2026] [security2:error] [pid 229246:tid 229416] [client 20.151.10.161:50930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/qterm.php"] [unique_id "al9KTiBMYeh5YLVG45yMTgAAAjw"]
[Tue Jul 21 07:30:38.985947 2026] [security2:error] [pid 229246:tid 229474] [client 134.122.44.174:62438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autoq.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9KTiBMYeh5YLVG45yMXQAAAnY"]
[Tue Jul 21 07:30:39.058900 2026] [security2:error] [pid 229246:tid 229278] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTyBMYeh5YLVG45yMYwACbx8"]
[Tue Jul 21 07:30:39.059123 2026] [security2:error] [pid 229246:tid 229467] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTyBMYeh5YLVG45yMYwACbx8"]
[Tue Jul 21 07:30:39.068281 2026] [security2:error] [pid 229246:tid 229476] [client 172.245.102.42:60859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KTiBMYeh5YLVG45yMUwAAAng"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:39.101843 2026] [security2:error] [pid 229246:tid 229464] [client 173.24.185.52:53096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KTyBMYeh5YLVG45yMZAAAAmw"]
[Tue Jul 21 07:30:39.101970 2026] [security2:error] [pid 229246:tid 229464] [client 173.24.185.52:53096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KTyBMYeh5YLVG45yMZAAAAmw"]
[Tue Jul 21 07:30:39.122891 2026] [security2:error] [pid 229246:tid 229262] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KTyBMYeh5YLVG45yMZQACMQ8"]
[Tue Jul 21 07:30:39.290186 2026] [security2:error] [pid 229246:tid 229264] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/wp.php"] [unique_id "al9KTyBMYeh5YLVG45yMbwACfhE"]
[Tue Jul 21 07:30:39.329794 2026] [security2:error] [pid 229246:tid 229477] [client 20.151.10.161:50918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/blurbs.php"] [unique_id "al9KTyBMYeh5YLVG45yMcgAAAnk"]
[Tue Jul 21 07:30:39.391878 2026] [security2:error] [pid 229246:tid 229376] [client 103.174.34.15:56049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTyBMYeh5YLVG45yMdQAAAhQ"]
[Tue Jul 21 07:30:39.392061 2026] [security2:error] [pid 229246:tid 229376] [client 103.174.34.15:56049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTyBMYeh5YLVG45yMdQAAAhQ"]
[Tue Jul 21 07:30:39.400586 2026] [security2:error] [pid 229246:tid 229435] [client 85.204.70.92:45746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.frsadvocacia.net"] [uri "/wp-login.php"] [unique_id "al9KTyBMYeh5YLVG45yMdgAAAk8"]
[Tue Jul 21 07:30:39.468473 2026] [security2:error] [pid 229246:tid 229260] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/new.php"] [unique_id "al9KTyBMYeh5YLVG45yMeAACJg0"]
[Tue Jul 21 07:30:39.545978 2026] [security2:error] [pid 229246:tid 229495] [client 134.122.44.174:63160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.44.122.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autoq.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTyBMYeh5YLVG45yMfwAAAos"]
[Tue Jul 21 07:30:39.636266 2026] [security2:error] [pid 229246:tid 229315] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/class-t.api.php"] [unique_id "al9KTyBMYeh5YLVG45yMggACSUQ"]
[Tue Jul 21 07:30:39.806908 2026] [security2:error] [pid 229246:tid 229324] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/plugins.php"] [unique_id "al9KTyBMYeh5YLVG45yMhwACMk0"]
[Tue Jul 21 07:30:39.976755 2026] [security2:error] [pid 229246:tid 229307] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/jp.php"] [unique_id "al9KTyBMYeh5YLVG45yMiwACcDw"]
[Tue Jul 21 07:30:40.065215 2026] [security2:error] [pid 229246:tid 229417] [client 20.104.96.117:59810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/for.php"] [unique_id "al9KUCBMYeh5YLVG45yMjwAAAj0"]
[Tue Jul 21 07:30:40.085829 2026] [autoindex:error] [pid 229246:tid 229465] [client 20.206.105.145:54532] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:40.119529 2026] [autoindex:error] [pid 229246:tid 229384] [client 20.206.105.145:54532] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:40.145661 2026] [security2:error] [pid 229246:tid 229248] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/error.php"] [unique_id "al9KUCBMYeh5YLVG45yMlAACRQE"]
[Tue Jul 21 07:30:40.151958 2026] [security2:error] [pid 229246:tid 229466] [client 20.206.105.145:54532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-temp.php"] [unique_id "al9KUCBMYeh5YLVG45yMlQAAAm4"]
[Tue Jul 21 07:30:40.190582 2026] [security2:error] [pid 229246:tid 229411] [client 45.8.17.134:45359] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/dist/vendor/about.php"] [unique_id "al9KUCBMYeh5YLVG45yMlgAAAjc"]
[Tue Jul 21 07:30:40.212679 2026] [security2:error] [pid 229246:tid 229405] [client 20.151.10.161:57359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/v543.php"] [unique_id "al9KUCBMYeh5YLVG45yMlwAAAjE"]
[Tue Jul 21 07:30:40.260536 2026] [security2:error] [pid 229246:tid 229439] [client 20.220.225.223:19672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KUCBMYeh5YLVG45yMngAAAlM"]
[Tue Jul 21 07:30:40.334303 2026] [security2:error] [pid 229246:tid 229360] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/classwithtostring.php"] [unique_id "al9KUCBMYeh5YLVG45yMogACV3E"]
[Tue Jul 21 07:30:40.513906 2026] [security2:error] [pid 229246:tid 229261] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/bless.php"] [unique_id "al9KUCBMYeh5YLVG45yMqAACjA4"]
[Tue Jul 21 07:30:40.606362 2026] [security2:error] [pid 229246:tid 229491] [client 20.220.225.223:45403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/inso.php"] [unique_id "al9KUCBMYeh5YLVG45yMrAAAAoc"]
[Tue Jul 21 07:30:40.609322 2026] [autoindex:error] [pid 229246:tid 229477] [client 85.204.70.92:60474] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:40.655561 2026] [security2:error] [pid 229246:tid 229435] [client 134.122.44.174:63470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.44.122.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autoq.com.br"] [uri "/wp-login.php"] [unique_id "al9KUCBMYeh5YLVG45yMrQAAAk8"]
[Tue Jul 21 07:30:40.682422 2026] [security2:error] [pid 229246:tid 229356] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/storage/index.php"] [unique_id "al9KUCBMYeh5YLVG45yMrgACjW0"]
[Tue Jul 21 07:30:40.849079 2026] [security2:error] [pid 229246:tid 229266] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/g.php"] [unique_id "al9KUCBMYeh5YLVG45yMugACRhM"]
[Tue Jul 21 07:30:41.456101 2026] [security2:error] [pid 229246:tid 229451] [client 20.220.225.223:19319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KUSBMYeh5YLVG45yMywAAAl8"]
[Tue Jul 21 07:30:41.507787 2026] [security2:error] [pid 229246:tid 229257] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/nf.php"] [unique_id "al9KUSBMYeh5YLVG45yMzAACawo"]
[Tue Jul 21 07:30:41.666747 2026] [security2:error] [pid 229246:tid 229490] [client 45.251.232.145:60920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KUSBMYeh5YLVG45yM0wAAAoY"]
[Tue Jul 21 07:30:41.666888 2026] [security2:error] [pid 229246:tid 229490] [client 45.251.232.145:60920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KUSBMYeh5YLVG45yM0wAAAoY"]
[Tue Jul 21 07:30:41.679349 2026] [security2:error] [pid 229246:tid 229376] [client 152.59.154.239:58083] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KUSBMYeh5YLVG45yM1AAAAhQ"]
[Tue Jul 21 07:30:41.679477 2026] [security2:error] [pid 229246:tid 229376] [client 152.59.154.239:58083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KUSBMYeh5YLVG45yM1AAAAhQ"]
[Tue Jul 21 07:30:41.780513 2026] [security2:error] [pid 229246:tid 229393] [client 62.102.148.164:34404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KUSBMYeh5YLVG45yM3QAAAiU"]
[Tue Jul 21 07:30:41.780606 2026] [security2:error] [pid 229246:tid 229393] [client 62.102.148.164:34404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KUSBMYeh5YLVG45yM3QAAAiU"]
[Tue Jul 21 07:30:41.905692 2026] [security2:error] [pid 229246:tid 229413] [client 85.204.70.92:45748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.frsadvocacia.net"] [uri "/wp-login.php"] [unique_id "al9KUSBMYeh5YLVG45yM5AAAAjk"]
[Tue Jul 21 07:30:41.923064 2026] [autoindex:error] [pid 229246:tid 229497] [client 20.206.105.145:54529] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/blocks/buttons/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:42.046472 2026] [security2:error] [pid 229246:tid 229320] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xda.php"] [unique_id "al9KUiBMYeh5YLVG45yM6QACgUk"]
[Tue Jul 21 07:30:42.069560 2026] [security2:error] [pid 229246:tid 229380] [client 20.104.96.117:59804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/ssla.php"] [unique_id "al9KUiBMYeh5YLVG45yM6gAAAhg"]
[Tue Jul 21 07:30:42.087780 2026] [security2:error] [pid 229246:tid 229389] [client 45.8.17.60:32259] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/footnotes/"] [unique_id "al9KUiBMYeh5YLVG45yM7AAAAiE"]
[Tue Jul 21 07:30:42.169633 2026] [autoindex:error] [pid 229246:tid 229498] [client 85.204.70.92:60474] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:42.250266 2026] [security2:error] [pid 229246:tid 229290] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/shell.php"] [unique_id "al9KUiBMYeh5YLVG45yM7wACdis"]
[Tue Jul 21 07:30:42.316380 2026] [security2:error] [pid 229246:tid 229480] [client 20.151.10.161:51264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/w3lls.php"] [unique_id "al9KUiBMYeh5YLVG45yM8AAAAnw"]
[Tue Jul 21 07:30:42.440612 2026] [security2:error] [pid 229246:tid 229253] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/3.php"] [unique_id "al9KUiBMYeh5YLVG45yM9wACbQY"]
[Tue Jul 21 07:30:42.546192 2026] [security2:error] [pid 229246:tid 229476] [client 20.206.105.145:54529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/xmu.php"] [unique_id "al9KUiBMYeh5YLVG45yM-gAAAng"]
[Tue Jul 21 07:30:42.609778 2026] [security2:error] [pid 229246:tid 229283] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/mds.php"] [unique_id "al9KUiBMYeh5YLVG45yM_wACWiQ"]
[Tue Jul 21 07:30:42.792865 2026] [security2:error] [pid 229246:tid 229332] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/archive.php"] [unique_id "al9KUiBMYeh5YLVG45yNBQACaVU"]
[Tue Jul 21 07:30:42.888980 2026] [security2:error] [pid 229246:tid 229439] [client 45.8.17.132:33985] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/pullquote/"] [unique_id "al9KUiBMYeh5YLVG45yNCwAAAlM"]
[Tue Jul 21 07:30:42.975104 2026] [security2:error] [pid 229246:tid 229363] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/amax.php"] [unique_id "al9KUiBMYeh5YLVG45yNFAACY3Q"]
[Tue Jul 21 07:30:43.147848 2026] [security2:error] [pid 229246:tid 229286] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/moon.php"] [unique_id "al9KUyBMYeh5YLVG45yNFwACgSc"]
[Tue Jul 21 07:30:43.317894 2026] [security2:error] [pid 229246:tid 229258] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KUyBMYeh5YLVG45yNHAACiQs"]
[Tue Jul 21 07:30:43.318044 2026] [security2:error] [pid 229246:tid 229493] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KUyBMYeh5YLVG45yNHAACiQs"]
[Tue Jul 21 07:30:43.324621 2026] [security2:error] [pid 229246:tid 229372] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/ws83.php"] [unique_id "al9KUyBMYeh5YLVG45yNHQACTX0"]
[Tue Jul 21 07:30:43.426466 2026] [security2:error] [pid 229246:tid 229429] [client 173.252.95.12:34718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9KUyBMYeh5YLVG45yNGgAAAkk"]
[Tue Jul 21 07:30:43.464564 2026] [security2:error] [pid 229246:tid 229481] [client 74.7.241.192:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.hunteron.pedido-online.net"] [uri "/index.php"] [unique_id "al9KUiBMYeh5YLVG45yNCgAAAn0"]
[Tue Jul 21 07:30:43.466320 2026] [security2:error] [pid 229246:tid 229424] [client 74.7.241.192:33772] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.hunteron.pedido-online.net"] [uri "/robots.txt"] [unique_id "al9KUiBMYeh5YLVG45yNCAACRGU"]
[Tue Jul 21 07:30:43.542514 2026] [security2:error] [pid 229246:tid 229483] [client 193.36.225.57:42331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KUyBMYeh5YLVG45yNKQAAAn8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:43.544092 2026] [security2:error] [pid 229246:tid 229451] [client 20.151.10.161:57986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-ws68.php"] [unique_id "al9KUyBMYeh5YLVG45yNKgAAAl8"]
[Tue Jul 21 07:30:43.703349 2026] [security2:error] [pid 229246:tid 229478] [client 20.104.96.117:42378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/zc-131.php"] [unique_id "al9KUyBMYeh5YLVG45yNKwAAAno"]
[Tue Jul 21 07:30:43.763176 2026] [security2:error] [pid 229246:tid 229293] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/CDX1.php"] [unique_id "al9KUyBMYeh5YLVG45yNLAACdC4"]
[Tue Jul 21 07:30:43.948934 2026] [security2:error] [pid 229246:tid 229281] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/inputs.php"] [unique_id "al9KUyBMYeh5YLVG45yNMgACVSI"]
[Tue Jul 21 07:30:44.012639 2026] [security2:error] [pid 229246:tid 229376] [client 173.252.95.31:37374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9KVCBMYeh5YLVG45yNNAAAAhQ"]
[Tue Jul 21 07:30:44.099559 2026] [security2:error] [pid 229246:tid 229452] [client 45.8.17.115:37297] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/simple.php"] [unique_id "al9KVCBMYeh5YLVG45yNPAAAAmA"]
[Tue Jul 21 07:30:44.137946 2026] [security2:error] [pid 229246:tid 229337] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/ms-edit.php"] [unique_id "al9KVCBMYeh5YLVG45yNPQACcFo"]
[Tue Jul 21 07:30:44.318903 2026] [security2:error] [pid 229246:tid 229315] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/simple.php"] [unique_id "al9KVCBMYeh5YLVG45yNUgACFkQ"]
[Tue Jul 21 07:30:44.359466 2026] [security2:error] [pid 229246:tid 229252] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KVCBMYeh5YLVG45yNVQACgQU"]
[Tue Jul 21 07:30:44.359598 2026] [security2:error] [pid 229246:tid 229485] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KVCBMYeh5YLVG45yNVQACgQU"]
[Tue Jul 21 07:30:44.391250 2026] [security2:error] [pid 229246:tid 229424] [client 20.220.225.223:19299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/dp.php"] [unique_id "al9KVCBMYeh5YLVG45yNWAAAAkQ"]
[Tue Jul 21 07:30:44.436509 2026] [security2:error] [pid 229246:tid 229379] [client 20.206.105.145:54568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9KVCBMYeh5YLVG45yNWwAAAhc"]
[Tue Jul 21 07:30:44.536519 2026] [security2:error] [pid 229246:tid 229350] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/404.php"] [unique_id "al9KVCBMYeh5YLVG45yNXgACWWc"]
[Tue Jul 21 07:30:44.720689 2026] [security2:error] [pid 229246:tid 229248] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/file3.php"] [unique_id "al9KVCBMYeh5YLVG45yNZQACdAE"]
[Tue Jul 21 07:30:44.888716 2026] [security2:error] [pid 229246:tid 229280] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/wp-mail.php"] [unique_id "al9KVCBMYeh5YLVG45yNawACgyE"]
[Tue Jul 21 07:30:45.082173 2026] [security2:error] [pid 229246:tid 229270] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/about.php"] [unique_id "al9KVSBMYeh5YLVG45yNcwACeRc"]
[Tue Jul 21 07:30:45.210053 2026] [security2:error] [pid 229246:tid 229494] [client 20.151.10.161:57987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/xyn.php"] [unique_id "al9KVSBMYeh5YLVG45yNdQAAAoo"]
[Tue Jul 21 07:30:45.220773 2026] [security2:error] [pid 229246:tid 229352] [remote 68.178.160.25:48326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fisiopelvicafloripa.com.br"] [uri "/wp-login.php"] [unique_id "al9KVSBMYeh5YLVG45yNdgACemk"]
[Tue Jul 21 07:30:45.233026 2026] [security2:error] [pid 229246:tid 229408] [client 20.206.105.145:7687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/puc.php"] [unique_id "al9KVSBMYeh5YLVG45yNdwAAAjQ"]
[Tue Jul 21 07:30:45.288298 2026] [security2:error] [pid 229246:tid 229469] [client 117.251.86.144:43300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KVSBMYeh5YLVG45yNeQAAAnE"]
[Tue Jul 21 07:30:45.288443 2026] [security2:error] [pid 229246:tid 229469] [client 117.251.86.144:43300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KVSBMYeh5YLVG45yNeQAAAnE"]
[Tue Jul 21 07:30:45.486695 2026] [security2:error] [pid 229246:tid 229474] [client 45.8.17.123:32495] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/includes/admin.php"] [unique_id "al9KVSBMYeh5YLVG45yNgAAAAnY"]
[Tue Jul 21 07:30:45.583916 2026] [security2:error] [pid 229246:tid 229398] [client 20.151.10.161:50900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/green3.php"] [unique_id "al9KVSBMYeh5YLVG45yNiQAAAio"]
[Tue Jul 21 07:30:45.732058 2026] [security2:error] [pid 229246:tid 229434] [client 173.252.95.34:55278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9KVSBMYeh5YLVG45yNiAAAAk4"]
[Tue Jul 21 07:30:45.862517 2026] [security2:error] [pid 229246:tid 229386] [client 20.52.136.55:1774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/gettest.php"] [unique_id "al9KVSBMYeh5YLVG45yNjwAAAh4"]
[Tue Jul 21 07:30:46.327898 2026] [security2:error] [pid 229246:tid 229353] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/adminfuns.php"] [unique_id "al9KViBMYeh5YLVG45yNmQACVWo"]
[Tue Jul 21 07:30:46.395874 2026] [security2:error] [pid 229246:tid 229377] [client 45.8.17.124:38957] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/css/dist/reusable-blocks/"] [unique_id "al9KViBMYeh5YLVG45yNmgAAAhU"]
[Tue Jul 21 07:30:46.475549 2026] [security2:error] [pid 229246:tid 229409] [client 20.206.105.145:54562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/themes.php"] [unique_id "al9KViBMYeh5YLVG45yNnQAAAjU"]
[Tue Jul 21 07:30:46.520927 2026] [security2:error] [pid 229246:tid 229257] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/php8.php"] [unique_id "al9KViBMYeh5YLVG45yNngACHQo"]
[Tue Jul 21 07:30:46.716013 2026] [security2:error] [pid 229246:tid 229335] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/info.php"] [unique_id "al9KViBMYeh5YLVG45yNpQACI1g"]
[Tue Jul 21 07:30:46.935867 2026] [security2:error] [pid 229246:tid 229311] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/edit.php"] [unique_id "al9KViBMYeh5YLVG45yNpgACVEA"]
[Tue Jul 21 07:30:46.937086 2026] [security2:error] [pid 229246:tid 229271] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KViBMYeh5YLVG45yNpwACbBg"]
[Tue Jul 21 07:30:46.937173 2026] [security2:error] [pid 229246:tid 229464] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KViBMYeh5YLVG45yNpwACbBg"]
[Tue Jul 21 07:30:47.116850 2026] [security2:error] [pid 229246:tid 229434] [client 20.151.10.161:51302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/ccs.php"] [unique_id "al9KVyBMYeh5YLVG45yNsgAAAk4"]
[Tue Jul 21 07:30:47.119434 2026] [security2:error] [pid 229246:tid 229354] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/166.php"] [unique_id "al9KVyBMYeh5YLVG45yNtAACJms"]
[Tue Jul 21 07:30:47.191586 2026] [security2:error] [pid 229246:tid 229491] [client 122.186.204.214:54220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KVyBMYeh5YLVG45yNugAAAoc"]
[Tue Jul 21 07:30:47.191707 2026] [security2:error] [pid 229246:tid 229491] [client 122.186.204.214:54220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KVyBMYeh5YLVG45yNugAAAoc"]
[Tue Jul 21 07:30:47.293706 2026] [security2:error] [pid 229246:tid 229253] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/8.php"] [unique_id "al9KVyBMYeh5YLVG45yNvgACUAY"]
[Tue Jul 21 07:30:47.466984 2026] [security2:error] [pid 229246:tid 229283] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KVyBMYeh5YLVG45yNwQACGCQ"]
[Tue Jul 21 07:30:47.467150 2026] [security2:error] [pid 229246:tid 229380] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KVyBMYeh5YLVG45yNwQACGCQ"]
[Tue Jul 21 07:30:47.471024 2026] [security2:error] [pid 229246:tid 229301] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/ws38.php"] [unique_id "al9KVyBMYeh5YLVG45yNwwACSzY"]
[Tue Jul 21 07:30:47.487640 2026] [security2:error] [pid 229246:tid 229496] [client 139.167.225.182:55476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KVyBMYeh5YLVG45yNwgAAAow"]
[Tue Jul 21 07:30:47.487775 2026] [security2:error] [pid 229246:tid 229496] [client 139.167.225.182:55476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KVyBMYeh5YLVG45yNwgAAAow"]
[Tue Jul 21 07:30:47.638539 2026] [security2:error] [pid 229246:tid 229396] [client 136.144.33.98:61429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KVyBMYeh5YLVG45yNywAAAig"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:47.644092 2026] [security2:error] [pid 229246:tid 229313] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/a7.php"] [unique_id "al9KVyBMYeh5YLVG45yNzQACd0I"]
[Tue Jul 21 07:30:47.763872 2026] [autoindex:error] [pid 229246:tid 229478] [client 198.235.24.248:60640] AH01276: Cannot serve directory /home4/ciclod61/bahtelecom.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:47.785134 2026] [security2:error] [pid 229246:tid 229410] [client 45.8.17.127:55993] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-signin.php"] [unique_id "al9KVyBMYeh5YLVG45yN3wAAAjY"]
[Tue Jul 21 07:30:47.834978 2026] [security2:error] [pid 229246:tid 229325] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/classsmtps.php"] [unique_id "al9KVyBMYeh5YLVG45yN4AACU04"]
[Tue Jul 21 07:30:47.926795 2026] [autoindex:error] [pid 229246:tid 229428] [client 20.206.105.145:54585] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:47.935711 2026] [security2:error] [pid 229246:tid 229416] [client 20.206.105.145:54585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/8.php"] [unique_id "al9KVyBMYeh5YLVG45yN4gAAAjw"]
[Tue Jul 21 07:30:47.961421 2026] [security2:error] [pid 229246:tid 229466] [client 103.162.129.114:54669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KVyBMYeh5YLVG45yN5AAAAm4"]
[Tue Jul 21 07:30:47.961511 2026] [security2:error] [pid 229246:tid 229466] [client 103.162.129.114:54669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KVyBMYeh5YLVG45yN5AAAAm4"]
[Tue Jul 21 07:30:47.978343 2026] [security2:error] [pid 229246:tid 229493] [client 103.106.20.201:62063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KVyBMYeh5YLVG45yN5QAAAok"]
[Tue Jul 21 07:30:47.978438 2026] [security2:error] [pid 229246:tid 229493] [client 103.106.20.201:62063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KVyBMYeh5YLVG45yN5QAAAok"]
[Tue Jul 21 07:30:48.053664 2026] [security2:error] [pid 229246:tid 229384] [client 20.151.10.161:51295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/ccc.php"] [unique_id "al9KWCBMYeh5YLVG45yN6wAAAhw"]
[Tue Jul 21 07:30:48.149754 2026] [security2:error] [pid 229246:tid 229480] [client 20.220.225.223:6813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KWCBMYeh5YLVG45yN8AAAAnw"]
[Tue Jul 21 07:30:48.272271 2026] [security2:error] [pid 229246:tid 229461] [client 59.96.220.140:56707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KWCBMYeh5YLVG45yN9QAAAmk"]
[Tue Jul 21 07:30:48.272372 2026] [security2:error] [pid 229246:tid 229461] [client 59.96.220.140:56707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KWCBMYeh5YLVG45yN9QAAAmk"]
[Tue Jul 21 07:30:48.274751 2026] [security2:error] [pid 229246:tid 229376] [client 91.217.249.195:58935] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jurencosmetics.com"] [uri "/wp-login.php"] [unique_id "al9KVyBMYeh5YLVG45yN4wAAAhQ"]
[Tue Jul 21 07:30:48.315861 2026] [security2:error] [pid 229246:tid 229337] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/rip.php"] [unique_id "al9KWCBMYeh5YLVG45yN9gACGFo"]
[Tue Jul 21 07:30:48.509658 2026] [security2:error] [pid 229246:tid 229263] [remote 74.249.245.134:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "luminabeauty.com.br"] [uri "/1.php"] [unique_id "al9KWCBMYeh5YLVG45yN-gACFRA"]
[Tue Jul 21 07:30:48.509797 2026] [security2:error] [pid 229246:tid 229263] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/1.php"] [unique_id "al9KWCBMYeh5YLVG45yN-gACFRA"]
[Tue Jul 21 07:30:48.676828 2026] [security2:error] [pid 229246:tid 229276] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/chosen.php"] [unique_id "al9KWCBMYeh5YLVG45yOAwACNx0"]
[Tue Jul 21 07:30:48.703321 2026] [security2:error] [pid 229246:tid 229478] [client 20.220.225.223:23484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KWCBMYeh5YLVG45yOBAAAAno"]
[Tue Jul 21 07:30:48.751523 2026] [security2:error] [pid 229246:tid 229362] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KWCBMYeh5YLVG45yOBQACL3M"]
[Tue Jul 21 07:30:48.751668 2026] [security2:error] [pid 229246:tid 229403] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KWCBMYeh5YLVG45yOBQACL3M"]
[Tue Jul 21 07:30:48.768870 2026] [security2:error] [pid 229246:tid 229439] [client 20.206.105.145:7694] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "bastarecomecar.com.br"] [uri "/1.php"] [unique_id "al9KWCBMYeh5YLVG45yOBwAAAlM"]
[Tue Jul 21 07:30:48.768963 2026] [security2:error] [pid 229246:tid 229439] [client 20.206.105.145:7694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/1.php"] [unique_id "al9KWCBMYeh5YLVG45yOBwAAAlM"]
[Tue Jul 21 07:30:48.883446 2026] [security2:error] [pid 229246:tid 229278] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/css.php"] [unique_id "al9KWCBMYeh5YLVG45yOEQACiR8"]
[Tue Jul 21 07:30:48.981231 2026] [security2:error] [pid 229246:tid 229384] [client 20.52.136.55:1757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/tfm.php"] [unique_id "al9KWCBMYeh5YLVG45yOEwAAAhw"]
[Tue Jul 21 07:30:49.058842 2026] [security2:error] [pid 229246:tid 229327] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/php.php"] [unique_id "al9KWSBMYeh5YLVG45yOFwACW1A"]
[Tue Jul 21 07:30:49.074402 2026] [security2:error] [pid 229246:tid 229386] [client 45.8.17.122:38883] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/config.php"] [unique_id "al9KWSBMYeh5YLVG45yOGAAAAh4"]
[Tue Jul 21 07:30:49.229004 2026] [security2:error] [pid 229246:tid 229310] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/aa.php"] [unique_id "al9KWSBMYeh5YLVG45yOIQACTD8"]
[Tue Jul 21 07:30:49.229065 2026] [security2:error] [pid 229246:tid 229446] [client 109.248.148.246:33974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOIgAAAlo"]
[Tue Jul 21 07:30:49.229133 2026] [security2:error] [pid 229246:tid 229446] [client 109.248.148.246:33974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOIgAAAlo"]
[Tue Jul 21 07:30:49.312213 2026] [security2:error] [pid 229246:tid 229260] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOJgACRA0"]
[Tue Jul 21 07:30:49.312339 2026] [security2:error] [pid 229246:tid 229424] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOJgACRA0"]
[Tue Jul 21 07:30:49.317423 2026] [security2:error] [pid 229246:tid 229452] [client 175.45.70.82:63903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOJwAAAmA"]
[Tue Jul 21 07:30:49.317510 2026] [security2:error] [pid 229246:tid 229452] [client 175.45.70.82:63903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOJwAAAmA"]
[Tue Jul 21 07:30:49.427654 2026] [security2:error] [pid 229246:tid 229410] [client 154.192.233.199:58610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOKQAAAjY"]
[Tue Jul 21 07:30:49.427799 2026] [security2:error] [pid 229246:tid 229410] [client 154.192.233.199:58610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOKQAAAjY"]
[Tue Jul 21 07:30:49.431674 2026] [security2:error] [pid 229246:tid 229315] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/bolt.php"] [unique_id "al9KWSBMYeh5YLVG45yOKgACd0Q"]
[Tue Jul 21 07:30:49.474834 2026] [security2:error] [pid 229246:tid 229477] [client 20.220.225.223:19650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/old.php"] [unique_id "al9KWSBMYeh5YLVG45yOKwAAAnk"]
[Tue Jul 21 07:30:49.614598 2026] [security2:error] [pid 229246:tid 229252] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/x.php"] [unique_id "al9KWSBMYeh5YLVG45yOLQACNwU"]
[Tue Jul 21 07:30:49.617827 2026] [security2:error] [pid 229246:tid 229482] [client 91.92.41.115:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.diegocarvalho1781571778941.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al9KWSBMYeh5YLVG45yOLgAAAn4"]
[Tue Jul 21 07:30:49.631060 2026] [security2:error] [pid 229246:tid 229307] [remote 42.200.84.61:56390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cestabasicadocarlao.com.br"] [uri "/wp-login.php"] [unique_id "al9KWSBMYeh5YLVG45yOMwACTTw"]
[Tue Jul 21 07:30:49.631625 2026] [security2:error] [pid 229246:tid 229463] [client 173.24.185.52:53560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yONAAAAms"]
[Tue Jul 21 07:30:49.631693 2026] [security2:error] [pid 229246:tid 229463] [client 173.24.185.52:53560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yONAAAAms"]
[Tue Jul 21 07:30:49.674847 2026] [security2:error] [pid 229246:tid 229461] [client 136.144.42.175:39797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.42.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/wp-login.php"] [unique_id "al9KWSBMYeh5YLVG45yONQAAAmk"]
[Tue Jul 21 07:30:49.697270 2026] [security2:error] [pid 229246:tid 229485] [client 213.152.162.104:45736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yONwAAAoE"]
[Tue Jul 21 07:30:49.697391 2026] [security2:error] [pid 229246:tid 229485] [client 213.152.162.104:45736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yONwAAAoE"]
[Tue Jul 21 07:30:49.825480 2026] [security2:error] [pid 229246:tid 229324] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/jga.php"] [unique_id "al9KWSBMYeh5YLVG45yOPQACkE0"]
[Tue Jul 21 07:30:49.838820 2026] [security2:error] [pid 229246:tid 229280] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOPgACcCE"]
[Tue Jul 21 07:30:49.838927 2026] [security2:error] [pid 229246:tid 229468] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOPgACcCE"]
[Tue Jul 21 07:30:49.864590 2026] [proxy:error] [pid 229246:tid 229447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:30:49.864670 2026] [proxy_http:error] [pid 229246:tid 229447] [client 91.92.41.115:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:30:49.865395 2026] [proxy:error] [pid 229246:tid 229447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:30:49.865438 2026] [proxy_http:error] [pid 229246:tid 229447] [client 91.92.41.115:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:30:49.997689 2026] [security2:error] [pid 229246:tid 229436] [client 62.102.148.164:38912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOQQAAAlA"]
[Tue Jul 21 07:30:49.997786 2026] [security2:error] [pid 229246:tid 229436] [client 62.102.148.164:38912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOQQAAAlA"]
[Tue Jul 21 07:30:50.045292 2026] [security2:error] [pid 229246:tid 229465] [client 20.206.105.145:7699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/100.php"] [unique_id "al9KWiBMYeh5YLVG45yORQAAAm0"]
[Tue Jul 21 07:30:50.103326 2026] [security2:error] [pid 229246:tid 229441] [client 103.174.34.15:56542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KWiBMYeh5YLVG45yORwAAAlU"]
[Tue Jul 21 07:30:50.103677 2026] [security2:error] [pid 229246:tid 229441] [client 103.174.34.15:56542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KWiBMYeh5YLVG45yORwAAAlU"]
[Tue Jul 21 07:30:50.308383 2026] [security2:error] [pid 229246:tid 229490] [client 20.151.10.161:50886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/get.php"] [unique_id "al9KWiBMYeh5YLVG45yOSgAAAoY"]
[Tue Jul 21 07:30:50.553852 2026] [security2:error] [pid 229246:tid 229333] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/k.php"] [unique_id "al9KWiBMYeh5YLVG45yOUwACT1Y"]
[Tue Jul 21 07:30:50.583057 2026] [security2:error] [pid 229246:tid 229481] [client 45.8.17.124:24447] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/freeform/"] [unique_id "al9KWiBMYeh5YLVG45yOVQAAAn0"]
[Tue Jul 21 07:30:50.672469 2026] [security2:error] [pid 229246:tid 229492] [client 20.206.105.145:7458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/about.php"] [unique_id "al9KWiBMYeh5YLVG45yOWgAAAog"]
[Tue Jul 21 07:30:50.726191 2026] [security2:error] [pid 229246:tid 229353] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/vx.php"] [unique_id "al9KWiBMYeh5YLVG45yOXAACNGo"]
[Tue Jul 21 07:30:50.749680 2026] [access_compat:error] [pid 229246:tid 229421] [client 162.241.63.68:59418] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:30:51.007920 2026] [security2:error] [pid 229246:tid 229453] [client 20.206.105.145:7755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/about.php"] [unique_id "al9KWyBMYeh5YLVG45yOYgAAAmE"]
[Tue Jul 21 07:30:51.045313 2026] [security2:error] [pid 229246:tid 229463] [client 20.206.105.145:7702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/admin.php"] [unique_id "al9KWyBMYeh5YLVG45yOYwAAAms"]
[Tue Jul 21 07:30:51.267156 2026] [security2:error] [pid 229246:tid 229440] [client 136.144.33.108:39551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KWyBMYeh5YLVG45yOaAAAAlQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:51.271668 2026] [security2:error] [pid 229246:tid 229417] [client 20.151.10.161:58001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/images.php"] [unique_id "al9KWyBMYeh5YLVG45yOaQAAAj0"]
[Tue Jul 21 07:30:51.356837 2026] [security2:error] [pid 229246:tid 229388] [client 20.206.105.145:7745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/admin.php"] [unique_id "al9KWyBMYeh5YLVG45yOagAAAiA"]
[Tue Jul 21 07:30:51.527530 2026] [security2:error] [pid 229246:tid 229476] [client 20.206.105.145:54552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/edit.php"] [unique_id "al9KWyBMYeh5YLVG45yObgAAAng"]
[Tue Jul 21 07:30:51.545150 2026] [security2:error] [pid 229246:tid 229398] [client 20.220.225.223:19309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/ms-new.php"] [unique_id "al9KWyBMYeh5YLVG45yObwAAAio"]
[Tue Jul 21 07:30:51.913454 2026] [security2:error] [pid 229246:tid 229379] [client 20.206.105.145:54559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9KWyBMYeh5YLVG45yOfAAAAhc"]
[Tue Jul 21 07:30:52.006157 2026] [security2:error] [pid 229246:tid 229467] [client 45.8.17.135:27361] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/maintenance/"] [unique_id "al9KXCBMYeh5YLVG45yOgQAAAm8"]
[Tue Jul 21 07:30:52.056000 2026] [security2:error] [pid 229246:tid 229396] [client 20.220.225.223:8123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KXCBMYeh5YLVG45yOggAAAig"]
[Tue Jul 21 07:30:52.130740 2026] [security2:error] [pid 229246:tid 229434] [client 45.251.232.145:61440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KXCBMYeh5YLVG45yOhQAAAk4"]
[Tue Jul 21 07:30:52.130879 2026] [security2:error] [pid 229246:tid 229434] [client 45.251.232.145:61440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KXCBMYeh5YLVG45yOhQAAAk4"]
[Tue Jul 21 07:30:52.136275 2026] [security2:error] [pid 229246:tid 229435] [client 20.151.10.161:57395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/alls.php"] [unique_id "al9KXCBMYeh5YLVG45yOhgAAAk8"]
[Tue Jul 21 07:30:52.138054 2026] [security2:error] [pid 229246:tid 229357] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/ws77.php"] [unique_id "al9KXCBMYeh5YLVG45yOhwACfW4"]
[Tue Jul 21 07:30:52.206538 2026] [security2:error] [pid 229246:tid 229470] [client 20.206.105.145:54581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/f6.php"] [unique_id "al9KXCBMYeh5YLVG45yOiQAAAnI"]
[Tue Jul 21 07:30:52.306223 2026] [security2:error] [pid 229246:tid 229301] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/2.php"] [unique_id "al9KXCBMYeh5YLVG45yOjgACQzY"]
[Tue Jul 21 07:30:52.385110 2026] [security2:error] [pid 229246:tid 229494] [client 20.220.225.223:46135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/wpx.php"] [unique_id "al9KXCBMYeh5YLVG45yOkgAAAoo"]
[Tue Jul 21 07:30:52.496720 2026] [core:alert] [pid 229246:tid 229500] [client 57.141.18.102:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:30:52.504803 2026] [security2:error] [pid 229246:tid 229502] [client 20.206.105.145:54586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/inputs.php"] [unique_id "al9KXCBMYeh5YLVG45yOlwAAApI"]
[Tue Jul 21 07:30:52.519998 2026] [security2:error] [pid 229246:tid 229363] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/asd.php"] [unique_id "al9KXCBMYeh5YLVG45yOmAACW3Q"]
[Tue Jul 21 07:30:52.572855 2026] [security2:error] [pid 229246:tid 229466] [client 20.206.105.145:7762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/inputs.php"] [unique_id "al9KXCBMYeh5YLVG45yOmwAAAm4"]
[Tue Jul 21 07:30:52.687146 2026] [security2:error] [pid 229246:tid 229292] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/default.php"] [unique_id "al9KXCBMYeh5YLVG45yOpQACXy0"]
[Tue Jul 21 07:30:52.729712 2026] [security2:error] [pid 229246:tid 229495] [client 20.206.105.145:54531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/av.php"] [unique_id "al9KXCBMYeh5YLVG45yOpgAAAos"]
[Tue Jul 21 07:30:52.876333 2026] [security2:error] [pid 229246:tid 229273] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/gettest.php"] [unique_id "al9KXCBMYeh5YLVG45yOqQACbxo"]
[Tue Jul 21 07:30:52.894344 2026] [security2:error] [pid 229246:tid 229396] [client 20.206.105.145:7797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/classwithtostring.php"] [unique_id "al9KXCBMYeh5YLVG45yOqgAAAig"]
[Tue Jul 21 07:30:53.024010 2026] [security2:error] [pid 229246:tid 229435] [client 20.151.10.161:57358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/yyu.php"] [unique_id "al9KXSBMYeh5YLVG45yOrQAAAk8"]
[Tue Jul 21 07:30:53.032853 2026] [security2:error] [pid 229246:tid 229318] [remote 68.178.165.65:33048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.165.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/wp-login.php"] [unique_id "al9KXSBMYeh5YLVG45yOrwACbEc"]
[Tue Jul 21 07:30:53.041576 2026] [security2:error] [pid 229246:tid 229293] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/tfm.php"] [unique_id "al9KXSBMYeh5YLVG45yOsAACVy4"]
[Tue Jul 21 07:30:53.093372 2026] [security2:error] [pid 229246:tid 229477] [client 45.8.17.144:58847] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/module.php"] [unique_id "al9KXSBMYeh5YLVG45yOsgAAAnk"]
[Tue Jul 21 07:30:53.208908 2026] [security2:error] [pid 229246:tid 229325] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/ws81.php"] [unique_id "al9KXSBMYeh5YLVG45yOtwACfk4"]
[Tue Jul 21 07:30:53.442011 2026] [security2:error] [pid 229246:tid 229386] [client 20.52.136.55:1780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/ws81.php"] [unique_id "al9KXSBMYeh5YLVG45yOugAAAh4"]
[Tue Jul 21 07:30:53.671965 2026] [security2:error] [pid 229246:tid 229502] [client 20.151.10.161:51301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/by.php"] [unique_id "al9KXSBMYeh5YLVG45yOvwAAApI"]
[Tue Jul 21 07:30:53.928444 2026] [security2:error] [pid 229246:tid 229337] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KXSBMYeh5YLVG45yOxQACbVo"]
[Tue Jul 21 07:30:53.928624 2026] [security2:error] [pid 229246:tid 229465] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KXSBMYeh5YLVG45yOxQACbVo"]
[Tue Jul 21 07:30:54.099298 2026] [security2:error] [pid 229246:tid 229379] [client 82.102.28.107:38242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KXiBMYeh5YLVG45yOygAAAhc"]
[Tue Jul 21 07:30:54.099377 2026] [security2:error] [pid 229246:tid 229379] [client 82.102.28.107:38242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KXiBMYeh5YLVG45yOygAAAhc"]
[Tue Jul 21 07:30:54.194865 2026] [security2:error] [pid 229246:tid 229288] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/222.php"] [unique_id "al9KXiBMYeh5YLVG45yOzAACMik"]
[Tue Jul 21 07:30:54.249213 2026] [security2:error] [pid 229246:tid 229449] [client 20.151.10.161:57354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/FAQ.php"] [unique_id "al9KXiBMYeh5YLVG45yOzwAAAl0"]
[Tue Jul 21 07:30:54.307361 2026] [security2:error] [pid 229246:tid 229467] [client 20.220.225.223:8125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/dp.php"] [unique_id "al9KXiBMYeh5YLVG45yO0gAAAm8"]
[Tue Jul 21 07:30:54.333956 2026] [security2:error] [pid 229246:tid 229474] [client 20.206.105.145:7746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9KXiBMYeh5YLVG45yO1AAAAnY"]
[Tue Jul 21 07:30:54.369825 2026] [security2:error] [pid 229246:tid 229289] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/t.php"] [unique_id "al9KXiBMYeh5YLVG45yO1QACfSo"]
[Tue Jul 21 07:30:54.531703 2026] [security2:error] [pid 229246:tid 229434] [client 213.152.162.104:60128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9KXiBMYeh5YLVG45yO1gAAAk4"]
[Tue Jul 21 07:30:54.531797 2026] [security2:error] [pid 229246:tid 229434] [client 213.152.162.104:60128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9KXiBMYeh5YLVG45yO1gAAAk4"]
[Tue Jul 21 07:30:54.539949 2026] [security2:error] [pid 229246:tid 229362] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/a.php"] [unique_id "al9KXiBMYeh5YLVG45yO1wACNHM"]
[Tue Jul 21 07:30:54.579730 2026] [security2:error] [pid 229246:tid 229385] [client 45.8.17.48:37991] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Requests/chosen.php"] [unique_id "al9KXiBMYeh5YLVG45yO3AAAAh0"]
[Tue Jul 21 07:30:54.928313 2026] [security2:error] [pid 229246:tid 229331] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KXiBMYeh5YLVG45yO4wACilQ"]
[Tue Jul 21 07:30:54.928457 2026] [security2:error] [pid 229246:tid 229494] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KXiBMYeh5YLVG45yO4wACilQ"]
[Tue Jul 21 07:30:55.204268 2026] [security2:error] [pid 229246:tid 229436] [client 20.206.105.145:7685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-blog.php"] [unique_id "al9KXyBMYeh5YLVG45yO7wAAAlA"]
[Tue Jul 21 07:30:55.211169 2026] [security2:error] [pid 229246:tid 229418] [client 117.217.38.194:51053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KXiBMYeh5YLVG45yOxgAAAj4"]
[Tue Jul 21 07:30:55.211294 2026] [security2:error] [pid 229246:tid 229418] [client 117.217.38.194:51053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KXiBMYeh5YLVG45yOxgAAAj4"]
[Tue Jul 21 07:30:55.229655 2026] [security2:error] [pid 229246:tid 229259] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/a1.php"] [unique_id "al9KXyBMYeh5YLVG45yO8AACRQw"]
[Tue Jul 21 07:30:55.326162 2026] [security2:error] [pid 229246:tid 229414] [client 20.220.225.223:23485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KXyBMYeh5YLVG45yO9AAAAjo"]
[Tue Jul 21 07:30:55.352865 2026] [security2:error] [pid 229246:tid 229410] [client 59.96.220.140:57159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KXyBMYeh5YLVG45yO9gAAAjY"]
[Tue Jul 21 07:30:55.352996 2026] [security2:error] [pid 229246:tid 229410] [client 59.96.220.140:57159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KXyBMYeh5YLVG45yO9gAAAjY"]
[Tue Jul 21 07:30:55.395931 2026] [security2:error] [pid 229246:tid 229307] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/w.php"] [unique_id "al9KXyBMYeh5YLVG45yO9wACjTw"]
[Tue Jul 21 07:30:55.455229 2026] [security2:error] [pid 229246:tid 229379] [client 20.220.225.223:52341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/ms-new.php"] [unique_id "al9KXyBMYeh5YLVG45yO-AAAAhc"]
[Tue Jul 21 07:30:55.596669 2026] [security2:error] [pid 229246:tid 229324] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/wp-good.php"] [unique_id "al9KXyBMYeh5YLVG45yPAQACT00"]
[Tue Jul 21 07:30:55.688112 2026] [security2:error] [pid 229246:tid 229470] [client 45.8.17.64:56279] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/admin.php"] [unique_id "al9KXyBMYeh5YLVG45yPBQAAAnI"]
[Tue Jul 21 07:30:55.717950 2026] [security2:error] [pid 229246:tid 229483] [client 20.151.10.161:51326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/coffexium.php"] [unique_id "al9KXyBMYeh5YLVG45yPBgAAAn8"]
[Tue Jul 21 07:30:55.764438 2026] [security2:error] [pid 229246:tid 229343] [remote 74.249.245.134:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "luminabeauty.com.br"] [uri "/.info.php"] [unique_id "al9KXyBMYeh5YLVG45yPCAACKGA"]
[Tue Jul 21 07:30:55.967026 2026] [security2:error] [pid 229246:tid 229269] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/item.php"] [unique_id "al9KXyBMYeh5YLVG45yPDQACiRY"]
[Tue Jul 21 07:30:56.060513 2026] [security2:error] [pid 229246:tid 229398] [client 117.251.86.144:40062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KYCBMYeh5YLVG45yPDwAAAio"]
[Tue Jul 21 07:30:56.060660 2026] [security2:error] [pid 229246:tid 229398] [client 117.251.86.144:40062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KYCBMYeh5YLVG45yPDwAAAio"]
[Tue Jul 21 07:30:56.133542 2026] [security2:error] [pid 229246:tid 229333] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/albin.php"] [unique_id "al9KYCBMYeh5YLVG45yPEQACcFY"]
[Tue Jul 21 07:30:56.308841 2026] [security2:error] [pid 229246:tid 229266] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/alfa.php"] [unique_id "al9KYCBMYeh5YLVG45yPFgACPhM"]
[Tue Jul 21 07:30:56.493691 2026] [security2:error] [pid 229246:tid 229353] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9KYCBMYeh5YLVG45yPGwACS2o"]
[Tue Jul 21 07:30:56.543686 2026] [security2:error] [pid 229246:tid 229497] [client 20.220.225.223:6816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/old.php"] [unique_id "al9KYCBMYeh5YLVG45yPHAAAAo0"]
[Tue Jul 21 07:30:56.666179 2026] [security2:error] [pid 229246:tid 229312] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/av.php"] [unique_id "al9KYCBMYeh5YLVG45yPIQACXUE"]
[Tue Jul 21 07:30:56.682987 2026] [security2:error] [pid 229246:tid 229397] [client 20.220.225.223:23453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/dp.php"] [unique_id "al9KYCBMYeh5YLVG45yPIgAAAik"]
[Tue Jul 21 07:30:56.788875 2026] [security2:error] [pid 229246:tid 229452] [client 45.8.17.128:59305] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/block-patterns/chosen.php"] [unique_id "al9KYCBMYeh5YLVG45yPIwAAAmA"]
[Tue Jul 21 07:30:56.816090 2026] [autoindex:error] [pid 229246:tid 229435] [client 20.206.105.145:7799] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:56.824882 2026] [security2:error] [pid 229246:tid 229464] [client 20.206.105.145:7799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9KYCBMYeh5YLVG45yPJQAAAmw"]
[Tue Jul 21 07:30:56.848390 2026] [security2:error] [pid 229246:tid 229370] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/gg.php"] [unique_id "al9KYCBMYeh5YLVG45yPJgACTns"]
[Tue Jul 21 07:30:57.001443 2026] [security2:error] [pid 229246:tid 229428] [client 20.52.136.55:1788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/222.php"] [unique_id "al9KYSBMYeh5YLVG45yPLQAAAkg"]
[Tue Jul 21 07:30:57.020318 2026] [security2:error] [pid 229246:tid 229267] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/sql.php"] [unique_id "al9KYSBMYeh5YLVG45yPLgACHhQ"]
[Tue Jul 21 07:30:57.151002 2026] [security2:error] [pid 229246:tid 229495] [client 193.36.225.58:51417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KXyBMYeh5YLVG45yPDgAAAos"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:57.203872 2026] [security2:error] [pid 229246:tid 229251] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/up.php"] [unique_id "al9KYSBMYeh5YLVG45yPNAACPQQ"]
[Tue Jul 21 07:30:57.371211 2026] [security2:error] [pid 229246:tid 229335] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/66.php"] [unique_id "al9KYSBMYeh5YLVG45yPNgACklg"]
[Tue Jul 21 07:30:57.413727 2026] [security2:error] [pid 229246:tid 229321] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KYSBMYeh5YLVG45yPNwACUEo"]
[Tue Jul 21 07:30:57.413916 2026] [security2:error] [pid 229246:tid 229436] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KYSBMYeh5YLVG45yPNwACUEo"]
[Tue Jul 21 07:30:57.487376 2026] [security2:error] [pid 229246:tid 229424] [client 139.167.225.182:56180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KYSBMYeh5YLVG45yPPgAAAkQ"]
[Tue Jul 21 07:30:57.487485 2026] [security2:error] [pid 229246:tid 229424] [client 139.167.225.182:56180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KYSBMYeh5YLVG45yPPgAAAkQ"]
[Tue Jul 21 07:30:57.759881 2026] [security2:error] [pid 229246:tid 229461] [client 20.220.225.223:23477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/old.php"] [unique_id "al9KYSBMYeh5YLVG45yPSAAAAmk"]
[Tue Jul 21 07:30:57.813442 2026] [security2:error] [pid 229246:tid 229467] [client 20.206.105.145:7707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/adminfuns.php"] [unique_id "al9KYSBMYeh5YLVG45yPSQAAAm8"]
[Tue Jul 21 07:30:57.847657 2026] [security2:error] [pid 229246:tid 229355] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/666.php"] [unique_id "al9KYSBMYeh5YLVG45yPSwACYGw"]
[Tue Jul 21 07:30:57.887296 2026] [security2:error] [pid 229246:tid 229481] [client 45.8.17.141:42589] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/ws.php"] [unique_id "al9KYSBMYeh5YLVG45yPTAAAAn0"]
[Tue Jul 21 07:30:57.961657 2026] [security2:error] [pid 229246:tid 229380] [client 122.186.204.214:54703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KYSBMYeh5YLVG45yPTQAAAhg"]
[Tue Jul 21 07:30:57.961829 2026] [security2:error] [pid 229246:tid 229380] [client 122.186.204.214:54703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KYSBMYeh5YLVG45yPTQAAAhg"]
[Tue Jul 21 07:30:57.977067 2026] [security2:error] [pid 229246:tid 229256] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KYSBMYeh5YLVG45yPTgACbAk"]
[Tue Jul 21 07:30:57.977241 2026] [security2:error] [pid 229246:tid 229464] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KYSBMYeh5YLVG45yPTgACbAk"]
[Tue Jul 21 07:30:58.016016 2026] [security2:error] [pid 229246:tid 229320] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/byp.php"] [unique_id "al9KYiBMYeh5YLVG45yPVAACMUk"]
[Tue Jul 21 07:30:58.181497 2026] [security2:error] [pid 229246:tid 229301] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/date.php"] [unique_id "al9KYiBMYeh5YLVG45yPVgACHjY"]
[Tue Jul 21 07:30:58.203764 2026] [security2:error] [pid 229246:tid 229482] [client 20.220.225.223:6787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/ms-new.php"] [unique_id "al9KYiBMYeh5YLVG45yPWgAAAn4"]
[Tue Jul 21 07:30:58.209780 2026] [security2:error] [pid 229246:tid 229489] [client 20.151.10.161:51293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/red.php"] [unique_id "al9KYiBMYeh5YLVG45yPWwAAAoU"]
[Tue Jul 21 07:30:58.358374 2026] [security2:error] [pid 229246:tid 229285] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/pomo.php"] [unique_id "al9KYiBMYeh5YLVG45yPXQACkiY"]
[Tue Jul 21 07:30:58.538895 2026] [security2:error] [pid 229246:tid 229292] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/test1.php"] [unique_id "al9KYiBMYeh5YLVG45yPYgACPi0"]
[Tue Jul 21 07:30:58.622298 2026] [security2:error] [pid 229246:tid 229496] [client 20.206.105.145:7476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/goods.php"] [unique_id "al9KYiBMYeh5YLVG45yPZgAAAow"]
[Tue Jul 21 07:30:58.778718 2026] [security2:error] [pid 229246:tid 229483] [client 103.106.20.201:62630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KYiBMYeh5YLVG45yPaQAAAn8"]
[Tue Jul 21 07:30:58.778843 2026] [security2:error] [pid 229246:tid 229483] [client 103.106.20.201:62630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KYiBMYeh5YLVG45yPaQAAAn8"]
[Tue Jul 21 07:30:58.973413 2026] [security2:error] [pid 229246:tid 229318] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/fw.php"] [unique_id "al9KYiBMYeh5YLVG45yPbgACbEc"]
[Tue Jul 21 07:30:59.067186 2026] [security2:error] [pid 229246:tid 229405] [client 20.220.225.223:52300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/track.php"] [unique_id "al9KYyBMYeh5YLVG45yPcwAAAjE"]
[Tue Jul 21 07:30:59.087226 2026] [security2:error] [pid 229246:tid 229470] [client 45.8.17.57:54441] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/tinymce/plugins/wp-load.php"] [unique_id "al9KYyBMYeh5YLVG45yPdgAAAnI"]
[Tue Jul 21 07:30:59.124851 2026] [security2:error] [pid 229246:tid 229424] [client 103.162.129.114:55134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KYyBMYeh5YLVG45yPewAAAkQ"]
[Tue Jul 21 07:30:59.124955 2026] [security2:error] [pid 229246:tid 229424] [client 103.162.129.114:55134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KYyBMYeh5YLVG45yPewAAAkQ"]
[Tue Jul 21 07:30:59.140653 2026] [security2:error] [pid 229246:tid 229325] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/fm.php"] [unique_id "al9KYyBMYeh5YLVG45yPfAACX04"]
[Tue Jul 21 07:30:59.250733 2026] [security2:error] [pid 229246:tid 229482] [client 20.206.105.145:54530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/ms-edit.php"] [unique_id "al9KYyBMYeh5YLVG45yPfQAAAn4"]
[Tue Jul 21 07:30:59.329665 2026] [security2:error] [pid 229246:tid 229281] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/ini.php"] [unique_id "al9KYyBMYeh5YLVG45yPfgACPSI"]
[Tue Jul 21 07:30:59.455424 2026] [security2:error] [pid 229246:tid 229286] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KYyBMYeh5YLVG45yPgwACiyc"]
[Tue Jul 21 07:30:59.455565 2026] [security2:error] [pid 229246:tid 229495] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KYyBMYeh5YLVG45yPgwACiyc"]
[Tue Jul 21 07:30:59.499205 2026] [security2:error] [pid 229246:tid 229369] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KYyBMYeh5YLVG45yPhgACa3o"]
[Tue Jul 21 07:30:59.499369 2026] [security2:error] [pid 229246:tid 229463] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KYyBMYeh5YLVG45yPhgACa3o"]
[Tue Jul 21 07:30:59.519080 2026] [security2:error] [pid 229246:tid 229263] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/themes.php"] [unique_id "al9KYyBMYeh5YLVG45yPiQACHBA"]
[Tue Jul 21 07:30:59.690191 2026] [security2:error] [pid 229246:tid 229348] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/dropdown.php"] [unique_id "al9KYyBMYeh5YLVG45yPkgACkGU"]
[Tue Jul 21 07:30:59.856849 2026] [security2:error] [pid 229246:tid 229278] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/wp-links.php"] [unique_id "al9KYyBMYeh5YLVG45yPmQACdR8"]
[Tue Jul 21 07:30:59.872639 2026] [security2:error] [pid 229246:tid 229477] [client 20.220.225.223:32396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/ms-new.php"] [unique_id "al9KYyBMYeh5YLVG45yPmgAAAnk"]
[Tue Jul 21 07:30:59.885770 2026] [security2:error] [pid 229246:tid 229447] [client 45.8.17.125:43559] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "al9KYyBMYeh5YLVG45yPmwAAAls"]
[Tue Jul 21 07:30:59.890443 2026] [security2:error] [pid 229246:tid 229379] [client 62.102.148.164:40312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9KYyBMYeh5YLVG45yPnAAAAhc"]
[Tue Jul 21 07:30:59.890540 2026] [security2:error] [pid 229246:tid 229379] [client 62.102.148.164:40312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9KYyBMYeh5YLVG45yPnAAAAhc"]
[Tue Jul 21 07:30:59.997095 2026] [security2:error] [pid 229246:tid 229390] [client 20.220.225.223:19288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/track.php"] [unique_id "al9KYyBMYeh5YLVG45yPnQAAAiI"]
[Tue Jul 21 07:31:00.068278 2026] [security2:error] [pid 229246:tid 229327] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPoAACKVA"]
[Tue Jul 21 07:31:00.068424 2026] [security2:error] [pid 229246:tid 229397] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPoAACKVA"]
[Tue Jul 21 07:31:00.117281 2026] [security2:error] [pid 229246:tid 229449] [client 20.220.225.223:8082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/track.php"] [unique_id "al9KZCBMYeh5YLVG45yPogAAAl0"]
[Tue Jul 21 07:31:00.120170 2026] [security2:error] [pid 229246:tid 229391] [client 154.192.233.199:59690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPpAAAAiM"]
[Tue Jul 21 07:31:00.120305 2026] [security2:error] [pid 229246:tid 229391] [client 154.192.233.199:59690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPpAAAAiM"]
[Tue Jul 21 07:31:00.139913 2026] [security2:error] [pid 229246:tid 229480] [client 175.45.70.82:64415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPpwAAAnw"]
[Tue Jul 21 07:31:00.140040 2026] [security2:error] [pid 229246:tid 229480] [client 175.45.70.82:64415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPpwAAAnw"]
[Tue Jul 21 07:31:00.276298 2026] [security2:error] [pid 229246:tid 229382] [client 173.24.185.52:54023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPqAAAAho"]
[Tue Jul 21 07:31:00.276423 2026] [security2:error] [pid 229246:tid 229382] [client 173.24.185.52:54023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPqAAAAho"]
[Tue Jul 21 07:31:00.461968 2026] [security2:error] [pid 229246:tid 229310] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmrlpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPrQACaz8"]
[Tue Jul 21 07:31:00.493097 2026] [security2:error] [pid 229246:tid 229259] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPrgACfgw"]
[Tue Jul 21 07:31:00.493230 2026] [security2:error] [pid 229246:tid 229482] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPrgACfgw"]
[Tue Jul 21 07:31:00.632170 2026] [security2:error] [pid 229246:tid 229307] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/htaccess.php"] [unique_id "al9KZCBMYeh5YLVG45yPtAACkDw"]
[Tue Jul 21 07:31:00.714405 2026] [security2:error] [pid 229246:tid 229439] [client 103.174.34.15:57034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPtgAAAlM"]
[Tue Jul 21 07:31:00.714508 2026] [security2:error] [pid 229246:tid 229439] [client 103.174.34.15:57034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPtgAAAlM"]
[Tue Jul 21 07:31:00.774159 2026] [security2:error] [pid 229246:tid 229403] [client 20.206.105.145:7287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/222.php"] [unique_id "al9KZCBMYeh5YLVG45yPtwAAAi8"]
[Tue Jul 21 07:31:00.805597 2026] [security2:error] [pid 229246:tid 229350] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/readme.php"] [unique_id "al9KZCBMYeh5YLVG45yPuAACJmc"]
[Tue Jul 21 07:31:01.004968 2026] [security2:error] [pid 229246:tid 229280] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/403.php"] [unique_id "al9KZSBMYeh5YLVG45yPvgACWyE"]
[Tue Jul 21 07:31:01.034426 2026] [autoindex:error] [pid 229246:tid 229379] [client 64.69.216.78:37460] AH01276: Cannot serve directory /home2/onfiel33/kotovicz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:01.140106 2026] [security2:error] [pid 229246:tid 229497] [client 193.36.225.55:46609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KZSBMYeh5YLVG45yPwwAAAo0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:01.182776 2026] [security2:error] [pid 229246:tid 229408] [client 45.8.17.116:38145] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/simple.php"] [unique_id "al9KZSBMYeh5YLVG45yPxQAAAjQ"]
[Tue Jul 21 07:31:01.192543 2026] [security2:error] [pid 229246:tid 229248] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/max.php"] [unique_id "al9KZSBMYeh5YLVG45yPxgACXQE"]
[Tue Jul 21 07:31:01.211464 2026] [security2:error] [pid 229246:tid 229391] [client 20.206.105.145:7728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9KZSBMYeh5YLVG45yPxwAAAiM"]
[Tue Jul 21 07:31:01.289743 2026] [proxy:error] [pid 229246:tid 229424] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:01.289834 2026] [proxy_http:error] [pid 229246:tid 229424] [client 20.151.10.161:50911] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:01.290321 2026] [proxy:error] [pid 229246:tid 229424] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:01.290362 2026] [proxy_http:error] [pid 229246:tid 229424] [client 20.151.10.161:50911] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:01.368771 2026] [security2:error] [pid 229246:tid 229469] [client 82.102.28.107:44240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9KZSBMYeh5YLVG45yPzgAAAnE"]
[Tue Jul 21 07:31:01.368881 2026] [security2:error] [pid 229246:tid 229469] [client 82.102.28.107:44240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9KZSBMYeh5YLVG45yPzgAAAnE"]
[Tue Jul 21 07:31:01.509608 2026] [security2:error] [pid 229246:tid 229463] [client 20.220.225.223:62863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/berlin.php"] [unique_id "al9KZSBMYeh5YLVG45yP0wAAAms"]
[Tue Jul 21 07:31:01.548606 2026] [security2:error] [pid 229246:tid 229470] [client 173.252.95.5:62992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9KZSBMYeh5YLVG45yP0AAAAnI"]
[Tue Jul 21 07:31:01.592990 2026] [autoindex:error] [pid 229246:tid 229384] [client 64.69.216.78:37514] AH01276: Cannot serve directory /home2/onfiel33/kotovicz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:01.780130 2026] [security2:error] [pid 229246:tid 229346] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/m.php"] [unique_id "al9KZSBMYeh5YLVG45yP2gACPmM"]
[Tue Jul 21 07:31:01.980253 2026] [security2:error] [pid 229246:tid 229252] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/click.php"] [unique_id "al9KZSBMYeh5YLVG45yP4AACfQU"]
[Tue Jul 21 07:31:01.986744 2026] [security2:error] [pid 229246:tid 229376] [client 173.252.95.63:36664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9KZSBMYeh5YLVG45yP4QAAAhQ"]
[Tue Jul 21 07:31:02.013131 2026] [autoindex:error] [pid 229246:tid 229435] [client 20.206.105.145:7379] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:02.043729 2026] [security2:error] [pid 229246:tid 229477] [client 20.206.105.145:7379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9KZiBMYeh5YLVG45yP5AAAAnk"]
[Tue Jul 21 07:31:02.152606 2026] [security2:error] [pid 229246:tid 229370] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/lv.php"] [unique_id "al9KZiBMYeh5YLVG45yP5gACIns"]
[Tue Jul 21 07:31:02.162718 2026] [security2:error] [pid 229246:tid 229379] [client 62.102.148.164:52088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KZiBMYeh5YLVG45yP5wAAAhc"]
[Tue Jul 21 07:31:02.162800 2026] [security2:error] [pid 229246:tid 229379] [client 62.102.148.164:52088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KZiBMYeh5YLVG45yP5wAAAhc"]
[Tue Jul 21 07:31:02.220155 2026] [security2:error] [pid 229246:tid 229397] [client 20.220.225.223:8078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/2352356666.php"] [unique_id "al9KZiBMYeh5YLVG45yP6wAAAik"]
[Tue Jul 21 07:31:02.329918 2026] [security2:error] [pid 229246:tid 229298] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/cong.php"] [unique_id "al9KZiBMYeh5YLVG45yP8AACdTM"]
[Tue Jul 21 07:31:02.393180 2026] [autoindex:error] [pid 229246:tid 229451] [client 20.206.105.145:7455] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:02.425934 2026] [autoindex:error] [pid 229246:tid 229386] [client 20.206.105.145:7455] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:02.515083 2026] [security2:error] [pid 229246:tid 229251] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/brand.php"] [unique_id "al9KZiBMYeh5YLVG45yP9wACSQQ"]
[Tue Jul 21 07:31:02.559373 2026] [security2:error] [pid 229246:tid 229361] [remote 152.53.111.131:36534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cezaretto.com.br"] [uri "/wp-login.php"] [unique_id "al9KZiBMYeh5YLVG45yP-gACiHI"]
[Tue Jul 21 07:31:02.598502 2026] [security2:error] [pid 229246:tid 229440] [client 45.251.232.145:61958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZiBMYeh5YLVG45yP-wAAAlQ"]
[Tue Jul 21 07:31:02.598632 2026] [security2:error] [pid 229246:tid 229440] [client 45.251.232.145:61958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZiBMYeh5YLVG45yP-wAAAlQ"]
[Tue Jul 21 07:31:02.599677 2026] [rewrite:warn] [pid 229246:tid 229328] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:31:02.646574 2026] [security2:error] [pid 229246:tid 229384] [client 20.220.225.223:45984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/berlin.php"] [unique_id "al9KZiBMYeh5YLVG45yP_QAAAhw"]
[Tue Jul 21 07:31:02.698821 2026] [security2:error] [pid 229246:tid 229321] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/atomlib.php"] [unique_id "al9KZiBMYeh5YLVG45yP_wACfEo"]
[Tue Jul 21 07:31:02.723092 2026] [security2:error] [pid 229246:tid 229388] [client 20.206.105.145:7455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/raw.php"] [unique_id "al9KZiBMYeh5YLVG45yQAgAAAiA"]
[Tue Jul 21 07:31:02.732563 2026] [security2:error] [pid 229246:tid 229254] [remote 173.252.87.39:37268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9KZiBMYeh5YLVG45yQBAACawc"]
[Tue Jul 21 07:31:02.771024 2026] [security2:error] [pid 229246:tid 229334] [remote 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naldoinvest.com.br"] [uri "/wp-admin/install.php"] [unique_id "al9KZiBMYeh5YLVG45yQBQACaVc"]
[Tue Jul 21 07:31:02.873901 2026] [security2:error] [pid 229246:tid 229439] [client 213.152.162.104:53042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9KZiBMYeh5YLVG45yQBwAAAlM"]
[Tue Jul 21 07:31:02.874013 2026] [security2:error] [pid 229246:tid 229439] [client 213.152.162.104:53042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9KZiBMYeh5YLVG45yQBwAAAlM"]
[Tue Jul 21 07:31:02.881806 2026] [security2:error] [pid 229246:tid 229271] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/0x.php"] [unique_id "al9KZiBMYeh5YLVG45yQCAACFRg"]
[Tue Jul 21 07:31:03.011572 2026] [security2:error] [pid 229246:tid 229424] [client 20.10.88.227:1860] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rioclaroimovel.com.br"] [uri "/index.php"] [unique_id "al9KZiBMYeh5YLVG45yP-AAAAkQ"]
[Tue Jul 21 07:31:03.052363 2026] [security2:error] [pid 229246:tid 229253] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/buy.php"] [unique_id "al9KZyBMYeh5YLVG45yQDAACQQY"]
[Tue Jul 21 07:31:03.218258 2026] [security2:error] [pid 229246:tid 229284] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/sx.php"] [unique_id "al9KZyBMYeh5YLVG45yQEQACKSU"]
[Tue Jul 21 07:31:03.269603 2026] [security2:error] [pid 229246:tid 229285] [remote 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naldoinvest.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9KZyBMYeh5YLVG45yQFQACTiY"]
[Tue Jul 21 07:31:03.394174 2026] [security2:error] [pid 229246:tid 229290] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/article.php"] [unique_id "al9KZyBMYeh5YLVG45yQGAACXys"]
[Tue Jul 21 07:31:03.568434 2026] [rewrite:warn] [pid 229246:tid 229332] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:31:03.569066 2026] [rewrite:warn] [pid 229246:tid 229318] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:31:03.573923 2026] [rewrite:warn] [pid 229246:tid 229341] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:31:03.573952 2026] [rewrite:warn] [pid 229246:tid 229273] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:31:03.593306 2026] [security2:error] [pid 229246:tid 229500] [client 45.8.17.131:57183] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/link/"] [unique_id "al9KZyBMYeh5YLVG45yQJwAAApA"]
[Tue Jul 21 07:31:03.599520 2026] [security2:error] [pid 229246:tid 229439] [client 20.206.105.145:7770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/abcd.php"] [unique_id "al9KZyBMYeh5YLVG45yQKAAAAlM"]
[Tue Jul 21 07:31:03.738041 2026] [rewrite:warn] [pid 229246:tid 229293] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:31:03.742761 2026] [rewrite:warn] [pid 229246:tid 229258] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:31:03.836217 2026] [security2:error] [pid 229246:tid 229338] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/bootstrap.php"] [unique_id "al9KZyBMYeh5YLVG45yQMQACL1s"]
[Tue Jul 21 07:31:03.971557 2026] [security2:error] [pid 229246:tid 229467] [client 117.217.38.194:51500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZyBMYeh5YLVG45yQNQAAAm8"]
[Tue Jul 21 07:31:03.971693 2026] [security2:error] [pid 229246:tid 229467] [client 117.217.38.194:51500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZyBMYeh5YLVG45yQNQAAAm8"]
[Tue Jul 21 07:31:04.016943 2026] [security2:error] [pid 229246:tid 229369] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/config-backup.php"] [unique_id "al9KaCBMYeh5YLVG45yQOQACTno"]
[Tue Jul 21 07:31:04.046321 2026] [security2:error] [pid 229246:tid 229391] [client 20.52.136.55:1733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/t.php"] [unique_id "al9KaCBMYeh5YLVG45yQOgAAAiM"]
[Tue Jul 21 07:31:04.186712 2026] [security2:error] [pid 229246:tid 229288] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/goods.php"] [unique_id "al9KaCBMYeh5YLVG45yQQAACKik"]
[Tue Jul 21 07:31:04.371246 2026] [security2:error] [pid 229246:tid 229372] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/init.php"] [unique_id "al9KaCBMYeh5YLVG45yQSAACa30"]
[Tue Jul 21 07:31:04.464112 2026] [autoindex:error] [pid 229246:tid 229362] [remote 100.50.152.193:0] AH01276: Cannot serve directory /home1/bastar15/lacorsini.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:04.521166 2026] [security2:error] [pid 229246:tid 229278] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KaCBMYeh5YLVG45yQSwACah8"]
[Tue Jul 21 07:31:04.521304 2026] [security2:error] [pid 229246:tid 229462] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KaCBMYeh5YLVG45yQSwACah8"]
[Tue Jul 21 07:31:04.695974 2026] [autoindex:error] [pid 229246:tid 229464] [client 3.219.86.171:47030] AH01276: Cannot serve directory /home1/bastar15/lacorsini.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:04.750179 2026] [authz_core:error] [pid 229246:tid 229310] [remote 74.249.245.134:0] AH01630: client denied by server configuration: /home1/deesmo24/luminabeauty.com.br/php.ini
[Tue Jul 21 07:31:04.843238 2026] [security2:error] [pid 229246:tid 229397] [client 20.206.105.145:7176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/a1.php"] [unique_id "al9KaCBMYeh5YLVG45yQWgAAAik"]
[Tue Jul 21 07:31:04.895783 2026] [rewrite:warn] [pid 229246:tid 229259] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:31:04.937999 2026] [security2:error] [pid 229246:tid 229296] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/settings.php"] [unique_id "al9KaCBMYeh5YLVG45yQXAACHjE"]
[Tue Jul 21 07:31:05.107117 2026] [security2:error] [pid 229246:tid 229472] [client 20.220.225.223:8086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/pn.php"] [unique_id "al9KaSBMYeh5YLVG45yQYAAAAnQ"]
[Tue Jul 21 07:31:05.145935 2026] [security2:error] [pid 229246:tid 229307] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/g.php"] [unique_id "al9KaSBMYeh5YLVG45yQYQACNTw"]
[Tue Jul 21 07:31:05.205364 2026] [security2:error] [pid 229246:tid 229492] [client 20.151.10.161:50934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9KaSBMYeh5YLVG45yQZAAAAog"]
[Tue Jul 21 07:31:05.312631 2026] [security2:error] [pid 229246:tid 229343] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/403.php"] [unique_id "al9KaSBMYeh5YLVG45yQbAACXmA"]
[Tue Jul 21 07:31:05.503185 2026] [security2:error] [pid 229246:tid 229367] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/api.php"] [unique_id "al9KaSBMYeh5YLVG45yQcAACf3g"]
[Tue Jul 21 07:31:05.539219 2026] [security2:error] [pid 229246:tid 229289] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KaSBMYeh5YLVG45yQcQACUCo"]
[Tue Jul 21 07:31:05.539342 2026] [security2:error] [pid 229246:tid 229436] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KaSBMYeh5YLVG45yQcQACUCo"]
[Tue Jul 21 07:31:05.593344 2026] [security2:error] [pid 229246:tid 229401] [client 45.8.17.48:29211] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/config.php"] [unique_id "al9KaSBMYeh5YLVG45yQdQAAAi0"]
[Tue Jul 21 07:31:05.903801 2026] [security2:error] [pid 229246:tid 229420] [client 152.59.154.239:59008] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KaSBMYeh5YLVG45yQfgAAAkA"]
[Tue Jul 21 07:31:05.906778 2026] [security2:error] [pid 229246:tid 229420] [client 152.59.154.239:59008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KaSBMYeh5YLVG45yQfgAAAkA"]
[Tue Jul 21 07:31:06.134243 2026] [security2:error] [pid 229246:tid 229492] [client 62.102.148.164:40320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KaiBMYeh5YLVG45yQiwAAAog"]
[Tue Jul 21 07:31:06.134350 2026] [security2:error] [pid 229246:tid 229492] [client 62.102.148.164:40320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KaiBMYeh5YLVG45yQiwAAAog"]
[Tue Jul 21 07:31:06.583810 2026] [security2:error] [pid 229246:tid 229410] [client 45.8.17.148:49807] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/colors/midnight/"] [unique_id "al9KaiBMYeh5YLVG45yQkgAAAjY"]
[Tue Jul 21 07:31:06.708361 2026] [security2:error] [pid 229246:tid 229378] [client 20.206.105.145:7473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9KaiBMYeh5YLVG45yQmQAAAhY"]
[Tue Jul 21 07:31:06.821224 2026] [security2:error] [pid 229246:tid 229451] [client 117.251.86.144:47608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KaiBMYeh5YLVG45yQmwAAAl8"]
[Tue Jul 21 07:31:06.821434 2026] [security2:error] [pid 229246:tid 229451] [client 117.251.86.144:47608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KaiBMYeh5YLVG45yQmwAAAl8"]
[Tue Jul 21 07:31:06.924368 2026] [security2:error] [pid 229246:tid 229428] [client 59.96.220.140:57617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KaiBMYeh5YLVG45yQnwAAAkg"]
[Tue Jul 21 07:31:06.924455 2026] [security2:error] [pid 229246:tid 229428] [client 59.96.220.140:57617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KaiBMYeh5YLVG45yQnwAAAkg"]
[Tue Jul 21 07:31:07.308099 2026] [security2:error] [pid 229246:tid 229361] [remote 117.0.21.154:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9KayBMYeh5YLVG45yQogACTnI"]
[Tue Jul 21 07:31:07.505261 2026] [security2:error] [pid 229246:tid 229388] [client 62.102.148.164:40322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9KayBMYeh5YLVG45yQrQAAAiA"]
[Tue Jul 21 07:31:07.505363 2026] [security2:error] [pid 229246:tid 229388] [client 62.102.148.164:40322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9KayBMYeh5YLVG45yQrQAAAiA"]
[Tue Jul 21 07:31:07.745198 2026] [security2:error] [pid 229246:tid 229478] [client 20.220.225.223:52190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/track.php"] [unique_id "al9KayBMYeh5YLVG45yQtgAAAno"]
[Tue Jul 21 07:31:07.746013 2026] [security2:error] [pid 229246:tid 229410] [client 20.220.225.223:48529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/billur.php"] [unique_id "al9KayBMYeh5YLVG45yQuAAAAjY"]
[Tue Jul 21 07:31:07.904486 2026] [security2:error] [pid 229246:tid 229427] [client 45.8.17.49:41563] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/codemirror/"] [unique_id "al9KayBMYeh5YLVG45yQvgAAAkc"]
[Tue Jul 21 07:31:07.929721 2026] [security2:error] [pid 229246:tid 229335] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KayBMYeh5YLVG45yQvwACLFg"]
[Tue Jul 21 07:31:07.929872 2026] [security2:error] [pid 229246:tid 229400] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KayBMYeh5YLVG45yQvwACLFg"]
[Tue Jul 21 07:31:08.229544 2026] [security2:error] [pid 229246:tid 229384] [client 139.167.225.182:56810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbCBMYeh5YLVG45yQxwAAAhw"]
[Tue Jul 21 07:31:08.229661 2026] [security2:error] [pid 229246:tid 229384] [client 139.167.225.182:56810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbCBMYeh5YLVG45yQxwAAAhw"]
[Tue Jul 21 07:31:08.454838 2026] [security2:error] [pid 229246:tid 229290] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbCBMYeh5YLVG45yQ0gACbSs"]
[Tue Jul 21 07:31:08.454997 2026] [security2:error] [pid 229246:tid 229465] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbCBMYeh5YLVG45yQ0gACbSs"]
[Tue Jul 21 07:31:08.626528 2026] [security2:error] [pid 229246:tid 229397] [client 122.186.204.214:55184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KbCBMYeh5YLVG45yQ3AAAAik"]
[Tue Jul 21 07:31:08.626656 2026] [security2:error] [pid 229246:tid 229397] [client 122.186.204.214:55184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KbCBMYeh5YLVG45yQ3AAAAik"]
[Tue Jul 21 07:31:08.647431 2026] [security2:error] [pid 229246:tid 229390] [client 37.140.223.68:46503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KbCBMYeh5YLVG45yQ3gAAAiI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:08.758076 2026] [security2:error] [pid 229246:tid 229428] [client 103.162.129.114:55553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KbCBMYeh5YLVG45yQ4gAAAkg"]
[Tue Jul 21 07:31:08.758224 2026] [security2:error] [pid 229246:tid 229428] [client 103.162.129.114:55553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KbCBMYeh5YLVG45yQ4gAAAkg"]
[Tue Jul 21 07:31:08.766664 2026] [security2:error] [pid 229246:tid 229396] [client 20.197.192.193:9412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KbCBMYeh5YLVG45yQ5AAAAig"]
[Tue Jul 21 07:31:09.015252 2026] [security2:error] [pid 229246:tid 229398] [client 45.8.17.125:60823] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/ab.php"] [unique_id "al9KbSBMYeh5YLVG45yQ6wAAAio"]
[Tue Jul 21 07:31:09.031958 2026] [security2:error] [pid 229246:tid 229414] [client 20.206.105.145:7453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9KbSBMYeh5YLVG45yQ7QAAAjo"]
[Tue Jul 21 07:31:09.184605 2026] [security2:error] [pid 229246:tid 229499] [client 20.197.192.193:9410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KbSBMYeh5YLVG45yQ8QAAAo8"]
[Tue Jul 21 07:31:09.544797 2026] [security2:error] [pid 229246:tid 229416] [client 20.220.225.223:63820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/2352356666.php"] [unique_id "al9KbSBMYeh5YLVG45yQ_QAAAjw"]
[Tue Jul 21 07:31:09.544841 2026] [security2:error] [pid 229246:tid 229397] [client 20.197.192.193:9433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wander.php"] [unique_id "al9KbSBMYeh5YLVG45yQ_gAAAik"]
[Tue Jul 21 07:31:09.544966 2026] [security2:error] [pid 229246:tid 229496] [client 103.106.20.201:63197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbSBMYeh5YLVG45yQ_wAAAow"]
[Tue Jul 21 07:31:09.545785 2026] [security2:error] [pid 229246:tid 229496] [client 103.106.20.201:63197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbSBMYeh5YLVG45yQ_wAAAow"]
[Tue Jul 21 07:31:09.979013 2026] [security2:error] [pid 229246:tid 229272] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KbSBMYeh5YLVG45yRCQACNRk"]
[Tue Jul 21 07:31:09.979251 2026] [security2:error] [pid 229246:tid 229409] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KbSBMYeh5YLVG45yRCQACNRk"]
[Tue Jul 21 07:31:10.192243 2026] [security2:error] [pid 229246:tid 229414] [client 45.8.17.119:43567] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/comments-pagination-numbers/"] [unique_id "al9KbiBMYeh5YLVG45yRDQAAAjo"]
[Tue Jul 21 07:31:10.268793 2026] [proxy:error] [pid 229246:tid 229486] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:10.268889 2026] [proxy_http:error] [pid 229246:tid 229486] [client 20.151.10.161:50910] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:10.269587 2026] [proxy:error] [pid 229246:tid 229486] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:10.269648 2026] [proxy_http:error] [pid 229246:tid 229486] [client 20.151.10.161:50910] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:10.491025 2026] [security2:error] [pid 229246:tid 229502] [client 74.7.241.130:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tryhealth.shop.oficialwebsite.com.br"] [uri "/index.php"] [unique_id "al9KbCBMYeh5YLVG45yQ2gAAApI"]
[Tue Jul 21 07:31:10.491908 2026] [security2:error] [pid 229246:tid 229431] [client 74.7.241.130:42282] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tryhealth.shop.oficialwebsite.com.br"] [uri "/robots.txt"] [unique_id "al9KbCBMYeh5YLVG45yQ1wACSyQ"]
[Tue Jul 21 07:31:10.520661 2026] [security2:error] [pid 229246:tid 229495] [client 20.197.192.193:8332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/jga.php"] [unique_id "al9KbiBMYeh5YLVG45yRGQAAAos"]
[Tue Jul 21 07:31:10.759529 2026] [security2:error] [pid 229246:tid 229416] [client 109.248.148.246:59756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9KbiBMYeh5YLVG45yRGwAAAjw"]
[Tue Jul 21 07:31:10.759620 2026] [security2:error] [pid 229246:tid 229416] [client 109.248.148.246:59756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9KbiBMYeh5YLVG45yRGwAAAjw"]
[Tue Jul 21 07:31:10.810696 2026] [security2:error] [pid 229246:tid 229386] [client 154.192.233.199:58876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbiBMYeh5YLVG45yRHAAAAh4"]
[Tue Jul 21 07:31:10.810794 2026] [security2:error] [pid 229246:tid 229386] [client 154.192.233.199:58876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbiBMYeh5YLVG45yRHAAAAh4"]
[Tue Jul 21 07:31:10.816265 2026] [security2:error] [pid 229246:tid 229278] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KbiBMYeh5YLVG45yRHQACgR8"]
[Tue Jul 21 07:31:10.816446 2026] [security2:error] [pid 229246:tid 229485] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KbiBMYeh5YLVG45yRHQACgR8"]
[Tue Jul 21 07:31:10.833542 2026] [security2:error] [pid 229246:tid 229403] [client 173.24.185.52:54484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KbiBMYeh5YLVG45yRHwAAAi8"]
[Tue Jul 21 07:31:10.833628 2026] [security2:error] [pid 229246:tid 229403] [client 173.24.185.52:54484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KbiBMYeh5YLVG45yRHwAAAi8"]
[Tue Jul 21 07:31:10.855078 2026] [security2:error] [pid 229246:tid 229482] [client 175.45.70.82:64944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbiBMYeh5YLVG45yRIAAAAn4"]
[Tue Jul 21 07:31:10.855192 2026] [security2:error] [pid 229246:tid 229482] [client 175.45.70.82:64944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbiBMYeh5YLVG45yRIAAAAn4"]
[Tue Jul 21 07:31:10.879184 2026] [security2:error] [pid 229246:tid 229273] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KbCBMYeh5YLVG45yQ5gACIxo"]
[Tue Jul 21 07:31:10.879422 2026] [security2:error] [pid 229246:tid 229391] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KbCBMYeh5YLVG45yQ5gACIxo"]
[Tue Jul 21 07:31:11.175850 2026] [security2:error] [pid 229246:tid 229500] [client 20.197.192.193:9435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/x.php"] [unique_id "al9KbyBMYeh5YLVG45yRLAAAApA"]
[Tue Jul 21 07:31:11.255604 2026] [security2:error] [pid 229246:tid 229276] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbyBMYeh5YLVG45yRMAACPR0"]
[Tue Jul 21 07:31:11.255744 2026] [security2:error] [pid 229246:tid 229417] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbyBMYeh5YLVG45yRMAACPR0"]
[Tue Jul 21 07:31:11.600834 2026] [security2:error] [pid 229246:tid 229395] [client 20.206.105.145:7436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-content/BypassBest.php"] [unique_id "al9KbyBMYeh5YLVG45yRPAAAAic"]
[Tue Jul 21 07:31:11.622232 2026] [security2:error] [pid 229246:tid 229418] [client 103.174.34.15:57523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbyBMYeh5YLVG45yRPQAAAj4"]
[Tue Jul 21 07:31:11.622335 2026] [security2:error] [pid 229246:tid 229418] [client 103.174.34.15:57523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbyBMYeh5YLVG45yRPQAAAj4"]
[Tue Jul 21 07:31:11.641032 2026] [security2:error] [pid 229246:tid 229380] [client 20.197.192.193:8347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9KbyBMYeh5YLVG45yRPgAAAhg"]
[Tue Jul 21 07:31:11.694749 2026] [security2:error] [pid 229246:tid 229502] [client 20.10.88.201:62592] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tryhealth.shop"] [uri "/robots.txt"] [unique_id "al9KbyBMYeh5YLVG45yRPwAAApI"]
[Tue Jul 21 07:31:11.782842 2026] [security2:error] [pid 229246:tid 229485] [client 45.8.17.136:60311] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/post-featured-image/"] [unique_id "al9KbyBMYeh5YLVG45yRQQAAAoE"]
[Tue Jul 21 07:31:12.139652 2026] [security2:error] [pid 229246:tid 229503] [client 20.197.192.193:8364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/ee.php"] [unique_id "al9KcCBMYeh5YLVG45yRTwAAApM"]
[Tue Jul 21 07:31:12.148188 2026] [security2:error] [pid 229246:tid 229409] [client 20.151.10.161:57996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/footer.php"] [unique_id "al9KcCBMYeh5YLVG45yRUAAAAjU"]
[Tue Jul 21 07:31:12.354564 2026] [security2:error] [pid 229246:tid 229451] [client 193.36.225.72:59999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KcCBMYeh5YLVG45yRUQAAAl8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:12.365148 2026] [security2:error] [pid 229246:tid 229500] [client 20.197.192.193:8327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/blue.php"] [unique_id "al9KcCBMYeh5YLVG45yRUgAAApA"]
[Tue Jul 21 07:31:12.552499 2026] [security2:error] [pid 229246:tid 229480] [client 20.197.192.193:8343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-signup.php"] [unique_id "al9KcCBMYeh5YLVG45yRWQAAAnw"]
[Tue Jul 21 07:31:12.667532 2026] [security2:error] [pid 229246:tid 229501] [client 20.206.105.145:39257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KcCBMYeh5YLVG45yRXgAAApE"]
[Tue Jul 21 07:31:12.746170 2026] [security2:error] [pid 229246:tid 229472] [client 20.220.225.223:56483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/pn.php"] [unique_id "al9KcCBMYeh5YLVG45yRYQAAAnQ"]
[Tue Jul 21 07:31:12.887222 2026] [security2:error] [pid 229246:tid 229377] [client 45.8.17.118:21225] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/wc-logs/"] [unique_id "al9KcCBMYeh5YLVG45yRYwAAAhU"]
[Tue Jul 21 07:31:12.998540 2026] [security2:error] [pid 229246:tid 229408] [client 20.52.136.55:1585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/a.php"] [unique_id "al9KcCBMYeh5YLVG45yRaAAAAjQ"]
[Tue Jul 21 07:31:13.073900 2026] [security2:error] [pid 229246:tid 229457] [client 45.251.232.145:62484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KcSBMYeh5YLVG45yRagAAAmU"]
[Tue Jul 21 07:31:13.074017 2026] [security2:error] [pid 229246:tid 229457] [client 45.251.232.145:62484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KcSBMYeh5YLVG45yRagAAAmU"]
[Tue Jul 21 07:31:13.182733 2026] [security2:error] [pid 229246:tid 229478] [client 20.220.225.223:6121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/2352356666.php"] [unique_id "al9KcSBMYeh5YLVG45yRbgAAAno"]
[Tue Jul 21 07:31:13.461226 2026] [security2:error] [pid 229246:tid 229401] [client 82.102.28.107:58324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KcSBMYeh5YLVG45yRcwAAAi0"]
[Tue Jul 21 07:31:13.461352 2026] [security2:error] [pid 229246:tid 229401] [client 82.102.28.107:58324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KcSBMYeh5YLVG45yRcwAAAi0"]
[Tue Jul 21 07:31:13.608845 2026] [security2:error] [pid 229246:tid 229477] [client 62.102.148.164:44478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9KcSBMYeh5YLVG45yReQAAAnk"]
[Tue Jul 21 07:31:13.608972 2026] [security2:error] [pid 229246:tid 229477] [client 62.102.148.164:44478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9KcSBMYeh5YLVG45yReQAAAnk"]
[Tue Jul 21 07:31:13.658525 2026] [security2:error] [pid 229246:tid 229471] [client 20.197.192.193:8382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/csa.php"] [unique_id "al9KcSBMYeh5YLVG45yRfAAAAnM"]
[Tue Jul 21 07:31:13.717230 2026] [security2:error] [pid 229246:tid 229494] [client 35.202.101.58:41926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.101.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9KcCBMYeh5YLVG45yRYAAAAoo"]
[Tue Jul 21 07:31:13.727784 2026] [security2:error] [pid 229246:tid 229413] [client 20.220.225.223:62883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/billur.php"] [unique_id "al9KcSBMYeh5YLVG45yRfwAAAjk"]
[Tue Jul 21 07:31:14.090281 2026] [proxy:error] [pid 229246:tid 229416] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:14.090354 2026] [proxy_http:error] [pid 229246:tid 229416] [client 20.151.10.161:51294] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:14.090785 2026] [proxy:error] [pid 229246:tid 229416] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:14.090810 2026] [proxy_http:error] [pid 229246:tid 229416] [client 20.151.10.161:51294] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:14.394323 2026] [security2:error] [pid 229246:tid 229383] [client 45.8.17.63:50517] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/upload.php"] [unique_id "al9KciBMYeh5YLVG45yRkQAAAhs"]
[Tue Jul 21 07:31:14.469864 2026] [security2:error] [pid 229246:tid 229424] [client 117.217.38.194:51981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KciBMYeh5YLVG45yRlAAAAkQ"]
[Tue Jul 21 07:31:14.469981 2026] [security2:error] [pid 229246:tid 229424] [client 117.217.38.194:51981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KciBMYeh5YLVG45yRlAAAAkQ"]
[Tue Jul 21 07:31:14.936877 2026] [security2:error] [pid 229246:tid 229440] [client 20.206.105.145:54567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/simple.php"] [unique_id "al9KciBMYeh5YLVG45yRoAAAAlQ"]
[Tue Jul 21 07:31:15.026115 2026] [security2:error] [pid 229246:tid 229480] [client 20.206.105.145:7482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/xxx.php"] [unique_id "al9KcyBMYeh5YLVG45yRowAAAnw"]
[Tue Jul 21 07:31:15.065475 2026] [security2:error] [pid 229246:tid 229395] [client 20.206.105.145:7765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/hypo.php"] [unique_id "al9KcyBMYeh5YLVG45yRpQAAAic"]
[Tue Jul 21 07:31:15.117096 2026] [security2:error] [pid 229246:tid 229251] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KcyBMYeh5YLVG45yRpwACOgQ"]
[Tue Jul 21 07:31:15.117246 2026] [security2:error] [pid 229246:tid 229414] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KcyBMYeh5YLVG45yRpwACOgQ"]
[Tue Jul 21 07:31:15.143768 2026] [security2:error] [pid 229246:tid 229496] [client 104.28.156.104:40169] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "carrosselbuique.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9KcyBMYeh5YLVG45yRqAAAAow"]
[Tue Jul 21 07:31:15.205499 2026] [security2:error] [pid 229246:tid 229484] [client 45.8.17.147:37803] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/maint/network/"] [unique_id "al9KcyBMYeh5YLVG45yRqwAAAoA"]
[Tue Jul 21 07:31:15.221235 2026] [security2:error] [pid 229246:tid 229378] [client 20.197.192.193:8383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/min.php"] [unique_id "al9KcyBMYeh5YLVG45yRrAAAAhY"]
[Tue Jul 21 07:31:15.230892 2026] [autoindex:error] [pid 229246:tid 229427] [client 20.206.105.145:7361] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:15.288190 2026] [security2:error] [pid 229246:tid 229382] [client 20.206.105.145:7361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/chosen.php"] [unique_id "al9KcyBMYeh5YLVG45yRsQAAAho"]
[Tue Jul 21 07:31:15.294857 2026] [security2:error] [pid 229246:tid 229489] [client 20.220.225.223:8079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/wp-wpbak.php"] [unique_id "al9KcyBMYeh5YLVG45yRsgAAAoU"]
[Tue Jul 21 07:31:15.491553 2026] [security2:error] [pid 229246:tid 229391] [client 20.197.192.193:8325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/echkm.php"] [unique_id "al9KcyBMYeh5YLVG45yRtAAAAiM"]
[Tue Jul 21 07:31:15.670801 2026] [security2:error] [pid 229246:tid 229390] [client 20.220.225.223:46084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/mimpi.php"] [unique_id "al9KcyBMYeh5YLVG45yRuQAAAiI"]
[Tue Jul 21 07:31:15.784217 2026] [autoindex:error] [pid 229246:tid 229433] [client 20.206.105.145:54549] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:15.803948 2026] [security2:error] [pid 229246:tid 229483] [client 20.206.105.145:54549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/file5.php"] [unique_id "al9KcyBMYeh5YLVG45yRvgAAAn8"]
[Tue Jul 21 07:31:15.897410 2026] [security2:error] [pid 229246:tid 229492] [client 62.102.148.164:34120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KcyBMYeh5YLVG45yRwQAAAog"]
[Tue Jul 21 07:31:15.897496 2026] [security2:error] [pid 229246:tid 229492] [client 62.102.148.164:34120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KcyBMYeh5YLVG45yRwQAAAog"]
[Tue Jul 21 07:31:16.039310 2026] [security2:error] [pid 229246:tid 229287] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KdCBMYeh5YLVG45yRwwACkCg"]
[Tue Jul 21 07:31:16.039439 2026] [security2:error] [pid 229246:tid 229500] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KdCBMYeh5YLVG45yRwwACkCg"]
[Tue Jul 21 07:31:16.185435 2026] [security2:error] [pid 229246:tid 229503] [client 45.8.17.146:59885] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/group/"] [unique_id "al9KdCBMYeh5YLVG45yRxwAAApM"]
[Tue Jul 21 07:31:16.240438 2026] [security2:error] [pid 229246:tid 229401] [client 20.197.192.193:9408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/mac.php"] [unique_id "al9KdCBMYeh5YLVG45yRyAAAAi0"]
[Tue Jul 21 07:31:16.272743 2026] [security2:error] [pid 229246:tid 229420] [client 104.28.156.104:40174] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "carrosselbuique.com.br"] [uri "/"] [unique_id "al9KdCBMYeh5YLVG45yRygAAAkA"]
[Tue Jul 21 07:31:16.325005 2026] [security2:error] [pid 229246:tid 229458] [client 122.129.67.13:59989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9KcyBMYeh5YLVG45yRpgAAAmY"]
[Tue Jul 21 07:31:16.377438 2026] [security2:error] [pid 229246:tid 229471] [client 193.36.225.68:32809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KdCBMYeh5YLVG45yRzgAAAnM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:16.615170 2026] [security2:error] [pid 229246:tid 229488] [client 59.96.220.140:58110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KdCBMYeh5YLVG45yR1wAAAoQ"]
[Tue Jul 21 07:31:16.615278 2026] [security2:error] [pid 229246:tid 229488] [client 59.96.220.140:58110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KdCBMYeh5YLVG45yR1wAAAoQ"]
[Tue Jul 21 07:31:16.881505 2026] [proxy:error] [pid 229246:tid 229431] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:16.881597 2026] [proxy_http:error] [pid 229246:tid 229431] [client 137.184.89.104:33794] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:16.882217 2026] [proxy:error] [pid 229246:tid 229431] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:16.882245 2026] [proxy_http:error] [pid 229246:tid 229431] [client 137.184.89.104:33794] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:17.221800 2026] [security2:error] [pid 229246:tid 229424] [client 20.220.225.223:8106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/dr.php"] [unique_id "al9KdSBMYeh5YLVG45yR3wAAAkQ"]
[Tue Jul 21 07:31:17.239656 2026] [proxy:error] [pid 229246:tid 229433] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:17.239726 2026] [proxy_http:error] [pid 229246:tid 229433] [client 137.184.89.104:33810] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.lambiduspet.com.br/
[Tue Jul 21 07:31:17.240242 2026] [proxy:error] [pid 229246:tid 229433] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:17.240276 2026] [proxy_http:error] [pid 229246:tid 229433] [client 137.184.89.104:33810] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.lambiduspet.com.br/
[Tue Jul 21 07:31:17.412276 2026] [security2:error] [pid 229246:tid 229429] [client 104.28.156.104:40177] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "carrosselbuique.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9KdSBMYeh5YLVG45yR6QAAAkk"]
[Tue Jul 21 07:31:17.485108 2026] [security2:error] [pid 229246:tid 229425] [client 20.206.105.145:39241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KdSBMYeh5YLVG45yR6gAAAkU"]
[Tue Jul 21 07:31:17.493519 2026] [security2:error] [pid 229246:tid 229503] [client 45.8.17.137:59769] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/tinymce/skins/lightgray/img/"] [unique_id "al9KdSBMYeh5YLVG45yR6wAAApM"]
[Tue Jul 21 07:31:17.538560 2026] [security2:error] [pid 229246:tid 229451] [client 20.197.192.193:8351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/samll.php"] [unique_id "al9KdSBMYeh5YLVG45yR7AAAAl8"]
[Tue Jul 21 07:31:17.618944 2026] [security2:error] [pid 229246:tid 229490] [client 117.251.86.144:54020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KdSBMYeh5YLVG45yR7QAAAoY"]
[Tue Jul 21 07:31:17.619076 2026] [security2:error] [pid 229246:tid 229490] [client 117.251.86.144:54020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KdSBMYeh5YLVG45yR7QAAAoY"]
[Tue Jul 21 07:31:17.727778 2026] [security2:error] [pid 229246:tid 229436] [client 20.220.225.223:23452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/pn.php"] [unique_id "al9KdSBMYeh5YLVG45yR8gAAAlA"]
[Tue Jul 21 07:31:17.781145 2026] [security2:error] [pid 229246:tid 229471] [client 20.206.105.145:7452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/file.php"] [unique_id "al9KdSBMYeh5YLVG45yR9AAAAnM"]
[Tue Jul 21 07:31:17.933379 2026] [security2:error] [pid 229246:tid 229376] [client 20.197.192.193:8324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/abcd.php"] [unique_id "al9KdSBMYeh5YLVG45yR-gAAAhQ"]
[Tue Jul 21 07:31:17.974028 2026] [proxy:error] [pid 229246:tid 229494] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:17.974071 2026] [proxy_http:error] [pid 229246:tid 229494] [client 137.184.89.104:46740] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:17.974640 2026] [proxy:error] [pid 229246:tid 229494] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:17.974661 2026] [proxy_http:error] [pid 229246:tid 229494] [client 137.184.89.104:46740] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:18.066675 2026] [security2:error] [pid 229246:tid 229416] [client 20.220.225.223:19300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/pn.php"] [unique_id "al9KdiBMYeh5YLVG45yR_AAAAjw"]
[Tue Jul 21 07:31:18.309270 2026] [security2:error] [pid 229246:tid 229449] [client 20.197.192.193:8368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/xyn.php"] [unique_id "al9KdiBMYeh5YLVG45ySAwAAAl0"]
[Tue Jul 21 07:31:18.402131 2026] [security2:error] [pid 229246:tid 229485] [client 20.220.225.223:46083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/dp.php"] [unique_id "al9KdiBMYeh5YLVG45ySBQAAAoE"]
[Tue Jul 21 07:31:18.466423 2026] [security2:error] [pid 229246:tid 229268] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KdiBMYeh5YLVG45ySCgACGhU"]
[Tue Jul 21 07:31:18.466541 2026] [security2:error] [pid 229246:tid 229382] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KdiBMYeh5YLVG45ySCgACGhU"]
[Tue Jul 21 07:31:18.483075 2026] [security2:error] [pid 229246:tid 229390] [client 45.8.17.127:21191] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/666.php"] [unique_id "al9KdiBMYeh5YLVG45ySCwAAAiI"]
[Tue Jul 21 07:31:18.507306 2026] [security2:error] [pid 229246:tid 229383] [client 20.197.192.193:8370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/byp8.php"] [unique_id "al9KdiBMYeh5YLVG45ySDAAAAhs"]
[Tue Jul 21 07:31:18.596925 2026] [security2:error] [pid 229246:tid 229422] [client 20.197.192.193:9427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/user.php"] [unique_id "al9KdiBMYeh5YLVG45ySDQAAAkI"]
[Tue Jul 21 07:31:18.720326 2026] [security2:error] [pid 229246:tid 229455] [client 139.167.225.182:57429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KdiBMYeh5YLVG45ySEAAAAmM"]
[Tue Jul 21 07:31:18.720433 2026] [security2:error] [pid 229246:tid 229455] [client 139.167.225.182:57429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KdiBMYeh5YLVG45ySEAAAAmM"]
[Tue Jul 21 07:31:18.728541 2026] [security2:error] [pid 229246:tid 229439] [client 20.220.225.223:52307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/wp-wpbak.php"] [unique_id "al9KdiBMYeh5YLVG45ySEgAAAlM"]
[Tue Jul 21 07:31:18.758969 2026] [security2:error] [pid 229246:tid 229458] [client 152.59.154.239:59472] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KdiBMYeh5YLVG45ySFAAAAmY"]
[Tue Jul 21 07:31:18.761227 2026] [security2:error] [pid 229246:tid 229458] [client 152.59.154.239:59472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KdiBMYeh5YLVG45ySFAAAAmY"]
[Tue Jul 21 07:31:18.816674 2026] [core:error] [pid 229246:tid 229322] [remote 52.167.144.191:36453] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:31:18.816701 2026] [core:error] [pid 229246:tid 229322] [remote 52.167.144.191:36453] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:31:18.828682 2026] [security2:error] [pid 229246:tid 229388] [client 20.220.225.223:6831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/2x.php"] [unique_id "al9KdiBMYeh5YLVG45ySFwAAAiA"]
[Tue Jul 21 07:31:18.833886 2026] [security2:error] [pid 229246:tid 229503] [client 20.206.105.145:7711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/aa2.php"] [unique_id "al9KdiBMYeh5YLVG45ySGAAAApM"]
[Tue Jul 21 07:31:18.858230 2026] [security2:error] [pid 229246:tid 229396] [client 20.197.192.193:8322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/ops.php"] [unique_id "al9KdiBMYeh5YLVG45ySGQAAAig"]
[Tue Jul 21 07:31:18.871646 2026] [security2:error] [pid 229246:tid 229437] [client 20.220.225.223:19683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9KdiBMYeh5YLVG45ySGgAAAlE"]
[Tue Jul 21 07:31:18.978788 2026] [security2:error] [pid 229246:tid 229288] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KdiBMYeh5YLVG45ySHwACNik"]
[Tue Jul 21 07:31:18.978900 2026] [security2:error] [pid 229246:tid 229410] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KdiBMYeh5YLVG45ySHwACNik"]
[Tue Jul 21 07:31:19.181542 2026] [security2:error] [pid 229246:tid 229331] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KdyBMYeh5YLVG45ySIgAChFQ"]
[Tue Jul 21 07:31:19.195785 2026] [security2:error] [pid 229246:tid 229387] [client 20.206.105.145:39276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/x.php"] [unique_id "al9KdyBMYeh5YLVG45ySIwAAAh8"]
[Tue Jul 21 07:31:19.205276 2026] [security2:error] [pid 229246:tid 229459] [client 103.162.129.114:55988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KdyBMYeh5YLVG45ySJAAAAmc"]
[Tue Jul 21 07:31:19.205393 2026] [security2:error] [pid 229246:tid 229459] [client 103.162.129.114:55988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KdyBMYeh5YLVG45ySJAAAAmc"]
[Tue Jul 21 07:31:19.208525 2026] [security2:error] [pid 229246:tid 229327] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KdyBMYeh5YLVG45ySJQACZVA"]
[Tue Jul 21 07:31:19.229539 2026] [security2:error] [pid 229246:tid 229365] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/dp.php"] [unique_id "al9KdyBMYeh5YLVG45ySJgACXXY"]
[Tue Jul 21 07:31:19.252129 2026] [security2:error] [pid 229246:tid 229299] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/old.php"] [unique_id "al9KdyBMYeh5YLVG45ySKAACNDQ"]
[Tue Jul 21 07:31:19.269731 2026] [security2:error] [pid 229246:tid 229427] [client 20.220.225.223:52191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/wp-wpbak.php"] [unique_id "al9KdyBMYeh5YLVG45ySKwAAAkc"]
[Tue Jul 21 07:31:19.271416 2026] [security2:error] [pid 229246:tid 229276] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/ms-new.php"] [unique_id "al9KdyBMYeh5YLVG45ySLAACbx0"]
[Tue Jul 21 07:31:19.284965 2026] [security2:error] [pid 229246:tid 229317] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/track.php"] [unique_id "al9KdyBMYeh5YLVG45ySLQACXkY"]
[Tue Jul 21 07:31:19.298098 2026] [security2:error] [pid 229246:tid 229259] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/2352356666.php"] [unique_id "al9KdyBMYeh5YLVG45ySLgACIgw"]
[Tue Jul 21 07:31:19.304196 2026] [security2:error] [pid 229246:tid 229383] [client 20.52.136.55:1586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/a1.php"] [unique_id "al9KdyBMYeh5YLVG45ySLwAAAhs"]
[Tue Jul 21 07:31:19.319574 2026] [security2:error] [pid 229246:tid 229296] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/pn.php"] [unique_id "al9KdyBMYeh5YLVG45ySMAACazE"]
[Tue Jul 21 07:31:19.336740 2026] [security2:error] [pid 229246:tid 229329] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/wp-wpbak.php"] [unique_id "al9KdyBMYeh5YLVG45ySMwACSFI"]
[Tue Jul 21 07:31:19.347892 2026] [security2:error] [pid 229246:tid 229492] [client 122.186.204.214:55672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KdyBMYeh5YLVG45ySNgAAAog"]
[Tue Jul 21 07:31:19.347994 2026] [security2:error] [pid 229246:tid 229492] [client 122.186.204.214:55672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KdyBMYeh5YLVG45ySNgAAAog"]
[Tue Jul 21 07:31:19.352377 2026] [security2:error] [pid 229246:tid 229291] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/dr.php"] [unique_id "al9KdyBMYeh5YLVG45ySNwACRCw"]
[Tue Jul 21 07:31:19.373583 2026] [security2:error] [pid 229246:tid 229280] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/2x.php"] [unique_id "al9KdyBMYeh5YLVG45ySOQACMCE"]
[Tue Jul 21 07:31:19.388988 2026] [security2:error] [pid 229246:tid 229248] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/kq1.php"] [unique_id "al9KdyBMYeh5YLVG45ySOgACNQE"]
[Tue Jul 21 07:31:19.401578 2026] [security2:error] [pid 229246:tid 229367] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/zzz.php"] [unique_id "al9KdyBMYeh5YLVG45ySOwACQHg"]
[Tue Jul 21 07:31:19.417059 2026] [security2:error] [pid 229246:tid 229340] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/wicked.php"] [unique_id "al9KdyBMYeh5YLVG45ySPAACe10"]
[Tue Jul 21 07:31:19.431287 2026] [security2:error] [pid 229246:tid 229289] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/edit.php"] [unique_id "al9KdyBMYeh5YLVG45ySPQACYyo"]
[Tue Jul 21 07:31:19.455088 2026] [security2:error] [pid 229246:tid 229345] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/kua.php"] [unique_id "al9KdyBMYeh5YLVG45ySQAACeWI"]
[Tue Jul 21 07:31:19.475191 2026] [security2:error] [pid 229246:tid 229440] [client 45.8.17.59:47361] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "al9KdyBMYeh5YLVG45ySQgAAAlQ"]
[Tue Jul 21 07:31:19.477052 2026] [security2:error] [pid 229246:tid 229350] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/ez.php"] [unique_id "al9KdyBMYeh5YLVG45ySQwACSWc"]
[Tue Jul 21 07:31:19.492637 2026] [security2:error] [pid 229246:tid 229269] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/fz.php"] [unique_id "al9KdyBMYeh5YLVG45ySRAACIxY"]
[Tue Jul 21 07:31:19.510682 2026] [security2:error] [pid 229246:tid 229346] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/la.php"] [unique_id "al9KdyBMYeh5YLVG45ySRQACJmM"]
[Tue Jul 21 07:31:19.514269 2026] [security2:error] [pid 229246:tid 229388] [client 20.206.105.145:7577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/ccou.php"] [unique_id "al9KdyBMYeh5YLVG45ySRgAAAiA"]
[Tue Jul 21 07:31:19.519300 2026] [security2:error] [pid 229246:tid 229503] [client 20.197.192.193:8328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/term.php"] [unique_id "al9KdyBMYeh5YLVG45ySRwAAApM"]
[Tue Jul 21 07:31:19.529783 2026] [security2:error] [pid 229246:tid 229353] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/nhvoanpl.php"] [unique_id "al9KdyBMYeh5YLVG45ySSAACKGo"]
[Tue Jul 21 07:31:19.549763 2026] [security2:error] [pid 229246:tid 229333] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/inso.php"] [unique_id "al9KdyBMYeh5YLVG45ySSQACf1Y"]
[Tue Jul 21 07:31:19.565918 2026] [security2:error] [pid 229246:tid 229370] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/wpx.php"] [unique_id "al9KdyBMYeh5YLVG45ySSgACcns"]
[Tue Jul 21 07:31:19.582234 2026] [security2:error] [pid 229246:tid 229342] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/berlin.php"] [unique_id "al9KdyBMYeh5YLVG45ySSwACUF8"]
[Tue Jul 21 07:31:19.608669 2026] [security2:error] [pid 229246:tid 229261] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/billur.php"] [unique_id "al9KdyBMYeh5YLVG45ySTAACfA4"]
[Tue Jul 21 07:31:19.631759 2026] [security2:error] [pid 229246:tid 229252] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/mimpi.php"] [unique_id "al9KdyBMYeh5YLVG45ySTgACdgU"]
[Tue Jul 21 07:31:19.646391 2026] [security2:error] [pid 229246:tid 229312] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/dp.php"] [unique_id "al9KdyBMYeh5YLVG45ySTwACOEE"]
[Tue Jul 21 07:31:19.667297 2026] [security2:error] [pid 229246:tid 229352] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/bootstrap.php"] [unique_id "al9KdyBMYeh5YLVG45ySUQACNmk"]
[Tue Jul 21 07:31:19.685417 2026] [security2:error] [pid 229246:tid 229274] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/wp-editor.php"] [unique_id "al9KdyBMYeh5YLVG45ySUgACPBs"]
[Tue Jul 21 07:31:19.706868 2026] [security2:error] [pid 229246:tid 229339] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/cro.php"] [unique_id "al9KdyBMYeh5YLVG45ySUwACW1w"]
[Tue Jul 21 07:31:19.728175 2026] [security2:error] [pid 229246:tid 229298] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/cron-tab.php"] [unique_id "al9KdyBMYeh5YLVG45ySVAAChTM"]
[Tue Jul 21 07:31:19.743795 2026] [security2:error] [pid 229246:tid 229348] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/koiy.php"] [unique_id "al9KdyBMYeh5YLVG45ySVQACLGU"]
[Tue Jul 21 07:31:19.759122 2026] [security2:error] [pid 229246:tid 229267] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/hp2.php"] [unique_id "al9KdyBMYeh5YLVG45ySVgAChBQ"]
[Tue Jul 21 07:31:19.772164 2026] [security2:error] [pid 229246:tid 229282] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/hp3.php"] [unique_id "al9KdyBMYeh5YLVG45ySWAACkiM"]
[Tue Jul 21 07:31:19.787564 2026] [security2:error] [pid 229246:tid 229328] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/aa1.php"] [unique_id "al9KdyBMYeh5YLVG45ySWgACfVE"]
[Tue Jul 21 07:31:19.809854 2026] [security2:error] [pid 229246:tid 229361] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/acew67.php"] [unique_id "al9KdyBMYeh5YLVG45ySXQACXXI"]
[Tue Jul 21 07:31:19.827315 2026] [security2:error] [pid 229246:tid 229247] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/bscclapb.php"] [unique_id "al9KdyBMYeh5YLVG45ySXgACNAA"]
[Tue Jul 21 07:31:19.850281 2026] [security2:error] [pid 229246:tid 229334] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/else1.php"] [unique_id "al9KdyBMYeh5YLVG45ySYAACS1c"]
[Tue Jul 21 07:31:19.867289 2026] [security2:error] [pid 229246:tid 229308] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/tkikikoko.php"] [unique_id "al9KdyBMYeh5YLVG45ySYgACgT0"]
[Tue Jul 21 07:31:19.893937 2026] [security2:error] [pid 229246:tid 229256] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/wp-Blogs.php"] [unique_id "al9KdyBMYeh5YLVG45ySYwACIgk"]
[Tue Jul 21 07:31:19.921465 2026] [security2:error] [pid 229246:tid 229311] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/wp-css.php"] [unique_id "al9KdyBMYeh5YLVG45ySZQACG0A"]
[Tue Jul 21 07:31:19.946752 2026] [security2:error] [pid 229246:tid 229335] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/wp-explorer.php"] [unique_id "al9KdyBMYeh5YLVG45ySZgACSFg"]
[Tue Jul 21 07:31:19.959177 2026] [security2:error] [pid 229246:tid 229320] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/akismet.php"] [unique_id "al9KdyBMYeh5YLVG45ySZwACiEk"]
[Tue Jul 21 07:31:19.968650 2026] [security2:error] [pid 229246:tid 229451] [client 193.36.225.72:53249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KdyBMYeh5YLVG45ySaAAAAl8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:19.981647 2026] [security2:error] [pid 229246:tid 229357] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/ace2.php"] [unique_id "al9KdyBMYeh5YLVG45ySawACTW4"]
[Tue Jul 21 07:31:19.997190 2026] [security2:error] [pid 229246:tid 229284] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/ms.php"] [unique_id "al9KdyBMYeh5YLVG45ySbQACeyU"]
[Tue Jul 21 07:31:20.007129 2026] [security2:error] [pid 229246:tid 229477] [client 20.151.10.161:50894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-content/index.php"] [unique_id "al9KeCBMYeh5YLVG45ySbgAAAnk"]
[Tue Jul 21 07:31:20.169374 2026] [security2:error] [pid 229246:tid 229384] [client 103.106.20.201:63775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeCBMYeh5YLVG45yScwAAAhw"]
[Tue Jul 21 07:31:20.170126 2026] [security2:error] [pid 229246:tid 229384] [client 103.106.20.201:63775] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeCBMYeh5YLVG45yScwAAAhw"]
[Tue Jul 21 07:31:20.320446 2026] [security2:error] [pid 229246:tid 229396] [client 20.206.105.145:7791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/dr.php"] [unique_id "al9KeCBMYeh5YLVG45ySeAAAAig"]
[Tue Jul 21 07:31:20.346489 2026] [security2:error] [pid 229246:tid 229330] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KdyBMYeh5YLVG45ySNQACP1M"]
[Tue Jul 21 07:31:20.346653 2026] [security2:error] [pid 229246:tid 229419] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KdyBMYeh5YLVG45ySNQACP1M"]
[Tue Jul 21 07:31:20.481629 2026] [security2:error] [pid 229246:tid 229257] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KeCBMYeh5YLVG45ySfAACYAo"]
[Tue Jul 21 07:31:20.481772 2026] [security2:error] [pid 229246:tid 229452] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KeCBMYeh5YLVG45ySfAACYAo"]
[Tue Jul 21 07:31:20.609295 2026] [security2:error] [pid 229246:tid 229412] [client 20.197.192.193:9417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/ah25.php"] [unique_id "al9KeCBMYeh5YLVG45ySgAAAAjg"]
[Tue Jul 21 07:31:20.780778 2026] [security2:error] [pid 229246:tid 229410] [client 45.8.17.60:58221] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/l10n/wp-conflg.php"] [unique_id "al9KeCBMYeh5YLVG45ySggAAAjY"]
[Tue Jul 21 07:31:21.075709 2026] [security2:error] [pid 229246:tid 229463] [client 20.206.105.145:39288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/j260624_13.php"] [unique_id "al9KeSBMYeh5YLVG45ySjwAAAms"]
[Tue Jul 21 07:31:21.164484 2026] [security2:error] [pid 229246:tid 229451] [client 20.220.225.223:19667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/dr.php"] [unique_id "al9KeSBMYeh5YLVG45ySkAAAAl8"]
[Tue Jul 21 07:31:21.205429 2026] [security2:error] [pid 229246:tid 229420] [client 20.220.225.223:8096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/kq1.php"] [unique_id "al9KeSBMYeh5YLVG45ySkgAAAkA"]
[Tue Jul 21 07:31:21.374495 2026] [security2:error] [pid 229246:tid 229458] [client 20.197.192.193:8379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/8.php"] [unique_id "al9KeSBMYeh5YLVG45ySkwAAAmY"]
[Tue Jul 21 07:31:21.382412 2026] [security2:error] [pid 229246:tid 229428] [client 173.24.185.52:54950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KeSBMYeh5YLVG45ySlAAAAkg"]
[Tue Jul 21 07:31:21.387370 2026] [security2:error] [pid 229246:tid 229428] [client 173.24.185.52:54950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KeSBMYeh5YLVG45ySlAAAAkg"]
[Tue Jul 21 07:31:21.435869 2026] [security2:error] [pid 229246:tid 229484] [client 154.192.233.199:59862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeSBMYeh5YLVG45ySmAAAAoA"]
[Tue Jul 21 07:31:21.435968 2026] [security2:error] [pid 229246:tid 229484] [client 154.192.233.199:59862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeSBMYeh5YLVG45ySmAAAAoA"]
[Tue Jul 21 07:31:21.550507 2026] [security2:error] [pid 229246:tid 229402] [client 175.45.70.82:65473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeSBMYeh5YLVG45ySmwAAAi4"]
[Tue Jul 21 07:31:21.550647 2026] [security2:error] [pid 229246:tid 229402] [client 175.45.70.82:65473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeSBMYeh5YLVG45ySmwAAAi4"]
[Tue Jul 21 07:31:21.634986 2026] [security2:error] [pid 229246:tid 229399] [client 20.197.192.193:8352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/red.php"] [unique_id "al9KeSBMYeh5YLVG45ySoQAAAis"]
[Tue Jul 21 07:31:21.661563 2026] [security2:error] [pid 229246:tid 229272] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KeSBMYeh5YLVG45ySogACThk"]
[Tue Jul 21 07:31:21.661689 2026] [security2:error] [pid 229246:tid 229434] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KeSBMYeh5YLVG45ySogACThk"]
[Tue Jul 21 07:31:21.840924 2026] [security2:error] [pid 229246:tid 229263] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeSBMYeh5YLVG45ySowACIBA"]
[Tue Jul 21 07:31:21.841131 2026] [security2:error] [pid 229246:tid 229388] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeSBMYeh5YLVG45ySowACIBA"]
[Tue Jul 21 07:31:21.847166 2026] [security2:error] [pid 229246:tid 229422] [client 20.220.225.223:63864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/dr.php"] [unique_id "al9KeSBMYeh5YLVG45ySpAAAAkI"]
[Tue Jul 21 07:31:22.038650 2026] [security2:error] [pid 229246:tid 229387] [client 20.206.105.145:54555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/file31.php"] [unique_id "al9KeiBMYeh5YLVG45ySqQAAAh8"]
[Tue Jul 21 07:31:22.277832 2026] [proxy:error] [pid 229246:tid 229502] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:22.277931 2026] [proxy_http:error] [pid 229246:tid 229502] [client 137.184.89.104:46858] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.lambiduspet.com.br/
[Tue Jul 21 07:31:22.278979 2026] [proxy:error] [pid 229246:tid 229502] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:22.279029 2026] [proxy_http:error] [pid 229246:tid 229502] [client 137.184.89.104:46858] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.lambiduspet.com.br/
[Tue Jul 21 07:31:22.361982 2026] [security2:error] [pid 229246:tid 229474] [client 103.174.34.15:58019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeiBMYeh5YLVG45yStQAAAnY"]
[Tue Jul 21 07:31:22.362108 2026] [security2:error] [pid 229246:tid 229474] [client 103.174.34.15:58019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeiBMYeh5YLVG45yStQAAAnY"]
[Tue Jul 21 07:31:22.411562 2026] [security2:error] [pid 229246:tid 229424] [client 20.197.192.193:9460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/fffm.php"] [unique_id "al9KeiBMYeh5YLVG45ySuAAAAkQ"]
[Tue Jul 21 07:31:22.579568 2026] [security2:error] [pid 229246:tid 229382] [client 45.8.17.49:64587] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/user.php"] [unique_id "al9KeiBMYeh5YLVG45ySvAAAAho"]
[Tue Jul 21 07:31:22.585220 2026] [security2:error] [pid 229246:tid 229331] [remote 45.79.123.44:51838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/wp-login.php"] [unique_id "al9KeiBMYeh5YLVG45ySvQACflQ"]
[Tue Jul 21 07:31:22.757399 2026] [security2:error] [pid 229246:tid 229381] [client 122.129.67.13:60422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9KeiBMYeh5YLVG45ySwQAAAhk"]
[Tue Jul 21 07:31:22.936569 2026] [security2:error] [pid 229246:tid 229436] [client 20.197.192.193:8363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/ftde.php"] [unique_id "al9KeiBMYeh5YLVG45ySyAAAAlA"]
[Tue Jul 21 07:31:22.965382 2026] [security2:error] [pid 229246:tid 229378] [client 20.206.105.145:39237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/d62.php"] [unique_id "al9KeiBMYeh5YLVG45ySyQAAAhY"]
[Tue Jul 21 07:31:23.273168 2026] [security2:error] [pid 229246:tid 229488] [client 20.197.192.193:9569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/yup.php"] [unique_id "al9KeyBMYeh5YLVG45ySzgAAAoQ"]
[Tue Jul 21 07:31:23.481990 2026] [security2:error] [pid 229246:tid 229486] [client 20.197.192.193:8346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/jj.php"] [unique_id "al9KeyBMYeh5YLVG45yS1wAAAoI"]
[Tue Jul 21 07:31:23.559801 2026] [security2:error] [pid 229246:tid 229450] [client 45.251.232.145:63003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeyBMYeh5YLVG45yS2QAAAl4"]
[Tue Jul 21 07:31:23.559960 2026] [security2:error] [pid 229246:tid 229450] [client 45.251.232.145:63003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeyBMYeh5YLVG45yS2QAAAl4"]
[Tue Jul 21 07:31:23.705006 2026] [security2:error] [pid 229246:tid 229388] [client 45.8.19.164:55247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luanaarruda.com"] [uri "/wp-login.php"] [unique_id "al9KeyBMYeh5YLVG45yS3wAAAiA"]
[Tue Jul 21 07:31:24.063803 2026] [security2:error] [pid 229246:tid 229464] [client 20.197.192.193:8360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/dragonshell.php"] [unique_id "al9KfCBMYeh5YLVG45yS6gAAAmw"]
[Tue Jul 21 07:31:24.129119 2026] [security2:error] [pid 229246:tid 229434] [client 20.206.105.145:7752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/file6.php"] [unique_id "al9KfCBMYeh5YLVG45yS7gAAAk4"]
[Tue Jul 21 07:31:24.185987 2026] [security2:error] [pid 229246:tid 229378] [client 45.8.17.110:40857] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/nextpage/"] [unique_id "al9KfCBMYeh5YLVG45yS7wAAAhY"]
[Tue Jul 21 07:31:24.228324 2026] [security2:error] [pid 229246:tid 229364] [remote 49.12.216.176:38812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.216.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shop-officialstore.com"] [uri "/wp-login.php"] [unique_id "al9KfCBMYeh5YLVG45yS8AACYnU"]
[Tue Jul 21 07:31:24.324264 2026] [security2:error] [pid 229246:tid 229490] [client 172.245.102.45:29177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KfCBMYeh5YLVG45yS9AAAAoY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:24.368373 2026] [security2:error] [pid 229246:tid 229329] [remote 46.105.28.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.28.105.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/wp-login.php"] [unique_id "al9KeyBMYeh5YLVG45yS0QACH1I"]
[Tue Jul 21 07:31:24.730441 2026] [security2:error] [pid 229246:tid 229450] [client 20.151.10.161:57369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/zoro.php"] [unique_id "al9KfCBMYeh5YLVG45yS_AAAAl4"]
[Tue Jul 21 07:31:24.763625 2026] [security2:error] [pid 229246:tid 229479] [client 20.197.192.193:9421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-mt.php"] [unique_id "al9KfCBMYeh5YLVG45yTAAAAAns"]
[Tue Jul 21 07:31:24.909252 2026] [security2:error] [pid 229246:tid 229400] [client 117.217.38.194:52392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KfCBMYeh5YLVG45yTAgAAAiw"]
[Tue Jul 21 07:31:24.909385 2026] [security2:error] [pid 229246:tid 229400] [client 117.217.38.194:52392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KfCBMYeh5YLVG45yTAgAAAiw"]
[Tue Jul 21 07:31:25.084501 2026] [security2:error] [pid 229246:tid 229482] [client 45.8.17.112:63535] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/code/"] [unique_id "al9KfSBMYeh5YLVG45yTBwAAAn4"]
[Tue Jul 21 07:31:25.260582 2026] [security2:error] [pid 229246:tid 229440] [client 20.206.105.145:7465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/file15.php"] [unique_id "al9KfSBMYeh5YLVG45yTCwAAAlQ"]
[Tue Jul 21 07:31:25.384896 2026] [security2:error] [pid 229246:tid 229407] [client 20.197.192.193:8373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/ww.php"] [unique_id "al9KfSBMYeh5YLVG45yTDQAAAjM"]
[Tue Jul 21 07:31:25.627807 2026] [security2:error] [pid 229246:tid 229428] [client 173.252.95.30:57344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9KfSBMYeh5YLVG45yTFQAAAkg"]
[Tue Jul 21 07:31:25.645544 2026] [security2:error] [pid 229246:tid 229449] [client 20.197.192.193:8353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/cron.php"] [unique_id "al9KfSBMYeh5YLVG45yTFgAAAl0"]
[Tue Jul 21 07:31:25.698378 2026] [security2:error] [pid 229246:tid 229267] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KfSBMYeh5YLVG45yTFwACFhQ"]
[Tue Jul 21 07:31:25.698561 2026] [security2:error] [pid 229246:tid 229378] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KfSBMYeh5YLVG45yTFwACFhQ"]
[Tue Jul 21 07:31:26.070489 2026] [security2:error] [pid 229246:tid 229429] [client 20.220.225.223:8914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/mimpi.php"] [unique_id "al9KfiBMYeh5YLVG45yTJAAAAkk"]
[Tue Jul 21 07:31:26.096371 2026] [security2:error] [pid 229246:tid 229403] [client 20.151.10.161:51321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/admin.php"] [unique_id "al9KfiBMYeh5YLVG45yTJgAAAi8"]
[Tue Jul 21 07:31:26.100307 2026] [security2:error] [pid 229246:tid 229479] [client 20.52.136.55:1766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/w.php"] [unique_id "al9KfiBMYeh5YLVG45yTJwAAAns"]
[Tue Jul 21 07:31:26.190832 2026] [security2:error] [pid 229246:tid 229455] [client 45.8.17.115:60399] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentytwo/assets/fonts/"] [unique_id "al9KfiBMYeh5YLVG45yTKAAAAmM"]
[Tue Jul 21 07:31:26.541471 2026] [security2:error] [pid 229246:tid 229308] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KfiBMYeh5YLVG45yTLQACIj0"]
[Tue Jul 21 07:31:26.541713 2026] [security2:error] [pid 229246:tid 229390] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KfiBMYeh5YLVG45yTLQACIj0"]
[Tue Jul 21 07:31:26.586582 2026] [security2:error] [pid 229246:tid 229311] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KfiBMYeh5YLVG45yTMQACJEA"]
[Tue Jul 21 07:31:26.586713 2026] [security2:error] [pid 229246:tid 229392] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KfiBMYeh5YLVG45yTMQACJEA"]
[Tue Jul 21 07:31:27.290775 2026] [security2:error] [pid 229246:tid 229463] [client 45.8.17.73:39127] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/t.php"] [unique_id "al9KfyBMYeh5YLVG45yTRAAAAms"]
[Tue Jul 21 07:31:27.450440 2026] [security2:error] [pid 229246:tid 229490] [client 62.102.148.164:48612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KfyBMYeh5YLVG45yTSQAAAoY"]
[Tue Jul 21 07:31:27.450529 2026] [security2:error] [pid 229246:tid 229490] [client 62.102.148.164:48612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KfyBMYeh5YLVG45yTSQAAAoY"]
[Tue Jul 21 07:31:27.496354 2026] [security2:error] [pid 229246:tid 229479] [client 20.220.225.223:19281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/2x.php"] [unique_id "al9KfyBMYeh5YLVG45yTSgAAAns"]
[Tue Jul 21 07:31:27.585008 2026] [security2:error] [pid 229246:tid 229457] [client 20.151.10.161:57348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/greap.php"] [unique_id "al9KfyBMYeh5YLVG45yTSwAAAmU"]
[Tue Jul 21 07:31:27.771331 2026] [security2:error] [pid 229246:tid 229382] [client 20.206.105.145:39255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ups.php"] [unique_id "al9KfyBMYeh5YLVG45yTUgAAAho"]
[Tue Jul 21 07:31:27.988315 2026] [security2:error] [pid 229246:tid 229475] [client 172.245.102.44:64857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KfyBMYeh5YLVG45yTVwAAAnc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:28.193067 2026] [security2:error] [pid 229246:tid 229399] [client 20.206.105.145:39293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/k.php"] [unique_id "al9KgCBMYeh5YLVG45yTXQAAAis"]
[Tue Jul 21 07:31:28.288945 2026] [security2:error] [pid 229246:tid 229440] [client 59.96.220.140:58668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KgCBMYeh5YLVG45yTYAAAAlQ"]
[Tue Jul 21 07:31:28.289618 2026] [security2:error] [pid 229246:tid 229440] [client 59.96.220.140:58668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KgCBMYeh5YLVG45yTYAAAAlQ"]
[Tue Jul 21 07:31:28.293295 2026] [security2:error] [pid 229246:tid 229452] [client 45.8.17.127:34763] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/html-api/chosen.php"] [unique_id "al9KgCBMYeh5YLVG45yTYQAAAmA"]
[Tue Jul 21 07:31:28.361584 2026] [security2:error] [pid 229246:tid 229502] [client 117.251.86.144:35336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KgCBMYeh5YLVG45yTZAAAApI"]
[Tue Jul 21 07:31:28.361731 2026] [security2:error] [pid 229246:tid 229502] [client 117.251.86.144:35336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KgCBMYeh5YLVG45yTZAAAApI"]
[Tue Jul 21 07:31:28.395806 2026] [security2:error] [pid 229246:tid 229454] [client 20.206.105.145:38912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/k2.php"] [unique_id "al9KgCBMYeh5YLVG45yTZQAAAmI"]
[Tue Jul 21 07:31:28.445615 2026] [security2:error] [pid 229246:tid 229437] [client 20.206.105.145:38917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/k3.php"] [unique_id "al9KgCBMYeh5YLVG45yTaQAAAlE"]
[Tue Jul 21 07:31:28.702146 2026] [security2:error] [pid 229246:tid 229427] [client 20.206.105.145:39264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/k4.php"] [unique_id "al9KgCBMYeh5YLVG45yTbQAAAkc"]
[Tue Jul 21 07:31:28.826028 2026] [security2:error] [pid 229246:tid 229410] [client 20.151.10.161:57398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/177.php"] [unique_id "al9KgCBMYeh5YLVG45yTbwAAAjY"]
[Tue Jul 21 07:31:28.993943 2026] [security2:error] [pid 229246:tid 229272] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KgCBMYeh5YLVG45yTdAACTRk"]
[Tue Jul 21 07:31:28.994139 2026] [security2:error] [pid 229246:tid 229433] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KgCBMYeh5YLVG45yTdAACTRk"]
[Tue Jul 21 07:31:29.250523 2026] [security2:error] [pid 229246:tid 229482] [client 20.197.192.193:9425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/xxx.php"] [unique_id "al9KgSBMYeh5YLVG45yTegAAAn4"]
[Tue Jul 21 07:31:29.301348 2026] [security2:error] [pid 229246:tid 229419] [client 139.167.225.182:58048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KgSBMYeh5YLVG45yTfAAAAj8"]
[Tue Jul 21 07:31:29.301512 2026] [security2:error] [pid 229246:tid 229419] [client 139.167.225.182:58048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KgSBMYeh5YLVG45yTfAAAAj8"]
[Tue Jul 21 07:31:29.474888 2026] [security2:error] [pid 229246:tid 229283] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KgSBMYeh5YLVG45yTfwACdyQ"]
[Tue Jul 21 07:31:29.475037 2026] [security2:error] [pid 229246:tid 229475] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KgSBMYeh5YLVG45yTfwACdyQ"]
[Tue Jul 21 07:31:29.596711 2026] [security2:error] [pid 229246:tid 229470] [client 45.8.17.105:52377] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/css/dist/edit-post/"] [unique_id "al9KgSBMYeh5YLVG45yTggAAAnI"]
[Tue Jul 21 07:31:29.805802 2026] [security2:error] [pid 229246:tid 229322] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KgSBMYeh5YLVG45yThwACPEs"]
[Tue Jul 21 07:31:29.805968 2026] [security2:error] [pid 229246:tid 229416] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KgSBMYeh5YLVG45yThwACPEs"]
[Tue Jul 21 07:31:29.869117 2026] [security2:error] [pid 229246:tid 229437] [client 20.220.225.223:4192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/2x.php"] [unique_id "al9KgSBMYeh5YLVG45yTiQAAAlE"]
[Tue Jul 21 07:31:29.875345 2026] [security2:error] [pid 229246:tid 229398] [client 103.162.129.114:56436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KgSBMYeh5YLVG45yTigAAAio"]
[Tue Jul 21 07:31:29.875457 2026] [security2:error] [pid 229246:tid 229398] [client 103.162.129.114:56436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KgSBMYeh5YLVG45yTigAAAio"]
[Tue Jul 21 07:31:29.885440 2026] [security2:error] [pid 229246:tid 229428] [client 20.206.105.145:7468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/jp.php"] [unique_id "al9KgSBMYeh5YLVG45yTiwAAAkg"]
[Tue Jul 21 07:31:29.914693 2026] [security2:error] [pid 229246:tid 229414] [client 20.206.105.145:38931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/k5.php"] [unique_id "al9KgSBMYeh5YLVG45yTkQAAAjo"]
[Tue Jul 21 07:31:30.045780 2026] [security2:error] [pid 229246:tid 229392] [client 122.186.204.214:56157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KgiBMYeh5YLVG45yTmwAAAiQ"]
[Tue Jul 21 07:31:30.045904 2026] [security2:error] [pid 229246:tid 229392] [client 122.186.204.214:56157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KgiBMYeh5YLVG45yTmwAAAiQ"]
[Tue Jul 21 07:31:30.176792 2026] [security2:error] [pid 229246:tid 229310] [remote 89.42.136.2:48780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.136.42.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9KgiBMYeh5YLVG45yToAACij8"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:31:30.332487 2026] [security2:error] [pid 229246:tid 229485] [client 20.197.192.193:9420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/hunter.php"] [unique_id "al9KgiBMYeh5YLVG45yTqwAAAoE"]
[Tue Jul 21 07:31:30.677134 2026] [security2:error] [pid 229246:tid 229473] [client 20.151.10.161:57450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/199.php"] [unique_id "al9KgiBMYeh5YLVG45yTsQAAAnU"]
[Tue Jul 21 07:31:30.966013 2026] [security2:error] [pid 229246:tid 229484] [client 103.106.20.201:64346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KgiBMYeh5YLVG45yTuAAAAoA"]
[Tue Jul 21 07:31:30.966141 2026] [security2:error] [pid 229246:tid 229484] [client 103.106.20.201:64346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KgiBMYeh5YLVG45yTuAAAAoA"]
[Tue Jul 21 07:31:30.983794 2026] [security2:error] [pid 229246:tid 229433] [client 45.8.17.131:53643] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/plugin/"] [unique_id "al9KgiBMYeh5YLVG45yTuQAAAk0"]
[Tue Jul 21 07:31:31.050806 2026] [security2:error] [pid 229246:tid 229291] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KgyBMYeh5YLVG45yTugACZSw"]
[Tue Jul 21 07:31:31.050943 2026] [security2:error] [pid 229246:tid 229457] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KgyBMYeh5YLVG45yTugACZSw"]
[Tue Jul 21 07:31:31.454502 2026] [security2:error] [pid 229246:tid 229500] [client 20.197.192.193:9456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/we.php"] [unique_id "al9KgyBMYeh5YLVG45yTywAAApA"]
[Tue Jul 21 07:31:31.988040 2026] [security2:error] [pid 229246:tid 229408] [client 173.24.185.52:55422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KgyBMYeh5YLVG45yT2AAAAjQ"]
[Tue Jul 21 07:31:31.988182 2026] [security2:error] [pid 229246:tid 229408] [client 173.24.185.52:55422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KgyBMYeh5YLVG45yT2AAAAjQ"]
[Tue Jul 21 07:31:31.992129 2026] [security2:error] [pid 229246:tid 229473] [client 20.206.105.145:7417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/f35.php"] [unique_id "al9KgyBMYeh5YLVG45yT2QAAAnU"]
[Tue Jul 21 07:31:32.061603 2026] [security2:error] [pid 229246:tid 229399] [client 154.192.233.199:60519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhCBMYeh5YLVG45yT2wAAAis"]
[Tue Jul 21 07:31:32.061726 2026] [security2:error] [pid 229246:tid 229399] [client 154.192.233.199:60519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhCBMYeh5YLVG45yT2wAAAis"]
[Tue Jul 21 07:31:32.095151 2026] [security2:error] [pid 229246:tid 229391] [client 20.220.225.223:56473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/kq1.php"] [unique_id "al9KhCBMYeh5YLVG45yT3AAAAiM"]
[Tue Jul 21 07:31:32.133593 2026] [security2:error] [pid 229246:tid 229499] [client 20.151.10.161:58006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/file52.php"] [unique_id "al9KhCBMYeh5YLVG45yT3wAAAo8"]
[Tue Jul 21 07:31:32.286199 2026] [security2:error] [pid 229246:tid 229474] [client 20.220.225.223:8068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/zzz.php"] [unique_id "al9KhCBMYeh5YLVG45yT4QAAAnY"]
[Tue Jul 21 07:31:32.334160 2026] [security2:error] [pid 229246:tid 229419] [client 74.7.241.160:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "vivafinanceiras.com.br"] [uri "/index.php"] [unique_id "al9KgyBMYeh5YLVG45yTxAAAAj8"]
[Tue Jul 21 07:31:32.335222 2026] [security2:error] [pid 229246:tid 229429] [client 74.7.241.160:45264] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "vivafinanceiras.com.br"] [uri "/robots.txt"] [unique_id "al9KgyBMYeh5YLVG45yTwgACSWc"]
[Tue Jul 21 07:31:32.348829 2026] [security2:error] [pid 229246:tid 229444] [client 175.45.70.82:49594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhCBMYeh5YLVG45yT4wAAAlg"]
[Tue Jul 21 07:31:32.348945 2026] [security2:error] [pid 229246:tid 229444] [client 175.45.70.82:49594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhCBMYeh5YLVG45yT4wAAAlg"]
[Tue Jul 21 07:31:32.360945 2026] [security2:error] [pid 229246:tid 229339] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhCBMYeh5YLVG45yT5AACRFw"]
[Tue Jul 21 07:31:32.361134 2026] [security2:error] [pid 229246:tid 229424] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhCBMYeh5YLVG45yT5AACRFw"]
[Tue Jul 21 07:31:32.369318 2026] [security2:error] [pid 229246:tid 229411] [client 82.102.28.107:45014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KhCBMYeh5YLVG45yT5QAAAjc"]
[Tue Jul 21 07:31:32.369390 2026] [security2:error] [pid 229246:tid 229411] [client 82.102.28.107:45014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KhCBMYeh5YLVG45yT5QAAAjc"]
[Tue Jul 21 07:31:32.482489 2026] [security2:error] [pid 229246:tid 229371] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KhCBMYeh5YLVG45yT6gACRnw"]
[Tue Jul 21 07:31:32.482714 2026] [security2:error] [pid 229246:tid 229426] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KhCBMYeh5YLVG45yT6gACRnw"]
[Tue Jul 21 07:31:32.801155 2026] [security2:error] [pid 229246:tid 229410] [client 172.245.102.46:26807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KhCBMYeh5YLVG45yT7AAAAjY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:32.980740 2026] [security2:error] [pid 229246:tid 229454] [client 20.220.225.223:19658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/kq1.php"] [unique_id "al9KhCBMYeh5YLVG45yT9AAAAmI"]
[Tue Jul 21 07:31:33.146725 2026] [security2:error] [pid 229246:tid 229448] [client 103.174.34.15:58519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhSBMYeh5YLVG45yT-QAAAlw"]
[Tue Jul 21 07:31:33.146934 2026] [security2:error] [pid 229246:tid 229448] [client 103.174.34.15:58519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhSBMYeh5YLVG45yT-QAAAlw"]
[Tue Jul 21 07:31:33.475122 2026] [security2:error] [pid 229246:tid 229490] [client 82.102.28.107:60766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9KhSBMYeh5YLVG45yUAgAAAoY"]
[Tue Jul 21 07:31:33.475218 2026] [security2:error] [pid 229246:tid 229490] [client 82.102.28.107:60766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9KhSBMYeh5YLVG45yUAgAAAoY"]
[Tue Jul 21 07:31:33.536727 2026] [security2:error] [pid 229246:tid 229458] [client 20.197.192.193:9446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/phpinfo.php1"] [unique_id "al9KhSBMYeh5YLVG45yUBQAAAmY"]
[Tue Jul 21 07:31:33.716246 2026] [security2:error] [pid 229246:tid 229444] [client 20.151.10.161:51290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/122.php"] [unique_id "al9KhSBMYeh5YLVG45yUDQAAAlg"]
[Tue Jul 21 07:31:34.014310 2026] [security2:error] [pid 229246:tid 229401] [client 45.251.232.145:63516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhiBMYeh5YLVG45yUFgAAAi0"]
[Tue Jul 21 07:31:34.014423 2026] [security2:error] [pid 229246:tid 229401] [client 45.251.232.145:63516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhiBMYeh5YLVG45yUFgAAAi0"]
[Tue Jul 21 07:31:34.139955 2026] [security2:error] [pid 229246:tid 229481] [client 152.59.154.239:59927] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KgyBMYeh5YLVG45yT0gAAAn0"]
[Tue Jul 21 07:31:34.140162 2026] [security2:error] [pid 229246:tid 229481] [client 152.59.154.239:59927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KgyBMYeh5YLVG45yT0gAAAn0"]
[Tue Jul 21 07:31:34.166738 2026] [security2:error] [pid 229246:tid 229403] [client 20.220.225.223:4172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/zzz.php"] [unique_id "al9KhiBMYeh5YLVG45yUGQAAAi8"]
[Tue Jul 21 07:31:34.419109 2026] [security2:error] [pid 229246:tid 229398] [client 20.220.225.223:6797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/wicked.php"] [unique_id "al9KhiBMYeh5YLVG45yUIAAAAio"]
[Tue Jul 21 07:31:34.679370 2026] [security2:error] [pid 229246:tid 229437] [client 45.8.17.64:48137] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/tinymce/langs/"] [unique_id "al9KhiBMYeh5YLVG45yUJQAAAlE"]
[Tue Jul 21 07:31:34.805294 2026] [security2:error] [pid 229246:tid 229475] [client 122.129.67.13:60991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9KhiBMYeh5YLVG45yUJgAAAnc"]
[Tue Jul 21 07:31:35.246589 2026] [security2:error] [pid 229246:tid 229494] [client 20.151.10.161:50909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/green1.php"] [unique_id "al9KhyBMYeh5YLVG45yUMwAAAoo"]
[Tue Jul 21 07:31:35.268777 2026] [security2:error] [pid 229246:tid 229249] [remote 134.209.147.209:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.147.209.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9KhyBMYeh5YLVG45yUNAACgAI"]
[Tue Jul 21 07:31:35.418150 2026] [security2:error] [pid 229246:tid 229420] [client 117.217.38.194:52806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhyBMYeh5YLVG45yUNgAAAkA"]
[Tue Jul 21 07:31:35.418262 2026] [security2:error] [pid 229246:tid 229420] [client 117.217.38.194:52806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhyBMYeh5YLVG45yUNgAAAkA"]
[Tue Jul 21 07:31:35.582983 2026] [security2:error] [pid 229246:tid 229318] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KhyBMYeh5YLVG45yUPQACSUc"]
[Tue Jul 21 07:31:35.583154 2026] [security2:error] [pid 229246:tid 229429] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KhyBMYeh5YLVG45yUPQACSUc"]
[Tue Jul 21 07:31:35.631165 2026] [security2:error] [pid 229246:tid 229360] [remote 72.167.132.114:59628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9KhyBMYeh5YLVG45yUPgAChHE"]
[Tue Jul 21 07:31:35.683968 2026] [security2:error] [pid 229246:tid 229471] [client 45.8.17.63:62887] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/query-pagination-previous/"] [unique_id "al9KhyBMYeh5YLVG45yUQAAAAnM"]
[Tue Jul 21 07:31:35.747219 2026] [security2:error] [pid 229246:tid 229481] [client 20.52.136.55:1777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/wp-good.php"] [unique_id "al9KhyBMYeh5YLVG45yUQQAAAn0"]
[Tue Jul 21 07:31:35.769017 2026] [security2:error] [pid 229246:tid 229410] [client 20.220.225.223:8127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/edit.php"] [unique_id "al9KhyBMYeh5YLVG45yUQgAAAjY"]
[Tue Jul 21 07:31:36.147725 2026] [security2:error] [pid 229246:tid 229502] [client 74.7.228.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "lucasmorgado1781638745686.0721679.meusitehostgator.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9KiCBMYeh5YLVG45yUSAACkkg"]
[Tue Jul 21 07:31:36.259866 2026] [security2:error] [pid 229246:tid 229325] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KiCBMYeh5YLVG45yUSgACNU4"]
[Tue Jul 21 07:31:36.260004 2026] [security2:error] [pid 229246:tid 229409] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KiCBMYeh5YLVG45yUSgACNU4"]
[Tue Jul 21 07:31:36.467603 2026] [security2:error] [pid 229246:tid 229384] [client 20.206.105.145:7463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-load.php"] [unique_id "al9KiCBMYeh5YLVG45yUSwAAAhw"]
[Tue Jul 21 07:31:36.935670 2026] [security2:error] [pid 229246:tid 229306] [remote 42.200.84.61:39992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "archrender.com.br"] [uri "/wp-login.php"] [unique_id "al9KiCBMYeh5YLVG45yUXgACOjs"]
[Tue Jul 21 07:31:37.071290 2026] [security2:error] [pid 229246:tid 229259] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KiSBMYeh5YLVG45yUaQACQAw"]
[Tue Jul 21 07:31:37.071451 2026] [security2:error] [pid 229246:tid 229420] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KiSBMYeh5YLVG45yUaQACQAw"]
[Tue Jul 21 07:31:37.317965 2026] [security2:error] [pid 229246:tid 229248] [remote 72.167.132.114:59632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "volyoaudiobooks.com"] [uri "/wp-login.php"] [unique_id "al9KiSBMYeh5YLVG45yUcAACgAE"]
[Tue Jul 21 07:31:37.359098 2026] [security2:error] [pid 229246:tid 229466] [client 20.220.225.223:31177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KiSBMYeh5YLVG45yUcQAAAm4"]
[Tue Jul 21 07:31:37.474592 2026] [security2:error] [pid 229246:tid 229450] [client 193.36.225.10:35867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KiSBMYeh5YLVG45yUdAAAAl4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:37.587231 2026] [security2:error] [pid 229246:tid 229502] [client 20.151.10.161:50882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/biufile.php"] [unique_id "al9KiSBMYeh5YLVG45yUeQAAApI"]
[Tue Jul 21 07:31:37.714381 2026] [security2:error] [pid 229246:tid 229487] [client 20.206.105.145:39278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/w.php"] [unique_id "al9KiSBMYeh5YLVG45yUfAAAAoM"]
[Tue Jul 21 07:31:38.089415 2026] [security2:error] [pid 229246:tid 229412] [client 45.8.17.73:27959] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Requests/src/Auth/"] [unique_id "al9KiiBMYeh5YLVG45yUgwAAAjg"]
[Tue Jul 21 07:31:38.578827 2026] [security2:error] [pid 229246:tid 229420] [client 74.7.175.143:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "taliafernandavidi1783665345000.0711679.meusitehostgator.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9KiiBMYeh5YLVG45yUkgACQGk"]
[Tue Jul 21 07:31:38.617092 2026] [security2:error] [pid 229246:tid 229339] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KiiBMYeh5YLVG45yUlQACXlw"]
[Tue Jul 21 07:31:38.720039 2026] [autoindex:error] [pid 229246:tid 229371] [remote 74.7.227.2:0] AH01276: Cannot serve directory /home2/taliaf34/taliafernandavidi1783665345000.0711679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:38.869092 2026] [autoindex:error] [pid 229246:tid 229416] [client 20.206.105.145:7761] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:38.928888 2026] [autoindex:error] [pid 229246:tid 229495] [client 20.206.105.145:7761] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:38.979706 2026] [security2:error] [pid 229246:tid 229441] [client 59.96.220.140:59385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KiiBMYeh5YLVG45yUnwAAAlU"]
[Tue Jul 21 07:31:38.979803 2026] [security2:error] [pid 229246:tid 229441] [client 59.96.220.140:59385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KiiBMYeh5YLVG45yUnwAAAlU"]
[Tue Jul 21 07:31:39.000881 2026] [security2:error] [pid 229246:tid 229453] [client 74.7.244.24:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "abdomenfirme.patihipopressivo.com"] [uri "/index.php"] [unique_id "al9KiCBMYeh5YLVG45yUXQAAAmE"]
[Tue Jul 21 07:31:39.001694 2026] [security2:error] [pid 229246:tid 229433] [client 74.7.244.24:45894] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "abdomenfirme.patihipopressivo.com"] [uri "/robots.txt"] [unique_id "al9KiCBMYeh5YLVG45yUWwACTUs"]
[Tue Jul 21 07:31:39.059524 2026] [security2:error] [pid 229246:tid 229267] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KiyBMYeh5YLVG45yUpAACZhQ"]
[Tue Jul 21 07:31:39.106216 2026] [security2:error] [pid 229246:tid 229474] [client 117.251.86.144:55886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KiyBMYeh5YLVG45yUpgAAAnY"]
[Tue Jul 21 07:31:39.106335 2026] [security2:error] [pid 229246:tid 229474] [client 117.251.86.144:55886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KiyBMYeh5YLVG45yUpgAAAnY"]
[Tue Jul 21 07:31:39.145924 2026] [security2:error] [pid 229246:tid 229457] [client 20.151.10.161:57388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wpconf.php"] [unique_id "al9KiyBMYeh5YLVG45yUqgAAAmU"]
[Tue Jul 21 07:31:39.486919 2026] [security2:error] [pid 229246:tid 229401] [client 45.8.17.134:63725] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/wp.php"] [unique_id "al9KiyBMYeh5YLVG45yUsQAAAi0"]
[Tue Jul 21 07:31:39.488580 2026] [security2:error] [pid 229246:tid 229282] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KiyBMYeh5YLVG45yUsAACfSM"]
[Tue Jul 21 07:31:39.488749 2026] [security2:error] [pid 229246:tid 229481] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KiyBMYeh5YLVG45yUsAACfSM"]
[Tue Jul 21 07:31:39.560056 2026] [security2:error] [pid 229246:tid 229308] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/media.php"] [unique_id "al9KiyBMYeh5YLVG45yUtQACXj0"]
[Tue Jul 21 07:31:39.868500 2026] [security2:error] [pid 229246:tid 229460] [client 139.167.225.182:58668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KiyBMYeh5YLVG45yUwwAAAmg"]
[Tue Jul 21 07:31:39.868594 2026] [security2:error] [pid 229246:tid 229460] [client 139.167.225.182:58668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KiyBMYeh5YLVG45yUwwAAAmg"]
[Tue Jul 21 07:31:40.000609 2026] [security2:error] [pid 229246:tid 229285] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KiyBMYeh5YLVG45yUxwACMCY"]
[Tue Jul 21 07:31:40.000748 2026] [security2:error] [pid 229246:tid 229404] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KiyBMYeh5YLVG45yUxwACMCY"]
[Tue Jul 21 07:31:40.199507 2026] [security2:error] [pid 229246:tid 229479] [client 20.151.10.161:51314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/mosty.php"] [unique_id "al9KjCBMYeh5YLVG45yU1AAAAns"]
[Tue Jul 21 07:31:40.275665 2026] [security2:error] [pid 229246:tid 229347] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KjCBMYeh5YLVG45yU1gACUWQ"]
[Tue Jul 21 07:31:40.275820 2026] [security2:error] [pid 229246:tid 229437] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KjCBMYeh5YLVG45yU1gACUWQ"]
[Tue Jul 21 07:31:40.387580 2026] [security2:error] [pid 229246:tid 229500] [client 45.8.17.124:25529] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/news-portal/sitebar.php"] [unique_id "al9KjCBMYeh5YLVG45yU2QAAApA"]
[Tue Jul 21 07:31:40.625518 2026] [security2:error] [pid 229246:tid 229423] [client 20.206.105.145:7761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9KjCBMYeh5YLVG45yU5QAAAkM"]
[Tue Jul 21 07:31:40.636260 2026] [security2:error] [pid 229246:tid 229452] [client 103.162.129.114:56875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KjCBMYeh5YLVG45yU5gAAAmA"]
[Tue Jul 21 07:31:40.636422 2026] [security2:error] [pid 229246:tid 229452] [client 103.162.129.114:56875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KjCBMYeh5YLVG45yU5gAAAmA"]
[Tue Jul 21 07:31:40.701310 2026] [security2:error] [pid 229246:tid 229453] [client 122.186.204.214:56647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KjCBMYeh5YLVG45yU6gAAAmE"]
[Tue Jul 21 07:31:40.705706 2026] [security2:error] [pid 229246:tid 229453] [client 122.186.204.214:56647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KjCBMYeh5YLVG45yU6gAAAmE"]
[Tue Jul 21 07:31:41.135110 2026] [security2:error] [pid 229246:tid 229499] [client 172.245.102.42:25001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KjSBMYeh5YLVG45yU9QAAAo8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:41.343034 2026] [security2:error] [pid 229246:tid 229313] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/images.php"] [unique_id "al9KjSBMYeh5YLVG45yU-wACSUI"]
[Tue Jul 21 07:31:41.361969 2026] [security2:error] [pid 229246:tid 229272] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/gecko.php"] [unique_id "al9KjSBMYeh5YLVG45yU_AACeRk"]
[Tue Jul 21 07:31:41.393313 2026] [security2:error] [pid 229246:tid 229316] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/82.php"] [unique_id "al9KjSBMYeh5YLVG45yU_QACKkU"]
[Tue Jul 21 07:31:41.429629 2026] [security2:error] [pid 229246:tid 229410] [client 20.220.225.223:8080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/kua.php"] [unique_id "al9KjSBMYeh5YLVG45yU_wAAAjY"]
[Tue Jul 21 07:31:41.579567 2026] [security2:error] [pid 229246:tid 229487] [client 45.8.17.65:51347] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/database.php"] [unique_id "al9KjSBMYeh5YLVG45yVAQAAAoM"]
[Tue Jul 21 07:31:41.608989 2026] [security2:error] [pid 229246:tid 229279] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KjSBMYeh5YLVG45yVBAACHSA"]
[Tue Jul 21 07:31:41.609152 2026] [security2:error] [pid 229246:tid 229385] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KjSBMYeh5YLVG45yVBAACHSA"]
[Tue Jul 21 07:31:41.789897 2026] [security2:error] [pid 229246:tid 229396] [client 103.106.20.201:64940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KjSBMYeh5YLVG45yVDgAAAig"]
[Tue Jul 21 07:31:41.789993 2026] [security2:error] [pid 229246:tid 229396] [client 103.106.20.201:64940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KjSBMYeh5YLVG45yVDgAAAig"]
[Tue Jul 21 07:31:41.935370 2026] [security2:error] [pid 229246:tid 229448] [client 20.220.225.223:63836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/wicked.php"] [unique_id "al9KjSBMYeh5YLVG45yVFAAAAlw"]
[Tue Jul 21 07:31:42.068215 2026] [security2:error] [pid 229246:tid 229449] [client 20.151.10.161:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/dejavu.php"] [unique_id "al9KjiBMYeh5YLVG45yVFQAAAl0"]
[Tue Jul 21 07:31:42.184273 2026] [security2:error] [pid 229246:tid 229310] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/admin.php"] [unique_id "al9KjiBMYeh5YLVG45yVGQACfj8"]
[Tue Jul 21 07:31:42.204120 2026] [security2:error] [pid 229246:tid 229327] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/adminner.php"] [unique_id "al9KjiBMYeh5YLVG45yVGgACMlA"]
[Tue Jul 21 07:31:42.373500 2026] [security2:error] [pid 229246:tid 229299] [remote 72.167.132.114:59646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9KjiBMYeh5YLVG45yVIwACjTQ"]
[Tue Jul 21 07:31:42.514123 2026] [security2:error] [pid 229246:tid 229455] [client 173.24.185.52:55890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KjiBMYeh5YLVG45yVJwAAAmM"]
[Tue Jul 21 07:31:42.514251 2026] [security2:error] [pid 229246:tid 229455] [client 173.24.185.52:55890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KjiBMYeh5YLVG45yVJwAAAmM"]
[Tue Jul 21 07:31:42.683431 2026] [security2:error] [pid 229246:tid 229277] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/admin.php"] [unique_id "al9KjiBMYeh5YLVG45yVKgACHR4"]
[Tue Jul 21 07:31:42.741592 2026] [security2:error] [pid 229246:tid 229474] [client 154.192.233.199:58980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KjiBMYeh5YLVG45yVLQAAAnY"]
[Tue Jul 21 07:31:42.741758 2026] [security2:error] [pid 229246:tid 229474] [client 154.192.233.199:58980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KjiBMYeh5YLVG45yVLQAAAnY"]
[Tue Jul 21 07:31:42.779634 2026] [security2:error] [pid 229246:tid 229427] [client 109.248.148.246:53852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KjiBMYeh5YLVG45yVLgAAAkc"]
[Tue Jul 21 07:31:42.779747 2026] [security2:error] [pid 229246:tid 229427] [client 109.248.148.246:53852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KjiBMYeh5YLVG45yVLgAAAkc"]
[Tue Jul 21 07:31:42.782269 2026] [security2:error] [pid 229246:tid 229364] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/k.php"] [unique_id "al9KjiBMYeh5YLVG45yVLwACd3U"]
[Tue Jul 21 07:31:42.888461 2026] [security2:error] [pid 229246:tid 229442] [client 45.8.17.138:54189] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/login.php"] [unique_id "al9KjiBMYeh5YLVG45yVVAAAAlY"]
[Tue Jul 21 07:31:43.012022 2026] [security2:error] [pid 229246:tid 229249] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KjyBMYeh5YLVG45yVcQACRgI"]
[Tue Jul 21 07:31:43.012152 2026] [security2:error] [pid 229246:tid 229426] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KjyBMYeh5YLVG45yVcQACRgI"]
[Tue Jul 21 07:31:43.066348 2026] [security2:error] [pid 229246:tid 229500] [client 175.45.70.82:50143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KjyBMYeh5YLVG45yVdgAAApA"]
[Tue Jul 21 07:31:43.066452 2026] [security2:error] [pid 229246:tid 229500] [client 175.45.70.82:50143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KjyBMYeh5YLVG45yVdgAAApA"]
[Tue Jul 21 07:31:43.093029 2026] [security2:error] [pid 229246:tid 229374] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KjyBMYeh5YLVG45yVeAACcn8"]
[Tue Jul 21 07:31:43.093194 2026] [security2:error] [pid 229246:tid 229470] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KjyBMYeh5YLVG45yVeAACcn8"]
[Tue Jul 21 07:31:43.132968 2026] [security2:error] [pid 229246:tid 229293] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/blurbs.php"] [unique_id "al9KjyBMYeh5YLVG45yVewACUS4"]
[Tue Jul 21 07:31:43.143559 2026] [security2:error] [pid 229246:tid 229489] [client 20.151.10.161:50931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/aaf.php"] [unique_id "al9KjyBMYeh5YLVG45yVfAAAAoU"]
[Tue Jul 21 07:31:43.160090 2026] [security2:error] [pid 229246:tid 229336] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/bajah.php"] [unique_id "al9KjyBMYeh5YLVG45yVfQACeVk"]
[Tue Jul 21 07:31:43.178958 2026] [security2:error] [pid 229246:tid 229301] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/a.php"] [unique_id "al9KjyBMYeh5YLVG45yVfgACcDY"]
[Tue Jul 21 07:31:43.197944 2026] [security2:error] [pid 229246:tid 229360] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/edit.php"] [unique_id "al9KjyBMYeh5YLVG45yVfwACK3E"]
[Tue Jul 21 07:31:43.202329 2026] [security2:error] [pid 229246:tid 229493] [client 20.220.225.223:31175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KjyBMYeh5YLVG45yVgAAAAok"]
[Tue Jul 21 07:31:43.217631 2026] [security2:error] [pid 229246:tid 229319] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/hosty.php"] [unique_id "al9KjyBMYeh5YLVG45yVgQACbkg"]
[Tue Jul 21 07:31:43.242694 2026] [security2:error] [pid 229246:tid 229272] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/k.php"] [unique_id "al9KjyBMYeh5YLVG45yVhgACdhk"]
[Tue Jul 21 07:31:43.712358 2026] [security2:error] [pid 229246:tid 229331] [remote 57.141.18.73:33948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapl.xml"] [unique_id "al9KjyBMYeh5YLVG45yVkwACVlQ"]
[Tue Jul 21 07:31:43.797719 2026] [security2:error] [pid 229246:tid 229499] [client 20.220.225.223:6795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/ez.php"] [unique_id "al9KjyBMYeh5YLVG45yVlgAAAo8"]
[Tue Jul 21 07:31:44.097126 2026] [security2:error] [pid 229246:tid 229438] [client 103.174.34.15:59013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KkCBMYeh5YLVG45yVmwAAAlI"]
[Tue Jul 21 07:31:44.097487 2026] [security2:error] [pid 229246:tid 229438] [client 103.174.34.15:59013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KkCBMYeh5YLVG45yVmwAAAlI"]
[Tue Jul 21 07:31:44.114249 2026] [security2:error] [pid 229246:tid 229419] [client 152.59.154.239:60396] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KkCBMYeh5YLVG45yVnAAAAj8"]
[Tue Jul 21 07:31:44.114422 2026] [security2:error] [pid 229246:tid 229419] [client 152.59.154.239:60396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KkCBMYeh5YLVG45yVnAAAAj8"]
[Tue Jul 21 07:31:44.223643 2026] [security2:error] [pid 229246:tid 229473] [client 20.220.225.223:6812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/fz.php"] [unique_id "al9KkCBMYeh5YLVG45yVnwAAAnU"]
[Tue Jul 21 07:31:44.268643 2026] [security2:error] [pid 229246:tid 229280] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/aaa.php"] [unique_id "al9KkCBMYeh5YLVG45yVpgACXyE"]
[Tue Jul 21 07:31:44.306423 2026] [security2:error] [pid 229246:tid 229404] [client 20.206.105.145:7596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-links.php"] [unique_id "al9KkCBMYeh5YLVG45yVqwAAAjA"]
[Tue Jul 21 07:31:44.352684 2026] [security2:error] [pid 229246:tid 229315] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/file5.php"] [unique_id "al9KkCBMYeh5YLVG45yVrAACQEQ"]
[Tue Jul 21 07:31:44.412367 2026] [security2:error] [pid 229246:tid 229248] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/222.php"] [unique_id "al9KkCBMYeh5YLVG45yVsgACTwE"]
[Tue Jul 21 07:31:44.569880 2026] [security2:error] [pid 229246:tid 229482] [client 45.251.232.145:64035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KkCBMYeh5YLVG45yVuAAAAn4"]
[Tue Jul 21 07:31:44.569996 2026] [security2:error] [pid 229246:tid 229482] [client 45.251.232.145:64035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KkCBMYeh5YLVG45yVuAAAAn4"]
[Tue Jul 21 07:31:44.698388 2026] [security2:error] [pid 229246:tid 229479] [client 20.220.225.223:31198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/wander.php"] [unique_id "al9KkCBMYeh5YLVG45yVugAAAns"]
[Tue Jul 21 07:31:44.719087 2026] [security2:error] [pid 229246:tid 229346] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/test.php"] [unique_id "al9KkCBMYeh5YLVG45yVuwACVWM"]
[Tue Jul 21 07:31:44.813856 2026] [security2:error] [pid 229246:tid 229434] [client 180.153.236.244:34589] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com.br"] [uri "/"] [unique_id "al9KkCBMYeh5YLVG45yVwQAAAk4"], referer: http://gradiente.com.br/
[Tue Jul 21 07:31:44.814003 2026] [security2:error] [pid 229246:tid 229434] [client 180.153.236.244:34589] ModSecurity: Warning. Matched phrase "360Spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com.br"] [uri "/"] [unique_id "al9KkCBMYeh5YLVG45yVwQAAAk4"], referer: http://gradiente.com.br/
[Tue Jul 21 07:31:44.860350 2026] [security2:error] [pid 229246:tid 229433] [client 20.151.10.161:57370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/term.php"] [unique_id "al9KkCBMYeh5YLVG45yVwgAAAk0"]
[Tue Jul 21 07:31:45.081111 2026] [security2:error] [pid 229246:tid 229443] [client 122.129.67.13:59763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9KkCBMYeh5YLVG45yVzgAAAlc"]
[Tue Jul 21 07:31:45.195751 2026] [security2:error] [pid 229246:tid 229384] [client 45.8.17.57:26525] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/user/config.php"] [unique_id "al9KkSBMYeh5YLVG45yV0QAAAhw"]
[Tue Jul 21 07:31:45.250688 2026] [security2:error] [pid 229246:tid 229267] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/aaa.php"] [unique_id "al9KkSBMYeh5YLVG45yV0wACIxQ"]
[Tue Jul 21 07:31:45.270078 2026] [security2:error] [pid 229246:tid 229348] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/11.php"] [unique_id "al9KkSBMYeh5YLVG45yV1AACaGU"]
[Tue Jul 21 07:31:45.288850 2026] [security2:error] [pid 229246:tid 229296] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/mac.php"] [unique_id "al9KkSBMYeh5YLVG45yV1QACTzE"]
[Tue Jul 21 07:31:45.314938 2026] [security2:error] [pid 229246:tid 229414] [client 20.220.225.223:19321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/zzz.php"] [unique_id "al9KkSBMYeh5YLVG45yV1gAAAjo"]
[Tue Jul 21 07:31:45.449849 2026] [security2:error] [pid 229246:tid 229274] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/chosen.php"] [unique_id "al9KkSBMYeh5YLVG45yV3QACFhs"]
[Tue Jul 21 07:31:45.468479 2026] [security2:error] [pid 229246:tid 229283] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/cream1.php"] [unique_id "al9KkSBMYeh5YLVG45yV3wACQiQ"]
[Tue Jul 21 07:31:45.532844 2026] [autoindex:error] [pid 229246:tid 229317] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:45.567629 2026] [autoindex:error] [pid 229246:tid 229278] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:45.609676 2026] [security2:error] [pid 229246:tid 229340] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/dr.php"] [unique_id "al9KkSBMYeh5YLVG45yV5gACRl0"]
[Tue Jul 21 07:31:45.627856 2026] [security2:error] [pid 229246:tid 229371] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/x.php"] [unique_id "al9KkSBMYeh5YLVG45yV5wACO3w"]
[Tue Jul 21 07:31:45.647666 2026] [security2:error] [pid 229246:tid 229329] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/155.php"] [unique_id "al9KkSBMYeh5YLVG45yV6AACWVI"]
[Tue Jul 21 07:31:45.660067 2026] [security2:error] [pid 229246:tid 229455] [client 193.36.225.66:44793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KkSBMYeh5YLVG45yV6QAAAmM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:45.716418 2026] [security2:error] [pid 229246:tid 229350] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/ops.php"] [unique_id "al9KkSBMYeh5YLVG45yV6gACWGc"]
[Tue Jul 21 07:31:45.736760 2026] [security2:error] [pid 229246:tid 229252] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/file31.php"] [unique_id "al9KkSBMYeh5YLVG45yV6wACXgU"]
[Tue Jul 21 07:31:45.830806 2026] [security2:error] [pid 229246:tid 229458] [client 82.102.28.107:59130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KkSBMYeh5YLVG45yV7wAAAmY"]
[Tue Jul 21 07:31:45.830913 2026] [security2:error] [pid 229246:tid 229458] [client 82.102.28.107:59130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KkSBMYeh5YLVG45yV7wAAAmY"]
[Tue Jul 21 07:31:45.905603 2026] [security2:error] [pid 229246:tid 229483] [client 117.217.38.194:53226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KkSBMYeh5YLVG45yV8gAAAn8"]
[Tue Jul 21 07:31:45.905786 2026] [security2:error] [pid 229246:tid 229483] [client 117.217.38.194:53226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KkSBMYeh5YLVG45yV8gAAAn8"]
[Tue Jul 21 07:31:46.091251 2026] [security2:error] [pid 229246:tid 229475] [client 20.151.10.161:58055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/ha.php"] [unique_id "al9KkiBMYeh5YLVG45yV-AAAAnc"]
[Tue Jul 21 07:31:46.233987 2026] [security2:error] [pid 229246:tid 229253] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/file6.php"] [unique_id "al9KkiBMYeh5YLVG45yV-gACYAY"]
[Tue Jul 21 07:31:46.292403 2026] [security2:error] [pid 229246:tid 229461] [client 20.206.105.145:7443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/solo1.php"] [unique_id "al9KkiBMYeh5YLVG45yV_AAAAmk"]
[Tue Jul 21 07:31:46.343086 2026] [security2:error] [pid 229246:tid 229264] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KkiBMYeh5YLVG45yV_QAChBE"]
[Tue Jul 21 07:31:46.343233 2026] [security2:error] [pid 229246:tid 229488] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KkiBMYeh5YLVG45yV_QAChBE"]
[Tue Jul 21 07:31:46.471904 2026] [security2:error] [pid 229246:tid 229469] [client 20.220.225.223:8071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/la.php"] [unique_id "al9KkiBMYeh5YLVG45yWAgAAAnE"]
[Tue Jul 21 07:31:46.485273 2026] [security2:error] [pid 229246:tid 229456] [client 62.102.148.164:51650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9KkiBMYeh5YLVG45yWBAAAAmQ"]
[Tue Jul 21 07:31:46.485347 2026] [security2:error] [pid 229246:tid 229456] [client 62.102.148.164:51650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9KkiBMYeh5YLVG45yWBAAAAmQ"]
[Tue Jul 21 07:31:46.514587 2026] [autoindex:error] [pid 229246:tid 229285] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:46.535542 2026] [security2:error] [pid 229246:tid 229397] [client 20.197.192.193:60972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KkiBMYeh5YLVG45yWCAAAAik"]
[Tue Jul 21 07:31:46.536170 2026] [security2:error] [pid 229246:tid 229373] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/adminfuns.php"] [unique_id "al9KkiBMYeh5YLVG45yWCQACFH4"]
[Tue Jul 21 07:31:46.548092 2026] [security2:error] [pid 229246:tid 229309] [remote 180.153.236.33:57421] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com.br"] [uri "/"] [unique_id "al9KkiBMYeh5YLVG45yWCgACLz4"], referer: https://gradiente.com.br/
[Tue Jul 21 07:31:46.548641 2026] [security2:error] [pid 229246:tid 229403] [client 180.153.236.33:57421] ModSecurity: Warning. Matched phrase "360Spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com.br"] [uri "/"] [unique_id "al9KkiBMYeh5YLVG45yWCgACLz4"], referer: https://gradiente.com.br/
[Tue Jul 21 07:31:46.557194 2026] [security2:error] [pid 229246:tid 229311] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/goods.php"] [unique_id "al9KkiBMYeh5YLVG45yWCwACdkA"]
[Tue Jul 21 07:31:46.609796 2026] [security2:error] [pid 229246:tid 229441] [client 20.197.192.193:44793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KkiBMYeh5YLVG45yWDQAAAlU"]
[Tue Jul 21 07:31:46.612629 2026] [security2:error] [pid 229246:tid 229355] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/100.php"] [unique_id "al9KkiBMYeh5YLVG45yWDgACGWw"]
[Tue Jul 21 07:31:46.634307 2026] [security2:error] [pid 229246:tid 229415] [client 20.197.192.193:60934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/dp.php"] [unique_id "al9KkiBMYeh5YLVG45yWDwAAAjs"]
[Tue Jul 21 07:31:46.671840 2026] [security2:error] [pid 229246:tid 229450] [client 20.197.192.193:60942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/old.php"] [unique_id "al9KkiBMYeh5YLVG45yWEAAAAl4"]
[Tue Jul 21 07:31:46.690835 2026] [security2:error] [pid 229246:tid 229458] [client 45.8.17.128:35389] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/languages/themes/admin.php"] [unique_id "al9KkiBMYeh5YLVG45yWEQAAAmY"]
[Tue Jul 21 07:31:46.776288 2026] [security2:error] [pid 229246:tid 229448] [client 20.220.225.223:61968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/edit.php"] [unique_id "al9KkiBMYeh5YLVG45yWFQAAAlw"]
[Tue Jul 21 07:31:46.794531 2026] [security2:error] [pid 229246:tid 229468] [client 20.197.192.193:60971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/ms-new.php"] [unique_id "al9KkiBMYeh5YLVG45yWFgAAAnA"]
[Tue Jul 21 07:31:46.887078 2026] [security2:error] [pid 229246:tid 229493] [client 20.197.192.193:44771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/track.php"] [unique_id "al9KkiBMYeh5YLVG45yWHAAAAok"]
[Tue Jul 21 07:31:46.892336 2026] [security2:error] [pid 229246:tid 229287] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KkiBMYeh5YLVG45yWHgACNig"]
[Tue Jul 21 07:31:46.892461 2026] [security2:error] [pid 229246:tid 229410] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KkiBMYeh5YLVG45yWHgACNig"]
[Tue Jul 21 07:31:46.953639 2026] [security2:error] [pid 229246:tid 229477] [client 20.151.10.161:57375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/hur.php"] [unique_id "al9KkiBMYeh5YLVG45yWIwAAAnk"]
[Tue Jul 21 07:31:46.960676 2026] [security2:error] [pid 229246:tid 229452] [client 20.197.192.193:60979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/2352356666.php"] [unique_id "al9KkiBMYeh5YLVG45yWJAAAAmA"]
[Tue Jul 21 07:31:47.013701 2026] [security2:error] [pid 229246:tid 229488] [client 20.197.192.193:60984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/pn.php"] [unique_id "al9KkyBMYeh5YLVG45yWJQAAAoQ"]
[Tue Jul 21 07:31:47.087437 2026] [security2:error] [pid 229246:tid 229257] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/about.php"] [unique_id "al9KkyBMYeh5YLVG45yWJwACTwo"]
[Tue Jul 21 07:31:47.106012 2026] [security2:error] [pid 229246:tid 229332] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/about.php"] [unique_id "al9KkyBMYeh5YLVG45yWKAACKlU"]
[Tue Jul 21 07:31:47.142839 2026] [security2:error] [pid 229246:tid 229247] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/admin.php"] [unique_id "al9KkyBMYeh5YLVG45yWKQACNQA"]
[Tue Jul 21 07:31:47.168690 2026] [security2:error] [pid 229246:tid 229379] [client 20.197.192.193:60990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9KkyBMYeh5YLVG45yWKgAAAhc"]
[Tue Jul 21 07:31:47.328761 2026] [security2:error] [pid 229246:tid 229427] [client 20.197.192.193:44778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/dr.php"] [unique_id "al9KkyBMYeh5YLVG45yWLAAAAkc"]
[Tue Jul 21 07:31:47.353654 2026] [security2:error] [pid 229246:tid 229374] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/admin.php"] [unique_id "al9KkyBMYeh5YLVG45yWLwACRH8"]
[Tue Jul 21 07:31:47.361130 2026] [security2:error] [pid 229246:tid 229499] [client 20.197.192.193:54088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/2x.php"] [unique_id "al9KkyBMYeh5YLVG45yWMAAAAo8"]
[Tue Jul 21 07:31:47.387394 2026] [security2:error] [pid 229246:tid 229376] [client 20.151.10.161:50920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/h02ugyh.php"] [unique_id "al9KkyBMYeh5YLVG45yWMQAAAhQ"]
[Tue Jul 21 07:31:47.414402 2026] [security2:error] [pid 229246:tid 229474] [client 20.197.192.193:60957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/kq1.php"] [unique_id "al9KkyBMYeh5YLVG45yWMgAAAnY"]
[Tue Jul 21 07:31:47.487598 2026] [security2:error] [pid 229246:tid 229434] [client 20.197.192.193:44798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/zzz.php"] [unique_id "al9KkyBMYeh5YLVG45yWOAAAAk4"]
[Tue Jul 21 07:31:47.526353 2026] [security2:error] [pid 229246:tid 229489] [client 20.197.192.193:44782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/wicked.php"] [unique_id "al9KkyBMYeh5YLVG45yWPQAAAoU"]
[Tue Jul 21 07:31:47.616894 2026] [security2:error] [pid 229246:tid 229416] [client 20.197.192.193:44749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/edit.php"] [unique_id "al9KkyBMYeh5YLVG45yWQAAAAjw"]
[Tue Jul 21 07:31:47.649470 2026] [security2:error] [pid 229246:tid 229444] [client 20.197.192.193:44774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/kua.php"] [unique_id "al9KkyBMYeh5YLVG45yWQgAAAlg"]
[Tue Jul 21 07:31:47.681062 2026] [security2:error] [pid 229246:tid 229263] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KkyBMYeh5YLVG45yWRwACixA"]
[Tue Jul 21 07:31:47.681198 2026] [security2:error] [pid 229246:tid 229495] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KkyBMYeh5YLVG45yWRwACixA"]
[Tue Jul 21 07:31:47.687219 2026] [security2:error] [pid 229246:tid 229404] [client 20.197.192.193:45098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/ez.php"] [unique_id "al9KkyBMYeh5YLVG45yWSAAAAjA"]
[Tue Jul 21 07:31:47.718474 2026] [security2:error] [pid 229246:tid 229313] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/themes.php"] [unique_id "al9KkyBMYeh5YLVG45yWSQACdUI"]
[Tue Jul 21 07:31:47.761001 2026] [security2:error] [pid 229246:tid 229461] [client 20.151.10.161:51313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/seiso.php"] [unique_id "al9KkyBMYeh5YLVG45yWSwAAAmk"]
[Tue Jul 21 07:31:47.784568 2026] [security2:error] [pid 229246:tid 229436] [client 45.8.17.147:38041] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/PHPMailer/"] [unique_id "al9KkyBMYeh5YLVG45yWTgAAAlA"]
[Tue Jul 21 07:31:47.794529 2026] [security2:error] [pid 229246:tid 229488] [client 20.197.192.193:44756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/fz.php"] [unique_id "al9KkyBMYeh5YLVG45yWTwAAAoQ"]
[Tue Jul 21 07:31:47.841624 2026] [security2:error] [pid 229246:tid 229389] [client 20.197.192.193:44736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/la.php"] [unique_id "al9KkyBMYeh5YLVG45yWUAAAAiE"]
[Tue Jul 21 07:31:47.903587 2026] [autoindex:error] [pid 229246:tid 229279] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:47.944052 2026] [security2:error] [pid 229246:tid 229379] [client 20.197.192.193:60952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9KkyBMYeh5YLVG45yWVAAAAhc"]
[Tue Jul 21 07:31:47.994798 2026] [security2:error] [pid 229246:tid 229499] [client 20.206.105.145:38921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/fpwch.php"] [unique_id "al9KkyBMYeh5YLVG45yWWAAAAo8"]
[Tue Jul 21 07:31:48.069198 2026] [security2:error] [pid 229246:tid 229445] [client 20.197.192.193:44775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/inso.php"] [unique_id "al9KlCBMYeh5YLVG45yWXQAAAlk"]
[Tue Jul 21 07:31:48.079328 2026] [security2:error] [pid 229246:tid 229337] [remote 216.73.160.192:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marketingderua.com.br"] [uri "/wp-login.php"] [unique_id "al9KlCBMYeh5YLVG45yWXgACHFo"]
[Tue Jul 21 07:31:48.096403 2026] [security2:error] [pid 229246:tid 229450] [client 20.151.10.161:57352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/155.php"] [unique_id "al9KlCBMYeh5YLVG45yWYgAAAl4"]
[Tue Jul 21 07:31:48.122490 2026] [security2:error] [pid 229246:tid 229429] [client 20.197.192.193:54085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/wpx.php"] [unique_id "al9KlCBMYeh5YLVG45yWZAAAAkk"]
[Tue Jul 21 07:31:48.189592 2026] [security2:error] [pid 229246:tid 229435] [client 173.252.95.4:58934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9KlCBMYeh5YLVG45yWWgAAAk8"]
[Tue Jul 21 07:31:48.251801 2026] [security2:error] [pid 229246:tid 229466] [client 20.220.225.223:6814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/nhvoanpl.php"] [unique_id "al9KlCBMYeh5YLVG45yWZgAAAm4"]
[Tue Jul 21 07:31:48.255671 2026] [security2:error] [pid 229246:tid 229470] [client 20.197.192.193:44740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/berlin.php"] [unique_id "al9KlCBMYeh5YLVG45yWZwAAAnI"]
[Tue Jul 21 07:31:48.289977 2026] [security2:error] [pid 229246:tid 229468] [client 20.197.192.193:44753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/billur.php"] [unique_id "al9KlCBMYeh5YLVG45yWaAAAAnA"]
[Tue Jul 21 07:31:48.344819 2026] [security2:error] [pid 229246:tid 229428] [client 20.197.192.193:60974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/mimpi.php"] [unique_id "al9KlCBMYeh5YLVG45yWagAAAkg"]
[Tue Jul 21 07:31:48.425514 2026] [security2:error] [pid 229246:tid 229444] [client 20.197.192.193:60947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/dp.php"] [unique_id "al9KlCBMYeh5YLVG45yWawAAAlg"]
[Tue Jul 21 07:31:48.463082 2026] [security2:error] [pid 229246:tid 229404] [client 20.151.10.161:57997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/ppp.php"] [unique_id "al9KlCBMYeh5YLVG45yWbAAAAjA"]
[Tue Jul 21 07:31:48.487199 2026] [security2:error] [pid 229246:tid 229437] [client 20.197.192.193:44795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/bootstrap.php"] [unique_id "al9KlCBMYeh5YLVG45yWbQAAAlE"]
[Tue Jul 21 07:31:48.564118 2026] [security2:error] [pid 229246:tid 229389] [client 20.197.192.193:44776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/wp-editor.php"] [unique_id "al9KlCBMYeh5YLVG45yWdAAAAiE"]
[Tue Jul 21 07:31:48.566472 2026] [security2:error] [pid 229246:tid 229385] [client 20.197.195.24:13122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KlCBMYeh5YLVG45yWdQAAAh0"]
[Tue Jul 21 07:31:48.583983 2026] [security2:error] [pid 229246:tid 229409] [client 20.197.192.193:44747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/cro.php"] [unique_id "al9KlCBMYeh5YLVG45yWdgAAAjU"]
[Tue Jul 21 07:31:48.607554 2026] [security2:error] [pid 229246:tid 229422] [client 20.197.192.193:54081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/cron-tab.php"] [unique_id "al9KlCBMYeh5YLVG45yWdwAAAkI"]
[Tue Jul 21 07:31:48.648087 2026] [security2:error] [pid 229246:tid 229460] [client 20.197.192.193:60959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/koiy.php"] [unique_id "al9KlCBMYeh5YLVG45yWeQAAAmg"]
[Tue Jul 21 07:31:48.732317 2026] [security2:error] [pid 229246:tid 229490] [client 20.197.192.193:45110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/hp2.php"] [unique_id "al9KlCBMYeh5YLVG45yWfAAAAoY"]
[Tue Jul 21 07:31:48.828467 2026] [security2:error] [pid 229246:tid 229445] [client 20.197.192.193:60936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/hp3.php"] [unique_id "al9KlCBMYeh5YLVG45yWfgAAAlk"]
[Tue Jul 21 07:31:48.835113 2026] [security2:error] [pid 229246:tid 229455] [client 20.220.225.223:46124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/wp-editor.php"] [unique_id "al9KlCBMYeh5YLVG45yWfwAAAmM"]
[Tue Jul 21 07:31:48.865186 2026] [security2:error] [pid 229246:tid 229426] [client 20.151.10.161:51265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/201.php"] [unique_id "al9KlCBMYeh5YLVG45yWgAAAAkY"]
[Tue Jul 21 07:31:48.889839 2026] [security2:error] [pid 229246:tid 229384] [client 20.197.192.193:44764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/aa1.php"] [unique_id "al9KlCBMYeh5YLVG45yWgQAAAhw"]
[Tue Jul 21 07:31:48.902257 2026] [security2:error] [pid 229246:tid 229430] [client 20.220.225.223:4176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/kua.php"] [unique_id "al9KlCBMYeh5YLVG45yWhAAAAko"]
[Tue Jul 21 07:31:48.975507 2026] [security2:error] [pid 229246:tid 229412] [client 20.197.192.193:60951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/acew67.php"] [unique_id "al9KlCBMYeh5YLVG45yWhgAAAjg"]
[Tue Jul 21 07:31:49.088353 2026] [security2:error] [pid 229246:tid 229416] [client 20.197.192.193:44773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/bscclapb.php"] [unique_id "al9KlSBMYeh5YLVG45yWjgAAAjw"]
[Tue Jul 21 07:31:49.104014 2026] [security2:error] [pid 229246:tid 229444] [client 20.197.192.193:54107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/else1.php"] [unique_id "al9KlSBMYeh5YLVG45yWjwAAAlg"]
[Tue Jul 21 07:31:49.126264 2026] [security2:error] [pid 229246:tid 229494] [client 20.197.192.193:44762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/tkikikoko.php"] [unique_id "al9KlSBMYeh5YLVG45yWkgAAAoo"]
[Tue Jul 21 07:31:49.164468 2026] [security2:error] [pid 229246:tid 229248] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/.well-known/about.php"] [unique_id "al9KlSBMYeh5YLVG45yWkwACaQE"]
[Tue Jul 21 07:31:49.186438 2026] [security2:error] [pid 229246:tid 229436] [client 20.206.105.145:54537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/sixxis.php"] [unique_id "al9KlSBMYeh5YLVG45yWlAAAAlA"]
[Tue Jul 21 07:31:49.192018 2026] [security2:error] [pid 229246:tid 229277] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9KlSBMYeh5YLVG45yWlQACcx4"]
[Tue Jul 21 07:31:49.196026 2026] [security2:error] [pid 229246:tid 229389] [client 20.197.192.193:54080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9KlSBMYeh5YLVG45yWlgAAAiE"]
[Tue Jul 21 07:31:49.237686 2026] [security2:error] [pid 229246:tid 229381] [client 20.220.225.223:62135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/bootstrap.php"] [unique_id "al9KlSBMYeh5YLVG45yWmgAAAhk"]
[Tue Jul 21 07:31:49.246960 2026] [security2:error] [pid 229246:tid 229379] [client 20.151.10.161:57465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/ops.php"] [unique_id "al9KlSBMYeh5YLVG45yWnAAAAhc"]
[Tue Jul 21 07:31:49.301828 2026] [security2:error] [pid 229246:tid 229397] [client 20.197.192.193:60928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/wp-css.php"] [unique_id "al9KlSBMYeh5YLVG45yWoQAAAik"]
[Tue Jul 21 07:31:49.339752 2026] [security2:error] [pid 229246:tid 229376] [client 20.52.136.55:1743] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "webmail.gradiente.com"] [uri "/.info.php"] [unique_id "al9KlSBMYeh5YLVG45yWogAAAhQ"]
[Tue Jul 21 07:31:49.352609 2026] [security2:error] [pid 229246:tid 229345] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/wefile.php"] [unique_id "al9KlSBMYeh5YLVG45yWowACfmI"]
[Tue Jul 21 07:31:49.366211 2026] [security2:error] [pid 229246:tid 229433] [client 20.220.225.223:4581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/ez.php"] [unique_id "al9KlSBMYeh5YLVG45yWpAAAAk0"]
[Tue Jul 21 07:31:49.408140 2026] [security2:error] [pid 229246:tid 229499] [client 20.197.192.193:44799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/wp-explorer.php"] [unique_id "al9KlSBMYeh5YLVG45yWpgAAAo8"]
[Tue Jul 21 07:31:49.513530 2026] [security2:error] [pid 229246:tid 229408] [client 20.220.225.223:8094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/inso.php"] [unique_id "al9KlSBMYeh5YLVG45yWqAAAAjQ"]
[Tue Jul 21 07:31:49.556710 2026] [security2:error] [pid 229246:tid 229464] [client 20.151.10.161:57995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/ingfo.php"] [unique_id "al9KlSBMYeh5YLVG45yWqQAAAmw"]
[Tue Jul 21 07:31:49.577458 2026] [security2:error] [pid 229246:tid 229492] [client 193.36.225.68:55209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KlSBMYeh5YLVG45yWrQAAAog"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:49.581870 2026] [security2:error] [pid 229246:tid 229500] [client 20.197.192.193:45072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/akismet.php"] [unique_id "al9KlSBMYeh5YLVG45yWrwAAApA"]
[Tue Jul 21 07:31:49.592772 2026] [security2:error] [pid 229246:tid 229485] [client 45.8.17.115:20967] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/wp-file-manager/file_folder_manager.php"] [unique_id "al9KlSBMYeh5YLVG45yWsQAAAoE"]
[Tue Jul 21 07:31:49.681315 2026] [security2:error] [pid 229246:tid 229404] [client 20.197.192.193:60988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/ace2.php"] [unique_id "al9KlSBMYeh5YLVG45yWtwAAAjA"]
[Tue Jul 21 07:31:49.696796 2026] [security2:error] [pid 229246:tid 229339] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9KlSBMYeh5YLVG45yWuAACilw"]
[Tue Jul 21 07:31:49.798830 2026] [autoindex:error] [pid 229246:tid 229370] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:49.805125 2026] [security2:error] [pid 229246:tid 229461] [client 20.197.192.193:44786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/ms.php"] [unique_id "al9KlSBMYeh5YLVG45yWvgAAAmk"]
[Tue Jul 21 07:31:49.858919 2026] [security2:error] [pid 229246:tid 229381] [client 20.151.10.161:57471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/error_log.php"] [unique_id "al9KlSBMYeh5YLVG45yWwQAAAhk"]
[Tue Jul 21 07:31:49.889260 2026] [autoindex:error] [pid 229246:tid 229367] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:49.925713 2026] [security2:error] [pid 229246:tid 229397] [client 20.197.195.24:13126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KlSBMYeh5YLVG45yWwgAAAik"]
[Tue Jul 21 07:31:49.940115 2026] [security2:error] [pid 229246:tid 229356] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9KlSBMYeh5YLVG45yWwwACfW0"]
[Tue Jul 21 07:31:49.958424 2026] [security2:error] [pid 229246:tid 229267] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/8.php"] [unique_id "al9KlSBMYeh5YLVG45yWxAACQhQ"]
[Tue Jul 21 07:31:50.014534 2026] [security2:error] [pid 229246:tid 229391] [client 59.96.220.140:59962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yWxQAAAiM"]
[Tue Jul 21 07:31:50.014634 2026] [security2:error] [pid 229246:tid 229391] [client 59.96.220.140:59962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yWxQAAAiM"]
[Tue Jul 21 07:31:50.044547 2026] [security2:error] [pid 229246:tid 229305] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yWxgACVTo"]
[Tue Jul 21 07:31:50.044647 2026] [security2:error] [pid 229246:tid 229441] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yWxgACVTo"]
[Tue Jul 21 07:31:50.116575 2026] [security2:error] [pid 229246:tid 229296] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9KliBMYeh5YLVG45yWywACYzE"]
[Tue Jul 21 07:31:50.135387 2026] [security2:error] [pid 229246:tid 229274] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/f6.php"] [unique_id "al9KliBMYeh5YLVG45yWzwACkhs"]
[Tue Jul 21 07:31:50.203695 2026] [security2:error] [pid 229246:tid 229283] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/inputs.php"] [unique_id "al9KliBMYeh5YLVG45yW0gACiCQ"]
[Tue Jul 21 07:31:50.251689 2026] [security2:error] [pid 229246:tid 229317] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/inputs.php"] [unique_id "al9KliBMYeh5YLVG45yW1AACXUY"]
[Tue Jul 21 07:31:50.269463 2026] [security2:error] [pid 229246:tid 229466] [client 20.220.225.223:38693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/jga.php"] [unique_id "al9KliBMYeh5YLVG45yW1QAAAm4"]
[Tue Jul 21 07:31:50.273326 2026] [security2:error] [pid 229246:tid 229278] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/classwithtostring.php"] [unique_id "al9KliBMYeh5YLVG45yW1gACOB8"]
[Tue Jul 21 07:31:50.286929 2026] [security2:error] [pid 229246:tid 229485] [client 20.151.10.161:51282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/xenon1337.php"] [unique_id "al9KliBMYeh5YLVG45yW1wAAAoE"]
[Tue Jul 21 07:31:50.291970 2026] [security2:error] [pid 229246:tid 229298] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9KliBMYeh5YLVG45yW2AACXzM"]
[Tue Jul 21 07:31:50.382807 2026] [security2:error] [pid 229246:tid 229475] [client 45.8.17.107:33821] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "al9KliBMYeh5YLVG45yW2wAAAnc"]
[Tue Jul 21 07:31:50.431777 2026] [security2:error] [pid 229246:tid 229329] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/wp-blog.php"] [unique_id "al9KliBMYeh5YLVG45yW3AACPFI"]
[Tue Jul 21 07:31:50.495662 2026] [security2:error] [pid 229246:tid 229470] [client 139.167.225.182:59292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yW3QAAAnI"]
[Tue Jul 21 07:31:50.495759 2026] [security2:error] [pid 229246:tid 229470] [client 139.167.225.182:59292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yW3QAAAnI"]
[Tue Jul 21 07:31:50.509347 2026] [autoindex:error] [pid 229246:tid 229350] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:50.511085 2026] [security2:error] [pid 229246:tid 229252] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yW3wACWAU"]
[Tue Jul 21 07:31:50.511188 2026] [security2:error] [pid 229246:tid 229444] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yW3wACWAU"]
[Tue Jul 21 07:31:50.531106 2026] [security2:error] [pid 229246:tid 229308] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9KliBMYeh5YLVG45yW4AACPz0"]
[Tue Jul 21 07:31:50.704195 2026] [security2:error] [pid 229246:tid 229461] [client 20.151.10.161:51316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/test11.php"] [unique_id "al9KliBMYeh5YLVG45yW5wAAAmk"]
[Tue Jul 21 07:31:50.742434 2026] [security2:error] [pid 229246:tid 229294] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yW6AACdS8"]
[Tue Jul 21 07:31:50.742658 2026] [security2:error] [pid 229246:tid 229473] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yW6AACdS8"]
[Tue Jul 21 07:31:50.815082 2026] [security2:error] [pid 229246:tid 229399] [client 213.152.162.104:37222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yW6wAAAis"]
[Tue Jul 21 07:31:50.815186 2026] [security2:error] [pid 229246:tid 229399] [client 213.152.162.104:37222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yW6wAAAis"]
[Tue Jul 21 07:31:50.849583 2026] [access_compat:error] [pid 229246:tid 229438] [client 162.241.63.68:11734] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:31:50.911474 2026] [security2:error] [pid 229246:tid 229497] [client 103.162.129.114:57315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yW7QAAAo0"]
[Tue Jul 21 07:31:50.911612 2026] [security2:error] [pid 229246:tid 229497] [client 103.162.129.114:57315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yW7QAAAo0"]
[Tue Jul 21 07:31:50.916160 2026] [security2:error] [pid 229246:tid 229253] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/ms-edit.php"] [unique_id "al9KliBMYeh5YLVG45yW7gACOgY"]
[Tue Jul 21 07:31:50.917486 2026] [security2:error] [pid 229246:tid 229481] [client 20.206.105.145:7400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/2P.update.php"] [unique_id "al9KliBMYeh5YLVG45yW7wAAAn0"]
[Tue Jul 21 07:31:50.936020 2026] [security2:error] [pid 229246:tid 229264] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9KliBMYeh5YLVG45yW8AACQhE"]
[Tue Jul 21 07:31:50.970881 2026] [autoindex:error] [pid 229246:tid 229255] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:50.995140 2026] [security2:error] [pid 229246:tid 229357] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9KliBMYeh5YLVG45yW8wACe24"]
[Tue Jul 21 07:31:51.030848 2026] [security2:error] [pid 229246:tid 229474] [client 20.197.195.24:13084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/media.php"] [unique_id "al9KlyBMYeh5YLVG45yW9AAAAnY"]
[Tue Jul 21 07:31:51.096738 2026] [security2:error] [pid 229246:tid 229445] [client 213.152.162.104:42006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9KlyBMYeh5YLVG45yW9QAAAlk"]
[Tue Jul 21 07:31:51.096810 2026] [security2:error] [pid 229246:tid 229445] [client 213.152.162.104:42006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9KlyBMYeh5YLVG45yW9QAAAlk"]
[Tue Jul 21 07:31:51.178034 2026] [autoindex:error] [pid 229246:tid 229309] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:51.189315 2026] [security2:error] [pid 229246:tid 229386] [client 20.151.10.161:50919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/koala.php"] [unique_id "al9KlyBMYeh5YLVG45yW-gAAAh4"]
[Tue Jul 21 07:31:51.225434 2026] [autoindex:error] [pid 229246:tid 229355] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:51.249894 2026] [security2:error] [pid 229246:tid 229368] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/abcd.php"] [unique_id "al9KlyBMYeh5YLVG45yW_wACXXk"]
[Tue Jul 21 07:31:51.332370 2026] [security2:error] [pid 229246:tid 229284] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/file15.php"] [unique_id "al9KlyBMYeh5YLVG45yXBwACPCU"]
[Tue Jul 21 07:31:51.385933 2026] [security2:error] [pid 229246:tid 229429] [client 122.186.204.214:57138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KlyBMYeh5YLVG45yXCAAAAkk"]
[Tue Jul 21 07:31:51.386095 2026] [security2:error] [pid 229246:tid 229429] [client 122.186.204.214:57138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KlyBMYeh5YLVG45yXCAAAAkk"]
[Tue Jul 21 07:31:51.428063 2026] [security2:error] [pid 229246:tid 229287] [remote 104.207.39.187:45425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.39.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9KlyBMYeh5YLVG45yXAQACVSg"]
[Tue Jul 21 07:31:51.691929 2026] [security2:error] [pid 229246:tid 229495] [client 45.8.17.138:24807] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/about.php"] [unique_id "al9KlyBMYeh5YLVG45yXEAAAAos"]
[Tue Jul 21 07:31:51.714852 2026] [security2:error] [pid 229246:tid 229488] [client 20.151.10.161:57374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/mac.php"] [unique_id "al9KlyBMYeh5YLVG45yXEgAAAoQ"]
[Tue Jul 21 07:31:52.012422 2026] [security2:error] [pid 229246:tid 229290] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KmCBMYeh5YLVG45yXFgACKys"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:52.016942 2026] [security2:error] [pid 229246:tid 229293] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KmCBMYeh5YLVG45yXGAACfS4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:52.048205 2026] [security2:error] [pid 229246:tid 229258] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KmCBMYeh5YLVG45yXGQACGQs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:52.055942 2026] [security2:error] [pid 229246:tid 229336] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/jp.php"] [unique_id "al9KmCBMYeh5YLVG45yXGgACFFk"]
[Tue Jul 21 07:31:52.122674 2026] [security2:error] [pid 229246:tid 229301] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KmCBMYeh5YLVG45yXGwACOjY"]
[Tue Jul 21 07:31:52.122916 2026] [security2:error] [pid 229246:tid 229414] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KmCBMYeh5YLVG45yXGwACOjY"]
[Tue Jul 21 07:31:52.125590 2026] [security2:error] [pid 229246:tid 229360] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/f35.php"] [unique_id "al9KmCBMYeh5YLVG45yXHAACfnE"]
[Tue Jul 21 07:31:52.147437 2026] [security2:error] [pid 229246:tid 229319] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/wp-load.php"] [unique_id "al9KmCBMYeh5YLVG45yXHQACI0g"]
[Tue Jul 21 07:31:52.178267 2026] [security2:error] [pid 229246:tid 229374] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KmCBMYeh5YLVG45yXFwACIX8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:52.193346 2026] [security2:error] [pid 229246:tid 229263] [remote 207.180.241.245:49690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9KmCBMYeh5YLVG45yXHgACKRA"]
[Tue Jul 21 07:31:52.558528 2026] [security2:error] [pid 229246:tid 229497] [client 103.106.20.201:65520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KmCBMYeh5YLVG45yXIAAAAo0"]
[Tue Jul 21 07:31:52.558652 2026] [security2:error] [pid 229246:tid 229497] [client 103.106.20.201:65520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KmCBMYeh5YLVG45yXIAAAAo0"]
[Tue Jul 21 07:31:53.050990 2026] [http2:info] [pid 254995:tid 254995] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 07:31:53.070677 2026] [security2:error] [pid 254995:tid 255126] [client 20.206.105.145:7191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/a.php"] [unique_id "al9Kmf7v0rlcEGmVraEfHQAAAx8"]
[Tue Jul 21 07:31:53.071245 2026] [security2:error] [pid 254995:tid 255125] [client 20.151.10.161:57400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9Kmf7v0rlcEGmVraEfHgAAAx4"]
[Tue Jul 21 07:31:53.071269 2026] [security2:error] [pid 254995:tid 255129] [client 20.197.195.24:13169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/images.php"] [unique_id "al9Kmf7v0rlcEGmVraEfHwAAAyI"]
[Tue Jul 21 07:31:53.072970 2026] [security2:error] [pid 254995:tid 255133] [client 45.8.17.122:43029] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/sitemaps/admin.php"] [unique_id "al9Kmf7v0rlcEGmVraEfIQAAAyY"]
[Tue Jul 21 07:31:53.072986 2026] [security2:error] [pid 254995:tid 255134] [client 20.220.225.223:8917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/wp-editor.php"] [unique_id "al9Kmf7v0rlcEGmVraEfIAAAAyc"]
[Tue Jul 21 07:31:53.077636 2026] [security2:error] [pid 254995:tid 255123] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/xyn.php"] [unique_id "al9Kmf7v0rlcEGmVraEfIwADIH8"]
[Tue Jul 21 07:31:53.106580 2026] [autoindex:error] [pid 254995:tid 254997] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:53.120625 2026] [security2:error] [pid 254995:tid 255152] [client 20.220.225.223:45978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/cro.php"] [unique_id "al9Kmf7v0rlcEGmVraEfJQAAAzk"]
[Tue Jul 21 07:31:53.208598 2026] [autoindex:error] [pid 254995:tid 254998] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:53.231576 2026] [security2:error] [pid 254995:tid 255003] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/ccc.php"] [unique_id "al9Kmf7v0rlcEGmVraEfLwADQgc"]
[Tue Jul 21 07:31:53.243419 2026] [security2:error] [pid 254995:tid 255005] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmf7v0rlcEGmVraEfMQADRgk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:53.243698 2026] [security2:error] [pid 254995:tid 255007] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmf7v0rlcEGmVraEfMwADSAs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:53.243795 2026] [security2:error] [pid 254995:tid 255006] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmf7v0rlcEGmVraEfMgADRwo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:53.243954 2026] [security2:error] [pid 254995:tid 255008] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmf7v0rlcEGmVraEfNAADSQw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:53.292570 2026] [security2:error] [pid 254995:tid 255009] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/w.php"] [unique_id "al9Kmf7v0rlcEGmVraEfNQADUg0"]
[Tue Jul 21 07:31:53.315070 2026] [security2:error] [pid 254995:tid 255011] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Kmf7v0rlcEGmVraEfNwADVA8"]
[Tue Jul 21 07:31:53.335923 2026] [security2:error] [pid 254995:tid 255012] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/FWAZ.php"] [unique_id "al9Kmf7v0rlcEGmVraEfOgADWhA"]
[Tue Jul 21 07:31:53.375891 2026] [security2:error] [pid 254995:tid 255137] [client 173.24.185.52:56361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Kmf7v0rlcEGmVraEfPAAAAyo"]
[Tue Jul 21 07:31:53.376036 2026] [security2:error] [pid 254995:tid 255137] [client 173.24.185.52:56361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Kmf7v0rlcEGmVraEfPAAAAyo"]
[Tue Jul 21 07:31:53.393915 2026] [security2:error] [pid 254995:tid 255014] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/miru1.php"] [unique_id "al9Kmf7v0rlcEGmVraEfPQADXRI"]
[Tue Jul 21 07:31:53.457941 2026] [security2:error] [pid 254995:tid 255018] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmf7v0rlcEGmVraEfQwADZxY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:53.468400 2026] [security2:error] [pid 254995:tid 255019] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmf7v0rlcEGmVraEfRQADahc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:53.490757 2026] [security2:error] [pid 254995:tid 255203] [client 20.220.225.223:4571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/fz.php"] [unique_id "al9Kmf7v0rlcEGmVraEfRwAAA2w"]
[Tue Jul 21 07:31:53.533789 2026] [security2:error] [pid 254995:tid 255021] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmf7v0rlcEGmVraEfSgADchk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:53.570043 2026] [security2:error] [pid 254995:tid 255022] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/aa.php"] [unique_id "al9Kmf7v0rlcEGmVraEfSwADcxo"]
[Tue Jul 21 07:31:53.584202 2026] [security2:error] [pid 254995:tid 255023] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kmf7v0rlcEGmVraEfTAADdxs"]
[Tue Jul 21 07:31:53.584317 2026] [security2:error] [pid 254995:tid 255215] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kmf7v0rlcEGmVraEfTAADdxs"]
[Tue Jul 21 07:31:53.592654 2026] [security2:error] [pid 254995:tid 255024] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Kmf7v0rlcEGmVraEfTQADeBw"]
[Tue Jul 21 07:31:53.592875 2026] [security2:error] [pid 254995:tid 255216] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Kmf7v0rlcEGmVraEfTQADeBw"]
[Tue Jul 21 07:31:53.608371 2026] [security2:error] [pid 254995:tid 255025] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/122.php"] [unique_id "al9Kmf7v0rlcEGmVraEfTgADeh0"]
[Tue Jul 21 07:31:53.683584 2026] [security2:error] [pid 254995:tid 255222] [client 20.151.10.161:57397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wefile.php"] [unique_id "al9Kmf7v0rlcEGmVraEfTwAAA34"]
[Tue Jul 21 07:31:53.695679 2026] [security2:error] [pid 254995:tid 255026] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmf7v0rlcEGmVraEfUAADfx4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:53.758770 2026] [security2:error] [pid 254995:tid 255027] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/get.php"] [unique_id "al9Kmf7v0rlcEGmVraEfUQADgR8"]
[Tue Jul 21 07:31:53.765726 2026] [security2:error] [pid 254995:tid 255139] [client 154.192.233.199:59426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kmf7v0rlcEGmVraEfUgAAAyw"]
[Tue Jul 21 07:31:53.765886 2026] [security2:error] [pid 254995:tid 255139] [client 154.192.233.199:59426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kmf7v0rlcEGmVraEfUgAAAyw"]
[Tue Jul 21 07:31:53.768913 2026] [security2:error] [pid 254995:tid 255028] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmf7v0rlcEGmVraEfUwADgiA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:53.778362 2026] [security2:error] [pid 254995:tid 255029] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/as.php"] [unique_id "al9Kmf7v0rlcEGmVraEfVAADgyE"]
[Tue Jul 21 07:31:53.804966 2026] [security2:error] [pid 254995:tid 255030] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmf7v0rlcEGmVraEfVQADfSI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:53.915069 2026] [security2:error] [pid 254995:tid 255031] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmf7v0rlcEGmVraEfVgADhyM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:53.927427 2026] [security2:error] [pid 254995:tid 255032] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/ccou.php"] [unique_id "al9Kmf7v0rlcEGmVraEfVwADiCQ"]
[Tue Jul 21 07:31:53.947903 2026] [security2:error] [pid 254995:tid 255033] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/w3lls.php"] [unique_id "al9Kmf7v0rlcEGmVraEfWAADiSU"]
[Tue Jul 21 07:31:53.968081 2026] [security2:error] [pid 254995:tid 255035] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/test1.php"] [unique_id "al9Kmf7v0rlcEGmVraEfXAADjSc"]
[Tue Jul 21 07:31:53.971146 2026] [security2:error] [pid 254995:tid 255265] [client 20.197.195.24:13179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/gecko.php"] [unique_id "al9Kmf7v0rlcEGmVraEfXQAAA48"]
[Tue Jul 21 07:31:53.989253 2026] [security2:error] [pid 254995:tid 255037] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/database.php"] [unique_id "al9Kmf7v0rlcEGmVraEfXwADlCk"]
[Tue Jul 21 07:31:54.001741 2026] [security2:error] [pid 254995:tid 255038] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmv7v0rlcEGmVraEfYAADlio"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:54.031183 2026] [security2:error] [pid 254995:tid 255039] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmv7v0rlcEGmVraEfYQADmSs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:54.039493 2026] [security2:error] [pid 254995:tid 255040] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmv7v0rlcEGmVraEfYgADmiw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:54.044256 2026] [security2:error] [pid 254995:tid 255041] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/file.php"] [unique_id "al9Kmv7v0rlcEGmVraEfYwADmy0"]
[Tue Jul 21 07:31:54.183535 2026] [security2:error] [pid 254995:tid 255046] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/file.php"] [unique_id "al9Kmv7v0rlcEGmVraEfawADNDI"]
[Tue Jul 21 07:31:54.203320 2026] [security2:error] [pid 254995:tid 255130] [client 172.245.102.46:38729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmv7v0rlcEGmVraEfbAAAAyM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:54.256210 2026] [security2:error] [pid 254995:tid 255148] [client 20.220.225.223:38673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/x.php"] [unique_id "al9Kmv7v0rlcEGmVraEfbQAAAzU"]
[Tue Jul 21 07:31:54.316426 2026] [security2:error] [pid 254995:tid 255151] [client 20.206.105.145:7367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/k.php"] [unique_id "al9Kmv7v0rlcEGmVraEfbgAAAzg"]
[Tue Jul 21 07:31:54.378430 2026] [security2:error] [pid 254995:tid 255047] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/777.php"] [unique_id "al9Kmv7v0rlcEGmVraEfbwADPDM"]
[Tue Jul 21 07:31:54.389015 2026] [security2:error] [pid 254995:tid 255158] [client 20.220.225.223:9222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/wpx.php"] [unique_id "al9Kmv7v0rlcEGmVraEfcAAAAz8"]
[Tue Jul 21 07:31:54.426571 2026] [proxy:error] [pid 254995:tid 255162] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:54.426612 2026] [proxy_http:error] [pid 254995:tid 255162] [client 20.151.10.161:51275] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:54.427176 2026] [proxy:error] [pid 254995:tid 255162] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:54.427197 2026] [proxy_http:error] [pid 254995:tid 255162] [client 20.151.10.161:51275] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:54.432960 2026] [security2:error] [pid 254995:tid 255224] [client 175.45.70.82:50931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kmv7v0rlcEGmVraEfcgAAA4A"]
[Tue Jul 21 07:31:54.433100 2026] [security2:error] [pid 254995:tid 255224] [client 175.45.70.82:50931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kmv7v0rlcEGmVraEfcgAAA4A"]
[Tue Jul 21 07:31:54.601772 2026] [security2:error] [pid 254995:tid 255051] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/ssixta.php"] [unique_id "al9Kmv7v0rlcEGmVraEfegADSzc"]
[Tue Jul 21 07:31:54.678496 2026] [security2:error] [pid 254995:tid 255172] [client 45.8.17.59:52259] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/js/widgets/maint/"] [unique_id "al9Kmv7v0rlcEGmVraEffQAAA00"]
[Tue Jul 21 07:31:54.753679 2026] [security2:error] [pid 254995:tid 255141] [client 103.174.34.15:59511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kmv7v0rlcEGmVraEffgAAAy4"]
[Tue Jul 21 07:31:54.753822 2026] [security2:error] [pid 254995:tid 255141] [client 103.174.34.15:59511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kmv7v0rlcEGmVraEffgAAAy4"]
[Tue Jul 21 07:31:54.807298 2026] [security2:error] [pid 254995:tid 255054] [remote 113.160.142.119:43426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "umapsicologiaqueprovoca.com"] [uri "/wp-login.php"] [unique_id "al9Kmv7v0rlcEGmVraEffwADMzo"]
[Tue Jul 21 07:31:54.989172 2026] [security2:error] [pid 254995:tid 255057] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/1c.php"] [unique_id "al9Kmv7v0rlcEGmVraEfhgADXD0"]
[Tue Jul 21 07:31:55.042758 2026] [security2:error] [pid 254995:tid 255152] [client 45.251.232.145:64553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Km_7v0rlcEGmVraEfiwAAAzk"]
[Tue Jul 21 07:31:55.042887 2026] [security2:error] [pid 254995:tid 255152] [client 45.251.232.145:64553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Km_7v0rlcEGmVraEfiwAAAzk"]
[Tue Jul 21 07:31:55.212636 2026] [security2:error] [pid 254995:tid 255062] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/test2.php"] [unique_id "al9Km_7v0rlcEGmVraEfkgADdEI"]
[Tue Jul 21 07:31:55.226892 2026] [security2:error] [pid 254995:tid 255213] [client 20.197.195.24:13162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/82.php"] [unique_id "al9Km_7v0rlcEGmVraEfkwAAA3U"]
[Tue Jul 21 07:31:55.234027 2026] [security2:error] [pid 254995:tid 255063] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/buy.php"] [unique_id "al9Km_7v0rlcEGmVraEflAADdkM"]
[Tue Jul 21 07:31:55.277407 2026] [security2:error] [pid 254995:tid 255064] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/ssend.php"] [unique_id "al9Km_7v0rlcEGmVraEflQADO0Q"]
[Tue Jul 21 07:31:55.366965 2026] [security2:error] [pid 254995:tid 255215] [client 213.152.162.104:37236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Km_7v0rlcEGmVraEflgAAA3c"]
[Tue Jul 21 07:31:55.367082 2026] [security2:error] [pid 254995:tid 255215] [client 213.152.162.104:37236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Km_7v0rlcEGmVraEflgAAA3c"]
[Tue Jul 21 07:31:55.416894 2026] [security2:error] [pid 254995:tid 255066] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/item.php"] [unique_id "al9Km_7v0rlcEGmVraEfmgADekY"]
[Tue Jul 21 07:31:55.553206 2026] [proxy:error] [pid 254995:tid 255178] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:55.553276 2026] [proxy_http:error] [pid 254995:tid 255178] [client 20.151.10.161:50906] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:55.553802 2026] [proxy:error] [pid 254995:tid 255178] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:55.553833 2026] [proxy_http:error] [pid 254995:tid 255178] [client 20.151.10.161:50906] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:55.669981 2026] [security2:error] [pid 254995:tid 255071] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/ss.php"] [unique_id "al9Km_7v0rlcEGmVraEfpgADkEs"]
[Tue Jul 21 07:31:55.684491 2026] [security2:error] [pid 254995:tid 255185] [client 122.129.67.13:60578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9Km_7v0rlcEGmVraEfpAAAA1o"]
[Tue Jul 21 07:31:55.688349 2026] [security2:error] [pid 254995:tid 255072] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/hypo.php"] [unique_id "al9Km_7v0rlcEGmVraEfpwADikw"]
[Tue Jul 21 07:31:55.785218 2026] [security2:error] [pid 254995:tid 255275] [client 45.8.17.114:59261] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/languages/classwithtostring.php"] [unique_id "al9Km_7v0rlcEGmVraEfqgAAA5k"]
[Tue Jul 21 07:31:56.061136 2026] [security2:error] [pid 254995:tid 255182] [client 152.59.154.239:60788] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KnP7v0rlcEGmVraEfqwAAA1c"]
[Tue Jul 21 07:31:56.061349 2026] [security2:error] [pid 254995:tid 255182] [client 152.59.154.239:60788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KnP7v0rlcEGmVraEfqwAAA1c"]
[Tue Jul 21 07:31:56.135862 2026] [security2:error] [pid 254995:tid 255153] [client 20.206.105.145:54576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/w.php"] [unique_id "al9KnP7v0rlcEGmVraEfswAAAzo"]
[Tue Jul 21 07:31:56.156243 2026] [security2:error] [pid 254995:tid 255078] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/users.php"] [unique_id "al9KnP7v0rlcEGmVraEftAADPFI"]
[Tue Jul 21 07:31:56.242747 2026] [security2:error] [pid 254995:tid 255079] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/177.php"] [unique_id "al9KnP7v0rlcEGmVraEftQADP1M"]
[Tue Jul 21 07:31:56.339684 2026] [security2:error] [pid 254995:tid 255081] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/config.php"] [unique_id "al9KnP7v0rlcEGmVraEftwADPVU"]
[Tue Jul 21 07:31:56.361297 2026] [security2:error] [pid 254995:tid 255082] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/gettest.php"] [unique_id "al9KnP7v0rlcEGmVraEfuAADKFY"]
[Tue Jul 21 07:31:56.441239 2026] [security2:error] [pid 254995:tid 255274] [client 117.217.38.194:53643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KnP7v0rlcEGmVraEfuQAAA5g"]
[Tue Jul 21 07:31:56.441405 2026] [security2:error] [pid 254995:tid 255274] [client 117.217.38.194:53643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KnP7v0rlcEGmVraEfuQAAA5g"]
[Tue Jul 21 07:31:56.484280 2026] [security2:error] [pid 254995:tid 255165] [client 82.102.28.107:33976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KnP7v0rlcEGmVraEfvQAAA0Y"]
[Tue Jul 21 07:31:56.484415 2026] [security2:error] [pid 254995:tid 255165] [client 82.102.28.107:33976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KnP7v0rlcEGmVraEfvQAAA0Y"]
[Tue Jul 21 07:31:56.484656 2026] [security2:error] [pid 254995:tid 255083] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/min.php"] [unique_id "al9KnP7v0rlcEGmVraEfvAADSFc"]
[Tue Jul 21 07:31:56.507067 2026] [security2:error] [pid 254995:tid 255084] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/dvjul.php"] [unique_id "al9KnP7v0rlcEGmVraEfvgADRFg"]
[Tue Jul 21 07:31:56.517148 2026] [security2:error] [pid 254995:tid 255085] [remote 192.241.143.148:40094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9KnP7v0rlcEGmVraEfvwADQFk"]
[Tue Jul 21 07:31:56.545644 2026] [security2:error] [pid 254995:tid 255168] [client 20.220.225.223:46139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/cron-tab.php"] [unique_id "al9KnP7v0rlcEGmVraEfwQAAA0k"]
[Tue Jul 21 07:31:56.619495 2026] [security2:error] [pid 254995:tid 255089] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/biufile.php"] [unique_id "al9KnP7v0rlcEGmVraEfxwADPl0"]
[Tue Jul 21 07:31:56.642214 2026] [security2:error] [pid 254995:tid 255090] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/av.php"] [unique_id "al9KnP7v0rlcEGmVraEfyQADLl4"]
[Tue Jul 21 07:31:56.670630 2026] [security2:error] [pid 254995:tid 255092] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/coffexium.php"] [unique_id "al9KnP7v0rlcEGmVraEfywADUmA"]
[Tue Jul 21 07:31:56.696029 2026] [security2:error] [pid 254995:tid 255093] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/core.php"] [unique_id "al9KnP7v0rlcEGmVraEfzAADM2E"]
[Tue Jul 21 07:31:56.736272 2026] [security2:error] [pid 254995:tid 255094] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/als.php"] [unique_id "al9KnP7v0rlcEGmVraEfzQADWGI"]
[Tue Jul 21 07:31:56.758206 2026] [security2:error] [pid 254995:tid 255095] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/simple.php"] [unique_id "al9KnP7v0rlcEGmVraEfzgADXWM"]
[Tue Jul 21 07:31:56.778302 2026] [security2:error] [pid 254995:tid 255096] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/init.php"] [unique_id "al9KnP7v0rlcEGmVraEfzwADKmQ"]
[Tue Jul 21 07:31:56.799927 2026] [security2:error] [pid 254995:tid 255097] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/fpwch.php"] [unique_id "al9KnP7v0rlcEGmVraEf0AADX2U"]
[Tue Jul 21 07:31:56.810273 2026] [security2:error] [pid 254995:tid 255173] [client 20.197.195.24:13145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/admin.php"] [unique_id "al9KnP7v0rlcEGmVraEf0QAAA04"]
[Tue Jul 21 07:31:56.823949 2026] [security2:error] [pid 254995:tid 255098] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/domvf.php"] [unique_id "al9KnP7v0rlcEGmVraEf0gADXGY"]
[Tue Jul 21 07:31:56.845477 2026] [security2:error] [pid 254995:tid 255099] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/wp.php"] [unique_id "al9KnP7v0rlcEGmVraEf0wADZ2c"]
[Tue Jul 21 07:31:56.883818 2026] [security2:error] [pid 254995:tid 255202] [client 45.8.17.129:62363] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "al9KnP7v0rlcEGmVraEf1AAAA2s"]
[Tue Jul 21 07:31:56.908470 2026] [security2:error] [pid 254995:tid 255100] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/class.php"] [unique_id "al9KnP7v0rlcEGmVraEf1QADbGg"]
[Tue Jul 21 07:31:57.154739 2026] [security2:error] [pid 254995:tid 255208] [client 20.220.225.223:19652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/wicked.php"] [unique_id "al9Knf7v0rlcEGmVraEf3AAAA3A"]
[Tue Jul 21 07:31:57.162885 2026] [security2:error] [pid 254995:tid 255103] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Knf7v0rlcEGmVraEf3QADYGs"]
[Tue Jul 21 07:31:57.163005 2026] [security2:error] [pid 254995:tid 255191] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Knf7v0rlcEGmVraEf3QADYGs"]
[Tue Jul 21 07:31:57.289017 2026] [security2:error] [pid 254995:tid 255106] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/echkm.php"] [unique_id "al9Knf7v0rlcEGmVraEf4gADUW4"]
[Tue Jul 21 07:31:57.354166 2026] [security2:error] [pid 254995:tid 255209] [client 20.206.105.145:7461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/insc.php"] [unique_id "al9Knf7v0rlcEGmVraEf4wAAA3E"]
[Tue Jul 21 07:31:57.415967 2026] [security2:error] [pid 254995:tid 255220] [client 20.151.10.161:50922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Knf7v0rlcEGmVraEf5AAAA3w"]
[Tue Jul 21 07:31:57.558177 2026] [security2:error] [pid 254995:tid 255108] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Knf7v0rlcEGmVraEf6AADhXA"]
[Tue Jul 21 07:31:57.558385 2026] [security2:error] [pid 254995:tid 255255] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Knf7v0rlcEGmVraEf6AADhXA"]
[Tue Jul 21 07:31:57.560627 2026] [security2:error] [pid 254995:tid 255109] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/lib.php"] [unique_id "al9Knf7v0rlcEGmVraEf6QADg3E"]
[Tue Jul 21 07:31:57.621056 2026] [security2:error] [pid 254995:tid 255111] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/login.php"] [unique_id "al9Knf7v0rlcEGmVraEf6wADU3M"]
[Tue Jul 21 07:31:57.638796 2026] [security2:error] [pid 254995:tid 255112] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/a2.php"] [unique_id "al9Knf7v0rlcEGmVraEf7gADgXQ"]
[Tue Jul 21 07:31:57.657458 2026] [security2:error] [pid 254995:tid 255113] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/d61.php"] [unique_id "al9Knf7v0rlcEGmVraEf7wADVnU"]
[Tue Jul 21 07:31:57.687833 2026] [security2:error] [pid 254995:tid 255264] [client 45.8.17.65:27709] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/colors/modern/test2.php"] [unique_id "al9Knf7v0rlcEGmVraEf8gAAA44"]
[Tue Jul 21 07:31:57.779704 2026] [security2:error] [pid 254995:tid 255116] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/info.php"] [unique_id "al9Knf7v0rlcEGmVraEf9QADlXg"]
[Tue Jul 21 07:31:57.809967 2026] [security2:error] [pid 254995:tid 255117] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/11.php"] [unique_id "al9Knf7v0rlcEGmVraEf9gADmnk"]
[Tue Jul 21 07:31:57.830124 2026] [security2:error] [pid 254995:tid 255118] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/v2.php"] [unique_id "al9Knf7v0rlcEGmVraEf9wADm3o"]
[Tue Jul 21 07:31:57.867984 2026] [security2:error] [pid 254995:tid 255120] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/panel.php"] [unique_id "al9Knf7v0rlcEGmVraEf-QADMnw"]
[Tue Jul 21 07:31:57.910195 2026] [security2:error] [pid 254995:tid 255121] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/dex.php"] [unique_id "al9Knf7v0rlcEGmVraEf-gADNn0"]
[Tue Jul 21 07:31:58.036597 2026] [security2:error] [pid 254995:tid 255122] [remote 20.197.195.24:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mcandidoadvocacia.com.br"] [uri "/1.php"] [unique_id "al9Knv7v0rlcEGmVraEf-wADI34"]
[Tue Jul 21 07:31:58.036695 2026] [security2:error] [pid 254995:tid 255122] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/1.php"] [unique_id "al9Knv7v0rlcEGmVraEf-wADI34"]
[Tue Jul 21 07:31:58.059296 2026] [autoindex:error] [pid 254995:tid 255148] [client 172.252.90.143:0] AH01276: Cannot serve directory /home2/inlaud99/distribuidorasja.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:58.066075 2026] [security2:error] [pid 254995:tid 254996] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Knv7v0rlcEGmVraEf_wADnQA"]
[Tue Jul 21 07:31:58.066194 2026] [security2:error] [pid 254995:tid 255279] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Knv7v0rlcEGmVraEf_wADnQA"]
[Tue Jul 21 07:31:58.099854 2026] [security2:error] [pid 254995:tid 255123] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/ms.php"] [unique_id "al9Knv7v0rlcEGmVraEgAAADk38"]
[Tue Jul 21 07:31:58.302744 2026] [security2:error] [pid 254995:tid 255157] [client 20.206.105.145:39250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/w2025.php"] [unique_id "al9Knv7v0rlcEGmVraEgCgAAAz4"]
[Tue Jul 21 07:31:58.320947 2026] [security2:error] [pid 254995:tid 255172] [client 20.52.136.55:1779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/item.php"] [unique_id "al9Knv7v0rlcEGmVraEgCwAAA00"]
[Tue Jul 21 07:31:58.412091 2026] [security2:error] [pid 254995:tid 255007] [remote 162.19.246.208:55188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9Knv7v0rlcEGmVraEgDQADJws"]
[Tue Jul 21 07:31:58.522711 2026] [security2:error] [pid 254995:tid 255141] [client 173.252.95.13:56210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Knv7v0rlcEGmVraEgDwAAAy4"]
[Tue Jul 21 07:31:58.545031 2026] [autoindex:error] [pid 254995:tid 255006] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:58.557780 2026] [security2:error] [pid 254995:tid 255137] [client 20.151.10.161:50937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/2P.php"] [unique_id "al9Knv7v0rlcEGmVraEgEAAAAyo"]
[Tue Jul 21 07:31:58.597784 2026] [security2:error] [pid 254995:tid 255202] [client 20.220.225.223:45968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/koiy.php"] [unique_id "al9Knv7v0rlcEGmVraEgFAAAA2s"]
[Tue Jul 21 07:31:58.656761 2026] [core:alert] [pid 254995:tid 255197] [client 57.141.18.32:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:31:58.787201 2026] [security2:error] [pid 254995:tid 255220] [client 45.8.17.148:61255] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentyfive/parts/"] [unique_id "al9Knv7v0rlcEGmVraEgIAAAA3w"]
[Tue Jul 21 07:31:58.852077 2026] [security2:error] [pid 254995:tid 255255] [client 20.206.105.145:7700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Knv7v0rlcEGmVraEgIgAAA4U"]
[Tue Jul 21 07:31:58.965852 2026] [security2:error] [pid 254995:tid 255014] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/memberfuns.php"] [unique_id "al9Knv7v0rlcEGmVraEgJQADhxI"]
[Tue Jul 21 07:31:58.985566 2026] [security2:error] [pid 254995:tid 255018] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/0.php"] [unique_id "al9Knv7v0rlcEGmVraEgJgADihY"]
[Tue Jul 21 07:31:59.005196 2026] [security2:error] [pid 254995:tid 255019] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/BDKR28.php"] [unique_id "al9Kn_7v0rlcEGmVraEgJwADWhc"]
[Tue Jul 21 07:31:59.042981 2026] [security2:error] [pid 254995:tid 255216] [client 172.245.102.42:40739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Kn_7v0rlcEGmVraEgKAAAA3g"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:59.080334 2026] [security2:error] [pid 254995:tid 255016] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/green1.php"] [unique_id "al9Kn_7v0rlcEGmVraEgKQADlBQ"]
[Tue Jul 21 07:31:59.105384 2026] [security2:error] [pid 254995:tid 255017] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/nc4.php"] [unique_id "al9Kn_7v0rlcEGmVraEgKgADmRU"]
[Tue Jul 21 07:31:59.130341 2026] [security2:error] [pid 254995:tid 255021] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/a1.php"] [unique_id "al9Kn_7v0rlcEGmVraEgKwADmhk"]
[Tue Jul 21 07:31:59.142216 2026] [security2:error] [pid 254995:tid 255126] [client 20.151.10.161:50921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/.well-known/about.php"] [unique_id "al9Kn_7v0rlcEGmVraEgLAAAAx8"]
[Tue Jul 21 07:31:59.150210 2026] [security2:error] [pid 254995:tid 255022] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/eee.php"] [unique_id "al9Kn_7v0rlcEGmVraEgLQADIho"]
[Tue Jul 21 07:31:59.172205 2026] [security2:error] [pid 254995:tid 255023] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/wp-aothait.php"] [unique_id "al9Kn_7v0rlcEGmVraEgMAADNhs"]
[Tue Jul 21 07:31:59.190806 2026] [security2:error] [pid 254995:tid 255020] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/config.json.php"] [unique_id "al9Kn_7v0rlcEGmVraEgMQADIxg"]
[Tue Jul 21 07:31:59.211467 2026] [security2:error] [pid 254995:tid 255024] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9Kn_7v0rlcEGmVraEgMgADnBw"]
[Tue Jul 21 07:31:59.215231 2026] [security2:error] [pid 254995:tid 255179] [client 59.96.220.140:60414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Kn_7v0rlcEGmVraEgMwAAA1Q"]
[Tue Jul 21 07:31:59.215319 2026] [security2:error] [pid 254995:tid 255179] [client 59.96.220.140:60414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Kn_7v0rlcEGmVraEgMwAAA1Q"]
[Tue Jul 21 07:31:59.229976 2026] [security2:error] [pid 254995:tid 255025] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/k2.php"] [unique_id "al9Kn_7v0rlcEGmVraEgNAADnR0"]
[Tue Jul 21 07:31:59.395387 2026] [security2:error] [pid 254995:tid 255172] [client 20.220.225.223:8908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/cro.php"] [unique_id "al9Kn_7v0rlcEGmVraEgPQAAA00"]
[Tue Jul 21 07:31:59.457416 2026] [security2:error] [pid 254995:tid 255164] [client 20.197.195.24:13129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/adminner.php"] [unique_id "al9Kn_7v0rlcEGmVraEgPgAAA0U"]
[Tue Jul 21 07:31:59.463105 2026] [security2:error] [pid 254995:tid 255177] [client 20.151.10.161:57382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9Kn_7v0rlcEGmVraEgPwAAA1I"]
[Tue Jul 21 07:31:59.995735 2026] [security2:error] [pid 254995:tid 255152] [client 20.151.10.161:57453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/bob.php"] [unique_id "al9Kn_7v0rlcEGmVraEgUwAAAzk"]
[Tue Jul 21 07:32:00.003783 2026] [security2:error] [pid 254995:tid 255034] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9KoP7v0rlcEGmVraEgVAADdiY"]
[Tue Jul 21 07:32:00.023885 2026] [security2:error] [pid 254995:tid 255037] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9KoP7v0rlcEGmVraEgVQADUCk"]
[Tue Jul 21 07:32:00.059909 2026] [security2:error] [pid 254995:tid 255039] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9KoP7v0rlcEGmVraEgVwADYCs"]
[Tue Jul 21 07:32:00.079688 2026] [security2:error] [pid 254995:tid 255040] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/for.php"] [unique_id "al9KoP7v0rlcEGmVraEgWgADUSw"]
[Tue Jul 21 07:32:00.089293 2026] [security2:error] [pid 254995:tid 255223] [client 45.8.17.146:53091] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/query-title/"] [unique_id "al9KoP7v0rlcEGmVraEgWwAAA38"]
[Tue Jul 21 07:32:00.105900 2026] [security2:error] [pid 254995:tid 255186] [client 20.220.225.223:6803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/berlin.php"] [unique_id "al9KoP7v0rlcEGmVraEgXAAAA1s"]
[Tue Jul 21 07:32:00.140408 2026] [security2:error] [pid 254995:tid 255041] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/raw.php"] [unique_id "al9KoP7v0rlcEGmVraEgXQADgi0"]
[Tue Jul 21 07:32:00.268513 2026] [security2:error] [pid 254995:tid 255252] [client 20.220.225.223:19289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/edit.php"] [unique_id "al9KoP7v0rlcEGmVraEgXwAAA4M"]
[Tue Jul 21 07:32:00.489546 2026] [proxy:error] [pid 254995:tid 255151] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:00.489619 2026] [proxy_http:error] [pid 254995:tid 255151] [client 20.151.10.161:57353] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:00.490269 2026] [proxy:error] [pid 254995:tid 255151] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:00.490310 2026] [proxy_http:error] [pid 254995:tid 255151] [client 20.151.10.161:57353] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:00.528556 2026] [security2:error] [pid 254995:tid 255133] [client 74.7.175.162:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "michaellacerda1748029545263.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9KoP7v0rlcEGmVraEgawADJig"]
[Tue Jul 21 07:32:00.563355 2026] [security2:error] [pid 254995:tid 255048] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KoP7v0rlcEGmVraEgbQADVDQ"]
[Tue Jul 21 07:32:00.563489 2026] [security2:error] [pid 254995:tid 255179] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KoP7v0rlcEGmVraEgbQADVDQ"]
[Tue Jul 21 07:32:00.781537 2026] [security2:error] [pid 254995:tid 255163] [client 213.152.162.104:54550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9KoP7v0rlcEGmVraEgbgAAA0Q"]
[Tue Jul 21 07:32:00.781646 2026] [security2:error] [pid 254995:tid 255163] [client 213.152.162.104:54550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9KoP7v0rlcEGmVraEgbgAAA0Q"]
[Tue Jul 21 07:32:01.020674 2026] [security2:error] [pid 254995:tid 255051] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kof7v0rlcEGmVraEgdgADjTc"]
[Tue Jul 21 07:32:01.020834 2026] [security2:error] [pid 254995:tid 255263] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kof7v0rlcEGmVraEgdgADjTc"]
[Tue Jul 21 07:32:01.175378 2026] [security2:error] [pid 254995:tid 255132] [client 20.197.195.24:13086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/admin.php"] [unique_id "al9Kof7v0rlcEGmVraEgeQAAAyU"]
[Tue Jul 21 07:32:01.211972 2026] [security2:error] [pid 254995:tid 255055] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kof7v0rlcEGmVraEgewADMzs"]
[Tue Jul 21 07:32:01.212148 2026] [security2:error] [pid 254995:tid 255146] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kof7v0rlcEGmVraEgewADMzs"]
[Tue Jul 21 07:32:01.291491 2026] [security2:error] [pid 254995:tid 255256] [client 139.167.225.182:59918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kof7v0rlcEGmVraEgfQAAA4Y"]
[Tue Jul 21 07:32:01.291625 2026] [security2:error] [pid 254995:tid 255256] [client 139.167.225.182:59918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kof7v0rlcEGmVraEgfQAAA4Y"]
[Tue Jul 21 07:32:01.294606 2026] [proxy:error] [pid 254995:tid 255218] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:01.294659 2026] [proxy_http:error] [pid 254995:tid 255218] [client 20.151.10.161:50932] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:01.295520 2026] [proxy:error] [pid 254995:tid 255218] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:01.295552 2026] [proxy_http:error] [pid 254995:tid 255218] [client 20.151.10.161:50932] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:01.480011 2026] [security2:error] [pid 254995:tid 255152] [client 20.220.225.223:38669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9Kof7v0rlcEGmVraEgiAAAAzk"]
[Tue Jul 21 07:32:01.508605 2026] [security2:error] [pid 254995:tid 255175] [client 20.220.225.223:9266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/billur.php"] [unique_id "al9Kof7v0rlcEGmVraEgiQAAA1A"]
[Tue Jul 21 07:32:01.563787 2026] [security2:error] [pid 254995:tid 255206] [client 20.206.105.145:7696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/u.php"] [unique_id "al9Kof7v0rlcEGmVraEgigAAA28"]
[Tue Jul 21 07:32:01.597911 2026] [security2:error] [pid 254995:tid 255144] [client 45.8.17.61:48947] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/config.php"] [unique_id "al9Kof7v0rlcEGmVraEgiwAAAzE"]
[Tue Jul 21 07:32:01.759591 2026] [security2:error] [pid 254995:tid 255162] [client 103.162.129.114:57816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Kof7v0rlcEGmVraEgjQAAA0M"]
[Tue Jul 21 07:32:01.759719 2026] [security2:error] [pid 254995:tid 255162] [client 103.162.129.114:57816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Kof7v0rlcEGmVraEgjQAAA0M"]
[Tue Jul 21 07:32:01.863065 2026] [security2:error] [pid 254995:tid 255064] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kof7v0rlcEGmVraEgjAADfEQ"]
[Tue Jul 21 07:32:01.863273 2026] [security2:error] [pid 254995:tid 255220] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kof7v0rlcEGmVraEgjAADfEQ"]
[Tue Jul 21 07:32:02.083619 2026] [security2:error] [pid 254995:tid 255190] [client 122.186.204.214:57636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kov7v0rlcEGmVraEgnAAAA18"]
[Tue Jul 21 07:32:02.083846 2026] [security2:error] [pid 254995:tid 255190] [client 122.186.204.214:57636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kov7v0rlcEGmVraEgnAAAA18"]
[Tue Jul 21 07:32:02.440282 2026] [security2:error] [pid 254995:tid 255167] [client 20.151.10.161:57434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/crgio.php"] [unique_id "al9Kov7v0rlcEGmVraEgowAAA0g"]
[Tue Jul 21 07:32:02.632188 2026] [core:error] [pid 254995:tid 255075] [remote 74.7.230.22:59558] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:32:02.632215 2026] [core:error] [pid 254995:tid 255075] [remote 74.7.230.22:59558] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:32:02.632380 2026] [security2:error] [pid 254995:tid 255147] [client 74.7.230.22:59558] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "limaradiologiadigital.com.br.limaradiologiadigital.com.br"] [uri "/index.php"] [unique_id "al9Kov7v0rlcEGmVraEgpwADNE8"]
[Tue Jul 21 07:32:02.738653 2026] [security2:error] [pid 254995:tid 255074] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kov7v0rlcEGmVraEgqAADLU4"]
[Tue Jul 21 07:32:02.738867 2026] [security2:error] [pid 254995:tid 255140] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kov7v0rlcEGmVraEgqAADLU4"]
[Tue Jul 21 07:32:02.984360 2026] [security2:error] [pid 254995:tid 255201] [client 20.206.105.145:38924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/scxy.php"] [unique_id "al9Kov7v0rlcEGmVraEgsgAAA2o"]
[Tue Jul 21 07:32:02.989433 2026] [security2:error] [pid 254995:tid 255208] [client 45.8.17.126:29699] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/images/"] [unique_id "al9Kov7v0rlcEGmVraEgswAAA3A"]
[Tue Jul 21 07:32:03.035591 2026] [security2:error] [pid 254995:tid 255171] [client 20.220.225.223:19325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/kua.php"] [unique_id "al9Ko_7v0rlcEGmVraEgtAAAA0w"]
[Tue Jul 21 07:32:03.197637 2026] [security2:error] [pid 254995:tid 255082] [remote 198.244.242.28:45266] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "upitech.com.br"] [uri "/robots.txt"] [unique_id "al9Ko_7v0rlcEGmVraEgtgADWFY"]
[Tue Jul 21 07:32:03.197847 2026] [security2:error] [pid 254995:tid 255183] [client 198.244.242.28:45266] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "upitech.com.br"] [uri "/robots.txt"] [unique_id "al9Ko_7v0rlcEGmVraEgtgADWFY"]
[Tue Jul 21 07:32:03.338421 2026] [security2:error] [pid 254995:tid 255156] [client 103.106.20.201:49962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ko_7v0rlcEGmVraEgtwAAAz0"]
[Tue Jul 21 07:32:03.338567 2026] [security2:error] [pid 254995:tid 255156] [client 103.106.20.201:49962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ko_7v0rlcEGmVraEgtwAAAz0"]
[Tue Jul 21 07:32:03.504690 2026] [security2:error] [pid 254995:tid 255261] [client 20.151.10.161:57364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/pucci.php"] [unique_id "al9Ko_7v0rlcEGmVraEgwAAAA4s"]
[Tue Jul 21 07:32:03.633123 2026] [security2:error] [pid 254995:tid 255206] [client 173.24.185.52:56832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Ko_7v0rlcEGmVraEgwgAAA28"]
[Tue Jul 21 07:32:03.633311 2026] [security2:error] [pid 254995:tid 255206] [client 173.24.185.52:56832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Ko_7v0rlcEGmVraEgwgAAA28"]
[Tue Jul 21 07:32:03.716789 2026] [security2:error] [pid 254995:tid 255216] [client 62.102.148.164:57184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Ko_7v0rlcEGmVraEgxAAAA3g"]
[Tue Jul 21 07:32:03.716906 2026] [security2:error] [pid 254995:tid 255216] [client 62.102.148.164:57184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Ko_7v0rlcEGmVraEgxAAAA3g"]
[Tue Jul 21 07:32:03.831601 2026] [security2:error] [pid 254995:tid 255176] [client 172.245.102.45:40589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Ko_7v0rlcEGmVraEgxgAAA1E"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:03.895634 2026] [security2:error] [pid 254995:tid 255276] [client 20.197.195.24:13182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/k.php"] [unique_id "al9Ko_7v0rlcEGmVraEgyAAAA5o"]
[Tue Jul 21 07:32:03.896739 2026] [proxy:error] [pid 254995:tid 255270] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:03.896823 2026] [proxy_http:error] [pid 254995:tid 255270] [client 20.151.10.161:57344] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:03.897791 2026] [proxy:error] [pid 254995:tid 255270] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:03.897826 2026] [proxy_http:error] [pid 254995:tid 255270] [client 20.151.10.161:57344] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:04.106407 2026] [security2:error] [pid 254995:tid 255091] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KpP7v0rlcEGmVraEg0QADlV8"]
[Tue Jul 21 07:32:04.106570 2026] [security2:error] [pid 254995:tid 255271] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KpP7v0rlcEGmVraEg0QADlV8"]
[Tue Jul 21 07:32:04.186252 2026] [security2:error] [pid 254995:tid 255159] [client 45.8.17.125:42459] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/index-string.php"] [unique_id "al9KpP7v0rlcEGmVraEg0wAAA0A"]
[Tue Jul 21 07:32:04.213096 2026] [security2:error] [pid 254995:tid 255094] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KpP7v0rlcEGmVraEg1AADH2I"]
[Tue Jul 21 07:32:04.213233 2026] [security2:error] [pid 254995:tid 255126] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KpP7v0rlcEGmVraEg1AADH2I"]
[Tue Jul 21 07:32:04.287630 2026] [security2:error] [pid 254995:tid 255257] [client 154.192.233.199:59862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KpP7v0rlcEGmVraEg1wAAA4c"]
[Tue Jul 21 07:32:04.287769 2026] [security2:error] [pid 254995:tid 255257] [client 154.192.233.199:59862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KpP7v0rlcEGmVraEg1wAAA4c"]
[Tue Jul 21 07:32:04.301447 2026] [proxy:error] [pid 254995:tid 255274] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:04.301508 2026] [proxy_http:error] [pid 254995:tid 255274] [client 20.151.10.161:51306] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:04.302432 2026] [proxy:error] [pid 254995:tid 255274] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:04.302473 2026] [proxy_http:error] [pid 254995:tid 255274] [client 20.151.10.161:51306] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:04.499500 2026] [security2:error] [pid 254995:tid 255269] [client 20.206.105.145:7725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/sss.php"] [unique_id "al9KpP7v0rlcEGmVraEg3AAAA5M"]
[Tue Jul 21 07:32:04.604490 2026] [security2:error] [pid 254995:tid 255199] [client 20.206.105.145:38930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/FWAZ.php"] [unique_id "al9KpP7v0rlcEGmVraEg5gAAA2g"]
[Tue Jul 21 07:32:04.674695 2026] [security2:error] [pid 254995:tid 255259] [client 175.45.70.82:51528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KpP7v0rlcEGmVraEg6AAAA4k"]
[Tue Jul 21 07:32:04.674846 2026] [security2:error] [pid 254995:tid 255259] [client 175.45.70.82:51528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KpP7v0rlcEGmVraEg6AAAA4k"]
[Tue Jul 21 07:32:04.707699 2026] [security2:error] [pid 254995:tid 255152] [client 20.220.225.223:6122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/kq1.php"] [unique_id "al9KpP7v0rlcEGmVraEg6gAAAzk"]
[Tue Jul 21 07:32:04.755229 2026] [security2:error] [pid 254995:tid 255103] [remote 142.44.233.186:37744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "upitech.com.br"] [uri "/"] [unique_id "al9KpP7v0rlcEGmVraEg6wADaWs"]
[Tue Jul 21 07:32:04.755862 2026] [security2:error] [pid 254995:tid 255200] [client 142.44.233.186:37744] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "upitech.com.br"] [uri "/"] [unique_id "al9KpP7v0rlcEGmVraEg6wADaWs"]
[Tue Jul 21 07:32:04.763254 2026] [security2:error] [pid 254995:tid 255212] [client 20.151.10.161:58020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-temp.php"] [unique_id "al9KpP7v0rlcEGmVraEg7AAAA3Q"]
[Tue Jul 21 07:32:05.566039 2026] [security2:error] [pid 254995:tid 255156] [client 45.251.232.145:65072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kpf7v0rlcEGmVraEhFAAAAz0"]
[Tue Jul 21 07:32:05.566157 2026] [security2:error] [pid 254995:tid 255156] [client 45.251.232.145:65072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kpf7v0rlcEGmVraEhFAAAAz0"]
[Tue Jul 21 07:32:05.571642 2026] [security2:error] [pid 254995:tid 255196] [client 103.174.34.15:60003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kpf7v0rlcEGmVraEhFQAAA2U"]
[Tue Jul 21 07:32:05.571763 2026] [security2:error] [pid 254995:tid 255196] [client 103.174.34.15:60003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kpf7v0rlcEGmVraEhFQAAA2U"]
[Tue Jul 21 07:32:05.600271 2026] [proxy:error] [pid 254995:tid 255197] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:05.600373 2026] [proxy_http:error] [pid 254995:tid 255197] [client 20.151.10.161:58007] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:05.601295 2026] [proxy:error] [pid 254995:tid 255197] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:05.601330 2026] [proxy_http:error] [pid 254995:tid 255197] [client 20.151.10.161:58007] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:05.687348 2026] [security2:error] [pid 254995:tid 255212] [client 45.8.17.108:32315] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/includes/images/index.php"] [unique_id "al9Kpf7v0rlcEGmVraEhGwAAA3Q"]
[Tue Jul 21 07:32:06.083548 2026] [security2:error] [pid 254995:tid 255266] [client 20.151.10.161:57461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9Kpv7v0rlcEGmVraEhHgAAA5A"]
[Tue Jul 21 07:32:06.093605 2026] [security2:error] [pid 254995:tid 255277] [client 20.206.105.145:39244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/qterm.php"] [unique_id "al9Kpv7v0rlcEGmVraEhHwAAA5s"]
[Tue Jul 21 07:32:06.458865 2026] [security2:error] [pid 254995:tid 255173] [client 122.129.67.13:59218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9Kpv7v0rlcEGmVraEhKgAAA04"]
[Tue Jul 21 07:32:06.484881 2026] [security2:error] [pid 254995:tid 254996] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kpv7v0rlcEGmVraEhKwADhwA"]
[Tue Jul 21 07:32:06.484986 2026] [security2:error] [pid 254995:tid 255257] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kpv7v0rlcEGmVraEhKwADhwA"]
[Tue Jul 21 07:32:06.492156 2026] [security2:error] [pid 254995:tid 255125] [client 20.220.225.223:56459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/la.php"] [unique_id "al9Kpv7v0rlcEGmVraEhLAAAAx4"]
[Tue Jul 21 07:32:06.663985 2026] [security2:error] [pid 254995:tid 255154] [client 20.197.195.24:13059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/blurbs.php"] [unique_id "al9Kpv7v0rlcEGmVraEhOAAAAzs"]
[Tue Jul 21 07:32:06.759350 2026] [security2:error] [pid 254995:tid 255190] [client 20.151.10.161:51287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/puc.php"] [unique_id "al9Kpv7v0rlcEGmVraEhbQAAA18"]
[Tue Jul 21 07:32:06.909637 2026] [security2:error] [pid 254995:tid 255138] [client 20.220.225.223:8954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/cron-tab.php"] [unique_id "al9Kpv7v0rlcEGmVraEhcgAAAys"]
[Tue Jul 21 07:32:06.950122 2026] [security2:error] [pid 254995:tid 255179] [client 117.217.38.194:54070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kpv7v0rlcEGmVraEhcwAAA1Q"]
[Tue Jul 21 07:32:06.950279 2026] [security2:error] [pid 254995:tid 255179] [client 117.217.38.194:54070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kpv7v0rlcEGmVraEhcwAAA1Q"]
[Tue Jul 21 07:32:07.109590 2026] [security2:error] [pid 254995:tid 255261] [client 152.59.154.239:61268] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kp_7v0rlcEGmVraEhgAAAA4s"]
[Tue Jul 21 07:32:07.109746 2026] [security2:error] [pid 254995:tid 255261] [client 152.59.154.239:61268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kp_7v0rlcEGmVraEhgAAAA4s"]
[Tue Jul 21 07:32:07.301197 2026] [security2:error] [pid 254995:tid 255278] [client 20.151.10.161:57350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/themes.php"] [unique_id "al9Kp_7v0rlcEGmVraEhwgAAA5w"]
[Tue Jul 21 07:32:07.337257 2026] [security2:error] [pid 254995:tid 255197] [client 62.102.148.164:57192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Kp_7v0rlcEGmVraEhwwAAA2Y"]
[Tue Jul 21 07:32:07.337355 2026] [security2:error] [pid 254995:tid 255197] [client 62.102.148.164:57192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Kp_7v0rlcEGmVraEhwwAAA2Y"]
[Tue Jul 21 07:32:07.423190 2026] [security2:error] [pid 254995:tid 255196] [client 82.102.28.107:47372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Kp_7v0rlcEGmVraEhygAAA2U"]
[Tue Jul 21 07:32:07.423295 2026] [security2:error] [pid 254995:tid 255196] [client 82.102.28.107:47372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Kp_7v0rlcEGmVraEhygAAA2U"]
[Tue Jul 21 07:32:07.451797 2026] [security2:error] [pid 254995:tid 255205] [client 20.52.136.55:1537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/albin.php"] [unique_id "al9Kp_7v0rlcEGmVraEhywAAA24"]
[Tue Jul 21 07:32:07.504679 2026] [security2:error] [pid 254995:tid 255177] [client 20.197.195.24:13158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/bajah.php"] [unique_id "al9Kp_7v0rlcEGmVraEhzAAAA1I"]
[Tue Jul 21 07:32:07.548256 2026] [security2:error] [pid 254995:tid 255149] [client 136.144.33.100:33607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Kp_7v0rlcEGmVraEhyAAAAzY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:07.585509 2026] [security2:error] [pid 254995:tid 255194] [client 45.8.17.108:46009] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/includes/update-core-time.php"] [unique_id "al9Kp_7v0rlcEGmVraEhzQAAA2M"]
[Tue Jul 21 07:32:07.638993 2026] [security2:error] [pid 254995:tid 255200] [client 20.206.105.145:39242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/blurbs.php"] [unique_id "al9Kp_7v0rlcEGmVraEhzgAAA2k"]
[Tue Jul 21 07:32:07.673530 2026] [security2:error] [pid 254995:tid 255212] [client 20.206.105.145:7682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/sss.php"] [unique_id "al9Kp_7v0rlcEGmVraEhzwAAA3Q"]
[Tue Jul 21 07:32:07.772144 2026] [security2:error] [pid 254995:tid 255137] [client 20.220.225.223:62087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/koiy.php"] [unique_id "al9Kp_7v0rlcEGmVraEh1gAAAyo"]
[Tue Jul 21 07:32:07.776018 2026] [security2:error] [pid 254995:tid 255277] [client 20.151.10.161:57368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/dx.php"] [unique_id "al9Kp_7v0rlcEGmVraEh1wAAA5s"]
[Tue Jul 21 07:32:07.858773 2026] [security2:error] [pid 254995:tid 255005] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Kp_7v0rlcEGmVraEh2wADXwk"]
[Tue Jul 21 07:32:07.858909 2026] [security2:error] [pid 254995:tid 255190] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Kp_7v0rlcEGmVraEh2wADXwk"]
[Tue Jul 21 07:32:07.891088 2026] [security2:error] [pid 254995:tid 255255] [client 20.220.225.223:19315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/ez.php"] [unique_id "al9Kp_7v0rlcEGmVraEh3AAAA4U"]
[Tue Jul 21 07:32:08.153956 2026] [security2:error] [pid 254995:tid 255034] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KqP7v0rlcEGmVraEh9gADRCY"]
[Tue Jul 21 07:32:08.154105 2026] [security2:error] [pid 254995:tid 255163] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KqP7v0rlcEGmVraEh9gADRCY"]
[Tue Jul 21 07:32:08.273725 2026] [security2:error] [pid 254995:tid 255166] [client 20.151.10.161:58002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/p.php"] [unique_id "al9KqP7v0rlcEGmVraEh_gAAA0c"]
[Tue Jul 21 07:32:08.450804 2026] [security2:error] [pid 254995:tid 255147] [client 218.252.242.195:1803] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "onkosclinica.com.br"] [uri "/home/wp-content/uploads/2017/08/IMG_5987-310x200.jpg"] [unique_id "al9KqP7v0rlcEGmVraEiAwAAAzQ"]
[Tue Jul 21 07:32:08.612452 2026] [security2:error] [pid 254995:tid 255041] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KqP7v0rlcEGmVraEiBAADmS0"]
[Tue Jul 21 07:32:08.612589 2026] [security2:error] [pid 254995:tid 255275] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KqP7v0rlcEGmVraEiBAADmS0"]
[Tue Jul 21 07:32:08.871089 2026] [proxy:error] [pid 254995:tid 255193] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:08.871181 2026] [proxy_http:error] [pid 254995:tid 255193] [client 20.151.10.161:50923] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:08.872546 2026] [proxy:error] [pid 254995:tid 255193] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:08.872580 2026] [proxy_http:error] [pid 254995:tid 255193] [client 20.151.10.161:50923] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:08.894851 2026] [security2:error] [pid 254995:tid 255153] [client 20.220.225.223:8955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/hp2.php"] [unique_id "al9KqP7v0rlcEGmVraEiFAAAAzo"]
[Tue Jul 21 07:32:09.000987 2026] [security2:error] [pid 254995:tid 255218] [client 20.197.195.24:13147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/a.php"] [unique_id "al9Kqf7v0rlcEGmVraEiFQAAA3o"]
[Tue Jul 21 07:32:09.007834 2026] [security2:error] [pid 254995:tid 255173] [client 141.11.107.74:60165] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ftp.happynbox.com.br"] [uri "/"] [unique_id "al9Kqf7v0rlcEGmVraEiFgAAA04"]
[Tue Jul 21 07:32:09.013186 2026] [security2:error] [pid 254995:tid 255159] [client 141.11.107.74:60175] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.happynbox.com.br"] [uri "/"] [unique_id "al9Kqf7v0rlcEGmVraEiGAAAA0A"]
[Tue Jul 21 07:32:09.018887 2026] [security2:error] [pid 254995:tid 255256] [client 141.11.107.74:60172] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "happynbox.com.br"] [uri "/"] [unique_id "al9Kqf7v0rlcEGmVraEiGQAAA4Y"]
[Tue Jul 21 07:32:09.393986 2026] [security2:error] [pid 254995:tid 255196] [client 20.220.225.223:8122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/mimpi.php"] [unique_id "al9Kqf7v0rlcEGmVraEiJAAAA2U"]
[Tue Jul 21 07:32:09.397620 2026] [security2:error] [pid 254995:tid 255149] [client 45.8.17.125:24287] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/woocommerce-call.php"] [unique_id "al9Kqf7v0rlcEGmVraEiJQAAAzY"]
[Tue Jul 21 07:32:09.415914 2026] [security2:error] [pid 254995:tid 255229] [client 20.151.10.161:50907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/bthil.php"] [unique_id "al9Kqf7v0rlcEGmVraEiJgAAA4I"]
[Tue Jul 21 07:32:09.738403 2026] [security2:error] [pid 254995:tid 255174] [client 193.36.225.102:36437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Kqf7v0rlcEGmVraEiJwAAA08"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:32:09.940283 2026] [security2:error] [pid 254995:tid 255259] [client 20.206.105.145:54569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/c.php"] [unique_id "al9Kqf7v0rlcEGmVraEiMgAAA4k"]
[Tue Jul 21 07:32:10.016447 2026] [security2:error] [pid 254995:tid 255127] [client 20.206.105.145:39234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/v543.php"] [unique_id "al9Kqv7v0rlcEGmVraEiNAAAAyA"]
[Tue Jul 21 07:32:10.028623 2026] [security2:error] [pid 254995:tid 255130] [client 20.197.195.24:13167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/edit.php"] [unique_id "al9Kqv7v0rlcEGmVraEiNQAAAyM"]
[Tue Jul 21 07:32:10.153003 2026] [security2:error] [pid 254995:tid 255167] [client 20.151.10.161:57405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/7.php"] [unique_id "al9Kqv7v0rlcEGmVraEiNgAAA0g"]
[Tue Jul 21 07:32:10.261765 2026] [security2:error] [pid 254995:tid 255158] [client 20.220.225.223:19674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/fz.php"] [unique_id "al9Kqv7v0rlcEGmVraEiOAAAAz8"]
[Tue Jul 21 07:32:10.489186 2026] [security2:error] [pid 254995:tid 255128] [client 45.8.17.105:38105] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/user/upgrade/index.php"] [unique_id "al9Kqv7v0rlcEGmVraEiQQAAAyE"]
[Tue Jul 21 07:32:10.809589 2026] [autoindex:error] [pid 254995:tid 255099] [remote 74.7.242.40:60190] AH01276: Cannot serve directory /home2/tamoio74/engeconconstrucoes.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:32:10.859395 2026] [security2:error] [pid 254995:tid 255190] [client 59.96.220.140:60878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Kqv7v0rlcEGmVraEidAAAA18"]
[Tue Jul 21 07:32:10.861259 2026] [security2:error] [pid 254995:tid 255190] [client 59.96.220.140:60878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Kqv7v0rlcEGmVraEidAAAA18"]
[Tue Jul 21 07:32:10.931485 2026] [security2:error] [pid 254995:tid 255261] [client 20.151.10.161:50917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/8.php"] [unique_id "al9Kqv7v0rlcEGmVraEiewAAA4s"]
[Tue Jul 21 07:32:11.060419 2026] [security2:error] [pid 254995:tid 255137] [client 20.197.195.24:13144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/hosty.php"] [unique_id "al9Kq_7v0rlcEGmVraEigAAAAyo"]
[Tue Jul 21 07:32:11.092241 2026] [security2:error] [pid 254995:tid 255105] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Kq_7v0rlcEGmVraEigQADkm0"]
[Tue Jul 21 07:32:11.092423 2026] [security2:error] [pid 254995:tid 255268] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Kq_7v0rlcEGmVraEigQADkm0"]
[Tue Jul 21 07:32:11.284225 2026] [security2:error] [pid 254995:tid 255279] [client 20.220.225.223:61959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/nhvoanpl.php"] [unique_id "al9Kq_7v0rlcEGmVraEihAAAA50"]
[Tue Jul 21 07:32:11.433615 2026] [security2:error] [pid 254995:tid 255127] [client 74.7.230.1:46248] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9Kq_7v0rlcEGmVraEikQADIAA"]
[Tue Jul 21 07:32:11.533361 2026] [security2:error] [pid 254995:tid 255026] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kq_7v0rlcEGmVraEilgADhR4"]
[Tue Jul 21 07:32:11.533470 2026] [security2:error] [pid 254995:tid 255255] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kq_7v0rlcEGmVraEilgADhR4"]
[Tue Jul 21 07:32:11.565300 2026] [security2:error] [pid 254995:tid 255149] [client 139.167.225.182:60549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kq_7v0rlcEGmVraEimAAAAzY"]
[Tue Jul 21 07:32:11.565398 2026] [security2:error] [pid 254995:tid 255149] [client 139.167.225.182:60549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kq_7v0rlcEGmVraEimAAAAzY"]
[Tue Jul 21 07:32:11.592572 2026] [security2:error] [pid 254995:tid 255169] [client 20.151.10.161:57403] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.reabfit.com.br"] [uri "/1.php"] [unique_id "al9Kq_7v0rlcEGmVraEimQAAA0o"]
[Tue Jul 21 07:32:11.592654 2026] [security2:error] [pid 254995:tid 255169] [client 20.151.10.161:57403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/1.php"] [unique_id "al9Kq_7v0rlcEGmVraEimQAAA0o"]
[Tue Jul 21 07:32:11.636250 2026] [security2:error] [pid 254995:tid 255263] [client 117.251.86.144:36386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Kq_7v0rlcEGmVraEinAAAA40"]
[Tue Jul 21 07:32:11.636334 2026] [security2:error] [pid 254995:tid 255263] [client 117.251.86.144:36386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Kq_7v0rlcEGmVraEinAAAA40"]
[Tue Jul 21 07:32:11.683108 2026] [security2:error] [pid 254995:tid 255006] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kq_7v0rlcEGmVraEingADTQo"]
[Tue Jul 21 07:32:11.683244 2026] [security2:error] [pid 254995:tid 255172] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kq_7v0rlcEGmVraEingADTQo"]
[Tue Jul 21 07:32:11.844995 2026] [security2:error] [pid 254995:tid 255206] [client 20.206.105.145:39279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/w3lls.php"] [unique_id "al9Kq_7v0rlcEGmVraEiowAAA28"]
[Tue Jul 21 07:32:11.859464 2026] [security2:error] [pid 254995:tid 255214] [client 20.220.225.223:6793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/dp.php"] [unique_id "al9Kq_7v0rlcEGmVraEipAAAA3Y"]
[Tue Jul 21 07:32:11.896172 2026] [security2:error] [pid 254995:tid 255161] [client 45.8.17.73:31493] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/maint/css/index.php"] [unique_id "al9Kq_7v0rlcEGmVraEiqQAAA0I"]
[Tue Jul 21 07:32:11.914577 2026] [security2:error] [pid 254995:tid 255268] [client 20.197.195.24:13083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/k.php"] [unique_id "al9Kq_7v0rlcEGmVraEiqgAAA5I"]
[Tue Jul 21 07:32:11.952759 2026] [security2:error] [pid 254995:tid 255277] [client 20.206.105.145:7479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/aa.php"] [unique_id "al9Kq_7v0rlcEGmVraEiqwAAA5s"]
[Tue Jul 21 07:32:12.056570 2026] [security2:error] [pid 254995:tid 255178] [client 20.151.10.161:57379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/100.php"] [unique_id "al9KrP7v0rlcEGmVraEitgAAA1M"]
[Tue Jul 21 07:32:12.198195 2026] [security2:error] [pid 254995:tid 255276] [client 193.36.225.66:36611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KrP7v0rlcEGmVraEivAAAA5o"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:12.230301 2026] [security2:error] [pid 254995:tid 255224] [client 103.162.129.114:58275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KrP7v0rlcEGmVraEivQAAA4A"]
[Tue Jul 21 07:32:12.230447 2026] [security2:error] [pid 254995:tid 255224] [client 103.162.129.114:58275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KrP7v0rlcEGmVraEivQAAA4A"]
[Tue Jul 21 07:32:12.631344 2026] [security2:error] [pid 254995:tid 255181] [client 20.151.10.161:50889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/about.php"] [unique_id "al9KrP7v0rlcEGmVraEiyAAAA1Y"]
[Tue Jul 21 07:32:12.701120 2026] [security2:error] [pid 254995:tid 255173] [client 122.186.204.214:58131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KrP7v0rlcEGmVraEiyQAAA04"]
[Tue Jul 21 07:32:12.701270 2026] [security2:error] [pid 254995:tid 255173] [client 122.186.204.214:58131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KrP7v0rlcEGmVraEiyQAAA04"]
[Tue Jul 21 07:32:12.984750 2026] [security2:error] [pid 254995:tid 255134] [client 20.151.10.161:51325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/admin.php"] [unique_id "al9KrP7v0rlcEGmVraEi0wAAAyc"]
[Tue Jul 21 07:32:13.069093 2026] [security2:error] [pid 254995:tid 255182] [client 20.206.105.145:38923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-ws68.php"] [unique_id "al9Krf7v0rlcEGmVraEi1gAAA1c"]
[Tue Jul 21 07:32:13.198525 2026] [security2:error] [pid 254995:tid 255145] [client 20.220.225.223:6080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/zzz.php"] [unique_id "al9Krf7v0rlcEGmVraEi2QAAAzI"]
[Tue Jul 21 07:32:13.397302 2026] [security2:error] [pid 254995:tid 255036] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Krf7v0rlcEGmVraEi4gADayg"]
[Tue Jul 21 07:32:13.397487 2026] [security2:error] [pid 254995:tid 255202] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Krf7v0rlcEGmVraEi4gADayg"]
[Tue Jul 21 07:32:13.525280 2026] [security2:error] [pid 254995:tid 255205] [client 20.197.195.24:13093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/aaa.php"] [unique_id "al9Krf7v0rlcEGmVraEi6gAAA24"]
[Tue Jul 21 07:32:13.701546 2026] [security2:error] [pid 254995:tid 255181] [client 20.220.225.223:4185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/inso.php"] [unique_id "al9Krf7v0rlcEGmVraEi6wAAA1Y"]
[Tue Jul 21 07:32:13.862992 2026] [security2:error] [pid 254995:tid 255138] [client 20.151.10.161:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/edit.php"] [unique_id "al9Krf7v0rlcEGmVraEi8wAAAys"]
[Tue Jul 21 07:32:14.010251 2026] [security2:error] [pid 254995:tid 255277] [client 20.206.105.145:39246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/xyn.php"] [unique_id "al9Krv7v0rlcEGmVraEi9wAAA5s"]
[Tue Jul 21 07:32:14.076894 2026] [security2:error] [pid 254995:tid 255208] [client 103.106.20.201:50537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Krv7v0rlcEGmVraEi_wAAA3A"]
[Tue Jul 21 07:32:14.077017 2026] [security2:error] [pid 254995:tid 255208] [client 103.106.20.201:50537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Krv7v0rlcEGmVraEi_wAAA3A"]
[Tue Jul 21 07:32:14.079023 2026] [security2:error] [pid 254995:tid 255187] [client 20.206.105.145:7459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/100.php"] [unique_id "al9Krv7v0rlcEGmVraEjAAAAA1w"]
[Tue Jul 21 07:32:14.093156 2026] [http2:info] [pid 255769:tid 255769] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 07:32:14.288809 2026] [security2:error] [pid 254995:tid 255156] [client 173.24.185.52:57295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Krv7v0rlcEGmVraEjBQAAAz0"]
[Tue Jul 21 07:32:14.288965 2026] [security2:error] [pid 254995:tid 255156] [client 173.24.185.52:57295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Krv7v0rlcEGmVraEjBQAAAz0"]
[Tue Jul 21 07:32:14.302880 2026] [security2:error] [pid 255769:tid 255901] [client 109.248.148.246:54240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9KrrxMYwyVGnfuwsJ8TQAAA6U"]
[Tue Jul 21 07:32:14.302995 2026] [security2:error] [pid 255769:tid 255901] [client 109.248.148.246:54240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9KrrxMYwyVGnfuwsJ8TQAAA6U"]
[Tue Jul 21 07:32:14.310137 2026] [security2:error] [pid 255769:tid 255903] [client 45.8.17.129:29255] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/pattern/index.php"] [unique_id "al9KrrxMYwyVGnfuwsJ8TwAAA6c"]
[Tue Jul 21 07:32:14.737508 2026] [security2:error] [pid 254995:tid 255171] [client 193.36.225.121:57871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Krv7v0rlcEGmVraEjDQAAA0w"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:32:14.800540 2026] [security2:error] [pid 254995:tid 255064] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Krv7v0rlcEGmVraEjEQADWEQ"]
[Tue Jul 21 07:32:14.800719 2026] [security2:error] [pid 254995:tid 255183] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Krv7v0rlcEGmVraEjEQADWEQ"]
[Tue Jul 21 07:32:14.802996 2026] [security2:error] [pid 254995:tid 255148] [client 20.151.10.161:57414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Krv7v0rlcEGmVraEjEgAAAzU"]
[Tue Jul 21 07:32:14.824330 2026] [security2:error] [pid 255769:tid 255771] [remote 124.55.178.99:36982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/wp-login.php"] [unique_id "al9KrrxMYwyVGnfuwsJ8VQADowE"]
[Tue Jul 21 07:32:14.917842 2026] [security2:error] [pid 255769:tid 255772] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KrrxMYwyVGnfuwsJ8VgADuQI"]
[Tue Jul 21 07:32:14.918026 2026] [security2:error] [pid 255769:tid 255921] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KrrxMYwyVGnfuwsJ8VgADuQI"]
[Tue Jul 21 07:32:15.281373 2026] [security2:error] [pid 254995:tid 255225] [client 20.206.105.145:38913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/green3.php"] [unique_id "al9Kr_7v0rlcEGmVraEjHAAAA4E"]
[Tue Jul 21 07:32:15.407385 2026] [security2:error] [pid 255769:tid 255920] [client 175.45.70.82:52043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kr7xMYwyVGnfuwsJ8VwAAA7g"]
[Tue Jul 21 07:32:15.407510 2026] [security2:error] [pid 255769:tid 255920] [client 175.45.70.82:52043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kr7xMYwyVGnfuwsJ8VwAAA7g"]
[Tue Jul 21 07:32:15.436794 2026] [security2:error] [pid 254995:tid 255145] [client 20.220.225.223:6120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/wicked.php"] [unique_id "al9Kr_7v0rlcEGmVraEjHgAAAzI"]
[Tue Jul 21 07:32:15.682436 2026] [security2:error] [pid 255769:tid 255906] [client 136.144.33.96:58321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Kr7xMYwyVGnfuwsJ8WAAAA6o"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:15.685615 2026] [security2:error] [pid 254995:tid 255181] [client 45.8.17.57:37453] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/upgrade-temp-backup/chosen.php"] [unique_id "al9Kr_7v0rlcEGmVraEjLQAAA1Y"]
[Tue Jul 21 07:32:16.039306 2026] [security2:error] [pid 254995:tid 255125] [client 45.251.232.145:49215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KsP7v0rlcEGmVraEjMAAAAx4"]
[Tue Jul 21 07:32:16.039446 2026] [security2:error] [pid 254995:tid 255125] [client 45.251.232.145:49215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KsP7v0rlcEGmVraEjMAAAAx4"]
[Tue Jul 21 07:32:16.182083 2026] [security2:error] [pid 255769:tid 255931] [client 20.151.10.161:50933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/f6.php"] [unique_id "al9KsLxMYwyVGnfuwsJ8WgAAA8M"]
[Tue Jul 21 07:32:16.188457 2026] [security2:error] [pid 254995:tid 255133] [client 154.192.233.199:60342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KsP7v0rlcEGmVraEjNwAAAyY"]
[Tue Jul 21 07:32:16.188549 2026] [security2:error] [pid 254995:tid 255133] [client 154.192.233.199:60342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KsP7v0rlcEGmVraEjNwAAAyY"]
[Tue Jul 21 07:32:16.209482 2026] [security2:error] [pid 255769:tid 255932] [client 20.206.105.145:7469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/footer.php"] [unique_id "al9KsLxMYwyVGnfuwsJ8WwAAA8Q"]
[Tue Jul 21 07:32:16.381154 2026] [security2:error] [pid 255769:tid 255926] [client 103.174.34.15:60496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KsLxMYwyVGnfuwsJ8XAAAA74"]
[Tue Jul 21 07:32:16.381297 2026] [security2:error] [pid 255769:tid 255926] [client 103.174.34.15:60496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KsLxMYwyVGnfuwsJ8XAAAA74"]
[Tue Jul 21 07:32:16.417032 2026] [security2:error] [pid 255769:tid 255937] [client 20.206.105.145:39287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ccs.php"] [unique_id "al9KsLxMYwyVGnfuwsJ8XgAAA8k"]
[Tue Jul 21 07:32:16.562572 2026] [security2:error] [pid 254995:tid 255196] [client 20.197.195.24:13078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/file5.php"] [unique_id "al9KsP7v0rlcEGmVraEjPAAAA2U"]
[Tue Jul 21 07:32:16.581943 2026] [security2:error] [pid 254995:tid 255255] [client 45.8.17.73:37743] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/elementor/includes/template-library/classes/view.php"] [unique_id "al9KsP7v0rlcEGmVraEjPQAAA4U"]
[Tue Jul 21 07:32:16.943369 2026] [security2:error] [pid 255769:tid 255953] [client 82.102.28.107:39482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KsLxMYwyVGnfuwsJ8ZwAAA9k"]
[Tue Jul 21 07:32:16.943503 2026] [security2:error] [pid 255769:tid 255953] [client 82.102.28.107:39482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KsLxMYwyVGnfuwsJ8ZwAAA9k"]
[Tue Jul 21 07:32:16.979681 2026] [security2:error] [pid 255769:tid 255954] [client 62.102.148.164:49654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9KsLxMYwyVGnfuwsJ8aAAAA9o"]
[Tue Jul 21 07:32:16.979788 2026] [security2:error] [pid 255769:tid 255954] [client 62.102.148.164:49654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9KsLxMYwyVGnfuwsJ8aAAAA9o"]
[Tue Jul 21 07:32:16.996656 2026] [core:error] [pid 254995:tid 255134] [client 101.37.88.240:57356] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Tue Jul 21 07:32:17.178075 2026] [security2:error] [pid 254995:tid 255166] [client 20.206.105.145:7771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/users.php"] [unique_id "al9Ksf7v0rlcEGmVraEjTgAAA0c"]
[Tue Jul 21 07:32:17.181782 2026] [security2:error] [pid 254995:tid 255169] [client 20.206.105.145:39280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ccc.php"] [unique_id "al9Ksf7v0rlcEGmVraEjTwAAA0o"]
[Tue Jul 21 07:32:17.389493 2026] [security2:error] [pid 255769:tid 255780] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KsbxMYwyVGnfuwsJ8bAAD4go"]
[Tue Jul 21 07:32:17.389634 2026] [security2:error] [pid 255769:tid 255962] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KsbxMYwyVGnfuwsJ8bAAD4go"]
[Tue Jul 21 07:32:17.439324 2026] [security2:error] [pid 254995:tid 255259] [client 117.217.38.194:54509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ksf7v0rlcEGmVraEjUAAAA4k"]
[Tue Jul 21 07:32:17.439463 2026] [security2:error] [pid 254995:tid 255259] [client 117.217.38.194:54509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ksf7v0rlcEGmVraEjUAAAA4k"]
[Tue Jul 21 07:32:17.614248 2026] [security2:error] [pid 255769:tid 255935] [client 74.7.230.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.royalbsolutions.com"] [uri "/index.php"] [unique_id "al9KsLxMYwyVGnfuwsJ8YAADxwU"]
[Tue Jul 21 07:32:17.829222 2026] [security2:error] [pid 255769:tid 255980] [client 20.197.195.24:13080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/222.php"] [unique_id "al9KsbxMYwyVGnfuwsJ8dQAAA_Q"]
[Tue Jul 21 07:32:17.880256 2026] [security2:error] [pid 255769:tid 255982] [client 45.8.17.116:53877] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/network/theme-install-function.php"] [unique_id "al9KsbxMYwyVGnfuwsJ8dwAAA_Y"]
[Tue Jul 21 07:32:18.106799 2026] [security2:error] [pid 255769:tid 255984] [client 74.7.230.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "royalbsolutions.com"] [uri "/index.php"] [unique_id "al9KsrxMYwyVGnfuwsJ8egAD-A4"], referer: https://www.royalbsolutions.com/robots.txt
[Tue Jul 21 07:32:18.110283 2026] [security2:error] [pid 255769:tid 255963] [client 193.36.225.139:61797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9KsbxMYwyVGnfuwsJ8eAAAA-M"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:32:18.344470 2026] [security2:error] [pid 255769:tid 255998] [client 20.206.105.145:39286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/get.php"] [unique_id "al9KsrxMYwyVGnfuwsJ8fQAABAQ"]
[Tue Jul 21 07:32:18.525941 2026] [security2:error] [pid 254995:tid 255114] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Ksv7v0rlcEGmVraEjZgADhHY"]
[Tue Jul 21 07:32:18.526090 2026] [security2:error] [pid 254995:tid 255254] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Ksv7v0rlcEGmVraEjZgADhHY"]
[Tue Jul 21 07:32:18.731842 2026] [security2:error] [pid 254995:tid 255169] [client 20.197.195.24:13075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/test.php"] [unique_id "al9Ksv7v0rlcEGmVraEjawAAA0o"]
[Tue Jul 21 07:32:19.057529 2026] [security2:error] [pid 254995:tid 255173] [client 20.206.105.145:38950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/images.php"] [unique_id "al9Ks_7v0rlcEGmVraEjbgAAA04"]
[Tue Jul 21 07:32:19.120605 2026] [security2:error] [pid 254995:tid 255122] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Ks_7v0rlcEGmVraEjbwADVn4"]
[Tue Jul 21 07:32:19.120747 2026] [security2:error] [pid 254995:tid 255181] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Ks_7v0rlcEGmVraEjbwADVn4"]
[Tue Jul 21 07:32:19.183580 2026] [security2:error] [pid 254995:tid 255204] [client 45.8.17.112:64421] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/shadow-bot.php"] [unique_id "al9Ks_7v0rlcEGmVraEjcQAAA20"]
[Tue Jul 21 07:32:19.223179 2026] [security2:error] [pid 255769:tid 255988] [client 152.59.154.239:61723] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ks7xMYwyVGnfuwsJ8iAAAA_w"]
[Tue Jul 21 07:32:19.223293 2026] [security2:error] [pid 255769:tid 255988] [client 152.59.154.239:61723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ks7xMYwyVGnfuwsJ8iAAAA_w"]
[Tue Jul 21 07:32:19.364178 2026] [security2:error] [pid 254995:tid 255167] [client 20.220.225.223:52182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/edit.php"] [unique_id "al9Ks_7v0rlcEGmVraEjdgAAA0g"]
[Tue Jul 21 07:32:19.553181 2026] [security2:error] [pid 255769:tid 255787] [remote 65.111.14.163:36739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.14.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9Ks7xMYwyVGnfuwsJ8jgAEIBE"]
[Tue Jul 21 07:32:19.651123 2026] [security2:error] [pid 254995:tid 255214] [client 20.197.195.24:13183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/aaa.php"] [unique_id "al9Ks_7v0rlcEGmVraEjewAAA3Y"]
[Tue Jul 21 07:32:19.662780 2026] [security2:error] [pid 255769:tid 255939] [client 122.129.67.13:60395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9KsbxMYwyVGnfuwsJ8awAAA8s"]
[Tue Jul 21 07:32:20.223502 2026] [security2:error] [pid 255769:tid 255923] [client 20.206.105.145:7260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/177.php"] [unique_id "al9KtLxMYwyVGnfuwsJ8lQAAA7s"]
[Tue Jul 21 07:32:20.504869 2026] [security2:error] [pid 255769:tid 255925] [client 20.206.105.145:38918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/alls.php"] [unique_id "al9KtLxMYwyVGnfuwsJ8lwAAA70"]
[Tue Jul 21 07:32:20.634977 2026] [security2:error] [pid 255769:tid 255791] [remote 45.79.123.44:52872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cestabasicadocarlao.com.br"] [uri "/wp-login.php"] [unique_id "al9KtLxMYwyVGnfuwsJ8mAADuhU"]
[Tue Jul 21 07:32:20.740525 2026] [security2:error] [pid 254995:tid 255199] [client 136.144.33.106:23771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KtP7v0rlcEGmVraEjkgAAA2g"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:20.954189 2026] [security2:error] [pid 254995:tid 255143] [client 173.252.95.21:33822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9KtP7v0rlcEGmVraEjmAAAAzA"]
[Tue Jul 21 07:32:21.220311 2026] [security2:error] [pid 255769:tid 255958] [client 20.197.195.24:13148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/11.php"] [unique_id "al9KtbxMYwyVGnfuwsJ8oAAAA94"]
[Tue Jul 21 07:32:21.295947 2026] [security2:error] [pid 255769:tid 255903] [client 59.96.220.140:61362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KtbxMYwyVGnfuwsJ8oQAAA6c"]
[Tue Jul 21 07:32:21.296078 2026] [security2:error] [pid 255769:tid 255903] [client 59.96.220.140:61362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KtbxMYwyVGnfuwsJ8oQAAA6c"]
[Tue Jul 21 07:32:21.395535 2026] [security2:error] [pid 254995:tid 255264] [client 20.220.225.223:6130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/kua.php"] [unique_id "al9Ktf7v0rlcEGmVraEjogAAA44"]
[Tue Jul 21 07:32:21.413754 2026] [security2:error] [pid 254995:tid 255159] [client 37.140.223.157:29167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Ktf7v0rlcEGmVraEjnwAAA0A"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:32:21.416516 2026] [security2:error] [pid 254995:tid 255224] [client 20.151.10.161:57463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/inputs.php"] [unique_id "al9Ktf7v0rlcEGmVraEjowAAA4A"]
[Tue Jul 21 07:32:21.630523 2026] [security2:error] [pid 255769:tid 255793] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KtbxMYwyVGnfuwsJ8qQAD8xc"]
[Tue Jul 21 07:32:21.630642 2026] [security2:error] [pid 255769:tid 255979] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KtbxMYwyVGnfuwsJ8qQAD8xc"]
[Tue Jul 21 07:32:21.782043 2026] [security2:error] [pid 255769:tid 255981] [client 45.8.17.113:40993] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/shadow-bot.php"] [unique_id "al9KtbxMYwyVGnfuwsJ8qgAAA_U"]
[Tue Jul 21 07:32:21.928402 2026] [security2:error] [pid 254995:tid 255257] [client 20.206.105.145:7727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/config.php"] [unique_id "al9Ktf7v0rlcEGmVraEjqwAAA4c"]
[Tue Jul 21 07:32:21.937712 2026] [security2:error] [pid 254995:tid 255254] [client 20.206.105.145:38971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/yyu.php"] [unique_id "al9Ktf7v0rlcEGmVraEjrQAAA4Q"]
[Tue Jul 21 07:32:21.961744 2026] [security2:error] [pid 255769:tid 255795] [remote 188.138.102.156:58226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compressoresra.com.br"] [uri "/wp-login.php"] [unique_id "al9KtbxMYwyVGnfuwsJ8rAAD6xk"]
[Tue Jul 21 07:32:22.000587 2026] [security2:error] [pid 255769:tid 255950] [client 117.251.86.144:43482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KtrxMYwyVGnfuwsJ8rQAAA9Y"]
[Tue Jul 21 07:32:22.000741 2026] [security2:error] [pid 255769:tid 255950] [client 117.251.86.144:43482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KtrxMYwyVGnfuwsJ8rQAAA9Y"]
[Tue Jul 21 07:32:22.039762 2026] [security2:error] [pid 255769:tid 255796] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KtrxMYwyVGnfuwsJ8rgAD8ho"]
[Tue Jul 21 07:32:22.039948 2026] [security2:error] [pid 255769:tid 255978] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KtrxMYwyVGnfuwsJ8rgAD8ho"]
[Tue Jul 21 07:32:22.060091 2026] [security2:error] [pid 255769:tid 255961] [client 139.167.225.182:61184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KtrxMYwyVGnfuwsJ8rwAAA-E"]
[Tue Jul 21 07:32:22.060252 2026] [security2:error] [pid 255769:tid 255961] [client 139.167.225.182:61184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KtrxMYwyVGnfuwsJ8rwAAA-E"]
[Tue Jul 21 07:32:22.693634 2026] [security2:error] [pid 255769:tid 255990] [client 103.162.129.114:58712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KtrxMYwyVGnfuwsJ8tQAAA_4"]
[Tue Jul 21 07:32:22.693795 2026] [security2:error] [pid 255769:tid 255990] [client 103.162.129.114:58712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KtrxMYwyVGnfuwsJ8tQAAA_4"]
[Tue Jul 21 07:32:22.732852 2026] [security2:error] [pid 254995:tid 255268] [client 20.220.225.223:62093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/hp3.php"] [unique_id "al9Ktv7v0rlcEGmVraEjuwAAA5I"]
[Tue Jul 21 07:32:23.140262 2026] [security2:error] [pid 255769:tid 255916] [client 20.206.105.145:7567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/gettest.php"] [unique_id "al9Kt7xMYwyVGnfuwsJ8vAAAA7Q"]
[Tue Jul 21 07:32:23.150518 2026] [security2:error] [pid 254995:tid 255025] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ktv7v0rlcEGmVraEjtAADPh0"]
[Tue Jul 21 07:32:23.150741 2026] [security2:error] [pid 254995:tid 255157] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ktv7v0rlcEGmVraEjtAADPh0"]
[Tue Jul 21 07:32:23.422630 2026] [security2:error] [pid 255769:tid 256021] [client 122.186.204.214:58637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kt7xMYwyVGnfuwsJ8wQAABBs"]
[Tue Jul 21 07:32:23.442543 2026] [security2:error] [pid 255769:tid 256021] [client 122.186.204.214:58637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kt7xMYwyVGnfuwsJ8wQAABBs"]
[Tue Jul 21 07:32:23.487683 2026] [security2:error] [pid 254995:tid 255196] [client 45.8.17.125:58881] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/load.php"] [unique_id "al9Kt_7v0rlcEGmVraEjywAAA2U"]
[Tue Jul 21 07:32:23.539031 2026] [security2:error] [pid 255769:tid 255934] [client 82.102.28.107:36868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Kt7xMYwyVGnfuwsJ8wwAAA8Y"]
[Tue Jul 21 07:32:23.539137 2026] [security2:error] [pid 255769:tid 255934] [client 82.102.28.107:36868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Kt7xMYwyVGnfuwsJ8wwAAA8Y"]
[Tue Jul 21 07:32:23.937263 2026] [security2:error] [pid 255769:tid 255802] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kt7xMYwyVGnfuwsJ8yAAD0CA"]
[Tue Jul 21 07:32:23.937434 2026] [security2:error] [pid 255769:tid 255944] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kt7xMYwyVGnfuwsJ8yAAD0CA"]
[Tue Jul 21 07:32:23.975895 2026] [security2:error] [pid 254995:tid 255229] [client 20.206.105.145:38969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/by.php"] [unique_id "al9Kt_7v0rlcEGmVraEj0wAAA4I"]
[Tue Jul 21 07:32:24.384845 2026] [security2:error] [pid 254995:tid 255154] [client 45.8.17.145:35073] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/wp-activate.php"] [unique_id "al9KuP7v0rlcEGmVraEj2gAAAzs"]
[Tue Jul 21 07:32:24.495444 2026] [security2:error] [pid 254995:tid 255224] [client 136.144.33.29:60971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KuP7v0rlcEGmVraEj3gAAA4A"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:24.551974 2026] [security2:error] [pid 255769:tid 255968] [client 20.220.225.223:62003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/wpx.php"] [unique_id "al9KuLxMYwyVGnfuwsJ8zQAAA-g"]
[Tue Jul 21 07:32:24.574733 2026] [security2:error] [pid 255769:tid 255975] [client 20.206.105.145:54534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/min.php"] [unique_id "al9KuLxMYwyVGnfuwsJ8zwAAA-8"]
[Tue Jul 21 07:32:24.589033 2026] [security2:error] [pid 255769:tid 255976] [client 20.220.225.223:6110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/ez.php"] [unique_id "al9KuLxMYwyVGnfuwsJ80AAAA_A"]
[Tue Jul 21 07:32:24.746428 2026] [security2:error] [pid 255769:tid 255805] [remote 156.67.31.167:46732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buyonlinetodayatadiscount.net"] [uri "/xmlrpc.php"] [unique_id "al9KuLxMYwyVGnfuwsJ80gADuCM"]
[Tue Jul 21 07:32:24.746627 2026] [security2:error] [pid 255769:tid 255920] [client 156.67.31.167:46732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "buyonlinetodayatadiscount.net"] [uri "/xmlrpc.php"] [unique_id "al9KuLxMYwyVGnfuwsJ80gADuCM"]
[Tue Jul 21 07:32:24.782922 2026] [security2:error] [pid 254995:tid 255194] [client 103.106.20.201:51106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KuP7v0rlcEGmVraEj5gAAA2M"]
[Tue Jul 21 07:32:24.783634 2026] [security2:error] [pid 254995:tid 255194] [client 103.106.20.201:51106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KuP7v0rlcEGmVraEj5gAAA2M"]
[Tue Jul 21 07:32:24.843190 2026] [security2:error] [pid 255769:tid 255935] [client 173.24.185.52:57763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KuLxMYwyVGnfuwsJ80wAAA8c"]
[Tue Jul 21 07:32:24.843338 2026] [security2:error] [pid 255769:tid 255935] [client 173.24.185.52:57763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KuLxMYwyVGnfuwsJ80wAAA8c"]
[Tue Jul 21 07:32:25.340504 2026] [security2:error] [pid 254995:tid 255172] [client 20.197.195.24:13063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/mac.php"] [unique_id "al9Kuf7v0rlcEGmVraEj7AAAA00"]
[Tue Jul 21 07:32:25.394806 2026] [security2:error] [pid 254995:tid 255053] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kuf7v0rlcEGmVraEj7QADVDk"]
[Tue Jul 21 07:32:25.394984 2026] [security2:error] [pid 254995:tid 255179] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kuf7v0rlcEGmVraEj7QADVDk"]
[Tue Jul 21 07:32:25.420266 2026] [security2:error] [pid 254995:tid 255213] [client 154.192.233.199:58804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kuf7v0rlcEGmVraEj7gAAA3U"]
[Tue Jul 21 07:32:25.420390 2026] [security2:error] [pid 254995:tid 255213] [client 154.192.233.199:58804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kuf7v0rlcEGmVraEj7gAAA3U"]
[Tue Jul 21 07:32:25.995084 2026] [security2:error] [pid 255769:tid 255809] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KubxMYwyVGnfuwsJ83gAD1yc"]
[Tue Jul 21 07:32:25.995271 2026] [security2:error] [pid 255769:tid 255951] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KubxMYwyVGnfuwsJ83gAD1yc"]
[Tue Jul 21 07:32:26.089531 2026] [security2:error] [pid 255769:tid 256014] [client 45.8.17.124:65189] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/module.php"] [unique_id "al9KurxMYwyVGnfuwsJ84gAABBQ"]
[Tue Jul 21 07:32:26.116094 2026] [security2:error] [pid 255769:tid 256019] [client 20.206.105.145:38949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/FAQ.php"] [unique_id "al9KurxMYwyVGnfuwsJ85AAABBk"]
[Tue Jul 21 07:32:26.131114 2026] [security2:error] [pid 255769:tid 255999] [client 175.45.70.82:52553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KurxMYwyVGnfuwsJ85gAABAU"]
[Tue Jul 21 07:32:26.131242 2026] [security2:error] [pid 255769:tid 255999] [client 175.45.70.82:52553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KurxMYwyVGnfuwsJ85gAABAU"]
[Tue Jul 21 07:32:26.405233 2026] [security2:error] [pid 255769:tid 255909] [client 213.152.162.104:50588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9KurxMYwyVGnfuwsJ87AAAA60"]
[Tue Jul 21 07:32:26.405368 2026] [security2:error] [pid 255769:tid 255909] [client 213.152.162.104:50588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9KurxMYwyVGnfuwsJ87AAAA60"]
[Tue Jul 21 07:32:26.427080 2026] [security2:error] [pid 255769:tid 255911] [client 20.220.225.223:8956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/aa1.php"] [unique_id "al9KurxMYwyVGnfuwsJ87QAAA68"]
[Tue Jul 21 07:32:26.497277 2026] [autoindex:error] [pid 255769:tid 255919] [client 172.252.73.13:0] AH01276: Cannot serve directory /home2/inlaud99/distribuidorasja.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:32:26.499169 2026] [security2:error] [pid 254995:tid 255167] [client 45.251.232.145:49743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kuv7v0rlcEGmVraEj_wAAA0g"]
[Tue Jul 21 07:32:26.499271 2026] [security2:error] [pid 254995:tid 255167] [client 45.251.232.145:49743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kuv7v0rlcEGmVraEj_wAAA0g"]
[Tue Jul 21 07:32:26.614224 2026] [security2:error] [pid 255769:tid 256021] [client 20.197.195.24:13057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/chosen.php"] [unique_id "al9KurxMYwyVGnfuwsJ88wAABBs"]
[Tue Jul 21 07:32:26.653786 2026] [security2:error] [pid 255769:tid 255927] [client 20.206.105.145:38964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/coffexium.php"] [unique_id "al9KurxMYwyVGnfuwsJ89AAAA78"]
[Tue Jul 21 07:32:26.908565 2026] [security2:error] [pid 254995:tid 255216] [client 20.206.105.145:39285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/red.php"] [unique_id "al9Kuv7v0rlcEGmVraEkCAAAA3g"]
[Tue Jul 21 07:32:26.986666 2026] [security2:error] [pid 254995:tid 255169] [client 20.151.10.161:57347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/av.php"] [unique_id "al9Kuv7v0rlcEGmVraEkCQAAA0o"]
[Tue Jul 21 07:32:27.080598 2026] [security2:error] [pid 255769:tid 255912] [client 103.174.34.15:60987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ku7xMYwyVGnfuwsJ89gAAA7A"]
[Tue Jul 21 07:32:27.080778 2026] [security2:error] [pid 255769:tid 255912] [client 103.174.34.15:60987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ku7xMYwyVGnfuwsJ89gAAA7A"]
[Tue Jul 21 07:32:27.166607 2026] [security2:error] [pid 255769:tid 255940] [client 20.220.225.223:23463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/fz.php"] [unique_id "al9Ku7xMYwyVGnfuwsJ8-AAAA8w"]
[Tue Jul 21 07:32:27.341644 2026] [security2:error] [pid 255769:tid 255954] [client 20.206.105.145:7613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/edorxrr.php"] [unique_id "al9Ku7xMYwyVGnfuwsJ8-wAAA9o"]
[Tue Jul 21 07:32:27.390698 2026] [security2:error] [pid 255769:tid 255960] [client 45.8.17.134:38441] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/wp-links-opml.php"] [unique_id "al9Ku7xMYwyVGnfuwsJ8_gAAA-A"]
[Tue Jul 21 07:32:27.532212 2026] [security2:error] [pid 255769:tid 255970] [client 20.220.225.223:46118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/hp3.php"] [unique_id "al9Ku7xMYwyVGnfuwsJ9AgAAA-o"]
[Tue Jul 21 07:32:27.658255 2026] [security2:error] [pid 254995:tid 255172] [client 20.197.195.24:13153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/cream1.php"] [unique_id "al9Ku_7v0rlcEGmVraEkEwAAA00"]
[Tue Jul 21 07:32:27.741995 2026] [security2:error] [pid 254995:tid 255144] [client 213.152.162.104:50602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Ku_7v0rlcEGmVraEkFwAAAzE"]
[Tue Jul 21 07:32:27.742088 2026] [security2:error] [pid 254995:tid 255144] [client 213.152.162.104:50602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Ku_7v0rlcEGmVraEkFwAAAzE"]
[Tue Jul 21 07:32:27.909107 2026] [security2:error] [pid 255769:tid 255946] [client 117.217.38.194:54935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ku7xMYwyVGnfuwsJ9BwAAA9I"]
[Tue Jul 21 07:32:27.909227 2026] [security2:error] [pid 255769:tid 255946] [client 117.217.38.194:54935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ku7xMYwyVGnfuwsJ9BwAAA9I"]
[Tue Jul 21 07:32:27.918553 2026] [security2:error] [pid 255769:tid 255819] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ku7xMYwyVGnfuwsJ9CAAD8TE"]
[Tue Jul 21 07:32:27.918707 2026] [security2:error] [pid 255769:tid 255977] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ku7xMYwyVGnfuwsJ9CAAD8TE"]
[Tue Jul 21 07:32:28.067572 2026] [proxy:error] [pid 255769:tid 255979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:28.067619 2026] [proxy_http:error] [pid 255769:tid 255979] [client 20.206.105.145:38916] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:28.068138 2026] [proxy:error] [pid 255769:tid 255979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:28.068158 2026] [proxy_http:error] [pid 255769:tid 255979] [client 20.206.105.145:38916] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:28.097352 2026] [security2:error] [pid 255769:tid 255932] [client 122.129.67.13:59347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9KvLxMYwyVGnfuwsJ9CQAAA8Q"]
[Tue Jul 21 07:32:28.589656 2026] [security2:error] [pid 255769:tid 255951] [client 45.8.17.62:23323] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/system.php"] [unique_id "al9KvLxMYwyVGnfuwsJ9FQAAA9c"]
[Tue Jul 21 07:32:28.629766 2026] [security2:error] [pid 255769:tid 255953] [client 172.245.102.42:21371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KvLxMYwyVGnfuwsJ9EwAAA9k"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:28.849519 2026] [security2:error] [pid 255769:tid 255900] [client 20.206.105.145:39273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9KvLxMYwyVGnfuwsJ9GgAAA6Q"]
[Tue Jul 21 07:32:28.977523 2026] [security2:error] [pid 254995:tid 255157] [client 20.151.10.161:50891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/classwithtostring.php"] [unique_id "al9KvP7v0rlcEGmVraEkKQAAAz4"]
[Tue Jul 21 07:32:29.278393 2026] [security2:error] [pid 255769:tid 255919] [client 20.220.225.223:4578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/berlin.php"] [unique_id "al9KvbxMYwyVGnfuwsJ9HQAAA7c"]
[Tue Jul 21 07:32:29.284675 2026] [security2:error] [pid 255769:tid 255826] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KvbxMYwyVGnfuwsJ9HgAEIDg"]
[Tue Jul 21 07:32:29.284823 2026] [security2:error] [pid 255769:tid 256026] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KvbxMYwyVGnfuwsJ9HgAEIDg"]
[Tue Jul 21 07:32:29.604071 2026] [security2:error] [pid 254995:tid 255270] [client 109.248.148.246:40464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Kvf7v0rlcEGmVraEkMwAAA5Q"]
[Tue Jul 21 07:32:29.604185 2026] [security2:error] [pid 254995:tid 255270] [client 109.248.148.246:40464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Kvf7v0rlcEGmVraEkMwAAA5Q"]
[Tue Jul 21 07:32:29.708035 2026] [security2:error] [pid 254995:tid 255119] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Kvf7v0rlcEGmVraEkNwADdXs"]
[Tue Jul 21 07:32:29.708174 2026] [security2:error] [pid 254995:tid 255213] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Kvf7v0rlcEGmVraEkNwADdXs"]
[Tue Jul 21 07:32:29.881863 2026] [security2:error] [pid 254995:tid 255199] [client 45.8.17.145:44235] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/wp-links-opml.php"] [unique_id "al9Kvf7v0rlcEGmVraEkOwAAA2g"]
[Tue Jul 21 07:32:30.275562 2026] [security2:error] [pid 254995:tid 255148] [client 20.151.10.161:57433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9Kvv7v0rlcEGmVraEkQgAAAzU"]
[Tue Jul 21 07:32:30.766127 2026] [proxy:error] [pid 254995:tid 255147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:30.766206 2026] [proxy_http:error] [pid 254995:tid 255147] [client 20.206.105.145:38980] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:30.766796 2026] [proxy:error] [pid 254995:tid 255147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:30.766836 2026] [proxy_http:error] [pid 254995:tid 255147] [client 20.206.105.145:38980] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:30.785261 2026] [security2:error] [pid 255769:tid 255977] [client 20.206.105.145:7756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/hur.php"] [unique_id "al9KvrxMYwyVGnfuwsJ9MQAAA_E"]
[Tue Jul 21 07:32:31.015042 2026] [security2:error] [pid 254995:tid 255254] [client 20.220.225.223:8077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/wp-editor.php"] [unique_id "al9Kv_7v0rlcEGmVraEkVAAAA4Q"]
[Tue Jul 21 07:32:31.066965 2026] [security2:error] [pid 255769:tid 255983] [client 20.151.10.161:57433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-blog.php"] [unique_id "al9Kv7xMYwyVGnfuwsJ9NgAAA_c"]
[Tue Jul 21 07:32:31.091253 2026] [security2:error] [pid 254995:tid 255156] [client 45.8.17.142:28349] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/ms-files.php"] [unique_id "al9Kv_7v0rlcEGmVraEkVgAAAz0"]
[Tue Jul 21 07:32:31.116437 2026] [security2:error] [pid 255769:tid 255954] [client 59.96.220.140:61606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Kv7xMYwyVGnfuwsJ9NwAAA9o"]
[Tue Jul 21 07:32:31.117361 2026] [security2:error] [pid 255769:tid 255954] [client 59.96.220.140:61606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Kv7xMYwyVGnfuwsJ9NwAAA9o"]
[Tue Jul 21 07:32:31.348927 2026] [security2:error] [pid 254995:tid 255193] [client 20.220.225.223:56497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/billur.php"] [unique_id "al9Kv_7v0rlcEGmVraEkWAAAA2I"]
[Tue Jul 21 07:32:31.448170 2026] [autoindex:error] [pid 255769:tid 255994] [client 20.197.195.24:48883] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:32:31.466408 2026] [autoindex:error] [pid 255769:tid 255992] [client 20.197.195.24:48883] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:32:31.470789 2026] [security2:error] [pid 255769:tid 255952] [client 20.197.195.24:48883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/dr.php"] [unique_id "al9Kv7xMYwyVGnfuwsJ9PQAAA9g"]
[Tue Jul 21 07:32:31.822364 2026] [security2:error] [pid 255769:tid 255979] [client 66.116.242.211:33118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.242.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/wp-login.php"] [unique_id "al9KvrxMYwyVGnfuwsJ9MgAAA_M"], referer: https://bravacomunicacao.com/wp-login.php
[Tue Jul 21 07:32:32.071380 2026] [security2:error] [pid 254995:tid 255149] [client 20.220.225.223:45979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/aa1.php"] [unique_id "al9KwP7v0rlcEGmVraEkawAAAzY"]
[Tue Jul 21 07:32:32.164721 2026] [security2:error] [pid 255769:tid 255836] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9QwAEFUI"]
[Tue Jul 21 07:32:32.164909 2026] [security2:error] [pid 255769:tid 256015] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9QwAEFUI"]
[Tue Jul 21 07:32:32.211661 2026] [proxy:error] [pid 255769:tid 256020] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:32.211735 2026] [proxy_http:error] [pid 255769:tid 256020] [client 20.151.10.161:58011] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:32.212294 2026] [proxy:error] [pid 255769:tid 256020] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:32.212321 2026] [proxy_http:error] [pid 255769:tid 256020] [client 20.151.10.161:58011] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:32.275553 2026] [security2:error] [pid 255769:tid 256025] [client 20.220.225.223:19298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9RQAABB8"]
[Tue Jul 21 07:32:32.305799 2026] [security2:error] [pid 255769:tid 255986] [client 152.59.154.239:62198] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9RgAAA_o"]
[Tue Jul 21 07:32:32.305951 2026] [security2:error] [pid 255769:tid 255986] [client 152.59.154.239:62198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9RgAAA_o"]
[Tue Jul 21 07:32:32.338023 2026] [security2:error] [pid 255769:tid 255963] [client 193.36.225.60:30471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9SAAAA-M"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:32.552952 2026] [security2:error] [pid 255769:tid 255838] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9TAAEGEQ"]
[Tue Jul 21 07:32:32.553077 2026] [security2:error] [pid 255769:tid 256018] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9TAAEGEQ"]
[Tue Jul 21 07:32:32.617532 2026] [security2:error] [pid 255769:tid 255839] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9TQADrUU"]
[Tue Jul 21 07:32:32.617698 2026] [security2:error] [pid 255769:tid 255909] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9TQADrUU"]
[Tue Jul 21 07:32:32.727090 2026] [security2:error] [pid 255769:tid 256011] [client 117.251.86.144:46190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9UAAABBE"]
[Tue Jul 21 07:32:32.727214 2026] [security2:error] [pid 255769:tid 256011] [client 117.251.86.144:46190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9UAAABBE"]
[Tue Jul 21 07:32:32.800026 2026] [security2:error] [pid 255769:tid 255999] [client 139.167.225.182:61812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9UQAABAU"]
[Tue Jul 21 07:32:32.800171 2026] [security2:error] [pid 255769:tid 255999] [client 139.167.225.182:61812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9UQAABAU"]
[Tue Jul 21 07:32:32.806558 2026] [security2:error] [pid 254995:tid 255193] [client 20.220.225.223:8098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/cro.php"] [unique_id "al9KwP7v0rlcEGmVraEkewAAA2I"]
[Tue Jul 21 07:32:32.878748 2026] [security2:error] [pid 255769:tid 256021] [client 20.206.105.145:7780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/zoro.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9UgAABBs"]
[Tue Jul 21 07:32:32.981195 2026] [security2:error] [pid 255769:tid 255927] [client 45.8.17.141:38363] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugin-install.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9UwAAA78"]
[Tue Jul 21 07:32:33.158824 2026] [security2:error] [pid 255769:tid 255912] [client 66.116.242.211:44004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.242.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/wp-login.php"] [unique_id "al9KwbxMYwyVGnfuwsJ9VAAAA7A"], referer: https://bravacomunicacao.com/wp-login.php
[Tue Jul 21 07:32:33.455797 2026] [security2:error] [pid 255769:tid 255959] [client 20.206.105.145:39232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/footer.php"] [unique_id "al9KwbxMYwyVGnfuwsJ9XAAAA98"]
[Tue Jul 21 07:32:33.529202 2026] [security2:error] [pid 255769:tid 255915] [client 103.162.129.114:59150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KwbxMYwyVGnfuwsJ9XgAAA7M"]
[Tue Jul 21 07:32:33.529346 2026] [security2:error] [pid 255769:tid 255915] [client 103.162.129.114:59150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KwbxMYwyVGnfuwsJ9XgAAA7M"]
[Tue Jul 21 07:32:33.593466 2026] [security2:error] [pid 255769:tid 255842] [remote 45.146.55.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.55.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mecanicanogueira.com.br"] [uri "/wp-login.php"] [unique_id "al9KwbxMYwyVGnfuwsJ9YAAD1Ug"]
[Tue Jul 21 07:32:33.791596 2026] [security2:error] [pid 255769:tid 255984] [client 20.220.225.223:46141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/acew67.php"] [unique_id "al9KwbxMYwyVGnfuwsJ9YgAAA_g"]
[Tue Jul 21 07:32:33.845303 2026] [security2:error] [pid 255769:tid 255978] [client 20.151.10.161:50925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9KwbxMYwyVGnfuwsJ9YwAAA_I"]
[Tue Jul 21 07:32:34.051469 2026] [security2:error] [pid 255769:tid 255960] [client 122.186.204.214:59147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KwrxMYwyVGnfuwsJ9awAAA-A"]
[Tue Jul 21 07:32:34.051603 2026] [security2:error] [pid 255769:tid 255960] [client 122.186.204.214:59147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KwrxMYwyVGnfuwsJ9awAAA-A"]
[Tue Jul 21 07:32:34.110379 2026] [security2:error] [pid 254995:tid 255127] [client 20.220.225.223:19307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/inso.php"] [unique_id "al9Kwv7v0rlcEGmVraEkkAAAAyA"]
[Tue Jul 21 07:32:34.332235 2026] [security2:error] [pid 255769:tid 256009] [client 66.116.242.211:44010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.242.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/wp-login.php"] [unique_id "al9KwrxMYwyVGnfuwsJ9cAAABA8"], referer: https://bravacomunicacao.com/wp-login.php
[Tue Jul 21 07:32:34.473421 2026] [security2:error] [pid 254995:tid 255149] [client 20.220.225.223:62007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/mimpi.php"] [unique_id "al9Kwv7v0rlcEGmVraEklwAAAzY"]
[Tue Jul 21 07:32:34.482491 2026] [security2:error] [pid 255769:tid 255847] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KwrxMYwyVGnfuwsJ9cQAEFE0"]
[Tue Jul 21 07:32:34.482633 2026] [security2:error] [pid 255769:tid 256014] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KwrxMYwyVGnfuwsJ9cQAEFE0"]
[Tue Jul 21 07:32:34.745771 2026] [security2:error] [pid 254995:tid 255166] [client 20.206.105.145:7759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/coffexium.php"] [unique_id "al9Kwv7v0rlcEGmVraEkoAAAA0c"]
[Tue Jul 21 07:32:35.091683 2026] [security2:error] [pid 255769:tid 255939] [client 20.151.10.161:51322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/adminfuns.php"] [unique_id "al9Kw7xMYwyVGnfuwsJ9eAAAA8s"]
[Tue Jul 21 07:32:35.401102 2026] [security2:error] [pid 255769:tid 255911] [client 173.24.185.52:58232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Kw7xMYwyVGnfuwsJ9fgAAA68"]
[Tue Jul 21 07:32:35.401239 2026] [security2:error] [pid 255769:tid 255911] [client 173.24.185.52:58232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Kw7xMYwyVGnfuwsJ9fgAAA68"]
[Tue Jul 21 07:32:35.486039 2026] [security2:error] [pid 254995:tid 255204] [client 45.8.17.107:27499] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/includes/class-walker-nav-menu-edit-interpreter.php"] [unique_id "al9Kw_7v0rlcEGmVraEkqwAAA20"]
[Tue Jul 21 07:32:35.548749 2026] [security2:error] [pid 255769:tid 255904] [client 103.106.20.201:51642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kw7xMYwyVGnfuwsJ9ggAAA6g"]
[Tue Jul 21 07:32:35.548896 2026] [security2:error] [pid 255769:tid 255904] [client 103.106.20.201:51642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kw7xMYwyVGnfuwsJ9ggAAA6g"]
[Tue Jul 21 07:32:35.865943 2026] [security2:error] [pid 254995:tid 255147] [client 20.197.195.24:13124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/x.php"] [unique_id "al9Kw_7v0rlcEGmVraEksAAAAzQ"]
[Tue Jul 21 07:32:35.992098 2026] [security2:error] [pid 254995:tid 255078] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kw_7v0rlcEGmVraEktAADSVI"]
[Tue Jul 21 07:32:35.992247 2026] [security2:error] [pid 254995:tid 255168] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kw_7v0rlcEGmVraEktAADSVI"]
[Tue Jul 21 07:32:35.993946 2026] [security2:error] [pid 255769:tid 255942] [client 20.151.10.161:57361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/goods.php"] [unique_id "al9Kw7xMYwyVGnfuwsJ9hgAAA84"]
[Tue Jul 21 07:32:36.063919 2026] [proxy:error] [pid 254995:tid 255218] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:36.064000 2026] [proxy_http:error] [pid 254995:tid 255218] [client 20.206.105.145:38942] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:36.064536 2026] [proxy:error] [pid 254995:tid 255218] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:36.064559 2026] [proxy_http:error] [pid 254995:tid 255218] [client 20.206.105.145:38942] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:36.114897 2026] [security2:error] [pid 255769:tid 256026] [client 154.192.233.199:59268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9hwAABCA"]
[Tue Jul 21 07:32:36.115024 2026] [security2:error] [pid 255769:tid 256026] [client 154.192.233.199:59268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9hwAABCA"]
[Tue Jul 21 07:32:36.150824 2026] [security2:error] [pid 254995:tid 255138] [client 20.220.225.223:19272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/wpx.php"] [unique_id "al9KxP7v0rlcEGmVraEkuAAAAys"]
[Tue Jul 21 07:32:36.189247 2026] [fcgid:warn] [pid 255769:tid 255959] (70014)End of file found: [client 199.45.155.74:42534] mod_fcgid: can't get data from http client
[Tue Jul 21 07:32:36.442377 2026] [security2:error] [pid 254995:tid 255257] [client 62.102.148.164:50644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9KxP7v0rlcEGmVraEkuwAAA4c"]
[Tue Jul 21 07:32:36.442498 2026] [security2:error] [pid 254995:tid 255257] [client 62.102.148.164:50644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9KxP7v0rlcEGmVraEkuwAAA4c"]
[Tue Jul 21 07:32:36.499979 2026] [security2:error] [pid 255769:tid 255967] [client 20.206.105.145:7758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/app.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9kQAAA-c"]
[Tue Jul 21 07:32:36.714821 2026] [security2:error] [pid 255769:tid 255856] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9lgAD7FY"]
[Tue Jul 21 07:32:36.715014 2026] [security2:error] [pid 255769:tid 255972] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9lgAD7FY"]
[Tue Jul 21 07:32:36.753585 2026] [security2:error] [pid 255769:tid 255993] [client 20.220.225.223:6796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/cron-tab.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9mAAABAA"]
[Tue Jul 21 07:32:36.787122 2026] [security2:error] [pid 255769:tid 255994] [client 45.8.17.64:57763] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/customize/class-wp-widget-area-customize-control-interpreter.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9mQAABAE"]
[Tue Jul 21 07:32:36.830092 2026] [security2:error] [pid 255769:tid 255997] [client 20.206.105.145:39281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-content/index.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9nAAABAM"]
[Tue Jul 21 07:32:36.872887 2026] [security2:error] [pid 255769:tid 255965] [client 175.45.70.82:53064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9ngAAA-U"]
[Tue Jul 21 07:32:36.873077 2026] [security2:error] [pid 255769:tid 255965] [client 175.45.70.82:53064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9ngAAA-U"]
[Tue Jul 21 07:32:36.988017 2026] [security2:error] [pid 255769:tid 255975] [client 45.251.232.145:50260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9nwAAA-8"]
[Tue Jul 21 07:32:36.988138 2026] [security2:error] [pid 255769:tid 255975] [client 45.251.232.145:50260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9nwAAA-8"]
[Tue Jul 21 07:32:37.168569 2026] [security2:error] [pid 255769:tid 255910] [client 37.140.223.138:23125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9nQAAA64"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:32:37.521250 2026] [security2:error] [pid 255769:tid 255861] [remote 41.76.214.143:40854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiferreira.com.br"] [uri "/wp-login.php"] [unique_id "al9KxbxMYwyVGnfuwsJ9rQAEAls"]
[Tue Jul 21 07:32:37.625795 2026] [security2:error] [pid 255769:tid 255902] [client 213.152.162.104:39486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9KxbxMYwyVGnfuwsJ9rgAAA6Y"]
[Tue Jul 21 07:32:37.625947 2026] [security2:error] [pid 255769:tid 255902] [client 213.152.162.104:39486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9KxbxMYwyVGnfuwsJ9rgAAA6Y"]
[Tue Jul 21 07:32:37.667634 2026] [security2:error] [pid 255769:tid 255947] [client 193.36.225.58:42171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KxbxMYwyVGnfuwsJ9rAAAA9M"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:37.695189 2026] [security2:error] [pid 255769:tid 255939] [client 45.8.17.124:65439] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/ai-client/adapters/admin.php"] [unique_id "al9KxbxMYwyVGnfuwsJ9rwAAA8s"]
[Tue Jul 21 07:32:37.717949 2026] [security2:error] [pid 254995:tid 255131] [client 20.206.105.145:39282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/zoro.php"] [unique_id "al9Kxf7v0rlcEGmVraEkygAAAyQ"]
[Tue Jul 21 07:32:37.889900 2026] [security2:error] [pid 254995:tid 255254] [client 103.174.34.15:61477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kxf7v0rlcEGmVraEkzwAAA4Q"]
[Tue Jul 21 07:32:37.890036 2026] [security2:error] [pid 254995:tid 255254] [client 103.174.34.15:61477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kxf7v0rlcEGmVraEkzwAAA4Q"]
[Tue Jul 21 07:32:38.046072 2026] [security2:error] [pid 255769:tid 255922] [client 20.220.225.223:19664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/berlin.php"] [unique_id "al9KxrxMYwyVGnfuwsJ9tgAAA7o"]
[Tue Jul 21 07:32:38.273505 2026] [security2:error] [pid 255769:tid 256019] [client 74.248.121.109:2136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KxbxMYwyVGnfuwsJ9pgAABBk"]
[Tue Jul 21 07:32:38.394641 2026] [security2:error] [pid 255769:tid 255903] [client 117.217.38.194:55370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KxrxMYwyVGnfuwsJ9wgAAA6c"]
[Tue Jul 21 07:32:38.394748 2026] [security2:error] [pid 255769:tid 255903] [client 117.217.38.194:55370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KxrxMYwyVGnfuwsJ9wgAAA6c"]
[Tue Jul 21 07:32:38.472347 2026] [security2:error] [pid 254995:tid 255222] [client 20.206.105.145:7573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/core.php"] [unique_id "al9Kxv7v0rlcEGmVraEk2QAAA34"]
[Tue Jul 21 07:32:38.472353 2026] [security2:error] [pid 254995:tid 255005] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kxv7v0rlcEGmVraEk2gADPgk"]
[Tue Jul 21 07:32:38.472508 2026] [security2:error] [pid 254995:tid 255157] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kxv7v0rlcEGmVraEk2gADPgk"]
[Tue Jul 21 07:32:38.817131 2026] [security2:error] [pid 254995:tid 255174] [client 74.248.121.109:1086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Kxv7v0rlcEGmVraEk3wAAA08"]
[Tue Jul 21 07:32:38.843184 2026] [security2:error] [pid 255769:tid 255926] [client 122.129.67.13:60792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9KxrxMYwyVGnfuwsJ9xgAAA74"]
[Tue Jul 21 07:32:38.900074 2026] [security2:error] [pid 255769:tid 255960] [client 45.8.17.103:55285] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/widget-group/index.php"] [unique_id "al9KxrxMYwyVGnfuwsJ9ywAAA-A"]
[Tue Jul 21 07:32:38.975850 2026] [security2:error] [pid 255769:tid 255978] [client 173.252.95.41:53416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9KxrxMYwyVGnfuwsJ9zgAAA_I"]
[Tue Jul 21 07:32:39.261632 2026] [security2:error] [pid 254995:tid 255145] [client 74.248.121.109:1025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/wp.php"] [unique_id "al9Kx_7v0rlcEGmVraEk5AAAAzI"]
[Tue Jul 21 07:32:39.492691 2026] [security2:error] [pid 255769:tid 256015] [client 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/12ohqpluagtoz1nkdo1tqazo1e.php"] [unique_id "al9Kx7xMYwyVGnfuwsJ91wAABBU"]
[Tue Jul 21 07:32:39.723365 2026] [security2:error] [pid 254995:tid 255136] [client 74.248.121.109:1036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/new.php"] [unique_id "al9Kx_7v0rlcEGmVraEk7wAAAyk"]
[Tue Jul 21 07:32:39.935938 2026] [security2:error] [pid 255769:tid 255870] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Kx7xMYwyVGnfuwsJ94QADy2Q"]
[Tue Jul 21 07:32:39.936204 2026] [security2:error] [pid 255769:tid 255939] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Kx7xMYwyVGnfuwsJ94QADy2Q"]
[Tue Jul 21 07:32:39.937533 2026] [security2:error] [pid 254995:tid 255229] [client 20.206.105.145:7689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/main.php"] [unique_id "al9Kx_7v0rlcEGmVraEk9QAAA4I"]
[Tue Jul 21 07:32:39.993651 2026] [security2:error] [pid 255769:tid 256018] [client 45.8.17.60:22601] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/preformatted/index.php"] [unique_id "al9Kx7xMYwyVGnfuwsJ94wAABBg"]
[Tue Jul 21 07:32:40.168464 2026] [security2:error] [pid 254995:tid 255268] [client 74.248.121.109:2129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/class-t.api.php"] [unique_id "al9KyP7v0rlcEGmVraEk-QAAA5I"]
[Tue Jul 21 07:32:40.185177 2026] [security2:error] [pid 255769:tid 255899] [client 20.220.225.223:19292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/billur.php"] [unique_id "al9KyLxMYwyVGnfuwsJ95AAAA6M"]
[Tue Jul 21 07:32:40.197453 2026] [security2:error] [pid 255769:tid 255921] [client 20.206.105.145:39292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/admin.php"] [unique_id "al9KyLxMYwyVGnfuwsJ95QAAA7k"]
[Tue Jul 21 07:32:40.226506 2026] [security2:error] [pid 254995:tid 255001] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KyP7v0rlcEGmVraEk-gADRgU"]
[Tue Jul 21 07:32:40.226636 2026] [security2:error] [pid 254995:tid 255165] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KyP7v0rlcEGmVraEk-gADRgU"]
[Tue Jul 21 07:32:40.385272 2026] [security2:error] [pid 255769:tid 255942] [client 20.220.225.223:46098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/bscclapb.php"] [unique_id "al9KyLxMYwyVGnfuwsJ96wAAA84"]
[Tue Jul 21 07:32:40.414928 2026] [security2:error] [pid 255769:tid 256019] [client 20.151.10.161:50914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/ms-edit.php"] [unique_id "al9KyLxMYwyVGnfuwsJ97AAABBk"]
[Tue Jul 21 07:32:40.524150 2026] [security2:error] [pid 254995:tid 255149] [client 20.220.225.223:6823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/koiy.php"] [unique_id "al9KyP7v0rlcEGmVraElBQAAAzY"]
[Tue Jul 21 07:32:40.610044 2026] [security2:error] [pid 255769:tid 255924] [client 74.248.121.109:1084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/plugins.php"] [unique_id "al9KyLxMYwyVGnfuwsJ97QAAA7w"]
[Tue Jul 21 07:32:40.795541 2026] [security2:error] [pid 254995:tid 255127] [client 193.36.225.142:20799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9KyP7v0rlcEGmVraElBgAAAyA"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:32:40.862509 2026] [security2:error] [pid 254995:tid 255125] [client 20.197.195.24:13170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/155.php"] [unique_id "al9KyP7v0rlcEGmVraElCwAAAx4"]
[Tue Jul 21 07:32:40.951588 2026] [security2:error] [pid 254995:tid 255177] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/backend/.env"] [unique_id "al9KyP7v0rlcEGmVraElDgAAA1I"]
[Tue Jul 21 07:32:41.086329 2026] [security2:error] [pid 255769:tid 255944] [client 74.248.121.109:1067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/jp.php"] [unique_id "al9KybxMYwyVGnfuwsJ99wAAA9A"]
[Tue Jul 21 07:32:41.283084 2026] [security2:error] [pid 255769:tid 255983] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9KybxMYwyVGnfuwsJ9-AAAA_c"]
[Tue Jul 21 07:32:41.487208 2026] [security2:error] [pid 255769:tid 255997] [client 20.206.105.145:7705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/init.php"] [unique_id "al9KybxMYwyVGnfuwsJ9_QAABAM"]
[Tue Jul 21 07:32:41.506724 2026] [security2:error] [pid 255769:tid 255965] [client 74.248.121.109:1052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/error.php"] [unique_id "al9KybxMYwyVGnfuwsJ9_gAAA-U"]
[Tue Jul 21 07:32:41.639582 2026] [security2:error] [pid 254995:tid 255154] [client 20.206.105.145:39277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/greap.php"] [unique_id "al9Kyf7v0rlcEGmVraElGQAAAzs"]
[Tue Jul 21 07:32:41.876571 2026] [security2:error] [pid 254995:tid 255229] [client 20.220.225.223:46011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/else1.php"] [unique_id "al9Kyf7v0rlcEGmVraElGwAAA4I"]
[Tue Jul 21 07:32:41.941427 2026] [security2:error] [pid 254995:tid 255195] [client 74.248.121.109:1059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/classwithtostring.php"] [unique_id "al9Kyf7v0rlcEGmVraElHAAAA2Q"]
[Tue Jul 21 07:32:41.989511 2026] [security2:error] [pid 255769:tid 255974] [client 45.8.17.129:27927] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/list/list/wp-config.php"] [unique_id "al9KybxMYwyVGnfuwsJ-BAAAA-4"]
[Tue Jul 21 07:32:42.382841 2026] [security2:error] [pid 254995:tid 255148] [client 172.245.102.44:49415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Kyv7v0rlcEGmVraElJgAAAzU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:42.408322 2026] [security2:error] [pid 254995:tid 255200] [client 74.248.121.109:2119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/bless.php"] [unique_id "al9Kyv7v0rlcEGmVraElJwAAA2k"]
[Tue Jul 21 07:32:42.543144 2026] [security2:error] [pid 255769:tid 256016] [client 20.151.10.161:51308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/222.php"] [unique_id "al9KyrxMYwyVGnfuwsJ-CwAABBY"]
[Tue Jul 21 07:32:42.626803 2026] [security2:error] [pid 254995:tid 255222] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/source/.env"] [unique_id "al9Kyv7v0rlcEGmVraElKwAAA34"]
[Tue Jul 21 07:32:42.729562 2026] [security2:error] [pid 255769:tid 255879] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KyrxMYwyVGnfuwsJ-DQADqW0"]
[Tue Jul 21 07:32:42.729715 2026] [security2:error] [pid 255769:tid 255905] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KyrxMYwyVGnfuwsJ-DQADqW0"]
[Tue Jul 21 07:32:42.789220 2026] [security2:error] [pid 255769:tid 255957] [client 59.96.220.140:62310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KyrxMYwyVGnfuwsJ-DgAAA90"]
[Tue Jul 21 07:32:42.789341 2026] [security2:error] [pid 255769:tid 255957] [client 59.96.220.140:62310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KyrxMYwyVGnfuwsJ-DgAAA90"]
[Tue Jul 21 07:32:42.912214 2026] [security2:error] [pid 254995:tid 255163] [client 74.248.121.109:2143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/storage/index.php"] [unique_id "al9Kyv7v0rlcEGmVraElLgAAA0Q"]
[Tue Jul 21 07:32:42.982509 2026] [security2:error] [pid 254995:tid 255138] [client 20.220.225.223:46122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/tkikikoko.php"] [unique_id "al9Kyv7v0rlcEGmVraElLwAAAys"]
[Tue Jul 21 07:32:43.008523 2026] [security2:error] [pid 255769:tid 255900] [client 20.220.225.223:19296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/mimpi.php"] [unique_id "al9Ky7xMYwyVGnfuwsJ-EQAAA6Q"]
[Tue Jul 21 07:32:43.083522 2026] [security2:error] [pid 254995:tid 255036] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ky_7v0rlcEGmVraElMQADiig"]
[Tue Jul 21 07:32:43.083701 2026] [security2:error] [pid 254995:tid 255260] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ky_7v0rlcEGmVraElMQADiig"]
[Tue Jul 21 07:32:43.086446 2026] [security2:error] [pid 255769:tid 255880] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ky7xMYwyVGnfuwsJ-EwADtW4"]
[Tue Jul 21 07:32:43.086610 2026] [security2:error] [pid 255769:tid 255917] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ky7xMYwyVGnfuwsJ-EwADtW4"]
[Tue Jul 21 07:32:43.138362 2026] [security2:error] [pid 255769:tid 255947] [client 139.167.225.182:62447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ky7xMYwyVGnfuwsJ-FgAAA9M"]
[Tue Jul 21 07:32:43.138500 2026] [security2:error] [pid 255769:tid 255947] [client 139.167.225.182:62447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ky7xMYwyVGnfuwsJ-FgAAA9M"]
[Tue Jul 21 07:32:43.164488 2026] [security2:error] [pid 255769:tid 255982] [client 20.206.105.145:7247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/prekel.php"] [unique_id "al9Ky7xMYwyVGnfuwsJ-GAAAA_Y"]
[Tue Jul 21 07:32:43.184106 2026] [security2:error] [pid 254995:tid 255150] [client 20.206.105.145:38920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/177.php"] [unique_id "al9Ky_7v0rlcEGmVraElNAAAAzc"]
[Tue Jul 21 07:32:43.348876 2026] [security2:error] [pid 255769:tid 255940] [client 74.248.121.109:1031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/g.php"] [unique_id "al9Ky7xMYwyVGnfuwsJ-GwAAA8w"]
[Tue Jul 21 07:32:43.479535 2026] [security2:error] [pid 254995:tid 255157] [client 117.251.86.144:39844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Ky_7v0rlcEGmVraElOgAAAz4"]
[Tue Jul 21 07:32:43.479652 2026] [security2:error] [pid 254995:tid 255157] [client 117.251.86.144:39844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Ky_7v0rlcEGmVraElOgAAAz4"]
[Tue Jul 21 07:32:43.520040 2026] [security2:error] [pid 255769:tid 255884] [remote 81.173.115.7:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9Ky7xMYwyVGnfuwsJ-IwAD23I"]
[Tue Jul 21 07:32:43.555995 2026] [security2:error] [pid 255769:tid 255970] [client 20.220.225.223:9252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/hp2.php"] [unique_id "al9Ky7xMYwyVGnfuwsJ-JgAAA-o"]
[Tue Jul 21 07:32:43.697723 2026] [security2:error] [pid 255769:tid 255885] [remote 45.79.123.44:57184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "woma.com.br"] [uri "/wp-login.php"] [unique_id "al9Ky7xMYwyVGnfuwsJ-KAAD3HM"]
[Tue Jul 21 07:32:43.777228 2026] [security2:error] [pid 254995:tid 255137] [client 74.248.121.109:2091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/nf.php"] [unique_id "al9Ky_7v0rlcEGmVraElPgAAAyo"]
[Tue Jul 21 07:32:43.778937 2026] [security2:error] [pid 255769:tid 255983] [client 45.8.17.129:53027] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/post-author-biography/post-author-biography/class-wp-http.php"] [unique_id "al9Ky7xMYwyVGnfuwsJ-KQAAA_c"]
[Tue Jul 21 07:32:44.030786 2026] [security2:error] [pid 254995:tid 255127] [client 103.162.129.114:59585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KzP7v0rlcEGmVraElQwAAAyA"]
[Tue Jul 21 07:32:44.030917 2026] [security2:error] [pid 254995:tid 255127] [client 103.162.129.114:59585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KzP7v0rlcEGmVraElQwAAAyA"]
[Tue Jul 21 07:32:44.212615 2026] [security2:error] [pid 255769:tid 255990] [client 74.248.121.109:2140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/xda.php"] [unique_id "al9KzLxMYwyVGnfuwsJ-NgAAA_4"]
[Tue Jul 21 07:32:44.311386 2026] [security2:error] [pid 255769:tid 256025] [client 20.151.10.161:57372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9KzLxMYwyVGnfuwsJ-OgAABB8"]
[Tue Jul 21 07:32:44.358598 2026] [security2:error] [pid 255769:tid 255958] [client 152.59.154.239:62742] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KzLxMYwyVGnfuwsJ-OwAAA94"]
[Tue Jul 21 07:32:44.358755 2026] [security2:error] [pid 255769:tid 255958] [client 152.59.154.239:62742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KzLxMYwyVGnfuwsJ-OwAAA94"]
[Tue Jul 21 07:32:44.588428 2026] [security2:error] [pid 255769:tid 255975] [client 20.220.225.223:19266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/dp.php"] [unique_id "al9KzLxMYwyVGnfuwsJ-PAAAA-8"]
[Tue Jul 21 07:32:44.637993 2026] [security2:error] [pid 254995:tid 255200] [client 74.248.121.109:1055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/shell.php"] [unique_id "al9KzP7v0rlcEGmVraElTgAAA2k"]
[Tue Jul 21 07:32:44.650694 2026] [security2:error] [pid 255769:tid 255972] [client 122.186.204.214:59651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KzLxMYwyVGnfuwsJ-PgAAA-w"]
[Tue Jul 21 07:32:44.650840 2026] [security2:error] [pid 255769:tid 255972] [client 122.186.204.214:59651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KzLxMYwyVGnfuwsJ-PgAAA-w"]
[Tue Jul 21 07:32:44.686572 2026] [security2:error] [pid 255769:tid 256023] [client 45.8.17.61:32121] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/post-time-to-read/post-time-to-read/post-template.php"] [unique_id "al9KzLxMYwyVGnfuwsJ-QQAABB0"]
[Tue Jul 21 07:32:44.958649 2026] [security2:error] [pid 255769:tid 256008] [client 193.36.225.103:38971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9KzLxMYwyVGnfuwsJ-RAAABA4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:32:44.976585 2026] [security2:error] [pid 254995:tid 255077] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KzP7v0rlcEGmVraElUgADe1E"]
[Tue Jul 21 07:32:44.976733 2026] [security2:error] [pid 254995:tid 255219] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KzP7v0rlcEGmVraElUgADe1E"]
[Tue Jul 21 07:32:45.085982 2026] [security2:error] [pid 255769:tid 255904] [client 74.248.121.109:1069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/3.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-RgAAA6g"]
[Tue Jul 21 07:32:45.328258 2026] [security2:error] [pid 255769:tid 255934] [client 20.52.136.55:1785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/autoload_classmap.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-TAAAA8Y"]
[Tue Jul 21 07:32:45.350074 2026] [security2:error] [pid 255769:tid 255924] [client 20.206.105.145:38956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/199.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-TQAAA7w"]
[Tue Jul 21 07:32:45.414254 2026] [security2:error] [pid 255769:tid 256026] [client 20.220.225.223:9223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/hp3.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-UAAABCA"]
[Tue Jul 21 07:32:45.506711 2026] [security2:error] [pid 255769:tid 255770] [remote 41.186.86.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexandrevitor1781543539748.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-UQAEGQA"]
[Tue Jul 21 07:32:45.506957 2026] [security2:error] [pid 255769:tid 256019] [client 41.186.86.12:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "alexandrevitor1781543539748.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-UQAEGQA"]
[Tue Jul 21 07:32:45.592984 2026] [security2:error] [pid 255769:tid 255955] [client 45.8.17.125:30861] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/post-template/post-template/api-gateway.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-UwAAA9s"]
[Tue Jul 21 07:32:45.606116 2026] [security2:error] [pid 255769:tid 255973] [client 74.248.121.109:1077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/mds.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-VAAAA-0"]
[Tue Jul 21 07:32:45.635485 2026] [security2:error] [pid 255769:tid 255946] [client 20.220.225.223:46134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-VgAAA9I"]
[Tue Jul 21 07:32:45.798148 2026] [security2:error] [pid 255769:tid 255960] [client 20.206.105.145:7787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/0.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-XQAAA-A"]
[Tue Jul 21 07:32:45.906357 2026] [security2:error] [pid 255769:tid 255980] [client 62.102.148.164:55366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-XgAAA_Q"]
[Tue Jul 21 07:32:45.906476 2026] [security2:error] [pid 255769:tid 255980] [client 62.102.148.164:55366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-XgAAA_Q"]
[Tue Jul 21 07:32:45.907614 2026] [security2:error] [pid 255769:tid 256006] [client 20.197.195.24:13177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/ops.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-XwAABAw"]
[Tue Jul 21 07:32:45.948480 2026] [security2:error] [pid 255769:tid 255968] [client 173.24.185.52:58705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-YAAAA-g"]
[Tue Jul 21 07:32:45.948620 2026] [security2:error] [pid 255769:tid 255968] [client 173.24.185.52:58705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-YAAAA-g"]
[Tue Jul 21 07:32:46.054616 2026] [security2:error] [pid 255769:tid 256000] [client 74.248.121.109:2139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/archive.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-YQAABAY"]
[Tue Jul 21 07:32:46.244043 2026] [security2:error] [pid 255769:tid 256013] [client 20.220.225.223:8115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/aa1.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-agAABBM"]
[Tue Jul 21 07:32:46.255729 2026] [security2:error] [pid 255769:tid 256028] [client 103.106.20.201:52187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-awAABCI"]
[Tue Jul 21 07:32:46.255877 2026] [security2:error] [pid 255769:tid 256028] [client 103.106.20.201:52187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-awAABCI"]
[Tue Jul 21 07:32:46.261935 2026] [security2:error] [pid 255769:tid 255964] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/framework/.env"] [unique_id "al9KzrxMYwyVGnfuwsJ-bAAAA-Q"]
[Tue Jul 21 07:32:46.264222 2026] [security2:error] [pid 255769:tid 255972] [client 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/config.inc.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-bQAAA-w"]
[Tue Jul 21 07:32:46.343421 2026] [security2:error] [pid 254995:tid 255190] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/ikiwiki/.env"] [unique_id "al9Kzv7v0rlcEGmVraElYwAAA18"]
[Tue Jul 21 07:32:46.468480 2026] [security2:error] [pid 254995:tid 255078] [remote 8.217.108.67:19650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Kzv7v0rlcEGmVraElZgADPVI"]
[Tue Jul 21 07:32:46.473427 2026] [security2:error] [pid 254995:tid 255181] [client 74.248.121.109:2134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/amax.php"] [unique_id "al9Kzv7v0rlcEGmVraElZwAAA1Y"]
[Tue Jul 21 07:32:46.518094 2026] [security2:error] [pid 255769:tid 255907] [client 136.144.33.53:56073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-cQAAA6s"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:46.629843 2026] [security2:error] [pid 255769:tid 255778] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-eQAEHQg"]
[Tue Jul 21 07:32:46.629978 2026] [security2:error] [pid 255769:tid 256023] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-eQAEHQg"]
[Tue Jul 21 07:32:46.788864 2026] [security2:error] [pid 255769:tid 255947] [client 45.8.17.113:43467] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/customize/network/index.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-ewAAA9M"]
[Tue Jul 21 07:32:46.800552 2026] [security2:error] [pid 255769:tid 256014] [client 154.192.233.199:59730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-fAAABBQ"]
[Tue Jul 21 07:32:46.800657 2026] [security2:error] [pid 255769:tid 256014] [client 154.192.233.199:59730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-fAAABBQ"]
[Tue Jul 21 07:32:46.906358 2026] [security2:error] [pid 255769:tid 255908] [client 74.248.121.109:1064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/moon.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-gAAAA6w"]
[Tue Jul 21 07:32:46.969480 2026] [security2:error] [pid 254995:tid 255166] [client 82.102.28.107:41192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Kzv7v0rlcEGmVraElbQAAA0c"]
[Tue Jul 21 07:32:46.969579 2026] [security2:error] [pid 254995:tid 255166] [client 82.102.28.107:41192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Kzv7v0rlcEGmVraElbQAAA0c"]
[Tue Jul 21 07:32:47.299433 2026] [security2:error] [pid 255769:tid 255970] [client 20.206.105.145:7709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/BDKR28.php"] [unique_id "al9Kz7xMYwyVGnfuwsJ-gwAAA-o"]
[Tue Jul 21 07:32:47.419085 2026] [security2:error] [pid 255769:tid 255973] [client 37.140.223.191:59345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Kz7xMYwyVGnfuwsJ-ggAAA-0"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:32:47.443757 2026] [security2:error] [pid 255769:tid 255923] [client 74.248.121.109:1035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/ws83.php"] [unique_id "al9Kz7xMYwyVGnfuwsJ-hwAAA7s"]
[Tue Jul 21 07:32:47.468589 2026] [security2:error] [pid 255769:tid 255937] [client 45.251.232.145:50772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kz7xMYwyVGnfuwsJ-iAAAA8k"]
[Tue Jul 21 07:32:47.468730 2026] [security2:error] [pid 255769:tid 255937] [client 45.251.232.145:50772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kz7xMYwyVGnfuwsJ-iAAAA8k"]
[Tue Jul 21 07:32:47.643985 2026] [proxy:error] [pid 254995:tid 255185] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:47.644054 2026] [proxy_http:error] [pid 254995:tid 255185] [client 20.151.10.161:50898] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:47.644483 2026] [proxy:error] [pid 254995:tid 255185] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:47.644516 2026] [proxy_http:error] [pid 254995:tid 255185] [client 20.151.10.161:50898] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:47.661911 2026] [security2:error] [pid 255769:tid 255792] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Kz7xMYwyVGnfuwsJ-jAAD3xY"]
[Tue Jul 21 07:32:47.662713 2026] [security2:error] [pid 255769:tid 255959] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Kz7xMYwyVGnfuwsJ-jAAD3xY"]
[Tue Jul 21 07:32:47.668292 2026] [security2:error] [pid 255769:tid 256026] [client 175.45.70.82:53585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kz7xMYwyVGnfuwsJ-jgAABCA"]
[Tue Jul 21 07:32:47.668393 2026] [security2:error] [pid 255769:tid 256026] [client 175.45.70.82:53585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kz7xMYwyVGnfuwsJ-jgAABCA"]
[Tue Jul 21 07:32:47.892580 2026] [security2:error] [pid 255769:tid 255950] [client 20.220.225.223:49578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Kz7xMYwyVGnfuwsJ-kgAAA9Y"]
[Tue Jul 21 07:32:47.908878 2026] [security2:error] [pid 254995:tid 255149] [client 74.248.121.109:1071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/CDX1.php"] [unique_id "al9Kz_7v0rlcEGmVraElhAAAAzY"]
[Tue Jul 21 07:32:47.993228 2026] [security2:error] [pid 254995:tid 255252] [client 20.220.225.223:8075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/acew67.php"] [unique_id "al9Kz_7v0rlcEGmVraElhQAAA4M"]
[Tue Jul 21 07:32:48.016978 2026] [security2:error] [pid 254995:tid 255133] [client 213.152.162.104:55686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9K0P7v0rlcEGmVraElhgAAAyY"]
[Tue Jul 21 07:32:48.017105 2026] [security2:error] [pid 254995:tid 255133] [client 213.152.162.104:55686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9K0P7v0rlcEGmVraElhgAAAyY"]
[Tue Jul 21 07:32:48.092911 2026] [security2:error] [pid 255769:tid 256015] [client 45.8.17.142:58255] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/widgets/theme-compat/index.php"] [unique_id "al9K0LxMYwyVGnfuwsJ-lAAABBU"]
[Tue Jul 21 07:32:48.359473 2026] [security2:error] [pid 255769:tid 256028] [client 74.248.121.109:2117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/inputs.php"] [unique_id "al9K0LxMYwyVGnfuwsJ-mQAABCI"]
[Tue Jul 21 07:32:48.419013 2026] [security2:error] [pid 255769:tid 255916] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/system/.env"] [unique_id "al9K0LxMYwyVGnfuwsJ-nwAAA7Q"]
[Tue Jul 21 07:32:48.421666 2026] [security2:error] [pid 255769:tid 255952] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/wp-config.php.backup"] [unique_id "al9K0LxMYwyVGnfuwsJ-oAAAA9g"]
[Tue Jul 21 07:32:48.461787 2026] [security2:error] [pid 255769:tid 255957] [client 20.220.225.223:38686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/wp-signup.php"] [unique_id "al9K0LxMYwyVGnfuwsJ-ogAAA90"]
[Tue Jul 21 07:32:48.481188 2026] [security2:error] [pid 255769:tid 256006] [client 103.174.34.15:61966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K0LxMYwyVGnfuwsJ-owAABAw"]
[Tue Jul 21 07:32:48.481337 2026] [security2:error] [pid 255769:tid 256006] [client 103.174.34.15:61966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K0LxMYwyVGnfuwsJ-owAABAw"]
[Tue Jul 21 07:32:48.540381 2026] [security2:error] [pid 255769:tid 255990] [client 171.61.166.54:30552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.166.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiapleno.com"] [uri "/xmlrpc.php"] [unique_id "al9K0LxMYwyVGnfuwsJ-mgAAA_4"]
[Tue Jul 21 07:32:48.540556 2026] [security2:error] [pid 255769:tid 255990] [client 171.61.166.54:30552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "guiapleno.com"] [uri "/xmlrpc.php"] [unique_id "al9K0LxMYwyVGnfuwsJ-mgAAA_4"]
[Tue Jul 21 07:32:48.736205 2026] [security2:error] [pid 255769:tid 256021] [client 20.220.225.223:4562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/dp.php"] [unique_id "al9K0LxMYwyVGnfuwsJ-pQAABBs"]
[Tue Jul 21 07:32:48.791860 2026] [security2:error] [pid 255769:tid 255900] [client 74.248.121.109:1061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/ms-edit.php"] [unique_id "al9K0LxMYwyVGnfuwsJ-pwAAA6Q"]
[Tue Jul 21 07:32:48.919102 2026] [security2:error] [pid 254995:tid 255174] [client 117.217.38.194:55805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K0P7v0rlcEGmVraElkAAAA08"]
[Tue Jul 21 07:32:48.919215 2026] [security2:error] [pid 254995:tid 255174] [client 117.217.38.194:55805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K0P7v0rlcEGmVraElkAAAA08"]
[Tue Jul 21 07:32:48.943070 2026] [security2:error] [pid 254995:tid 255193] [client 20.220.225.223:24205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9K0P7v0rlcEGmVraElkwAAA2I"]
[Tue Jul 21 07:32:48.987520 2026] [security2:error] [pid 255769:tid 255799] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K0LxMYwyVGnfuwsJ-qwADuR0"]
[Tue Jul 21 07:32:48.987684 2026] [security2:error] [pid 255769:tid 255921] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K0LxMYwyVGnfuwsJ-qwADuR0"]
[Tue Jul 21 07:32:49.090205 2026] [security2:error] [pid 254995:tid 255139] [client 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/app_dev.php/_profiler/open"] [unique_id "al9K0f7v0rlcEGmVraEllQAAAyw"]
[Tue Jul 21 07:32:49.102420 2026] [security2:error] [pid 254995:tid 255156] [client 20.206.105.145:7704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/f35.update.php"] [unique_id "al9K0f7v0rlcEGmVraEllgAAAz0"]
[Tue Jul 21 07:32:49.142358 2026] [security2:error] [pid 254995:tid 255181] [client 20.206.105.145:39235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file52.php"] [unique_id "al9K0f7v0rlcEGmVraEllwAAA1Y"]
[Tue Jul 21 07:32:49.190922 2026] [security2:error] [pid 255769:tid 255924] [client 20.220.225.223:49819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9K0bxMYwyVGnfuwsJ-rQAAA7w"]
[Tue Jul 21 07:32:49.252336 2026] [security2:error] [pid 255769:tid 255955] [client 74.248.121.109:2113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/simple.php"] [unique_id "al9K0bxMYwyVGnfuwsJ-sAAAA9s"]
[Tue Jul 21 07:32:49.255330 2026] [security2:error] [pid 254995:tid 255155] [client 20.197.195.24:13172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/file31.php"] [unique_id "al9K0f7v0rlcEGmVraElmgAAAzw"]
[Tue Jul 21 07:32:49.286396 2026] [security2:error] [pid 254995:tid 255154] [client 45.8.17.59:40259] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/upgrade/patterns/index.php"] [unique_id "al9K0f7v0rlcEGmVraElnAAAAzs"]
[Tue Jul 21 07:32:49.301148 2026] [security2:error] [pid 254995:tid 255202] [client 20.220.225.223:6791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/bscclapb.php"] [unique_id "al9K0f7v0rlcEGmVraElnQAAA2s"]
[Tue Jul 21 07:32:49.328292 2026] [security2:error] [pid 254995:tid 255136] [client 213.152.162.104:48208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9K0f7v0rlcEGmVraElngAAAyk"]
[Tue Jul 21 07:32:49.328374 2026] [security2:error] [pid 254995:tid 255136] [client 213.152.162.104:48208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9K0f7v0rlcEGmVraElngAAAyk"]
[Tue Jul 21 07:32:49.472533 2026] [security2:error] [pid 255769:tid 255994] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/wp-content/mysql.sql"] [unique_id "al9K0bxMYwyVGnfuwsJ-twAABAE"]
[Tue Jul 21 07:32:49.698450 2026] [security2:error] [pid 255769:tid 255998] [client 74.248.121.109:2154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/404.php"] [unique_id "al9K0bxMYwyVGnfuwsJ-uQAABAQ"]
[Tue Jul 21 07:32:49.769024 2026] [security2:error] [pid 255769:tid 255992] [client 193.36.225.103:45273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9K0bxMYwyVGnfuwsJ-vQAAA_8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:32:49.833912 2026] [security2:error] [pid 254995:tid 255084] [remote 57.141.18.84:38554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9Kz_7v0rlcEGmVraElggADK1g"]
[Tue Jul 21 07:32:49.874333 2026] [security2:error] [pid 255769:tid 256000] [client 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/php-info.php"] [unique_id "al9K0bxMYwyVGnfuwsJ-vwAABAY"]
[Tue Jul 21 07:32:50.163307 2026] [security2:error] [pid 254995:tid 255219] [client 74.248.121.109:1079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/file3.php"] [unique_id "al9K0v7v0rlcEGmVraElrQAAA3s"]
[Tue Jul 21 07:32:50.492396 2026] [security2:error] [pid 255769:tid 255975] [client 45.8.17.128:50475] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/images/widgets/index.php"] [unique_id "al9K0rxMYwyVGnfuwsJ-yQAAA-8"]
[Tue Jul 21 07:32:50.574203 2026] [security2:error] [pid 254995:tid 255135] [client 20.197.195.24:13168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/file6.php"] [unique_id "al9K0v7v0rlcEGmVraElswAAAyg"]
[Tue Jul 21 07:32:50.600714 2026] [security2:error] [pid 255769:tid 255952] [client 74.248.121.109:1037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/wp-mail.php"] [unique_id "al9K0rxMYwyVGnfuwsJ-zAAAA9g"]
[Tue Jul 21 07:32:50.647847 2026] [security2:error] [pid 255769:tid 255804] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K0rxMYwyVGnfuwsJ-zQAD3iI"]
[Tue Jul 21 07:32:50.647968 2026] [security2:error] [pid 255769:tid 255958] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K0rxMYwyVGnfuwsJ-zQAD3iI"]
[Tue Jul 21 07:32:50.703450 2026] [security2:error] [pid 255769:tid 256006] [client 20.151.10.161:50896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9K0rxMYwyVGnfuwsJ-zgAABAw"]
[Tue Jul 21 07:32:50.730274 2026] [security2:error] [pid 255769:tid 255907] [client 20.206.105.145:7717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/f900.php"] [unique_id "al9K0rxMYwyVGnfuwsJ-zwAAA6s"]
[Tue Jul 21 07:32:50.742678 2026] [security2:error] [pid 255769:tid 255809] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9K0rxMYwyVGnfuwsJ-0QAD_ic"]
[Tue Jul 21 07:32:50.742848 2026] [security2:error] [pid 255769:tid 255990] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9K0rxMYwyVGnfuwsJ-0QAD_ic"]
[Tue Jul 21 07:32:51.032827 2026] [security2:error] [pid 255769:tid 256014] [client 20.206.105.145:39253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/122.php"] [unique_id "al9K07xMYwyVGnfuwsJ-2AAABBQ"]
[Tue Jul 21 07:32:51.070219 2026] [security2:error] [pid 255769:tid 255908] [client 74.248.121.109:1043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/about.php"] [unique_id "al9K07xMYwyVGnfuwsJ-2gAAA6w"]
[Tue Jul 21 07:32:51.207182 2026] [access_compat:error] [pid 255769:tid 255948] [client 162.241.63.68:22062] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:32:51.243500 2026] [security2:error] [pid 254995:tid 255160] [client 136.144.33.29:60405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9K0_7v0rlcEGmVraElwAAAA0E"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:51.420472 2026] [proxy:error] [pid 255769:tid 255956] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:51.420511 2026] [proxy_http:error] [pid 255769:tid 255956] [client 198.235.24.243:59450] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:51.420946 2026] [proxy:error] [pid 255769:tid 255956] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:51.420968 2026] [proxy_http:error] [pid 255769:tid 255956] [client 198.235.24.243:59450] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:51.706762 2026] [security2:error] [pid 255769:tid 255923] [client 20.206.105.145:7581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/xmrl.php"] [unique_id "al9K07xMYwyVGnfuwsJ-4QAAA7s"]
[Tue Jul 21 07:32:51.759817 2026] [security2:error] [pid 255769:tid 255984] [client 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/info.php.bak"] [unique_id "al9K07xMYwyVGnfuwsJ-5AAAA_g"]
[Tue Jul 21 07:32:51.797228 2026] [security2:error] [pid 255769:tid 255994] [client 74.248.121.109:2057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/adminfuns.php"] [unique_id "al9K07xMYwyVGnfuwsJ-5QAABAE"]
[Tue Jul 21 07:32:51.908340 2026] [security2:error] [pid 255769:tid 255973] [client 193.36.225.105:24885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9K07xMYwyVGnfuwsJ-4gAAA-0"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:32:51.996980 2026] [security2:error] [pid 254995:tid 255275] [client 20.220.225.223:24242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9K0_7v0rlcEGmVraEl0AAAA5k"]
[Tue Jul 21 07:32:52.003954 2026] [autoindex:error] [pid 254995:tid 255166] [client 20.197.195.24:13121] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:32:52.012803 2026] [security2:error] [pid 254995:tid 255131] [client 20.197.195.24:13121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/adminfuns.php"] [unique_id "al9K1P7v0rlcEGmVraEl0QAAAyQ"]
[Tue Jul 21 07:32:52.115852 2026] [security2:error] [pid 254995:tid 255254] [client 20.52.136.55:1552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/av.php"] [unique_id "al9K1P7v0rlcEGmVraEl1QAAA4Q"]
[Tue Jul 21 07:32:52.157092 2026] [security2:error] [pid 254995:tid 255183] [client 82.102.28.107:49552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9K1P7v0rlcEGmVraEl1gAAA1g"]
[Tue Jul 21 07:32:52.157167 2026] [security2:error] [pid 254995:tid 255183] [client 82.102.28.107:49552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9K1P7v0rlcEGmVraEl1gAAA1g"]
[Tue Jul 21 07:32:52.284214 2026] [security2:error] [pid 254995:tid 255144] [client 45.8.17.108:58275] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/customize/includes/index.php"] [unique_id "al9K1P7v0rlcEGmVraEl2AAAAzE"]
[Tue Jul 21 07:32:52.337553 2026] [security2:error] [pid 254995:tid 255189] [client 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/phpinfo.php.bak"] [unique_id "al9K1P7v0rlcEGmVraEl2QAAA14"]
[Tue Jul 21 07:32:52.405384 2026] [security2:error] [pid 255769:tid 255961] [client 74.248.121.109:2069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/php8.php"] [unique_id "al9K1LxMYwyVGnfuwsJ-6gAAA-E"]
[Tue Jul 21 07:32:52.419226 2026] [security2:error] [pid 254995:tid 255138] [client 20.220.225.223:19267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/bootstrap.php"] [unique_id "al9K1P7v0rlcEGmVraEl2wAAAys"]
[Tue Jul 21 07:32:52.555058 2026] [security2:error] [pid 255769:tid 256002] [client 20.220.225.223:46086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/wp-css.php"] [unique_id "al9K1LxMYwyVGnfuwsJ-6wAABAg"]
[Tue Jul 21 07:32:52.662043 2026] [security2:error] [pid 254995:tid 255198] [client 20.206.105.145:54573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/memberfuns.php"] [unique_id "al9K1P7v0rlcEGmVraEl4QAAA2c"]
[Tue Jul 21 07:32:52.724882 2026] [security2:error] [pid 255769:tid 256028] [client 20.197.195.24:13069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/goods.php"] [unique_id "al9K1LxMYwyVGnfuwsJ-7wAABCI"]
[Tue Jul 21 07:32:52.729393 2026] [security2:error] [pid 255769:tid 255975] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/env/.env"] [unique_id "al9K1LxMYwyVGnfuwsJ-8AAAA-8"]
[Tue Jul 21 07:32:52.883602 2026] [security2:error] [pid 254995:tid 255141] [client 74.248.121.109:2125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/info.php"] [unique_id "al9K1P7v0rlcEGmVraEl5AAAAy4"]
[Tue Jul 21 07:32:52.995156 2026] [security2:error] [pid 255769:tid 255907] [client 74.7.244.14:47002] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "a12.arcoll.com.br"] [uri "/robots.txt"] [unique_id "al9K1LxMYwyVGnfuwsJ-9QADqy8"]
[Tue Jul 21 07:32:53.243112 2026] [security2:error] [pid 255769:tid 255927] [client 213.152.162.104:48220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9K1bxMYwyVGnfuwsJ--gAAA78"]
[Tue Jul 21 07:32:53.243260 2026] [security2:error] [pid 255769:tid 255927] [client 213.152.162.104:48220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9K1bxMYwyVGnfuwsJ--gAAA78"]
[Tue Jul 21 07:32:53.317001 2026] [security2:error] [pid 255769:tid 255820] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9K1bxMYwyVGnfuwsJ-_AAEGzI"]
[Tue Jul 21 07:32:53.317161 2026] [security2:error] [pid 255769:tid 256021] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9K1bxMYwyVGnfuwsJ-_AAEGzI"]
[Tue Jul 21 07:32:53.317725 2026] [security2:error] [pid 254995:tid 255155] [client 59.96.220.140:62791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9K1f7v0rlcEGmVraEl7AAAAzw"]
[Tue Jul 21 07:32:53.317880 2026] [security2:error] [pid 254995:tid 255155] [client 59.96.220.140:62791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9K1f7v0rlcEGmVraEl7AAAAzw"]
[Tue Jul 21 07:32:53.386676 2026] [security2:error] [pid 255769:tid 255904] [client 45.8.17.145:37063] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/colors/upgrade/index.php"] [unique_id "al9K1bxMYwyVGnfuwsJ-_QAAA6g"]
[Tue Jul 21 07:32:53.388570 2026] [security2:error] [pid 255769:tid 256022] [client 74.248.121.109:1049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/edit.php"] [unique_id "al9K1bxMYwyVGnfuwsJ-_gAABBw"]
[Tue Jul 21 07:32:53.400391 2026] [security2:error] [pid 255769:tid 255919] [client 20.197.195.24:13140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/100.php"] [unique_id "al9K1bxMYwyVGnfuwsJ-_wAAA7c"]
[Tue Jul 21 07:32:53.512643 2026] [security2:error] [pid 254995:tid 255157] [client 20.220.225.223:31213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/csa.php"] [unique_id "al9K1f7v0rlcEGmVraEl7wAAAz4"]
[Tue Jul 21 07:32:53.581495 2026] [security2:error] [pid 254995:tid 255024] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K1f7v0rlcEGmVraEl8AADOhw"]
[Tue Jul 21 07:32:53.581683 2026] [security2:error] [pid 254995:tid 255153] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K1f7v0rlcEGmVraEl8AADOhw"]
[Tue Jul 21 07:32:53.583075 2026] [security2:error] [pid 255769:tid 255953] [client 20.206.105.145:7466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/ms.php"] [unique_id "al9K1bxMYwyVGnfuwsJ_AgAAA9k"]
[Tue Jul 21 07:32:53.599240 2026] [security2:error] [pid 255769:tid 255947] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/src/.env"] [unique_id "al9K1bxMYwyVGnfuwsJ_AwAAA9M"]
[Tue Jul 21 07:32:53.688796 2026] [security2:error] [pid 255769:tid 255934] [client 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/config/app.php"] [unique_id "al9K1bxMYwyVGnfuwsJ_BgAAA8Y"]
[Tue Jul 21 07:32:53.796428 2026] [security2:error] [pid 255769:tid 255916] [client 139.167.225.182:63085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K1bxMYwyVGnfuwsJ_BwAAA7Q"]
[Tue Jul 21 07:32:53.796563 2026] [security2:error] [pid 255769:tid 255916] [client 139.167.225.182:63085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K1bxMYwyVGnfuwsJ_BwAAA7Q"]
[Tue Jul 21 07:32:53.846374 2026] [security2:error] [pid 254995:tid 255139] [client 74.248.121.109:1065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/166.php"] [unique_id "al9K1f7v0rlcEGmVraEl9wAAAyw"]
[Tue Jul 21 07:32:54.248393 2026] [security2:error] [pid 254995:tid 255267] [client 117.251.86.144:60520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9K1v7v0rlcEGmVraEmAAAAA5E"]
[Tue Jul 21 07:32:54.248499 2026] [security2:error] [pid 254995:tid 255267] [client 117.251.86.144:60520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9K1v7v0rlcEGmVraEmAAAAA5E"]
[Tue Jul 21 07:32:54.315280 2026] [security2:error] [pid 255769:tid 256018] [client 74.248.121.109:1083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/8.php"] [unique_id "al9K1rxMYwyVGnfuwsJ_DgAABBg"]
[Tue Jul 21 07:32:54.377141 2026] [security2:error] [pid 255769:tid 255984] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/web/.env"] [unique_id "al9K1rxMYwyVGnfuwsJ_DwAAA_g"]
[Tue Jul 21 07:32:54.388483 2026] [security2:error] [pid 255769:tid 255937] [client 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9K1rxMYwyVGnfuwsJ_EAAAA8k"]
[Tue Jul 21 07:32:54.440874 2026] [security2:error] [pid 255769:tid 255973] [client 20.206.105.145:39247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/green1.php"] [unique_id "al9K1rxMYwyVGnfuwsJ_EQAAA-0"]
[Tue Jul 21 07:32:54.553102 2026] [security2:error] [pid 255769:tid 255822] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K1bxMYwyVGnfuwsJ_AQAD9jQ"]
[Tue Jul 21 07:32:54.553313 2026] [security2:error] [pid 255769:tid 255982] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K1bxMYwyVGnfuwsJ_AQAD9jQ"]
[Tue Jul 21 07:32:54.609950 2026] [security2:error] [pid 255769:tid 256000] [client 20.197.195.24:13066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/about.php"] [unique_id "al9K1rxMYwyVGnfuwsJ_FQAABAY"]
[Tue Jul 21 07:32:54.684931 2026] [security2:error] [pid 255769:tid 255981] [client 45.8.17.48:40049] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/news-portal/user-install.php"] [unique_id "al9K1rxMYwyVGnfuwsJ_GAAAA_U"]
[Tue Jul 21 07:32:54.721713 2026] [security2:error] [pid 255769:tid 256025] [client 20.206.105.145:7751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/zz.php"] [unique_id "al9K1rxMYwyVGnfuwsJ_HAAABB8"]
[Tue Jul 21 07:32:54.780992 2026] [security2:error] [pid 254995:tid 255268] [client 109.248.148.246:58816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9K1v7v0rlcEGmVraEmCwAAA5I"]
[Tue Jul 21 07:32:54.781172 2026] [security2:error] [pid 254995:tid 255268] [client 109.248.148.246:58816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9K1v7v0rlcEGmVraEmCwAAA5I"]
[Tue Jul 21 07:32:54.781208 2026] [security2:error] [pid 254995:tid 255254] [client 74.248.121.109:2048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/ws38.php"] [unique_id "al9K1v7v0rlcEGmVraEmDAAAA4Q"]
[Tue Jul 21 07:32:54.814379 2026] [security2:error] [pid 255769:tid 255949] [client 103.162.129.114:60030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9K1rxMYwyVGnfuwsJ_HwAAA9U"]
[Tue Jul 21 07:32:54.814507 2026] [security2:error] [pid 255769:tid 255949] [client 103.162.129.114:60030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9K1rxMYwyVGnfuwsJ_HwAAA9U"]
[Tue Jul 21 07:32:55.225181 2026] [security2:error] [pid 255769:tid 255925] [client 20.206.105.145:54589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/for.php"] [unique_id "al9K17xMYwyVGnfuwsJ_IgAAA70"]
[Tue Jul 21 07:32:55.281022 2026] [security2:error] [pid 255769:tid 255939] [client 74.248.121.109:1074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/a7.php"] [unique_id "al9K17xMYwyVGnfuwsJ_JAAAA8s"]
[Tue Jul 21 07:32:55.381833 2026] [security2:error] [pid 255769:tid 256002] [client 122.186.204.214:60159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9K17xMYwyVGnfuwsJ_KQAABAg"]
[Tue Jul 21 07:32:55.381966 2026] [security2:error] [pid 255769:tid 256002] [client 122.186.204.214:60159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9K17xMYwyVGnfuwsJ_KQAABAg"]
[Tue Jul 21 07:32:55.446155 2026] [security2:error] [pid 255769:tid 256022] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/core/.env"] [unique_id "al9K17xMYwyVGnfuwsJ_KgAABBw"]
[Tue Jul 21 07:32:55.587685 2026] [security2:error] [pid 255769:tid 256007] [client 20.197.195.24:13082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/about.php"] [unique_id "al9K17xMYwyVGnfuwsJ_LAAABA0"]
[Tue Jul 21 07:32:55.604376 2026] [security2:error] [pid 255769:tid 255953] [client 20.220.225.223:9256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/else1.php"] [unique_id "al9K17xMYwyVGnfuwsJ_LgAAA9k"]
[Tue Jul 21 07:32:55.707611 2026] [security2:error] [pid 255769:tid 255825] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K17xMYwyVGnfuwsJ_LwAEFDc"]
[Tue Jul 21 07:32:55.707749 2026] [security2:error] [pid 255769:tid 256014] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K17xMYwyVGnfuwsJ_LwAEFDc"]
[Tue Jul 21 07:32:55.741411 2026] [security2:error] [pid 254995:tid 255174] [client 172.245.102.42:58803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9K1_7v0rlcEGmVraEmFwAAA08"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:55.758921 2026] [security2:error] [pid 255769:tid 256011] [client 74.248.121.109:2112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/classsmtps.php"] [unique_id "al9K17xMYwyVGnfuwsJ_MgAABBE"]
[Tue Jul 21 07:32:55.764252 2026] [proxy:error] [pid 255769:tid 255948] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:55.764306 2026] [proxy_http:error] [pid 255769:tid 255948] [client 20.151.10.161:57383] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:55.765101 2026] [proxy:error] [pid 255769:tid 255948] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:55.765144 2026] [proxy_http:error] [pid 255769:tid 255948] [client 20.151.10.161:57383] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:55.788543 2026] [security2:error] [pid 255769:tid 255946] [client 45.8.17.148:57047] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/missing/missing/theme-single.php"] [unique_id "al9K17xMYwyVGnfuwsJ_NwAAA9I"]
[Tue Jul 21 07:32:56.170484 2026] [security2:error] [pid 255769:tid 255994] [client 20.10.88.201:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "produto-express.com"] [uri "/index.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_PQAEAUA"]
[Tue Jul 21 07:32:56.174429 2026] [security2:error] [pid 255769:tid 255977] [client 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/phpinfo.php3"] [unique_id "al9K2LxMYwyVGnfuwsJ_PgAAA_E"]
[Tue Jul 21 07:32:56.253771 2026] [security2:error] [pid 255769:tid 255960] [client 74.248.121.109:1030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/rip.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_PwAAA-A"]
[Tue Jul 21 07:32:56.501123 2026] [security2:error] [pid 255769:tid 255835] [remote 45.79.123.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/wp/wp-login.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_RQAD9EE"]
[Tue Jul 21 07:32:56.551300 2026] [security2:error] [pid 255769:tid 255972] [client 20.220.225.223:19670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/wp-editor.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_RgAAA-w"]
[Tue Jul 21 07:32:56.589287 2026] [security2:error] [pid 255769:tid 256027] [client 173.24.185.52:59182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_RwAABCE"]
[Tue Jul 21 07:32:56.593970 2026] [security2:error] [pid 255769:tid 256027] [client 173.24.185.52:59182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_RwAABCE"]
[Tue Jul 21 07:32:56.630239 2026] [security2:error] [pid 255769:tid 255978] [client 20.206.105.145:39260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/biufile.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_SgAAA_I"]
[Tue Jul 21 07:32:56.716642 2026] [security2:error] [pid 255769:tid 255952] [client 74.248.121.109:1056] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "issimastore.com.issima.net.br"] [uri "/1.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_SwAAA9g"]
[Tue Jul 21 07:32:56.716799 2026] [security2:error] [pid 255769:tid 255952] [client 74.248.121.109:1056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/1.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_SwAAA9g"]
[Tue Jul 21 07:32:56.787587 2026] [security2:error] [pid 255769:tid 255979] [client 45.8.17.126:38965] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/admin-header-string.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_TAAAA_M"]
[Tue Jul 21 07:32:56.828632 2026] [security2:error] [pid 255769:tid 255907] [client 20.220.225.223:24264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/wander.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_TQAAA6s"]
[Tue Jul 21 07:32:56.830260 2026] [security2:error] [pid 254995:tid 255270] [client 20.206.105.145:54563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/yup.php"] [unique_id "al9K2P7v0rlcEGmVraEmJgAAA5Q"]
[Tue Jul 21 07:32:56.973158 2026] [security2:error] [pid 255769:tid 256000] [client 103.106.20.201:52729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_TwAABAY"]
[Tue Jul 21 07:32:56.973288 2026] [security2:error] [pid 255769:tid 256000] [client 103.106.20.201:52729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_TwAABAY"]
[Tue Jul 21 07:32:57.260968 2026] [security2:error] [pid 254995:tid 255223] [client 74.248.121.109:2147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/chosen.php"] [unique_id "al9K2f7v0rlcEGmVraEmLQAAA38"]
[Tue Jul 21 07:32:57.265993 2026] [security2:error] [pid 255769:tid 255837] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K2bxMYwyVGnfuwsJ_VAAEDUM"]
[Tue Jul 21 07:32:57.266161 2026] [security2:error] [pid 255769:tid 256007] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K2bxMYwyVGnfuwsJ_VAAEDUM"]
[Tue Jul 21 07:32:57.463337 2026] [security2:error] [pid 255769:tid 256006] [client 154.192.233.199:60206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K2bxMYwyVGnfuwsJ_WAAABAw"]
[Tue Jul 21 07:32:57.463444 2026] [security2:error] [pid 255769:tid 256006] [client 154.192.233.199:60206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K2bxMYwyVGnfuwsJ_WAAABAw"]
[Tue Jul 21 07:32:57.537997 2026] [security2:error] [pid 255769:tid 255903] [client 20.220.225.223:6100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/nhvoanpl.php"] [unique_id "al9K2bxMYwyVGnfuwsJ_WQAAA6c"]
[Tue Jul 21 07:32:57.559523 2026] [security2:error] [pid 255769:tid 255976] [client 20.197.195.24:13104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/admin.php"] [unique_id "al9K2bxMYwyVGnfuwsJ_WgAAA_A"]
[Tue Jul 21 07:32:57.731253 2026] [security2:error] [pid 255769:tid 255933] [client 74.248.121.109:1054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/css.php"] [unique_id "al9K2bxMYwyVGnfuwsJ_XwAAA8U"]
[Tue Jul 21 07:32:57.788322 2026] [security2:error] [pid 254995:tid 255172] [client 45.8.17.113:63713] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/fonts-long.php"] [unique_id "al9K2f7v0rlcEGmVraEmNgAAA00"]
[Tue Jul 21 07:32:57.795443 2026] [security2:error] [pid 255769:tid 255987] [client 20.220.225.223:19316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/cro.php"] [unique_id "al9K2bxMYwyVGnfuwsJ_ZAAAA_s"]
[Tue Jul 21 07:32:57.944744 2026] [security2:error] [pid 255769:tid 255919] [client 45.251.232.145:51291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K2bxMYwyVGnfuwsJ_agAAA7c"]
[Tue Jul 21 07:32:57.944871 2026] [security2:error] [pid 255769:tid 255919] [client 45.251.232.145:51291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K2bxMYwyVGnfuwsJ_agAAA7c"]
[Tue Jul 21 07:32:58.001641 2026] [security2:error] [pid 255769:tid 255980] [client 20.206.105.145:7571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wpxml.php"] [unique_id "al9K2rxMYwyVGnfuwsJ_awAAA_Q"]
[Tue Jul 21 07:32:58.192553 2026] [security2:error] [pid 254995:tid 255220] [client 74.248.121.109:1063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/php.php"] [unique_id "al9K2v7v0rlcEGmVraEmOgAAA3w"]
[Tue Jul 21 07:32:58.270628 2026] [security2:error] [pid 255769:tid 256000] [client 20.220.225.223:44229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/bootstrap.php"] [unique_id "al9K2rxMYwyVGnfuwsJ_fgAABAY"]
[Tue Jul 21 07:32:58.332322 2026] [security2:error] [pid 254995:tid 255121] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K2v7v0rlcEGmVraEmPgADKX0"]
[Tue Jul 21 07:32:58.332461 2026] [security2:error] [pid 254995:tid 255136] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K2v7v0rlcEGmVraEmPgADKX0"]
[Tue Jul 21 07:32:58.491501 2026] [security2:error] [pid 255769:tid 255982] [client 175.45.70.82:54089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K2rxMYwyVGnfuwsJ_hwAAA_Y"]
[Tue Jul 21 07:32:58.491595 2026] [security2:error] [pid 255769:tid 255982] [client 175.45.70.82:54089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K2rxMYwyVGnfuwsJ_hwAAA_Y"]
[Tue Jul 21 07:32:58.554266 2026] [security2:error] [pid 254995:tid 255134] [client 20.206.105.145:38947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wpconf.php"] [unique_id "al9K2v7v0rlcEGmVraEmQwAAAyc"]
[Tue Jul 21 07:32:58.704319 2026] [security2:error] [pid 255769:tid 255906] [client 109.248.148.246:36748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9K2rxMYwyVGnfuwsJ_kwAAA6o"]
[Tue Jul 21 07:32:58.704408 2026] [security2:error] [pid 255769:tid 255906] [client 109.248.148.246:36748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9K2rxMYwyVGnfuwsJ_kwAAA6o"]
[Tue Jul 21 07:32:58.706260 2026] [security2:error] [pid 255769:tid 255961] [client 185.198.240.213:45347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9K2rxMYwyVGnfuwsJ_kgAAA-E"]
[Tue Jul 21 07:32:58.706682 2026] [security2:error] [pid 254995:tid 255173] [client 185.198.240.194:24577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9K2v7v0rlcEGmVraEmRwAAA04"]
[Tue Jul 21 07:32:58.711736 2026] [security2:error] [pid 254995:tid 255215] [client 20.220.225.223:23482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/inso.php"] [unique_id "al9K2v7v0rlcEGmVraEmSAAAA3c"]
[Tue Jul 21 07:32:58.755299 2026] [security2:error] [pid 254995:tid 255195] [client 74.248.121.109:2133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/aa.php"] [unique_id "al9K2v7v0rlcEGmVraEmSgAAA2Q"]
[Tue Jul 21 07:32:58.986479 2026] [security2:error] [pid 254995:tid 255141] [client 45.8.17.131:50529] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/wp-config/index.php"] [unique_id "al9K2v7v0rlcEGmVraEmTgAAAy4"]
[Tue Jul 21 07:32:59.249279 2026] [security2:error] [pid 255769:tid 255965] [client 74.248.121.109:2116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/bolt.php"] [unique_id "al9K27xMYwyVGnfuwsJ_owAAA-U"]
[Tue Jul 21 07:32:59.321774 2026] [security2:error] [pid 255769:tid 256011] [client 103.174.34.15:62456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K27xMYwyVGnfuwsJ_pgAABBE"]
[Tue Jul 21 07:32:59.321909 2026] [security2:error] [pid 255769:tid 256011] [client 103.174.34.15:62456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K27xMYwyVGnfuwsJ_pgAABBE"]
[Tue Jul 21 07:32:59.381253 2026] [security2:error] [pid 255769:tid 256026] [client 117.217.38.194:56240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K27xMYwyVGnfuwsJ_qAAABCA"]
[Tue Jul 21 07:32:59.381397 2026] [security2:error] [pid 255769:tid 256026] [client 117.217.38.194:56240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K27xMYwyVGnfuwsJ_qAAABCA"]
[Tue Jul 21 07:32:59.501892 2026] [security2:error] [pid 255769:tid 255944] [client 20.197.195.24:13176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/admin.php"] [unique_id "al9K27xMYwyVGnfuwsJ_qQAAA9A"]
[Tue Jul 21 07:32:59.512507 2026] [security2:error] [pid 255769:tid 255926] [client 172.245.102.30:57379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9K27xMYwyVGnfuwsJ_pwAAA74"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:32:59.521124 2026] [security2:error] [pid 255769:tid 255878] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K27xMYwyVGnfuwsJ_rAAD7mw"]
[Tue Jul 21 07:32:59.521334 2026] [security2:error] [pid 255769:tid 255974] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K27xMYwyVGnfuwsJ_rAAD7mw"]
[Tue Jul 21 07:32:59.594555 2026] [security2:error] [pid 255769:tid 255972] [client 20.220.225.223:61954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/wp-editor.php"] [unique_id "al9K27xMYwyVGnfuwsJ_rwAAA-w"]
[Tue Jul 21 07:32:59.635600 2026] [security2:error] [pid 255769:tid 255978] [client 20.220.225.223:46107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/wp-explorer.php"] [unique_id "al9K27xMYwyVGnfuwsJ_sAAAA_I"]
[Tue Jul 21 07:32:59.727423 2026] [security2:error] [pid 255769:tid 255988] [client 74.248.121.109:1050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/x.php"] [unique_id "al9K27xMYwyVGnfuwsJ_tAAAA_w"]
[Tue Jul 21 07:32:59.883222 2026] [security2:error] [pid 255769:tid 255884] [remote 103.112.62.59:42670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.62.112.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "psooffshore.com.br"] [uri "/wp-login.php"] [unique_id "al9K27xMYwyVGnfuwsJ_twAEFXI"]
[Tue Jul 21 07:32:59.884240 2026] [security2:error] [pid 254995:tid 255153] [client 45.8.17.119:46709] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/cyber-security-blocks/parts/parts/user-edit.php"] [unique_id "al9K2_7v0rlcEGmVraEmWgAAAzo"]
[Tue Jul 21 07:33:00.191757 2026] [security2:error] [pid 255769:tid 256007] [client 74.248.121.109:2049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/jga.php"] [unique_id "al9K3LxMYwyVGnfuwsJ_vAAABA0"]
[Tue Jul 21 07:33:00.508318 2026] [security2:error] [pid 254995:tid 255084] [remote 34.141.229.34:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "marmorariasolare.com.br"] [uri "/data:,"] [unique_id "al9K3P7v0rlcEGmVraEmYwADIlg"]
[Tue Jul 21 07:33:00.508550 2026] [security2:error] [pid 254995:tid 255129] [client 34.141.229.34:0] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "marmorariasolare.com.br"] [uri "/data:,"] [unique_id "al9K3P7v0rlcEGmVraEmYwADIlg"]
[Tue Jul 21 07:33:00.658380 2026] [security2:error] [pid 255769:tid 255976] [client 20.206.105.145:7437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/fffm.php"] [unique_id "al9K3LxMYwyVGnfuwsJ_wgAAA_A"]
[Tue Jul 21 07:33:00.689234 2026] [security2:error] [pid 254995:tid 255165] [client 136.144.33.215:56033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9K2_7v0rlcEGmVraEmVAAAA0Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:00.931679 2026] [security2:error] [pid 254995:tid 255185] [client 62.102.148.164:53418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9K3P7v0rlcEGmVraEmcwAAA1o"]
[Tue Jul 21 07:33:00.931766 2026] [security2:error] [pid 254995:tid 255185] [client 62.102.148.164:53418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9K3P7v0rlcEGmVraEmcwAAA1o"]
[Tue Jul 21 07:33:00.946124 2026] [security2:error] [pid 254995:tid 255183] [client 74.248.121.109:2159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/k.php"] [unique_id "al9K3P7v0rlcEGmVraEmdAAAA1g"]
[Tue Jul 21 07:33:01.049494 2026] [security2:error] [pid 255769:tid 255887] [remote 154.61.75.100:54126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-login.php"] [unique_id "al9K3bxMYwyVGnfuwsJ_ygADvHU"]
[Tue Jul 21 07:33:01.081446 2026] [security2:error] [pid 254995:tid 255179] [client 45.8.17.62:30319] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/shadow-bot.php"] [unique_id "al9K3f7v0rlcEGmVraEmdgAAA1Q"]
[Tue Jul 21 07:33:01.316460 2026] [security2:error] [pid 254995:tid 255008] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9K3f7v0rlcEGmVraEmfgADXQw"]
[Tue Jul 21 07:33:01.316653 2026] [security2:error] [pid 254995:tid 255188] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9K3f7v0rlcEGmVraEmfgADXQw"]
[Tue Jul 21 07:33:01.398890 2026] [security2:error] [pid 255769:tid 255980] [client 213.152.162.104:50228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9K3bxMYwyVGnfuwsJ_0QAAA_Q"]
[Tue Jul 21 07:33:01.399013 2026] [security2:error] [pid 255769:tid 255980] [client 213.152.162.104:50228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9K3bxMYwyVGnfuwsJ_0QAAA_Q"]
[Tue Jul 21 07:33:01.542901 2026] [security2:error] [pid 254995:tid 255028] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K3f7v0rlcEGmVraEmfwADiCA"]
[Tue Jul 21 07:33:01.543040 2026] [security2:error] [pid 254995:tid 255258] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K3f7v0rlcEGmVraEmfwADiCA"]
[Tue Jul 21 07:33:01.591221 2026] [security2:error] [pid 254995:tid 255229] [client 74.248.121.109:2060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/vx.php"] [unique_id "al9K3f7v0rlcEGmVraEmgAAAA4I"]
[Tue Jul 21 07:33:01.775801 2026] [security2:error] [pid 255769:tid 256024] [client 20.206.105.145:39274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/mosty.php"] [unique_id "al9K3bxMYwyVGnfuwsJ_1AAABB4"]
[Tue Jul 21 07:33:01.811129 2026] [security2:error] [pid 255769:tid 255886] [remote 65.111.10.224:26611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.10.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9K3LxMYwyVGnfuwsJ_wAADxnQ"]
[Tue Jul 21 07:33:02.187644 2026] [security2:error] [pid 255769:tid 255919] [client 45.8.17.107:50777] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/html/html/dark-mode.php"] [unique_id "al9K3rxMYwyVGnfuwsJ_5QAAA7c"]
[Tue Jul 21 07:33:02.325068 2026] [security2:error] [pid 255769:tid 255946] [client 20.197.195.24:13139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/themes.php"] [unique_id "al9K3rxMYwyVGnfuwsJ_5wAAA9I"]
[Tue Jul 21 07:33:02.367076 2026] [security2:error] [pid 254995:tid 255146] [client 74.248.121.109:1070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/ws77.php"] [unique_id "al9K3v7v0rlcEGmVraEmjgAAAzM"]
[Tue Jul 21 07:33:02.745201 2026] [security2:error] [pid 254995:tid 255206] [client 20.220.225.223:46095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/akismet.php"] [unique_id "al9K3v7v0rlcEGmVraEmlAAAA28"]
[Tue Jul 21 07:33:02.860506 2026] [security2:error] [pid 255769:tid 255935] [client 74.248.121.109:2120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/2.php"] [unique_id "al9K3rxMYwyVGnfuwsJ_7AAAA8c"]
[Tue Jul 21 07:33:02.931493 2026] [security2:error] [pid 254995:tid 255158] [client 20.52.136.55:1759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/gg.php"] [unique_id "al9K3v7v0rlcEGmVraEmmAAAAz8"]
[Tue Jul 21 07:33:03.085510 2026] [security2:error] [pid 255769:tid 255981] [client 20.206.105.145:39294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/dejavu.php"] [unique_id "al9K37xMYwyVGnfuwsJ_8AAAA_U"]
[Tue Jul 21 07:33:03.224306 2026] [security2:error] [pid 255769:tid 256019] [client 20.220.225.223:6792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/tkikikoko.php"] [unique_id "al9K37xMYwyVGnfuwsJ_9QAABBk"]
[Tue Jul 21 07:33:03.290567 2026] [security2:error] [pid 255769:tid 255949] [client 45.8.17.137:53445] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/includes/menu-beta.php"] [unique_id "al9K37xMYwyVGnfuwsJ_9wAAA9U"]
[Tue Jul 21 07:33:03.294514 2026] [security2:error] [pid 254995:tid 255027] [remote 209.42.21.221:56636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.21.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9K3_7v0rlcEGmVraEmnwADXx8"]
[Tue Jul 21 07:33:03.368616 2026] [security2:error] [pid 255769:tid 255980] [client 20.220.225.223:63856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/cro.php"] [unique_id "al9K37xMYwyVGnfuwsJ_-QAAA_Q"]
[Tue Jul 21 07:33:03.370349 2026] [security2:error] [pid 254995:tid 255164] [client 74.248.121.109:2173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/asd.php"] [unique_id "al9K3_7v0rlcEGmVraEmoQAAA0U"]
[Tue Jul 21 07:33:03.506277 2026] [autoindex:error] [pid 254995:tid 255186] [client 20.197.195.24:13133] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:03.622468 2026] [security2:error] [pid 254995:tid 255256] [client 193.36.225.123:40361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9K3v7v0rlcEGmVraEmjwAAA4Y"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:33:03.870867 2026] [security2:error] [pid 254995:tid 255091] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9K3_7v0rlcEGmVraEmsQADQF8"]
[Tue Jul 21 07:33:03.871032 2026] [security2:error] [pid 254995:tid 255159] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9K3_7v0rlcEGmVraEmsQADQF8"]
[Tue Jul 21 07:33:03.914280 2026] [security2:error] [pid 255769:tid 255905] [client 74.248.121.109:2130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/default.php"] [unique_id "al9K37xMYwyVGnfuwsJ_-gAAA6k"]
[Tue Jul 21 07:33:04.022329 2026] [security2:error] [pid 255769:tid 255780] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K4LxMYwyVGnfuwsJ__QADvQo"]
[Tue Jul 21 07:33:04.022555 2026] [security2:error] [pid 255769:tid 255925] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K4LxMYwyVGnfuwsJ__QADvQo"]
[Tue Jul 21 07:33:04.079772 2026] [security2:error] [pid 255769:tid 255782] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K4LxMYwyVGnfuwsJ__wADqww"]
[Tue Jul 21 07:33:04.079956 2026] [security2:error] [pid 255769:tid 255907] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K4LxMYwyVGnfuwsJ__wADqww"]
[Tue Jul 21 07:33:04.089682 2026] [security2:error] [pid 255769:tid 255957] [client 59.96.220.140:63246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9K4LxMYwyVGnfuwsKAAAAAA90"]
[Tue Jul 21 07:33:04.089831 2026] [security2:error] [pid 255769:tid 255957] [client 59.96.220.140:63246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9K4LxMYwyVGnfuwsKAAAAAA90"]
[Tue Jul 21 07:33:04.156308 2026] [security2:error] [pid 254995:tid 255012] [remote 104.207.36.190:45493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.36.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9K4P7v0rlcEGmVraEmtAADYxA"]
[Tue Jul 21 07:33:04.286709 2026] [security2:error] [pid 255769:tid 255982] [client 45.8.17.124:36847] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/block-bindings/lib/index.php"] [unique_id "al9K4LxMYwyVGnfuwsKABAAAA_Y"]
[Tue Jul 21 07:33:04.339849 2026] [security2:error] [pid 254995:tid 255166] [client 74.248.121.109:2156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/gettest.php"] [unique_id "al9K4P7v0rlcEGmVraEmuQAAA0c"]
[Tue Jul 21 07:33:04.362228 2026] [security2:error] [pid 254995:tid 255263] [client 20.206.105.145:38926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/aaf.php"] [unique_id "al9K4P7v0rlcEGmVraEmugAAA40"]
[Tue Jul 21 07:33:04.423611 2026] [security2:error] [pid 254995:tid 255140] [client 139.167.225.182:63716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K4P7v0rlcEGmVraEmvAAAAy0"]
[Tue Jul 21 07:33:04.423752 2026] [security2:error] [pid 254995:tid 255140] [client 139.167.225.182:63716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K4P7v0rlcEGmVraEmvAAAAy0"]
[Tue Jul 21 07:33:04.449311 2026] [security2:error] [pid 255769:tid 256023] [client 20.220.225.223:8945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/else1.php"] [unique_id "al9K4LxMYwyVGnfuwsKABQAABB0"]
[Tue Jul 21 07:33:04.784307 2026] [security2:error] [pid 254995:tid 255169] [client 20.197.195.24:13133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/.well-known/about.php"] [unique_id "al9K4P7v0rlcEGmVraEmwgAAA0o"]
[Tue Jul 21 07:33:04.952439 2026] [security2:error] [pid 255769:tid 255922] [client 117.251.86.144:39764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9K4LxMYwyVGnfuwsKADAAAA7o"]
[Tue Jul 21 07:33:04.952551 2026] [security2:error] [pid 255769:tid 255922] [client 117.251.86.144:39764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9K4LxMYwyVGnfuwsKADAAAA7o"]
[Tue Jul 21 07:33:05.039504 2026] [security2:error] [pid 255769:tid 255917] [client 74.248.121.109:1076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/tfm.php"] [unique_id "al9K4bxMYwyVGnfuwsKAEAAAA7U"]
[Tue Jul 21 07:33:05.073972 2026] [security2:error] [pid 255769:tid 255955] [client 209.141.34.121:62554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "oliviapintoadv.com.br"] [uri "/"] [unique_id "al9K4bxMYwyVGnfuwsKAEwAAA9s"]
[Tue Jul 21 07:33:05.289949 2026] [security2:error] [pid 255769:tid 255994] [client 45.8.17.140:35769] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/network/theme-install-table.php"] [unique_id "al9K4bxMYwyVGnfuwsKAGQAABAE"]
[Tue Jul 21 07:33:05.403034 2026] [security2:error] [pid 255769:tid 255952] [client 172.245.102.42:43205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9K4bxMYwyVGnfuwsKAHAAAA9g"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:05.517239 2026] [security2:error] [pid 255769:tid 255968] [client 74.248.121.109:2122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/ws81.php"] [unique_id "al9K4bxMYwyVGnfuwsKAHwAAA-g"]
[Tue Jul 21 07:33:05.589139 2026] [security2:error] [pid 255769:tid 255947] [client 209.141.34.121:62597] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "oliviapintoadv.com.br"] [uri "/"] [unique_id "al9K4bxMYwyVGnfuwsKAIAAAA9M"]
[Tue Jul 21 07:33:05.638632 2026] [core:alert] [pid 255769:tid 255904] [client 57.141.18.21:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:33:05.726673 2026] [security2:error] [pid 255769:tid 255976] [client 74.7.241.174:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bellascleaningsolutionsllc.com"] [uri "/index.php"] [unique_id "al9K4bxMYwyVGnfuwsKAEQAAA_A"]
[Tue Jul 21 07:33:05.727675 2026] [security2:error] [pid 254995:tid 255151] [client 74.7.241.174:51948] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bellascleaningsolutionsllc.com"] [uri "/robots.txt"] [unique_id "al9K4f7v0rlcEGmVraEmxwADOD8"]
[Tue Jul 21 07:33:05.795571 2026] [security2:error] [pid 255769:tid 255970] [client 103.162.129.114:60480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9K4bxMYwyVGnfuwsKAJwAAA-o"]
[Tue Jul 21 07:33:05.795726 2026] [security2:error] [pid 255769:tid 255970] [client 103.162.129.114:60480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9K4bxMYwyVGnfuwsKAJwAAA-o"]
[Tue Jul 21 07:33:05.851294 2026] [security2:error] [pid 254995:tid 255172] [client 20.206.105.145:7486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/gecko.php"] [unique_id "al9K4f7v0rlcEGmVraEm2AAAA00"]
[Tue Jul 21 07:33:05.962348 2026] [security2:error] [pid 254995:tid 255268] [client 74.248.121.109:1068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/222.php"] [unique_id "al9K4f7v0rlcEGmVraEm2wAAA5I"]
[Tue Jul 21 07:33:06.054095 2026] [security2:error] [pid 254995:tid 255077] [remote 162.19.246.208:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9K4v7v0rlcEGmVraEm4AADa1E"]
[Tue Jul 21 07:33:06.064029 2026] [security2:error] [pid 255769:tid 255966] [client 122.186.204.214:60662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9K4rxMYwyVGnfuwsKAMAAAA-Y"]
[Tue Jul 21 07:33:06.064168 2026] [security2:error] [pid 255769:tid 255966] [client 122.186.204.214:60662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9K4rxMYwyVGnfuwsKAMAAAA-Y"]
[Tue Jul 21 07:33:06.121122 2026] [security2:error] [pid 254995:tid 255136] [client 20.197.195.24:13152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9K4v7v0rlcEGmVraEm4QAAAyk"]
[Tue Jul 21 07:33:06.175324 2026] [security2:error] [pid 255769:tid 255783] [remote 163.61.236.12:36566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.236.61.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9K4bxMYwyVGnfuwsKAFgAEDg0"]
[Tue Jul 21 07:33:06.287909 2026] [security2:error] [pid 255769:tid 256014] [client 45.8.17.146:47565] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/chosen.php"] [unique_id "al9K4rxMYwyVGnfuwsKAMwAABBQ"]
[Tue Jul 21 07:33:06.601217 2026] [security2:error] [pid 255769:tid 255906] [client 74.248.121.109:2135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/t.php"] [unique_id "al9K4rxMYwyVGnfuwsKANQAAA6o"]
[Tue Jul 21 07:33:06.801851 2026] [security2:error] [pid 254995:tid 255277] [client 122.162.144.145:30753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9K4v7v0rlcEGmVraEm6gAAA5s"]
[Tue Jul 21 07:33:06.802054 2026] [security2:error] [pid 254995:tid 255277] [client 122.162.144.145:30753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9K4v7v0rlcEGmVraEm6gAAA5s"]
[Tue Jul 21 07:33:06.826962 2026] [security2:error] [pid 254995:tid 255117] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K4v7v0rlcEGmVraEm6wADXXk"]
[Tue Jul 21 07:33:06.827124 2026] [security2:error] [pid 254995:tid 255188] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K4v7v0rlcEGmVraEm6wADXXk"]
[Tue Jul 21 07:33:06.870276 2026] [security2:error] [pid 255769:tid 255973] [client 62.102.148.164:59068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9K4rxMYwyVGnfuwsKAPQAAA-0"]
[Tue Jul 21 07:33:06.870359 2026] [security2:error] [pid 255769:tid 255973] [client 62.102.148.164:59068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9K4rxMYwyVGnfuwsKAPQAAA-0"]
[Tue Jul 21 07:33:07.059872 2026] [security2:error] [pid 254995:tid 255229] [client 74.248.121.109:1044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/a.php"] [unique_id "al9K4_7v0rlcEGmVraEm8AAAA4I"]
[Tue Jul 21 07:33:07.194010 2026] [security2:error] [pid 255769:tid 255993] [client 173.24.185.52:59656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9K47xMYwyVGnfuwsKARQAABAA"]
[Tue Jul 21 07:33:07.194193 2026] [security2:error] [pid 255769:tid 255993] [client 173.24.185.52:59656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9K47xMYwyVGnfuwsKARQAABAA"]
[Tue Jul 21 07:33:07.207098 2026] [security2:error] [pid 255769:tid 255935] [client 78.47.98.55:19106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9K47xMYwyVGnfuwsKARgAAA8c"], referer: https://artetoner.com.br
[Tue Jul 21 07:33:07.483253 2026] [security2:error] [pid 255769:tid 255918] [client 45.8.17.119:22879] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/SimplePie/src/Content/autoload_classmap.php"] [unique_id "al9K47xMYwyVGnfuwsKATAAAA7Y"]
[Tue Jul 21 07:33:07.599673 2026] [security2:error] [pid 254995:tid 255224] [client 74.248.121.109:1080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/a1.php"] [unique_id "al9K4_7v0rlcEGmVraEm9AAAA4A"]
[Tue Jul 21 07:33:07.664015 2026] [security2:error] [pid 255769:tid 255912] [client 103.106.20.201:53288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K47xMYwyVGnfuwsKATwAAA7A"]
[Tue Jul 21 07:33:07.664847 2026] [security2:error] [pid 255769:tid 255912] [client 103.106.20.201:53288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K47xMYwyVGnfuwsKATwAAA7A"]
[Tue Jul 21 07:33:07.858982 2026] [security2:error] [pid 255769:tid 256021] [client 20.220.225.223:4195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/cron-tab.php"] [unique_id "al9K47xMYwyVGnfuwsKAVAAABBs"]
[Tue Jul 21 07:33:07.947655 2026] [security2:error] [pid 254995:tid 255073] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K4_7v0rlcEGmVraEm-wADik0"]
[Tue Jul 21 07:33:07.947789 2026] [security2:error] [pid 254995:tid 255260] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K4_7v0rlcEGmVraEm-wADik0"]
[Tue Jul 21 07:33:08.196380 2026] [security2:error] [pid 255769:tid 255976] [client 154.192.233.199:58671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5LxMYwyVGnfuwsKAYQAAA_A"]
[Tue Jul 21 07:33:08.196540 2026] [security2:error] [pid 255769:tid 255976] [client 154.192.233.199:58671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5LxMYwyVGnfuwsKAYQAAA_A"]
[Tue Jul 21 07:33:08.207092 2026] [security2:error] [pid 255769:tid 255931] [client 20.220.225.223:8089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/wp-Blogs.php"] [unique_id "al9K5LxMYwyVGnfuwsKAYgAAA8M"]
[Tue Jul 21 07:33:08.289779 2026] [security2:error] [pid 255769:tid 255958] [client 74.248.121.109:2003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/w.php"] [unique_id "al9K5LxMYwyVGnfuwsKAZQAAA94"]
[Tue Jul 21 07:33:08.485701 2026] [security2:error] [pid 255769:tid 255970] [client 45.251.232.145:51814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5LxMYwyVGnfuwsKAfgAAA-o"]
[Tue Jul 21 07:33:08.485901 2026] [security2:error] [pid 255769:tid 255970] [client 45.251.232.145:51814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5LxMYwyVGnfuwsKAfgAAA-o"]
[Tue Jul 21 07:33:08.691993 2026] [security2:error] [pid 255769:tid 256011] [client 45.8.17.110:58575] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/IXR/shadow-bot.php"] [unique_id "al9K5LxMYwyVGnfuwsKAgwAABBE"]
[Tue Jul 21 07:33:08.771243 2026] [security2:error] [pid 255769:tid 255947] [client 20.220.225.223:19668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/cron-tab.php"] [unique_id "al9K5LxMYwyVGnfuwsKAhQAAA9M"]
[Tue Jul 21 07:33:08.776238 2026] [security2:error] [pid 255769:tid 255981] [client 20.206.105.145:38939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/term.php"] [unique_id "al9K5LxMYwyVGnfuwsKAhgAAA_U"]
[Tue Jul 21 07:33:08.827610 2026] [security2:error] [pid 255769:tid 255996] [client 74.248.121.109:2141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/wp-good.php"] [unique_id "al9K5LxMYwyVGnfuwsKAhwAABAI"]
[Tue Jul 21 07:33:09.144378 2026] [security2:error] [pid 255769:tid 255837] [remote 41.76.214.143:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9K5bxMYwyVGnfuwsKAkwADvkM"]
[Tue Jul 21 07:33:09.172790 2026] [security2:error] [pid 255769:tid 255932] [client 20.220.225.223:49836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/old.php"] [unique_id "al9K5bxMYwyVGnfuwsKAlQAAA8Q"]
[Tue Jul 21 07:33:09.219967 2026] [security2:error] [pid 255769:tid 256028] [client 193.36.225.72:50881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9K5bxMYwyVGnfuwsKAkAAABCI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:09.228069 2026] [security2:error] [pid 254995:tid 255162] [client 175.45.70.82:54602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5f7v0rlcEGmVraEnDAAAA0M"]
[Tue Jul 21 07:33:09.228178 2026] [security2:error] [pid 254995:tid 255162] [client 175.45.70.82:54602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5f7v0rlcEGmVraEnDAAAA0M"]
[Tue Jul 21 07:33:09.376473 2026] [security2:error] [pid 255769:tid 255944] [client 74.248.121.109:2109] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "issimastore.com.issima.net.br"] [uri "/.info.php"] [unique_id "al9K5bxMYwyVGnfuwsKAmwAAA9A"]
[Tue Jul 21 07:33:09.403986 2026] [security2:error] [pid 255769:tid 255840] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K5bxMYwyVGnfuwsKAnQADqUY"]
[Tue Jul 21 07:33:09.404173 2026] [security2:error] [pid 255769:tid 255905] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K5bxMYwyVGnfuwsKAnQADqUY"]
[Tue Jul 21 07:33:09.658345 2026] [security2:error] [pid 255769:tid 255998] [client 152.59.154.239:63895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5bxMYwyVGnfuwsKAoAAABAQ"]
[Tue Jul 21 07:33:09.658534 2026] [security2:error] [pid 255769:tid 255998] [client 152.59.154.239:63895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5bxMYwyVGnfuwsKAoAAABAQ"]
[Tue Jul 21 07:33:09.689251 2026] [security2:error] [pid 254995:tid 255186] [client 45.8.17.127:54079] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/chosen.php"] [unique_id "al9K5f7v0rlcEGmVraEnEQAAA1s"]
[Tue Jul 21 07:33:09.841354 2026] [security2:error] [pid 255769:tid 255957] [client 117.217.38.194:56679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5bxMYwyVGnfuwsKApgAAA90"]
[Tue Jul 21 07:33:09.841525 2026] [security2:error] [pid 255769:tid 255957] [client 117.217.38.194:56679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5bxMYwyVGnfuwsKApgAAA90"]
[Tue Jul 21 07:33:09.883190 2026] [security2:error] [pid 254995:tid 255182] [client 74.248.121.109:1072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/item.php"] [unique_id "al9K5f7v0rlcEGmVraEnFAAAA1c"]
[Tue Jul 21 07:33:09.973032 2026] [security2:error] [pid 254995:tid 255181] [client 20.197.195.24:13178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wefile.php"] [unique_id "al9K5f7v0rlcEGmVraEnFQAAA1Y"]
[Tue Jul 21 07:33:10.010240 2026] [security2:error] [pid 255769:tid 256018] [client 103.174.34.15:62963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5rxMYwyVGnfuwsKAqgAABBg"]
[Tue Jul 21 07:33:10.010355 2026] [security2:error] [pid 255769:tid 256018] [client 103.174.34.15:62963] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5rxMYwyVGnfuwsKAqgAABBg"]
[Tue Jul 21 07:33:10.355590 2026] [security2:error] [pid 255769:tid 255959] [client 74.248.121.109:1027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/albin.php"] [unique_id "al9K5rxMYwyVGnfuwsKArQAAA98"]
[Tue Jul 21 07:33:10.408096 2026] [security2:error] [pid 254995:tid 255066] [remote 54.39.210.190:21530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.gpbikesbrasil.com.br"] [uri "/robots.txt"] [unique_id "al9K5v7v0rlcEGmVraEnIQADmEY"]
[Tue Jul 21 07:33:10.408239 2026] [security2:error] [pid 254995:tid 255274] [client 54.39.210.190:21530] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.gpbikesbrasil.com.br"] [uri "/robots.txt"] [unique_id "al9K5v7v0rlcEGmVraEnIQADmEY"]
[Tue Jul 21 07:33:10.581875 2026] [security2:error] [pid 254995:tid 255187] [client 20.197.195.24:13117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9K5v7v0rlcEGmVraEnJQAAA1w"]
[Tue Jul 21 07:33:10.583403 2026] [security2:error] [pid 255769:tid 255935] [client 20.206.105.145:54538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/a1.php"] [unique_id "al9K5rxMYwyVGnfuwsKAsAAAA8c"]
[Tue Jul 21 07:33:10.629465 2026] [autoindex:error] [pid 255769:tid 255981] [client 20.197.195.24:13056] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:10.687398 2026] [autoindex:error] [pid 255769:tid 255937] [client 20.197.195.24:13056] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:10.692372 2026] [security2:error] [pid 255769:tid 255910] [client 45.8.17.146:48091] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/prenota/gecko.php"] [unique_id "al9K5rxMYwyVGnfuwsKAtAAAA64"]
[Tue Jul 21 07:33:10.695966 2026] [security2:error] [pid 255769:tid 255918] [client 20.197.195.24:13056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9K5rxMYwyVGnfuwsKAtQAAA7Y"]
[Tue Jul 21 07:33:10.754849 2026] [security2:error] [pid 255769:tid 255903] [client 82.102.28.107:48214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9K5rxMYwyVGnfuwsKAtgAAA6c"]
[Tue Jul 21 07:33:10.755013 2026] [security2:error] [pid 255769:tid 255903] [client 82.102.28.107:48214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9K5rxMYwyVGnfuwsKAtgAAA6c"]
[Tue Jul 21 07:33:10.846356 2026] [security2:error] [pid 254995:tid 255224] [client 74.248.121.109:2065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/alfa.php"] [unique_id "al9K5v7v0rlcEGmVraEnKgAAA4A"]
[Tue Jul 21 07:33:11.004081 2026] [proxy:error] [pid 254995:tid 255197] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:11.004154 2026] [proxy_http:error] [pid 254995:tid 255197] [client 20.151.10.161:57991] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:11.005513 2026] [proxy:error] [pid 254995:tid 255197] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:11.005557 2026] [proxy_http:error] [pid 254995:tid 255197] [client 20.151.10.161:57991] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:11.026553 2026] [security2:error] [pid 255769:tid 255960] [client 20.197.195.24:48862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/8.php"] [unique_id "al9K57xMYwyVGnfuwsKAvAAAA-A"]
[Tue Jul 21 07:33:11.246152 2026] [security2:error] [pid 254995:tid 255198] [client 20.206.105.145:38948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ha.php"] [unique_id "al9K5_7v0rlcEGmVraEnNgAAA2c"]
[Tue Jul 21 07:33:11.270303 2026] [security2:error] [pid 255769:tid 255983] [client 122.129.67.13:59626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9K57xMYwyVGnfuwsKAwAAAA_c"]
[Tue Jul 21 07:33:11.313543 2026] [security2:error] [pid 255769:tid 255934] [client 20.220.225.223:8081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/wp-css.php"] [unique_id "al9K57xMYwyVGnfuwsKAxAAAA8Y"]
[Tue Jul 21 07:33:11.655425 2026] [security2:error] [pid 255769:tid 255941] [client 74.248.121.109:2146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/autoload_classmap.php"] [unique_id "al9K57xMYwyVGnfuwsKAzgAAA80"]
[Tue Jul 21 07:33:11.753975 2026] [security2:error] [pid 255769:tid 255857] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9K57xMYwyVGnfuwsKA1AAD3Fc"]
[Tue Jul 21 07:33:11.754136 2026] [security2:error] [pid 255769:tid 255956] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9K57xMYwyVGnfuwsKA1AAD3Fc"]
[Tue Jul 21 07:33:11.895336 2026] [security2:error] [pid 255769:tid 255907] [client 45.8.17.64:32247] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/css/as.php"] [unique_id "al9K57xMYwyVGnfuwsKA2wAAA6s"]
[Tue Jul 21 07:33:11.945773 2026] [security2:error] [pid 255769:tid 255863] [remote 167.114.139.57:16806] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.gpbikesbrasil.com.br"] [uri "/"] [unique_id "al9K57xMYwyVGnfuwsKA4AAD3l0"]
[Tue Jul 21 07:33:11.945923 2026] [security2:error] [pid 255769:tid 255958] [client 167.114.139.57:16806] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.gpbikesbrasil.com.br"] [uri "/"] [unique_id "al9K57xMYwyVGnfuwsKA4AAD3l0"]
[Tue Jul 21 07:33:12.156213 2026] [security2:error] [pid 255769:tid 255879] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K6LxMYwyVGnfuwsKA7gAEBW0"]
[Tue Jul 21 07:33:12.156375 2026] [security2:error] [pid 255769:tid 255999] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K6LxMYwyVGnfuwsKA7gAEBW0"]
[Tue Jul 21 07:33:12.274946 2026] [security2:error] [pid 255769:tid 255893] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K6LxMYwyVGnfuwsKA-QAEAHs"]
[Tue Jul 21 07:33:12.275079 2026] [security2:error] [pid 255769:tid 255993] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K6LxMYwyVGnfuwsKA-QAEAHs"]
[Tue Jul 21 07:33:12.277078 2026] [security2:error] [pid 254995:tid 255270] [client 20.220.225.223:45973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/ace2.php"] [unique_id "al9K6P7v0rlcEGmVraEncAAAA5Q"]
[Tue Jul 21 07:33:12.358933 2026] [security2:error] [pid 255769:tid 255983] [client 74.248.121.109:2126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/av.php"] [unique_id "al9K6LxMYwyVGnfuwsKBAAAAA_c"]
[Tue Jul 21 07:33:12.563220 2026] [security2:error] [pid 255769:tid 256003] [client 20.52.136.55:1563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/sql.php"] [unique_id "al9K6LxMYwyVGnfuwsKBDQAABAk"]
[Tue Jul 21 07:33:12.569377 2026] [security2:error] [pid 255769:tid 255931] [client 20.206.105.145:7478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/k2.php"] [unique_id "al9K6LxMYwyVGnfuwsKBDgAAA8M"]
[Tue Jul 21 07:33:12.670432 2026] [security2:error] [pid 254995:tid 255165] [client 20.151.10.161:58029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp.php"] [unique_id "al9K6P7v0rlcEGmVraEnewAAA0Y"]
[Tue Jul 21 07:33:12.757933 2026] [security2:error] [pid 255769:tid 256024] [client 20.220.225.223:6106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/wpx.php"] [unique_id "al9K6LxMYwyVGnfuwsKBFwAABB4"]
[Tue Jul 21 07:33:12.830145 2026] [security2:error] [pid 255769:tid 256022] [client 74.248.121.109:2094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/gg.php"] [unique_id "al9K6LxMYwyVGnfuwsKBHAAABBw"]
[Tue Jul 21 07:33:13.023583 2026] [security2:error] [pid 255769:tid 255923] [client 193.36.225.60:34373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9K6bxMYwyVGnfuwsKBIQAAA7s"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:13.120117 2026] [security2:error] [pid 254995:tid 255254] [client 20.197.195.24:13062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp-content/admin.php"] [unique_id "al9K6f7v0rlcEGmVraEnhQAAA4Q"]
[Tue Jul 21 07:33:13.401329 2026] [security2:error] [pid 254995:tid 255125] [client 74.248.121.109:2138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/sql.php"] [unique_id "al9K6f7v0rlcEGmVraEniAAAAx4"]
[Tue Jul 21 07:33:13.686562 2026] [security2:error] [pid 255769:tid 255988] [client 59.96.220.140:63726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9K6bxMYwyVGnfuwsKBKwAAA_w"]
[Tue Jul 21 07:33:13.687329 2026] [security2:error] [pid 255769:tid 255988] [client 59.96.220.140:63726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9K6bxMYwyVGnfuwsKBKwAAA_w"]
[Tue Jul 21 07:33:13.830421 2026] [security2:error] [pid 255769:tid 256021] [client 20.220.225.223:24275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/x.php"] [unique_id "al9K6bxMYwyVGnfuwsKBLgAABBs"]
[Tue Jul 21 07:33:13.851723 2026] [security2:error] [pid 255769:tid 255960] [client 45.8.17.116:44185] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/home-link/wp-login.php"] [unique_id "al9K6bxMYwyVGnfuwsKBKgAAA-A"]
[Tue Jul 21 07:33:13.942364 2026] [security2:error] [pid 254995:tid 255209] [client 136.144.33.213:24145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9K6P7v0rlcEGmVraEnfQAAA3E"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:33:14.032435 2026] [security2:error] [pid 255769:tid 256004] [client 20.220.225.223:45977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/ms.php"] [unique_id "al9K6rxMYwyVGnfuwsKBMgAABAo"]
[Tue Jul 21 07:33:14.087212 2026] [security2:error] [pid 254995:tid 255220] [client 74.248.121.109:2089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/up.php"] [unique_id "al9K6v7v0rlcEGmVraEnlwAAA3w"]
[Tue Jul 21 07:33:14.163445 2026] [security2:error] [pid 255769:tid 255921] [client 20.206.105.145:39289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/hur.php"] [unique_id "al9K6rxMYwyVGnfuwsKBNQAAA7k"]
[Tue Jul 21 07:33:14.250823 2026] [security2:error] [pid 255769:tid 255919] [client 20.206.105.145:7749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/82.php"] [unique_id "al9K6rxMYwyVGnfuwsKBPAAAA7c"]
[Tue Jul 21 07:33:14.397957 2026] [security2:error] [pid 254995:tid 255258] [client 20.151.10.161:57404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/abcd.php"] [unique_id "al9K6v7v0rlcEGmVraEnnAAAA4g"]
[Tue Jul 21 07:33:14.408420 2026] [security2:error] [pid 254995:tid 255111] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9K6v7v0rlcEGmVraEnnQADg3M"]
[Tue Jul 21 07:33:14.408535 2026] [security2:error] [pid 254995:tid 255252] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9K6v7v0rlcEGmVraEnnQADg3M"]
[Tue Jul 21 07:33:14.598930 2026] [security2:error] [pid 255769:tid 255808] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K6rxMYwyVGnfuwsKBQgAD4SY"]
[Tue Jul 21 07:33:14.599043 2026] [security2:error] [pid 255769:tid 255961] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K6rxMYwyVGnfuwsKBQgAD4SY"]
[Tue Jul 21 07:33:14.610730 2026] [security2:error] [pid 254995:tid 255157] [client 74.7.244.48:41668] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "politicaemdebate.org"] [uri "/robots.txt"] [unique_id "al9K6v7v0rlcEGmVraEnpwADPg4"]
[Tue Jul 21 07:33:14.647904 2026] [security2:error] [pid 254995:tid 255109] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K6v7v0rlcEGmVraEnnwADSnE"]
[Tue Jul 21 07:33:14.648136 2026] [security2:error] [pid 254995:tid 255169] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K6v7v0rlcEGmVraEnnwADSnE"]
[Tue Jul 21 07:33:14.690804 2026] [security2:error] [pid 255769:tid 255917] [client 74.248.121.109:1991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/66.php"] [unique_id "al9K6rxMYwyVGnfuwsKBRgAAA7U"]
[Tue Jul 21 07:33:14.953844 2026] [security2:error] [pid 255769:tid 255984] [client 139.167.225.182:64348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K6rxMYwyVGnfuwsKBSQAAA_g"]
[Tue Jul 21 07:33:14.954003 2026] [security2:error] [pid 255769:tid 255984] [client 139.167.225.182:64348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K6rxMYwyVGnfuwsKBSQAAA_g"]
[Tue Jul 21 07:33:15.118787 2026] [security2:error] [pid 255769:tid 255996] [client 20.220.225.223:6827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/wp-explorer.php"] [unique_id "al9K67xMYwyVGnfuwsKBTQAABAI"]
[Tue Jul 21 07:33:15.186461 2026] [security2:error] [pid 255769:tid 255937] [client 20.197.195.24:13079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/f6.php"] [unique_id "al9K67xMYwyVGnfuwsKBTwAAA8k"]
[Tue Jul 21 07:33:15.262804 2026] [security2:error] [pid 255769:tid 255924] [client 20.151.10.161:57467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/a1.php"] [unique_id "al9K67xMYwyVGnfuwsKBUgAAA7w"]
[Tue Jul 21 07:33:15.297826 2026] [security2:error] [pid 255769:tid 255810] [remote 154.61.75.100:35842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/wp-login.php"] [unique_id "al9K67xMYwyVGnfuwsKBUwADrig"]
[Tue Jul 21 07:33:15.395850 2026] [security2:error] [pid 255769:tid 255986] [client 45.8.17.58:64657] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/fix/admin.php"] [unique_id "al9K67xMYwyVGnfuwsKBVQAAA_o"]
[Tue Jul 21 07:33:15.462870 2026] [security2:error] [pid 255769:tid 255804] [remote 116.179.37.99:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9K6rxMYwyVGnfuwsKBPQADpCI"], referer: https://androapkmod.com/groovepad-premium/
[Tue Jul 21 07:33:15.634905 2026] [security2:error] [pid 254995:tid 255164] [client 117.251.86.144:50824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9K6_7v0rlcEGmVraEntQAAA0U"]
[Tue Jul 21 07:33:15.635063 2026] [security2:error] [pid 254995:tid 255164] [client 117.251.86.144:50824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9K6_7v0rlcEGmVraEntQAAA0U"]
[Tue Jul 21 07:33:15.722310 2026] [proxy:error] [pid 254995:tid 255268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:15.722346 2026] [proxy_http:error] [pid 254995:tid 255268] [client 198.235.24.152:60750] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:15.722869 2026] [proxy:error] [pid 254995:tid 255268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:15.722898 2026] [proxy_http:error] [pid 254995:tid 255268] [client 198.235.24.152:60750] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:15.732663 2026] [security2:error] [pid 255769:tid 256004] [client 20.151.10.161:57381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9K67xMYwyVGnfuwsKBXgAABAo"]
[Tue Jul 21 07:33:15.802388 2026] [security2:error] [pid 255769:tid 255930] [client 103.162.129.114:61055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9K67xMYwyVGnfuwsKBYAAAA8I"]
[Tue Jul 21 07:33:15.802527 2026] [security2:error] [pid 255769:tid 255930] [client 103.162.129.114:61055] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9K67xMYwyVGnfuwsKBYAAAA8I"]
[Tue Jul 21 07:33:16.096011 2026] [security2:error] [pid 255769:tid 255941] [client 74.248.121.109:2063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/666.php"] [unique_id "al9K7LxMYwyVGnfuwsKBZQAAA80"]
[Tue Jul 21 07:33:16.453736 2026] [security2:error] [pid 254995:tid 255194] [client 20.206.105.145:7445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/config.json.php"] [unique_id "al9K7P7v0rlcEGmVraEnwwAAA2M"]
[Tue Jul 21 07:33:16.485683 2026] [proxy:error] [pid 254995:tid 255174] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:16.485758 2026] [proxy_http:error] [pid 254995:tid 255174] [client 20.151.10.161:51288] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:16.486913 2026] [proxy:error] [pid 254995:tid 255174] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:16.486971 2026] [proxy_http:error] [pid 254995:tid 255174] [client 20.151.10.161:51288] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:16.513979 2026] [security2:error] [pid 254995:tid 255154] [client 20.220.225.223:8074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/akismet.php"] [unique_id "al9K7P7v0rlcEGmVraEnxgAAAzs"]
[Tue Jul 21 07:33:16.649985 2026] [security2:error] [pid 255769:tid 256007] [client 74.248.121.109:2127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/byp.php"] [unique_id "al9K7LxMYwyVGnfuwsKBbAAABA0"]
[Tue Jul 21 07:33:16.699704 2026] [security2:error] [pid 255769:tid 256022] [client 45.8.17.137:56889] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/fix/ioxi-o.php"] [unique_id "al9K7LxMYwyVGnfuwsKBbwAABBw"]
[Tue Jul 21 07:33:16.747970 2026] [security2:error] [pid 254995:tid 255269] [client 122.186.204.214:61166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9K7P7v0rlcEGmVraEnywAAA5M"]
[Tue Jul 21 07:33:16.748118 2026] [security2:error] [pid 254995:tid 255269] [client 122.186.204.214:61166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9K7P7v0rlcEGmVraEnywAAA5M"]
[Tue Jul 21 07:33:16.761659 2026] [security2:error] [pid 254995:tid 255195] [client 37.140.223.191:62655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9K7P7v0rlcEGmVraEnzAAAA2Q"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:33:16.883758 2026] [security2:error] [pid 255769:tid 255947] [client 20.206.105.145:7439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/fpwch.php"] [unique_id "al9K7LxMYwyVGnfuwsKBdgAAA9M"]
[Tue Jul 21 07:33:17.016289 2026] [security2:error] [pid 255769:tid 255955] [client 20.206.105.145:38972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/h02ugyh.php"] [unique_id "al9K7bxMYwyVGnfuwsKBeAAAA9s"]
[Tue Jul 21 07:33:17.085102 2026] [proxy:error] [pid 255769:tid 255910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:17.085166 2026] [proxy_http:error] [pid 255769:tid 255910] [client 20.151.10.161:57443] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:17.085617 2026] [proxy:error] [pid 255769:tid 255910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:17.085650 2026] [proxy_http:error] [pid 255769:tid 255910] [client 20.151.10.161:57443] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:17.175806 2026] [security2:error] [pid 254995:tid 255181] [client 193.36.225.70:26573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9K7f7v0rlcEGmVraEnzwAAA1Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:17.276285 2026] [security2:error] [pid 255769:tid 255957] [client 122.162.144.145:24914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9K7bxMYwyVGnfuwsKBhQAAA90"]
[Tue Jul 21 07:33:17.276378 2026] [security2:error] [pid 255769:tid 255957] [client 122.162.144.145:24914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9K7bxMYwyVGnfuwsKBhQAAA90"]
[Tue Jul 21 07:33:17.362097 2026] [security2:error] [pid 254995:tid 255211] [client 20.220.225.223:4546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/koiy.php"] [unique_id "al9K7f7v0rlcEGmVraEn1QAAA3M"]
[Tue Jul 21 07:33:17.386548 2026] [security2:error] [pid 254995:tid 255107] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K7f7v0rlcEGmVraEn1gADcW8"]
[Tue Jul 21 07:33:17.386682 2026] [security2:error] [pid 254995:tid 255209] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K7f7v0rlcEGmVraEn1gADcW8"]
[Tue Jul 21 07:33:17.398402 2026] [security2:error] [pid 255769:tid 255960] [client 74.248.121.109:2073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/date.php"] [unique_id "al9K7bxMYwyVGnfuwsKBhgAAA-A"]
[Tue Jul 21 07:33:17.563257 2026] [proxy:error] [pid 254995:tid 255135] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:17.563324 2026] [proxy_http:error] [pid 254995:tid 255135] [client 20.151.10.161:50881] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:17.563754 2026] [proxy:error] [pid 254995:tid 255135] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:17.563781 2026] [proxy_http:error] [pid 254995:tid 255135] [client 20.151.10.161:50881] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:17.617761 2026] [security2:error] [pid 254995:tid 255271] [client 20.220.225.223:62134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/tkikikoko.php"] [unique_id "al9K7f7v0rlcEGmVraEn3AAAA5U"]
[Tue Jul 21 07:33:17.654803 2026] [security2:error] [pid 254995:tid 255198] [client 20.197.195.24:13076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/inputs.php"] [unique_id "al9K7f7v0rlcEGmVraEn3QAAA2c"]
[Tue Jul 21 07:33:17.655603 2026] [security2:error] [pid 255769:tid 255976] [client 20.220.225.223:9279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/ace2.php"] [unique_id "al9K7bxMYwyVGnfuwsKBhwAAA_A"]
[Tue Jul 21 07:33:17.711939 2026] [security2:error] [pid 255769:tid 255934] [client 173.24.185.52:60326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9K7bxMYwyVGnfuwsKBiAAAA8Y"]
[Tue Jul 21 07:33:17.712062 2026] [security2:error] [pid 255769:tid 255934] [client 173.24.185.52:60326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9K7bxMYwyVGnfuwsKBiAAAA8Y"]
[Tue Jul 21 07:33:17.872355 2026] [security2:error] [pid 254995:tid 255169] [client 20.151.10.161:57407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9K7f7v0rlcEGmVraEn5gAAA0o"]
[Tue Jul 21 07:33:17.883747 2026] [security2:error] [pid 255769:tid 256020] [client 74.248.121.109:2167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/pomo.php"] [unique_id "al9K7bxMYwyVGnfuwsKBiwAABBo"]
[Tue Jul 21 07:33:18.029130 2026] [security2:error] [pid 254995:tid 255139] [client 20.206.105.145:38959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/seiso.php"] [unique_id "al9K7v7v0rlcEGmVraEn5wAAAyw"]
[Tue Jul 21 07:33:18.177267 2026] [security2:error] [pid 254995:tid 255190] [client 20.151.10.161:58073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/gettest.php"] [unique_id "al9K7v7v0rlcEGmVraEn6QAAA18"]
[Tue Jul 21 07:33:18.194918 2026] [security2:error] [pid 255769:tid 255950] [client 20.220.225.223:6799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/ms.php"] [unique_id "al9K7rxMYwyVGnfuwsKBkgAAA9Y"]
[Tue Jul 21 07:33:18.291177 2026] [security2:error] [pid 255769:tid 255899] [client 20.52.136.55:1577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/up.php"] [unique_id "al9K7rxMYwyVGnfuwsKBlgAAA6M"]
[Tue Jul 21 07:33:18.327170 2026] [security2:error] [pid 255769:tid 255931] [client 103.106.20.201:53851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K7rxMYwyVGnfuwsKBlwAAA8M"]
[Tue Jul 21 07:33:18.327278 2026] [security2:error] [pid 255769:tid 255931] [client 103.106.20.201:53851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K7rxMYwyVGnfuwsKBlwAAA8M"]
[Tue Jul 21 07:33:18.526724 2026] [security2:error] [pid 255769:tid 255821] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K7rxMYwyVGnfuwsKBmwAD8zM"]
[Tue Jul 21 07:33:18.526867 2026] [security2:error] [pid 255769:tid 255979] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K7rxMYwyVGnfuwsKBmwAD8zM"]
[Tue Jul 21 07:33:18.542410 2026] [security2:error] [pid 255769:tid 255937] [client 74.248.121.109:1032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/test1.php"] [unique_id "al9K7rxMYwyVGnfuwsKBnAAAA8k"]
[Tue Jul 21 07:33:18.671622 2026] [proxy:error] [pid 255769:tid 255955] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:18.671702 2026] [proxy_http:error] [pid 255769:tid 255955] [client 20.151.10.161:51277] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:18.672167 2026] [proxy:error] [pid 255769:tid 255955] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:18.672195 2026] [proxy_http:error] [pid 255769:tid 255955] [client 20.151.10.161:51277] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:18.945992 2026] [security2:error] [pid 255769:tid 255917] [client 45.251.232.145:52339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K7rxMYwyVGnfuwsKBpAAAA7U"]
[Tue Jul 21 07:33:18.946108 2026] [security2:error] [pid 255769:tid 255917] [client 45.251.232.145:52339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K7rxMYwyVGnfuwsKBpAAAA7U"]
[Tue Jul 21 07:33:18.981058 2026] [security2:error] [pid 255769:tid 255972] [client 45.8.17.121:45757] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/ioxi-o.php"] [unique_id "al9K7rxMYwyVGnfuwsKBpgAAA-w"]
[Tue Jul 21 07:33:19.003003 2026] [security2:error] [pid 255769:tid 255974] [client 107.149.152.43:29309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.152.149.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-plain.php"] [unique_id "al9K77xMYwyVGnfuwsKBqAAAA-4"], referer: www.google.com
[Tue Jul 21 07:33:19.003700 2026] [security2:error] [pid 254995:tid 255164] [client 107.149.152.43:62971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.152.149.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al9K7_7v0rlcEGmVraEn9AAAA0U"]
[Tue Jul 21 07:33:19.005391 2026] [security2:error] [pid 254995:tid 255150] [client 107.149.152.43:51039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.152.149.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al9K7_7v0rlcEGmVraEn9QAAAzc"], referer: www.google.com
[Tue Jul 21 07:33:19.127337 2026] [security2:error] [pid 254995:tid 255183] [client 20.151.10.161:57393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/simple.php"] [unique_id "al9K7_7v0rlcEGmVraEn9wAAA1g"]
[Tue Jul 21 07:33:19.212314 2026] [security2:error] [pid 254995:tid 255222] [client 107.149.152.43:30543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.152.149.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/nwmbnobn.php"] [unique_id "al9K7_7v0rlcEGmVraEn-gAAA34"], referer: www.google.com
[Tue Jul 21 07:33:19.253666 2026] [security2:error] [pid 255769:tid 255906] [client 154.192.233.199:59140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K77xMYwyVGnfuwsKBqQAAA6o"]
[Tue Jul 21 07:33:19.253859 2026] [security2:error] [pid 255769:tid 255906] [client 154.192.233.199:59140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K77xMYwyVGnfuwsKBqQAAA6o"]
[Tue Jul 21 07:33:19.265979 2026] [security2:error] [pid 255769:tid 255926] [client 74.248.121.109:2082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/fw.php"] [unique_id "al9K77xMYwyVGnfuwsKBqgAAA74"]
[Tue Jul 21 07:33:19.670712 2026] [security2:error] [pid 255769:tid 255941] [client 20.151.10.161:50924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/xxx.php"] [unique_id "al9K77xMYwyVGnfuwsKB3AAAA80"]
[Tue Jul 21 07:33:19.712032 2026] [security2:error] [pid 254995:tid 255215] [client 20.197.195.24:13163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/inputs.php"] [unique_id "al9K7_7v0rlcEGmVraEoAQAAA3c"]
[Tue Jul 21 07:33:19.767355 2026] [security2:error] [pid 254995:tid 255269] [client 20.220.225.223:61970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/hp2.php"] [unique_id "al9K7_7v0rlcEGmVraEoAwAAA5M"]
[Tue Jul 21 07:33:19.793798 2026] [security2:error] [pid 254995:tid 255194] [client 107.149.152.43:42563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.152.149.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al9K7_7v0rlcEGmVraEoBAAAA2M"], referer: www.google.com
[Tue Jul 21 07:33:19.834025 2026] [security2:error] [pid 255769:tid 255969] [client 20.206.105.145:39262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/155.php"] [unique_id "al9K77xMYwyVGnfuwsKB4gAAA-k"]
[Tue Jul 21 07:33:19.962301 2026] [security2:error] [pid 254995:tid 255140] [client 74.248.121.109:2102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/fm.php"] [unique_id "al9K7_7v0rlcEGmVraEoCQAAAy0"]
[Tue Jul 21 07:33:20.008638 2026] [security2:error] [pid 255769:tid 256019] [client 175.45.70.82:55119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K8LxMYwyVGnfuwsKB6QAABBk"]
[Tue Jul 21 07:33:20.008734 2026] [security2:error] [pid 255769:tid 256019] [client 175.45.70.82:55119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K8LxMYwyVGnfuwsKB6QAABBk"]
[Tue Jul 21 07:33:20.091263 2026] [security2:error] [pid 255769:tid 255990] [client 107.149.152.43:47109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.152.149.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-plain.php"] [unique_id "al9K8LxMYwyVGnfuwsKCMwAAA_4"], referer: www.google.com
[Tue Jul 21 07:33:20.178664 2026] [security2:error] [pid 255769:tid 255829] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K8LxMYwyVGnfuwsKCPQADvTs"]
[Tue Jul 21 07:33:20.178773 2026] [security2:error] [pid 255769:tid 255925] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K8LxMYwyVGnfuwsKCPQADvTs"]
[Tue Jul 21 07:33:20.295320 2026] [security2:error] [pid 255769:tid 256011] [client 20.151.10.161:51300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/hypo.php"] [unique_id "al9K8LxMYwyVGnfuwsKCPgAABBE"]
[Tue Jul 21 07:33:20.323122 2026] [security2:error] [pid 254995:tid 255154] [client 117.217.38.194:57122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K8P7v0rlcEGmVraEoDAAAAzs"]
[Tue Jul 21 07:33:20.323261 2026] [security2:error] [pid 254995:tid 255154] [client 117.217.38.194:57122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K8P7v0rlcEGmVraEoDAAAAzs"]
[Tue Jul 21 07:33:20.336007 2026] [security2:error] [pid 255769:tid 256001] [client 20.220.225.223:49592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9K8LxMYwyVGnfuwsKCQQAABAc"]
[Tue Jul 21 07:33:20.770551 2026] [security2:error] [pid 254995:tid 255205] [client 74.248.121.109:1084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/ini.php"] [unique_id "al9K8P7v0rlcEGmVraEoFAAAA24"]
[Tue Jul 21 07:33:20.780766 2026] [security2:error] [pid 255769:tid 255952] [client 45.8.17.148:43519] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wpx/index.php"] [unique_id "al9K8LxMYwyVGnfuwsKCRQAAA9g"]
[Tue Jul 21 07:33:20.825698 2026] [security2:error] [pid 255769:tid 256022] [client 103.174.34.15:63544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K8LxMYwyVGnfuwsKCRgAABBw"]
[Tue Jul 21 07:33:20.826716 2026] [security2:error] [pid 255769:tid 256022] [client 103.174.34.15:63544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K8LxMYwyVGnfuwsKCRgAABBw"]
[Tue Jul 21 07:33:20.829913 2026] [security2:error] [pid 255769:tid 255848] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K8LxMYwyVGnfuwsKCRwAEG04"]
[Tue Jul 21 07:33:20.830061 2026] [security2:error] [pid 255769:tid 256021] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K8LxMYwyVGnfuwsKCRwAEG04"]
[Tue Jul 21 07:33:20.959886 2026] [security2:error] [pid 254995:tid 255012] [remote 154.61.75.100:35846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9K8P7v0rlcEGmVraEoFgADdhA"]
[Tue Jul 21 07:33:21.142633 2026] [security2:error] [pid 255769:tid 255906] [client 20.206.105.145:38932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ppp.php"] [unique_id "al9K8bxMYwyVGnfuwsKCTgAAA6o"]
[Tue Jul 21 07:33:21.282508 2026] [security2:error] [pid 255769:tid 255956] [client 172.245.102.41:20991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9K8bxMYwyVGnfuwsKCTQAAA9w"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:21.527128 2026] [proxy:error] [pid 254995:tid 255171] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:21.527218 2026] [proxy_http:error] [pid 254995:tid 255171] [client 20.151.10.161:57989] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:21.528482 2026] [proxy:error] [pid 254995:tid 255171] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:21.528529 2026] [proxy_http:error] [pid 254995:tid 255171] [client 20.151.10.161:57989] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:21.642281 2026] [security2:error] [pid 254995:tid 255257] [client 20.220.225.223:48142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9K8f7v0rlcEGmVraEoIgAAA4c"]
[Tue Jul 21 07:33:21.710014 2026] [security2:error] [pid 254995:tid 255201] [client 20.220.225.223:4549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/hp3.php"] [unique_id "al9K8f7v0rlcEGmVraEoIwAAA2o"]
[Tue Jul 21 07:33:21.902483 2026] [security2:error] [pid 254995:tid 255165] [client 74.248.121.109:1066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/themes.php"] [unique_id "al9K8f7v0rlcEGmVraEoJwAAA0Y"]
[Tue Jul 21 07:33:21.988456 2026] [security2:error] [pid 254995:tid 255268] [client 45.8.17.135:26129] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-matcha1.php"] [unique_id "al9K8f7v0rlcEGmVraEoLAAAA5I"]
[Tue Jul 21 07:33:22.300841 2026] [security2:error] [pid 255769:tid 255959] [client 107.149.152.43:33549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.152.149.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/tsogegba.php"] [unique_id "al9K8rxMYwyVGnfuwsKCXgAAA98"], referer: www.google.com
[Tue Jul 21 07:33:22.330319 2026] [security2:error] [pid 255769:tid 255858] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9K8rxMYwyVGnfuwsKCXwAD9Vg"]
[Tue Jul 21 07:33:22.331043 2026] [security2:error] [pid 255769:tid 255981] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9K8rxMYwyVGnfuwsKCXwAD9Vg"]
[Tue Jul 21 07:33:22.518427 2026] [security2:error] [pid 255769:tid 255910] [client 20.151.10.161:50943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/chosen.php"] [unique_id "al9K8rxMYwyVGnfuwsKCZAAAA64"]
[Tue Jul 21 07:33:22.629347 2026] [security2:error] [pid 255769:tid 255908] [client 74.248.121.109:2086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/dropdown.php"] [unique_id "al9K8rxMYwyVGnfuwsKCaAAAA6w"]
[Tue Jul 21 07:33:22.881414 2026] [security2:error] [pid 255769:tid 255926] [client 20.220.225.223:49563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/ms-new.php"] [unique_id "al9K8rxMYwyVGnfuwsKCdwAAA74"]
[Tue Jul 21 07:33:22.967713 2026] [security2:error] [pid 255769:tid 255788] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K8rxMYwyVGnfuwsKCewAD5BI"]
[Tue Jul 21 07:33:22.967847 2026] [security2:error] [pid 255769:tid 255964] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K8rxMYwyVGnfuwsKCewAD5BI"]
[Tue Jul 21 07:33:23.090867 2026] [security2:error] [pid 255769:tid 256004] [client 45.8.17.124:28871] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwenty/assets/js/index.php"] [unique_id "al9K87xMYwyVGnfuwsKCkAAABAo"]
[Tue Jul 21 07:33:23.091480 2026] [security2:error] [pid 254995:tid 255187] [client 20.220.225.223:8933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9K8_7v0rlcEGmVraEoOQAAA1w"]
[Tue Jul 21 07:33:23.133575 2026] [security2:error] [pid 255769:tid 255983] [client 74.248.121.109:1039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/wp-links.php"] [unique_id "al9K87xMYwyVGnfuwsKCkgAAA_c"]
[Tue Jul 21 07:33:23.268323 2026] [security2:error] [pid 255769:tid 255912] [client 104.28.163.33:27054] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "10db.com.br"] [uri "/"] [unique_id "al9K87xMYwyVGnfuwsKCnAAAA7A"]
[Tue Jul 21 07:33:23.475614 2026] [security2:error] [pid 255769:tid 255915] [client 20.197.195.24:13061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/classwithtostring.php"] [unique_id "al9K87xMYwyVGnfuwsKCnwAAA7M"]
[Tue Jul 21 07:33:23.758465 2026] [security2:error] [pid 255769:tid 255944] [client 2.57.168.20:32477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.168.57.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cursosonlinesiteoficial.com"] [uri "/wp-login.php"] [unique_id "al9K87xMYwyVGnfuwsKCowAAA9A"]
[Tue Jul 21 07:33:23.813609 2026] [security2:error] [pid 255769:tid 255968] [client 152.59.154.239:64414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K87xMYwyVGnfuwsKCpAAAA-g"]
[Tue Jul 21 07:33:23.813740 2026] [security2:error] [pid 255769:tid 255968] [client 152.59.154.239:64414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K87xMYwyVGnfuwsKCpAAAA-g"]
[Tue Jul 21 07:33:23.851393 2026] [security2:error] [pid 254995:tid 255211] [client 74.248.121.109:1999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/xmrlpc.php"] [unique_id "al9K8_7v0rlcEGmVraEoQwAAA3M"]
[Tue Jul 21 07:33:24.283503 2026] [security2:error] [pid 255769:tid 255917] [client 45.8.17.137:48409] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/dlex/dlex.php"] [unique_id "al9K9LxMYwyVGnfuwsKCsgAAA7U"]
[Tue Jul 21 07:33:24.288882 2026] [security2:error] [pid 255769:tid 256007] [client 193.36.225.104:24235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9K87xMYwyVGnfuwsKCpgAABA0"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:33:24.323607 2026] [security2:error] [pid 255769:tid 255939] [client 59.96.220.140:64208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9K9LxMYwyVGnfuwsKCswAAA8s"]
[Tue Jul 21 07:33:24.323714 2026] [security2:error] [pid 255769:tid 255939] [client 59.96.220.140:64208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9K9LxMYwyVGnfuwsKCswAAA8s"]
[Tue Jul 21 07:33:24.335985 2026] [security2:error] [pid 255769:tid 255910] [client 74.248.121.109:2161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/htaccess.php"] [unique_id "al9K9LxMYwyVGnfuwsKCtAAAA64"]
[Tue Jul 21 07:33:24.476439 2026] [security2:error] [pid 255769:tid 255906] [client 20.151.10.161:2709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mitolyn.tryhealth.shop"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9K9LxMYwyVGnfuwsKCugAAA6o"]
[Tue Jul 21 07:33:24.677601 2026] [proxy:error] [pid 255769:tid 256028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:24.677675 2026] [proxy_http:error] [pid 255769:tid 256028] [client 20.151.10.161:57411] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:24.678224 2026] [proxy:error] [pid 255769:tid 256028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:24.678249 2026] [proxy_http:error] [pid 255769:tid 256028] [client 20.151.10.161:57411] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:24.761496 2026] [security2:error] [pid 255769:tid 255980] [client 20.151.10.161:2718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mitolyn.tryhealth.shop"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9K9LxMYwyVGnfuwsKCwAAAA_Q"]
[Tue Jul 21 07:33:24.927453 2026] [security2:error] [pid 255769:tid 255793] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9K9LxMYwyVGnfuwsKCwwAD1xc"]
[Tue Jul 21 07:33:24.927592 2026] [security2:error] [pid 255769:tid 255951] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9K9LxMYwyVGnfuwsKCwwAD1xc"]
[Tue Jul 21 07:33:24.959917 2026] [security2:error] [pid 255769:tid 255777] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K9LxMYwyVGnfuwsKCxAAEBQc"]
[Tue Jul 21 07:33:24.960101 2026] [security2:error] [pid 255769:tid 255999] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K9LxMYwyVGnfuwsKCxAAEBQc"]
[Tue Jul 21 07:33:24.963177 2026] [security2:error] [pid 255769:tid 255921] [client 109.248.148.246:44020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9K9LxMYwyVGnfuwsKCxQAAA7k"]
[Tue Jul 21 07:33:24.963286 2026] [security2:error] [pid 255769:tid 255921] [client 109.248.148.246:44020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9K9LxMYwyVGnfuwsKCxQAAA7k"]
[Tue Jul 21 07:33:24.993805 2026] [security2:error] [pid 254995:tid 255189] [client 193.36.225.70:31909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9K9P7v0rlcEGmVraEoTwAAA14"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:25.039920 2026] [security2:error] [pid 254995:tid 255252] [client 20.151.10.161:2947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mitolyn.tryhealth.shop"] [uri "/images.php"] [unique_id "al9K9f7v0rlcEGmVraEoUAAAA4M"]
[Tue Jul 21 07:33:25.143262 2026] [security2:error] [pid 255769:tid 255774] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K9bxMYwyVGnfuwsKCxgADswQ"]
[Tue Jul 21 07:33:25.143411 2026] [security2:error] [pid 255769:tid 255915] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K9bxMYwyVGnfuwsKCxgADswQ"]
[Tue Jul 21 07:33:25.246871 2026] [security2:error] [pid 255769:tid 255969] [client 74.248.121.109:1073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/readme.php"] [unique_id "al9K9bxMYwyVGnfuwsKCxwAAA-k"]
[Tue Jul 21 07:33:25.325633 2026] [security2:error] [pid 254995:tid 255169] [client 20.151.10.161:2953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mitolyn.tryhealth.shop"] [uri "/for.php"] [unique_id "al9K9f7v0rlcEGmVraEoVgAAA0o"]
[Tue Jul 21 07:33:25.327222 2026] [security2:error] [pid 255769:tid 255926] [client 139.167.225.182:64981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K9bxMYwyVGnfuwsKCygAAA74"]
[Tue Jul 21 07:33:25.327404 2026] [security2:error] [pid 255769:tid 255926] [client 139.167.225.182:64981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K9bxMYwyVGnfuwsKCygAAA74"]
[Tue Jul 21 07:33:25.398159 2026] [security2:error] [pid 255769:tid 255916] [client 104.28.163.33:27060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "10db.com.br"] [uri "/"] [unique_id "al9K9bxMYwyVGnfuwsKCywAAA7Q"]
[Tue Jul 21 07:33:25.507299 2026] [security2:error] [pid 255769:tid 255944] [client 20.220.225.223:62133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/wp-css.php"] [unique_id "al9K9bxMYwyVGnfuwsKCzQAAA9A"]
[Tue Jul 21 07:33:25.603362 2026] [security2:error] [pid 255769:tid 255943] [client 20.151.10.161:2708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mitolyn.tryhealth.shop"] [uri "/2larp.php"] [unique_id "al9K9bxMYwyVGnfuwsKC0QAAA88"]
[Tue Jul 21 07:33:25.820566 2026] [security2:error] [pid 255769:tid 255918] [client 20.52.136.55:1753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/66.php"] [unique_id "al9K9bxMYwyVGnfuwsKC1AAAA7Y"]
[Tue Jul 21 07:33:25.879605 2026] [security2:error] [pid 255769:tid 255903] [client 20.151.10.161:2721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mitolyn.tryhealth.shop"] [uri "/adminner.php"] [unique_id "al9K9bxMYwyVGnfuwsKC1QAAA6c"]
[Tue Jul 21 07:33:25.994192 2026] [security2:error] [pid 254995:tid 255208] [client 45.8.17.141:50725] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/view-source/ioxi-o.php"] [unique_id "al9K9f7v0rlcEGmVraEoYQAAA3A"]
[Tue Jul 21 07:33:26.157233 2026] [security2:error] [pid 255769:tid 255937] [client 20.151.10.161:2702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mitolyn.tryhealth.shop"] [uri "/82.php"] [unique_id "al9K9rxMYwyVGnfuwsKC2gAAA8k"]
[Tue Jul 21 07:33:26.229865 2026] [security2:error] [pid 255769:tid 256009] [client 20.197.195.24:13100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9K9rxMYwyVGnfuwsKC4QAABA8"]
[Tue Jul 21 07:33:26.274915 2026] [security2:error] [pid 255769:tid 255994] [client 103.162.129.114:61631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9K9rxMYwyVGnfuwsKC5AAABAE"]
[Tue Jul 21 07:33:26.275080 2026] [security2:error] [pid 255769:tid 255994] [client 103.162.129.114:61631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9K9rxMYwyVGnfuwsKC5AAABAE"]
[Tue Jul 21 07:33:26.325345 2026] [security2:error] [pid 254995:tid 255190] [client 117.251.86.144:45134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9K9v7v0rlcEGmVraEoagAAA18"]
[Tue Jul 21 07:33:26.325439 2026] [security2:error] [pid 254995:tid 255190] [client 117.251.86.144:45134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9K9v7v0rlcEGmVraEoagAAA18"]
[Tue Jul 21 07:33:26.434297 2026] [security2:error] [pid 255769:tid 255980] [client 20.151.10.161:2747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mitolyn.tryhealth.shop"] [uri "/kir.php"] [unique_id "al9K9rxMYwyVGnfuwsKC6gAAA_Q"]
[Tue Jul 21 07:33:26.454104 2026] [security2:error] [pid 255769:tid 255983] [client 74.248.121.109:2058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/403.php"] [unique_id "al9K9rxMYwyVGnfuwsKC6wAAA_c"]
[Tue Jul 21 07:33:26.516177 2026] [security2:error] [pid 255769:tid 255922] [client 104.28.163.33:27066] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "10db.com.br"] [uri "/"] [unique_id "al9K9rxMYwyVGnfuwsKC7QAAA7o"]
[Tue Jul 21 07:33:26.553774 2026] [security2:error] [pid 254995:tid 255222] [client 20.151.10.161:51323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/als.php"] [unique_id "al9K9v7v0rlcEGmVraEocQAAA34"]
[Tue Jul 21 07:33:26.980522 2026] [security2:error] [pid 255769:tid 255968] [client 20.220.225.223:4589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/aa1.php"] [unique_id "al9K9rxMYwyVGnfuwsKC-AAAA-g"]
[Tue Jul 21 07:33:27.289362 2026] [security2:error] [pid 255769:tid 256006] [client 45.8.17.117:46663] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/network/cache/index.php"] [unique_id "al9K97xMYwyVGnfuwsKC_gAABAw"]
[Tue Jul 21 07:33:27.451042 2026] [security2:error] [pid 255769:tid 255969] [client 122.186.204.214:61669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9K97xMYwyVGnfuwsKDBQAAA-k"]
[Tue Jul 21 07:33:27.451141 2026] [security2:error] [pid 255769:tid 255969] [client 122.186.204.214:61669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9K97xMYwyVGnfuwsKDBQAAA-k"]
[Tue Jul 21 07:33:27.619860 2026] [security2:error] [pid 255769:tid 255985] [client 20.220.225.223:51493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/track.php"] [unique_id "al9K97xMYwyVGnfuwsKDCgAAA_k"]
[Tue Jul 21 07:33:27.648168 2026] [security2:error] [pid 255769:tid 255984] [client 104.28.163.33:27072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "10db.com.br"] [uri "/"] [unique_id "al9K97xMYwyVGnfuwsKDCwAAA_g"]
[Tue Jul 21 07:33:27.710125 2026] [security2:error] [pid 254995:tid 255196] [client 20.151.10.161:58034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/pol.php"] [unique_id "al9K9_7v0rlcEGmVraEoiQAAA2U"]
[Tue Jul 21 07:33:27.825646 2026] [autoindex:error] [pid 255769:tid 255894] [remote 74.7.242.38:51988] AH01276: Cannot serve directory /home4/arcoll06/y.arcoll.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:27.880397 2026] [security2:error] [pid 254995:tid 255149] [client 74.248.121.109:1078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/max.php"] [unique_id "al9K9_7v0rlcEGmVraEojQAAAzY"]
[Tue Jul 21 07:33:28.053102 2026] [authz_core:error] [pid 254995:tid 255197] [client 213.35.113.47:62265] AH01630: client denied by server configuration: /home1/ofic8899/aizenpower.shop-officialstore.com/wp-content/uploads/index.php
[Tue Jul 21 07:33:28.076408 2026] [security2:error] [pid 255769:tid 255997] [client 20.220.225.223:8939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/wp-explorer.php"] [unique_id "al9K-LxMYwyVGnfuwsKDEAAABAM"]
[Tue Jul 21 07:33:28.091039 2026] [security2:error] [pid 255769:tid 255955] [client 122.162.144.145:15598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9K-LxMYwyVGnfuwsKDEQAAA9s"]
[Tue Jul 21 07:33:28.091174 2026] [security2:error] [pid 255769:tid 255955] [client 122.162.144.145:15598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9K-LxMYwyVGnfuwsKDEQAAA9s"]
[Tue Jul 21 07:33:28.177872 2026] [security2:error] [pid 255769:tid 255896] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K-LxMYwyVGnfuwsKDEgAEIn4"]
[Tue Jul 21 07:33:28.178064 2026] [security2:error] [pid 255769:tid 256028] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K-LxMYwyVGnfuwsKDEgAEIn4"]
[Tue Jul 21 07:33:28.261674 2026] [security2:error] [pid 254995:tid 255198] [client 193.36.225.105:39479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9K-P7v0rlcEGmVraEolwAAA2c"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:33:28.300920 2026] [security2:error] [pid 255769:tid 255980] [client 173.24.185.52:60792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9K-LxMYwyVGnfuwsKDGAAAA_Q"]
[Tue Jul 21 07:33:28.301013 2026] [security2:error] [pid 255769:tid 255980] [client 173.24.185.52:60792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9K-LxMYwyVGnfuwsKDGAAAA_Q"]
[Tue Jul 21 07:33:28.453772 2026] [security2:error] [pid 255769:tid 255909] [client 213.152.162.104:41514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9K-LxMYwyVGnfuwsKDGQAAA60"]
[Tue Jul 21 07:33:28.453882 2026] [security2:error] [pid 255769:tid 255909] [client 213.152.162.104:41514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9K-LxMYwyVGnfuwsKDGQAAA60"]
[Tue Jul 21 07:33:28.578138 2026] [security2:error] [pid 255769:tid 255961] [client 74.7.175.169:39230] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.y.arcoll.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9K-LxMYwyVGnfuwsKDGwAD4QU"]
[Tue Jul 21 07:33:28.672467 2026] [security2:error] [pid 255769:tid 255931] [client 20.52.136.55:1588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/666.php"] [unique_id "al9K-LxMYwyVGnfuwsKDHgAAA8M"]
[Tue Jul 21 07:33:28.784865 2026] [security2:error] [pid 254995:tid 255161] [client 45.8.17.144:55669] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/table/table/updater-tool.php"] [unique_id "al9K-P7v0rlcEGmVraEopwAAA0I"]
[Tue Jul 21 07:33:28.822110 2026] [security2:error] [pid 254995:tid 255261] [client 20.220.225.223:38692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/echkm.php"] [unique_id "al9K-P7v0rlcEGmVraEoqAAAA4s"]
[Tue Jul 21 07:33:28.959483 2026] [security2:error] [pid 254995:tid 255279] [client 20.151.10.161:50927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/file5.php"] [unique_id "al9K-P7v0rlcEGmVraEorQAAA50"]
[Tue Jul 21 07:33:29.005027 2026] [security2:error] [pid 255769:tid 255916] [client 103.106.20.201:54462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-bxMYwyVGnfuwsKDJgAAA7Q"]
[Tue Jul 21 07:33:29.005175 2026] [security2:error] [pid 255769:tid 255916] [client 103.106.20.201:54462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-bxMYwyVGnfuwsKDJgAAA7Q"]
[Tue Jul 21 07:33:29.018109 2026] [security2:error] [pid 254995:tid 255186] [client 20.197.195.24:13103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp-blog.php"] [unique_id "al9K-f7v0rlcEGmVraEosAAAA1s"]
[Tue Jul 21 07:33:29.095571 2026] [security2:error] [pid 255769:tid 255785] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-bxMYwyVGnfuwsKDJwADow8"]
[Tue Jul 21 07:33:29.095746 2026] [security2:error] [pid 255769:tid 255899] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-bxMYwyVGnfuwsKDJwADow8"]
[Tue Jul 21 07:33:29.114794 2026] [autoindex:error] [pid 254995:tid 255138] [client 213.35.113.47:62265] AH01276: Cannot serve directory /home1/ofic8899/aizenpower.shop-officialstore.com/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:29.252646 2026] [security2:error] [pid 254995:tid 255135] [client 160.30.136.8:65172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buyonlinetodayatadiscount.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9K-f7v0rlcEGmVraEougAAAyg"]
[Tue Jul 21 07:33:29.254627 2026] [security2:error] [pid 254995:tid 255159] [client 20.220.225.223:24244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/tinyfilemanager.php"] [unique_id "al9K-f7v0rlcEGmVraEouwAAA0A"]
[Tue Jul 21 07:33:29.317232 2026] [security2:error] [pid 254995:tid 255259] [client 74.248.121.109:2076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/m.php"] [unique_id "al9K-f7v0rlcEGmVraEowAAAA4k"]
[Tue Jul 21 07:33:29.362238 2026] [security2:error] [pid 254995:tid 255019] [remote 162.19.86.63:52048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "insp1.com.br"] [uri "/wp-login.php"] [unique_id "al9K-f7v0rlcEGmVraEowgADehc"]
[Tue Jul 21 07:33:29.371461 2026] [security2:error] [pid 254995:tid 255136] [client 20.206.105.145:39275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/201.php"] [unique_id "al9K-f7v0rlcEGmVraEowwAAAyk"]
[Tue Jul 21 07:33:29.434830 2026] [security2:error] [pid 255769:tid 255987] [client 45.251.232.145:52861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-bxMYwyVGnfuwsKDKQAAA_s"]
[Tue Jul 21 07:33:29.434957 2026] [security2:error] [pid 255769:tid 255987] [client 45.251.232.145:52861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-bxMYwyVGnfuwsKDKQAAA_s"]
[Tue Jul 21 07:33:29.664273 2026] [security2:error] [pid 255769:tid 255908] [client 62.102.148.164:48932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9K-bxMYwyVGnfuwsKDLQAAA6w"]
[Tue Jul 21 07:33:29.664394 2026] [security2:error] [pid 255769:tid 255908] [client 62.102.148.164:48932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9K-bxMYwyVGnfuwsKDLQAAA6w"]
[Tue Jul 21 07:33:29.757189 2026] [security2:error] [pid 255769:tid 255966] [client 20.151.10.161:57373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9K-bxMYwyVGnfuwsKDLgAAA-Y"]
[Tue Jul 21 07:33:29.824545 2026] [security2:error] [pid 255769:tid 256015] [client 136.144.33.101:59705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9K-bxMYwyVGnfuwsKDLAAABBU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:29.840908 2026] [security2:error] [pid 255769:tid 255985] [client 20.206.105.145:38929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ops.php"] [unique_id "al9K-bxMYwyVGnfuwsKDMQAAA_k"]
[Tue Jul 21 07:33:29.846507 2026] [security2:error] [pid 254995:tid 255221] [client 154.192.233.199:59595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-f7v0rlcEGmVraEozwAAA30"]
[Tue Jul 21 07:33:29.846668 2026] [security2:error] [pid 254995:tid 255221] [client 154.192.233.199:59595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-f7v0rlcEGmVraEozwAAA30"]
[Tue Jul 21 07:33:29.963079 2026] [security2:error] [pid 254995:tid 255269] [client 160.30.136.8:57524] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "buyonlinetodayatadiscount.net"] [uri "/"] [unique_id "al9K-f7v0rlcEGmVraEo0gAAA5M"]
[Tue Jul 21 07:33:30.407987 2026] [security2:error] [pid 255769:tid 255999] [client 20.220.225.223:8934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/akismet.php"] [unique_id "al9K-rxMYwyVGnfuwsKDNwAABAU"]
[Tue Jul 21 07:33:30.562616 2026] [security2:error] [pid 254995:tid 255275] [client 213.35.113.47:62379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.113.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/wp-login.php"] [unique_id "al9K-v7v0rlcEGmVraEo4gAAA5k"]
[Tue Jul 21 07:33:30.590058 2026] [security2:error] [pid 255769:tid 256005] [client 74.248.121.109:2105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/click.php"] [unique_id "al9K-rxMYwyVGnfuwsKDOQAABAs"]
[Tue Jul 21 07:33:30.678296 2026] [security2:error] [pid 255769:tid 255962] [client 160.30.136.8:61280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buyonlinetodayatadiscount.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9K-rxMYwyVGnfuwsKDPgAAA-I"]
[Tue Jul 21 07:33:30.758969 2026] [security2:error] [pid 255769:tid 255982] [client 175.45.70.82:55633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-rxMYwyVGnfuwsKDQAAAA_Y"]
[Tue Jul 21 07:33:30.759069 2026] [security2:error] [pid 255769:tid 255982] [client 175.45.70.82:55633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-rxMYwyVGnfuwsKDQAAAA_Y"]
[Tue Jul 21 07:33:30.809544 2026] [security2:error] [pid 255769:tid 255983] [client 117.217.38.194:57557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-rxMYwyVGnfuwsKDQQAAA_c"]
[Tue Jul 21 07:33:30.809662 2026] [security2:error] [pid 255769:tid 255983] [client 117.217.38.194:57557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-rxMYwyVGnfuwsKDQQAAA_c"]
[Tue Jul 21 07:33:31.160725 2026] [security2:error] [pid 254995:tid 255177] [client 20.151.10.161:50926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/file.php"] [unique_id "al9K-_7v0rlcEGmVraEo7QAAA1I"]
[Tue Jul 21 07:33:31.279889 2026] [security2:error] [pid 255769:tid 255916] [client 45.8.17.146:52029] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/maintenance.php"] [unique_id "al9K-7xMYwyVGnfuwsKDSgAAA7Q"]
[Tue Jul 21 07:33:31.356090 2026] [security2:error] [pid 254995:tid 255068] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-_7v0rlcEGmVraEo8AADh0g"]
[Tue Jul 21 07:33:31.356232 2026] [security2:error] [pid 254995:tid 255257] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-_7v0rlcEGmVraEo8AADh0g"]
[Tue Jul 21 07:33:31.393214 2026] [security2:error] [pid 254995:tid 255201] [client 160.30.136.8:53968] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "buyonlinetodayatadiscount.net"] [uri "/"] [unique_id "al9K-_7v0rlcEGmVraEo8QAAA2o"]
[Tue Jul 21 07:33:31.413945 2026] [security2:error] [pid 255769:tid 255930] [client 103.174.34.15:64238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-7xMYwyVGnfuwsKDTgAAA8I"]
[Tue Jul 21 07:33:31.414076 2026] [security2:error] [pid 255769:tid 255930] [client 103.174.34.15:64238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-7xMYwyVGnfuwsKDTgAAA8I"]
[Tue Jul 21 07:33:31.703555 2026] [security2:error] [pid 255769:tid 256020] [client 20.220.225.223:62850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/ace2.php"] [unique_id "al9K-7xMYwyVGnfuwsKDUgAABBo"]
[Tue Jul 21 07:33:31.788311 2026] [security2:error] [pid 255769:tid 255905] [client 20.206.105.145:38940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ingfo.php"] [unique_id "al9K-7xMYwyVGnfuwsKDUwAAA6k"]
[Tue Jul 21 07:33:31.797141 2026] [security2:error] [pid 255769:tid 256022] [client 20.220.225.223:19697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/hp2.php"] [unique_id "al9K-7xMYwyVGnfuwsKDVAAABBw"]
[Tue Jul 21 07:33:31.827189 2026] [autoindex:error] [pid 255769:tid 255959] [client 20.197.195.24:13074] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:31.974987 2026] [security2:error] [pid 254995:tid 255139] [client 20.220.225.223:24261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/ee.php"] [unique_id "al9K-_7v0rlcEGmVraEo_wAAAyw"]
[Tue Jul 21 07:33:32.085638 2026] [security2:error] [pid 254995:tid 255159] [client 74.248.121.109:2169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/lv.php"] [unique_id "al9K_P7v0rlcEGmVraEpAQAAA0A"]
[Tue Jul 21 07:33:32.123679 2026] [security2:error] [pid 254995:tid 255178] [client 160.30.136.8:52391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buyonlinetodayatadiscount.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9K_P7v0rlcEGmVraEpAgAAA1M"]
[Tue Jul 21 07:33:32.154474 2026] [security2:error] [pid 255769:tid 255925] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K-rxMYwyVGnfuwsKDRAADvWo"]
[Tue Jul 21 07:33:32.771653 2026] [security2:error] [pid 255769:tid 255940] [client 20.197.195.24:13074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp-content/admin.php"] [unique_id "al9K_LxMYwyVGnfuwsKDYQAAA8w"]
[Tue Jul 21 07:33:32.831254 2026] [security2:error] [pid 254995:tid 255090] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9K_P7v0rlcEGmVraEpHQADQV4"]
[Tue Jul 21 07:33:32.831443 2026] [security2:error] [pid 254995:tid 255160] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9K_P7v0rlcEGmVraEpHQADQV4"]
[Tue Jul 21 07:33:32.840212 2026] [security2:error] [pid 255769:tid 256025] [client 160.30.136.8:51299] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "buyonlinetodayatadiscount.net"] [uri "/"] [unique_id "al9K_LxMYwyVGnfuwsKDYgAABB8"]
[Tue Jul 21 07:33:32.876721 2026] [security2:error] [pid 255769:tid 255912] [client 20.206.105.145:38951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/error_log.php"] [unique_id "al9K_LxMYwyVGnfuwsKDYwAAA7A"]
[Tue Jul 21 07:33:32.959256 2026] [security2:error] [pid 254995:tid 255224] [client 20.220.225.223:19310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/hp3.php"] [unique_id "al9K_P7v0rlcEGmVraEpHwAAA4A"]
[Tue Jul 21 07:33:33.017423 2026] [security2:error] [pid 254995:tid 255211] [client 74.248.121.109:2175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/cong.php"] [unique_id "al9K_f7v0rlcEGmVraEpIQAAA3M"]
[Tue Jul 21 07:33:33.184830 2026] [security2:error] [pid 255769:tid 255989] [client 20.220.225.223:8958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/ms.php"] [unique_id "al9K_bxMYwyVGnfuwsKDZgAAA_0"]
[Tue Jul 21 07:33:33.272506 2026] [security2:error] [pid 255769:tid 255909] [client 20.220.225.223:49841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/2352356666.php"] [unique_id "al9K_bxMYwyVGnfuwsKDaAAAA60"]
[Tue Jul 21 07:33:33.479749 2026] [security2:error] [pid 254995:tid 255155] [client 45.8.17.118:20509] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/admin.php"] [unique_id "al9K_f7v0rlcEGmVraEpKAAAAzw"]
[Tue Jul 21 07:33:33.616113 2026] [security2:error] [pid 254995:tid 255115] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K_f7v0rlcEGmVraEpLQADeHc"]
[Tue Jul 21 07:33:33.616284 2026] [security2:error] [pid 254995:tid 255216] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K_f7v0rlcEGmVraEpLQADeHc"]
[Tue Jul 21 07:33:33.647297 2026] [security2:error] [pid 254995:tid 255177] [client 160.30.136.8:55953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buyonlinetodayatadiscount.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9K_f7v0rlcEGmVraEpLgAAA1I"]
[Tue Jul 21 07:33:33.649593 2026] [security2:error] [pid 255769:tid 255918] [client 74.248.121.109:1029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/brand.php"] [unique_id "al9K_bxMYwyVGnfuwsKDbgAAA7Y"]
[Tue Jul 21 07:33:33.663970 2026] [security2:error] [pid 255769:tid 255903] [client 20.220.225.223:61997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/acew67.php"] [unique_id "al9K_bxMYwyVGnfuwsKDbwAAA6c"]
[Tue Jul 21 07:33:33.724456 2026] [security2:error] [pid 255769:tid 255930] [client 20.52.136.55:1545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/byp.php"] [unique_id "al9K_bxMYwyVGnfuwsKDcAAAA8I"]
[Tue Jul 21 07:33:33.745665 2026] [security2:error] [pid 255769:tid 255967] [client 20.197.195.24:13077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/ms-edit.php"] [unique_id "al9K_bxMYwyVGnfuwsKDcQAAA-c"]
[Tue Jul 21 07:33:33.802530 2026] [core:error] [pid 255769:tid 255859] [remote 40.77.167.77:18347] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:33:33.802552 2026] [core:error] [pid 255769:tid 255859] [remote 40.77.167.77:18347] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:33:34.036797 2026] [security2:error] [pid 255769:tid 256026] [client 20.151.10.161:57392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/cfile.php"] [unique_id "al9K_rxMYwyVGnfuwsKDdQAABCA"]
[Tue Jul 21 07:33:34.362288 2026] [security2:error] [pid 255769:tid 255959] [client 160.30.136.8:50387] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "buyonlinetodayatadiscount.net"] [uri "/"] [unique_id "al9K_rxMYwyVGnfuwsKDdwAAA98"]
[Tue Jul 21 07:33:34.384652 2026] [security2:error] [pid 255769:tid 255915] [client 136.144.33.29:25117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9K_rxMYwyVGnfuwsKDeAAAA7M"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:34.393562 2026] [security2:error] [pid 255769:tid 256009] [client 45.8.17.145:44875] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/home.php"] [unique_id "al9K_rxMYwyVGnfuwsKDeQAABA8"]
[Tue Jul 21 07:33:34.549942 2026] [security2:error] [pid 255769:tid 255937] [client 20.206.105.145:39132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/xenon1337.php"] [unique_id "al9K_rxMYwyVGnfuwsKDfAAAA8k"]
[Tue Jul 21 07:33:34.579454 2026] [security2:error] [pid 255769:tid 255850] [remote 173.212.252.15:52902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9K_rxMYwyVGnfuwsKDfQAEGlA"]
[Tue Jul 21 07:33:34.693540 2026] [security2:error] [pid 255769:tid 255993] [client 74.248.121.109:1042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/atomlib.php"] [unique_id "al9K_rxMYwyVGnfuwsKDfgAABAA"]
[Tue Jul 21 07:33:34.862366 2026] [security2:error] [pid 255769:tid 255994] [client 59.96.220.140:64702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9K_rxMYwyVGnfuwsKDgQAABAE"]
[Tue Jul 21 07:33:34.862498 2026] [security2:error] [pid 255769:tid 255994] [client 59.96.220.140:64702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9K_rxMYwyVGnfuwsKDgQAABAE"]
[Tue Jul 21 07:33:35.253036 2026] [security2:error] [pid 255769:tid 255953] [client 20.151.10.161:57441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/class-wp.php"] [unique_id "al9K_7xMYwyVGnfuwsKDiQAAA9k"]
[Tue Jul 21 07:33:35.410585 2026] [security2:error] [pid 255769:tid 255943] [client 74.248.121.109:2056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/0x.php"] [unique_id "al9K_7xMYwyVGnfuwsKDjAAAA88"]
[Tue Jul 21 07:33:35.425969 2026] [security2:error] [pid 254995:tid 254996] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K__7v0rlcEGmVraEpZQADHgA"]
[Tue Jul 21 07:33:35.426140 2026] [security2:error] [pid 254995:tid 255125] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K__7v0rlcEGmVraEpZQADHgA"]
[Tue Jul 21 07:33:35.481003 2026] [security2:error] [pid 254995:tid 254999] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9K__7v0rlcEGmVraEpZwADeQM"]
[Tue Jul 21 07:33:35.481152 2026] [security2:error] [pid 254995:tid 255217] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9K__7v0rlcEGmVraEpZwADeQM"]
[Tue Jul 21 07:33:35.522910 2026] [security2:error] [pid 255769:tid 255906] [client 20.197.195.24:13110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/cgi-bin/index.php"] [unique_id "al9K_7xMYwyVGnfuwsKDjwAAA6o"]
[Tue Jul 21 07:33:35.671311 2026] [security2:error] [pid 255769:tid 255845] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K_7xMYwyVGnfuwsKDkQAD20s"]
[Tue Jul 21 07:33:35.671453 2026] [security2:error] [pid 255769:tid 255955] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K_7xMYwyVGnfuwsKDkQAD20s"]
[Tue Jul 21 07:33:35.792919 2026] [security2:error] [pid 254995:tid 255195] [client 74.7.241.156:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "fernandadealencarluc1748790617000.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9K__7v0rlcEGmVraEpbAADZEA"]
[Tue Jul 21 07:33:35.808899 2026] [security2:error] [pid 254995:tid 255223] [client 139.167.225.182:49234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K__7v0rlcEGmVraEpbQAAA38"]
[Tue Jul 21 07:33:35.808996 2026] [security2:error] [pid 254995:tid 255223] [client 139.167.225.182:49234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K__7v0rlcEGmVraEpbQAAA38"]
[Tue Jul 21 07:33:35.977563 2026] [security2:error] [pid 255769:tid 255938] [client 20.220.225.223:19275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/aa1.php"] [unique_id "al9K_7xMYwyVGnfuwsKDtwAAA8o"]
[Tue Jul 21 07:33:36.092164 2026] [security2:error] [pid 255769:tid 256001] [client 20.151.10.161:50908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/admin.php"] [unique_id "al9LALxMYwyVGnfuwsKDuAAABAc"]
[Tue Jul 21 07:33:36.184858 2026] [security2:error] [pid 254995:tid 255154] [client 45.8.17.58:35511] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/oceanwp/content-index.php"] [unique_id "al9LAP7v0rlcEGmVraEpgQAAAzs"]
[Tue Jul 21 07:33:36.194838 2026] [security2:error] [pid 255769:tid 255996] [client 74.248.121.109:1062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/buy.php"] [unique_id "al9LALxMYwyVGnfuwsKD0AAABAI"]
[Tue Jul 21 07:33:36.302622 2026] [security2:error] [pid 254995:tid 255222] [client 47.128.29.176:55094] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "casaejardimperfeito.com.br"] [uri "/robots.txt"] [unique_id "al9LAP7v0rlcEGmVraEphwAAA34"]
[Tue Jul 21 07:33:36.491134 2026] [security2:error] [pid 255769:tid 255973] [client 20.206.105.145:38927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/test11.php"] [unique_id "al9LALxMYwyVGnfuwsKD0wAAA-0"]
[Tue Jul 21 07:33:36.566293 2026] [security2:error] [pid 254995:tid 255170] [client 74.7.230.16:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "divmax.com.br"] [uri "/index.php"] [unique_id "al9K__7v0rlcEGmVraEpYQAAA0s"]
[Tue Jul 21 07:33:36.567150 2026] [security2:error] [pid 255769:tid 255956] [client 74.7.230.16:46884] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "divmax.com.br"] [uri "/robots.txt"] [unique_id "al9K_7xMYwyVGnfuwsKDigAD3Ds"]
[Tue Jul 21 07:33:36.623868 2026] [security2:error] [pid 255769:tid 255958] [client 20.220.225.223:49794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/pn.php"] [unique_id "al9LALxMYwyVGnfuwsKD1QAAA94"]
[Tue Jul 21 07:33:36.711493 2026] [security2:error] [pid 255769:tid 255916] [client 152.59.154.239:64910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LALxMYwyVGnfuwsKD4QAAA7Q"]
[Tue Jul 21 07:33:36.711575 2026] [security2:error] [pid 255769:tid 255916] [client 152.59.154.239:64910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LALxMYwyVGnfuwsKD4QAAA7Q"]
[Tue Jul 21 07:33:36.745539 2026] [security2:error] [pid 254995:tid 255129] [client 20.151.10.161:57355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/aa2.php"] [unique_id "al9LAP7v0rlcEGmVraEplgAAAyI"]
[Tue Jul 21 07:33:36.930741 2026] [security2:error] [pid 254995:tid 255133] [client 103.162.129.114:62074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LAP7v0rlcEGmVraEpmAAAAyY"]
[Tue Jul 21 07:33:36.930888 2026] [security2:error] [pid 254995:tid 255133] [client 103.162.129.114:62074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LAP7v0rlcEGmVraEpmAAAAyY"]
[Tue Jul 21 07:33:37.026235 2026] [security2:error] [pid 255769:tid 255998] [client 117.251.86.144:49132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LAbxMYwyVGnfuwsKD8QAABAQ"]
[Tue Jul 21 07:33:37.026416 2026] [security2:error] [pid 255769:tid 255998] [client 117.251.86.144:49132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LAbxMYwyVGnfuwsKD8QAABAQ"]
[Tue Jul 21 07:33:37.213420 2026] [security2:error] [pid 255769:tid 255967] [client 74.248.121.109:2166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/sx.php"] [unique_id "al9LAbxMYwyVGnfuwsKD_AAAA-c"]
[Tue Jul 21 07:33:37.275803 2026] [security2:error] [pid 255769:tid 255990] [client 20.151.10.161:58065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/ccou.php"] [unique_id "al9LAbxMYwyVGnfuwsKD_wAAA_4"]
[Tue Jul 21 07:33:37.318555 2026] [autoindex:error] [pid 255769:tid 255968] [client 20.197.195.24:13108] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:37.343435 2026] [security2:error] [pid 255769:tid 255988] [client 20.197.195.24:13108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/BDKR28WP.php"] [unique_id "al9LAbxMYwyVGnfuwsKEAgAAA_w"]
[Tue Jul 21 07:33:37.413357 2026] [security2:error] [pid 255769:tid 256020] [client 20.220.225.223:49854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-wpbak.php"] [unique_id "al9LAbxMYwyVGnfuwsKEVwAABBo"]
[Tue Jul 21 07:33:37.497088 2026] [security2:error] [pid 255769:tid 256003] [client 45.8.17.118:39855] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/Divi/content-index.php"] [unique_id "al9LAbxMYwyVGnfuwsKEWgAABAk"]
[Tue Jul 21 07:33:37.543331 2026] [security2:error] [pid 255769:tid 255998] [client 20.220.225.223:19659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/acew67.php"] [unique_id "al9LAbxMYwyVGnfuwsKEWwAABAQ"]
[Tue Jul 21 07:33:37.789288 2026] [security2:error] [pid 255769:tid 255989] [client 20.151.10.161:50941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/dr.php"] [unique_id "al9LAbxMYwyVGnfuwsKEYAAAA_0"]
[Tue Jul 21 07:33:38.127783 2026] [security2:error] [pid 255769:tid 255952] [client 122.186.204.214:62175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LArxMYwyVGnfuwsKEZgAAA9g"]
[Tue Jul 21 07:33:38.127911 2026] [security2:error] [pid 255769:tid 255952] [client 122.186.204.214:62175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LArxMYwyVGnfuwsKEZgAAA9g"]
[Tue Jul 21 07:33:38.133135 2026] [security2:error] [pid 254995:tid 255257] [client 193.36.225.55:26227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LAv7v0rlcEGmVraEpxwAAA4c"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:38.250447 2026] [security2:error] [pid 255769:tid 255966] [client 20.220.225.223:49811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/old.php"] [unique_id "al9LArxMYwyVGnfuwsKEZwAAA-Y"]
[Tue Jul 21 07:33:38.299400 2026] [security2:error] [pid 254995:tid 255170] [client 20.220.225.223:38701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/mac.php"] [unique_id "al9LAv7v0rlcEGmVraEpzgAAA0s"]
[Tue Jul 21 07:33:38.335058 2026] [security2:error] [pid 254995:tid 255177] [client 20.151.10.161:51272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/xamp.php"] [unique_id "al9LAv7v0rlcEGmVraEpzwAAA1I"]
[Tue Jul 21 07:33:38.489295 2026] [security2:error] [pid 255769:tid 255903] [client 74.248.121.109:2165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/article.php"] [unique_id "al9LArxMYwyVGnfuwsKEaQAAA6c"]
[Tue Jul 21 07:33:38.548123 2026] [autoindex:error] [pid 255769:tid 256001] [client 20.197.195.24:48870] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:38.567387 2026] [autoindex:error] [pid 255769:tid 255924] [client 20.197.195.24:48870] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:38.572915 2026] [security2:error] [pid 255769:tid 256020] [client 20.197.195.24:48870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/abcd.php"] [unique_id "al9LArxMYwyVGnfuwsKEbwAABBo"]
[Tue Jul 21 07:33:38.721419 2026] [security2:error] [pid 254995:tid 255213] [client 20.52.136.55:1591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/date.php"] [unique_id "al9LAv7v0rlcEGmVraEp2AAAA3U"]
[Tue Jul 21 07:33:38.731230 2026] [security2:error] [pid 254995:tid 255204] [client 82.102.28.107:37168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9LAv7v0rlcEGmVraEp2QAAA20"]
[Tue Jul 21 07:33:38.731316 2026] [security2:error] [pid 254995:tid 255204] [client 82.102.28.107:37168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9LAv7v0rlcEGmVraEp2QAAA20"]
[Tue Jul 21 07:33:38.753865 2026] [security2:error] [pid 255769:tid 255986] [client 173.24.185.52:61249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LArxMYwyVGnfuwsKEeQAAA_o"]
[Tue Jul 21 07:33:38.753974 2026] [security2:error] [pid 255769:tid 255986] [client 173.24.185.52:61249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LArxMYwyVGnfuwsKEeQAAA_o"]
[Tue Jul 21 07:33:38.788924 2026] [security2:error] [pid 255769:tid 256025] [client 45.8.17.123:53309] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/exnova/content-index.php"] [unique_id "al9LArxMYwyVGnfuwsKEfQAABB8"]
[Tue Jul 21 07:33:38.878959 2026] [security2:error] [pid 255769:tid 255926] [client 20.151.10.161:57406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/bless.php"] [unique_id "al9LArxMYwyVGnfuwsKEfwAAA74"]
[Tue Jul 21 07:33:38.905394 2026] [security2:error] [pid 254995:tid 255199] [client 122.162.144.145:29947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LAv7v0rlcEGmVraEp4AAAA2g"]
[Tue Jul 21 07:33:38.905501 2026] [security2:error] [pid 254995:tid 255199] [client 122.162.144.145:29947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LAv7v0rlcEGmVraEp4AAAA2g"]
[Tue Jul 21 07:33:39.039790 2026] [security2:error] [pid 255769:tid 256006] [client 20.206.105.145:38966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/koala.php"] [unique_id "al9LA7xMYwyVGnfuwsKEhAAABAw"]
[Tue Jul 21 07:33:39.158477 2026] [security2:error] [pid 255769:tid 255808] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LA7xMYwyVGnfuwsKEhwAD2yY"]
[Tue Jul 21 07:33:39.158608 2026] [security2:error] [pid 255769:tid 255955] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LA7xMYwyVGnfuwsKEhwAD2yY"]
[Tue Jul 21 07:33:39.247863 2026] [security2:error] [pid 255769:tid 255923] [client 20.151.10.161:58037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/file46.php"] [unique_id "al9LA7xMYwyVGnfuwsKEiAAAA7s"]
[Tue Jul 21 07:33:39.334905 2026] [security2:error] [pid 254995:tid 255223] [client 74.248.121.109:2068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/bootstrap.php"] [unique_id "al9LA_7v0rlcEGmVraEp5gAAA38"]
[Tue Jul 21 07:33:39.361358 2026] [security2:error] [pid 255769:tid 255899] [client 20.220.225.223:4217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/bscclapb.php"] [unique_id "al9LA7xMYwyVGnfuwsKEiwAAA6M"]
[Tue Jul 21 07:33:39.519372 2026] [security2:error] [pid 254995:tid 255224] [client 20.220.225.223:6107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/billur.php"] [unique_id "al9LA_7v0rlcEGmVraEp6gAAA4A"]
[Tue Jul 21 07:33:39.634806 2026] [security2:error] [pid 254995:tid 255073] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LA_7v0rlcEGmVraEp7wADWU0"]
[Tue Jul 21 07:33:39.635004 2026] [security2:error] [pid 254995:tid 255184] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LA_7v0rlcEGmVraEp7wADWU0"]
[Tue Jul 21 07:33:39.664075 2026] [security2:error] [pid 254995:tid 255176] [client 103.106.20.201:55039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LA_7v0rlcEGmVraEp8AAAA1E"]
[Tue Jul 21 07:33:39.665730 2026] [security2:error] [pid 254995:tid 255176] [client 103.106.20.201:55039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LA_7v0rlcEGmVraEp8AAAA1E"]
[Tue Jul 21 07:33:39.667230 2026] [security2:error] [pid 254995:tid 255218] [client 20.197.195.24:13137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/file15.php"] [unique_id "al9LA_7v0rlcEGmVraEp8QAAA3o"]
[Tue Jul 21 07:33:39.883679 2026] [security2:error] [pid 255769:tid 255930] [client 45.251.232.145:53387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LA7xMYwyVGnfuwsKEkQAAA8I"]
[Tue Jul 21 07:33:39.883853 2026] [security2:error] [pid 255769:tid 255930] [client 45.251.232.145:53387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LA7xMYwyVGnfuwsKEkQAAA8I"]
[Tue Jul 21 07:33:39.894228 2026] [security2:error] [pid 254995:tid 255181] [client 20.151.10.161:58627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/eee.php"] [unique_id "al9LA_7v0rlcEGmVraEp9gAAA1Y"]
[Tue Jul 21 07:33:39.951214 2026] [security2:error] [pid 254995:tid 255173] [client 20.220.225.223:24193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/blue.php"] [unique_id "al9LA_7v0rlcEGmVraEp9wAAA04"]
[Tue Jul 21 07:33:39.986326 2026] [security2:error] [pid 254995:tid 255156] [client 45.8.17.128:35119] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/specia/content-index.php"] [unique_id "al9LA_7v0rlcEGmVraEp-QAAAz0"]
[Tue Jul 21 07:33:40.297078 2026] [security2:error] [pid 254995:tid 255229] [client 74.248.121.109:2081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/config-backup.php"] [unique_id "al9LBP7v0rlcEGmVraEqAAAAA4I"]
[Tue Jul 21 07:33:40.301726 2026] [security2:error] [pid 255769:tid 255985] [client 20.151.10.161:57998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/file25.php"] [unique_id "al9LBLxMYwyVGnfuwsKEkgAAA_k"]
[Tue Jul 21 07:33:40.484939 2026] [security2:error] [pid 254995:tid 255220] [client 154.192.233.199:60071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LBP7v0rlcEGmVraEqAwAAA3w"]
[Tue Jul 21 07:33:40.485102 2026] [security2:error] [pid 254995:tid 255220] [client 154.192.233.199:60071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LBP7v0rlcEGmVraEqAwAAA3w"]
[Tue Jul 21 07:33:41.000686 2026] [security2:error] [pid 254995:tid 255183] [client 74.248.121.109:2114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/goods.php"] [unique_id "al9LBP7v0rlcEGmVraEqEgAAA1g"]
[Tue Jul 21 07:33:41.099394 2026] [security2:error] [pid 255769:tid 256010] [client 109.248.148.246:55524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LBbxMYwyVGnfuwsKEnAAABBA"]
[Tue Jul 21 07:33:41.099486 2026] [security2:error] [pid 255769:tid 256010] [client 109.248.148.246:55524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LBbxMYwyVGnfuwsKEnAAABBA"]
[Tue Jul 21 07:33:41.187269 2026] [security2:error] [pid 255769:tid 256021] [client 45.8.17.62:63391] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/wordpress-seo/index.php"] [unique_id "al9LBbxMYwyVGnfuwsKEnwAABBs"]
[Tue Jul 21 07:33:41.273020 2026] [security2:error] [pid 255769:tid 256018] [client 117.217.38.194:57996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LBbxMYwyVGnfuwsKEoQAABBg"]
[Tue Jul 21 07:33:41.273145 2026] [security2:error] [pid 255769:tid 256018] [client 117.217.38.194:57996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LBbxMYwyVGnfuwsKEoQAABBg"]
[Tue Jul 21 07:33:41.284618 2026] [security2:error] [pid 255769:tid 255987] [client 20.151.10.161:51285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/file48.php"] [unique_id "al9LBbxMYwyVGnfuwsKEogAAA_s"]
[Tue Jul 21 07:33:41.450243 2026] [security2:error] [pid 254995:tid 255264] [client 74.7.175.172:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "taliafernandavidi1782074982000.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9LBf7v0rlcEGmVraEqGQADjnE"]
[Tue Jul 21 07:33:41.457219 2026] [security2:error] [pid 254995:tid 255265] [client 175.45.70.82:56142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LBf7v0rlcEGmVraEqGgAAA48"]
[Tue Jul 21 07:33:41.457336 2026] [security2:error] [pid 254995:tid 255265] [client 175.45.70.82:56142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LBf7v0rlcEGmVraEqGgAAA48"]
[Tue Jul 21 07:33:41.519849 2026] [security2:error] [pid 254995:tid 255159] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LBf7v0rlcEGmVraEqGwADQGw"]
[Tue Jul 21 07:33:41.527600 2026] [security2:error] [pid 254995:tid 255136] [client 74.248.121.109:2171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/init.php"] [unique_id "al9LBf7v0rlcEGmVraEqHAAAAyk"]
[Tue Jul 21 07:33:41.670595 2026] [security2:error] [pid 255769:tid 255974] [client 37.140.223.118:39935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LBbxMYwyVGnfuwsKEowAAA-4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:33:41.755506 2026] [security2:error] [pid 254995:tid 255135] [client 20.151.10.161:50887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/file6.php"] [unique_id "al9LBf7v0rlcEGmVraEqIAAAAyg"]
[Tue Jul 21 07:33:41.764960 2026] [security2:error] [pid 254995:tid 255160] [client 20.220.225.223:49580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/ms-new.php"] [unique_id "al9LBf7v0rlcEGmVraEqIQAAA0E"]
[Tue Jul 21 07:33:41.918153 2026] [security2:error] [pid 255769:tid 255989] [client 20.220.225.223:6098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/mimpi.php"] [unique_id "al9LBbxMYwyVGnfuwsKErAAAA_0"]
[Tue Jul 21 07:33:42.071758 2026] [security2:error] [pid 255769:tid 255988] [client 20.52.136.55:1584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/pomo.php"] [unique_id "al9LBrxMYwyVGnfuwsKEuAAAA_w"]
[Tue Jul 21 07:33:42.125082 2026] [security2:error] [pid 255769:tid 255899] [client 20.220.225.223:56496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/else1.php"] [unique_id "al9LBrxMYwyVGnfuwsKEuQAAA6M"]
[Tue Jul 21 07:33:42.181762 2026] [security2:error] [pid 255769:tid 255996] [client 20.151.10.161:57448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/a2.php"] [unique_id "al9LBrxMYwyVGnfuwsKEuwAABAI"]
[Tue Jul 21 07:33:42.215114 2026] [security2:error] [pid 255769:tid 255980] [client 20.197.195.24:48846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/jp.php"] [unique_id "al9LBrxMYwyVGnfuwsKEwQAAA_Q"]
[Tue Jul 21 07:33:42.318538 2026] [security2:error] [pid 255769:tid 255820] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LBrxMYwyVGnfuwsKEzQAD2DI"]
[Tue Jul 21 07:33:42.318686 2026] [security2:error] [pid 255769:tid 255952] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LBrxMYwyVGnfuwsKEzQAD2DI"]
[Tue Jul 21 07:33:42.353831 2026] [security2:error] [pid 255769:tid 255906] [client 103.174.34.15:64771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LBrxMYwyVGnfuwsKEzgAAA6o"]
[Tue Jul 21 07:33:42.353949 2026] [security2:error] [pid 255769:tid 255906] [client 103.174.34.15:64771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LBrxMYwyVGnfuwsKEzgAAA6o"]
[Tue Jul 21 07:33:42.383315 2026] [security2:error] [pid 255769:tid 255958] [client 193.36.225.71:24999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LBrxMYwyVGnfuwsKEwAAAA94"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:42.401148 2026] [security2:error] [pid 255769:tid 255854] [remote 154.61.75.100:51118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9LBrxMYwyVGnfuwsKE0AADs1Q"]
[Tue Jul 21 07:33:42.431458 2026] [security2:error] [pid 255769:tid 255902] [client 20.206.105.145:38957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/mac.php"] [unique_id "al9LBrxMYwyVGnfuwsKE1QAAA6Y"]
[Tue Jul 21 07:33:42.460366 2026] [authz_core:error] [pid 255769:tid 255910] [client 74.248.121.109:2137] AH01630: client denied by server configuration: /home2/issima95/issimastore.com/php.ini
[Tue Jul 21 07:33:42.489572 2026] [security2:error] [pid 255769:tid 256000] [client 20.151.10.161:57385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/file15.php"] [unique_id "al9LBrxMYwyVGnfuwsKE3gAABAY"]
[Tue Jul 21 07:33:42.599515 2026] [security2:error] [pid 255769:tid 255986] [client 45.8.17.113:24377] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/css/eroor.php"] [unique_id "al9LBrxMYwyVGnfuwsKE3wAAA_o"]
[Tue Jul 21 07:33:42.671658 2026] [security2:error] [pid 255769:tid 255997] [client 74.248.121.109:2137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/settings.php"] [unique_id "al9LBrxMYwyVGnfuwsKE6AAABAM"]
[Tue Jul 21 07:33:42.894544 2026] [security2:error] [pid 255769:tid 255950] [client 20.151.10.161:57396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/jp.php"] [unique_id "al9LBrxMYwyVGnfuwsKE6gAAA9Y"]
[Tue Jul 21 07:33:43.170131 2026] [security2:error] [pid 255769:tid 255880] [remote 51.68.111.209:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "githec.com"] [uri "/robots.txt"] [unique_id "al9LB7xMYwyVGnfuwsKE6wADvm4"]
[Tue Jul 21 07:33:43.170276 2026] [security2:error] [pid 255769:tid 255926] [client 51.68.111.209:0] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "githec.com"] [uri "/robots.txt"] [unique_id "al9LB7xMYwyVGnfuwsKE6wADvm4"]
[Tue Jul 21 07:33:43.283810 2026] [security2:error] [pid 255769:tid 255918] [client 74.248.121.109:2080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/g.php"] [unique_id "al9LB7xMYwyVGnfuwsKE7gAAA7Y"]
[Tue Jul 21 07:33:43.290877 2026] [security2:error] [pid 255769:tid 255983] [client 20.220.225.223:31191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/samll.php"] [unique_id "al9LB7xMYwyVGnfuwsKE7wAAA_c"]
[Tue Jul 21 07:33:43.338779 2026] [security2:error] [pid 255769:tid 255879] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LB7xMYwyVGnfuwsKE8AAEC20"]
[Tue Jul 21 07:33:43.338943 2026] [security2:error] [pid 255769:tid 256005] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LB7xMYwyVGnfuwsKE8AAEC20"]
[Tue Jul 21 07:33:43.513102 2026] [security2:error] [pid 255769:tid 255943] [client 20.151.10.161:57345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/f35.php"] [unique_id "al9LB7xMYwyVGnfuwsKE9AAAA88"]
[Tue Jul 21 07:33:43.562969 2026] [security2:error] [pid 255769:tid 255955] [client 20.10.88.201:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "digital-universo.com"] [uri "/index.php"] [unique_id "al9LB7xMYwyVGnfuwsKE8wAD2w8"]
[Tue Jul 21 07:33:43.836731 2026] [security2:error] [pid 255769:tid 256015] [client 20.220.225.223:48131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/track.php"] [unique_id "al9LB7xMYwyVGnfuwsKE_QAABBU"]
[Tue Jul 21 07:33:43.888476 2026] [security2:error] [pid 255769:tid 255953] [client 74.248.121.109:1048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/403.php"] [unique_id "al9LB7xMYwyVGnfuwsKE_gAAA9k"]
[Tue Jul 21 07:33:43.963277 2026] [security2:error] [pid 254995:tid 255098] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9LB_7v0rlcEGmVraEqPwADQmY"]
[Tue Jul 21 07:33:43.979338 2026] [security2:error] [pid 254995:tid 255150] [client 20.220.225.223:24194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/wp-signup.php"] [unique_id "al9LB_7v0rlcEGmVraEqQgAAAzc"]
[Tue Jul 21 07:33:43.986380 2026] [security2:error] [pid 254995:tid 255127] [client 45.8.17.110:48343] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/languages/themes/home.php"] [unique_id "al9LB_7v0rlcEGmVraEqQwAAAyA"]
[Tue Jul 21 07:33:43.994810 2026] [security2:error] [pid 255769:tid 255931] [client 20.220.225.223:23428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/dp.php"] [unique_id "al9LB7xMYwyVGnfuwsKFAAAAA8M"]
[Tue Jul 21 07:33:44.185672 2026] [security2:error] [pid 255769:tid 255952] [client 20.151.10.161:57993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-load.php"] [unique_id "al9LCLxMYwyVGnfuwsKFAQAAA9g"]
[Tue Jul 21 07:33:44.272341 2026] [security2:error] [pid 255769:tid 255915] [client 216.244.66.229:54006] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "megaroteiros.com.br"] [uri "/wp-content/uploads/2015/07/tam.png"] [unique_id "al9LCLxMYwyVGnfuwsKFBQAAA7M"]
[Tue Jul 21 07:33:44.272468 2026] [security2:error] [pid 255769:tid 255915] [client 216.244.66.229:54006] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "megaroteiros.com.br"] [uri "/wp-content/uploads/2015/07/tam.png"] [unique_id "al9LCLxMYwyVGnfuwsKFBQAAA7M"]
[Tue Jul 21 07:33:44.303970 2026] [security2:error] [pid 255769:tid 255847] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LCLxMYwyVGnfuwsKFBgAD-E0"]
[Tue Jul 21 07:33:44.304120 2026] [security2:error] [pid 255769:tid 255984] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LCLxMYwyVGnfuwsKFBgAD-E0"]
[Tue Jul 21 07:33:44.342136 2026] [security2:error] [pid 255769:tid 256004] [client 180.153.236.67:51211] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.treeoflifehealth.online"] [uri "/"] [unique_id "al9LCLxMYwyVGnfuwsKFCAAABAo"], referer: http://www.treeoflifehealth.online/
[Tue Jul 21 07:33:44.342244 2026] [security2:error] [pid 255769:tid 256004] [client 180.153.236.67:51211] ModSecurity: Warning. Matched phrase "360Spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.treeoflifehealth.online"] [uri "/"] [unique_id "al9LCLxMYwyVGnfuwsKFCAAABAo"], referer: http://www.treeoflifehealth.online/
[Tue Jul 21 07:33:44.411389 2026] [security2:error] [pid 255769:tid 255957] [client 74.248.121.109:2066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/api.php"] [unique_id "al9LCLxMYwyVGnfuwsKFCgAAA90"]
[Tue Jul 21 07:33:44.502214 2026] [security2:error] [pid 254995:tid 255136] [client 20.151.10.161:57466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/xwpg.php"] [unique_id "al9LCP7v0rlcEGmVraEqUQAAAyk"]
[Tue Jul 21 07:33:44.653763 2026] [security2:error] [pid 255769:tid 256010] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9LCLxMYwyVGnfuwsKFDgAABBA"]
[Tue Jul 21 07:33:44.771752 2026] [security2:error] [pid 255769:tid 256018] [client 122.129.67.13:59594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9LB7xMYwyVGnfuwsKE8QAABBg"]
[Tue Jul 21 07:33:44.895821 2026] [proxy:error] [pid 254995:tid 255224] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:44.895899 2026] [proxy_http:error] [pid 254995:tid 255224] [client 20.151.10.161:57458] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:44.896551 2026] [proxy:error] [pid 254995:tid 255224] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:44.896587 2026] [proxy_http:error] [pid 254995:tid 255224] [client 20.151.10.161:57458] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:44.937146 2026] [security2:error] [pid 254995:tid 254996] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9LCP7v0rlcEGmVraEqVwADQQA"]
[Tue Jul 21 07:33:44.977313 2026] [security2:error] [pid 254995:tid 255028] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/media.php"] [unique_id "al9LCP7v0rlcEGmVraEqWAADLyA"]
[Tue Jul 21 07:33:45.007098 2026] [security2:error] [pid 254995:tid 255045] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/images.php"] [unique_id "al9LCf7v0rlcEGmVraEqWQADKjE"]
[Tue Jul 21 07:33:45.022732 2026] [security2:error] [pid 254995:tid 254999] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/gecko.php"] [unique_id "al9LCf7v0rlcEGmVraEqWgADWQM"]
[Tue Jul 21 07:33:45.093170 2026] [security2:error] [pid 254995:tid 255217] [client 85.204.70.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LCP7v0rlcEGmVraEqVgAAA3k"]
[Tue Jul 21 07:33:45.146491 2026] [security2:error] [pid 254995:tid 255274] [client 20.220.225.223:31202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/abcd.php"] [unique_id "al9LCf7v0rlcEGmVraEqXwAAA5g"]
[Tue Jul 21 07:33:45.161020 2026] [security2:error] [pid 255769:tid 255912] [client 213.152.162.104:52174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9LCbxMYwyVGnfuwsKFFAAAA7A"]
[Tue Jul 21 07:33:45.161137 2026] [security2:error] [pid 255769:tid 255912] [client 213.152.162.104:52174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9LCbxMYwyVGnfuwsKFFAAAA7A"]
[Tue Jul 21 07:33:45.285605 2026] [proxy:error] [pid 255769:tid 255998] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:45.285693 2026] [proxy_http:error] [pid 255769:tid 255998] [client 20.151.10.161:58000] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:45.286588 2026] [proxy:error] [pid 255769:tid 255998] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:45.286631 2026] [proxy_http:error] [pid 255769:tid 255998] [client 20.151.10.161:58000] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:45.377688 2026] [security2:error] [pid 255769:tid 255993] [client 45.8.17.130:58089] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/languages/plugins/options.php"] [unique_id "al9LCbxMYwyVGnfuwsKFGAAABAA"]
[Tue Jul 21 07:33:45.410719 2026] [autoindex:error] [pid 254995:tid 255141] [client 198.235.24.72:60142] AH01276: Cannot serve directory /home2/cla35313/olhobionico.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:45.418691 2026] [security2:error] [pid 255769:tid 255948] [client 59.96.220.140:65187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LCbxMYwyVGnfuwsKFGgAAA9Q"]
[Tue Jul 21 07:33:45.419291 2026] [security2:error] [pid 255769:tid 255948] [client 59.96.220.140:65187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LCbxMYwyVGnfuwsKFGgAAA9Q"]
[Tue Jul 21 07:33:45.509622 2026] [security2:error] [pid 254995:tid 255268] [client 37.140.223.190:45457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LCP7v0rlcEGmVraEqSgAAA5I"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:33:45.534440 2026] [security2:error] [pid 255769:tid 255967] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9LCbxMYwyVGnfuwsKFHwAAA-c"]
[Tue Jul 21 07:33:45.659608 2026] [security2:error] [pid 255769:tid 256005] [client 20.151.10.161:51327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/waf.php"] [unique_id "al9LCbxMYwyVGnfuwsKFIAAABAs"]
[Tue Jul 21 07:33:45.693250 2026] [security2:error] [pid 255769:tid 255960] [client 20.197.195.24:13156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/f35.php"] [unique_id "al9LCbxMYwyVGnfuwsKFIQAAA-A"]
[Tue Jul 21 07:33:45.741258 2026] [security2:error] [pid 255769:tid 255939] [client 74.7.228.40:48792] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ewfconstrucao.com.br"] [uri "/index.php"] [unique_id "al9LCLxMYwyVGnfuwsKFDAADy0k"]
[Tue Jul 21 07:33:45.808095 2026] [security2:error] [pid 254995:tid 255189] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9LCf7v0rlcEGmVraEqZwAAA14"]
[Tue Jul 21 07:33:45.896266 2026] [security2:error] [pid 254995:tid 255006] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LCf7v0rlcEGmVraEqaQADNgo"]
[Tue Jul 21 07:33:45.896390 2026] [security2:error] [pid 254995:tid 255149] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LCf7v0rlcEGmVraEqaQADNgo"]
[Tue Jul 21 07:33:45.930312 2026] [security2:error] [pid 255769:tid 255899] [client 20.220.225.223:19654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/bscclapb.php"] [unique_id "al9LCbxMYwyVGnfuwsKFJAAAA6M"]
[Tue Jul 21 07:33:45.944031 2026] [security2:error] [pid 254995:tid 255038] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/82.php"] [unique_id "al9LCf7v0rlcEGmVraEqagADhyo"]
[Tue Jul 21 07:33:45.978107 2026] [security2:error] [pid 254995:tid 255044] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/admin.php"] [unique_id "al9LCf7v0rlcEGmVraEqbAADkDA"]
[Tue Jul 21 07:33:46.005529 2026] [security2:error] [pid 254995:tid 255012] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/adminner.php"] [unique_id "al9LCv7v0rlcEGmVraEqbQADORA"]
[Tue Jul 21 07:33:46.015331 2026] [security2:error] [pid 254995:tid 255017] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LCv7v0rlcEGmVraEqbwADZxU"]
[Tue Jul 21 07:33:46.015550 2026] [security2:error] [pid 254995:tid 255198] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LCv7v0rlcEGmVraEqbwADZxU"]
[Tue Jul 21 07:33:46.019491 2026] [security2:error] [pid 255769:tid 255908] [client 20.151.10.161:57391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/xstelth.php"] [unique_id "al9LCrxMYwyVGnfuwsKFJgAAA6w"]
[Tue Jul 21 07:33:46.081447 2026] [security2:error] [pid 255769:tid 256016] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9LCrxMYwyVGnfuwsKFKAAABBY"]
[Tue Jul 21 07:33:46.174753 2026] [security2:error] [pid 255769:tid 255980] [client 20.220.225.223:49556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/2352356666.php"] [unique_id "al9LCrxMYwyVGnfuwsKFKQAAA_Q"]
[Tue Jul 21 07:33:46.190685 2026] [security2:error] [pid 255769:tid 255852] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LCrxMYwyVGnfuwsKFKgAD21I"]
[Tue Jul 21 07:33:46.190852 2026] [security2:error] [pid 255769:tid 255955] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LCrxMYwyVGnfuwsKFKgAD21I"]
[Tue Jul 21 07:33:46.206620 2026] [security2:error] [pid 255769:tid 255953] [client 20.220.225.223:49796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/dr.php"] [unique_id "al9LCrxMYwyVGnfuwsKFLQAAA9k"]
[Tue Jul 21 07:33:46.355880 2026] [security2:error] [pid 255769:tid 255973] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9LCrxMYwyVGnfuwsKFLwAAA-0"]
[Tue Jul 21 07:33:46.364774 2026] [security2:error] [pid 255769:tid 256001] [client 20.151.10.161:58009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-links.php"] [unique_id "al9LCrxMYwyVGnfuwsKFMQAABAc"]
[Tue Jul 21 07:33:46.381053 2026] [security2:error] [pid 254995:tid 255173] [client 139.167.225.182:49864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LCv7v0rlcEGmVraEqcgAAA04"]
[Tue Jul 21 07:33:46.381155 2026] [security2:error] [pid 254995:tid 255173] [client 139.167.225.182:49864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LCv7v0rlcEGmVraEqcgAAA04"]
[Tue Jul 21 07:33:46.541800 2026] [security2:error] [pid 254995:tid 255014] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/admin.php"] [unique_id "al9LCv7v0rlcEGmVraEqdgADdBI"]
[Tue Jul 21 07:33:46.608005 2026] [security2:error] [pid 254995:tid 255024] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/k.php"] [unique_id "al9LCv7v0rlcEGmVraEqeQADQhw"]
[Tue Jul 21 07:33:46.624141 2026] [security2:error] [pid 254995:tid 255091] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/blurbs.php"] [unique_id "al9LCv7v0rlcEGmVraEqegADJl8"]
[Tue Jul 21 07:33:46.629717 2026] [security2:error] [pid 255769:tid 255927] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9LCrxMYwyVGnfuwsKFNgAAA78"]
[Tue Jul 21 07:33:46.672138 2026] [security2:error] [pid 254995:tid 255172] [client 20.151.10.161:51286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9LCv7v0rlcEGmVraEqewAAA00"]
[Tue Jul 21 07:33:46.681127 2026] [security2:error] [pid 255769:tid 255906] [client 45.8.17.144:34581] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/tinymce/themes/panel.php"] [unique_id "al9LCrxMYwyVGnfuwsKFNwAAA6o"]
[Tue Jul 21 07:33:46.697863 2026] [security2:error] [pid 254995:tid 255055] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/bajah.php"] [unique_id "al9LCv7v0rlcEGmVraEqfAADXTs"]
[Tue Jul 21 07:33:46.714418 2026] [security2:error] [pid 254995:tid 255051] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/a.php"] [unique_id "al9LCv7v0rlcEGmVraEqfQADPDc"]
[Tue Jul 21 07:33:46.738472 2026] [security2:error] [pid 254995:tid 255015] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/edit.php"] [unique_id "al9LCv7v0rlcEGmVraEqfgADlBM"]
[Tue Jul 21 07:33:46.754856 2026] [security2:error] [pid 254995:tid 255048] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/hosty.php"] [unique_id "al9LCv7v0rlcEGmVraEqfwADPjQ"]
[Tue Jul 21 07:33:46.772274 2026] [security2:error] [pid 254995:tid 255119] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/k.php"] [unique_id "al9LCv7v0rlcEGmVraEqgAADmXs"]
[Tue Jul 21 07:33:46.787646 2026] [security2:error] [pid 254995:tid 255056] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/aaa.php"] [unique_id "al9LCv7v0rlcEGmVraEqgQADXzw"]
[Tue Jul 21 07:33:46.828265 2026] [security2:error] [pid 254995:tid 255064] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/file5.php"] [unique_id "al9LCv7v0rlcEGmVraEqggADbUQ"]
[Tue Jul 21 07:33:46.856799 2026] [security2:error] [pid 254995:tid 255072] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/222.php"] [unique_id "al9LCv7v0rlcEGmVraEqgwADNUw"]
[Tue Jul 21 07:33:46.902765 2026] [security2:error] [pid 255769:tid 255900] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9LCrxMYwyVGnfuwsKFOwAAA6Q"]
[Tue Jul 21 07:33:46.909798 2026] [security2:error] [pid 255769:tid 255811] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/test.php"] [unique_id "al9LCrxMYwyVGnfuwsKFPAAEGyk"]
[Tue Jul 21 07:33:46.942985 2026] [security2:error] [pid 254995:tid 255070] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/aaa.php"] [unique_id "al9LCv7v0rlcEGmVraEqhgADcEo"]
[Tue Jul 21 07:33:46.982680 2026] [security2:error] [pid 254995:tid 255068] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/11.php"] [unique_id "al9LCv7v0rlcEGmVraEqhwADSkg"]
[Tue Jul 21 07:33:47.002797 2026] [security2:error] [pid 254995:tid 255065] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/mac.php"] [unique_id "al9LC_7v0rlcEGmVraEqiAADaEU"]
[Tue Jul 21 07:33:47.009627 2026] [security2:error] [pid 254995:tid 255278] [client 20.151.10.161:57366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/aaa.php"] [unique_id "al9LC_7v0rlcEGmVraEqiQAAA5w"]
[Tue Jul 21 07:33:47.176260 2026] [security2:error] [pid 255769:tid 255916] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9LC7xMYwyVGnfuwsKFPgAAA7Q"]
[Tue Jul 21 07:33:47.249810 2026] [security2:error] [pid 254995:tid 255151] [client 20.220.225.223:19972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/else1.php"] [unique_id "al9LC_7v0rlcEGmVraEqjgAAAzg"]
[Tue Jul 21 07:33:47.255539 2026] [security2:error] [pid 254995:tid 255185] [client 103.162.129.114:62507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LC_7v0rlcEGmVraEqjwAAA1o"]
[Tue Jul 21 07:33:47.255656 2026] [security2:error] [pid 254995:tid 255185] [client 103.162.129.114:62507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LC_7v0rlcEGmVraEqjwAAA1o"]
[Tue Jul 21 07:33:47.294999 2026] [security2:error] [pid 254995:tid 255215] [client 172.245.102.41:23197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LC_7v0rlcEGmVraEqkAAAA3c"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:47.448598 2026] [security2:error] [pid 255769:tid 255971] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9LC7xMYwyVGnfuwsKFRAAAA-s"]
[Tue Jul 21 07:33:47.452354 2026] [security2:error] [pid 255769:tid 255967] [client 109.248.148.246:38406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9LC7xMYwyVGnfuwsKFRQAAA-c"]
[Tue Jul 21 07:33:47.452423 2026] [security2:error] [pid 255769:tid 255967] [client 109.248.148.246:38406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9LC7xMYwyVGnfuwsKFRQAAA-c"]
[Tue Jul 21 07:33:47.489208 2026] [security2:error] [pid 255769:tid 255977] [client 20.220.225.223:49799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/2x.php"] [unique_id "al9LC7xMYwyVGnfuwsKFSgAAA_E"]
[Tue Jul 21 07:33:47.550314 2026] [security2:error] [pid 255769:tid 255960] [client 20.220.225.223:49828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/pn.php"] [unique_id "al9LC7xMYwyVGnfuwsKFTAAAA-A"]
[Tue Jul 21 07:33:47.589770 2026] [security2:error] [pid 254995:tid 255071] [remote 160.187.68.132:45396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/wp-login.php"] [unique_id "al9LC_7v0rlcEGmVraEqlAADm0s"]
[Tue Jul 21 07:33:47.654217 2026] [security2:error] [pid 255769:tid 255908] [client 20.220.225.223:31173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/xyn.php"] [unique_id "al9LC7xMYwyVGnfuwsKFUgAAA6w"]
[Tue Jul 21 07:33:47.655720 2026] [security2:error] [pid 255769:tid 255986] [client 117.251.86.144:34536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LC7xMYwyVGnfuwsKFUQAAA_o"]
[Tue Jul 21 07:33:47.655807 2026] [security2:error] [pid 255769:tid 255986] [client 117.251.86.144:34536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LC7xMYwyVGnfuwsKFUQAAA_o"]
[Tue Jul 21 07:33:47.672928 2026] [security2:error] [pid 255769:tid 255963] [client 20.197.195.24:13060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp-load.php"] [unique_id "al9LC7xMYwyVGnfuwsKFUwAAA-M"]
[Tue Jul 21 07:33:47.723375 2026] [security2:error] [pid 255769:tid 255980] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9LC7xMYwyVGnfuwsKFVAAAA_Q"]
[Tue Jul 21 07:33:47.773719 2026] [security2:error] [pid 255769:tid 255988] [client 173.252.95.58:49248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LC7xMYwyVGnfuwsKFVwAAA_w"]
[Tue Jul 21 07:33:47.864339 2026] [security2:error] [pid 254995:tid 255033] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/chosen.php"] [unique_id "al9LC_7v0rlcEGmVraEqmAADUyU"]
[Tue Jul 21 07:33:47.881060 2026] [security2:error] [pid 254995:tid 255052] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/cream1.php"] [unique_id "al9LC_7v0rlcEGmVraEqmQADgDg"]
[Tue Jul 21 07:33:47.909995 2026] [autoindex:error] [pid 254995:tid 255059] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:47.938293 2026] [autoindex:error] [pid 254995:tid 255076] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:47.985230 2026] [security2:error] [pid 254995:tid 255079] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/dr.php"] [unique_id "al9LC_7v0rlcEGmVraEqnQADQVM"]
[Tue Jul 21 07:33:47.996380 2026] [security2:error] [pid 255769:tid 255950] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9LC7xMYwyVGnfuwsKFXAAAA9Y"]
[Tue Jul 21 07:33:48.002140 2026] [security2:error] [pid 254995:tid 255118] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/x.php"] [unique_id "al9LDP7v0rlcEGmVraEqngADL3o"]
[Tue Jul 21 07:33:48.086294 2026] [security2:error] [pid 255769:tid 255985] [client 45.8.17.116:31969] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Requests/Response/Response/multisite-setup.php"] [unique_id "al9LDLxMYwyVGnfuwsKFXgAAA_k"]
[Tue Jul 21 07:33:48.270463 2026] [security2:error] [pid 255769:tid 256004] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9LDLxMYwyVGnfuwsKFYAAABAo"]
[Tue Jul 21 07:33:48.345602 2026] [security2:error] [pid 255769:tid 255915] [client 173.252.95.14:57822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LDLxMYwyVGnfuwsKFYQAAA7M"]
[Tue Jul 21 07:33:48.543806 2026] [security2:error] [pid 255769:tid 255946] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9LDLxMYwyVGnfuwsKFaAAAA9I"]
[Tue Jul 21 07:33:48.771537 2026] [security2:error] [pid 255769:tid 256007] [client 152.59.154.239:65384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LDLxMYwyVGnfuwsKFagAABA0"]
[Tue Jul 21 07:33:48.776276 2026] [security2:error] [pid 255769:tid 256007] [client 152.59.154.239:65384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LDLxMYwyVGnfuwsKFagAABA0"]
[Tue Jul 21 07:33:48.810972 2026] [security2:error] [pid 255769:tid 255958] [client 122.186.204.214:62676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LDLxMYwyVGnfuwsKFbQAAA94"]
[Tue Jul 21 07:33:48.811085 2026] [security2:error] [pid 255769:tid 255958] [client 122.186.204.214:62676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LDLxMYwyVGnfuwsKFbQAAA94"]
[Tue Jul 21 07:33:48.818070 2026] [security2:error] [pid 255769:tid 256006] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9LDLxMYwyVGnfuwsKFbgAABAw"]
[Tue Jul 21 07:33:48.880498 2026] [security2:error] [pid 254995:tid 255116] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/155.php"] [unique_id "al9LDP7v0rlcEGmVraEqqQADM3g"]
[Tue Jul 21 07:33:49.082528 2026] [security2:error] [pid 255769:tid 255899] [client 20.220.225.223:49817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-wpbak.php"] [unique_id "al9LDbxMYwyVGnfuwsKFcwAAA6M"]
[Tue Jul 21 07:33:49.090220 2026] [security2:error] [pid 254995:tid 255222] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9LDf7v0rlcEGmVraEqrwAAA34"]
[Tue Jul 21 07:33:49.119586 2026] [security2:error] [pid 254995:tid 255141] [client 173.252.95.16:50228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LDP7v0rlcEGmVraEqqwAAAy4"]
[Tue Jul 21 07:33:49.348079 2026] [security2:error] [pid 255769:tid 255907] [client 173.24.185.52:61721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LDbxMYwyVGnfuwsKFdQAAA6s"]
[Tue Jul 21 07:33:49.348219 2026] [security2:error] [pid 255769:tid 255907] [client 173.24.185.52:61721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LDbxMYwyVGnfuwsKFdQAAA6s"]
[Tue Jul 21 07:33:49.365647 2026] [security2:error] [pid 254995:tid 255272] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9LDf7v0rlcEGmVraEqswAAA5Y"]
[Tue Jul 21 07:33:49.565442 2026] [security2:error] [pid 255769:tid 256015] [client 20.197.195.24:48844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/xyn.php"] [unique_id "al9LDbxMYwyVGnfuwsKFeQAABBU"]
[Tue Jul 21 07:33:49.638240 2026] [security2:error] [pid 255769:tid 255956] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9LDbxMYwyVGnfuwsKFewAAA9w"]
[Tue Jul 21 07:33:49.640446 2026] [security2:error] [pid 255769:tid 255902] [client 20.206.105.145:38922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/25d653587fdfd1.php"] [unique_id "al9LDbxMYwyVGnfuwsKFfAAAA6Y"]
[Tue Jul 21 07:33:49.765549 2026] [security2:error] [pid 254995:tid 255042] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LDf7v0rlcEGmVraEqugADQi4"]
[Tue Jul 21 07:33:49.765704 2026] [security2:error] [pid 254995:tid 255161] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LDf7v0rlcEGmVraEqugADQi4"]
[Tue Jul 21 07:33:49.781121 2026] [security2:error] [pid 255769:tid 255939] [client 122.162.144.145:14032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LDbxMYwyVGnfuwsKFfwAAA8s"]
[Tue Jul 21 07:33:49.781266 2026] [security2:error] [pid 255769:tid 255939] [client 122.162.144.145:14032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LDbxMYwyVGnfuwsKFfwAAA8s"]
[Tue Jul 21 07:33:49.790245 2026] [security2:error] [pid 255769:tid 255957] [client 45.8.17.124:25027] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/data.php"] [unique_id "al9LDbxMYwyVGnfuwsKFgQAAA90"]
[Tue Jul 21 07:33:49.822372 2026] [security2:error] [pid 255769:tid 256028] [client 47.128.26.55:52884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nrfilmes.com"] [uri "/robots.txt"] [unique_id "al9LDbxMYwyVGnfuwsKFggAABCI"]
[Tue Jul 21 07:33:50.165879 2026] [security2:error] [pid 255769:tid 255804] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LDrxMYwyVGnfuwsKFhAADySI"]
[Tue Jul 21 07:33:50.166000 2026] [security2:error] [pid 255769:tid 255937] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LDrxMYwyVGnfuwsKFhAADySI"]
[Tue Jul 21 07:33:50.218694 2026] [security2:error] [pid 254995:tid 255112] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/ops.php"] [unique_id "al9LDv7v0rlcEGmVraEqxAADNXQ"]
[Tue Jul 21 07:33:50.272106 2026] [security2:error] [pid 254995:tid 255104] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/file31.php"] [unique_id "al9LDv7v0rlcEGmVraEqyAADIWw"]
[Tue Jul 21 07:33:50.287276 2026] [security2:error] [pid 254995:tid 255097] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/file6.php"] [unique_id "al9LDv7v0rlcEGmVraEqyQADcGU"]
[Tue Jul 21 07:33:50.318276 2026] [autoindex:error] [pid 254995:tid 255026] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:50.354514 2026] [security2:error] [pid 254995:tid 255122] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/adminfuns.php"] [unique_id "al9LDv7v0rlcEGmVraEqzQADk34"]
[Tue Jul 21 07:33:50.368282 2026] [security2:error] [pid 255769:tid 256022] [client 45.251.232.145:53907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LDrxMYwyVGnfuwsKFhwAABBw"]
[Tue Jul 21 07:33:50.368384 2026] [security2:error] [pid 255769:tid 256022] [client 45.251.232.145:53907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LDrxMYwyVGnfuwsKFhwAABBw"]
[Tue Jul 21 07:33:50.373700 2026] [security2:error] [pid 254995:tid 255100] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/goods.php"] [unique_id "al9LDv7v0rlcEGmVraEqzgADMWg"]
[Tue Jul 21 07:33:50.394106 2026] [security2:error] [pid 255769:tid 256003] [client 103.106.20.201:55614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LDrxMYwyVGnfuwsKFiAAABAk"]
[Tue Jul 21 07:33:50.394179 2026] [security2:error] [pid 255769:tid 256003] [client 103.106.20.201:55614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LDrxMYwyVGnfuwsKFiAAABAk"]
[Tue Jul 21 07:33:50.493094 2026] [autoindex:error] [pid 255769:tid 255973] [client 20.197.195.24:48854] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:50.575254 2026] [autoindex:error] [pid 255769:tid 255930] [client 20.197.195.24:48854] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:50.599187 2026] [security2:error] [pid 255769:tid 255998] [client 20.197.195.24:48854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/ccc.php"] [unique_id "al9LDrxMYwyVGnfuwsKFjwAABAQ"]
[Tue Jul 21 07:33:50.622639 2026] [security2:error] [pid 254995:tid 255185] [client 20.220.225.223:48130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/kq1.php"] [unique_id "al9LDv7v0rlcEGmVraEq0AAAA1o"]
[Tue Jul 21 07:33:50.872510 2026] [security2:error] [pid 254995:tid 255223] [client 20.220.225.223:44230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/tkikikoko.php"] [unique_id "al9LDv7v0rlcEGmVraEq1QAAA38"]
[Tue Jul 21 07:33:50.972019 2026] [security2:error] [pid 254995:tid 255105] [remote 13.41.15.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.15.41.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "extrapro21.com"] [uri "/wp-login.php"] [unique_id "al9LDv7v0rlcEGmVraEq1gADnW0"]
[Tue Jul 21 07:33:51.044911 2026] [security2:error] [pid 255769:tid 255959] [client 37.140.223.68:42471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LD7xMYwyVGnfuwsKFkwAAA98"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:51.218685 2026] [security2:error] [pid 255769:tid 256002] [client 154.192.233.199:60527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LD7xMYwyVGnfuwsKFlwAABAg"]
[Tue Jul 21 07:33:51.218800 2026] [security2:error] [pid 255769:tid 256002] [client 154.192.233.199:60527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LD7xMYwyVGnfuwsKFlwAABAg"]
[Tue Jul 21 07:33:51.263407 2026] [access_compat:error] [pid 255769:tid 255982] [client 162.241.63.68:38972] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:33:51.665732 2026] [security2:error] [pid 255769:tid 255990] [client 20.220.225.223:31176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/byp8.php"] [unique_id "al9LD7xMYwyVGnfuwsKFnQAAA_4"]
[Tue Jul 21 07:33:51.739946 2026] [security2:error] [pid 254995:tid 255005] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/100.php"] [unique_id "al9LD_7v0rlcEGmVraEq4QADOwk"]
[Tue Jul 21 07:33:51.798035 2026] [security2:error] [pid 255769:tid 255907] [client 20.197.195.24:13128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/w.php"] [unique_id "al9LD7xMYwyVGnfuwsKFnwAAA6s"]
[Tue Jul 21 07:33:51.825308 2026] [security2:error] [pid 255769:tid 255967] [client 117.217.38.194:58435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LD7xMYwyVGnfuwsKFoQAAA-c"]
[Tue Jul 21 07:33:51.826019 2026] [security2:error] [pid 255769:tid 255967] [client 117.217.38.194:58435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LD7xMYwyVGnfuwsKFoQAAA-c"]
[Tue Jul 21 07:33:51.981448 2026] [security2:error] [pid 255769:tid 255923] [client 45.8.17.62:26763] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/crop/crop/sitemap-generator.php"] [unique_id "al9LD7xMYwyVGnfuwsKFpwAAA7s"]
[Tue Jul 21 07:33:52.031184 2026] [security2:error] [pid 255769:tid 255902] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LD7xMYwyVGnfuwsKFpgADpjo"]
[Tue Jul 21 07:33:52.094978 2026] [security2:error] [pid 254995:tid 255134] [client 175.45.70.82:56658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LEP7v0rlcEGmVraEq5QAAAyc"]
[Tue Jul 21 07:33:52.095116 2026] [security2:error] [pid 254995:tid 255134] [client 175.45.70.82:56658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LEP7v0rlcEGmVraEq5QAAAyc"]
[Tue Jul 21 07:33:52.559726 2026] [security2:error] [pid 255769:tid 256010] [client 20.206.105.145:39248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wefile.php"] [unique_id "al9LELxMYwyVGnfuwsKFrAAABBA"]
[Tue Jul 21 07:33:52.779333 2026] [security2:error] [pid 255769:tid 255973] [client 62.102.148.164:35950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9LELxMYwyVGnfuwsKFsQAAA-0"]
[Tue Jul 21 07:33:52.779425 2026] [security2:error] [pid 255769:tid 255973] [client 62.102.148.164:35950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9LELxMYwyVGnfuwsKFsQAAA-0"]
[Tue Jul 21 07:33:52.901286 2026] [security2:error] [pid 255769:tid 255930] [client 20.220.225.223:48134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/dr.php"] [unique_id "al9LELxMYwyVGnfuwsKFtAAAA8I"]
[Tue Jul 21 07:33:52.947479 2026] [security2:error] [pid 255769:tid 255993] [client 20.220.225.223:48154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/zzz.php"] [unique_id "al9LELxMYwyVGnfuwsKFtgAABAA"]
[Tue Jul 21 07:33:52.965150 2026] [security2:error] [pid 254995:tid 254997] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/about.php"] [unique_id "al9LEP7v0rlcEGmVraEq8wADcgE"]
[Tue Jul 21 07:33:53.087533 2026] [security2:error] [pid 255769:tid 256005] [client 45.8.17.135:31279] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Requests/Transport/Transport/spam-filter.php"] [unique_id "al9LEbxMYwyVGnfuwsKFvwAABAs"]
[Tue Jul 21 07:33:53.113733 2026] [security2:error] [pid 255769:tid 256009] [client 103.174.34.15:65288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LEbxMYwyVGnfuwsKFwgAABA8"]
[Tue Jul 21 07:33:53.113836 2026] [security2:error] [pid 255769:tid 256009] [client 103.174.34.15:65288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LEbxMYwyVGnfuwsKFwgAABA8"]
[Tue Jul 21 07:33:53.187350 2026] [security2:error] [pid 255769:tid 255885] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LEbxMYwyVGnfuwsKFyQAD5nM"]
[Tue Jul 21 07:33:53.187507 2026] [security2:error] [pid 255769:tid 255966] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LEbxMYwyVGnfuwsKFyQAD5nM"]
[Tue Jul 21 07:33:53.193241 2026] [security2:error] [pid 255769:tid 255968] [client 20.197.195.24:13134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9LEbxMYwyVGnfuwsKFygAAA-g"]
[Tue Jul 21 07:33:53.491575 2026] [security2:error] [pid 254995:tid 255041] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/about.php"] [unique_id "al9LEf7v0rlcEGmVraErMwADjC0"]
[Tue Jul 21 07:33:53.512699 2026] [security2:error] [pid 254995:tid 255037] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/admin.php"] [unique_id "al9LEf7v0rlcEGmVraErNAADbCk"]
[Tue Jul 21 07:33:53.527983 2026] [security2:error] [pid 254995:tid 254996] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/admin.php"] [unique_id "al9LEf7v0rlcEGmVraErNQADjQA"]
[Tue Jul 21 07:33:53.569781 2026] [security2:error] [pid 254995:tid 255028] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/themes.php"] [unique_id "al9LEf7v0rlcEGmVraErNgADiSA"]
[Tue Jul 21 07:33:53.596797 2026] [autoindex:error] [pid 254995:tid 255045] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:53.846731 2026] [security2:error] [pid 254995:tid 255001] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LEf7v0rlcEGmVraErQQADnAU"]
[Tue Jul 21 07:33:53.846933 2026] [security2:error] [pid 254995:tid 255278] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LEf7v0rlcEGmVraErQQADnAU"]
[Tue Jul 21 07:33:53.896785 2026] [security2:error] [pid 254995:tid 255060] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/.well-known/about.php"] [unique_id "al9LEf7v0rlcEGmVraErRAADNkA"]
[Tue Jul 21 07:33:53.913168 2026] [security2:error] [pid 254995:tid 255054] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9LEf7v0rlcEGmVraErRQADXDo"]
[Tue Jul 21 07:33:53.941299 2026] [security2:error] [pid 254995:tid 255006] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wefile.php"] [unique_id "al9LEf7v0rlcEGmVraErRwADSQo"]
[Tue Jul 21 07:33:53.956598 2026] [security2:error] [pid 254995:tid 255038] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9LEf7v0rlcEGmVraErSAADbyo"]
[Tue Jul 21 07:33:54.048128 2026] [security2:error] [pid 255769:tid 255909] [client 20.197.195.24:13067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/FWAZ.php"] [unique_id "al9LErxMYwyVGnfuwsKF5QAAA60"]
[Tue Jul 21 07:33:54.151404 2026] [autoindex:error] [pid 254995:tid 255012] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:54.187298 2026] [security2:error] [pid 255769:tid 255999] [client 45.8.17.106:40875] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/db-status.php"] [unique_id "al9LErxMYwyVGnfuwsKF6AAABAU"]
[Tue Jul 21 07:33:54.292582 2026] [autoindex:error] [pid 254995:tid 255017] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:54.311942 2026] [security2:error] [pid 254995:tid 255040] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9LEv7v0rlcEGmVraErUQADciw"]
[Tue Jul 21 07:33:54.328119 2026] [security2:error] [pid 254995:tid 255032] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/8.php"] [unique_id "al9LEv7v0rlcEGmVraErUwADJCQ"]
[Tue Jul 21 07:33:54.595222 2026] [security2:error] [pid 254995:tid 255050] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9LEv7v0rlcEGmVraErXAADXTY"]
[Tue Jul 21 07:33:55.028179 2026] [security2:error] [pid 255769:tid 255810] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LE7xMYwyVGnfuwsKF8QADsCg"]
[Tue Jul 21 07:33:55.028347 2026] [security2:error] [pid 255769:tid 255912] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LE7xMYwyVGnfuwsKF8QADsCg"]
[Tue Jul 21 07:33:55.049963 2026] [security2:error] [pid 254995:tid 255119] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/f6.php"] [unique_id "al9LE_7v0rlcEGmVraErYQADSns"]
[Tue Jul 21 07:33:55.072576 2026] [security2:error] [pid 254995:tid 255064] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/inputs.php"] [unique_id "al9LE_7v0rlcEGmVraErYwADVUQ"]
[Tue Jul 21 07:33:55.087618 2026] [security2:error] [pid 254995:tid 255030] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/inputs.php"] [unique_id "al9LE_7v0rlcEGmVraErZAADkyI"]
[Tue Jul 21 07:33:55.102909 2026] [security2:error] [pid 254995:tid 255072] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/classwithtostring.php"] [unique_id "al9LE_7v0rlcEGmVraErZgADPkw"]
[Tue Jul 21 07:33:55.172064 2026] [rewrite:error] [pid 255769:tid 255951] [client 187.49.76.218:17473] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:33:55.173207 2026] [rewrite:error] [pid 255769:tid 255948] [client 187.49.76.218:17505] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:33:55.179926 2026] [security2:error] [pid 254995:tid 255221] [client 20.220.225.223:49833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wicked.php"] [unique_id "al9LE_7v0rlcEGmVraEraQAAA30"]
[Tue Jul 21 07:33:55.192500 2026] [rewrite:error] [pid 254995:tid 255264] [client 187.49.76.218:17633] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:33:55.395586 2026] [security2:error] [pid 255769:tid 255960] [client 45.8.17.146:26419] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/SimplePie/XML/XML/sitemap-generator.php"] [unique_id "al9LE7xMYwyVGnfuwsKF-gAAA-A"]
[Tue Jul 21 07:33:55.711544 2026] [security2:error] [pid 255769:tid 255963] [client 20.197.195.24:13142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/miru1.php"] [unique_id "al9LE7xMYwyVGnfuwsKGAwAAA-M"]
[Tue Jul 21 07:33:55.880626 2026] [security2:error] [pid 254995:tid 255198] [client 136.144.33.110:24355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LE_7v0rlcEGmVraEreAAAA2c"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:55.891294 2026] [security2:error] [pid 254995:tid 255265] [client 82.102.28.107:54066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9LE_7v0rlcEGmVraEreQAAA48"]
[Tue Jul 21 07:33:55.891399 2026] [security2:error] [pid 254995:tid 255265] [client 82.102.28.107:54066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9LE_7v0rlcEGmVraEreQAAA48"]
[Tue Jul 21 07:33:56.003630 2026] [security2:error] [pid 254995:tid 255052] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9LFP7v0rlcEGmVraErewADLTg"]
[Tue Jul 21 07:33:56.011465 2026] [proxy:error] [pid 254995:tid 255137] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:56.011532 2026] [proxy_http:error] [pid 254995:tid 255137] [client 20.206.105.145:38963] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:56.012195 2026] [proxy:error] [pid 254995:tid 255137] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:56.012225 2026] [proxy_http:error] [pid 254995:tid 255137] [client 20.206.105.145:38963] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:56.033734 2026] [security2:error] [pid 254995:tid 255219] [client 122.129.67.13:59014] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9LFP7v0rlcEGmVraErfQAAA3s"]
[Tue Jul 21 07:33:56.033905 2026] [security2:error] [pid 254995:tid 255219] [client 122.129.67.13:59014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9LFP7v0rlcEGmVraErfQAAA3s"]
[Tue Jul 21 07:33:56.382304 2026] [security2:error] [pid 254995:tid 255086] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-blog.php"] [unique_id "al9LFP7v0rlcEGmVraErgAADI1o"]
[Tue Jul 21 07:33:56.410354 2026] [autoindex:error] [pid 254995:tid 255118] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:56.426452 2026] [security2:error] [pid 255769:tid 255886] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LFLxMYwyVGnfuwsKGCgAEB3Q"]
[Tue Jul 21 07:33:56.426658 2026] [security2:error] [pid 255769:tid 256001] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LFLxMYwyVGnfuwsKGCgAEB3Q"]
[Tue Jul 21 07:33:56.428166 2026] [security2:error] [pid 254995:tid 255123] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9LFP7v0rlcEGmVraErgwADnH8"]
[Tue Jul 21 07:33:56.444167 2026] [security2:error] [pid 254995:tid 255067] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/ms-edit.php"] [unique_id "al9LFP7v0rlcEGmVraErhAADNkc"]
[Tue Jul 21 07:33:56.460500 2026] [security2:error] [pid 254995:tid 255092] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9LFP7v0rlcEGmVraErhQADXGA"]
[Tue Jul 21 07:33:56.572525 2026] [security2:error] [pid 255769:tid 255892] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LFLxMYwyVGnfuwsKGCwAEGno"]
[Tue Jul 21 07:33:56.572697 2026] [security2:error] [pid 255769:tid 256020] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LFLxMYwyVGnfuwsKGCwAEGno"]
[Tue Jul 21 07:33:56.691865 2026] [security2:error] [pid 255769:tid 255799] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LFLxMYwyVGnfuwsKGEAADph0"]
[Tue Jul 21 07:33:56.692076 2026] [security2:error] [pid 255769:tid 255902] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LFLxMYwyVGnfuwsKGEAADph0"]
[Tue Jul 21 07:33:56.870022 2026] [autoindex:error] [pid 254995:tid 255082] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:56.889374 2026] [security2:error] [pid 255769:tid 255931] [client 45.8.17.137:59581] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/test.php"] [unique_id "al9LFLxMYwyVGnfuwsKGEQAAA8M"]
[Tue Jul 21 07:33:56.920493 2026] [security2:error] [pid 255769:tid 255987] [client 139.167.225.182:50499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LFLxMYwyVGnfuwsKGEgAAA_s"]
[Tue Jul 21 07:33:56.922182 2026] [security2:error] [pid 255769:tid 255987] [client 139.167.225.182:50499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LFLxMYwyVGnfuwsKGEgAAA_s"]
[Tue Jul 21 07:33:57.217304 2026] [security2:error] [pid 254995:tid 255200] [client 20.197.195.24:13161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/aa.php"] [unique_id "al9LFf7v0rlcEGmVraErkgAAA2k"]
[Tue Jul 21 07:33:57.319454 2026] [security2:error] [pid 254995:tid 255002] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9LFf7v0rlcEGmVraErkwADkgY"]
[Tue Jul 21 07:33:57.740724 2026] [autoindex:error] [pid 254995:tid 255058] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:57.802717 2026] [security2:error] [pid 255769:tid 256011] [client 37.140.223.49:45739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LFLxMYwyVGnfuwsKGDwAABBE"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:33:57.815744 2026] [security2:error] [pid 254995:tid 255271] [client 103.162.129.114:62944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LFf7v0rlcEGmVraErmwAAA5U"]
[Tue Jul 21 07:33:57.815898 2026] [security2:error] [pid 254995:tid 255271] [client 103.162.129.114:62944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LFf7v0rlcEGmVraErmwAAA5U"]
[Tue Jul 21 07:33:57.890274 2026] [security2:error] [pid 255769:tid 256005] [client 109.248.148.246:38876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9LFbxMYwyVGnfuwsKGHwAABAs"]
[Tue Jul 21 07:33:57.890383 2026] [security2:error] [pid 255769:tid 256005] [client 109.248.148.246:38876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9LFbxMYwyVGnfuwsKGHwAABAs"]
[Tue Jul 21 07:33:57.917467 2026] [autoindex:error] [pid 254995:tid 255042] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:57.936067 2026] [security2:error] [pid 254995:tid 255111] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/abcd.php"] [unique_id "al9LFf7v0rlcEGmVraEroAADdnM"]
[Tue Jul 21 07:33:57.985191 2026] [security2:error] [pid 255769:tid 255943] [client 82.102.28.107:54078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9LFbxMYwyVGnfuwsKGIQAAA88"]
[Tue Jul 21 07:33:57.985288 2026] [security2:error] [pid 255769:tid 255943] [client 82.102.28.107:54078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9LFbxMYwyVGnfuwsKGIQAAA88"]
[Tue Jul 21 07:33:58.012153 2026] [security2:error] [pid 254995:tid 255103] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/file15.php"] [unique_id "al9LFv7v0rlcEGmVraEroQADSms"]
[Tue Jul 21 07:33:58.056503 2026] [security2:error] [pid 254995:tid 255115] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/jp.php"] [unique_id "al9LFv7v0rlcEGmVraErogADVXc"]
[Tue Jul 21 07:33:58.085050 2026] [security2:error] [pid 254995:tid 255010] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/f35.php"] [unique_id "al9LFv7v0rlcEGmVraErpAADPg4"]
[Tue Jul 21 07:33:58.112080 2026] [security2:error] [pid 254995:tid 255104] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-load.php"] [unique_id "al9LFv7v0rlcEGmVraErqAADbWw"]
[Tue Jul 21 07:33:58.125738 2026] [security2:error] [pid 254995:tid 255144] [client 20.220.225.223:48137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/edit.php"] [unique_id "al9LFv7v0rlcEGmVraErqgAAAzE"]
[Tue Jul 21 07:33:58.127883 2026] [security2:error] [pid 254995:tid 255097] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/xyn.php"] [unique_id "al9LFv7v0rlcEGmVraErqwADd2U"]
[Tue Jul 21 07:33:58.154170 2026] [autoindex:error] [pid 254995:tid 255089] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:58.171455 2026] [security2:error] [pid 254995:tid 255223] [client 20.197.195.24:13106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/122.php"] [unique_id "al9LFv7v0rlcEGmVraErrwAAA38"]
[Tue Jul 21 07:33:58.188433 2026] [security2:error] [pid 254995:tid 255195] [client 45.8.17.60:38515] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/jquery/ui/ui/forum-engine.php"] [unique_id "al9LFv7v0rlcEGmVraErsAAAA2Q"]
[Tue Jul 21 07:33:58.317200 2026] [autoindex:error] [pid 254995:tid 255100] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:58.436167 2026] [security2:error] [pid 254995:tid 255011] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/ccc.php"] [unique_id "al9LFv7v0rlcEGmVraEruAADWQ8"]
[Tue Jul 21 07:33:58.451807 2026] [security2:error] [pid 254995:tid 255114] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/w.php"] [unique_id "al9LFv7v0rlcEGmVraEruQADZ3Y"]
[Tue Jul 21 07:33:58.457124 2026] [security2:error] [pid 255769:tid 256018] [client 117.251.86.144:50928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LFrxMYwyVGnfuwsKGJQAABBg"]
[Tue Jul 21 07:33:58.457231 2026] [security2:error] [pid 255769:tid 256018] [client 117.251.86.144:50928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LFrxMYwyVGnfuwsKGJQAABBg"]
[Tue Jul 21 07:33:58.467916 2026] [security2:error] [pid 254995:tid 255093] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9LFv7v0rlcEGmVraErugADj2E"]
[Tue Jul 21 07:33:58.481070 2026] [security2:error] [pid 255769:tid 255772] [remote 117.50.194.130:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "denarios.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9LFLxMYwyVGnfuwsKGFAAD5QI"]
[Tue Jul 21 07:33:58.502611 2026] [security2:error] [pid 254995:tid 255031] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/FWAZ.php"] [unique_id "al9LFv7v0rlcEGmVraEruwADeSM"]
[Tue Jul 21 07:33:58.517543 2026] [security2:error] [pid 254995:tid 255105] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/miru1.php"] [unique_id "al9LFv7v0rlcEGmVraErvAADU20"]
[Tue Jul 21 07:33:58.559891 2026] [security2:error] [pid 254995:tid 255080] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/aa.php"] [unique_id "al9LFv7v0rlcEGmVraErvQADelQ"]
[Tue Jul 21 07:33:58.827387 2026] [security2:error] [pid 254995:tid 255201] [client 20.197.195.24:13123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/get.php"] [unique_id "al9LFv7v0rlcEGmVraErxQAAA2o"]
[Tue Jul 21 07:33:58.862564 2026] [proxy:error] [pid 255769:tid 255953] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:58.862643 2026] [proxy_http:error] [pid 255769:tid 255953] [client 20.206.105.145:39127] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:58.863459 2026] [proxy:error] [pid 255769:tid 255953] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:58.863490 2026] [proxy_http:error] [pid 255769:tid 255953] [client 20.206.105.145:39127] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:58.917534 2026] [security2:error] [pid 254995:tid 255005] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/122.php"] [unique_id "al9LFv7v0rlcEGmVraEryAADcQk"]
[Tue Jul 21 07:33:58.944019 2026] [security2:error] [pid 254995:tid 255094] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/get.php"] [unique_id "al9LFv7v0rlcEGmVraEryQADXmI"]
[Tue Jul 21 07:33:58.951483 2026] [security2:error] [pid 254995:tid 255141] [client 20.52.136.55:1593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/test1.php"] [unique_id "al9LFv7v0rlcEGmVraErygAAAy4"]
[Tue Jul 21 07:33:59.138246 2026] [security2:error] [pid 254995:tid 255000] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/as.php"] [unique_id "al9LF_7v0rlcEGmVraErzAADRwQ"]
[Tue Jul 21 07:33:59.153751 2026] [security2:error] [pid 254995:tid 255083] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/ccou.php"] [unique_id "al9LF_7v0rlcEGmVraErzQADNFc"]
[Tue Jul 21 07:33:59.169220 2026] [security2:error] [pid 254995:tid 255007] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/w3lls.php"] [unique_id "al9LF_7v0rlcEGmVraErzgADJAs"]
[Tue Jul 21 07:33:59.232616 2026] [security2:error] [pid 255769:tid 255965] [client 117.50.194.130:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "denarios.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9LFLxMYwyVGnfuwsKGFAAD5QI"]
[Tue Jul 21 07:33:59.456164 2026] [security2:error] [pid 254995:tid 255278] [client 122.186.204.214:63176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LF_7v0rlcEGmVraEr0wAAA5w"]
[Tue Jul 21 07:33:59.456269 2026] [security2:error] [pid 254995:tid 255278] [client 122.186.204.214:63176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LF_7v0rlcEGmVraEr0wAAA5w"]
[Tue Jul 21 07:33:59.488136 2026] [security2:error] [pid 255769:tid 255937] [client 45.8.17.58:53647] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/tinymce/plugins/ms-files.php"] [unique_id "al9LF7xMYwyVGnfuwsKGMwAAA8k"]
[Tue Jul 21 07:33:59.623736 2026] [security2:error] [pid 254995:tid 255061] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/test1.php"] [unique_id "al9LF_7v0rlcEGmVraEr1QADQkE"]
[Tue Jul 21 07:33:59.677118 2026] [security2:error] [pid 254995:tid 254997] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/database.php"] [unique_id "al9LF_7v0rlcEGmVraEr1wADJgE"]
[Tue Jul 21 07:33:59.777991 2026] [security2:error] [pid 254995:tid 255155] [client 20.220.225.223:49547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/2x.php"] [unique_id "al9LF_7v0rlcEGmVraEr2QAAAzw"]
[Tue Jul 21 07:33:59.802104 2026] [security2:error] [pid 254995:tid 255279] [client 193.36.225.62:28065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LF_7v0rlcEGmVraEr2gAAA50"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:59.895608 2026] [security2:error] [pid 255769:tid 255978] [client 173.24.185.52:62194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LF7xMYwyVGnfuwsKGOwAAA_I"]
[Tue Jul 21 07:33:59.895719 2026] [security2:error] [pid 255769:tid 255978] [client 173.24.185.52:62194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LF7xMYwyVGnfuwsKGOwAAA_I"]
[Tue Jul 21 07:33:59.915538 2026] [security2:error] [pid 255769:tid 255964] [client 20.197.195.24:13118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/as.php"] [unique_id "al9LF7xMYwyVGnfuwsKGPQAAA-Q"]
[Tue Jul 21 07:33:59.915980 2026] [security2:error] [pid 254995:tid 255088] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/file.php"] [unique_id "al9LF_7v0rlcEGmVraEr3QADX1w"]
[Tue Jul 21 07:34:00.081233 2026] [core:error] [pid 255769:tid 255784] [remote 74.7.244.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:34:00.081252 2026] [core:error] [pid 255769:tid 255784] [remote 74.7.244.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:34:00.081447 2026] [security2:error] [pid 255769:tid 255994] [client 74.7.244.51:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.digitalbelfort.com"] [uri "/___proxy_subdomain_webmail/htdocs/bagisto-2.4/public/___proxy_subdomain_webmail/htdocs/bagisto-2.4/public/___proxy_subdomain_webmail/htdocs/bagisto-2.4/public/___proxy_subdomain_webmail/htdocs/bagisto-2.4/public/___proxy_subdomain_webmail/htdocs/bagisto-2.4/public/___proxy_subdomain_webmail/htdocs/bagisto-2.4/public/___proxy_subdomain_webmail/htdocs/bagisto-2.4/public/___proxy_subdomain_webmail/htdocs/bagisto-2.4/public/___proxy_subdomain_webmail/htdocs/bagisto-2.4/public/___proxy_subdomain_webmail/htdocs/bagisto-2.4/public/___proxy_subdomain_webmail/robots.txt"] [unique_id "al9LGLxMYwyVGnfuwsKGPgAEAQ4"]
[Tue Jul 21 07:34:00.156112 2026] [security2:error] [pid 254995:tid 255037] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/file.php"] [unique_id "al9LGP7v0rlcEGmVraEr4QADSik"]
[Tue Jul 21 07:34:00.380682 2026] [security2:error] [pid 255769:tid 255911] [client 37.140.223.117:47279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LGLxMYwyVGnfuwsKGQwAAA68"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:00.387978 2026] [security2:error] [pid 255769:tid 255802] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGRAADzyA"]
[Tue Jul 21 07:34:00.388163 2026] [security2:error] [pid 255769:tid 255943] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGRAADzyA"]
[Tue Jul 21 07:34:00.475124 2026] [security2:error] [pid 255769:tid 255900] [client 122.162.144.145:4626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGRwAAA6Q"]
[Tue Jul 21 07:34:00.475213 2026] [security2:error] [pid 255769:tid 255900] [client 122.162.144.145:4626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGRwAAA6Q"]
[Tue Jul 21 07:34:00.620755 2026] [security2:error] [pid 255769:tid 255996] [client 152.59.154.239:20657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGSQAABAI"]
[Tue Jul 21 07:34:00.625784 2026] [security2:error] [pid 255769:tid 255996] [client 152.59.154.239:20657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGSQAABAI"]
[Tue Jul 21 07:34:00.644239 2026] [security2:error] [pid 254995:tid 255021] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/777.php"] [unique_id "al9LGP7v0rlcEGmVraEr5gADfRk"]
[Tue Jul 21 07:34:00.681448 2026] [security2:error] [pid 254995:tid 255045] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/ssixta.php"] [unique_id "al9LGP7v0rlcEGmVraEr5wADjjE"]
[Tue Jul 21 07:34:00.745331 2026] [security2:error] [pid 254995:tid 255101] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/1c.php"] [unique_id "al9LGP7v0rlcEGmVraEr6QADf2k"]
[Tue Jul 21 07:34:00.757924 2026] [security2:error] [pid 255769:tid 255956] [client 20.220.225.223:49831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/kua.php"] [unique_id "al9LGLxMYwyVGnfuwsKGTAAAA9w"]
[Tue Jul 21 07:34:00.788628 2026] [security2:error] [pid 255769:tid 255877] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGUAAEFms"]
[Tue Jul 21 07:34:00.788763 2026] [security2:error] [pid 255769:tid 256016] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGUAAEFms"]
[Tue Jul 21 07:34:00.860256 2026] [security2:error] [pid 255769:tid 255947] [client 82.102.28.107:40156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGUgAAA9M"]
[Tue Jul 21 07:34:00.860344 2026] [security2:error] [pid 255769:tid 255947] [client 82.102.28.107:40156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGUgAAA9M"]
[Tue Jul 21 07:34:00.876072 2026] [security2:error] [pid 255769:tid 256011] [client 45.251.232.145:54436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGUwAABBE"]
[Tue Jul 21 07:34:00.876172 2026] [security2:error] [pid 255769:tid 256011] [client 45.251.232.145:54436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGUwAABBE"]
[Tue Jul 21 07:34:00.885425 2026] [security2:error] [pid 255769:tid 255927] [client 45.8.17.121:41323] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/includes/includes/logo/se.php"] [unique_id "al9LGLxMYwyVGnfuwsKGVAAAA78"]
[Tue Jul 21 07:34:00.894794 2026] [security2:error] [pid 255769:tid 256004] [client 20.220.225.223:49812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/kq1.php"] [unique_id "al9LGLxMYwyVGnfuwsKGVQAABAo"]
[Tue Jul 21 07:34:01.094613 2026] [security2:error] [pid 254995:tid 254999] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/test2.php"] [unique_id "al9LGf7v0rlcEGmVraEr7AADJQM"]
[Tue Jul 21 07:34:01.110658 2026] [security2:error] [pid 254995:tid 255060] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/buy.php"] [unique_id "al9LGf7v0rlcEGmVraEr7QADVkA"]
[Tue Jul 21 07:34:01.162795 2026] [security2:error] [pid 255769:tid 255963] [client 103.106.20.201:56361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGbxMYwyVGnfuwsKGWAAAA-M"]
[Tue Jul 21 07:34:01.162975 2026] [security2:error] [pid 255769:tid 255963] [client 103.106.20.201:56361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGbxMYwyVGnfuwsKGWAAAA-M"]
[Tue Jul 21 07:34:01.191075 2026] [security2:error] [pid 254995:tid 255006] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/ssend.php"] [unique_id "al9LGf7v0rlcEGmVraEr7wADYwo"]
[Tue Jul 21 07:34:01.254698 2026] [security2:error] [pid 254995:tid 255018] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/item.php"] [unique_id "al9LGf7v0rlcEGmVraEr8wADgBY"]
[Tue Jul 21 07:34:01.397999 2026] [security2:error] [pid 254995:tid 255218] [client 20.197.195.24:48814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/ccou.php"] [unique_id "al9LGf7v0rlcEGmVraEr-AAAA3o"]
[Tue Jul 21 07:34:01.760646 2026] [security2:error] [pid 254995:tid 255130] [client 20.206.105.145:39148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9LGf7v0rlcEGmVraEsAQAAAyM"]
[Tue Jul 21 07:34:01.841556 2026] [security2:error] [pid 254995:tid 255032] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/ss.php"] [unique_id "al9LGf7v0rlcEGmVraEsAgADaiQ"]
[Tue Jul 21 07:34:01.903883 2026] [security2:error] [pid 254995:tid 255009] [remote 160.187.68.132:57878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tempex.com.br"] [uri "/wp-login.php"] [unique_id "al9LGf7v0rlcEGmVraEsBAADYg0"]
[Tue Jul 21 07:34:01.960127 2026] [security2:error] [pid 255769:tid 255931] [client 154.192.233.199:58965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGbxMYwyVGnfuwsKGZgAAA8M"]
[Tue Jul 21 07:34:01.960317 2026] [security2:error] [pid 255769:tid 255931] [client 154.192.233.199:58965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGbxMYwyVGnfuwsKGZgAAA8M"]
[Tue Jul 21 07:34:02.263845 2026] [security2:error] [pid 255769:tid 255996] [client 20.197.195.24:13064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/w3lls.php"] [unique_id "al9LGrxMYwyVGnfuwsKGbAAABAI"]
[Tue Jul 21 07:34:02.365772 2026] [security2:error] [pid 255769:tid 255964] [client 117.217.38.194:58878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGrxMYwyVGnfuwsKGcAAAA-Q"]
[Tue Jul 21 07:34:02.365880 2026] [security2:error] [pid 255769:tid 255964] [client 117.217.38.194:58878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGrxMYwyVGnfuwsKGcAAAA-Q"]
[Tue Jul 21 07:34:02.406953 2026] [security2:error] [pid 254995:tid 255257] [client 109.248.148.246:52432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9LGv7v0rlcEGmVraEsCQAAA4c"]
[Tue Jul 21 07:34:02.407043 2026] [security2:error] [pid 254995:tid 255257] [client 109.248.148.246:52432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9LGv7v0rlcEGmVraEsCQAAA4c"]
[Tue Jul 21 07:34:02.465280 2026] [security2:error] [pid 254995:tid 255125] [client 37.140.223.157:33277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LGv7v0rlcEGmVraEsCwAAAx4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:02.480075 2026] [security2:error] [pid 254995:tid 255266] [client 45.8.17.144:36105] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/widgets/shadow-bot.php"] [unique_id "al9LGv7v0rlcEGmVraEsDAAAA5A"]
[Tue Jul 21 07:34:02.571124 2026] [security2:error] [pid 255769:tid 255988] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LGrxMYwyVGnfuwsKGdQAD_GE"]
[Tue Jul 21 07:34:02.645314 2026] [rewrite:error] [pid 254995:tid 255134] [client 187.49.76.218:17761] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2409
[Tue Jul 21 07:34:02.647241 2026] [rewrite:error] [pid 255769:tid 255909] [client 187.49.76.218:17793] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2409
[Tue Jul 21 07:34:02.666954 2026] [rewrite:error] [pid 254995:tid 255272] [client 187.49.76.218:17857] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2409
[Tue Jul 21 07:34:02.781244 2026] [security2:error] [pid 255769:tid 255936] [client 175.45.70.82:57166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGrxMYwyVGnfuwsKGewAAA8g"]
[Tue Jul 21 07:34:02.781372 2026] [security2:error] [pid 255769:tid 255936] [client 175.45.70.82:57166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGrxMYwyVGnfuwsKGewAAA8g"]
[Tue Jul 21 07:34:02.855749 2026] [security2:error] [pid 254995:tid 255274] [client 18.233.221.210:29095] ModSecurity: Warning. Matched phrase "Who.is Bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.combolog.com.br"] [uri "/index.php"] [unique_id "al9LGf7v0rlcEGmVraEr-gAAA5g"]
[Tue Jul 21 07:34:03.369208 2026] [security2:error] [pid 254995:tid 255173] [client 20.220.225.223:49595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/ez.php"] [unique_id "al9LG_7v0rlcEGmVraEsGgAAA04"]
[Tue Jul 21 07:34:03.381329 2026] [security2:error] [pid 254995:tid 255056] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/hypo.php"] [unique_id "al9LG_7v0rlcEGmVraEsGwADNTw"]
[Tue Jul 21 07:34:03.402508 2026] [security2:error] [pid 254995:tid 255065] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/users.php"] [unique_id "al9LG_7v0rlcEGmVraEsHAADhEU"]
[Tue Jul 21 07:34:03.439130 2026] [security2:error] [pid 254995:tid 255070] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/177.php"] [unique_id "al9LG_7v0rlcEGmVraEsHQADdko"]
[Tue Jul 21 07:34:03.476028 2026] [security2:error] [pid 254995:tid 255121] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/config.php"] [unique_id "al9LG_7v0rlcEGmVraEsHwADmX0"]
[Tue Jul 21 07:34:03.492538 2026] [security2:error] [pid 254995:tid 255025] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/gettest.php"] [unique_id "al9LG_7v0rlcEGmVraEsIAADVR0"]
[Tue Jul 21 07:34:03.507697 2026] [security2:error] [pid 254995:tid 255095] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/min.php"] [unique_id "al9LG_7v0rlcEGmVraEsIgADXWM"]
[Tue Jul 21 07:34:03.685525 2026] [security2:error] [pid 255769:tid 255994] [client 45.8.17.142:54803] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/login.php"] [unique_id "al9LG7xMYwyVGnfuwsKGiAAABAE"]
[Tue Jul 21 07:34:03.814910 2026] [security2:error] [pid 255769:tid 255969] [client 20.197.195.24:48882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/test1.php"] [unique_id "al9LG7xMYwyVGnfuwsKGigAAA-k"]
[Tue Jul 21 07:34:03.828244 2026] [security2:error] [pid 254995:tid 255172] [client 18.233.221.210:9218] ModSecurity: Warning. Matched phrase "Who.is Bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "combolog.com.br"] [uri "/index.php"] [unique_id "al9LG_7v0rlcEGmVraEsHgAAA00"]
[Tue Jul 21 07:34:03.868457 2026] [security2:error] [pid 255769:tid 255982] [client 62.102.148.164:42554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9LG7xMYwyVGnfuwsKGiwAAA_Y"]
[Tue Jul 21 07:34:03.868543 2026] [security2:error] [pid 255769:tid 255982] [client 62.102.148.164:42554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9LG7xMYwyVGnfuwsKGiwAAA_Y"]
[Tue Jul 21 07:34:04.515350 2026] [security2:error] [pid 255769:tid 255985] [client 193.36.225.66:46143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LHLxMYwyVGnfuwsKGkgAAA_k"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:04.611445 2026] [security2:error] [pid 254995:tid 255076] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LHP7v0rlcEGmVraEsMwADl1A"]
[Tue Jul 21 07:34:04.611566 2026] [security2:error] [pid 254995:tid 255273] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LHP7v0rlcEGmVraEsMwADl1A"]
[Tue Jul 21 07:34:04.710829 2026] [security2:error] [pid 254995:tid 255126] [client 20.220.225.223:49852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/zzz.php"] [unique_id "al9LHP7v0rlcEGmVraEsNQAAAx8"]
[Tue Jul 21 07:34:04.799914 2026] [security2:error] [pid 254995:tid 255118] [remote 173.212.252.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samilacalculos.com.br"] [uri "/wp-login.php"] [unique_id "al9LHP7v0rlcEGmVraEsNgADWXo"]
[Tue Jul 21 07:34:04.921412 2026] [security2:error] [pid 255769:tid 256004] [client 20.220.225.223:24246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/min.php"] [unique_id "al9LHLxMYwyVGnfuwsKGmwAABAo"]
[Tue Jul 21 07:34:05.039538 2026] [security2:error] [pid 255769:tid 255974] [client 103.174.34.15:49390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LHbxMYwyVGnfuwsKGowAAA-4"]
[Tue Jul 21 07:34:05.039633 2026] [security2:error] [pid 255769:tid 255974] [client 103.174.34.15:49390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LHbxMYwyVGnfuwsKGowAAA-4"]
[Tue Jul 21 07:34:05.093697 2026] [security2:error] [pid 255769:tid 255905] [client 45.8.17.136:64615] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/well-known/index.php"] [unique_id "al9LHbxMYwyVGnfuwsKGpAAAA6k"]
[Tue Jul 21 07:34:05.132317 2026] [security2:error] [pid 254995:tid 255225] [client 20.197.195.24:48856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/database.php"] [unique_id "al9LHf7v0rlcEGmVraEsOwAAA4E"]
[Tue Jul 21 07:34:05.253568 2026] [security2:error] [pid 254995:tid 255087] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/dvjul.php"] [unique_id "al9LHf7v0rlcEGmVraEsPQADL1s"]
[Tue Jul 21 07:34:05.271771 2026] [security2:error] [pid 254995:tid 255079] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/biufile.php"] [unique_id "al9LHf7v0rlcEGmVraEsPgADK1M"]
[Tue Jul 21 07:34:05.301492 2026] [proxy:error] [pid 255769:tid 255915] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:05.301530 2026] [proxy_http:error] [pid 255769:tid 255915] [client 147.185.132.249:63832] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:05.302200 2026] [proxy:error] [pid 255769:tid 255915] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:05.302227 2026] [proxy_http:error] [pid 255769:tid 255915] [client 147.185.132.249:63832] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:05.441714 2026] [security2:error] [pid 255769:tid 256022] [client 173.252.95.21:36358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LHbxMYwyVGnfuwsKGrAAABBw"]
[Tue Jul 21 07:34:05.466391 2026] [security2:error] [pid 254995:tid 255120] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/av.php"] [unique_id "al9LHf7v0rlcEGmVraEsQgADM3w"]
[Tue Jul 21 07:34:05.482666 2026] [security2:error] [pid 254995:tid 255102] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/coffexium.php"] [unique_id "al9LHf7v0rlcEGmVraEsQwADbGo"]
[Tue Jul 21 07:34:05.499405 2026] [security2:error] [pid 254995:tid 255002] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/core.php"] [unique_id "al9LHf7v0rlcEGmVraEsRAADPQY"]
[Tue Jul 21 07:34:05.721242 2026] [security2:error] [pid 255769:tid 255834] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LHbxMYwyVGnfuwsKGtQADyUA"]
[Tue Jul 21 07:34:05.721396 2026] [security2:error] [pid 255769:tid 255937] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LHbxMYwyVGnfuwsKGtQADyUA"]
[Tue Jul 21 07:34:05.726744 2026] [security2:error] [pid 255769:tid 256002] [client 74.7.228.46:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "safirarentacar.com.br.bomexito.com.br"] [uri "/index.php"] [unique_id "al9LHbxMYwyVGnfuwsKGpwAABAg"]
[Tue Jul 21 07:34:05.727510 2026] [security2:error] [pid 255769:tid 256010] [client 74.7.228.46:44978] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "safirarentacar.com.br.bomexito.com.br"] [uri "/robots.txt"] [unique_id "al9LHbxMYwyVGnfuwsKGpQAEEB8"]
[Tue Jul 21 07:34:05.761130 2026] [security2:error] [pid 254995:tid 255195] [client 173.252.95.37:50650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LHP7v0rlcEGmVraEsMgAAA2Q"]
[Tue Jul 21 07:34:05.818689 2026] [security2:error] [pid 255769:tid 255949] [client 136.144.33.24:25469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LHLxMYwyVGnfuwsKGlwAAA9U"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:05.859408 2026] [security2:error] [pid 255769:tid 255983] [client 20.220.225.223:63854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/wp-Blogs.php"] [unique_id "al9LHbxMYwyVGnfuwsKGtgAAA_c"]
[Tue Jul 21 07:34:06.028373 2026] [security2:error] [pid 254995:tid 255042] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/als.php"] [unique_id "al9LHv7v0rlcEGmVraEsTgADJy4"]
[Tue Jul 21 07:34:06.055357 2026] [security2:error] [pid 254995:tid 255191] [client 20.220.225.223:19277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9LHv7v0rlcEGmVraEsTwAAA2A"]
[Tue Jul 21 07:34:06.186524 2026] [security2:error] [pid 254995:tid 255161] [client 45.8.17.131:45145] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/backup.php"] [unique_id "al9LHv7v0rlcEGmVraEsUQAAA0I"]
[Tue Jul 21 07:34:06.245092 2026] [security2:error] [pid 254995:tid 255085] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LHv7v0rlcEGmVraEsUgADllk"]
[Tue Jul 21 07:34:06.245231 2026] [security2:error] [pid 254995:tid 255272] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LHv7v0rlcEGmVraEsUgADllk"]
[Tue Jul 21 07:34:06.442983 2026] [security2:error] [pid 254995:tid 255150] [client 20.220.225.223:49834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wicked.php"] [unique_id "al9LHv7v0rlcEGmVraEsVwAAAzc"]
[Tue Jul 21 07:34:06.500649 2026] [security2:error] [pid 254995:tid 255010] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/simple.php"] [unique_id "al9LHv7v0rlcEGmVraEsWQADlA4"]
[Tue Jul 21 07:34:06.520179 2026] [security2:error] [pid 254995:tid 255104] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/init.php"] [unique_id "al9LHv7v0rlcEGmVraEsWgADTmw"]
[Tue Jul 21 07:34:06.536375 2026] [security2:error] [pid 254995:tid 255112] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/fpwch.php"] [unique_id "al9LHv7v0rlcEGmVraEsWwADNXQ"]
[Tue Jul 21 07:34:06.557273 2026] [security2:error] [pid 254995:tid 255097] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/domvf.php"] [unique_id "al9LHv7v0rlcEGmVraEsXAADhGU"]
[Tue Jul 21 07:34:06.590193 2026] [security2:error] [pid 254995:tid 255089] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp.php"] [unique_id "al9LHv7v0rlcEGmVraEsXQADdl0"]
[Tue Jul 21 07:34:06.605223 2026] [security2:error] [pid 254995:tid 255026] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/class.php"] [unique_id "al9LHv7v0rlcEGmVraEsXgADmR4"]
[Tue Jul 21 07:34:06.739983 2026] [security2:error] [pid 254995:tid 255152] [client 59.96.220.140:49551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LHv7v0rlcEGmVraEsYAAAAzk"]
[Tue Jul 21 07:34:06.740123 2026] [security2:error] [pid 254995:tid 255152] [client 59.96.220.140:49551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LHv7v0rlcEGmVraEsYAAAAzk"]
[Tue Jul 21 07:34:06.892935 2026] [security2:error] [pid 255769:tid 255806] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LHrxMYwyVGnfuwsKGzwADtyQ"]
[Tue Jul 21 07:34:06.893116 2026] [security2:error] [pid 255769:tid 255919] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LHrxMYwyVGnfuwsKGzwADtyQ"]
[Tue Jul 21 07:34:07.098688 2026] [security2:error] [pid 255769:tid 255872] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LH7xMYwyVGnfuwsKG0QAD7mY"]
[Tue Jul 21 07:34:07.098877 2026] [security2:error] [pid 255769:tid 255974] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LH7xMYwyVGnfuwsKG0QAD7mY"]
[Tue Jul 21 07:34:07.198195 2026] [security2:error] [pid 254995:tid 255031] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LH_7v0rlcEGmVraEsbAADhiM"]
[Tue Jul 21 07:34:07.198352 2026] [security2:error] [pid 254995:tid 255256] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LH_7v0rlcEGmVraEsbAADhiM"]
[Tue Jul 21 07:34:07.272538 2026] [security2:error] [pid 254995:tid 255105] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/echkm.php"] [unique_id "al9LH_7v0rlcEGmVraEsbQADZm0"]
[Tue Jul 21 07:34:07.383411 2026] [security2:error] [pid 254995:tid 255224] [client 20.220.225.223:4196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/wp-css.php"] [unique_id "al9LH_7v0rlcEGmVraEscQAAA4A"]
[Tue Jul 21 07:34:07.464504 2026] [security2:error] [pid 254995:tid 255022] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/lib.php"] [unique_id "al9LH_7v0rlcEGmVraEscwADWRo"]
[Tue Jul 21 07:34:07.595871 2026] [security2:error] [pid 254995:tid 255225] [client 45.8.17.60:31495] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/user/freedoms-old.php"] [unique_id "al9LH_7v0rlcEGmVraEseAAAA4E"]
[Tue Jul 21 07:34:07.740498 2026] [security2:error] [pid 254995:tid 255066] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/login.php"] [unique_id "al9LH_7v0rlcEGmVraEsewADKkY"]
[Tue Jul 21 07:34:07.757789 2026] [security2:error] [pid 254995:tid 255000] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/a2.php"] [unique_id "al9LH_7v0rlcEGmVraEsfAADMwQ"]
[Tue Jul 21 07:34:07.863682 2026] [security2:error] [pid 254995:tid 255199] [client 139.167.225.182:51130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LH_7v0rlcEGmVraEsfgAAA2g"]
[Tue Jul 21 07:34:07.863772 2026] [security2:error] [pid 254995:tid 255199] [client 139.167.225.182:51130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LH_7v0rlcEGmVraEsfgAAA2g"]
[Tue Jul 21 07:34:08.017797 2026] [security2:error] [pid 255769:tid 255921] [client 20.197.195.24:48845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/file.php"] [unique_id "al9LILxMYwyVGnfuwsKG9gAAA7k"]
[Tue Jul 21 07:34:08.205756 2026] [security2:error] [pid 255769:tid 255828] [remote 216.73.216.238:11436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/contato.php"] [unique_id "al9LILxMYwyVGnfuwsKG_QADsjo"]
[Tue Jul 21 07:34:08.502613 2026] [security2:error] [pid 254995:tid 255084] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/d61.php"] [unique_id "al9LIP7v0rlcEGmVraEsiAADLlg"]
[Tue Jul 21 07:34:08.539597 2026] [security2:error] [pid 255769:tid 255800] [remote 216.73.216.238:11436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/mapa.php"] [unique_id "al9LILxMYwyVGnfuwsKHGwADqx4"]
[Tue Jul 21 07:34:08.575386 2026] [security2:error] [pid 254995:tid 255013] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/info.php"] [unique_id "al9LIP7v0rlcEGmVraEsjAADNBE"]
[Tue Jul 21 07:34:08.593933 2026] [security2:error] [pid 254995:tid 255107] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/11.php"] [unique_id "al9LIP7v0rlcEGmVraEsjQADcW8"]
[Tue Jul 21 07:34:08.614990 2026] [security2:error] [pid 254995:tid 255134] [client 20.220.225.223:24224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/echkm.php"] [unique_id "al9LIP7v0rlcEGmVraEsjgAAAyc"]
[Tue Jul 21 07:34:08.645304 2026] [security2:error] [pid 254995:tid 255088] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/v2.php"] [unique_id "al9LIP7v0rlcEGmVraEsjwADI1w"]
[Tue Jul 21 07:34:08.661280 2026] [security2:error] [pid 255769:tid 255967] [client 20.52.136.55:1474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/fw.php"] [unique_id "al9LILxMYwyVGnfuwsKHHAAAA-c"]
[Tue Jul 21 07:34:08.802371 2026] [security2:error] [pid 255769:tid 255958] [client 103.162.129.114:63382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LILxMYwyVGnfuwsKHHgAAA94"]
[Tue Jul 21 07:34:08.802484 2026] [security2:error] [pid 255769:tid 255958] [client 103.162.129.114:63382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LILxMYwyVGnfuwsKHHgAAA94"]
[Tue Jul 21 07:34:08.880480 2026] [security2:error] [pid 255769:tid 255971] [client 45.8.17.124:35711] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/post-author-name-path.php"] [unique_id "al9LILxMYwyVGnfuwsKHHwAAA-s"]
[Tue Jul 21 07:34:08.921970 2026] [security2:error] [pid 254995:tid 255037] [remote 124.55.178.99:58746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sogastro.com.br"] [uri "/wp-login.php"] [unique_id "al9LIP7v0rlcEGmVraEskgADJSk"]
[Tue Jul 21 07:34:08.938647 2026] [security2:error] [pid 254995:tid 255041] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/panel.php"] [unique_id "al9LIP7v0rlcEGmVraEskwADOi0"]
[Tue Jul 21 07:34:09.140114 2026] [security2:error] [pid 255769:tid 255943] [client 117.251.86.144:39790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LIbxMYwyVGnfuwsKHJwAAA88"]
[Tue Jul 21 07:34:09.140242 2026] [security2:error] [pid 255769:tid 255943] [client 117.251.86.144:39790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LIbxMYwyVGnfuwsKHJwAAA88"]
[Tue Jul 21 07:34:09.419005 2026] [security2:error] [pid 254995:tid 255265] [client 193.36.225.67:21903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LIf7v0rlcEGmVraEsnAAAA48"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:09.747916 2026] [security2:error] [pid 254995:tid 255008] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/dex.php"] [unique_id "al9LIf7v0rlcEGmVraEspAADUgw"]
[Tue Jul 21 07:34:09.894092 2026] [security2:error] [pid 255769:tid 256017] [client 45.8.17.73:57507] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/class-wp-error-character.php"] [unique_id "al9LIbxMYwyVGnfuwsKHLwAABBc"]
[Tue Jul 21 07:34:10.116240 2026] [security2:error] [pid 255769:tid 255972] [client 122.186.204.214:63679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LIrxMYwyVGnfuwsKHMgAAA-w"]
[Tue Jul 21 07:34:10.116382 2026] [security2:error] [pid 255769:tid 255972] [client 122.186.204.214:63679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LIrxMYwyVGnfuwsKHMgAAA-w"]
[Tue Jul 21 07:34:10.427637 2026] [security2:error] [pid 255769:tid 256003] [client 20.197.195.24:13181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/file.php"] [unique_id "al9LIrxMYwyVGnfuwsKHNQAABAk"]
[Tue Jul 21 07:34:10.551490 2026] [security2:error] [pid 255769:tid 255946] [client 173.24.185.52:62662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LIrxMYwyVGnfuwsKHOQAAA9I"]
[Tue Jul 21 07:34:10.551623 2026] [security2:error] [pid 255769:tid 255946] [client 173.24.185.52:62662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LIrxMYwyVGnfuwsKHOQAAA9I"]
[Tue Jul 21 07:34:10.619222 2026] [security2:error] [pid 254995:tid 255038] [remote 20.197.195.24:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "hauptmann.com.br"] [uri "/1.php"] [unique_id "al9LIv7v0rlcEGmVraEsrQADZio"]
[Tue Jul 21 07:34:10.619324 2026] [security2:error] [pid 254995:tid 255038] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/1.php"] [unique_id "al9LIv7v0rlcEGmVraEsrQADZio"]
[Tue Jul 21 07:34:10.635252 2026] [security2:error] [pid 254995:tid 255019] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/ms.php"] [unique_id "al9LIv7v0rlcEGmVraEsrgADMhc"]
[Tue Jul 21 07:34:10.639385 2026] [security2:error] [pid 254995:tid 255159] [client 20.220.225.223:49577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/fz.php"] [unique_id "al9LIv7v0rlcEGmVraEssAAAA0A"]
[Tue Jul 21 07:34:10.728462 2026] [autoindex:error] [pid 254995:tid 255027] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:34:10.749897 2026] [security2:error] [pid 254995:tid 255044] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/memberfuns.php"] [unique_id "al9LIv7v0rlcEGmVraEsswADVjA"]
[Tue Jul 21 07:34:10.808019 2026] [security2:error] [pid 254995:tid 255040] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/0.php"] [unique_id "al9LIv7v0rlcEGmVraEstAADKSw"]
[Tue Jul 21 07:34:10.823778 2026] [security2:error] [pid 254995:tid 255032] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/BDKR28.php"] [unique_id "al9LIv7v0rlcEGmVraEstQADWSQ"]
[Tue Jul 21 07:34:10.867707 2026] [security2:error] [pid 254995:tid 255009] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/green1.php"] [unique_id "al9LIv7v0rlcEGmVraEstgADKA0"]
[Tue Jul 21 07:34:10.886302 2026] [security2:error] [pid 255769:tid 255875] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LIrxMYwyVGnfuwsKHPgAEFWk"]
[Tue Jul 21 07:34:10.886488 2026] [security2:error] [pid 255769:tid 256015] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LIrxMYwyVGnfuwsKHPgAEFWk"]
[Tue Jul 21 07:34:10.903273 2026] [security2:error] [pid 254995:tid 255024] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/nc4.php"] [unique_id "al9LIv7v0rlcEGmVraEsuAADjRw"]
[Tue Jul 21 07:34:10.918971 2026] [security2:error] [pid 254995:tid 255091] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/a1.php"] [unique_id "al9LIv7v0rlcEGmVraEsuQADiV8"]
[Tue Jul 21 07:34:10.946932 2026] [security2:error] [pid 255769:tid 255918] [client 20.206.105.145:39284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/2P.php"] [unique_id "al9LIrxMYwyVGnfuwsKHQQAAA7Y"]
[Tue Jul 21 07:34:10.954365 2026] [security2:error] [pid 254995:tid 255043] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/eee.php"] [unique_id "al9LIv7v0rlcEGmVraEsugADeS8"]
[Tue Jul 21 07:34:11.158153 2026] [security2:error] [pid 254995:tid 255179] [client 122.162.144.145:4495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LI_7v0rlcEGmVraEsvQAAA1Q"]
[Tue Jul 21 07:34:11.160749 2026] [security2:error] [pid 254995:tid 255179] [client 122.162.144.145:4495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LI_7v0rlcEGmVraEsvQAAA1Q"]
[Tue Jul 21 07:34:11.297476 2026] [autoindex:error] [pid 254995:tid 255142] [client 205.210.31.14:61988] AH01276: Cannot serve directory /home2/inlaud99/erp.choppcontrol.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:34:11.317754 2026] [security2:error] [pid 254995:tid 255178] [client 62.102.148.164:38362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9LI_7v0rlcEGmVraEswQAAA1M"]
[Tue Jul 21 07:34:11.317849 2026] [security2:error] [pid 254995:tid 255178] [client 62.102.148.164:38362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9LI_7v0rlcEGmVraEswQAAA1M"]
[Tue Jul 21 07:34:11.376711 2026] [security2:error] [pid 254995:tid 255258] [client 45.251.232.145:54954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LI_7v0rlcEGmVraEswwAAA4g"]
[Tue Jul 21 07:34:11.376825 2026] [security2:error] [pid 254995:tid 255258] [client 45.251.232.145:54954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LI_7v0rlcEGmVraEswwAAA4g"]
[Tue Jul 21 07:34:11.446312 2026] [security2:error] [pid 255769:tid 255857] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LI7xMYwyVGnfuwsKHRwAD6Fc"]
[Tue Jul 21 07:34:11.446446 2026] [security2:error] [pid 255769:tid 255968] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LI7xMYwyVGnfuwsKHRwAD6Fc"]
[Tue Jul 21 07:34:11.698880 2026] [security2:error] [pid 255769:tid 255902] [client 136.144.33.25:62685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LIrxMYwyVGnfuwsKHOAAAA6Y"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:11.925835 2026] [security2:error] [pid 254995:tid 255056] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-aothait.php"] [unique_id "al9LI_7v0rlcEGmVraEsyQADNjw"]
[Tue Jul 21 07:34:11.937458 2026] [security2:error] [pid 255769:tid 255967] [client 103.106.20.201:57053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LI7xMYwyVGnfuwsKHUAAAA-c"]
[Tue Jul 21 07:34:11.937645 2026] [security2:error] [pid 255769:tid 255967] [client 103.106.20.201:57053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LI7xMYwyVGnfuwsKHUAAAA-c"]
[Tue Jul 21 07:34:12.101670 2026] [security2:error] [pid 255769:tid 256017] [client 20.197.195.24:13073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/777.php"] [unique_id "al9LJLxMYwyVGnfuwsKHUgAABBc"]
[Tue Jul 21 07:34:12.184279 2026] [security2:error] [pid 254995:tid 255125] [client 45.8.17.136:60491] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-cron-element.php"] [unique_id "al9LJP7v0rlcEGmVraEszQAAAx4"]
[Tue Jul 21 07:34:12.713639 2026] [security2:error] [pid 255769:tid 255988] [client 154.192.233.199:59422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJLxMYwyVGnfuwsKHWQAAA_w"]
[Tue Jul 21 07:34:12.713859 2026] [security2:error] [pid 255769:tid 255988] [client 154.192.233.199:59422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJLxMYwyVGnfuwsKHWQAAA_w"]
[Tue Jul 21 07:34:12.730878 2026] [security2:error] [pid 255769:tid 255812] [remote 216.73.216.238:25891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/tarifas.php"] [unique_id "al9LJLxMYwyVGnfuwsKHWgAEGyo"]
[Tue Jul 21 07:34:12.766465 2026] [security2:error] [pid 255769:tid 255856] [remote 216.73.216.238:25891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/regulamento.php"] [unique_id "al9LJLxMYwyVGnfuwsKHWwAEAVY"]
[Tue Jul 21 07:34:12.826841 2026] [security2:error] [pid 255769:tid 256028] [client 152.59.154.239:49947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJLxMYwyVGnfuwsKHXgAABCI"]
[Tue Jul 21 07:34:12.826933 2026] [security2:error] [pid 255769:tid 256028] [client 152.59.154.239:49947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJLxMYwyVGnfuwsKHXgAABCI"]
[Tue Jul 21 07:34:12.839204 2026] [security2:error] [pid 255769:tid 255974] [client 117.217.38.194:59322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJLxMYwyVGnfuwsKHXwAAA-4"]
[Tue Jul 21 07:34:12.839327 2026] [security2:error] [pid 255769:tid 255974] [client 117.217.38.194:59322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJLxMYwyVGnfuwsKHXwAAA-4"]
[Tue Jul 21 07:34:12.927898 2026] [core:alert] [pid 255769:tid 255918] [client 57.141.18.45:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:34:13.012285 2026] [security2:error] [pid 255769:tid 255931] [client 62.102.148.164:38372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9LJbxMYwyVGnfuwsKHZQAAA8M"]
[Tue Jul 21 07:34:13.012371 2026] [security2:error] [pid 255769:tid 255931] [client 62.102.148.164:38372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9LJbxMYwyVGnfuwsKHZQAAA8M"]
[Tue Jul 21 07:34:13.041979 2026] [security2:error] [pid 254995:tid 255062] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/config.json.php"] [unique_id "al9LJf7v0rlcEGmVraEs2AADeEI"]
[Tue Jul 21 07:34:13.060978 2026] [security2:error] [pid 254995:tid 255033] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9LJf7v0rlcEGmVraEs2QADnSU"]
[Tue Jul 21 07:34:13.121185 2026] [security2:error] [pid 254995:tid 255077] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/k2.php"] [unique_id "al9LJf7v0rlcEGmVraEs2wADlVE"]
[Tue Jul 21 07:34:13.161201 2026] [security2:error] [pid 254995:tid 255086] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9LJf7v0rlcEGmVraEs3QADlFo"]
[Tue Jul 21 07:34:13.203404 2026] [security2:error] [pid 254995:tid 255118] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9LJf7v0rlcEGmVraEs3gADRXo"]
[Tue Jul 21 07:34:13.211791 2026] [security2:error] [pid 255769:tid 255957] [client 193.36.225.10:47415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LJbxMYwyVGnfuwsKHagAAA90"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:13.232579 2026] [security2:error] [pid 254995:tid 255123] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9LJf7v0rlcEGmVraEs4AADNX8"]
[Tue Jul 21 07:34:13.286563 2026] [security2:error] [pid 254995:tid 255275] [client 45.8.17.134:26487] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/sitemaps/chosen.php"] [unique_id "al9LJf7v0rlcEGmVraEs4wAAA5k"]
[Tue Jul 21 07:34:13.321075 2026] [security2:error] [pid 254995:tid 255081] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/for.php"] [unique_id "al9LJf7v0rlcEGmVraEs5QADVVU"]
[Tue Jul 21 07:34:13.351790 2026] [security2:error] [pid 254995:tid 255079] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/raw.php"] [unique_id "al9LJf7v0rlcEGmVraEs5wADTlM"]
[Tue Jul 21 07:34:13.386948 2026] [security2:error] [pid 254995:tid 255177] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LJf7v0rlcEGmVraEs5gADUls"]
[Tue Jul 21 07:34:13.592451 2026] [security2:error] [pid 255769:tid 256015] [client 175.45.70.82:57702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJbxMYwyVGnfuwsKHcAAABBU"]
[Tue Jul 21 07:34:13.592627 2026] [security2:error] [pid 255769:tid 256015] [client 175.45.70.82:57702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJbxMYwyVGnfuwsKHcAAABBU"]
[Tue Jul 21 07:34:13.792049 2026] [security2:error] [pid 255769:tid 255967] [client 20.197.195.24:48838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/ssixta.php"] [unique_id "al9LJbxMYwyVGnfuwsKHcwAAA-c"]
[Tue Jul 21 07:34:13.873954 2026] [security2:error] [pid 255769:tid 255919] [client 82.102.28.107:50368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9LJbxMYwyVGnfuwsKHdwAAA7c"]
[Tue Jul 21 07:34:13.874065 2026] [security2:error] [pid 255769:tid 255919] [client 82.102.28.107:50368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9LJbxMYwyVGnfuwsKHdwAAA7c"]
[Tue Jul 21 07:34:13.892297 2026] [security2:error] [pid 255769:tid 256027] [client 185.251.19.67:22895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiferreira.com.br"] [uri "/wp-login.php"] [unique_id "al9LJbxMYwyVGnfuwsKHeAAABCE"]
[Tue Jul 21 07:34:14.284851 2026] [security2:error] [pid 254995:tid 255145] [client 45.8.17.49:60097] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/antiperfo.php"] [unique_id "al9LJv7v0rlcEGmVraEs8QAAAzI"]
[Tue Jul 21 07:34:14.536408 2026] [security2:error] [pid 255769:tid 255939] [client 103.174.34.15:49885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJrxMYwyVGnfuwsKHfAAAA8s"]
[Tue Jul 21 07:34:14.536533 2026] [security2:error] [pid 255769:tid 255939] [client 103.174.34.15:49885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJrxMYwyVGnfuwsKHfAAAA8s"]
[Tue Jul 21 07:34:14.761052 2026] [security2:error] [pid 254995:tid 255217] [client 20.197.195.24:48768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/1c.php"] [unique_id "al9LJv7v0rlcEGmVraEs-QAAA3k"]
[Tue Jul 21 07:34:14.862488 2026] [security2:error] [pid 255769:tid 256022] [client 213.152.162.104:43138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LJrxMYwyVGnfuwsKHfgAABBw"]
[Tue Jul 21 07:34:14.862592 2026] [security2:error] [pid 255769:tid 256022] [client 213.152.162.104:43138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LJrxMYwyVGnfuwsKHfgAABBw"]
[Tue Jul 21 07:34:14.942488 2026] [security2:error] [pid 254995:tid 255183] [client 193.36.225.153:34183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LJf7v0rlcEGmVraEs7QAAA1g"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:15.290967 2026] [security2:error] [pid 255769:tid 255891] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LJ7xMYwyVGnfuwsKHhgAD13k"]
[Tue Jul 21 07:34:15.291099 2026] [security2:error] [pid 255769:tid 255951] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LJ7xMYwyVGnfuwsKHhgAD13k"]
[Tue Jul 21 07:34:15.496744 2026] [security2:error] [pid 254995:tid 255110] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJ_7v0rlcEGmVraEtBQADYnI"]
[Tue Jul 21 07:34:15.496870 2026] [security2:error] [pid 254995:tid 255193] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJ_7v0rlcEGmVraEtBQADYnI"]
[Tue Jul 21 07:34:15.682629 2026] [security2:error] [pid 254995:tid 255174] [client 45.8.17.122:30935] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/blog-stream/inc/upgrade-to-pro/section-pro.php"] [unique_id "al9LJ_7v0rlcEGmVraEtCAAAA08"]
[Tue Jul 21 07:34:15.823794 2026] [security2:error] [pid 254995:tid 255166] [client 20.220.225.223:61973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/wp-explorer.php"] [unique_id "al9LJ_7v0rlcEGmVraEtDgAAA0c"]
[Tue Jul 21 07:34:16.096410 2026] [security2:error] [pid 255769:tid 255785] [remote 216.73.216.238:25695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/casa.php"] [unique_id "al9LKLxMYwyVGnfuwsKHjwAEAg8"]
[Tue Jul 21 07:34:16.221799 2026] [security2:error] [pid 255769:tid 255776] [remote 216.73.216.238:25695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/galeria.php"] [unique_id "al9LKLxMYwyVGnfuwsKHkAAD-QY"]
[Tue Jul 21 07:34:16.336693 2026] [security2:error] [pid 255769:tid 255913] [client 20.197.195.24:13120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/test2.php"] [unique_id "al9LKLxMYwyVGnfuwsKHkgAAA7E"]
[Tue Jul 21 07:34:16.381586 2026] [security2:error] [pid 255769:tid 255876] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LKLxMYwyVGnfuwsKHkwAD92o"]
[Tue Jul 21 07:34:16.381763 2026] [security2:error] [pid 255769:tid 255983] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LKLxMYwyVGnfuwsKHkwAD92o"]
[Tue Jul 21 07:34:16.782050 2026] [security2:error] [pid 255769:tid 255888] [remote 160.187.68.132:36550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "companhiatop.com.br"] [uri "/wp-login.php"] [unique_id "al9LKLxMYwyVGnfuwsKHlQADtXY"]
[Tue Jul 21 07:34:16.800925 2026] [security2:error] [pid 255769:tid 255806] [remote 212.47.76.178:52028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.76.47.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "insp1.com.br"] [uri "/wp-login.php"] [unique_id "al9LKLxMYwyVGnfuwsKHlgAEESQ"]
[Tue Jul 21 07:34:16.986009 2026] [security2:error] [pid 254995:tid 255275] [client 45.8.17.115:30941] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/fusion-styles/user/index.php"] [unique_id "al9LKP7v0rlcEGmVraEtHQAAA5k"]
[Tue Jul 21 07:34:17.093214 2026] [security2:error] [pid 254995:tid 255272] [client 216.73.160.27:30785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/wp-login.php"] [unique_id "al9LKf7v0rlcEGmVraEtIAAAA5Y"]
[Tue Jul 21 07:34:17.366678 2026] [security2:error] [pid 254995:tid 255216] [client 59.96.220.140:50071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LKf7v0rlcEGmVraEtJAAAA3g"]
[Tue Jul 21 07:34:17.366807 2026] [security2:error] [pid 254995:tid 255216] [client 59.96.220.140:50071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LKf7v0rlcEGmVraEtJAAAA3g"]
[Tue Jul 21 07:34:17.373339 2026] [security2:error] [pid 254995:tid 255161] [client 193.36.225.71:20827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LKf7v0rlcEGmVraEtJgAAA0I"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:17.377125 2026] [security2:error] [pid 254995:tid 255122] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LKf7v0rlcEGmVraEtJwADWn4"]
[Tue Jul 21 07:34:17.377252 2026] [security2:error] [pid 254995:tid 255185] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LKf7v0rlcEGmVraEtJwADWn4"]
[Tue Jul 21 07:34:17.571449 2026] [security2:error] [pid 255769:tid 255919] [client 20.220.225.223:48155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/la.php"] [unique_id "al9LKbxMYwyVGnfuwsKHmQAAA7c"]
[Tue Jul 21 07:34:17.658402 2026] [security2:error] [pid 255769:tid 255872] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LKbxMYwyVGnfuwsKHmwAEA2Y"]
[Tue Jul 21 07:34:17.658550 2026] [security2:error] [pid 255769:tid 255997] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LKbxMYwyVGnfuwsKHmwAEA2Y"]
[Tue Jul 21 07:34:17.707184 2026] [security2:error] [pid 255769:tid 255831] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LKbxMYwyVGnfuwsKHnAADpj0"]
[Tue Jul 21 07:34:17.707339 2026] [security2:error] [pid 255769:tid 255902] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LKbxMYwyVGnfuwsKHnAADpj0"]
[Tue Jul 21 07:34:18.003724 2026] [security2:error] [pid 255769:tid 256023] [client 20.220.225.223:4222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/akismet.php"] [unique_id "al9LKrxMYwyVGnfuwsKHpAAABB0"]
[Tue Jul 21 07:34:18.190769 2026] [security2:error] [pid 254995:tid 255136] [client 45.8.17.145:32231] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentyfive/parts/upgrade/index.php"] [unique_id "al9LKv7v0rlcEGmVraEtNwAAAyk"]
[Tue Jul 21 07:34:18.192122 2026] [security2:error] [pid 254995:tid 255217] [client 20.197.195.24:13109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/buy.php"] [unique_id "al9LKv7v0rlcEGmVraEtOAAAA3k"]
[Tue Jul 21 07:34:18.493110 2026] [security2:error] [pid 255769:tid 255976] [client 139.167.225.182:51766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LKrxMYwyVGnfuwsKHrAAAA_A"]
[Tue Jul 21 07:34:18.493221 2026] [security2:error] [pid 255769:tid 255976] [client 139.167.225.182:51766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LKrxMYwyVGnfuwsKHrAAAA_A"]
[Tue Jul 21 07:34:19.103960 2026] [security2:error] [pid 255769:tid 255836] [remote 45.79.123.44:54968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9LK7xMYwyVGnfuwsKHrwADpEI"]
[Tue Jul 21 07:34:19.390717 2026] [security2:error] [pid 254995:tid 255187] [client 45.8.17.146:39211] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/network/theme-install-variable.php"] [unique_id "al9LK_7v0rlcEGmVraEtSwAAA1w"]
[Tue Jul 21 07:34:19.480514 2026] [security2:error] [pid 255769:tid 255994] [client 20.220.225.223:56489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/ace2.php"] [unique_id "al9LK7xMYwyVGnfuwsKHtQAABAE"]
[Tue Jul 21 07:34:19.549181 2026] [security2:error] [pid 255769:tid 256007] [client 20.29.57.244:49468] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "162.241.63.68"] [uri "/index.cgi"] [unique_id "al9LK7xMYwyVGnfuwsKHuAAABA0"]
[Tue Jul 21 07:34:19.614920 2026] [security2:error] [pid 254995:tid 255191] [client 20.197.195.24:13136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/ssend.php"] [unique_id "al9LK_7v0rlcEGmVraEtTgAAA2A"]
[Tue Jul 21 07:34:19.811053 2026] [security2:error] [pid 254995:tid 255219] [client 117.251.86.144:36206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LK_7v0rlcEGmVraEtUgAAA3s"]
[Tue Jul 21 07:34:19.811167 2026] [security2:error] [pid 254995:tid 255219] [client 117.251.86.144:36206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LK_7v0rlcEGmVraEtUgAAA3s"]
[Tue Jul 21 07:34:20.159329 2026] [security2:error] [pid 254995:tid 255168] [client 103.162.129.114:63825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LLP7v0rlcEGmVraEtWgAAA0k"]
[Tue Jul 21 07:34:20.159469 2026] [security2:error] [pid 254995:tid 255168] [client 103.162.129.114:63825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LLP7v0rlcEGmVraEtWgAAA0k"]
[Tue Jul 21 07:34:20.345413 2026] [security2:error] [pid 255769:tid 255999] [client 20.220.225.223:24249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/mac.php"] [unique_id "al9LLLxMYwyVGnfuwsKHxQAABAU"]
[Tue Jul 21 07:34:20.767327 2026] [security2:error] [pid 255769:tid 255909] [client 122.186.204.214:64177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LLLxMYwyVGnfuwsKHygAAA60"]
[Tue Jul 21 07:34:20.767457 2026] [security2:error] [pid 255769:tid 255909] [client 122.186.204.214:64177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LLLxMYwyVGnfuwsKHygAAA60"]
[Tue Jul 21 07:34:20.890771 2026] [security2:error] [pid 254995:tid 255127] [client 45.8.17.115:53501] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentynineteen/sass/site/index.php"] [unique_id "al9LLP7v0rlcEGmVraEtYgAAAyA"]
[Tue Jul 21 07:34:21.308445 2026] [security2:error] [pid 255769:tid 255918] [client 173.252.95.0:54614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LLbxMYwyVGnfuwsKHzwAAA7Y"]
[Tue Jul 21 07:34:21.363160 2026] [security2:error] [pid 255769:tid 256002] [client 173.24.185.52:63141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LLbxMYwyVGnfuwsKH0AAABAg"]
[Tue Jul 21 07:34:21.363299 2026] [security2:error] [pid 255769:tid 256002] [client 173.24.185.52:63141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LLbxMYwyVGnfuwsKH0AAABAg"]
[Tue Jul 21 07:34:21.472632 2026] [security2:error] [pid 255769:tid 255871] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LLbxMYwyVGnfuwsKH0wADwWU"]
[Tue Jul 21 07:34:21.472820 2026] [security2:error] [pid 255769:tid 255929] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LLbxMYwyVGnfuwsKH0wADwWU"]
[Tue Jul 21 07:34:21.501417 2026] [security2:error] [pid 254995:tid 255019] [remote 216.73.216.238:23998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/casa.php"] [unique_id "al9LLf7v0rlcEGmVraEtbAADbRc"]
[Tue Jul 21 07:34:21.501572 2026] [security2:error] [pid 254995:tid 255012] [remote 216.73.216.238:23998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/casa.php"] [unique_id "al9LLf7v0rlcEGmVraEtbQADbRA"]
[Tue Jul 21 07:34:21.511373 2026] [security2:error] [pid 255769:tid 255925] [client 20.220.225.223:49585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/edit.php"] [unique_id "al9LLbxMYwyVGnfuwsKH1AAAA70"]
[Tue Jul 21 07:34:21.772650 2026] [security2:error] [pid 255769:tid 255957] [client 20.220.225.223:24200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/samll.php"] [unique_id "al9LLbxMYwyVGnfuwsKH2QAAA90"]
[Tue Jul 21 07:34:21.788327 2026] [security2:error] [pid 254995:tid 255223] [client 20.220.225.223:38702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/ops.php"] [unique_id "al9LLf7v0rlcEGmVraEtcAAAA38"]
[Tue Jul 21 07:34:21.823935 2026] [security2:error] [pid 254995:tid 255224] [client 20.197.195.24:13058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/item.php"] [unique_id "al9LLf7v0rlcEGmVraEtcgAAA4A"]
[Tue Jul 21 07:34:21.851481 2026] [security2:error] [pid 255769:tid 255998] [client 45.251.232.145:55736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LLbxMYwyVGnfuwsKH3QAABAQ"]
[Tue Jul 21 07:34:21.851604 2026] [security2:error] [pid 255769:tid 255998] [client 45.251.232.145:55736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LLbxMYwyVGnfuwsKH3QAABAQ"]
[Tue Jul 21 07:34:21.954086 2026] [security2:error] [pid 255769:tid 255967] [client 20.52.136.55:1755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/fm.php"] [unique_id "al9LLbxMYwyVGnfuwsKH4gAAA-c"]
[Tue Jul 21 07:34:22.048173 2026] [security2:error] [pid 254995:tid 255277] [client 122.162.144.145:3089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LLv7v0rlcEGmVraEtdgAAA5s"]
[Tue Jul 21 07:34:22.048312 2026] [security2:error] [pid 254995:tid 255277] [client 122.162.144.145:3089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LLv7v0rlcEGmVraEtdgAAA5s"]
[Tue Jul 21 07:34:22.080062 2026] [security2:error] [pid 254995:tid 255184] [client 45.8.17.148:54035] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentyone/assets/sass/05-blocks/preformatted/index.php"] [unique_id "al9LLv7v0rlcEGmVraEteAAAA1k"]
[Tue Jul 21 07:34:22.092788 2026] [security2:error] [pid 255769:tid 255952] [client 172.245.102.33:58211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LLLxMYwyVGnfuwsKHyQAAA9g"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:22.177057 2026] [security2:error] [pid 254995:tid 255091] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LLv7v0rlcEGmVraEtegADMF8"]
[Tue Jul 21 07:34:22.177193 2026] [security2:error] [pid 254995:tid 255143] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LLv7v0rlcEGmVraEtegADMF8"]
[Tue Jul 21 07:34:22.313696 2026] [security2:error] [pid 255769:tid 256001] [client 193.36.225.66:55855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LLrxMYwyVGnfuwsKH6AAABAc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:22.486215 2026] [security2:error] [pid 255769:tid 256008] [client 20.220.225.223:49539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/nhvoanpl.php"] [unique_id "al9LLrxMYwyVGnfuwsKH7QAABA4"]
[Tue Jul 21 07:34:22.586698 2026] [security2:error] [pid 255769:tid 255909] [client 20.197.195.24:13071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/ss.php"] [unique_id "al9LLrxMYwyVGnfuwsKH8AAAA60"]
[Tue Jul 21 07:34:22.618594 2026] [security2:error] [pid 255769:tid 255975] [client 103.106.20.201:57632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LLrxMYwyVGnfuwsKH8QAAA-8"]
[Tue Jul 21 07:34:22.618738 2026] [security2:error] [pid 255769:tid 255975] [client 103.106.20.201:57632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LLrxMYwyVGnfuwsKH8QAAA-8"]
[Tue Jul 21 07:34:23.305664 2026] [security2:error] [pid 254995:tid 255154] [client 117.217.38.194:59769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LL_7v0rlcEGmVraEtjAAAAzs"]
[Tue Jul 21 07:34:23.305917 2026] [security2:error] [pid 254995:tid 255154] [client 117.217.38.194:59769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LL_7v0rlcEGmVraEtjAAAAzs"]
[Tue Jul 21 07:34:23.393387 2026] [security2:error] [pid 255769:tid 255994] [client 45.8.17.121:27577] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/elex/elex.php"] [unique_id "al9LL7xMYwyVGnfuwsKH_gAABAE"]
[Tue Jul 21 07:34:23.500028 2026] [security2:error] [pid 254995:tid 255153] [client 20.220.225.223:48152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/inso.php"] [unique_id "al9LL_7v0rlcEGmVraEtkAAAAzo"]
[Tue Jul 21 07:34:23.523678 2026] [security2:error] [pid 255769:tid 255973] [client 154.192.233.199:59891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LL7xMYwyVGnfuwsKIAQAAA-0"]
[Tue Jul 21 07:34:23.523850 2026] [security2:error] [pid 255769:tid 255973] [client 154.192.233.199:59891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LL7xMYwyVGnfuwsKIAQAAA-0"]
[Tue Jul 21 07:34:23.802139 2026] [security2:error] [pid 255769:tid 255957] [client 20.220.225.223:6131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/wp-editor.php"] [unique_id "al9LL7xMYwyVGnfuwsKIBAAAA90"]
[Tue Jul 21 07:34:23.888278 2026] [security2:error] [pid 254995:tid 255025] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LL_7v0rlcEGmVraEtlgADKx0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:23.892213 2026] [security2:error] [pid 254995:tid 255064] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LL_7v0rlcEGmVraEtmAADj0Q"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:23.945258 2026] [security2:error] [pid 255769:tid 255804] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LL7xMYwyVGnfuwsKIAwADsCI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:23.963143 2026] [security2:error] [pid 255769:tid 255904] [client 20.197.195.24:13097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/hypo.php"] [unique_id "al9LL7xMYwyVGnfuwsKIBgAAA6g"]
[Tue Jul 21 07:34:24.046434 2026] [security2:error] [pid 255769:tid 255846] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LL7xMYwyVGnfuwsKIAgAD3Ew"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:24.240838 2026] [security2:error] [pid 255769:tid 255913] [client 175.45.70.82:58235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LMLxMYwyVGnfuwsKICAAAA7E"]
[Tue Jul 21 07:34:24.240955 2026] [security2:error] [pid 255769:tid 255913] [client 175.45.70.82:58235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LMLxMYwyVGnfuwsKICAAAA7E"]
[Tue Jul 21 07:34:24.305956 2026] [security2:error] [pid 254995:tid 255077] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LMP7v0rlcEGmVraEtowADX1E"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:24.340332 2026] [security2:error] [pid 255769:tid 256009] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LMLxMYwyVGnfuwsKICgAEDyU"]
[Tue Jul 21 07:34:24.389117 2026] [security2:error] [pid 255769:tid 255967] [client 45.8.17.62:45947] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/oceanwp/sass/base/1.php"] [unique_id "al9LMLxMYwyVGnfuwsKIDAAAA-c"]
[Tue Jul 21 07:34:24.399313 2026] [security2:error] [pid 254995:tid 255086] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LMP7v0rlcEGmVraEtpgADhVo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:24.514175 2026] [security2:error] [pid 254995:tid 255223] [client 213.152.162.104:47970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9LMP7v0rlcEGmVraEtqQAAA38"]
[Tue Jul 21 07:34:24.514286 2026] [security2:error] [pid 254995:tid 255223] [client 213.152.162.104:47970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9LMP7v0rlcEGmVraEtqQAAA38"]
[Tue Jul 21 07:34:24.812940 2026] [security2:error] [pid 254995:tid 255081] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LMP7v0rlcEGmVraEtrwADiVU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:24.834778 2026] [security2:error] [pid 255769:tid 255961] [client 152.59.154.239:50430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LMLxMYwyVGnfuwsKIEAAAA-E"]
[Tue Jul 21 07:34:24.834877 2026] [security2:error] [pid 255769:tid 255961] [client 152.59.154.239:50430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LMLxMYwyVGnfuwsKIEAAAA-E"]
[Tue Jul 21 07:34:24.887358 2026] [security2:error] [pid 255769:tid 255963] [client 20.220.225.223:24263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/abcd.php"] [unique_id "al9LMLxMYwyVGnfuwsKIEQAAA-M"]
[Tue Jul 21 07:34:24.955448 2026] [security2:error] [pid 254995:tid 255079] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LMP7v0rlcEGmVraEtsQADKlM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:25.001598 2026] [security2:error] [pid 254995:tid 255262] [client 20.197.195.24:13165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/users.php"] [unique_id "al9LMf7v0rlcEGmVraEtswAAA4w"]
[Tue Jul 21 07:34:25.073335 2026] [security2:error] [pid 254995:tid 255053] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LMf7v0rlcEGmVraEttQADWTk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:25.175653 2026] [security2:error] [pid 255769:tid 255907] [client 20.220.225.223:49552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wpx.php"] [unique_id "al9LMbxMYwyVGnfuwsKIHAAAA6s"]
[Tue Jul 21 07:34:25.213973 2026] [security2:error] [pid 254995:tid 255082] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LMf7v0rlcEGmVraEtuAADbFY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:25.316251 2026] [security2:error] [pid 255769:tid 255819] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LMbxMYwyVGnfuwsKIHQAEDjE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:25.323726 2026] [security2:error] [pid 255769:tid 255945] [client 103.174.34.15:50367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LMbxMYwyVGnfuwsKIHgAAA9E"]
[Tue Jul 21 07:34:25.323839 2026] [security2:error] [pid 255769:tid 255945] [client 103.174.34.15:50367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LMbxMYwyVGnfuwsKIHgAAA9E"]
[Tue Jul 21 07:34:25.363623 2026] [security2:error] [pid 255769:tid 255830] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LMbxMYwyVGnfuwsKIHwADpDw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:25.385917 2026] [security2:error] [pid 254995:tid 255201] [client 45.8.17.114:62789] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentyone/emerance.php"] [unique_id "al9LMf7v0rlcEGmVraEtvAAAA2o"]
[Tue Jul 21 07:34:25.408123 2026] [security2:error] [pid 254995:tid 254998] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LMf7v0rlcEGmVraEtvQADawI"]
[Tue Jul 21 07:34:25.408239 2026] [security2:error] [pid 254995:tid 255202] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LMf7v0rlcEGmVraEtvQADawI"]
[Tue Jul 21 07:34:25.617158 2026] [security2:error] [pid 254995:tid 255106] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LMf7v0rlcEGmVraEtwwADb24"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:26.024496 2026] [security2:error] [pid 255769:tid 255883] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LMrxMYwyVGnfuwsKIJgAEEXE"]
[Tue Jul 21 07:34:26.024645 2026] [security2:error] [pid 255769:tid 256011] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LMrxMYwyVGnfuwsKIJgAEEXE"]
[Tue Jul 21 07:34:26.140324 2026] [security2:error] [pid 254995:tid 255143] [client 193.36.225.63:41051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LMv7v0rlcEGmVraEtyQAAAzA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:26.252422 2026] [security2:error] [pid 254995:tid 255002] [remote 195.26.253.119:44838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.253.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "essenceclinicadesaude.com.br"] [uri "/wp-login.php"] [unique_id "al9LMf7v0rlcEGmVraEtugADUwY"]
[Tue Jul 21 07:34:26.812108 2026] [security2:error] [pid 254995:tid 255129] [client 37.140.223.134:20881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LMv7v0rlcEGmVraEt0AAAAyI"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:26.847843 2026] [security2:error] [pid 254995:tid 255089] [remote 45.79.123.44:38476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9LMv7v0rlcEGmVraEt1QADfl0"]
[Tue Jul 21 07:34:26.847967 2026] [security2:error] [pid 254995:tid 255222] [client 45.79.123.44:38476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9LMv7v0rlcEGmVraEt1QADfl0"]
[Tue Jul 21 07:34:26.849400 2026] [security2:error] [pid 255769:tid 255996] [client 20.197.195.24:13094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/177.php"] [unique_id "al9LMrxMYwyVGnfuwsKIKwAABAI"]
[Tue Jul 21 07:34:27.238929 2026] [security2:error] [pid 255769:tid 255855] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LM7xMYwyVGnfuwsKILwAEA1U"]
[Tue Jul 21 07:34:27.239129 2026] [security2:error] [pid 255769:tid 255997] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LM7xMYwyVGnfuwsKILwAEA1U"]
[Tue Jul 21 07:34:27.691887 2026] [security2:error] [pid 254995:tid 255190] [client 45.8.17.65:20671] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentynineteen/content-index.php"] [unique_id "al9LM_7v0rlcEGmVraEt3wAAA18"]
[Tue Jul 21 07:34:28.186200 2026] [security2:error] [pid 254995:tid 255093] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LNP7v0rlcEGmVraEt6gADVmE"]
[Tue Jul 21 07:34:28.186401 2026] [security2:error] [pid 254995:tid 255181] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LNP7v0rlcEGmVraEt6gADVmE"]
[Tue Jul 21 07:34:28.234230 2026] [security2:error] [pid 255769:tid 255837] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LNLxMYwyVGnfuwsKIMAAD0EM"]
[Tue Jul 21 07:34:28.234361 2026] [security2:error] [pid 255769:tid 255944] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LNLxMYwyVGnfuwsKIMAAD0EM"]
[Tue Jul 21 07:34:28.319359 2026] [security2:error] [pid 255769:tid 255968] [client 20.197.195.24:13157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/config.php"] [unique_id "al9LNLxMYwyVGnfuwsKIMQAAA-g"]
[Tue Jul 21 07:34:28.365135 2026] [rewrite:error] [pid 254995:tid 255146] [client 187.49.76.218:18177] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:34:28.367182 2026] [rewrite:error] [pid 255769:tid 255905] [client 187.49.76.218:18241] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:34:28.386681 2026] [rewrite:error] [pid 254995:tid 255221] [client 187.49.76.218:18273] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:34:28.505316 2026] [security2:error] [pid 254995:tid 255215] [client 122.129.67.13:59877] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9LNP7v0rlcEGmVraEt8QAAA3c"]
[Tue Jul 21 07:34:28.505445 2026] [security2:error] [pid 254995:tid 255215] [client 122.129.67.13:59877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9LNP7v0rlcEGmVraEt8QAAA3c"]
[Tue Jul 21 07:34:28.719344 2026] [autoindex:error] [pid 254995:tid 255144] [client 66.132.172.218:4136] AH01276: Cannot serve directory /home4/dralul00/deiacakes.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:34:28.845856 2026] [security2:error] [pid 254995:tid 255031] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LM_7v0rlcEGmVraEt5QADlyM"]
[Tue Jul 21 07:34:28.846121 2026] [security2:error] [pid 254995:tid 255273] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LM_7v0rlcEGmVraEt5QADlyM"]
[Tue Jul 21 07:34:29.032628 2026] [security2:error] [pid 254995:tid 255193] [client 20.197.195.24:13114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/gettest.php"] [unique_id "al9LNf7v0rlcEGmVraEt-gAAA2I"]
[Tue Jul 21 07:34:29.111700 2026] [security2:error] [pid 254995:tid 255137] [client 139.167.225.182:52395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LNf7v0rlcEGmVraEt-wAAAyo"]
[Tue Jul 21 07:34:29.111798 2026] [security2:error] [pid 254995:tid 255137] [client 139.167.225.182:52395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LNf7v0rlcEGmVraEt-wAAAyo"]
[Tue Jul 21 07:34:29.356544 2026] [security2:error] [pid 255769:tid 255853] [remote 65.111.0.247:58643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.0.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9LNbxMYwyVGnfuwsKIPgADuVM"]
[Tue Jul 21 07:34:29.743010 2026] [security2:error] [pid 254995:tid 255222] [client 20.197.195.24:13141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/min.php"] [unique_id "al9LNf7v0rlcEGmVraEuCwAAA34"]
[Tue Jul 21 07:34:29.774904 2026] [security2:error] [pid 254995:tid 255168] [client 20.220.225.223:49798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/kua.php"] [unique_id "al9LNf7v0rlcEGmVraEuDQAAA0k"]
[Tue Jul 21 07:34:29.837943 2026] [security2:error] [pid 254995:tid 255254] [client 20.52.136.55:1497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/ini.php"] [unique_id "al9LNf7v0rlcEGmVraEuEAAAA4Q"]
[Tue Jul 21 07:34:30.087019 2026] [autoindex:error] [pid 255769:tid 255828] [remote 2a03:2880:10ff:7:::0] AH01276: Cannot serve directory /home1/bastar15/lacorsini.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:34:30.248412 2026] [security2:error] [pid 255769:tid 256008] [client 193.36.225.140:38345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LNrxMYwyVGnfuwsKIPwAABA4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:30.464068 2026] [security2:error] [pid 254995:tid 255278] [client 117.251.86.144:58636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LNv7v0rlcEGmVraEuGwAAA5w"]
[Tue Jul 21 07:34:30.464201 2026] [security2:error] [pid 254995:tid 255278] [client 117.251.86.144:58636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LNv7v0rlcEGmVraEuGwAAA5w"]
[Tue Jul 21 07:34:30.563464 2026] [security2:error] [pid 254995:tid 255272] [client 20.220.225.223:56504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/ms.php"] [unique_id "al9LNv7v0rlcEGmVraEuHwAAA5Y"]
[Tue Jul 21 07:34:30.703205 2026] [security2:error] [pid 255769:tid 255919] [client 20.220.225.223:31179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/term.php"] [unique_id "al9LNrxMYwyVGnfuwsKIQwAAA7c"]
[Tue Jul 21 07:34:30.791912 2026] [security2:error] [pid 254995:tid 255256] [client 103.162.129.114:64274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LNv7v0rlcEGmVraEuIAAAA4Y"]
[Tue Jul 21 07:34:30.792019 2026] [security2:error] [pid 254995:tid 255256] [client 103.162.129.114:64274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LNv7v0rlcEGmVraEuIAAAA4Y"]
[Tue Jul 21 07:34:30.889007 2026] [security2:error] [pid 254995:tid 255208] [client 45.8.17.125:46583] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/responsive-lightbox/assets/nivo/themes/wp-load.php"] [unique_id "al9LNv7v0rlcEGmVraEuIwAAA3A"]
[Tue Jul 21 07:34:30.895419 2026] [security2:error] [pid 255769:tid 255998] [client 20.197.195.24:48836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/dvjul.php"] [unique_id "al9LNrxMYwyVGnfuwsKIRQAABAQ"]
[Tue Jul 21 07:34:31.074524 2026] [rewrite:error] [pid 254995:tid 255194] [client 187.49.76.218:18273] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2410
[Tue Jul 21 07:34:31.074629 2026] [rewrite:error] [pid 255769:tid 255986] [client 187.49.76.218:18241] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2410
[Tue Jul 21 07:34:31.075020 2026] [rewrite:error] [pid 254995:tid 255156] [client 187.49.76.218:18177] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2410
[Tue Jul 21 07:34:31.209493 2026] [security2:error] [pid 254995:tid 255260] [client 172.245.102.44:51955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LN_7v0rlcEGmVraEuKQAAA4o"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:31.396513 2026] [security2:error] [pid 254995:tid 255184] [client 122.186.204.214:64684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LN_7v0rlcEGmVraEuMAAAA1k"]
[Tue Jul 21 07:34:31.396633 2026] [security2:error] [pid 254995:tid 255184] [client 122.186.204.214:64684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LN_7v0rlcEGmVraEuMAAAA1k"]
[Tue Jul 21 07:34:32.049345 2026] [security2:error] [pid 255769:tid 256017] [client 20.220.225.223:25431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/xyn.php"] [unique_id "al9LOLxMYwyVGnfuwsKITwAABBc"]
[Tue Jul 21 07:34:32.117668 2026] [security2:error] [pid 254995:tid 255205] [client 173.24.185.52:63655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LOP7v0rlcEGmVraEuQgAAA24"]
[Tue Jul 21 07:34:32.117779 2026] [security2:error] [pid 254995:tid 255205] [client 173.24.185.52:63655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LOP7v0rlcEGmVraEuQgAAA24"]
[Tue Jul 21 07:34:32.127642 2026] [security2:error] [pid 255769:tid 255777] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LOLxMYwyVGnfuwsKIUQADvQc"]
[Tue Jul 21 07:34:32.127759 2026] [security2:error] [pid 255769:tid 255925] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LOLxMYwyVGnfuwsKIUQADvQc"]
[Tue Jul 21 07:34:32.219624 2026] [security2:error] [pid 254995:tid 255155] [client 59.96.220.140:50564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LOP7v0rlcEGmVraEuRAAAAzw"]
[Tue Jul 21 07:34:32.219755 2026] [security2:error] [pid 254995:tid 255155] [client 59.96.220.140:50564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LOP7v0rlcEGmVraEuRAAAAzw"]
[Tue Jul 21 07:34:32.281030 2026] [security2:error] [pid 254995:tid 254999] [remote 195.26.244.42:58580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "issimastore.com"] [uri "/wp-login.php"] [unique_id "al9LOP7v0rlcEGmVraEuRgADiAM"]
[Tue Jul 21 07:34:32.357588 2026] [security2:error] [pid 254995:tid 255154] [client 45.251.232.145:56356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LOP7v0rlcEGmVraEuSAAAAzs"]
[Tue Jul 21 07:34:32.357668 2026] [security2:error] [pid 254995:tid 255154] [client 45.251.232.145:56356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LOP7v0rlcEGmVraEuSAAAAzs"]
[Tue Jul 21 07:34:32.542188 2026] [security2:error] [pid 255769:tid 255961] [client 172.245.102.34:52363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LOLxMYwyVGnfuwsKIVQAAA-E"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:32.679242 2026] [security2:error] [pid 255769:tid 255993] [client 45.8.17.107:64621] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/responsive-lightbox/assets/jstree/themes/system.php"] [unique_id "al9LOLxMYwyVGnfuwsKIXAAABAA"]
[Tue Jul 21 07:34:32.685822 2026] [security2:error] [pid 255769:tid 255927] [client 20.220.225.223:49587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/berlin.php"] [unique_id "al9LOLxMYwyVGnfuwsKIXQAAA78"]
[Tue Jul 21 07:34:32.693765 2026] [security2:error] [pid 255769:tid 255946] [client 20.220.225.223:48156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/ez.php"] [unique_id "al9LOLxMYwyVGnfuwsKIXgAAA9I"]
[Tue Jul 21 07:34:32.741595 2026] [security2:error] [pid 255769:tid 255893] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LOLxMYwyVGnfuwsKIXwADp3s"]
[Tue Jul 21 07:34:32.741750 2026] [security2:error] [pid 255769:tid 255903] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LOLxMYwyVGnfuwsKIXwADp3s"]
[Tue Jul 21 07:34:32.753076 2026] [security2:error] [pid 254995:tid 255129] [client 122.162.144.145:10387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LOP7v0rlcEGmVraEuTwAAAyI"]
[Tue Jul 21 07:34:32.753191 2026] [security2:error] [pid 254995:tid 255129] [client 122.162.144.145:10387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LOP7v0rlcEGmVraEuTwAAAyI"]
[Tue Jul 21 07:34:33.043792 2026] [security2:error] [pid 255769:tid 255815] [remote 124.55.178.99:41810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9LObxMYwyVGnfuwsKIYgAD7C0"]
[Tue Jul 21 07:34:33.339232 2026] [security2:error] [pid 255769:tid 256022] [client 103.106.20.201:58211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LObxMYwyVGnfuwsKIagAABBw"]
[Tue Jul 21 07:34:33.339358 2026] [security2:error] [pid 255769:tid 256022] [client 103.106.20.201:58211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LObxMYwyVGnfuwsKIagAABBw"]
[Tue Jul 21 07:34:33.565908 2026] [security2:error] [pid 255769:tid 255973] [client 20.197.195.24:13150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/biufile.php"] [unique_id "al9LObxMYwyVGnfuwsKIbQAAA-0"]
[Tue Jul 21 07:34:33.590552 2026] [security2:error] [pid 255769:tid 255969] [client 45.8.17.130:59973] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/contact-form-7/includes/js/jquery-ui/themes/data.php"] [unique_id "al9LObxMYwyVGnfuwsKIbgAAA-k"]
[Tue Jul 21 07:34:33.795699 2026] [security2:error] [pid 254995:tid 255224] [client 117.217.38.194:60215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LOf7v0rlcEGmVraEuYQAAA4A"]
[Tue Jul 21 07:34:33.795841 2026] [security2:error] [pid 254995:tid 255224] [client 117.217.38.194:60215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LOf7v0rlcEGmVraEuYQAAA4A"]
[Tue Jul 21 07:34:34.107785 2026] [security2:error] [pid 255769:tid 255974] [client 20.220.225.223:23454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/cro.php"] [unique_id "al9LOrxMYwyVGnfuwsKIdAAAA-4"]
[Tue Jul 21 07:34:34.142127 2026] [security2:error] [pid 255769:tid 255994] [client 154.192.233.199:60372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LOrxMYwyVGnfuwsKIdQAABAE"]
[Tue Jul 21 07:34:34.142269 2026] [security2:error] [pid 255769:tid 255994] [client 154.192.233.199:60372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LOrxMYwyVGnfuwsKIdQAABAE"]
[Tue Jul 21 07:34:34.396727 2026] [security2:error] [pid 255769:tid 255771] [remote 45.3.41.95:50043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.41.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9LObxMYwyVGnfuwsKIawADuQE"]
[Tue Jul 21 07:34:34.693867 2026] [security2:error] [pid 255769:tid 256017] [client 45.8.17.118:36155] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/windazo/inc/plugins/wp-blog-header.php"] [unique_id "al9LOrxMYwyVGnfuwsKIegAABBc"]
[Tue Jul 21 07:34:34.696664 2026] [security2:error] [pid 255769:tid 255936] [client 20.220.225.223:59167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/cron-tab.php"] [unique_id "al9LOrxMYwyVGnfuwsKIewAAA8g"]
[Tue Jul 21 07:34:34.900381 2026] [security2:error] [pid 255769:tid 255998] [client 193.36.225.55:48623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LOrxMYwyVGnfuwsKIfgAABAQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:34.966808 2026] [security2:error] [pid 254995:tid 255137] [client 175.45.70.82:58750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LOv7v0rlcEGmVraEudQAAAyo"]
[Tue Jul 21 07:34:34.966949 2026] [security2:error] [pid 254995:tid 255137] [client 175.45.70.82:58750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LOv7v0rlcEGmVraEudQAAAyo"]
[Tue Jul 21 07:34:35.249748 2026] [security2:error] [pid 254995:tid 255134] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LO_7v0rlcEGmVraEuewADJzg"]
[Tue Jul 21 07:34:35.450228 2026] [security2:error] [pid 254995:tid 255211] [client 213.14.231.164:3316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.231.14.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "health-24.shop"] [uri "/xmlrpc.php"] [unique_id "al9LO_7v0rlcEGmVraEufQAAA3M"]
[Tue Jul 21 07:34:35.450373 2026] [security2:error] [pid 254995:tid 255211] [client 213.14.231.164:3316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "health-24.shop"] [uri "/xmlrpc.php"] [unique_id "al9LO_7v0rlcEGmVraEufQAAA3M"]
[Tue Jul 21 07:34:35.602825 2026] [security2:error] [pid 254995:tid 255087] [remote 97.74.87.194:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9LO_7v0rlcEGmVraEugQADg1s"]
[Tue Jul 21 07:34:35.705352 2026] [security2:error] [pid 255769:tid 256021] [client 20.220.225.223:23425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/koiy.php"] [unique_id "al9LO7xMYwyVGnfuwsKIhgAABBs"]
[Tue Jul 21 07:34:35.786655 2026] [security2:error] [pid 254995:tid 255277] [client 45.8.17.63:63927] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/js_composer/include/classes/vendors/plugins/api.php"] [unique_id "al9LO_7v0rlcEGmVraEujgAAA5s"]
[Tue Jul 21 07:34:35.958583 2026] [security2:error] [pid 255769:tid 256012] [client 213.152.162.104:32866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9LO7xMYwyVGnfuwsKIiQAABBI"]
[Tue Jul 21 07:34:35.958696 2026] [security2:error] [pid 255769:tid 256012] [client 213.152.162.104:32866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9LO7xMYwyVGnfuwsKIiQAABBI"]
[Tue Jul 21 07:34:35.991438 2026] [security2:error] [pid 254995:tid 255067] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LO_7v0rlcEGmVraEukQADVEc"]
[Tue Jul 21 07:34:35.991574 2026] [security2:error] [pid 254995:tid 255179] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LO_7v0rlcEGmVraEukQADVEc"]
[Tue Jul 21 07:34:36.021426 2026] [security2:error] [pid 255769:tid 255922] [client 103.174.34.15:50853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LPLxMYwyVGnfuwsKIiwAAA7o"]
[Tue Jul 21 07:34:36.021536 2026] [security2:error] [pid 255769:tid 255922] [client 103.174.34.15:50853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LPLxMYwyVGnfuwsKIiwAAA7o"]
[Tue Jul 21 07:34:36.148101 2026] [security2:error] [pid 254995:tid 255117] [remote 49.12.216.176:35468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.216.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "woma.com.br"] [uri "/wp-login.php"] [unique_id "al9LPP7v0rlcEGmVraEulwADZnk"]
[Tue Jul 21 07:34:36.561925 2026] [security2:error] [pid 254995:tid 255129] [client 152.59.154.239:50901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LPP7v0rlcEGmVraEuoQAAAyI"]
[Tue Jul 21 07:34:36.566622 2026] [security2:error] [pid 254995:tid 255129] [client 152.59.154.239:50901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LPP7v0rlcEGmVraEuoQAAAyI"]
[Tue Jul 21 07:34:36.582520 2026] [security2:error] [pid 255769:tid 255889] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LPLxMYwyVGnfuwsKIlgAEHHc"]
[Tue Jul 21 07:34:36.582745 2026] [security2:error] [pid 255769:tid 256022] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LPLxMYwyVGnfuwsKIlgAEHHc"]
[Tue Jul 21 07:34:36.700116 2026] [security2:error] [pid 255769:tid 255989] [client 20.197.195.24:13127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/av.php"] [unique_id "al9LPLxMYwyVGnfuwsKInAAAA_0"]
[Tue Jul 21 07:34:36.949975 2026] [security2:error] [pid 254995:tid 255268] [client 20.220.225.223:38718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/ah25.php"] [unique_id "al9LPP7v0rlcEGmVraEuqQAAA5I"]
[Tue Jul 21 07:34:37.045800 2026] [security2:error] [pid 254995:tid 255137] [client 85.208.96.204:13620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.transitoaberto.com.br"] [uri "/robots.txt"] [unique_id "al9LPf7v0rlcEGmVraEuqwAAAyo"]
[Tue Jul 21 07:34:37.045971 2026] [security2:error] [pid 254995:tid 255137] [client 85.208.96.204:13620] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.transitoaberto.com.br"] [uri "/robots.txt"] [unique_id "al9LPf7v0rlcEGmVraEuqwAAAyo"]
[Tue Jul 21 07:34:37.094658 2026] [security2:error] [pid 254995:tid 255274] [client 45.8.17.130:32061] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/stockholm/woocommerce/single-product/add-to-cart/internal.php"] [unique_id "al9LPf7v0rlcEGmVraEurAAAA5g"]
[Tue Jul 21 07:34:37.402708 2026] [security2:error] [pid 255769:tid 255947] [client 85.208.96.201:39294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9LPbxMYwyVGnfuwsKIogAAA9M"]
[Tue Jul 21 07:34:37.402872 2026] [security2:error] [pid 255769:tid 255947] [client 85.208.96.201:39294] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9LPbxMYwyVGnfuwsKIogAAA9M"]
[Tue Jul 21 07:34:37.740091 2026] [security2:error] [pid 255769:tid 255918] [client 74.7.244.14:37926] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "evolutionlisbon.kettlebellevolution.com.br"] [uri "/index.php"] [unique_id "al9LPbxMYwyVGnfuwsKIngADtgQ"]
[Tue Jul 21 07:34:37.893888 2026] [security2:error] [pid 255769:tid 255908] [client 20.52.136.55:1762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/themes.php"] [unique_id "al9LPbxMYwyVGnfuwsKIqAAAA6w"]
[Tue Jul 21 07:34:37.927735 2026] [security2:error] [pid 255769:tid 255800] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LPbxMYwyVGnfuwsKIqQAD5B4"]
[Tue Jul 21 07:34:37.927931 2026] [security2:error] [pid 255769:tid 255964] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LPbxMYwyVGnfuwsKIqQAD5B4"]
[Tue Jul 21 07:34:38.187641 2026] [security2:error] [pid 255769:tid 255950] [client 45.8.17.73:41767] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/post-template/index.php"] [unique_id "al9LPrxMYwyVGnfuwsKIqwAAA9Y"]
[Tue Jul 21 07:34:38.315824 2026] [security2:error] [pid 255769:tid 255784] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LPrxMYwyVGnfuwsKIsAADyw4"]
[Tue Jul 21 07:34:38.315948 2026] [security2:error] [pid 255769:tid 255939] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LPrxMYwyVGnfuwsKIsAADyw4"]
[Tue Jul 21 07:34:38.601569 2026] [security2:error] [pid 255769:tid 255906] [client 59.96.220.140:51072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LPrxMYwyVGnfuwsKIugAAA6o"]
[Tue Jul 21 07:34:38.602337 2026] [security2:error] [pid 255769:tid 255906] [client 59.96.220.140:51072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LPrxMYwyVGnfuwsKIugAAA6o"]
[Tue Jul 21 07:34:38.744628 2026] [security2:error] [pid 255769:tid 255877] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LPrxMYwyVGnfuwsKIwgADyms"]
[Tue Jul 21 07:34:38.744763 2026] [security2:error] [pid 255769:tid 255938] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LPrxMYwyVGnfuwsKIwgADyms"]
[Tue Jul 21 07:34:38.756343 2026] [security2:error] [pid 255769:tid 255775] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LPrxMYwyVGnfuwsKIxAADtAU"]
[Tue Jul 21 07:34:38.756485 2026] [security2:error] [pid 255769:tid 255916] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LPrxMYwyVGnfuwsKIxAADtAU"]
[Tue Jul 21 07:34:38.929935 2026] [security2:error] [pid 254995:tid 255099] [remote 130.185.118.215:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/wp-login.php"] [unique_id "al9LPv7v0rlcEGmVraEu0wADPmc"]
[Tue Jul 21 07:34:39.210137 2026] [security2:error] [pid 255769:tid 255929] [client 20.220.225.223:49561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/fz.php"] [unique_id "al9LP7xMYwyVGnfuwsKI0QAAA8E"]
[Tue Jul 21 07:34:39.486476 2026] [security2:error] [pid 255769:tid 256010] [client 139.167.225.182:53030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LP7xMYwyVGnfuwsKI2wAABBA"]
[Tue Jul 21 07:34:39.486590 2026] [security2:error] [pid 255769:tid 256010] [client 139.167.225.182:53030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LP7xMYwyVGnfuwsKI2wAABBA"]
[Tue Jul 21 07:34:39.654665 2026] [security2:error] [pid 255769:tid 255905] [client 20.206.105.145:39123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9LP7xMYwyVGnfuwsKI4QAAA6k"]
[Tue Jul 21 07:34:39.690460 2026] [security2:error] [pid 255769:tid 255962] [client 45.8.17.141:62879] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/images/index.php"] [unique_id "al9LP7xMYwyVGnfuwsKI5AAAA-I"]
[Tue Jul 21 07:34:39.861291 2026] [security2:error] [pid 255769:tid 255902] [client 136.144.33.99:48087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LP7xMYwyVGnfuwsKI4wAAA6Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:39.877476 2026] [security2:error] [pid 255769:tid 255930] [client 20.220.225.223:23429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/hp2.php"] [unique_id "al9LP7xMYwyVGnfuwsKI6QAAA8I"]
[Tue Jul 21 07:34:40.163734 2026] [security2:error] [pid 254995:tid 255162] [client 20.197.195.24:13132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/coffexium.php"] [unique_id "al9LQP7v0rlcEGmVraEu3wAAA0M"]
[Tue Jul 21 07:34:40.893160 2026] [security2:error] [pid 255769:tid 255900] [client 45.8.17.134:28335] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/css/dist/block-directory/index.php"] [unique_id "al9LQLxMYwyVGnfuwsKI9wAAA6Q"]
[Tue Jul 21 07:34:41.276439 2026] [security2:error] [pid 254995:tid 255209] [client 103.162.129.114:64712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LQf7v0rlcEGmVraEu7wAAA3E"]
[Tue Jul 21 07:34:41.276545 2026] [security2:error] [pid 254995:tid 255209] [client 103.162.129.114:64712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LQf7v0rlcEGmVraEu7wAAA3E"]
[Tue Jul 21 07:34:41.314941 2026] [security2:error] [pid 255769:tid 255926] [client 117.251.86.144:37556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LQbxMYwyVGnfuwsKI_AAAA74"]
[Tue Jul 21 07:34:41.315073 2026] [security2:error] [pid 255769:tid 255926] [client 117.251.86.144:37556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LQbxMYwyVGnfuwsKI_AAAA74"]
[Tue Jul 21 07:34:41.320866 2026] [security2:error] [pid 255769:tid 255959] [client 109.248.148.246:48390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9LQbxMYwyVGnfuwsKI_gAAA98"]
[Tue Jul 21 07:34:41.320971 2026] [security2:error] [pid 255769:tid 255959] [client 109.248.148.246:48390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9LQbxMYwyVGnfuwsKI_gAAA98"]
[Tue Jul 21 07:34:41.364698 2026] [security2:error] [pid 255769:tid 255969] [client 122.129.67.13:59690] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9LQbxMYwyVGnfuwsKJAAAAA-k"]
[Tue Jul 21 07:34:41.364862 2026] [security2:error] [pid 255769:tid 255969] [client 122.129.67.13:59690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9LQbxMYwyVGnfuwsKJAAAAA-k"]
[Tue Jul 21 07:34:41.731933 2026] [security2:error] [pid 255769:tid 255856] [remote 34.91.119.153:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "alangefersonsouzabat1751481531845.0721679.meusitehostgator.com.br"] [uri "/"] [unique_id "al9LQbxMYwyVGnfuwsKJBgAEF1Y"]
[Tue Jul 21 07:34:41.732135 2026] [security2:error] [pid 255769:tid 256017] [client 34.91.119.153:0] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "alangefersonsouzabat1751481531845.0721679.meusitehostgator.com.br"] [uri "/"] [unique_id "al9LQbxMYwyVGnfuwsKJBgAEF1Y"]
[Tue Jul 21 07:34:41.877333 2026] [security2:error] [pid 255769:tid 256003] [client 20.197.195.24:13112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/core.php"] [unique_id "al9LQbxMYwyVGnfuwsKJCwAABAk"]
[Tue Jul 21 07:34:41.881049 2026] [security2:error] [pid 254995:tid 255167] [client 45.8.17.140:62769] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "al9LQf7v0rlcEGmVraEu-AAAA0g"]
[Tue Jul 21 07:34:42.116466 2026] [security2:error] [pid 255769:tid 256004] [client 122.186.204.214:65184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LQrxMYwyVGnfuwsKJDQAABAo"]
[Tue Jul 21 07:34:42.116582 2026] [security2:error] [pid 255769:tid 256004] [client 122.186.204.214:65184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LQrxMYwyVGnfuwsKJDQAABAo"]
[Tue Jul 21 07:34:42.191087 2026] [security2:error] [pid 255769:tid 255787] [remote 216.73.216.238:7748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/casa.php"] [unique_id "al9LQrxMYwyVGnfuwsKJDwAD2xE"]
[Tue Jul 21 07:34:42.249762 2026] [security2:error] [pid 254995:tid 255179] [client 82.102.28.107:56996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LQv7v0rlcEGmVraEvAQAAA1Q"]
[Tue Jul 21 07:34:42.249870 2026] [security2:error] [pid 254995:tid 255179] [client 82.102.28.107:56996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LQv7v0rlcEGmVraEvAQAAA1Q"]
[Tue Jul 21 07:34:42.721707 2026] [security2:error] [pid 254995:tid 255204] [client 173.24.185.52:64150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LQv7v0rlcEGmVraEvCQAAA20"]
[Tue Jul 21 07:34:42.721810 2026] [security2:error] [pid 254995:tid 255204] [client 173.24.185.52:64150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LQv7v0rlcEGmVraEvCQAAA20"]
[Tue Jul 21 07:34:42.834370 2026] [security2:error] [pid 254995:tid 255254] [client 45.251.232.145:56891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LQv7v0rlcEGmVraEvCgAAA4Q"]
[Tue Jul 21 07:34:42.834477 2026] [security2:error] [pid 254995:tid 255254] [client 45.251.232.145:56891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LQv7v0rlcEGmVraEvCgAAA4Q"]
[Tue Jul 21 07:34:42.892309 2026] [security2:error] [pid 255769:tid 255833] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LQrxMYwyVGnfuwsKJHgADvz8"]
[Tue Jul 21 07:34:42.892459 2026] [security2:error] [pid 255769:tid 255927] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LQrxMYwyVGnfuwsKJHgADvz8"]
[Tue Jul 21 07:34:43.281482 2026] [security2:error] [pid 255769:tid 255891] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LQ7xMYwyVGnfuwsKJJgADynk"]
[Tue Jul 21 07:34:43.281615 2026] [security2:error] [pid 255769:tid 255938] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LQ7xMYwyVGnfuwsKJJgADynk"]
[Tue Jul 21 07:34:43.287674 2026] [security2:error] [pid 255769:tid 255986] [client 45.8.17.134:51065] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "al9LQ7xMYwyVGnfuwsKJJwAAA_o"]
[Tue Jul 21 07:34:43.338031 2026] [security2:error] [pid 254995:tid 255054] [remote 188.95.113.76:41894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kaducontractor.com"] [uri "/wp-login.php"] [unique_id "al9LQ_7v0rlcEGmVraEvDwADVjo"]
[Tue Jul 21 07:34:43.566639 2026] [security2:error] [pid 255769:tid 256006] [client 122.162.144.145:2913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LQ7xMYwyVGnfuwsKJLwAABAw"]
[Tue Jul 21 07:34:43.566758 2026] [security2:error] [pid 255769:tid 256006] [client 122.162.144.145:2913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LQ7xMYwyVGnfuwsKJLwAABAw"]
[Tue Jul 21 07:34:44.015832 2026] [security2:error] [pid 255769:tid 256004] [client 20.220.225.223:49586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/la.php"] [unique_id "al9LRLxMYwyVGnfuwsKJOAAABAo"]
[Tue Jul 21 07:34:44.046598 2026] [security2:error] [pid 255769:tid 256014] [client 103.106.20.201:58791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LRLxMYwyVGnfuwsKJOQAABBQ"]
[Tue Jul 21 07:34:44.046742 2026] [security2:error] [pid 255769:tid 256014] [client 103.106.20.201:58791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LRLxMYwyVGnfuwsKJOQAABBQ"]
[Tue Jul 21 07:34:44.207145 2026] [security2:error] [pid 255769:tid 256021] [client 20.206.105.145:39267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/bob.php"] [unique_id "al9LRLxMYwyVGnfuwsKJPQAABBs"]
[Tue Jul 21 07:34:44.314742 2026] [security2:error] [pid 255769:tid 255941] [client 117.217.38.194:60662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LRLxMYwyVGnfuwsKJRAAAA80"]
[Tue Jul 21 07:34:44.314863 2026] [security2:error] [pid 255769:tid 255941] [client 117.217.38.194:60662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LRLxMYwyVGnfuwsKJRAAAA80"]
[Tue Jul 21 07:34:44.385052 2026] [security2:error] [pid 255769:tid 255976] [client 20.197.195.24:13085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/als.php"] [unique_id "al9LRLxMYwyVGnfuwsKJRgAAA_A"]
[Tue Jul 21 07:34:44.454277 2026] [security2:error] [pid 255769:tid 255927] [client 20.220.225.223:24196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/byp8.php"] [unique_id "al9LRLxMYwyVGnfuwsKJSAAAA78"]
[Tue Jul 21 07:34:44.484087 2026] [security2:error] [pid 255769:tid 255973] [client 45.8.17.105:22165] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9LRLxMYwyVGnfuwsKJSgAAA-0"]
[Tue Jul 21 07:34:44.537085 2026] [security2:error] [pid 255769:tid 256022] [client 82.102.28.107:56998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9LRLxMYwyVGnfuwsKJSwAABBw"]
[Tue Jul 21 07:34:44.537185 2026] [security2:error] [pid 255769:tid 256022] [client 82.102.28.107:56998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9LRLxMYwyVGnfuwsKJSwAABBw"]
[Tue Jul 21 07:34:44.599565 2026] [security2:error] [pid 254995:tid 255256] [client 193.36.225.10:33627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LRP7v0rlcEGmVraEvHwAAA4Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:44.616626 2026] [security2:error] [pid 255769:tid 255948] [client 20.197.195.24:62700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9LRLxMYwyVGnfuwsKJTwAAA9Q"]
[Tue Jul 21 07:34:44.838848 2026] [security2:error] [pid 254995:tid 255194] [client 154.192.233.199:59275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LRP7v0rlcEGmVraEvIwAAA2M"]
[Tue Jul 21 07:34:44.838949 2026] [security2:error] [pid 254995:tid 255194] [client 154.192.233.199:59275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LRP7v0rlcEGmVraEvIwAAA2M"]
[Tue Jul 21 07:34:45.186855 2026] [security2:error] [pid 255769:tid 255952] [client 104.196.214.11:61135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.214.196.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oab.arcoll.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LRbxMYwyVGnfuwsKJXAAAA9g"]
[Tue Jul 21 07:34:45.361861 2026] [security2:error] [pid 254995:tid 255189] [client 20.220.225.223:23451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/hp3.php"] [unique_id "al9LRf7v0rlcEGmVraEvKgAAA14"]
[Tue Jul 21 07:34:45.366833 2026] [security2:error] [pid 255769:tid 256009] [client 20.52.136.55:1536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/dropdown.php"] [unique_id "al9LRbxMYwyVGnfuwsKJXgAABA8"]
[Tue Jul 21 07:34:45.597360 2026] [security2:error] [pid 254995:tid 255134] [client 45.8.17.139:52433] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/theme-check/theme-check.php"] [unique_id "al9LRf7v0rlcEGmVraEvLQAAAyc"]
[Tue Jul 21 07:34:45.651540 2026] [security2:error] [pid 255769:tid 255953] [client 175.45.70.82:59261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LRbxMYwyVGnfuwsKJZQAAA9k"]
[Tue Jul 21 07:34:45.651689 2026] [security2:error] [pid 255769:tid 255953] [client 175.45.70.82:59261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LRbxMYwyVGnfuwsKJZQAAA9k"]
[Tue Jul 21 07:34:45.703899 2026] [security2:error] [pid 255769:tid 256004] [client 20.220.225.223:38696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/8.php"] [unique_id "al9LRbxMYwyVGnfuwsKJZgAABAo"]
[Tue Jul 21 07:34:45.782762 2026] [security2:error] [pid 254995:tid 255275] [client 20.197.195.24:62621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9LRf7v0rlcEGmVraEvNgAAA5k"]
[Tue Jul 21 07:34:46.054106 2026] [security2:error] [pid 255769:tid 255961] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LRbxMYwyVGnfuwsKJbgAD4Sw"]
[Tue Jul 21 07:34:46.096398 2026] [security2:error] [pid 255769:tid 255907] [client 20.197.195.24:48800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/simple.php"] [unique_id "al9LRrxMYwyVGnfuwsKJcQAAA6s"]
[Tue Jul 21 07:34:46.199434 2026] [proxy:error] [pid 255769:tid 255964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:46.199502 2026] [proxy_http:error] [pid 255769:tid 255964] [client 20.206.105.145:38915] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:46.200213 2026] [proxy:error] [pid 255769:tid 255964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:46.200243 2026] [proxy_http:error] [pid 255769:tid 255964] [client 20.206.105.145:38915] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:46.298578 2026] [security2:error] [pid 254995:tid 255177] [client 213.152.162.104:34914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9LRv7v0rlcEGmVraEvQQAAA1I"]
[Tue Jul 21 07:34:46.298675 2026] [security2:error] [pid 254995:tid 255177] [client 213.152.162.104:34914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9LRv7v0rlcEGmVraEvQQAAA1I"]
[Tue Jul 21 07:34:46.383471 2026] [security2:error] [pid 255769:tid 256027] [client 74.7.230.33:59540] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "kolkehillot.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9LRrxMYwyVGnfuwsKJegAEIQg"]
[Tue Jul 21 07:34:46.412743 2026] [security2:error] [pid 255769:tid 256024] [client 20.220.225.223:49803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/nhvoanpl.php"] [unique_id "al9LRrxMYwyVGnfuwsKJfAAABB4"]
[Tue Jul 21 07:34:46.501365 2026] [security2:error] [pid 255769:tid 255859] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LRrxMYwyVGnfuwsKJfQAEBVk"]
[Tue Jul 21 07:34:46.501529 2026] [security2:error] [pid 255769:tid 255999] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LRrxMYwyVGnfuwsKJfQAEBVk"]
[Tue Jul 21 07:34:46.685883 2026] [security2:error] [pid 255769:tid 255990] [client 103.174.34.15:51338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LRrxMYwyVGnfuwsKJgAAAA_4"]
[Tue Jul 21 07:34:46.686015 2026] [security2:error] [pid 255769:tid 255990] [client 103.174.34.15:51338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LRrxMYwyVGnfuwsKJgAAAA_4"]
[Tue Jul 21 07:34:46.838865 2026] [security2:error] [pid 255769:tid 256015] [client 20.197.195.24:62628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/media.php"] [unique_id "al9LRrxMYwyVGnfuwsKJhgAABBU"]
[Tue Jul 21 07:34:46.883309 2026] [security2:error] [pid 255769:tid 255996] [client 45.8.17.115:60067] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/wp-conflg.php"] [unique_id "al9LRrxMYwyVGnfuwsKJhwAABAI"]
[Tue Jul 21 07:34:47.218428 2026] [security2:error] [pid 254995:tid 255181] [client 82.102.28.107:55102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9LR_7v0rlcEGmVraEvTAAAA1Y"]
[Tue Jul 21 07:34:47.218505 2026] [security2:error] [pid 254995:tid 255181] [client 82.102.28.107:55102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9LR_7v0rlcEGmVraEvTAAAA1Y"]
[Tue Jul 21 07:34:47.292153 2026] [security2:error] [pid 254995:tid 255175] [client 20.197.195.24:62677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/images.php"] [unique_id "al9LR_7v0rlcEGmVraEvUgAAA1A"]
[Tue Jul 21 07:34:47.454355 2026] [security2:error] [pid 255769:tid 255933] [client 20.197.195.24:13098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/init.php"] [unique_id "al9LR7xMYwyVGnfuwsKJkgAAA8U"]
[Tue Jul 21 07:34:47.620337 2026] [security2:error] [pid 255769:tid 255909] [client 20.220.225.223:49597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/inso.php"] [unique_id "al9LR7xMYwyVGnfuwsKJlgAAA60"]
[Tue Jul 21 07:34:47.828400 2026] [security2:error] [pid 255769:tid 255843] [remote 45.3.50.206:63361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.50.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9LR7xMYwyVGnfuwsKJngAD5Uk"]
[Tue Jul 21 07:34:48.164613 2026] [security2:error] [pid 255769:tid 255948] [client 20.197.195.24:62682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/gecko.php"] [unique_id "al9LSLxMYwyVGnfuwsKJpAAAA9Q"]
[Tue Jul 21 07:34:48.195895 2026] [security2:error] [pid 254995:tid 255153] [client 45.8.17.63:34411] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/function/function.php"] [unique_id "al9LSP7v0rlcEGmVraEvYAAAAzo"]
[Tue Jul 21 07:34:48.327780 2026] [security2:error] [pid 255769:tid 255990] [client 20.220.225.223:31180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/red.php"] [unique_id "al9LSLxMYwyVGnfuwsKJqAAAA_4"]
[Tue Jul 21 07:34:48.352201 2026] [security2:error] [pid 255769:tid 255935] [client 193.36.225.66:36263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LSLxMYwyVGnfuwsKJqQAAA8c"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:48.426913 2026] [security2:error] [pid 254995:tid 255147] [client 37.140.223.138:58911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LSP7v0rlcEGmVraEvYwAAAzQ"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:48.653072 2026] [security2:error] [pid 255769:tid 255790] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LSLxMYwyVGnfuwsKJtAAD3BQ"]
[Tue Jul 21 07:34:48.653264 2026] [security2:error] [pid 255769:tid 255956] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LSLxMYwyVGnfuwsKJtAAD3BQ"]
[Tue Jul 21 07:34:48.752470 2026] [security2:error] [pid 255769:tid 255952] [client 20.197.195.24:62674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/82.php"] [unique_id "al9LSLxMYwyVGnfuwsKJuQAAA9g"]
[Tue Jul 21 07:34:48.969990 2026] [security2:error] [pid 255769:tid 255902] [client 20.220.225.223:19293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/wp-explorer.php"] [unique_id "al9LSLxMYwyVGnfuwsKJvQAAA6Y"]
[Tue Jul 21 07:34:48.975913 2026] [proxy:error] [pid 254995:tid 255276] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:48.975985 2026] [proxy_http:error] [pid 254995:tid 255276] [client 20.206.105.145:39107] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:48.976658 2026] [proxy:error] [pid 254995:tid 255276] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:48.976681 2026] [proxy_http:error] [pid 254995:tid 255276] [client 20.206.105.145:39107] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:49.190239 2026] [security2:error] [pid 255769:tid 255961] [client 109.248.148.246:52208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9LSbxMYwyVGnfuwsKJwQAAA-E"]
[Tue Jul 21 07:34:49.190341 2026] [security2:error] [pid 255769:tid 255961] [client 109.248.148.246:52208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9LSbxMYwyVGnfuwsKJwQAAA-E"]
[Tue Jul 21 07:34:49.209745 2026] [security2:error] [pid 255769:tid 255850] [remote 124.55.178.99:36678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9LSbxMYwyVGnfuwsKJwwAD7lA"]
[Tue Jul 21 07:34:49.209907 2026] [security2:error] [pid 255769:tid 255974] [client 124.55.178.99:36678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9LSbxMYwyVGnfuwsKJwwAD7lA"]
[Tue Jul 21 07:34:49.287056 2026] [security2:error] [pid 255769:tid 255792] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LSbxMYwyVGnfuwsKJxAADrRY"]
[Tue Jul 21 07:34:49.287245 2026] [security2:error] [pid 255769:tid 255909] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LSbxMYwyVGnfuwsKJxAADrRY"]
[Tue Jul 21 07:34:49.299312 2026] [security2:error] [pid 255769:tid 255903] [client 45.8.17.110:59701] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "al9LSbxMYwyVGnfuwsKJxQAAA6c"]
[Tue Jul 21 07:34:49.300893 2026] [security2:error] [pid 254995:tid 255089] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LSf7v0rlcEGmVraEvdgADPF0"]
[Tue Jul 21 07:34:49.301015 2026] [security2:error] [pid 254995:tid 255155] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LSf7v0rlcEGmVraEvdgADPF0"]
[Tue Jul 21 07:34:49.336007 2026] [security2:error] [pid 255769:tid 255870] [remote 216.73.216.238:6114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/casa.php"] [unique_id "al9LSbxMYwyVGnfuwsKJxwAEDmQ"]
[Tue Jul 21 07:34:49.376106 2026] [security2:error] [pid 254995:tid 255110] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LSf7v0rlcEGmVraEveAADg3I"]
[Tue Jul 21 07:34:49.376237 2026] [security2:error] [pid 254995:tid 255252] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LSf7v0rlcEGmVraEveAADg3I"]
[Tue Jul 21 07:34:49.444619 2026] [security2:error] [pid 255769:tid 256007] [client 20.206.105.145:39258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/crgio.php"] [unique_id "al9LSbxMYwyVGnfuwsKJ0AAABA0"]
[Tue Jul 21 07:34:49.471874 2026] [security2:error] [pid 255769:tid 255957] [client 20.197.195.24:62602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/admin.php"] [unique_id "al9LSbxMYwyVGnfuwsKJ0QAAA90"]
[Tue Jul 21 07:34:49.910133 2026] [security2:error] [pid 254995:tid 255011] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LSf7v0rlcEGmVraEvgAADLQ8"]
[Tue Jul 21 07:34:49.910261 2026] [security2:error] [pid 254995:tid 255140] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LSf7v0rlcEGmVraEvgAADLQ8"]
[Tue Jul 21 07:34:50.027063 2026] [security2:error] [pid 255769:tid 256026] [client 20.197.195.24:62705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/adminner.php"] [unique_id "al9LSrxMYwyVGnfuwsKJ3AAABCA"]
[Tue Jul 21 07:34:50.133656 2026] [security2:error] [pid 255769:tid 255862] [remote 45.3.39.244:40027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.39.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9LSrxMYwyVGnfuwsKJ3QADqFw"]
[Tue Jul 21 07:34:50.151669 2026] [security2:error] [pid 255769:tid 255972] [client 139.167.225.182:53662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LSrxMYwyVGnfuwsKJ3gAAA-w"]
[Tue Jul 21 07:34:50.151755 2026] [security2:error] [pid 255769:tid 255972] [client 139.167.225.182:53662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LSrxMYwyVGnfuwsKJ3gAAA-w"]
[Tue Jul 21 07:34:50.253482 2026] [security2:error] [pid 255769:tid 255969] [client 59.96.220.140:51573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LSrxMYwyVGnfuwsKJ4AAAA-k"]
[Tue Jul 21 07:34:50.253562 2026] [security2:error] [pid 255769:tid 255969] [client 59.96.220.140:51573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LSrxMYwyVGnfuwsKJ4AAAA-k"]
[Tue Jul 21 07:34:50.384968 2026] [security2:error] [pid 255769:tid 255937] [client 20.206.105.145:39163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/pucci.php"] [unique_id "al9LSrxMYwyVGnfuwsKJ5AAAA8k"]
[Tue Jul 21 07:34:50.661733 2026] [security2:error] [pid 254995:tid 255181] [client 20.10.88.201:61376] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gnxinox.com.br"] [uri "/index.php"] [unique_id "al9LSv7v0rlcEGmVraEvjAAAA1Y"]
[Tue Jul 21 07:34:50.983870 2026] [security2:error] [pid 254995:tid 255198] [client 20.197.195.24:13164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/fpwch.php"] [unique_id "al9LSv7v0rlcEGmVraEvkQAAA2c"]
[Tue Jul 21 07:34:51.012555 2026] [security2:error] [pid 254995:tid 255225] [client 20.220.225.223:6084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/aa1.php"] [unique_id "al9LS_7v0rlcEGmVraEvkwAAA4E"]
[Tue Jul 21 07:34:51.294825 2026] [security2:error] [pid 254995:tid 255163] [client 45.8.17.49:44839] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/network/upgrade/index.php"] [unique_id "al9LS_7v0rlcEGmVraEvlgAAA0Q"]
[Tue Jul 21 07:34:51.322713 2026] [security2:error] [pid 255769:tid 255927] [client 20.197.195.24:62638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/admin.php"] [unique_id "al9LS7xMYwyVGnfuwsKJ9QAAA78"]
[Tue Jul 21 07:34:51.447130 2026] [security2:error] [pid 255769:tid 255948] [client 37.140.223.117:23779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LS7xMYwyVGnfuwsKJ-gAAA9Q"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:51.477005 2026] [proxy:error] [pid 254995:tid 255184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:51.477075 2026] [proxy_http:error] [pid 254995:tid 255184] [client 20.206.105.145:38925] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:51.477666 2026] [proxy:error] [pid 254995:tid 255184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:51.477694 2026] [proxy_http:error] [pid 254995:tid 255184] [client 20.206.105.145:38925] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:51.583072 2026] [access_compat:error] [pid 255769:tid 255910] [client 162.241.63.68:52872] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:34:51.829186 2026] [security2:error] [pid 255769:tid 255936] [client 20.197.195.24:62702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/k.php"] [unique_id "al9LS7xMYwyVGnfuwsKKAAAAA8g"]
[Tue Jul 21 07:34:51.852800 2026] [security2:error] [pid 254995:tid 255193] [client 103.162.129.114:65157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LS_7v0rlcEGmVraEvoAAAA2I"]
[Tue Jul 21 07:34:51.852906 2026] [security2:error] [pid 254995:tid 255193] [client 103.162.129.114:65157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LS_7v0rlcEGmVraEvoAAAA2I"]
[Tue Jul 21 07:34:52.008293 2026] [security2:error] [pid 254995:tid 255256] [client 117.251.86.144:49962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LTP7v0rlcEGmVraEvoQAAA4Y"]
[Tue Jul 21 07:34:52.008389 2026] [security2:error] [pid 254995:tid 255256] [client 117.251.86.144:49962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LTP7v0rlcEGmVraEvoQAAA4Y"]
[Tue Jul 21 07:34:52.284181 2026] [rewrite:error] [pid 255769:tid 256017] [client 187.49.76.218:18625] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:34:52.285719 2026] [rewrite:error] [pid 255769:tid 255913] [client 187.49.76.218:18689] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:34:52.293222 2026] [security2:error] [pid 254995:tid 255205] [client 213.152.162.104:42094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LTP7v0rlcEGmVraEvpQAAA24"]
[Tue Jul 21 07:34:52.293310 2026] [security2:error] [pid 254995:tid 255205] [client 213.152.162.104:42094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LTP7v0rlcEGmVraEvpQAAA24"]
[Tue Jul 21 07:34:52.304720 2026] [rewrite:error] [pid 255769:tid 255952] [client 187.49.76.218:18721] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:34:52.309398 2026] [proxy:error] [pid 255769:tid 255901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:52.309459 2026] [proxy_http:error] [pid 255769:tid 255901] [client 20.206.105.145:38919] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:52.310132 2026] [proxy:error] [pid 255769:tid 255901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:52.310169 2026] [proxy_http:error] [pid 255769:tid 255901] [client 20.206.105.145:38919] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:52.417090 2026] [security2:error] [pid 255769:tid 255855] [remote 104.207.33.244:45183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.33.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9LTLxMYwyVGnfuwsKKDAAD51U"]
[Tue Jul 21 07:34:52.430438 2026] [security2:error] [pid 255769:tid 256014] [client 20.197.195.24:62708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/blurbs.php"] [unique_id "al9LTLxMYwyVGnfuwsKKFAAABBQ"]
[Tue Jul 21 07:34:52.488463 2026] [security2:error] [pid 255769:tid 255956] [client 45.8.17.63:62549] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/style-engine/wp-conflg.php"] [unique_id "al9LTLxMYwyVGnfuwsKKFgAAA9w"]
[Tue Jul 21 07:34:52.553561 2026] [security2:error] [pid 255769:tid 255922] [client 20.197.195.24:13070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/domvf.php"] [unique_id "al9LTLxMYwyVGnfuwsKKFwAAA7o"]
[Tue Jul 21 07:34:52.642470 2026] [security2:error] [pid 255769:tid 255963] [client 20.220.225.223:49540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wpx.php"] [unique_id "al9LTLxMYwyVGnfuwsKKGQAAA-M"]
[Tue Jul 21 07:34:52.705242 2026] [security2:error] [pid 255769:tid 255941] [client 20.206.105.145:39271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-temp.php"] [unique_id "al9LTLxMYwyVGnfuwsKKGgAAA80"]
[Tue Jul 21 07:34:52.802630 2026] [security2:error] [pid 255769:tid 255918] [client 122.186.204.214:49309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LTLxMYwyVGnfuwsKKHQAAA7Y"]
[Tue Jul 21 07:34:52.802768 2026] [security2:error] [pid 255769:tid 255918] [client 122.186.204.214:49309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LTLxMYwyVGnfuwsKKHQAAA7Y"]
[Tue Jul 21 07:34:52.819221 2026] [proxy:error] [pid 255769:tid 256008] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:52.819286 2026] [proxy_http:error] [pid 255769:tid 256008] [client 20.206.105.145:38975] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:52.819783 2026] [proxy:error] [pid 255769:tid 256008] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:52.819808 2026] [proxy_http:error] [pid 255769:tid 256008] [client 20.206.105.145:38975] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:52.963364 2026] [security2:error] [pid 254995:tid 255269] [client 20.220.225.223:19264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/akismet.php"] [unique_id "al9LTP7v0rlcEGmVraEvrQAAA5M"]
[Tue Jul 21 07:34:53.042584 2026] [security2:error] [pid 255769:tid 255934] [client 20.197.195.24:62623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/bajah.php"] [unique_id "al9LTbxMYwyVGnfuwsKKJQAAA8Y"]
[Tue Jul 21 07:34:53.238967 2026] [security2:error] [pid 255769:tid 255985] [client 173.24.185.52:64819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LTbxMYwyVGnfuwsKKKAAAA_k"]
[Tue Jul 21 07:34:53.239080 2026] [security2:error] [pid 255769:tid 255985] [client 173.24.185.52:64819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LTbxMYwyVGnfuwsKKKAAAA_k"]
[Tue Jul 21 07:34:53.305504 2026] [security2:error] [pid 255769:tid 255944] [client 45.251.232.145:57414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LTbxMYwyVGnfuwsKKLAAAA9A"]
[Tue Jul 21 07:34:53.306126 2026] [security2:error] [pid 255769:tid 255944] [client 45.251.232.145:57414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LTbxMYwyVGnfuwsKKLAAAA9A"]
[Tue Jul 21 07:34:53.477416 2026] [security2:error] [pid 254995:tid 255268] [client 136.144.33.111:33971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LTf7v0rlcEGmVraEvsgAAA5I"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:53.569008 2026] [security2:error] [pid 254995:tid 255133] [client 82.102.28.107:54454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9LTf7v0rlcEGmVraEvuQAAAyY"]
[Tue Jul 21 07:34:53.569182 2026] [security2:error] [pid 254995:tid 255133] [client 82.102.28.107:54454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9LTf7v0rlcEGmVraEvuQAAAyY"]
[Tue Jul 21 07:34:53.570795 2026] [security2:error] [pid 255769:tid 256024] [client 20.220.225.223:24233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/user.php"] [unique_id "al9LTbxMYwyVGnfuwsKKMAAABB4"]
[Tue Jul 21 07:34:53.583054 2026] [security2:error] [pid 255769:tid 255878] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LTbxMYwyVGnfuwsKKMQADrmw"]
[Tue Jul 21 07:34:53.583218 2026] [security2:error] [pid 255769:tid 255910] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LTbxMYwyVGnfuwsKKMQADrmw"]
[Tue Jul 21 07:34:53.744561 2026] [security2:error] [pid 255769:tid 255929] [client 20.197.195.24:62692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/a.php"] [unique_id "al9LTbxMYwyVGnfuwsKKNgAAA8E"]
[Tue Jul 21 07:34:53.810332 2026] [rewrite:error] [pid 255769:tid 255969] [client 187.49.76.218:18721] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2411
[Tue Jul 21 07:34:53.810729 2026] [rewrite:error] [pid 255769:tid 255998] [client 187.49.76.218:18689] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2411
[Tue Jul 21 07:34:53.812966 2026] [rewrite:error] [pid 255769:tid 256006] [client 187.49.76.218:18625] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2411
[Tue Jul 21 07:34:53.842212 2026] [security2:error] [pid 255769:tid 255783] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LTbxMYwyVGnfuwsKKPQADsw0"]
[Tue Jul 21 07:34:53.842321 2026] [security2:error] [pid 255769:tid 255915] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LTbxMYwyVGnfuwsKKPQADsw0"]
[Tue Jul 21 07:34:53.885141 2026] [security2:error] [pid 255769:tid 256009] [client 45.8.17.138:45593] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9LTbxMYwyVGnfuwsKKPwAABA8"]
[Tue Jul 21 07:34:54.041749 2026] [security2:error] [pid 255769:tid 255953] [client 20.206.105.145:39252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-admin/js/index.php"] [unique_id "al9LTrxMYwyVGnfuwsKKQwAAA9k"]
[Tue Jul 21 07:34:54.184862 2026] [security2:error] [pid 255769:tid 256012] [client 20.52.136.55:1554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/wp-links.php"] [unique_id "al9LTrxMYwyVGnfuwsKKRwAABBI"]
[Tue Jul 21 07:34:54.301913 2026] [security2:error] [pid 254995:tid 255166] [client 122.162.144.145:12647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LTv7v0rlcEGmVraEvwAAAA0c"]
[Tue Jul 21 07:34:54.302067 2026] [security2:error] [pid 254995:tid 255166] [client 122.162.144.145:12647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LTv7v0rlcEGmVraEvwAAAA0c"]
[Tue Jul 21 07:34:54.314959 2026] [security2:error] [pid 255769:tid 255961] [client 20.197.195.24:62629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/edit.php"] [unique_id "al9LTrxMYwyVGnfuwsKKSQAAA-E"]
[Tue Jul 21 07:34:54.501624 2026] [security2:error] [pid 255769:tid 255964] [client 20.197.195.24:48886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp.php"] [unique_id "al9LTrxMYwyVGnfuwsKKTgAAA-Q"]
[Tue Jul 21 07:34:54.712512 2026] [security2:error] [pid 255769:tid 255934] [client 20.220.225.223:19323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/ace2.php"] [unique_id "al9LTrxMYwyVGnfuwsKKUgAAA8Y"]
[Tue Jul 21 07:34:54.764361 2026] [security2:error] [pid 255769:tid 255955] [client 103.106.20.201:59360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LTrxMYwyVGnfuwsKKVQAAA9s"]
[Tue Jul 21 07:34:54.764463 2026] [security2:error] [pid 255769:tid 255955] [client 103.106.20.201:59360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LTrxMYwyVGnfuwsKKVQAAA9s"]
[Tue Jul 21 07:34:54.782370 2026] [security2:error] [pid 255769:tid 255967] [client 117.217.38.194:61105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LTrxMYwyVGnfuwsKKVwAAA-c"]
[Tue Jul 21 07:34:54.782452 2026] [security2:error] [pid 255769:tid 255967] [client 117.217.38.194:61105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LTrxMYwyVGnfuwsKKVwAAA-c"]
[Tue Jul 21 07:34:55.119350 2026] [security2:error] [pid 255769:tid 255935] [client 20.220.225.223:38705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/fffm.php"] [unique_id "al9LT7xMYwyVGnfuwsKKXgAAA8c"]
[Tue Jul 21 07:34:55.188785 2026] [security2:error] [pid 255769:tid 256024] [client 45.8.17.73:39065] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9LT7xMYwyVGnfuwsKKXwAABB4"]
[Tue Jul 21 07:34:55.441045 2026] [autoindex:error] [pid 255769:tid 255989] [client 198.235.24.15:64692] AH01276: Cannot serve directory /home1/warlle02/ewfconstrucao.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:34:55.491228 2026] [security2:error] [pid 254995:tid 255129] [client 20.197.195.24:48852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/class.php"] [unique_id "al9LT_7v0rlcEGmVraEv0AAAAyI"]
[Tue Jul 21 07:34:55.782674 2026] [security2:error] [pid 255769:tid 256001] [client 20.197.195.24:62595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/hosty.php"] [unique_id "al9LT7xMYwyVGnfuwsKKbAAABAc"]
[Tue Jul 21 07:34:55.901624 2026] [security2:error] [pid 254995:tid 255143] [client 20.206.105.145:39131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/puc.php"] [unique_id "al9LT_7v0rlcEGmVraEv1gAAAzA"]
[Tue Jul 21 07:34:56.094280 2026] [security2:error] [pid 255769:tid 255913] [client 20.220.225.223:6086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/acew67.php"] [unique_id "al9LULxMYwyVGnfuwsKKcAAAA7E"]
[Tue Jul 21 07:34:56.183843 2026] [security2:error] [pid 255769:tid 256004] [client 20.197.195.24:13115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/echkm.php"] [unique_id "al9LULxMYwyVGnfuwsKKcgAABAo"]
[Tue Jul 21 07:34:56.264525 2026] [security2:error] [pid 255769:tid 255975] [client 20.220.225.223:49816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/mimpi.php"] [unique_id "al9LULxMYwyVGnfuwsKKdAAAA-8"]
[Tue Jul 21 07:34:56.420397 2026] [security2:error] [pid 255769:tid 255922] [client 20.206.105.145:38968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/themes.php"] [unique_id "al9LULxMYwyVGnfuwsKKdgAAA7o"]
[Tue Jul 21 07:34:56.476865 2026] [security2:error] [pid 254995:tid 255193] [client 175.45.70.82:59779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LUP7v0rlcEGmVraEv4AAAA2I"]
[Tue Jul 21 07:34:56.477012 2026] [security2:error] [pid 254995:tid 255193] [client 175.45.70.82:59779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LUP7v0rlcEGmVraEv4AAAA2I"]
[Tue Jul 21 07:34:56.537399 2026] [security2:error] [pid 255769:tid 255960] [client 154.192.233.199:59726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LULxMYwyVGnfuwsKKegAAA-A"]
[Tue Jul 21 07:34:56.537547 2026] [security2:error] [pid 255769:tid 255960] [client 154.192.233.199:59726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LULxMYwyVGnfuwsKKegAAA-A"]
[Tue Jul 21 07:34:56.678895 2026] [security2:error] [pid 255769:tid 255827] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/1vluqojw5imsz1tiek5x9hr85p.php"] [unique_id "al9LULxMYwyVGnfuwsKKfwAEHDk"]
[Tue Jul 21 07:34:56.683663 2026] [security2:error] [pid 255769:tid 255976] [client 45.8.17.134:54375] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/network/chosen.php"] [unique_id "al9LULxMYwyVGnfuwsKKgAAAA_A"]
[Tue Jul 21 07:34:56.695341 2026] [security2:error] [pid 255769:tid 255945] [client 20.197.195.24:48855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/lib.php"] [unique_id "al9LULxMYwyVGnfuwsKKgQAAA9E"]
[Tue Jul 21 07:34:56.797777 2026] [security2:error] [pid 255769:tid 255955] [client 109.248.148.246:37718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9LULxMYwyVGnfuwsKKhgAAA9s"]
[Tue Jul 21 07:34:56.797862 2026] [security2:error] [pid 255769:tid 255955] [client 109.248.148.246:37718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9LULxMYwyVGnfuwsKKhgAAA9s"]
[Tue Jul 21 07:34:56.959855 2026] [security2:error] [pid 255769:tid 255974] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LULxMYwyVGnfuwsKKhwAD7ig"]
[Tue Jul 21 07:34:56.968842 2026] [security2:error] [pid 254995:tid 255127] [client 87.58.197.194:42922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.63.71"] [uri "/.env"] [unique_id "al9LUP7v0rlcEGmVraEv5QAAAyA"]
[Tue Jul 21 07:34:56.978595 2026] [security2:error] [pid 254995:tid 255152] [client 82.102.28.107:54456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LUP7v0rlcEGmVraEv5gAAAzk"]
[Tue Jul 21 07:34:56.978683 2026] [security2:error] [pid 254995:tid 255152] [client 82.102.28.107:54456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LUP7v0rlcEGmVraEv5gAAAzk"]
[Tue Jul 21 07:34:57.016017 2026] [security2:error] [pid 255769:tid 255910] [client 20.206.105.145:39233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/dx.php"] [unique_id "al9LUbxMYwyVGnfuwsKKjAAAA64"]
[Tue Jul 21 07:34:57.083276 2026] [security2:error] [pid 255769:tid 255893] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alphafix.com.br"] [uri "/.env"] [unique_id "al9LUbxMYwyVGnfuwsKKjwAD_Xs"]
[Tue Jul 21 07:34:57.083845 2026] [security2:error] [pid 254995:tid 255057] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alphafix.com.br"] [uri "/backend/.env"] [unique_id "al9LUf7v0rlcEGmVraEv6gADVz0"]
[Tue Jul 21 07:34:57.098063 2026] [security2:error] [pid 254995:tid 255015] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LUf7v0rlcEGmVraEv6wADNhM"]
[Tue Jul 21 07:34:57.098177 2026] [security2:error] [pid 254995:tid 255149] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LUf7v0rlcEGmVraEv6wADNhM"]
[Tue Jul 21 07:34:57.260224 2026] [security2:error] [pid 254995:tid 255261] [client 103.174.34.15:51818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LUf7v0rlcEGmVraEv7QAAA4s"]
[Tue Jul 21 07:34:57.260367 2026] [security2:error] [pid 254995:tid 255261] [client 103.174.34.15:51818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LUf7v0rlcEGmVraEv7QAAA4s"]
[Tue Jul 21 07:34:57.290628 2026] [security2:error] [pid 255769:tid 255925] [client 20.206.105.145:39259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/p.php"] [unique_id "al9LUbxMYwyVGnfuwsKKlwAAA70"]
[Tue Jul 21 07:34:57.421055 2026] [proxy:error] [pid 255769:tid 255983] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:57.421146 2026] [proxy_http:error] [pid 255769:tid 255983] [client 20.206.105.145:39261] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:57.421831 2026] [proxy:error] [pid 255769:tid 255983] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:57.421871 2026] [proxy_http:error] [pid 255769:tid 255983] [client 20.206.105.145:39261] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:57.473196 2026] [security2:error] [pid 255769:tid 256028] [client 20.197.195.24:13091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/login.php"] [unique_id "al9LUbxMYwyVGnfuwsKKnQAABCI"]
[Tue Jul 21 07:34:57.519897 2026] [security2:error] [pid 255769:tid 256004] [client 20.220.225.223:19973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/ms.php"] [unique_id "al9LUbxMYwyVGnfuwsKKngAABAo"]
[Tue Jul 21 07:34:57.538201 2026] [security2:error] [pid 254995:tid 255218] [client 20.52.136.55:1791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/xmrlpc.php"] [unique_id "al9LUf7v0rlcEGmVraEv8QAAA3o"]
[Tue Jul 21 07:34:57.628330 2026] [security2:error] [pid 254995:tid 255009] [remote 159.223.116.62:48680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.116.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/wp-login.php"] [unique_id "al9LUf7v0rlcEGmVraEv8gADmw0"]
[Tue Jul 21 07:34:57.645511 2026] [core:error] [pid 255769:tid 255794] [remote 45.148.10.238:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:34:57.645530 2026] [core:error] [pid 255769:tid 255794] [remote 45.148.10.238:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:34:57.659292 2026] [security2:error] [pid 255769:tid 255886] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LUbxMYwyVGnfuwsKKowADxXQ"]
[Tue Jul 21 07:34:57.659416 2026] [security2:error] [pid 255769:tid 255933] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LUbxMYwyVGnfuwsKKowADxXQ"]
[Tue Jul 21 07:34:57.715365 2026] [security2:error] [pid 254995:tid 255140] [client 20.206.105.145:38954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/bthil.php"] [unique_id "al9LUf7v0rlcEGmVraEv9AAAAy0"]
[Tue Jul 21 07:34:57.739903 2026] [security2:error] [pid 254995:tid 255159] [client 20.220.225.223:49800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/dp.php"] [unique_id "al9LUf7v0rlcEGmVraEv9gAAA0A"]
[Tue Jul 21 07:34:57.783213 2026] [security2:error] [pid 255769:tid 255971] [client 20.197.195.24:62701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/k.php"] [unique_id "al9LUbxMYwyVGnfuwsKKpgAAA-s"]
[Tue Jul 21 07:34:57.790214 2026] [security2:error] [pid 255769:tid 255992] [client 20.206.105.145:39290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/7.php"] [unique_id "al9LUbxMYwyVGnfuwsKKpwAAA_8"]
[Tue Jul 21 07:34:57.852746 2026] [security2:error] [pid 255769:tid 255892] [remote 160.187.68.132:45580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9LUbxMYwyVGnfuwsKKqgADqXo"]
[Tue Jul 21 07:34:57.852931 2026] [security2:error] [pid 255769:tid 255905] [client 160.187.68.132:45580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9LUbxMYwyVGnfuwsKKqgADqXo"]
[Tue Jul 21 07:34:57.870011 2026] [security2:error] [pid 254995:tid 255165] [client 20.206.105.145:39129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/8.php"] [unique_id "al9LUf7v0rlcEGmVraEv-gAAA0Y"]
[Tue Jul 21 07:34:57.987787 2026] [security2:error] [pid 254995:tid 255262] [client 45.8.17.138:38655] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "al9LUf7v0rlcEGmVraEv-wAAA4w"]
[Tue Jul 21 07:34:58.096898 2026] [security2:error] [pid 255769:tid 255952] [client 193.36.225.71:23687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LUrxMYwyVGnfuwsKKsAAAA9g"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:58.279064 2026] [security2:error] [pid 255769:tid 255899] [client 20.220.225.223:24259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/ops.php"] [unique_id "al9LUrxMYwyVGnfuwsKKsgAAA6M"]
[Tue Jul 21 07:34:58.346133 2026] [security2:error] [pid 255769:tid 255906] [client 20.206.105.145:39156] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.goldentrips40.com"] [uri "/1.php"] [unique_id "al9LUrxMYwyVGnfuwsKKswAAA6o"]
[Tue Jul 21 07:34:58.346240 2026] [security2:error] [pid 255769:tid 255906] [client 20.206.105.145:39156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/1.php"] [unique_id "al9LUrxMYwyVGnfuwsKKswAAA6o"]
[Tue Jul 21 07:34:58.501616 2026] [security2:error] [pid 254995:tid 255033] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alphafix.com.br"] [uri "/source/.env"] [unique_id "al9LUv7v0rlcEGmVraEwBAADaiU"]
[Tue Jul 21 07:34:58.632215 2026] [security2:error] [pid 254995:tid 255142] [client 20.206.105.145:38914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/100.php"] [unique_id "al9LUv7v0rlcEGmVraEwCAAAAy8"]
[Tue Jul 21 07:34:58.752436 2026] [security2:error] [pid 254995:tid 255225] [client 20.206.105.145:39283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/about.php"] [unique_id "al9LUv7v0rlcEGmVraEwCwAAA4E"]
[Tue Jul 21 07:34:59.016394 2026] [security2:error] [pid 254995:tid 255279] [client 20.206.105.145:39238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/admin.php"] [unique_id "al9LU_7v0rlcEGmVraEwEQAAA50"]
[Tue Jul 21 07:34:59.106982 2026] [security2:error] [pid 254995:tid 255067] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alphafix.com.br"] [uri "/framework/.env"] [unique_id "al9LU_7v0rlcEGmVraEwFgADJUc"]
[Tue Jul 21 07:34:59.113311 2026] [security2:error] [pid 255769:tid 255774] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alphafix.com.br"] [uri "/ikiwiki/.env"] [unique_id "al9LU7xMYwyVGnfuwsKKvAADrQQ"]
[Tue Jul 21 07:34:59.120888 2026] [security2:error] [pid 254995:tid 255168] [client 20.220.225.223:38709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/ftde.php"] [unique_id "al9LU_7v0rlcEGmVraEwFwAAA0k"]
[Tue Jul 21 07:34:59.227694 2026] [security2:error] [pid 254995:tid 255108] [remote 119.195.102.159:49004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9LU_7v0rlcEGmVraEwGAADZ3A"]
[Tue Jul 21 07:34:59.240150 2026] [security2:error] [pid 254995:tid 255042] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/config.inc.php"] [unique_id "al9LU_7v0rlcEGmVraEwGQADHy4"]
[Tue Jul 21 07:34:59.274403 2026] [security2:error] [pid 255769:tid 255800] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LU7xMYwyVGnfuwsKKvwADyh4"]
[Tue Jul 21 07:34:59.274538 2026] [security2:error] [pid 255769:tid 255938] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LU7xMYwyVGnfuwsKKvwADyh4"]
[Tue Jul 21 07:34:59.327182 2026] [security2:error] [pid 254995:tid 255274] [client 20.197.195.24:62631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/aaa.php"] [unique_id "al9LU_7v0rlcEGmVraEwGwAAA5g"]
[Tue Jul 21 07:34:59.419806 2026] [security2:error] [pid 255769:tid 255784] [remote 38.242.157.30:50532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9LU7xMYwyVGnfuwsKKwQAD4g4"]
[Tue Jul 21 07:34:59.585964 2026] [security2:error] [pid 255769:tid 255947] [client 20.197.195.24:13065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/a2.php"] [unique_id "al9LU7xMYwyVGnfuwsKKxQAAA9M"]
[Tue Jul 21 07:34:59.767386 2026] [security2:error] [pid 254995:tid 255058] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LU_7v0rlcEGmVraEwIQADQz4"]
[Tue Jul 21 07:34:59.767585 2026] [security2:error] [pid 254995:tid 255162] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LU_7v0rlcEGmVraEwIQADQz4"]
[Tue Jul 21 07:34:59.818270 2026] [security2:error] [pid 255769:tid 255772] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alphafix.com.br"] [uri "/system/.env"] [unique_id "al9LU7xMYwyVGnfuwsKKxwAECgI"]
[Tue Jul 21 07:34:59.827500 2026] [security2:error] [pid 254995:tid 255187] [client 59.96.220.140:52067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LU_7v0rlcEGmVraEwIwAAA1w"]
[Tue Jul 21 07:34:59.829302 2026] [security2:error] [pid 254995:tid 255187] [client 59.96.220.140:52067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LU_7v0rlcEGmVraEwIwAAA1w"]
[Tue Jul 21 07:34:59.831442 2026] [security2:error] [pid 254995:tid 255001] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LU_7v0rlcEGmVraEwJAADcQU"]
[Tue Jul 21 07:34:59.831676 2026] [security2:error] [pid 254995:tid 255209] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LU_7v0rlcEGmVraEwJAADcQU"]
[Tue Jul 21 07:34:59.851364 2026] [security2:error] [pid 255769:tid 255975] [client 20.206.105.145:39111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/edit.php"] [unique_id "al9LU7xMYwyVGnfuwsKKyAAAA-8"]
[Tue Jul 21 07:34:59.973691 2026] [security2:error] [pid 254995:tid 255258] [client 37.140.223.134:23739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LU_7v0rlcEGmVraEwKAAAA4g"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:59.997625 2026] [security2:error] [pid 255769:tid 255958] [client 20.197.195.24:62649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/file5.php"] [unique_id "al9LU7xMYwyVGnfuwsKK0AAAA94"]
[Tue Jul 21 07:35:00.428614 2026] [security2:error] [pid 255769:tid 255981] [client 20.197.195.24:62645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/222.php"] [unique_id "al9LVLxMYwyVGnfuwsKK2QAAA_U"]
[Tue Jul 21 07:35:00.554135 2026] [security2:error] [pid 255769:tid 255896] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/app_dev.php/_profiler/open"] [unique_id "al9LVLxMYwyVGnfuwsKK3gAEHH4"]
[Tue Jul 21 07:35:00.690628 2026] [security2:error] [pid 255769:tid 255976] [client 45.8.17.134:61805] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/news-portal/fm.php"] [unique_id "al9LVLxMYwyVGnfuwsKK4AAAA_A"]
[Tue Jul 21 07:35:00.753487 2026] [security2:error] [pid 255769:tid 255934] [client 20.197.195.24:62619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/test.php"] [unique_id "al9LVLxMYwyVGnfuwsKK4gAAA8Y"]
[Tue Jul 21 07:35:00.777360 2026] [security2:error] [pid 255769:tid 255907] [client 20.197.195.24:48863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/d61.php"] [unique_id "al9LVLxMYwyVGnfuwsKK4wAAA6s"]
[Tue Jul 21 07:35:00.834603 2026] [security2:error] [pid 254995:tid 255271] [client 20.220.225.223:6111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/bscclapb.php"] [unique_id "al9LVP7v0rlcEGmVraEwNAAAA5U"]
[Tue Jul 21 07:35:00.942079 2026] [security2:error] [pid 255769:tid 255941] [client 139.167.225.182:54291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LVLxMYwyVGnfuwsKK5gAAA80"]
[Tue Jul 21 07:35:00.942243 2026] [security2:error] [pid 255769:tid 255941] [client 139.167.225.182:54291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LVLxMYwyVGnfuwsKK5gAAA80"]
[Tue Jul 21 07:35:00.994417 2026] [security2:error] [pid 255769:tid 255944] [client 20.206.105.145:39249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-content/admin.php"] [unique_id "al9LVLxMYwyVGnfuwsKK6AAAA9A"]
[Tue Jul 21 07:35:01.099660 2026] [security2:error] [pid 255769:tid 255926] [client 87.58.197.194:47480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.63.71"] [uri "/.env"] [unique_id "al9LVbxMYwyVGnfuwsKK6wAAA74"]
[Tue Jul 21 07:35:01.106477 2026] [security2:error] [pid 255769:tid 255875] [remote 192.241.143.148:49288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "powerflats.com.br"] [uri "/wp-login.php"] [unique_id "al9LVbxMYwyVGnfuwsKK7AAD22k"]
[Tue Jul 21 07:35:01.211662 2026] [security2:error] [pid 255769:tid 255988] [client 20.197.195.24:62626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/aaa.php"] [unique_id "al9LVbxMYwyVGnfuwsKK7gAAA_w"]
[Tue Jul 21 07:35:01.434377 2026] [security2:error] [pid 254995:tid 255122] [remote 160.187.68.132:50658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cestabasicadocarlao.com.br"] [uri "/wp-login.php"] [unique_id "al9LVf7v0rlcEGmVraEwQAADQX4"]
[Tue Jul 21 07:35:01.701751 2026] [security2:error] [pid 255769:tid 255947] [client 20.197.195.24:62713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/11.php"] [unique_id "al9LVbxMYwyVGnfuwsKK-gAAA9M"]
[Tue Jul 21 07:35:01.871107 2026] [security2:error] [pid 255769:tid 255975] [client 20.206.105.145:38958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/f6.php"] [unique_id "al9LVbxMYwyVGnfuwsKK_wAAA-8"]
[Tue Jul 21 07:35:01.877241 2026] [security2:error] [pid 255769:tid 255901] [client 45.8.17.139:32121] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/customize/index.php"] [unique_id "al9LVbxMYwyVGnfuwsKLAAAAA6U"]
[Tue Jul 21 07:35:02.186821 2026] [security2:error] [pid 255769:tid 255902] [client 20.197.195.24:62710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/mac.php"] [unique_id "al9LVrxMYwyVGnfuwsKLBAAAA6Y"]
[Tue Jul 21 07:35:02.481912 2026] [security2:error] [pid 255769:tid 256004] [client 103.162.129.114:49211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LVrxMYwyVGnfuwsKLCQAABAo"]
[Tue Jul 21 07:35:02.482091 2026] [security2:error] [pid 255769:tid 256004] [client 103.162.129.114:49211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LVrxMYwyVGnfuwsKLCQAABAo"]
[Tue Jul 21 07:35:02.562588 2026] [security2:error] [pid 255769:tid 255959] [client 20.220.225.223:38707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/yup.php"] [unique_id "al9LVrxMYwyVGnfuwsKLCwAAA98"]
[Tue Jul 21 07:35:02.615199 2026] [security2:error] [pid 255769:tid 255817] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alphafix.com.br"] [uri "/wp-content/mysql.sql"] [unique_id "al9LVrxMYwyVGnfuwsKLDQAD0S8"]
[Tue Jul 21 07:35:02.635775 2026] [security2:error] [pid 255769:tid 255934] [client 20.197.195.24:62603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/chosen.php"] [unique_id "al9LVrxMYwyVGnfuwsKLEAAAA8Y"]
[Tue Jul 21 07:35:02.714399 2026] [security2:error] [pid 254995:tid 255255] [client 193.36.225.67:24815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LVv7v0rlcEGmVraEwUAAAA4U"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:02.771916 2026] [security2:error] [pid 254995:tid 255163] [client 117.251.86.144:57002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LVv7v0rlcEGmVraEwUgAAA0Q"]
[Tue Jul 21 07:35:02.772062 2026] [security2:error] [pid 254995:tid 255163] [client 117.251.86.144:57002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LVv7v0rlcEGmVraEwUgAAA0Q"]
[Tue Jul 21 07:35:02.843967 2026] [security2:error] [pid 255769:tid 255944] [client 20.220.225.223:48133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/berlin.php"] [unique_id "al9LVrxMYwyVGnfuwsKLFAAAA9A"]
[Tue Jul 21 07:35:02.885580 2026] [security2:error] [pid 255769:tid 256011] [client 45.8.17.62:35957] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/colors/admin.php"] [unique_id "al9LVrxMYwyVGnfuwsKLFQAABBE"]
[Tue Jul 21 07:35:03.188113 2026] [security2:error] [pid 254995:tid 255188] [client 82.102.28.107:48602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9LV_7v0rlcEGmVraEwWAAAA10"]
[Tue Jul 21 07:35:03.188239 2026] [security2:error] [pid 254995:tid 255188] [client 82.102.28.107:48602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9LV_7v0rlcEGmVraEwWAAAA10"]
[Tue Jul 21 07:35:03.277052 2026] [security2:error] [pid 255769:tid 255989] [client 20.197.195.24:13087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/info.php"] [unique_id "al9LV7xMYwyVGnfuwsKLGAAAA_0"]
[Tue Jul 21 07:35:03.288618 2026] [security2:error] [pid 255769:tid 255909] [client 20.220.225.223:24215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/term.php"] [unique_id "al9LV7xMYwyVGnfuwsKLGgAAA60"]
[Tue Jul 21 07:35:03.367402 2026] [security2:error] [pid 255769:tid 255787] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/php-info.php"] [unique_id "al9LV7xMYwyVGnfuwsKLHQADvRE"]
[Tue Jul 21 07:35:03.399556 2026] [security2:error] [pid 255769:tid 255990] [client 20.220.225.223:49549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/billur.php"] [unique_id "al9LV7xMYwyVGnfuwsKLIAAAA_4"]
[Tue Jul 21 07:35:03.457555 2026] [security2:error] [pid 255769:tid 256027] [client 122.186.204.214:49827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LV7xMYwyVGnfuwsKLIQAABCE"]
[Tue Jul 21 07:35:03.457674 2026] [security2:error] [pid 255769:tid 256027] [client 122.186.204.214:49827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LV7xMYwyVGnfuwsKLIQAABCE"]
[Tue Jul 21 07:35:03.466767 2026] [security2:error] [pid 254995:tid 255130] [client 152.59.154.239:51796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LV_7v0rlcEGmVraEwXQAAAyM"]
[Tue Jul 21 07:35:03.466869 2026] [security2:error] [pid 254995:tid 255130] [client 152.59.154.239:51796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LV_7v0rlcEGmVraEwXQAAAyM"]
[Tue Jul 21 07:35:03.750436 2026] [security2:error] [pid 254995:tid 255109] [remote 216.73.216.238:40513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/chales.php"] [unique_id "al9LV_7v0rlcEGmVraEwYQADYnE"]
[Tue Jul 21 07:35:03.783943 2026] [security2:error] [pid 255769:tid 255969] [client 173.24.185.52:65475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LV7xMYwyVGnfuwsKLJwAAA-k"]
[Tue Jul 21 07:35:03.784089 2026] [security2:error] [pid 255769:tid 255969] [client 173.24.185.52:65475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LV7xMYwyVGnfuwsKLJwAAA-k"]
[Tue Jul 21 07:35:03.806612 2026] [security2:error] [pid 255769:tid 256024] [client 45.251.232.145:57948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LV7xMYwyVGnfuwsKLKAAABB4"]
[Tue Jul 21 07:35:03.806740 2026] [security2:error] [pid 255769:tid 256024] [client 45.251.232.145:57948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LV7xMYwyVGnfuwsKLKAAABB4"]
[Tue Jul 21 07:35:03.842245 2026] [security2:error] [pid 255769:tid 255833] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/info.php.bak"] [unique_id "al9LV7xMYwyVGnfuwsKLKgAEFz8"]
[Tue Jul 21 07:35:03.842451 2026] [security2:error] [pid 255769:tid 255834] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/phpinfo.php.bak"] [unique_id "al9LV7xMYwyVGnfuwsKLKwAEF0A"]
[Tue Jul 21 07:35:04.036148 2026] [security2:error] [pid 254995:tid 255147] [client 193.36.225.102:48853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LVv7v0rlcEGmVraEwVAAAAzQ"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:35:04.088412 2026] [security2:error] [pid 255769:tid 255902] [client 45.8.17.112:23479] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/images/wp-conflg.php"] [unique_id "al9LWLxMYwyVGnfuwsKLMQAAA6Y"]
[Tue Jul 21 07:35:04.097699 2026] [security2:error] [pid 254995:tid 255209] [client 173.252.95.114:36138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LWP7v0rlcEGmVraEwZgAAA3E"]
[Tue Jul 21 07:35:04.119132 2026] [security2:error] [pid 255769:tid 255884] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LWLxMYwyVGnfuwsKLMgAD43I"]
[Tue Jul 21 07:35:04.119310 2026] [security2:error] [pid 255769:tid 255963] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LWLxMYwyVGnfuwsKLMgAD43I"]
[Tue Jul 21 07:35:04.133598 2026] [security2:error] [pid 255769:tid 255918] [client 20.197.195.24:62715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/cream1.php"] [unique_id "al9LWLxMYwyVGnfuwsKLMwAAA7Y"]
[Tue Jul 21 07:35:04.207220 2026] [security2:error] [pid 255769:tid 255981] [client 20.206.105.145:38933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/inputs.php"] [unique_id "al9LWLxMYwyVGnfuwsKLNgAAA_U"]
[Tue Jul 21 07:35:04.392268 2026] [security2:error] [pid 255769:tid 255786] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alphafix.com.br"] [uri "/env/.env"] [unique_id "al9LWLxMYwyVGnfuwsKLPgADqhA"]
[Tue Jul 21 07:35:04.470158 2026] [security2:error] [pid 255769:tid 255814] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LWLxMYwyVGnfuwsKLQAADzCw"]
[Tue Jul 21 07:35:04.470287 2026] [security2:error] [pid 255769:tid 255940] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LWLxMYwyVGnfuwsKLQAADzCw"]
[Tue Jul 21 07:35:04.532428 2026] [security2:error] [pid 255769:tid 255941] [client 20.220.225.223:6141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/else1.php"] [unique_id "al9LWLxMYwyVGnfuwsKLQQAAA80"]
[Tue Jul 21 07:35:04.806372 2026] [security2:error] [pid 255769:tid 255917] [client 20.220.225.223:49566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/bootstrap.php"] [unique_id "al9LWLxMYwyVGnfuwsKLRgAAA7U"]
[Tue Jul 21 07:35:04.825854 2026] [security2:error] [pid 255769:tid 255859] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alphafix.com.br"] [uri "/src/.env"] [unique_id "al9LWLxMYwyVGnfuwsKLSAAD_Vk"]
[Tue Jul 21 07:35:04.857946 2026] [security2:error] [pid 255769:tid 255909] [client 20.220.225.223:31168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/jj.php"] [unique_id "al9LWLxMYwyVGnfuwsKLSgAAA60"]
[Tue Jul 21 07:35:05.011622 2026] [security2:error] [pid 255769:tid 255976] [client 122.162.144.145:27020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LWbxMYwyVGnfuwsKLTgAAA_A"]
[Tue Jul 21 07:35:05.011739 2026] [security2:error] [pid 255769:tid 255976] [client 122.162.144.145:27020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LWbxMYwyVGnfuwsKLTgAAA_A"]
[Tue Jul 21 07:35:05.184583 2026] [security2:error] [pid 255769:tid 256009] [client 45.8.17.64:20693] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Text/chosen.php"] [unique_id "al9LWbxMYwyVGnfuwsKLTwAABA8"]
[Tue Jul 21 07:35:05.243538 2026] [security2:error] [pid 254995:tid 255176] [client 117.217.38.194:61555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LWf7v0rlcEGmVraEwdgAAA1E"]
[Tue Jul 21 07:35:05.243649 2026] [security2:error] [pid 254995:tid 255176] [client 117.217.38.194:61555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LWf7v0rlcEGmVraEwdgAAA1E"]
[Tue Jul 21 07:35:05.530492 2026] [security2:error] [pid 255769:tid 256008] [client 103.106.20.201:59970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LWbxMYwyVGnfuwsKLWQAABA4"]
[Tue Jul 21 07:35:05.530629 2026] [security2:error] [pid 255769:tid 256008] [client 103.106.20.201:59970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LWbxMYwyVGnfuwsKLWQAABA4"]
[Tue Jul 21 07:35:05.555005 2026] [security2:error] [pid 255769:tid 255843] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/config/app.php"] [unique_id "al9LWbxMYwyVGnfuwsKLWgAD6Ek"]
[Tue Jul 21 07:35:05.562205 2026] [security2:error] [pid 255769:tid 255836] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9LWbxMYwyVGnfuwsKLWwAD70I"]
[Tue Jul 21 07:35:05.641618 2026] [security2:error] [pid 255769:tid 256012] [client 20.52.136.55:1750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/htaccess.php"] [unique_id "al9LWbxMYwyVGnfuwsKLXgAABBI"]
[Tue Jul 21 07:35:05.720224 2026] [security2:error] [pid 254995:tid 255175] [client 20.220.225.223:6137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/tkikikoko.php"] [unique_id "al9LWf7v0rlcEGmVraEwfwAAA1A"]
[Tue Jul 21 07:35:05.767449 2026] [security2:error] [pid 254995:tid 255144] [client 20.197.195.24:48861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/11.php"] [unique_id "al9LWf7v0rlcEGmVraEwgQAAAzE"]
[Tue Jul 21 07:35:05.905124 2026] [security2:error] [pid 255769:tid 255958] [client 20.220.225.223:49822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-editor.php"] [unique_id "al9LWbxMYwyVGnfuwsKLYAAAA94"]
[Tue Jul 21 07:35:06.050598 2026] [security2:error] [pid 255769:tid 255871] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alphafix.com.br"] [uri "/web/.env"] [unique_id "al9LWrxMYwyVGnfuwsKLZQAD2GU"]
[Tue Jul 21 07:35:06.050659 2026] [security2:error] [pid 255769:tid 255781] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alphafix.com.br"] [uri "/core/.env"] [unique_id "al9LWrxMYwyVGnfuwsKLZAAD2As"]
[Tue Jul 21 07:35:06.146257 2026] [security2:error] [pid 254995:tid 255165] [client 154.192.233.199:59324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LWv7v0rlcEGmVraEwhwAAA0Y"]
[Tue Jul 21 07:35:06.146388 2026] [security2:error] [pid 254995:tid 255165] [client 154.192.233.199:59324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LWv7v0rlcEGmVraEwhwAAA0Y"]
[Tue Jul 21 07:35:06.401025 2026] [security2:error] [pid 255769:tid 255870] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/phpinfo.php3"] [unique_id "al9LWrxMYwyVGnfuwsKLawADt2Q"]
[Tue Jul 21 07:35:06.592706 2026] [security2:error] [pid 255769:tid 255831] [remote 65.111.0.167:42973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.0.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9LWLxMYwyVGnfuwsKLQgAD-z0"]
[Tue Jul 21 07:35:06.701819 2026] [security2:error] [pid 255769:tid 255926] [client 20.220.225.223:31123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/dragonshell.php"] [unique_id "al9LWrxMYwyVGnfuwsKLdgAAA74"]
[Tue Jul 21 07:35:06.890439 2026] [security2:error] [pid 255769:tid 256027] [client 45.8.17.125:41237] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/chosen.php"] [unique_id "al9LWrxMYwyVGnfuwsKLegAABCE"]
[Tue Jul 21 07:35:07.065660 2026] [security2:error] [pid 255769:tid 256003] [client 20.206.105.145:39291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/av.php"] [unique_id "al9LW7xMYwyVGnfuwsKLfQAABAk"]
[Tue Jul 21 07:35:07.170784 2026] [security2:error] [pid 255769:tid 255955] [client 175.45.70.82:60289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LW7xMYwyVGnfuwsKLfwAAA9s"]
[Tue Jul 21 07:35:07.170935 2026] [security2:error] [pid 255769:tid 255955] [client 175.45.70.82:60289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LW7xMYwyVGnfuwsKLfwAAA9s"]
[Tue Jul 21 07:35:07.183796 2026] [security2:error] [pid 254995:tid 255127] [client 213.152.162.104:58988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9LW_7v0rlcEGmVraEwmAAAAyA"]
[Tue Jul 21 07:35:07.183908 2026] [security2:error] [pid 254995:tid 255127] [client 213.152.162.104:58988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9LW_7v0rlcEGmVraEwmAAAAyA"]
[Tue Jul 21 07:35:07.230020 2026] [security2:error] [pid 255769:tid 256001] [client 128.140.106.114:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9LW7xMYwyVGnfuwsKLgAAEB1s"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:35:07.281624 2026] [autoindex:error] [pid 255769:tid 255901] [client 20.197.195.24:62668] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:07.475014 2026] [security2:error] [pid 254995:tid 255182] [client 193.36.225.57:62763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LW_7v0rlcEGmVraEwmgAAA1c"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:07.574255 2026] [security2:error] [pid 255769:tid 255951] [client 20.220.225.223:49840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/cro.php"] [unique_id "al9LW7xMYwyVGnfuwsKLhgAAA9c"]
[Tue Jul 21 07:35:07.583557 2026] [security2:error] [pid 254995:tid 255056] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LW_7v0rlcEGmVraEwoAADNjw"]
[Tue Jul 21 07:35:07.583658 2026] [security2:error] [pid 254995:tid 255149] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LW_7v0rlcEGmVraEwoAADNjw"]
[Tue Jul 21 07:35:07.689050 2026] [security2:error] [pid 255769:tid 256021] [client 45.8.17.137:48941] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/system.php"] [unique_id "al9LW7xMYwyVGnfuwsKLhwAABBs"]
[Tue Jul 21 07:35:07.756075 2026] [rewrite:error] [pid 254995:tid 255155] [client 187.49.76.218:19201] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:35:07.758460 2026] [rewrite:error] [pid 254995:tid 255271] [client 187.49.76.218:19233] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:35:07.774376 2026] [security2:error] [pid 254995:tid 255223] [client 128.140.106.114:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9LW_7v0rlcEGmVraEwpwADfyE"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:35:07.777775 2026] [rewrite:error] [pid 254995:tid 255268] [client 187.49.76.218:19265] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:35:07.926860 2026] [security2:error] [pid 254995:tid 255218] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LW_7v0rlcEGmVraEwqwADekw"]
[Tue Jul 21 07:35:07.993376 2026] [security2:error] [pid 255769:tid 255975] [client 103.174.34.15:52303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LW7xMYwyVGnfuwsKLigAAA-8"]
[Tue Jul 21 07:35:07.993481 2026] [security2:error] [pid 255769:tid 255975] [client 103.174.34.15:52303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LW7xMYwyVGnfuwsKLigAAA-8"]
[Tue Jul 21 07:35:08.000714 2026] [security2:error] [pid 255769:tid 255952] [client 20.197.195.24:48840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/v2.php"] [unique_id "al9LXLxMYwyVGnfuwsKLiwAAA9g"]
[Tue Jul 21 07:35:08.033805 2026] [autoindex:error] [pid 255769:tid 255977] [client 20.197.195.24:62668] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:08.056164 2026] [security2:error] [pid 255769:tid 255943] [client 20.197.195.24:62668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/dr.php"] [unique_id "al9LXLxMYwyVGnfuwsKLjQAAA88"]
[Tue Jul 21 07:35:08.097315 2026] [security2:error] [pid 254995:tid 255063] [remote 152.42.137.70:49868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.137.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9LXP7v0rlcEGmVraEwsAADN0M"]
[Tue Jul 21 07:35:08.202495 2026] [security2:error] [pid 255769:tid 255838] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LXLxMYwyVGnfuwsKLjwADo0Q"]
[Tue Jul 21 07:35:08.202606 2026] [security2:error] [pid 255769:tid 255899] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LXLxMYwyVGnfuwsKLjwADo0Q"]
[Tue Jul 21 07:35:08.991613 2026] [security2:error] [pid 255769:tid 255959] [client 45.8.17.140:32507] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/PHPMailer/wp-conflg.php"] [unique_id "al9LXLxMYwyVGnfuwsKLnwAAA98"]
[Tue Jul 21 07:35:09.056392 2026] [security2:error] [pid 255769:tid 255962] [client 20.197.195.24:62717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/x.php"] [unique_id "al9LXbxMYwyVGnfuwsKLoQAAA-I"]
[Tue Jul 21 07:35:09.096326 2026] [security2:error] [pid 255769:tid 256002] [client 20.220.225.223:49593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/cron-tab.php"] [unique_id "al9LXbxMYwyVGnfuwsKLogAABAg"]
[Tue Jul 21 07:35:09.261733 2026] [security2:error] [pid 254995:tid 255262] [client 20.206.105.145:39254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/classwithtostring.php"] [unique_id "al9LXf7v0rlcEGmVraEwwwAAA4w"]
[Tue Jul 21 07:35:09.821982 2026] [security2:error] [pid 254995:tid 255143] [client 20.197.195.24:48894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/panel.php"] [unique_id "al9LXf7v0rlcEGmVraEwzQAAAzA"]
[Tue Jul 21 07:35:09.905099 2026] [security2:error] [pid 255769:tid 255881] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LXbxMYwyVGnfuwsKLrgAEAm8"]
[Tue Jul 21 07:35:09.905278 2026] [security2:error] [pid 255769:tid 255996] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LXbxMYwyVGnfuwsKLrgAEAm8"]
[Tue Jul 21 07:35:10.014196 2026] [security2:error] [pid 254995:tid 255042] [remote 212.80.9.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.9.80.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/wp-login.php"] [unique_id "al9LXv7v0rlcEGmVraEw0wADaC4"]
[Tue Jul 21 07:35:10.085118 2026] [security2:error] [pid 255769:tid 255945] [client 45.8.17.60:37177] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/news-portal/wp-admins.php"] [unique_id "al9LXrxMYwyVGnfuwsKLtAAAA9E"]
[Tue Jul 21 07:35:10.285831 2026] [security2:error] [pid 255769:tid 255853] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LXrxMYwyVGnfuwsKLtwADrVM"]
[Tue Jul 21 07:35:10.285962 2026] [security2:error] [pid 255769:tid 255909] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LXrxMYwyVGnfuwsKLtwADrVM"]
[Tue Jul 21 07:35:10.385185 2026] [security2:error] [pid 255769:tid 255813] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LXrxMYwyVGnfuwsKLuwAD5ys"]
[Tue Jul 21 07:35:10.385326 2026] [security2:error] [pid 255769:tid 255967] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LXrxMYwyVGnfuwsKLuwAD5ys"]
[Tue Jul 21 07:35:10.430835 2026] [security2:error] [pid 255769:tid 255925] [client 20.197.195.24:62685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/155.php"] [unique_id "al9LXrxMYwyVGnfuwsKLvAAAA70"]
[Tue Jul 21 07:35:10.442394 2026] [security2:error] [pid 255769:tid 255951] [client 59.96.220.140:52585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LXrxMYwyVGnfuwsKLvQAAA9c"]
[Tue Jul 21 07:35:10.443214 2026] [security2:error] [pid 255769:tid 255951] [client 59.96.220.140:52585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LXrxMYwyVGnfuwsKLvQAAA9c"]
[Tue Jul 21 07:35:10.896948 2026] [security2:error] [pid 255769:tid 255931] [client 45.8.17.103:52979] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/images/chosen.php"] [unique_id "al9LXrxMYwyVGnfuwsKLygAAA8M"]
[Tue Jul 21 07:35:10.911804 2026] [security2:error] [pid 255769:tid 256020] [client 20.197.195.24:62669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/ops.php"] [unique_id "al9LXrxMYwyVGnfuwsKLzAAABBo"]
[Tue Jul 21 07:35:11.311351 2026] [security2:error] [pid 255769:tid 255975] [client 20.220.225.223:24212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/ah25.php"] [unique_id "al9LX7xMYwyVGnfuwsKMDwAAA-8"]
[Tue Jul 21 07:35:11.639460 2026] [security2:error] [pid 255769:tid 255927] [client 139.167.225.182:55076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LX7xMYwyVGnfuwsKMGAAAA78"]
[Tue Jul 21 07:35:11.639552 2026] [security2:error] [pid 255769:tid 255927] [client 139.167.225.182:55076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LX7xMYwyVGnfuwsKMGAAAA78"]
[Tue Jul 21 07:35:11.730641 2026] [security2:error] [pid 255769:tid 255962] [client 69.171.230.27:38410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LXrxMYwyVGnfuwsKLwAAAA-I"]
[Tue Jul 21 07:35:11.784070 2026] [security2:error] [pid 255769:tid 256006] [client 20.197.195.24:50341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/file31.php"] [unique_id "al9LX7xMYwyVGnfuwsKMHQAABAw"]
[Tue Jul 21 07:35:11.899184 2026] [security2:error] [pid 255769:tid 256022] [client 172.245.102.44:33999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LX7xMYwyVGnfuwsKMIwAABBw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:12.164081 2026] [security2:error] [pid 254995:tid 255131] [client 20.197.195.24:62618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/file6.php"] [unique_id "al9LYP7v0rlcEGmVraEw8AAAAyQ"]
[Tue Jul 21 07:35:12.258950 2026] [security2:error] [pid 255769:tid 255923] [client 20.52.136.55:1756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/readme.php"] [unique_id "al9LYLxMYwyVGnfuwsKMJQAAA7s"]
[Tue Jul 21 07:35:12.441561 2026] [security2:error] [pid 255769:tid 255920] [client 20.220.225.223:49829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/koiy.php"] [unique_id "al9LYLxMYwyVGnfuwsKMKgAAA7g"]
[Tue Jul 21 07:35:12.465533 2026] [autoindex:error] [pid 255769:tid 255919] [client 20.197.195.24:62654] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:12.489616 2026] [security2:error] [pid 255769:tid 256011] [client 20.197.195.24:62654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/adminfuns.php"] [unique_id "al9LYLxMYwyVGnfuwsKMLQAABBE"]
[Tue Jul 21 07:35:12.533201 2026] [security2:error] [pid 255769:tid 255952] [client 168.119.53.160:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9LYLxMYwyVGnfuwsKMLgAD2BY"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:35:12.553276 2026] [security2:error] [pid 255769:tid 256010] [client 185.213.175.37:40356] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/"] [unique_id "al9LYLxMYwyVGnfuwsKMLwAABBA"]
[Tue Jul 21 07:35:12.692453 2026] [security2:error] [pid 254995:tid 255163] [client 45.8.17.124:61813] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css.php"] [unique_id "al9LYP7v0rlcEGmVraEw-wAAA0Q"]
[Tue Jul 21 07:35:12.760841 2026] [security2:error] [pid 255769:tid 255990] [client 168.119.53.160:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9LYLxMYwyVGnfuwsKMNQAD_hw"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:35:12.912981 2026] [security2:error] [pid 255769:tid 256027] [client 20.197.195.24:62646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/goods.php"] [unique_id "al9LYLxMYwyVGnfuwsKMNwAABCE"]
[Tue Jul 21 07:35:13.094850 2026] [security2:error] [pid 255769:tid 256002] [client 20.206.105.145:39149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9LYbxMYwyVGnfuwsKMOAAABAg"]
[Tue Jul 21 07:35:13.358818 2026] [security2:error] [pid 255769:tid 255976] [client 103.162.129.114:49649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LYbxMYwyVGnfuwsKMPgAAA_A"]
[Tue Jul 21 07:35:13.358932 2026] [security2:error] [pid 255769:tid 255976] [client 103.162.129.114:49649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LYbxMYwyVGnfuwsKMPgAAA_A"]
[Tue Jul 21 07:35:13.371479 2026] [security2:error] [pid 255769:tid 255937] [client 74.7.241.184:45380] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "orixmed.com.inlaudo.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9LYbxMYwyVGnfuwsKMQAADySI"]
[Tue Jul 21 07:35:13.397929 2026] [security2:error] [pid 255769:tid 255897] [remote 104.207.58.230:47405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9LYbxMYwyVGnfuwsKMQgAD338"]
[Tue Jul 21 07:35:13.439385 2026] [security2:error] [pid 254995:tid 255135] [client 117.251.86.144:39372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LYf7v0rlcEGmVraExCAAAAyg"]
[Tue Jul 21 07:35:13.439494 2026] [security2:error] [pid 254995:tid 255135] [client 117.251.86.144:39372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LYf7v0rlcEGmVraExCAAAAyg"]
[Tue Jul 21 07:35:13.698375 2026] [security2:error] [pid 255769:tid 256010] [client 20.206.105.145:38944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-blog.php"] [unique_id "al9LYbxMYwyVGnfuwsKMTQAABBA"]
[Tue Jul 21 07:35:13.702315 2026] [security2:error] [pid 255769:tid 255977] [client 20.197.195.24:13068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/dex.php"] [unique_id "al9LYbxMYwyVGnfuwsKMTgAAA_E"]
[Tue Jul 21 07:35:13.711672 2026] [security2:error] [pid 254995:tid 255168] [client 20.197.195.24:62650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/100.php"] [unique_id "al9LYf7v0rlcEGmVraExDAAAA0k"]
[Tue Jul 21 07:35:13.832174 2026] [security2:error] [pid 255769:tid 255909] [client 74.7.230.46:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "304"] [hostname "www.digiterapia.com.br"] [uri "/public/robots.txt"] [unique_id "al9LYbxMYwyVGnfuwsKMUAADrUQ"]
[Tue Jul 21 07:35:14.117450 2026] [security2:error] [pid 254995:tid 255200] [client 20.197.195.24:13154] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "eduardogoesadv.com"] [uri "/1.php"] [unique_id "al9LYv7v0rlcEGmVraExFAAAA2k"]
[Tue Jul 21 07:35:14.117557 2026] [security2:error] [pid 254995:tid 255200] [client 20.197.195.24:13154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/1.php"] [unique_id "al9LYv7v0rlcEGmVraExFAAAA2k"]
[Tue Jul 21 07:35:14.190899 2026] [security2:error] [pid 255769:tid 256012] [client 122.186.204.214:50341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LYrxMYwyVGnfuwsKMVAAABBI"]
[Tue Jul 21 07:35:14.191070 2026] [security2:error] [pid 255769:tid 256012] [client 122.186.204.214:50341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LYrxMYwyVGnfuwsKMVAAABBI"]
[Tue Jul 21 07:35:14.252931 2026] [security2:error] [pid 255769:tid 255947] [client 20.197.195.24:50349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/about.php"] [unique_id "al9LYrxMYwyVGnfuwsKMXQAAA9M"]
[Tue Jul 21 07:35:14.261132 2026] [security2:error] [pid 254995:tid 255275] [client 45.251.232.145:58475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LYv7v0rlcEGmVraExFwAAA5k"]
[Tue Jul 21 07:35:14.261213 2026] [security2:error] [pid 254995:tid 255275] [client 45.251.232.145:58475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LYv7v0rlcEGmVraExFwAAA5k"]
[Tue Jul 21 07:35:14.262080 2026] [security2:error] [pid 254995:tid 255180] [client 74.7.241.163:43964] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "carlaalbuquerqueugc.online"] [uri "/index.php"] [unique_id "al9LYf7v0rlcEGmVraExDQADVX0"]
[Tue Jul 21 07:35:14.314517 2026] [proxy:error] [pid 254995:tid 255218] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:35:14.314586 2026] [proxy_http:error] [pid 254995:tid 255218] [client 20.206.105.145:38970] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:35:14.315148 2026] [proxy:error] [pid 254995:tid 255218] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:35:14.315174 2026] [proxy_http:error] [pid 254995:tid 255218] [client 20.206.105.145:38970] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:35:14.347019 2026] [security2:error] [pid 255769:tid 256018] [client 20.197.195.24:48802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/ms.php"] [unique_id "al9LYrxMYwyVGnfuwsKMXwAABBg"]
[Tue Jul 21 07:35:14.433245 2026] [security2:error] [pid 255769:tid 255985] [client 173.24.185.52:49614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LYrxMYwyVGnfuwsKMYQAAA_k"]
[Tue Jul 21 07:35:14.433328 2026] [security2:error] [pid 255769:tid 255985] [client 173.24.185.52:49614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LYrxMYwyVGnfuwsKMYQAAA_k"]
[Tue Jul 21 07:35:14.762733 2026] [security2:error] [pid 255769:tid 255826] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LYrxMYwyVGnfuwsKMcQAD6zg"]
[Tue Jul 21 07:35:14.762895 2026] [security2:error] [pid 255769:tid 255971] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LYrxMYwyVGnfuwsKMcQAD6zg"]
[Tue Jul 21 07:35:14.869942 2026] [security2:error] [pid 255769:tid 255948] [client 69.171.230.41:39536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LYLxMYwyVGnfuwsKMNAAAA9Q"]
[Tue Jul 21 07:35:14.873090 2026] [security2:error] [pid 255769:tid 255940] [client 45.8.17.58:38713] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/pwnd/pwnd.php"] [unique_id "al9LYrxMYwyVGnfuwsKMegAAA8w"]
[Tue Jul 21 07:35:15.028049 2026] [security2:error] [pid 255769:tid 256003] [client 20.220.225.223:49793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/hp2.php"] [unique_id "al9LY7xMYwyVGnfuwsKMfgAABAk"]
[Tue Jul 21 07:35:15.159647 2026] [security2:error] [pid 255769:tid 255927] [client 20.197.195.24:49170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/about.php"] [unique_id "al9LY7xMYwyVGnfuwsKMfwAAA78"]
[Tue Jul 21 07:35:15.168571 2026] [security2:error] [pid 254995:tid 255120] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LY_7v0rlcEGmVraExIgADl3w"]
[Tue Jul 21 07:35:15.168724 2026] [security2:error] [pid 254995:tid 255273] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LY_7v0rlcEGmVraExIgADl3w"]
[Tue Jul 21 07:35:15.499514 2026] [security2:error] [pid 255769:tid 255921] [client 136.144.33.99:56775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LY7xMYwyVGnfuwsKMhwAAA7k"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:15.542376 2026] [security2:error] [pid 254995:tid 255279] [client 74.7.230.23:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "guilhermegleinobende1781912616969.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9LY_7v0rlcEGmVraExKQADnQg"]
[Tue Jul 21 07:35:15.713846 2026] [security2:error] [pid 254995:tid 255265] [client 122.162.144.145:31623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LY_7v0rlcEGmVraExKgAAA48"]
[Tue Jul 21 07:35:15.713952 2026] [security2:error] [pid 254995:tid 255265] [client 122.162.144.145:31623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LY_7v0rlcEGmVraExKgAAA48"]
[Tue Jul 21 07:35:15.724631 2026] [security2:error] [pid 255769:tid 255901] [client 117.217.38.194:62009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LY7xMYwyVGnfuwsKMjQAAA6U"]
[Tue Jul 21 07:35:15.724726 2026] [security2:error] [pid 255769:tid 255901] [client 117.217.38.194:62009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LY7xMYwyVGnfuwsKMjQAAA6U"]
[Tue Jul 21 07:35:15.875277 2026] [security2:error] [pid 255769:tid 255907] [client 45.8.17.126:60311] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/advanced-product-fields-for-woocommerce/db.php"] [unique_id "al9LY7xMYwyVGnfuwsKMkwAAA6s"]
[Tue Jul 21 07:35:15.880438 2026] [security2:error] [pid 255769:tid 255941] [client 20.197.195.24:62614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/admin.php"] [unique_id "al9LY7xMYwyVGnfuwsKMlAAAA80"]
[Tue Jul 21 07:35:16.142725 2026] [security2:error] [pid 254995:tid 255220] [client 20.206.105.145:39144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-content/admin.php"] [unique_id "al9LZP7v0rlcEGmVraExMQAAA3w"]
[Tue Jul 21 07:35:16.323188 2026] [security2:error] [pid 255769:tid 255968] [client 103.106.20.201:60566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZLxMYwyVGnfuwsKMmwAAA-g"]
[Tue Jul 21 07:35:16.323274 2026] [security2:error] [pid 255769:tid 255968] [client 103.106.20.201:60566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZLxMYwyVGnfuwsKMmwAAA-g"]
[Tue Jul 21 07:35:16.326826 2026] [security2:error] [pid 255769:tid 255945] [client 20.220.225.223:6090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/wp-Blogs.php"] [unique_id "al9LZLxMYwyVGnfuwsKMnAAAA9E"]
[Tue Jul 21 07:35:16.377009 2026] [autoindex:error] [pid 255769:tid 256004] [client 20.197.195.24:48842] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:16.406306 2026] [security2:error] [pid 255769:tid 255899] [client 20.197.195.24:48842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/memberfuns.php"] [unique_id "al9LZLxMYwyVGnfuwsKMngAAA6M"]
[Tue Jul 21 07:35:16.413468 2026] [security2:error] [pid 255769:tid 255894] [remote 207.180.241.245:56044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9LZLxMYwyVGnfuwsKMnwADrXw"]
[Tue Jul 21 07:35:16.651906 2026] [security2:error] [pid 255769:tid 255973] [client 152.59.154.239:52341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZLxMYwyVGnfuwsKMowAAA-0"]
[Tue Jul 21 07:35:16.652058 2026] [security2:error] [pid 255769:tid 255973] [client 152.59.154.239:52341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZLxMYwyVGnfuwsKMowAAA-0"]
[Tue Jul 21 07:35:16.717412 2026] [security2:error] [pid 254995:tid 255148] [client 20.220.225.223:31188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9LZP7v0rlcEGmVraExOgAAAzU"]
[Tue Jul 21 07:35:16.757542 2026] [security2:error] [pid 254995:tid 255054] [remote 64.225.121.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onlinebuyerwebsite.com"] [uri "/wp-login.php"] [unique_id "al9LZP7v0rlcEGmVraExOwADXTo"]
[Tue Jul 21 07:35:16.789349 2026] [security2:error] [pid 255769:tid 256013] [client 154.192.233.199:60129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZLxMYwyVGnfuwsKMpAAABBM"]
[Tue Jul 21 07:35:16.789469 2026] [security2:error] [pid 255769:tid 256013] [client 154.192.233.199:60129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZLxMYwyVGnfuwsKMpAAABBM"]
[Tue Jul 21 07:35:16.883145 2026] [security2:error] [pid 255769:tid 255917] [client 45.33.101.131:51126] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "ns1103.hostgator.com.br"] [uri "/"] [unique_id "al9LZLxMYwyVGnfuwsKMqAAAA7U"]
[Tue Jul 21 07:35:16.956114 2026] [security2:error] [pid 255769:tid 256022] [client 20.197.195.24:62594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/admin.php"] [unique_id "al9LZLxMYwyVGnfuwsKMqwAABBw"]
[Tue Jul 21 07:35:17.087455 2026] [security2:error] [pid 254995:tid 255192] [client 20.197.195.24:13135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/0.php"] [unique_id "al9LZf7v0rlcEGmVraExRQAAA2E"]
[Tue Jul 21 07:35:17.185930 2026] [security2:error] [pid 254995:tid 255135] [client 45.8.17.148:33405] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/wp.php"] [unique_id "al9LZf7v0rlcEGmVraExRgAAAyg"]
[Tue Jul 21 07:35:17.391659 2026] [security2:error] [pid 255769:tid 255907] [client 20.197.195.24:62616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/themes.php"] [unique_id "al9LZbxMYwyVGnfuwsKMsQAAA6s"]
[Tue Jul 21 07:35:17.513872 2026] [security2:error] [pid 255769:tid 255928] [client 20.197.195.24:48851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/BDKR28.php"] [unique_id "al9LZbxMYwyVGnfuwsKMsgAAA8A"]
[Tue Jul 21 07:35:17.771879 2026] [security2:error] [pid 255769:tid 255988] [client 20.220.225.223:38665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/wp-mt.php"] [unique_id "al9LZbxMYwyVGnfuwsKMtgAAA_w"]
[Tue Jul 21 07:35:17.804018 2026] [autoindex:error] [pid 255769:tid 255969] [client 20.197.195.24:62672] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:17.845957 2026] [security2:error] [pid 255769:tid 255926] [client 20.197.195.24:48872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/green1.php"] [unique_id "al9LZbxMYwyVGnfuwsKMugAAA74"]
[Tue Jul 21 07:35:17.897484 2026] [security2:error] [pid 255769:tid 255774] [remote 160.187.68.132:56652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cdatecnologia.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZbxMYwyVGnfuwsKMvQAECQQ"]
[Tue Jul 21 07:35:17.897619 2026] [security2:error] [pid 255769:tid 256003] [client 160.187.68.132:56652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cdatecnologia.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZbxMYwyVGnfuwsKMvQAECQQ"]
[Tue Jul 21 07:35:17.947349 2026] [security2:error] [pid 255769:tid 255996] [client 175.45.70.82:60812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZbxMYwyVGnfuwsKMvgAABAI"]
[Tue Jul 21 07:35:17.947506 2026] [security2:error] [pid 255769:tid 255996] [client 175.45.70.82:60812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZbxMYwyVGnfuwsKMvgAABAI"]
[Tue Jul 21 07:35:18.135945 2026] [security2:error] [pid 255769:tid 255848] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LZrxMYwyVGnfuwsKMxAADrU4"]
[Tue Jul 21 07:35:18.136067 2026] [security2:error] [pid 255769:tid 255909] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LZrxMYwyVGnfuwsKMxAADrU4"]
[Tue Jul 21 07:35:18.355618 2026] [security2:error] [pid 255769:tid 255998] [client 20.197.195.24:13105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/nc4.php"] [unique_id "al9LZrxMYwyVGnfuwsKMxQAABAQ"]
[Tue Jul 21 07:35:18.463663 2026] [security2:error] [pid 255769:tid 255946] [client 20.220.225.223:31169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9LZrxMYwyVGnfuwsKMyAAAA9I"]
[Tue Jul 21 07:35:18.556187 2026] [security2:error] [pid 255769:tid 256009] [client 37.140.223.150:38047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LZrxMYwyVGnfuwsKMyQAABA8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:35:18.737595 2026] [security2:error] [pid 255769:tid 255925] [client 103.174.34.15:52788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZrxMYwyVGnfuwsKMzQAAA70"]
[Tue Jul 21 07:35:18.737699 2026] [security2:error] [pid 255769:tid 255925] [client 103.174.34.15:52788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZrxMYwyVGnfuwsKMzQAAA70"]
[Tue Jul 21 07:35:18.742708 2026] [security2:error] [pid 255769:tid 255921] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LZrxMYwyVGnfuwsKMzAADuUA"]
[Tue Jul 21 07:35:18.759500 2026] [security2:error] [pid 255769:tid 255829] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZrxMYwyVGnfuwsKMzgADwzs"]
[Tue Jul 21 07:35:18.759632 2026] [security2:error] [pid 255769:tid 255931] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZrxMYwyVGnfuwsKMzgADwzs"]
[Tue Jul 21 07:35:18.827595 2026] [security2:error] [pid 255769:tid 255908] [client 122.164.127.47:64290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LZrxMYwyVGnfuwsKMzwAAA6w"]
[Tue Jul 21 07:35:18.827717 2026] [security2:error] [pid 255769:tid 255908] [client 122.164.127.47:64290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LZrxMYwyVGnfuwsKMzwAAA6w"]
[Tue Jul 21 07:35:18.869823 2026] [security2:error] [pid 255769:tid 255856] [remote 5.252.52.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9LZrxMYwyVGnfuwsKM0AADulY"]
[Tue Jul 21 07:35:18.872277 2026] [security2:error] [pid 255769:tid 256010] [client 45.8.17.73:64177] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9LZrxMYwyVGnfuwsKM0QAABBA"]
[Tue Jul 21 07:35:19.679179 2026] [security2:error] [pid 255769:tid 255899] [client 20.220.225.223:51516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/hp3.php"] [unique_id "al9LZ7xMYwyVGnfuwsKM3gAAA6M"]
[Tue Jul 21 07:35:19.732203 2026] [security2:error] [pid 255769:tid 255909] [client 213.152.162.104:53120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9LZ7xMYwyVGnfuwsKM4wAAA60"]
[Tue Jul 21 07:35:19.732292 2026] [security2:error] [pid 255769:tid 255909] [client 213.152.162.104:53120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9LZ7xMYwyVGnfuwsKM4wAAA60"]
[Tue Jul 21 07:35:19.814715 2026] [security2:error] [pid 255769:tid 255891] [remote 216.73.216.238:24122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/chales.php"] [unique_id "al9LZ7xMYwyVGnfuwsKM5QAECnk"]
[Tue Jul 21 07:35:19.815110 2026] [core:alert] [pid 255769:tid 255947] [client 57.141.18.22:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:35:19.882761 2026] [security2:error] [pid 255769:tid 255918] [client 45.8.17.59:45791] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al9LZ7xMYwyVGnfuwsKM5wAAA7Y"]
[Tue Jul 21 07:35:20.006809 2026] [security2:error] [pid 255769:tid 255962] [client 20.197.195.24:48827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/a1.php"] [unique_id "al9LaLxMYwyVGnfuwsKM6QAAA-I"]
[Tue Jul 21 07:35:20.080628 2026] [security2:error] [pid 255769:tid 255972] [client 136.144.33.98:35011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LaLxMYwyVGnfuwsKM7wAAA-w"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:20.588334 2026] [security2:error] [pid 254995:tid 255087] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LaP7v0rlcEGmVraExeAADRls"]
[Tue Jul 21 07:35:20.588475 2026] [security2:error] [pid 254995:tid 255165] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LaP7v0rlcEGmVraExeAADRls"]
[Tue Jul 21 07:35:20.785928 2026] [security2:error] [pid 255769:tid 255969] [client 213.152.162.104:33382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LaLxMYwyVGnfuwsKM_AAAA-k"]
[Tue Jul 21 07:35:20.786010 2026] [security2:error] [pid 255769:tid 255969] [client 213.152.162.104:33382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LaLxMYwyVGnfuwsKM_AAAA-k"]
[Tue Jul 21 07:35:20.814906 2026] [security2:error] [pid 255769:tid 255778] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LaLxMYwyVGnfuwsKM_QADuwg"]
[Tue Jul 21 07:35:20.815066 2026] [security2:error] [pid 255769:tid 255923] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LaLxMYwyVGnfuwsKM_QADuwg"]
[Tue Jul 21 07:35:20.934721 2026] [security2:error] [pid 255769:tid 255770] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LaLxMYwyVGnfuwsKM_gAD6AA"]
[Tue Jul 21 07:35:20.934922 2026] [security2:error] [pid 255769:tid 255968] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LaLxMYwyVGnfuwsKM_gAD6AA"]
[Tue Jul 21 07:35:21.051988 2026] [security2:error] [pid 254995:tid 255205] [client 213.152.162.104:53132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Laf7v0rlcEGmVraExfwAAA24"]
[Tue Jul 21 07:35:21.052096 2026] [security2:error] [pid 254995:tid 255205] [client 213.152.162.104:53132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Laf7v0rlcEGmVraExfwAAA24"]
[Tue Jul 21 07:35:21.136263 2026] [security2:error] [pid 255769:tid 256002] [client 20.197.195.24:48877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/eee.php"] [unique_id "al9LabxMYwyVGnfuwsKNBAAABAg"]
[Tue Jul 21 07:35:21.175334 2026] [security2:error] [pid 254995:tid 255270] [client 45.8.17.48:52263] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/Simple.php"] [unique_id "al9Laf7v0rlcEGmVraExgAAAA5Q"]
[Tue Jul 21 07:35:21.336300 2026] [security2:error] [pid 255769:tid 255948] [client 216.73.160.183:40429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9LabxMYwyVGnfuwsKNCAAAA9Q"]
[Tue Jul 21 07:35:21.501700 2026] [security2:error] [pid 254995:tid 255225] [client 216.73.160.25:62561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9Laf7v0rlcEGmVraExggAAA4E"]
[Tue Jul 21 07:35:21.503275 2026] [security2:error] [pid 255769:tid 255988] [client 216.73.160.39:25757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.160.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9LabxMYwyVGnfuwsKNCQAAA_w"]
[Tue Jul 21 07:35:21.510887 2026] [security2:error] [pid 254995:tid 255260] [client 59.96.220.140:53091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Laf7v0rlcEGmVraExhAAAA4o"]
[Tue Jul 21 07:35:21.510966 2026] [security2:error] [pid 254995:tid 255260] [client 59.96.220.140:53091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Laf7v0rlcEGmVraExhAAAA4o"]
[Tue Jul 21 07:35:21.517215 2026] [security2:error] [pid 255769:tid 255882] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "santaofertas.com.br"] [uri "/.env"] [unique_id "al9LabxMYwyVGnfuwsKNCwADtHA"]
[Tue Jul 21 07:35:21.532137 2026] [security2:error] [pid 255769:tid 255971] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "santaofertas.com.br.anapaulaguimaraesdos1781613203317.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9LabxMYwyVGnfuwsKNDQAAA-s"]
[Tue Jul 21 07:35:21.602648 2026] [security2:error] [pid 255769:tid 255917] [client 20.197.195.24:62672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/.well-known/about.php"] [unique_id "al9LabxMYwyVGnfuwsKNEQAAA7U"]
[Tue Jul 21 07:35:21.662966 2026] [security2:error] [pid 255769:tid 255806] [remote 74.7.243.250:51534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orixmed.com.inlaudo.com.br"] [uri "/blog/artigo2.php"] [unique_id "al9LabxMYwyVGnfuwsKNCgAD-SQ"], referer: https://orixmed.com.inlaudo.com.br/blog/
[Tue Jul 21 07:35:21.681544 2026] [security2:error] [pid 255769:tid 255941] [client 20.197.195.24:50333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9LabxMYwyVGnfuwsKNEwAAA80"]
[Tue Jul 21 07:35:21.922660 2026] [security2:error] [pid 254995:tid 255168] [client 20.197.195.24:62704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/wefile.php"] [unique_id "al9Laf7v0rlcEGmVraExiwAAA0k"]
[Tue Jul 21 07:35:21.998408 2026] [security2:error] [pid 254995:tid 255193] [client 216.73.160.194:33433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9Laf7v0rlcEGmVraExjAAAA2I"]
[Tue Jul 21 07:35:22.116153 2026] [security2:error] [pid 254995:tid 255211] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "santaofertas.com.br"] [uri "/.env"] [unique_id "al9Lav7v0rlcEGmVraExkQAAA3M"]
[Tue Jul 21 07:35:22.125960 2026] [security2:error] [pid 254995:tid 255169] [client 172.245.102.30:58675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LaP7v0rlcEGmVraExfAAAA0o"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:35:22.207201 2026] [security2:error] [pid 255769:tid 255963] [client 20.197.195.24:48891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp-aothait.php"] [unique_id "al9LarxMYwyVGnfuwsKNHAAAA-M"]
[Tue Jul 21 07:35:22.363777 2026] [security2:error] [pid 254995:tid 255192] [client 139.167.225.182:55869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lav7v0rlcEGmVraExlwAAA2E"]
[Tue Jul 21 07:35:22.363934 2026] [security2:error] [pid 254995:tid 255192] [client 139.167.225.182:55869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lav7v0rlcEGmVraExlwAAA2E"]
[Tue Jul 21 07:35:22.624978 2026] [security2:error] [pid 255769:tid 255946] [client 20.197.195.24:62661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9LarxMYwyVGnfuwsKNJQAAA9I"]
[Tue Jul 21 07:35:22.863521 2026] [security2:error] [pid 254995:tid 255125] [client 20.206.105.145:39105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/adminfuns.php"] [unique_id "al9Lav7v0rlcEGmVraExpAAAAx4"]
[Tue Jul 21 07:35:22.868775 2026] [autoindex:error] [pid 255769:tid 255948] [client 20.197.195.24:49195] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:22.958706 2026] [autoindex:error] [pid 255769:tid 255988] [client 20.197.195.24:49195] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:22.991397 2026] [security2:error] [pid 255769:tid 255925] [client 20.197.195.24:48848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/config.json.php"] [unique_id "al9LarxMYwyVGnfuwsKNLgAAA70"]
[Tue Jul 21 07:35:23.028749 2026] [security2:error] [pid 255769:tid 255972] [client 20.220.225.223:31137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/ww.php"] [unique_id "al9La7xMYwyVGnfuwsKNLwAAA-w"]
[Tue Jul 21 07:35:23.033603 2026] [security2:error] [pid 255769:tid 255902] [client 20.197.195.24:49195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9La7xMYwyVGnfuwsKNMAAAA6Y"]
[Tue Jul 21 07:35:23.175967 2026] [security2:error] [pid 255769:tid 255941] [client 45.8.17.62:40195] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/index.php"] [unique_id "al9La7xMYwyVGnfuwsKNMwAAA80"]
[Tue Jul 21 07:35:23.409679 2026] [security2:error] [pid 254995:tid 255257] [client 20.197.195.24:62683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/8.php"] [unique_id "al9La_7v0rlcEGmVraExrQAAA4c"]
[Tue Jul 21 07:35:23.592117 2026] [security2:error] [pid 255769:tid 255967] [client 20.220.225.223:6128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/wp-css.php"] [unique_id "al9La7xMYwyVGnfuwsKNQgAAA-c"]
[Tue Jul 21 07:35:23.735330 2026] [security2:error] [pid 255769:tid 255847] [remote 74.7.243.250:51534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orixmed.com.inlaudo.com.br"] [uri "/blog/artigo3.php"] [unique_id "al9La7xMYwyVGnfuwsKNSgADuk0"], referer: https://orixmed.com.inlaudo.com.br/blog/
[Tue Jul 21 07:35:23.820499 2026] [security2:error] [pid 254995:tid 255160] [client 20.197.195.24:13155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9La_7v0rlcEGmVraExuAAAA0E"]
[Tue Jul 21 07:35:23.832526 2026] [security2:error] [pid 255769:tid 255985] [client 103.162.129.114:50117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9La7xMYwyVGnfuwsKNSwAAA_k"]
[Tue Jul 21 07:35:23.832652 2026] [security2:error] [pid 255769:tid 255985] [client 103.162.129.114:50117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9La7xMYwyVGnfuwsKNSwAAA_k"]
[Tue Jul 21 07:35:24.067984 2026] [security2:error] [pid 255769:tid 255946] [client 20.197.195.24:62592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9LbLxMYwyVGnfuwsKNTQAAA9I"]
[Tue Jul 21 07:35:24.115302 2026] [security2:error] [pid 254995:tid 255176] [client 172.245.102.42:44063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LbP7v0rlcEGmVraExvwAAA1E"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:24.133799 2026] [security2:error] [pid 255769:tid 255910] [client 20.220.225.223:24211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/8.php"] [unique_id "al9LbLxMYwyVGnfuwsKNUAAAA64"]
[Tue Jul 21 07:35:24.190841 2026] [security2:error] [pid 255769:tid 255902] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "santaofertas.com.br.anapaulaguimaraesdos1781613203317.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9LbLxMYwyVGnfuwsKNUgAAA6Y"]
[Tue Jul 21 07:35:24.270107 2026] [security2:error] [pid 255769:tid 255931] [client 117.251.86.144:45492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LbLxMYwyVGnfuwsKNVQAAA8M"]
[Tue Jul 21 07:35:24.270222 2026] [security2:error] [pid 255769:tid 255931] [client 117.251.86.144:45492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LbLxMYwyVGnfuwsKNVQAAA8M"]
[Tue Jul 21 07:35:24.599789 2026] [security2:error] [pid 255769:tid 255915] [client 20.197.195.24:62617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/f6.php"] [unique_id "al9LbLxMYwyVGnfuwsKNXAAAA7M"]
[Tue Jul 21 07:35:24.752184 2026] [security2:error] [pid 255769:tid 255960] [client 45.251.232.145:59006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LbLxMYwyVGnfuwsKNYwAAA-A"]
[Tue Jul 21 07:35:24.752343 2026] [security2:error] [pid 255769:tid 255960] [client 45.251.232.145:59006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LbLxMYwyVGnfuwsKNYwAAA-A"]
[Tue Jul 21 07:35:24.807623 2026] [security2:error] [pid 255769:tid 255987] [client 122.186.204.214:50846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LbLxMYwyVGnfuwsKNZAAAA_s"]
[Tue Jul 21 07:35:24.807757 2026] [security2:error] [pid 255769:tid 255987] [client 122.186.204.214:50846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LbLxMYwyVGnfuwsKNZAAAA_s"]
[Tue Jul 21 07:35:24.878518 2026] [security2:error] [pid 255769:tid 255954] [client 45.8.17.64:52591] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/storage/framework/views/shell.php"] [unique_id "al9LbLxMYwyVGnfuwsKNZwAAA9o"]
[Tue Jul 21 07:35:24.951953 2026] [security2:error] [pid 255769:tid 256003] [client 173.24.185.52:50957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LbLxMYwyVGnfuwsKNaAAABAk"]
[Tue Jul 21 07:35:24.952094 2026] [security2:error] [pid 255769:tid 256003] [client 173.24.185.52:50957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LbLxMYwyVGnfuwsKNaAAABAk"]
[Tue Jul 21 07:35:25.174657 2026] [security2:error] [pid 254995:tid 255223] [client 20.197.195.24:13096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/k2.php"] [unique_id "al9Lbf7v0rlcEGmVraEx0wAAA38"]
[Tue Jul 21 07:35:25.185695 2026] [security2:error] [pid 254995:tid 255203] [client 20.197.195.24:62612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/inputs.php"] [unique_id "al9Lbf7v0rlcEGmVraEx1AAAA2w"]
[Tue Jul 21 07:35:25.299974 2026] [security2:error] [pid 254995:tid 255023] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lbf7v0rlcEGmVraEx2AADUhs"]
[Tue Jul 21 07:35:25.300164 2026] [security2:error] [pid 254995:tid 255177] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lbf7v0rlcEGmVraEx2AADUhs"]
[Tue Jul 21 07:35:25.430377 2026] [security2:error] [pid 254995:tid 255215] [client 20.197.195.24:50309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/inputs.php"] [unique_id "al9Lbf7v0rlcEGmVraEx2gAAA3c"]
[Tue Jul 21 07:35:25.431480 2026] [security2:error] [pid 254995:tid 255268] [client 20.220.225.223:49832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/dp.php"] [unique_id "al9Lbf7v0rlcEGmVraEx2wAAA5I"]
[Tue Jul 21 07:35:25.545376 2026] [security2:error] [pid 255769:tid 255787] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "santaofertas.com.br"] [uri "/api/.env"] [unique_id "al9LbbxMYwyVGnfuwsKNbwAD_BE"]
[Tue Jul 21 07:35:25.618978 2026] [security2:error] [pid 255769:tid 255905] [client 20.197.195.24:62608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/classwithtostring.php"] [unique_id "al9LbbxMYwyVGnfuwsKNcAAAA6k"]
[Tue Jul 21 07:35:25.777273 2026] [security2:error] [pid 255769:tid 255902] [client 45.8.17.59:35275] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/tinyfilemanager/tinyfilemanager.php"] [unique_id "al9LbbxMYwyVGnfuwsKNcgAAA6Y"]
[Tue Jul 21 07:35:25.953153 2026] [security2:error] [pid 255769:tid 255945] [client 20.197.195.24:49181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9LbbxMYwyVGnfuwsKNdAAAA9E"]
[Tue Jul 21 07:35:26.052831 2026] [security2:error] [pid 255769:tid 255789] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LbrxMYwyVGnfuwsKNdwADvRM"]
[Tue Jul 21 07:35:26.052970 2026] [security2:error] [pid 255769:tid 255925] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LbrxMYwyVGnfuwsKNdwADvRM"]
[Tue Jul 21 07:35:26.076037 2026] [security2:error] [pid 255769:tid 256013] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "santaofertas.com.br"] [uri "/api/.env"] [unique_id "al9LbrxMYwyVGnfuwsKNeAAABBM"]
[Tue Jul 21 07:35:26.230833 2026] [security2:error] [pid 254995:tid 255142] [client 117.217.38.194:62471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lbv7v0rlcEGmVraEx7AAAAy8"]
[Tue Jul 21 07:35:26.230979 2026] [security2:error] [pid 254995:tid 255142] [client 117.217.38.194:62471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lbv7v0rlcEGmVraEx7AAAAy8"]
[Tue Jul 21 07:35:26.504474 2026] [security2:error] [pid 255769:tid 255908] [client 122.162.144.145:16723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LbrxMYwyVGnfuwsKNgAAAA6w"]
[Tue Jul 21 07:35:26.507183 2026] [security2:error] [pid 255769:tid 255908] [client 122.162.144.145:16723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LbrxMYwyVGnfuwsKNgAAAA6w"]
[Tue Jul 21 07:35:26.627368 2026] [security2:error] [pid 254995:tid 255194] [client 20.197.195.24:62688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/wp-blog.php"] [unique_id "al9Lbv7v0rlcEGmVraEx8gAAA2M"]
[Tue Jul 21 07:35:26.680003 2026] [security2:error] [pid 254995:tid 255148] [client 45.8.17.135:32257] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/shell.php"] [unique_id "al9Lbv7v0rlcEGmVraEx9QAAAzU"]
[Tue Jul 21 07:35:26.813795 2026] [security2:error] [pid 254995:tid 255126] [client 20.197.195.24:48864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/uiuvs58l.php"] [unique_id "al9Lbv7v0rlcEGmVraEx-gAAAx8"]
[Tue Jul 21 07:35:27.166150 2026] [security2:error] [pid 254995:tid 255264] [client 103.106.20.201:61148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lb_7v0rlcEGmVraEyBAAAA44"]
[Tue Jul 21 07:35:27.166399 2026] [security2:error] [pid 254995:tid 255264] [client 103.106.20.201:61148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lb_7v0rlcEGmVraEyBAAAA44"]
[Tue Jul 21 07:35:27.508504 2026] [security2:error] [pid 254995:tid 255145] [client 154.192.233.199:58875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lb_7v0rlcEGmVraEyCgAAAzI"]
[Tue Jul 21 07:35:27.508684 2026] [security2:error] [pid 254995:tid 255145] [client 154.192.233.199:58875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lb_7v0rlcEGmVraEyCgAAAzI"]
[Tue Jul 21 07:35:27.579930 2026] [rewrite:error] [pid 254995:tid 255272] [client 187.49.76.218:19425] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2413
[Tue Jul 21 07:35:27.580605 2026] [rewrite:error] [pid 254995:tid 255277] [client 187.49.76.218:19457] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2413
[Tue Jul 21 07:35:27.601481 2026] [rewrite:error] [pid 254995:tid 255167] [client 187.49.76.218:19489] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2413
[Tue Jul 21 07:35:27.601497 2026] [security2:error] [pid 255769:tid 255987] [client 136.144.33.104:46983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Lb7xMYwyVGnfuwsKNiAAAA_s"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:27.703911 2026] [security2:error] [pid 255769:tid 255946] [client 20.197.195.24:48865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/40p9ixjd.php"] [unique_id "al9Lb7xMYwyVGnfuwsKNiQAAA9I"]
[Tue Jul 21 07:35:27.714776 2026] [autoindex:error] [pid 254995:tid 255155] [client 20.197.195.24:62599] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:27.723922 2026] [security2:error] [pid 254995:tid 255223] [client 20.197.195.24:62599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Lb_7v0rlcEGmVraEyFAAAA38"]
[Tue Jul 21 07:35:27.886187 2026] [security2:error] [pid 254995:tid 255170] [client 45.8.17.146:38735] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/aatdgetgdg/main.php"] [unique_id "al9Lb_7v0rlcEGmVraEyGQAAA0s"]
[Tue Jul 21 07:35:28.212619 2026] [security2:error] [pid 254995:tid 255206] [client 20.220.225.223:38691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/wander.php"] [unique_id "al9LcP7v0rlcEGmVraEyJAAAA28"]
[Tue Jul 21 07:35:28.315439 2026] [security2:error] [pid 254995:tid 255144] [client 20.197.195.24:62707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/ms-edit.php"] [unique_id "al9LcP7v0rlcEGmVraEyJgAAAzE"]
[Tue Jul 21 07:35:28.488554 2026] [security2:error] [pid 255769:tid 255972] [client 20.197.195.24:48873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/uiuvs58l.update.php"] [unique_id "al9LcLxMYwyVGnfuwsKNkQAAA-w"]
[Tue Jul 21 07:35:28.693593 2026] [security2:error] [pid 255769:tid 255790] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LcLxMYwyVGnfuwsKNlwADtRQ"]
[Tue Jul 21 07:35:28.693705 2026] [security2:error] [pid 255769:tid 255917] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LcLxMYwyVGnfuwsKNlwADtRQ"]
[Tue Jul 21 07:35:28.761215 2026] [security2:error] [pid 255769:tid 255959] [client 20.206.105.145:39268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/goods.php"] [unique_id "al9LcLxMYwyVGnfuwsKNmAAAA98"]
[Tue Jul 21 07:35:29.057561 2026] [security2:error] [pid 254995:tid 255134] [client 109.248.148.246:55180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Lcf7v0rlcEGmVraEyNgAAAyc"]
[Tue Jul 21 07:35:29.057685 2026] [security2:error] [pid 254995:tid 255134] [client 109.248.148.246:55180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Lcf7v0rlcEGmVraEyNgAAAyc"]
[Tue Jul 21 07:35:29.082964 2026] [security2:error] [pid 254995:tid 255258] [client 45.8.17.126:29927] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/asasx.php"] [unique_id "al9Lcf7v0rlcEGmVraEyOAAAA4g"]
[Tue Jul 21 07:35:29.165553 2026] [security2:error] [pid 255769:tid 255971] [client 122.164.127.47:64973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LcbxMYwyVGnfuwsKNnQAAA-s"]
[Tue Jul 21 07:35:29.165663 2026] [security2:error] [pid 255769:tid 255971] [client 122.164.127.47:64973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LcbxMYwyVGnfuwsKNnQAAA-s"]
[Tue Jul 21 07:35:29.325310 2026] [security2:error] [pid 255769:tid 255798] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LcbxMYwyVGnfuwsKNnwAD4Bw"]
[Tue Jul 21 07:35:29.325449 2026] [security2:error] [pid 255769:tid 255960] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LcbxMYwyVGnfuwsKNnwAD4Bw"]
[Tue Jul 21 07:35:29.327541 2026] [security2:error] [pid 255769:tid 255932] [client 20.197.195.24:48803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/for.php"] [unique_id "al9LcbxMYwyVGnfuwsKNoAAAA8Q"]
[Tue Jul 21 07:35:29.449995 2026] [security2:error] [pid 255769:tid 255921] [client 20.197.195.24:50359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9LcbxMYwyVGnfuwsKNpAAAA7k"]
[Tue Jul 21 07:35:29.493227 2026] [security2:error] [pid 255769:tid 255957] [client 103.174.34.15:53270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LcbxMYwyVGnfuwsKNpQAAA90"]
[Tue Jul 21 07:35:29.493355 2026] [security2:error] [pid 255769:tid 255957] [client 103.174.34.15:53270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LcbxMYwyVGnfuwsKNpQAAA90"]
[Tue Jul 21 07:35:29.517914 2026] [security2:error] [pid 254995:tid 255055] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lcf7v0rlcEGmVraEyQgADUTs"]
[Tue Jul 21 07:35:29.518050 2026] [security2:error] [pid 254995:tid 255176] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lcf7v0rlcEGmVraEyQgADUTs"]
[Tue Jul 21 07:35:29.825394 2026] [security2:error] [pid 255769:tid 255923] [client 193.36.225.104:61439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LcbxMYwyVGnfuwsKNpgAAA7s"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:35:29.947367 2026] [security2:error] [pid 255769:tid 255969] [client 152.59.154.239:52848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LcbxMYwyVGnfuwsKNrAAAA-k"]
[Tue Jul 21 07:35:29.947477 2026] [security2:error] [pid 255769:tid 255969] [client 152.59.154.239:52848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LcbxMYwyVGnfuwsKNrAAAA-k"]
[Tue Jul 21 07:35:30.077443 2026] [security2:error] [pid 254995:tid 255277] [client 45.8.17.125:32263] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/template-wploader.php"] [unique_id "al9Lcv7v0rlcEGmVraEyTgAAA5s"]
[Tue Jul 21 07:35:30.150049 2026] [security2:error] [pid 255769:tid 255974] [client 20.220.225.223:38704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/cron.php"] [unique_id "al9LcrxMYwyVGnfuwsKNsAAAA-4"]
[Tue Jul 21 07:35:30.479268 2026] [security2:error] [pid 254995:tid 255191] [client 103.69.96.15:48964] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 15.96.69.103.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/wp-comments-post.php"] [unique_id "al9Lcf7v0rlcEGmVraEyPgAAA2A"]
[Tue Jul 21 07:35:30.479422 2026] [security2:error] [pid 254995:tid 255191] [client 103.69.96.15:48964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "diariomineral.com"] [uri "/wp-comments-post.php"] [unique_id "al9Lcf7v0rlcEGmVraEyPgAAA2A"]
[Tue Jul 21 07:35:31.080286 2026] [security2:error] [pid 255769:tid 256009] [client 45.8.17.60:56731] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/test.php"] [unique_id "al9Lc7xMYwyVGnfuwsKNvQAABA8"]
[Tue Jul 21 07:35:31.082717 2026] [security2:error] [pid 255769:tid 256025] [client 20.197.195.24:13092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/raw.php"] [unique_id "al9Lc7xMYwyVGnfuwsKNvwAABB8"]
[Tue Jul 21 07:35:31.093017 2026] [autoindex:error] [pid 255769:tid 255948] [client 20.197.195.24:62680] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:31.109196 2026] [security2:error] [pid 255769:tid 255915] [client 20.197.195.24:62680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9Lc7xMYwyVGnfuwsKNwAAAA7M"]
[Tue Jul 21 07:35:31.166336 2026] [security2:error] [pid 255769:tid 255818] [remote 74.7.243.250:45036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orixmed.com.inlaudo.com.br"] [uri "/index.php"] [unique_id "al9Lc7xMYwyVGnfuwsKNwQAD4TA"], referer: https://orixmed.com.inlaudo.com.br/blog/
[Tue Jul 21 07:35:31.224830 2026] [security2:error] [pid 255769:tid 255838] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lc7xMYwyVGnfuwsKNwwAEE0Q"]
[Tue Jul 21 07:35:31.224954 2026] [security2:error] [pid 255769:tid 256013] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lc7xMYwyVGnfuwsKNwwAEE0Q"]
[Tue Jul 21 07:35:31.419459 2026] [security2:error] [pid 255769:tid 256015] [client 172.245.102.44:60773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Lc7xMYwyVGnfuwsKNxAAABBU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:31.464897 2026] [security2:error] [pid 255769:tid 255864] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Lc7xMYwyVGnfuwsKNxQADp14"]
[Tue Jul 21 07:35:31.465074 2026] [security2:error] [pid 255769:tid 255903] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Lc7xMYwyVGnfuwsKNxQADp14"]
[Tue Jul 21 07:35:31.544637 2026] [security2:error] [pid 255769:tid 255908] [client 20.220.225.223:38662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/jga.php"] [unique_id "al9Lc7xMYwyVGnfuwsKNxgAAA6w"]
[Tue Jul 21 07:35:31.616776 2026] [security2:error] [pid 255769:tid 255960] [client 20.206.105.145:38961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ms-edit.php"] [unique_id "al9Lc7xMYwyVGnfuwsKNyAAAA-A"]
[Tue Jul 21 07:35:32.171657 2026] [security2:error] [pid 255769:tid 255900] [client 45.8.17.135:36423] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "al9LdLxMYwyVGnfuwsKNzQAAA6Q"]
[Tue Jul 21 07:35:32.303006 2026] [security2:error] [pid 254995:tid 255148] [client 37.140.223.200:29103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Lc_7v0rlcEGmVraEyeAAAAzU"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:35:32.347811 2026] [security2:error] [pid 255769:tid 255821] [remote 4.205.168.44:48986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/wp-login.php"] [unique_id "al9LdLxMYwyVGnfuwsKNzwADyjM"]
[Tue Jul 21 07:35:32.869881 2026] [security2:error] [pid 255769:tid 256024] [client 139.167.225.182:56520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LdLxMYwyVGnfuwsKN0wAABB4"]
[Tue Jul 21 07:35:32.870007 2026] [security2:error] [pid 255769:tid 256024] [client 139.167.225.182:56520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LdLxMYwyVGnfuwsKN0wAABB4"]
[Tue Jul 21 07:35:32.949891 2026] [security2:error] [pid 255769:tid 255977] [client 59.96.220.140:53587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LdLxMYwyVGnfuwsKN1gAAA_E"]
[Tue Jul 21 07:35:32.950014 2026] [security2:error] [pid 255769:tid 255977] [client 59.96.220.140:53587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LdLxMYwyVGnfuwsKN1gAAA_E"]
[Tue Jul 21 07:35:33.050912 2026] [security2:error] [pid 254995:tid 254998] [remote 216.73.216.238:59322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/chales.php"] [unique_id "al9Ldf7v0rlcEGmVraEyjQADLgI"]
[Tue Jul 21 07:35:33.081437 2026] [security2:error] [pid 255769:tid 255985] [client 45.8.17.60:27061] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/moon.php"] [unique_id "al9LdbxMYwyVGnfuwsKN1wAAA_k"]
[Tue Jul 21 07:35:33.163126 2026] [autoindex:error] [pid 255769:tid 255910] [client 20.197.195.24:62659] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:33.565229 2026] [autoindex:error] [pid 255769:tid 255996] [client 20.197.195.24:62659] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:33.571087 2026] [security2:error] [pid 255769:tid 256007] [client 20.197.195.24:62659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/abcd.php"] [unique_id "al9LdbxMYwyVGnfuwsKN5QAABA0"]
[Tue Jul 21 07:35:33.608703 2026] [security2:error] [pid 255769:tid 255976] [client 82.102.28.107:34030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9LdbxMYwyVGnfuwsKN5wAAA_A"]
[Tue Jul 21 07:35:33.608787 2026] [security2:error] [pid 255769:tid 255976] [client 82.102.28.107:34030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9LdbxMYwyVGnfuwsKN5wAAA_A"]
[Tue Jul 21 07:35:33.658452 2026] [security2:error] [pid 254995:tid 255223] [client 82.102.28.107:58328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Ldf7v0rlcEGmVraEylAAAA38"]
[Tue Jul 21 07:35:33.658531 2026] [security2:error] [pid 254995:tid 255223] [client 82.102.28.107:58328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Ldf7v0rlcEGmVraEylAAAA38"]
[Tue Jul 21 07:35:33.855932 2026] [security2:error] [pid 254995:tid 255129] [client 20.220.225.223:49568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/bootstrap.php"] [unique_id "al9Ldf7v0rlcEGmVraEymQAAAyI"]
[Tue Jul 21 07:35:33.867887 2026] [security2:error] [pid 255769:tid 255855] [remote 216.73.216.238:64131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/chales.php"] [unique_id "al9LdbxMYwyVGnfuwsKN6wAD01U"]
[Tue Jul 21 07:35:33.925192 2026] [security2:error] [pid 255769:tid 255788] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LdbxMYwyVGnfuwsKN7QADphI"]
[Tue Jul 21 07:35:33.925307 2026] [security2:error] [pid 255769:tid 255902] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LdbxMYwyVGnfuwsKN7QADphI"]
[Tue Jul 21 07:35:34.086021 2026] [security2:error] [pid 254995:tid 255142] [client 20.220.225.223:23477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/wp-explorer.php"] [unique_id "al9Ldv7v0rlcEGmVraEymwAAAy8"]
[Tue Jul 21 07:35:34.127629 2026] [security2:error] [pid 255769:tid 255901] [client 20.206.105.145:39165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/222.php"] [unique_id "al9LdrxMYwyVGnfuwsKN7gAAA6U"]
[Tue Jul 21 07:35:34.395084 2026] [security2:error] [pid 254995:tid 255201] [client 45.8.17.110:30757] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/upload/"] [unique_id "al9Ldv7v0rlcEGmVraEyogAAA2o"]
[Tue Jul 21 07:35:34.596257 2026] [security2:error] [pid 255769:tid 256016] [client 103.162.129.114:50547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LdrxMYwyVGnfuwsKN-gAABBY"]
[Tue Jul 21 07:35:34.596369 2026] [security2:error] [pid 255769:tid 256016] [client 103.162.129.114:50547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LdrxMYwyVGnfuwsKN-gAABBY"]
[Tue Jul 21 07:35:34.792003 2026] [security2:error] [pid 255769:tid 255905] [client 20.220.225.223:52198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/akismet.php"] [unique_id "al9LdrxMYwyVGnfuwsKN_QAAA6k"]
[Tue Jul 21 07:35:34.802684 2026] [security2:error] [pid 254995:tid 255143] [client 20.197.195.24:62719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/file15.php"] [unique_id "al9Ldv7v0rlcEGmVraEyrAAAAzA"]
[Tue Jul 21 07:35:34.875306 2026] [security2:error] [pid 255769:tid 255927] [client 117.251.86.144:37374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LdrxMYwyVGnfuwsKOAQAAA78"]
[Tue Jul 21 07:35:34.875435 2026] [security2:error] [pid 255769:tid 255927] [client 117.251.86.144:37374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LdrxMYwyVGnfuwsKOAQAAA78"]
[Tue Jul 21 07:35:35.136135 2026] [security2:error] [pid 254995:tid 255144] [client 193.36.225.68:26373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Ld_7v0rlcEGmVraEysAAAAzE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:35.200477 2026] [security2:error] [pid 255769:tid 255975] [client 20.220.225.223:31182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/xxx.php"] [unique_id "al9Ld7xMYwyVGnfuwsKOBQAAA-8"]
[Tue Jul 21 07:35:35.228920 2026] [security2:error] [pid 254995:tid 255128] [client 45.251.232.145:59531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ld_7v0rlcEGmVraEysQAAAyE"]
[Tue Jul 21 07:35:35.229042 2026] [security2:error] [pid 254995:tid 255128] [client 45.251.232.145:59531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ld_7v0rlcEGmVraEysQAAAyE"]
[Tue Jul 21 07:35:35.276452 2026] [security2:error] [pid 255769:tid 255996] [client 45.8.17.110:52925] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/css/index.php"] [unique_id "al9Ld7xMYwyVGnfuwsKOCAAABAI"]
[Tue Jul 21 07:35:35.496754 2026] [security2:error] [pid 254995:tid 255185] [client 109.248.148.246:55188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Ld_7v0rlcEGmVraEytwAAA1o"]
[Tue Jul 21 07:35:35.496859 2026] [security2:error] [pid 254995:tid 255185] [client 109.248.148.246:55188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Ld_7v0rlcEGmVraEytwAAA1o"]
[Tue Jul 21 07:35:35.498190 2026] [security2:error] [pid 255769:tid 255959] [client 173.24.185.52:51438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Ld7xMYwyVGnfuwsKOCwAAA98"]
[Tue Jul 21 07:35:35.498304 2026] [security2:error] [pid 255769:tid 255959] [client 173.24.185.52:51438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Ld7xMYwyVGnfuwsKOCwAAA98"]
[Tue Jul 21 07:35:35.784820 2026] [security2:error] [pid 254995:tid 255090] [remote 202.51.202.242:53698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "growe-ag.jaypi.com.br"] [uri "/wp-login.php"] [unique_id "al9Ld_7v0rlcEGmVraEyuQADZl4"]
[Tue Jul 21 07:35:35.787041 2026] [security2:error] [pid 254995:tid 255186] [client 122.186.204.214:51359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ld_7v0rlcEGmVraEyugAAA1s"]
[Tue Jul 21 07:35:35.787170 2026] [security2:error] [pid 254995:tid 255186] [client 122.186.204.214:51359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ld_7v0rlcEGmVraEyugAAA1s"]
[Tue Jul 21 07:35:35.787538 2026] [security2:error] [pid 254995:tid 255114] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ld_7v0rlcEGmVraEyuwADlHY"]
[Tue Jul 21 07:35:35.787680 2026] [security2:error] [pid 254995:tid 255270] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ld_7v0rlcEGmVraEyuwADlHY"]
[Tue Jul 21 07:35:36.283607 2026] [security2:error] [pid 254995:tid 255137] [client 45.8.17.135:28145] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/network/cache/"] [unique_id "al9LeP7v0rlcEGmVraEyyAAAAyo"]
[Tue Jul 21 07:35:36.333843 2026] [security2:error] [pid 254995:tid 255146] [client 172.245.102.31:21397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Ldv7v0rlcEGmVraEynQAAAzM"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:35:36.610931 2026] [security2:error] [pid 255769:tid 255957] [client 20.197.195.24:62634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/jp.php"] [unique_id "al9LeLxMYwyVGnfuwsKOFQAAA90"]
[Tue Jul 21 07:35:36.720312 2026] [security2:error] [pid 255769:tid 255951] [client 20.206.105.145:39166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/cgi-bin/index.php"] [unique_id "al9LeLxMYwyVGnfuwsKOFgAAA9c"]
[Tue Jul 21 07:35:36.729049 2026] [security2:error] [pid 254995:tid 255141] [client 117.217.38.194:62934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LeP7v0rlcEGmVraEyzwAAAy4"]
[Tue Jul 21 07:35:36.729180 2026] [security2:error] [pid 254995:tid 255141] [client 117.217.38.194:62934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LeP7v0rlcEGmVraEyzwAAAy4"]
[Tue Jul 21 07:35:36.743544 2026] [security2:error] [pid 255769:tid 255827] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LeLxMYwyVGnfuwsKOFwAEFzk"]
[Tue Jul 21 07:35:36.743673 2026] [security2:error] [pid 255769:tid 256017] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LeLxMYwyVGnfuwsKOFwAEFzk"]
[Tue Jul 21 07:35:37.248513 2026] [security2:error] [pid 255769:tid 255966] [client 122.162.144.145:2938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LebxMYwyVGnfuwsKOHAAAA-Y"]
[Tue Jul 21 07:35:37.248647 2026] [security2:error] [pid 255769:tid 255966] [client 122.162.144.145:2938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LebxMYwyVGnfuwsKOHAAAA-Y"]
[Tue Jul 21 07:35:37.282714 2026] [security2:error] [pid 254995:tid 255217] [client 45.8.17.63:36631] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/abcd.php"] [unique_id "al9Lef7v0rlcEGmVraEy2AAAA3k"]
[Tue Jul 21 07:35:37.292219 2026] [security2:error] [pid 254995:tid 255219] [client 196.251.121.187:49163] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "bestdealsvalmir.com"] [uri "/"] [unique_id "al9Lef7v0rlcEGmVraEy2QAAA3s"]
[Tue Jul 21 07:35:37.297934 2026] [security2:error] [pid 254995:tid 255136] [client 185.213.175.37:63116] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "appontime.com.br"] [uri "/"] [unique_id "al9Lef7v0rlcEGmVraEy2gAAAyk"]
[Tue Jul 21 07:35:37.298000 2026] [security2:error] [pid 254995:tid 255136] [client 185.213.175.37:63116] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "appontime.com.br"] [uri "/"] [unique_id "al9Lef7v0rlcEGmVraEy2gAAAyk"]
[Tue Jul 21 07:35:37.581400 2026] [security2:error] [pid 254995:tid 255199] [client 20.220.225.223:23450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/ace2.php"] [unique_id "al9Lef7v0rlcEGmVraEy4wAAA2g"]
[Tue Jul 21 07:35:37.651105 2026] [security2:error] [pid 255769:tid 255945] [client 213.152.162.104:50464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LebxMYwyVGnfuwsKOIwAAA9E"]
[Tue Jul 21 07:35:37.651202 2026] [security2:error] [pid 255769:tid 255945] [client 213.152.162.104:50464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LebxMYwyVGnfuwsKOIwAAA9E"]
[Tue Jul 21 07:35:37.871105 2026] [security2:error] [pid 255769:tid 255931] [client 103.106.20.201:61721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LebxMYwyVGnfuwsKOKAAAA8M"]
[Tue Jul 21 07:35:37.871192 2026] [security2:error] [pid 255769:tid 255931] [client 103.106.20.201:61721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LebxMYwyVGnfuwsKOKAAAA8M"]
[Tue Jul 21 07:35:37.916722 2026] [security2:error] [pid 254995:tid 255172] [client 40.124.175.30:53082] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "162.241.63.72"] [uri "/index.cgi"] [unique_id "al9Lef7v0rlcEGmVraEy6AAAA00"]
[Tue Jul 21 07:35:38.013574 2026] [security2:error] [pid 255769:tid 256007] [client 20.220.225.223:24213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/red.php"] [unique_id "al9LerxMYwyVGnfuwsKOKwAABA0"]
[Tue Jul 21 07:35:38.076014 2026] [security2:error] [pid 255769:tid 255961] [client 45.8.17.126:28535] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentyfour/patterns/template-singl-portfolio.php"] [unique_id "al9LerxMYwyVGnfuwsKOLQAAA-E"]
[Tue Jul 21 07:35:38.294481 2026] [security2:error] [pid 255769:tid 255908] [client 20.197.195.24:62690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/f35.php"] [unique_id "al9LerxMYwyVGnfuwsKOMQAAA6w"]
[Tue Jul 21 07:35:38.333793 2026] [security2:error] [pid 254995:tid 255214] [client 20.220.225.223:38685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/hunter.php"] [unique_id "al9Lev7v0rlcEGmVraEy6wAAA3Y"]
[Tue Jul 21 07:35:38.644806 2026] [security2:error] [pid 255769:tid 255996] [client 154.192.233.199:60443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LerxMYwyVGnfuwsKOPAAABAI"]
[Tue Jul 21 07:35:38.645220 2026] [security2:error] [pid 255769:tid 255996] [client 154.192.233.199:60443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LerxMYwyVGnfuwsKOPAAABAI"]
[Tue Jul 21 07:35:39.168262 2026] [security2:error] [pid 254995:tid 255264] [client 193.36.225.54:37343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Le_7v0rlcEGmVraEy9QAAA44"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:39.378069 2026] [security2:error] [pid 255769:tid 255972] [client 45.8.17.103:49591] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/class-wp-smtp-bar.php"] [unique_id "al9Le7xMYwyVGnfuwsKORgAAA-w"]
[Tue Jul 21 07:35:39.605095 2026] [security2:error] [pid 254995:tid 255268] [client 20.197.195.24:62655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/wp-load.php"] [unique_id "al9Le_7v0rlcEGmVraEy-QAAA5I"]
[Tue Jul 21 07:35:39.643011 2026] [security2:error] [pid 255769:tid 255993] [client 136.144.33.25:49339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LerxMYwyVGnfuwsKONwAABAA"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:35:39.856595 2026] [security2:error] [pid 254995:tid 255155] [client 109.248.148.246:35392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Le_7v0rlcEGmVraEy_QAAAzw"]
[Tue Jul 21 07:35:39.856692 2026] [security2:error] [pid 254995:tid 255155] [client 109.248.148.246:35392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Le_7v0rlcEGmVraEy_QAAAzw"]
[Tue Jul 21 07:35:39.911880 2026] [security2:error] [pid 254995:tid 255028] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Le_7v0rlcEGmVraEy_gADYiA"]
[Tue Jul 21 07:35:39.912112 2026] [security2:error] [pid 254995:tid 255193] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Le_7v0rlcEGmVraEy_gADYiA"]
[Tue Jul 21 07:35:40.113399 2026] [security2:error] [pid 255769:tid 255998] [client 122.164.127.47:65533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LfLxMYwyVGnfuwsKOTgAABAQ"]
[Tue Jul 21 07:35:40.114134 2026] [security2:error] [pid 255769:tid 255998] [client 122.164.127.47:65533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LfLxMYwyVGnfuwsKOTgAABAQ"]
[Tue Jul 21 07:35:40.157618 2026] [security2:error] [pid 254995:tid 255203] [client 103.174.34.15:53754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LfP7v0rlcEGmVraEzBQAAA2w"]
[Tue Jul 21 07:35:40.157718 2026] [security2:error] [pid 254995:tid 255203] [client 103.174.34.15:53754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LfP7v0rlcEGmVraEzBQAAA2w"]
[Tue Jul 21 07:35:40.253764 2026] [security2:error] [pid 254995:tid 255167] [client 173.252.95.19:58388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LfP7v0rlcEGmVraEzBgAAA0g"]
[Tue Jul 21 07:35:40.376215 2026] [security2:error] [pid 254995:tid 255019] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LfP7v0rlcEGmVraEzCgADgxc"]
[Tue Jul 21 07:35:40.376429 2026] [security2:error] [pid 254995:tid 255252] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LfP7v0rlcEGmVraEzCgADgxc"]
[Tue Jul 21 07:35:40.583487 2026] [security2:error] [pid 254995:tid 255150] [client 45.8.17.61:27451] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/assets/images/selam.php"] [unique_id "al9LfP7v0rlcEGmVraEzDwAAAzc"]
[Tue Jul 21 07:35:40.643749 2026] [security2:error] [pid 255769:tid 255923] [client 20.220.225.223:52177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/ms.php"] [unique_id "al9LfLxMYwyVGnfuwsKOUAAAA7s"]
[Tue Jul 21 07:35:40.820050 2026] [security2:error] [pid 254995:tid 255044] [remote 156.59.198.136:11984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "issima.net.br"] [uri "/equestre/brasao/brasao-azul-e-branco.pdf"] [unique_id "al9LfP7v0rlcEGmVraEzFAADeTA"]
[Tue Jul 21 07:35:40.934081 2026] [security2:error] [pid 255769:tid 255929] [client 20.197.195.24:50304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/xyn.php"] [unique_id "al9LfLxMYwyVGnfuwsKOUgAAA8E"]
[Tue Jul 21 07:35:41.617382 2026] [autoindex:error] [pid 255769:tid 255969] [client 20.197.195.24:50316] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:41.667779 2026] [security2:error] [pid 255769:tid 255918] [client 45.8.17.106:64121] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/manager.php"] [unique_id "al9LfbxMYwyVGnfuwsKOYAAAA7Y"]
[Tue Jul 21 07:35:41.709676 2026] [autoindex:error] [pid 255769:tid 255968] [client 20.197.195.24:50316] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:41.736568 2026] [security2:error] [pid 255769:tid 255985] [client 20.197.195.24:50316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/ccc.php"] [unique_id "al9LfbxMYwyVGnfuwsKOYwAAA_k"]
[Tue Jul 21 07:35:41.836408 2026] [security2:error] [pid 255769:tid 255978] [client 20.220.225.223:24222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/fffm.php"] [unique_id "al9LfbxMYwyVGnfuwsKOZAAAA_I"]
[Tue Jul 21 07:35:41.875558 2026] [security2:error] [pid 255769:tid 255802] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LfbxMYwyVGnfuwsKOZQADyCA"]
[Tue Jul 21 07:35:41.875726 2026] [security2:error] [pid 255769:tid 255936] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LfbxMYwyVGnfuwsKOZQADyCA"]
[Tue Jul 21 07:35:41.888914 2026] [security2:error] [pid 255769:tid 255886] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LfbxMYwyVGnfuwsKOZgAEF3Q"]
[Tue Jul 21 07:35:41.889063 2026] [security2:error] [pid 255769:tid 256017] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LfbxMYwyVGnfuwsKOZgAEF3Q"]
[Tue Jul 21 07:35:41.899753 2026] [security2:error] [pid 254995:tid 255147] [client 152.59.154.239:53333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lff7v0rlcEGmVraEzIQAAAzQ"]
[Tue Jul 21 07:35:41.899911 2026] [security2:error] [pid 254995:tid 255147] [client 152.59.154.239:53333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lff7v0rlcEGmVraEzIQAAAzQ"]
[Tue Jul 21 07:35:42.017656 2026] [security2:error] [pid 255769:tid 255811] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LfrxMYwyVGnfuwsKOaQADwCk"]
[Tue Jul 21 07:35:42.017841 2026] [security2:error] [pid 255769:tid 255928] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LfrxMYwyVGnfuwsKOaQADwCk"]
[Tue Jul 21 07:35:42.505549 2026] [security2:error] [pid 255769:tid 255957] [client 59.96.220.140:54098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LfrxMYwyVGnfuwsKOdAAAA90"]
[Tue Jul 21 07:35:42.506291 2026] [security2:error] [pid 255769:tid 255957] [client 59.96.220.140:54098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LfrxMYwyVGnfuwsKOdAAAA90"]
[Tue Jul 21 07:35:42.645021 2026] [proxy:error] [pid 255769:tid 255980] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:35:42.645123 2026] [proxy_http:error] [pid 255769:tid 255980] [client 20.206.105.145:38986] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:35:42.645723 2026] [proxy:error] [pid 255769:tid 255980] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:35:42.645750 2026] [proxy_http:error] [pid 255769:tid 255980] [client 20.206.105.145:38986] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:35:42.667863 2026] [security2:error] [pid 255769:tid 255959] [client 20.197.195.24:62609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/w.php"] [unique_id "al9LfrxMYwyVGnfuwsKOdwAAA98"]
[Tue Jul 21 07:35:42.740778 2026] [security2:error] [pid 255769:tid 256013] [client 20.220.225.223:24192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/ftde.php"] [unique_id "al9LfrxMYwyVGnfuwsKOegAABBM"]
[Tue Jul 21 07:35:43.055272 2026] [security2:error] [pid 255769:tid 255915] [client 193.36.225.11:29367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LfrxMYwyVGnfuwsKOjQAAA7M"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:43.071737 2026] [security2:error] [pid 254995:tid 255210] [client 45.8.17.129:49735] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/upload.php"] [unique_id "al9Lf_7v0rlcEGmVraEzPAAAA3I"]
[Tue Jul 21 07:35:43.636115 2026] [security2:error] [pid 255769:tid 256008] [client 20.197.195.24:62641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Lf7xMYwyVGnfuwsKOoAAABA4"]
[Tue Jul 21 07:35:43.851548 2026] [security2:error] [pid 255769:tid 255957] [client 20.197.195.24:62647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/FWAZ.php"] [unique_id "al9Lf7xMYwyVGnfuwsKOpQAAA90"]
[Tue Jul 21 07:35:43.871414 2026] [security2:error] [pid 255769:tid 255938] [client 45.8.17.139:60087] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "al9Lf7xMYwyVGnfuwsKOpgAAA8o"]
[Tue Jul 21 07:35:44.297656 2026] [security2:error] [pid 255769:tid 255847] [remote 103.112.62.59:48934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.62.112.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/wp-login.php"] [unique_id "al9LgLxMYwyVGnfuwsKOrwAEH00"]
[Tue Jul 21 07:35:44.403225 2026] [security2:error] [pid 254995:tid 255147] [client 20.206.105.145:38468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9LgP7v0rlcEGmVraEzXAAAAzQ"]
[Tue Jul 21 07:35:44.497155 2026] [security2:error] [pid 255769:tid 255916] [client 139.167.225.182:57176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LgLxMYwyVGnfuwsKOswAAA7Q"]
[Tue Jul 21 07:35:44.497308 2026] [security2:error] [pid 255769:tid 255916] [client 139.167.225.182:57176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LgLxMYwyVGnfuwsKOswAAA7Q"]
[Tue Jul 21 07:35:44.543086 2026] [security2:error] [pid 254995:tid 255267] [client 20.197.195.24:50348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/miru1.php"] [unique_id "al9LgP7v0rlcEGmVraEzXgAAA5E"]
[Tue Jul 21 07:35:44.814226 2026] [security2:error] [pid 255769:tid 255843] [remote 159.223.116.62:37234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.116.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9LgLxMYwyVGnfuwsKOuQAD80k"]
[Tue Jul 21 07:35:44.843285 2026] [security2:error] [pid 255769:tid 255867] [remote 47.128.25.17:50984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcoll.com.br"] [uri "/web/page.php"] [unique_id "al9LgLxMYwyVGnfuwsKOugAD-GE"]
[Tue Jul 21 07:35:44.867179 2026] [security2:error] [pid 255769:tid 255954] [client 20.197.195.24:62716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/aa.php"] [unique_id "al9LgLxMYwyVGnfuwsKOvAAAA9o"]
[Tue Jul 21 07:35:44.980250 2026] [security2:error] [pid 255769:tid 256016] [client 45.8.17.103:59917] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/buy.php"] [unique_id "al9LgLxMYwyVGnfuwsKOvQAABBY"]
[Tue Jul 21 07:35:45.486396 2026] [security2:error] [pid 255769:tid 255969] [client 103.162.129.114:51006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LgbxMYwyVGnfuwsKOwwAAA-k"]
[Tue Jul 21 07:35:45.486550 2026] [security2:error] [pid 255769:tid 255969] [client 103.162.129.114:51006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LgbxMYwyVGnfuwsKOwwAAA-k"]
[Tue Jul 21 07:35:45.540304 2026] [security2:error] [pid 255769:tid 255952] [client 117.251.86.144:40332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LgbxMYwyVGnfuwsKOxAAAA9g"]
[Tue Jul 21 07:35:45.540414 2026] [security2:error] [pid 255769:tid 255952] [client 117.251.86.144:40332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LgbxMYwyVGnfuwsKOxAAAA9g"]
[Tue Jul 21 07:35:45.673774 2026] [security2:error] [pid 255769:tid 255948] [client 20.220.225.223:49837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-editor.php"] [unique_id "al9LgbxMYwyVGnfuwsKOxQAAA9Q"]
[Tue Jul 21 07:35:45.679217 2026] [security2:error] [pid 255769:tid 255973] [client 45.251.232.145:60051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LgbxMYwyVGnfuwsKOxgAAA-0"]
[Tue Jul 21 07:35:45.679348 2026] [security2:error] [pid 255769:tid 255973] [client 45.251.232.145:60051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LgbxMYwyVGnfuwsKOxgAAA-0"]
[Tue Jul 21 07:35:45.879529 2026] [security2:error] [pid 255769:tid 255962] [client 20.197.195.24:49165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/122.php"] [unique_id "al9LgbxMYwyVGnfuwsKOywAAA-I"]
[Tue Jul 21 07:35:46.043062 2026] [security2:error] [pid 255769:tid 255980] [client 20.220.225.223:24197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/yup.php"] [unique_id "al9LgrxMYwyVGnfuwsKOzgAAA_Q"]
[Tue Jul 21 07:35:46.130024 2026] [security2:error] [pid 254995:tid 255272] [client 173.24.185.52:51910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Lgv7v0rlcEGmVraEzcAAAA5Y"]
[Tue Jul 21 07:35:46.130154 2026] [security2:error] [pid 254995:tid 255272] [client 173.24.185.52:51910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Lgv7v0rlcEGmVraEzcAAAA5Y"]
[Tue Jul 21 07:35:46.173981 2026] [security2:error] [pid 255769:tid 255932] [client 45.8.17.117:25031] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/zgbrarc/cong.php"] [unique_id "al9LgrxMYwyVGnfuwsKO0AAAA8Q"]
[Tue Jul 21 07:35:46.299880 2026] [security2:error] [pid 255769:tid 255832] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LgrxMYwyVGnfuwsKO0QAD9z4"]
[Tue Jul 21 07:35:46.300090 2026] [security2:error] [pid 255769:tid 255983] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LgrxMYwyVGnfuwsKO0QAD9z4"]
[Tue Jul 21 07:35:46.590743 2026] [security2:error] [pid 255769:tid 255996] [client 20.197.195.24:62675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/get.php"] [unique_id "al9LgrxMYwyVGnfuwsKO1AAABAI"]
[Tue Jul 21 07:35:46.624960 2026] [security2:error] [pid 255769:tid 255959] [client 20.206.105.145:39118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/BDKR28WP.php"] [unique_id "al9LgrxMYwyVGnfuwsKO1QAAA98"]
[Tue Jul 21 07:35:46.637316 2026] [security2:error] [pid 255769:tid 255938] [client 122.186.204.214:51869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LgrxMYwyVGnfuwsKO1gAAA8o"]
[Tue Jul 21 07:35:46.637417 2026] [security2:error] [pid 255769:tid 255938] [client 122.186.204.214:51869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LgrxMYwyVGnfuwsKO1gAAA8o"]
[Tue Jul 21 07:35:46.697769 2026] [security2:error] [pid 254995:tid 255169] [client 20.197.195.24:49173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/as.php"] [unique_id "al9Lgv7v0rlcEGmVraEzoAAAA0o"]
[Tue Jul 21 07:35:46.805305 2026] [security2:error] [pid 255769:tid 256003] [client 20.197.195.24:62689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/ccou.php"] [unique_id "al9LgrxMYwyVGnfuwsKO2AAABAk"]
[Tue Jul 21 07:35:46.850079 2026] [security2:error] [pid 255769:tid 255789] [remote 132.148.72.88:38916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9LgrxMYwyVGnfuwsKO2QADthM"]
[Tue Jul 21 07:35:47.026825 2026] [security2:error] [pid 255769:tid 255997] [client 20.197.195.24:50315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/w3lls.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO3gAABAM"]
[Tue Jul 21 07:35:47.127104 2026] [security2:error] [pid 255769:tid 255982] [client 20.206.105.145:37931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO4AAAA_Y"]
[Tue Jul 21 07:35:47.219055 2026] [security2:error] [pid 255769:tid 255961] [client 117.217.38.194:63405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO4QAAA-E"]
[Tue Jul 21 07:35:47.219185 2026] [security2:error] [pid 255769:tid 255961] [client 117.217.38.194:63405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO4QAAA-E"]
[Tue Jul 21 07:35:47.222780 2026] [security2:error] [pid 255769:tid 256011] [client 193.36.225.70:55413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO4gAABBE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:47.227983 2026] [security2:error] [pid 255769:tid 255926] [client 20.197.195.24:62630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/test1.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO4wAAA74"]
[Tue Jul 21 07:35:47.371172 2026] [security2:error] [pid 255769:tid 255870] [remote 173.212.252.15:50404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "odontoclinicms.com.br"] [uri "/wp-login.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO5QADuWQ"]
[Tue Jul 21 07:35:47.409518 2026] [security2:error] [pid 255769:tid 256005] [client 122.129.67.13:59520] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9LgrxMYwyVGnfuwsKOzwAABAs"]
[Tue Jul 21 07:35:47.409623 2026] [security2:error] [pid 255769:tid 256005] [client 122.129.67.13:59520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9LgrxMYwyVGnfuwsKOzwAABAs"]
[Tue Jul 21 07:35:47.431341 2026] [security2:error] [pid 255769:tid 255793] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO5gADwBc"]
[Tue Jul 21 07:35:47.431516 2026] [security2:error] [pid 255769:tid 255928] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO5gADwBc"]
[Tue Jul 21 07:35:47.535717 2026] [proxy:error] [pid 254995:tid 255269] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:35:47.535791 2026] [proxy_http:error] [pid 254995:tid 255269] [client 20.206.105.145:39293] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:35:47.536325 2026] [proxy:error] [pid 254995:tid 255269] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:35:47.536349 2026] [proxy_http:error] [pid 254995:tid 255269] [client 20.206.105.145:39293] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:35:47.726141 2026] [security2:error] [pid 255769:tid 255980] [client 20.197.195.24:62635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/database.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO6QAAA_Q"]
[Tue Jul 21 07:35:47.734975 2026] [security2:error] [pid 255769:tid 256024] [client 175.45.70.82:56989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO6gAABB4"]
[Tue Jul 21 07:35:47.735076 2026] [security2:error] [pid 255769:tid 256024] [client 175.45.70.82:56989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO6gAABB4"]
[Tue Jul 21 07:35:47.910512 2026] [security2:error] [pid 255769:tid 256026] [client 122.162.144.145:6879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO7gAABCA"]
[Tue Jul 21 07:35:47.913172 2026] [security2:error] [pid 255769:tid 256026] [client 122.162.144.145:6879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO7gAABCA"]
[Tue Jul 21 07:35:47.996874 2026] [security2:error] [pid 254995:tid 255182] [client 20.220.225.223:24274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/jj.php"] [unique_id "al9Lg_7v0rlcEGmVraEzvgAAA1c"]
[Tue Jul 21 07:35:48.048249 2026] [proxy:error] [pid 254995:tid 255185] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:35:48.048332 2026] [proxy_http:error] [pid 254995:tid 255185] [client 20.206.105.145:39112] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:35:48.048936 2026] [proxy:error] [pid 254995:tid 255185] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:35:48.048974 2026] [proxy_http:error] [pid 254995:tid 255185] [client 20.206.105.145:39112] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:35:48.343158 2026] [security2:error] [pid 254995:tid 255130] [client 20.197.195.24:62665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/file.php"] [unique_id "al9LhP7v0rlcEGmVraEzyQAAAyM"]
[Tue Jul 21 07:35:48.511677 2026] [security2:error] [pid 255769:tid 255983] [client 20.220.225.223:49825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/cro.php"] [unique_id "al9LhLxMYwyVGnfuwsKO9gAAA_c"]
[Tue Jul 21 07:35:48.557592 2026] [security2:error] [pid 255769:tid 255948] [client 103.106.20.201:62287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LhLxMYwyVGnfuwsKO9wAAA9Q"]
[Tue Jul 21 07:35:48.557723 2026] [security2:error] [pid 255769:tid 255948] [client 103.106.20.201:62287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LhLxMYwyVGnfuwsKO9wAAA9Q"]
[Tue Jul 21 07:35:48.573840 2026] [security2:error] [pid 254995:tid 255210] [client 45.8.17.144:31753] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9LhP7v0rlcEGmVraEz0QAAA3I"]
[Tue Jul 21 07:35:48.977002 2026] [security2:error] [pid 254995:tid 255125] [client 20.197.195.24:62651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/file.php"] [unique_id "al9LhP7v0rlcEGmVraEz3gAAAx4"]
[Tue Jul 21 07:35:49.082541 2026] [security2:error] [pid 255769:tid 255919] [client 20.206.105.145:38955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp.php"] [unique_id "al9LhbxMYwyVGnfuwsKO-gAAA7c"]
[Tue Jul 21 07:35:49.153053 2026] [security2:error] [pid 254995:tid 255166] [client 20.206.105.145:37899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/x.php"] [unique_id "al9Lhf7v0rlcEGmVraEz7QAAA0c"]
[Tue Jul 21 07:35:49.374252 2026] [security2:error] [pid 254995:tid 255140] [client 45.8.17.62:58553] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/customize/wp-conflg.php"] [unique_id "al9Lhf7v0rlcEGmVraEz-QAAAy0"]
[Tue Jul 21 07:35:49.564042 2026] [security2:error] [pid 255769:tid 255903] [client 20.197.195.24:50319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/777.php"] [unique_id "al9LhbxMYwyVGnfuwsKO_QAAA6c"]
[Tue Jul 21 07:35:49.673008 2026] [security2:error] [pid 255769:tid 256021] [client 20.206.105.145:39295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/abcd.php"] [unique_id "al9LhbxMYwyVGnfuwsKO_gAABBs"]
[Tue Jul 21 07:35:50.270514 2026] [rewrite:error] [pid 255769:tid 255966] [client 187.49.76.218:19841] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:35:50.272545 2026] [rewrite:error] [pid 255769:tid 255943] [client 187.49.76.218:19873] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:35:50.290880 2026] [rewrite:error] [pid 255769:tid 255999] [client 187.49.76.218:19905] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:35:50.462222 2026] [security2:error] [pid 255769:tid 255790] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LhrxMYwyVGnfuwsKPCQADvhQ"]
[Tue Jul 21 07:35:50.462423 2026] [security2:error] [pid 255769:tid 255926] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LhrxMYwyVGnfuwsKPCQADvhQ"]
[Tue Jul 21 07:35:50.593552 2026] [security2:error] [pid 254995:tid 255229] [client 122.164.127.47:49688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Lhv7v0rlcEGmVraE0GQAAA4I"]
[Tue Jul 21 07:35:50.593666 2026] [security2:error] [pid 254995:tid 255229] [client 122.164.127.47:49688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Lhv7v0rlcEGmVraE0GQAAA4I"]
[Tue Jul 21 07:35:50.674436 2026] [security2:error] [pid 255769:tid 255962] [client 45.8.17.128:60189] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/themes.php"] [unique_id "al9LhrxMYwyVGnfuwsKPFgAAA-I"]
[Tue Jul 21 07:35:50.681195 2026] [security2:error] [pid 255769:tid 255957] [client 20.206.105.145:37910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/j260624_13.php"] [unique_id "al9LhrxMYwyVGnfuwsKPGAAAA90"]
[Tue Jul 21 07:35:50.686909 2026] [security2:error] [pid 255769:tid 255986] [client 20.220.225.223:31105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/we.php"] [unique_id "al9LhrxMYwyVGnfuwsKPGQAAA_o"]
[Tue Jul 21 07:35:50.698846 2026] [security2:error] [pid 255769:tid 255899] [client 20.197.195.24:49158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/ssixta.php"] [unique_id "al9LhrxMYwyVGnfuwsKPGgAAA6M"]
[Tue Jul 21 07:35:50.955024 2026] [security2:error] [pid 255769:tid 255920] [client 103.174.34.15:54243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LhrxMYwyVGnfuwsKPHAAAA7g"]
[Tue Jul 21 07:35:50.955169 2026] [security2:error] [pid 255769:tid 255920] [client 103.174.34.15:54243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LhrxMYwyVGnfuwsKPHAAAA7g"]
[Tue Jul 21 07:35:51.185423 2026] [security2:error] [pid 255769:tid 255979] [client 136.144.33.105:30871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Lh7xMYwyVGnfuwsKPHgAAA_M"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:51.249783 2026] [security2:error] [pid 255769:tid 255818] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lh7xMYwyVGnfuwsKPJgADwjA"]
[Tue Jul 21 07:35:51.250047 2026] [security2:error] [pid 255769:tid 255930] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lh7xMYwyVGnfuwsKPJgADwjA"]
[Tue Jul 21 07:35:51.582894 2026] [security2:error] [pid 255769:tid 255987] [client 45.8.17.135:46075] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/fmadmin.php"] [unique_id "al9Lh7xMYwyVGnfuwsKPKwAAA_s"]
[Tue Jul 21 07:35:51.811200 2026] [security2:error] [pid 255769:tid 255982] [client 20.52.136.55:1729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/max.php"] [unique_id "al9Lh7xMYwyVGnfuwsKPLgAAA_Y"]
[Tue Jul 21 07:35:51.853281 2026] [security2:error] [pid 255769:tid 255999] [client 20.197.195.24:62686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/1c.php"] [unique_id "al9Lh7xMYwyVGnfuwsKPLwAABAU"]
[Tue Jul 21 07:35:51.957643 2026] [access_compat:error] [pid 255769:tid 255950] [client 162.241.63.68:58306] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:35:52.056690 2026] [security2:error] [pid 254995:tid 255168] [client 20.220.225.223:49835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/cron-tab.php"] [unique_id "al9LiP7v0rlcEGmVraE0KgAAA0k"]
[Tue Jul 21 07:35:52.087641 2026] [security2:error] [pid 255769:tid 255864] [remote 74.7.243.250:50296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orixmed.com.inlaudo.com.br"] [uri "/blog/artigo1.php"] [unique_id "al9LiLxMYwyVGnfuwsKPNAAD2F4"], referer: https://orixmed.com.inlaudo.com.br/blog/
[Tue Jul 21 07:35:52.355613 2026] [security2:error] [pid 255769:tid 255839] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LiLxMYwyVGnfuwsKPNwAD4kU"]
[Tue Jul 21 07:35:52.355776 2026] [security2:error] [pid 255769:tid 255962] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LiLxMYwyVGnfuwsKPNwAD4kU"]
[Tue Jul 21 07:35:52.540980 2026] [security2:error] [pid 254995:tid 255074] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LiP7v0rlcEGmVraE0MgADgU4"]
[Tue Jul 21 07:35:52.541131 2026] [security2:error] [pid 254995:tid 255225] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LiP7v0rlcEGmVraE0MgADgU4"]
[Tue Jul 21 07:35:52.565350 2026] [security2:error] [pid 255769:tid 255837] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LiLxMYwyVGnfuwsKPOwADpUM"]
[Tue Jul 21 07:35:52.565486 2026] [security2:error] [pid 255769:tid 255901] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LiLxMYwyVGnfuwsKPOwADpUM"]
[Tue Jul 21 07:35:52.809953 2026] [rewrite:error] [pid 255769:tid 255948] [client 187.49.76.218:19905] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2414
[Tue Jul 21 07:35:52.809954 2026] [rewrite:error] [pid 255769:tid 255970] [client 187.49.76.218:19873] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2414
[Tue Jul 21 07:35:52.811993 2026] [rewrite:error] [pid 255769:tid 255960] [client 187.49.76.218:19841] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2414
[Tue Jul 21 07:35:53.218133 2026] [security2:error] [pid 255769:tid 255925] [client 20.52.136.55:1539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/m.php"] [unique_id "al9LibxMYwyVGnfuwsKPRQAAA70"]
[Tue Jul 21 07:35:53.283239 2026] [security2:error] [pid 255769:tid 255916] [client 20.197.195.24:62658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/test2.php"] [unique_id "al9LibxMYwyVGnfuwsKPRgAAA7Q"]
[Tue Jul 21 07:35:53.679106 2026] [security2:error] [pid 255769:tid 256021] [client 45.8.17.60:38865] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/class.api.php"] [unique_id "al9LibxMYwyVGnfuwsKPTgAABBs"]
[Tue Jul 21 07:35:53.805807 2026] [security2:error] [pid 254995:tid 255126] [client 20.206.105.145:38497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/d62.php"] [unique_id "al9Lif7v0rlcEGmVraE0RwAAAx8"]
[Tue Jul 21 07:35:53.992604 2026] [security2:error] [pid 255769:tid 255929] [client 152.59.154.239:53825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LibxMYwyVGnfuwsKPUgAAA8E"]
[Tue Jul 21 07:35:53.992728 2026] [security2:error] [pid 255769:tid 255929] [client 152.59.154.239:53825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LibxMYwyVGnfuwsKPUgAAA8E"]
[Tue Jul 21 07:35:54.087054 2026] [security2:error] [pid 254995:tid 255199] [client 109.248.148.246:55884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Liv7v0rlcEGmVraE0TwAAA2g"]
[Tue Jul 21 07:35:54.087173 2026] [security2:error] [pid 254995:tid 255199] [client 109.248.148.246:55884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Liv7v0rlcEGmVraE0TwAAA2g"]
[Tue Jul 21 07:35:54.255372 2026] [security2:error] [pid 254995:tid 255182] [client 20.197.195.24:62662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/buy.php"] [unique_id "al9Liv7v0rlcEGmVraE0VgAAA1c"]
[Tue Jul 21 07:35:54.462423 2026] [security2:error] [pid 254995:tid 255091] [remote 45.150.79.142:36632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oferta.happynbox.com.br"] [uri "/wp-login.php"] [unique_id "al9Liv7v0rlcEGmVraE0VwADNF8"]
[Tue Jul 21 07:35:54.509524 2026] [security2:error] [pid 254995:tid 255269] [client 139.167.225.182:57819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Liv7v0rlcEGmVraE0WAAAA5M"]
[Tue Jul 21 07:35:54.509687 2026] [security2:error] [pid 254995:tid 255269] [client 139.167.225.182:57819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Liv7v0rlcEGmVraE0WAAAA5M"]
[Tue Jul 21 07:35:54.584173 2026] [security2:error] [pid 254995:tid 255215] [client 20.206.105.145:39126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/a1.php"] [unique_id "al9Liv7v0rlcEGmVraE0WgAAA3c"]
[Tue Jul 21 07:35:54.676639 2026] [security2:error] [pid 255769:tid 256008] [client 45.8.17.59:20693] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "al9LirxMYwyVGnfuwsKPUwAABA4"]
[Tue Jul 21 07:35:54.784510 2026] [security2:error] [pid 255769:tid 255936] [client 20.52.136.55:1741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/click.php"] [unique_id "al9LirxMYwyVGnfuwsKPVgAAA8g"]
[Tue Jul 21 07:35:54.940114 2026] [security2:error] [pid 254995:tid 255188] [client 213.152.162.104:48696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Liv7v0rlcEGmVraE0YQAAA10"]
[Tue Jul 21 07:35:54.940222 2026] [security2:error] [pid 254995:tid 255188] [client 213.152.162.104:48696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Liv7v0rlcEGmVraE0YQAAA10"]
[Tue Jul 21 07:35:55.111827 2026] [security2:error] [pid 254995:tid 255176] [client 20.197.195.24:62699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/ssend.php"] [unique_id "al9Li_7v0rlcEGmVraE0ZAAAA1E"]
[Tue Jul 21 07:35:55.341568 2026] [security2:error] [pid 254995:tid 255170] [client 20.220.225.223:48139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/koiy.php"] [unique_id "al9Li_7v0rlcEGmVraE0awAAA0s"]
[Tue Jul 21 07:35:55.353966 2026] [security2:error] [pid 255769:tid 256013] [client 20.220.225.223:31184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9Li7xMYwyVGnfuwsKPYAAABBM"]
[Tue Jul 21 07:35:55.456551 2026] [security2:error] [pid 255769:tid 255985] [client 20.220.225.223:38660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/phpinfo.php1"] [unique_id "al9Li7xMYwyVGnfuwsKPYQAAA_k"]
[Tue Jul 21 07:35:55.500137 2026] [security2:error] [pid 255769:tid 256009] [client 20.197.195.24:50308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/item.php"] [unique_id "al9Li7xMYwyVGnfuwsKPYgAABA8"]
[Tue Jul 21 07:35:55.677746 2026] [security2:error] [pid 254995:tid 255141] [client 45.8.17.105:45195] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/includes/index.php"] [unique_id "al9Li_7v0rlcEGmVraE0bQAAAy4"]
[Tue Jul 21 07:35:55.909954 2026] [security2:error] [pid 255769:tid 256025] [client 20.197.195.24:62693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/ss.php"] [unique_id "al9Li7xMYwyVGnfuwsKPZQAABB8"]
[Tue Jul 21 07:35:56.030836 2026] [security2:error] [pid 255769:tid 255940] [client 103.162.129.114:51487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LjLxMYwyVGnfuwsKPZwAAA8w"]
[Tue Jul 21 07:35:56.030945 2026] [security2:error] [pid 255769:tid 255940] [client 103.162.129.114:51487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LjLxMYwyVGnfuwsKPZwAAA8w"]
[Tue Jul 21 07:35:56.209197 2026] [security2:error] [pid 254995:tid 255132] [client 45.251.232.145:60582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LjP7v0rlcEGmVraE0dwAAAyU"]
[Tue Jul 21 07:35:56.209304 2026] [security2:error] [pid 254995:tid 255132] [client 45.251.232.145:60582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LjP7v0rlcEGmVraE0dwAAAyU"]
[Tue Jul 21 07:35:56.267070 2026] [security2:error] [pid 255769:tid 255990] [client 20.197.195.24:62604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/hypo.php"] [unique_id "al9LjLxMYwyVGnfuwsKPagAAA_4"]
[Tue Jul 21 07:35:56.585696 2026] [security2:error] [pid 255769:tid 256022] [client 45.8.17.134:64773] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9LjLxMYwyVGnfuwsKPbwAABBw"]
[Tue Jul 21 07:35:56.616759 2026] [security2:error] [pid 255769:tid 255965] [client 20.197.195.24:62601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/users.php"] [unique_id "al9LjLxMYwyVGnfuwsKPcAAAA-U"]
[Tue Jul 21 07:35:56.769247 2026] [security2:error] [pid 255769:tid 255855] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LjLxMYwyVGnfuwsKPdAAECVU"]
[Tue Jul 21 07:35:56.769426 2026] [security2:error] [pid 255769:tid 256003] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LjLxMYwyVGnfuwsKPdAAECVU"]
[Tue Jul 21 07:35:56.819868 2026] [security2:error] [pid 255769:tid 255938] [client 173.24.185.52:52391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LjLxMYwyVGnfuwsKPdQAAA8o"]
[Tue Jul 21 07:35:56.819998 2026] [security2:error] [pid 255769:tid 255938] [client 173.24.185.52:52391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LjLxMYwyVGnfuwsKPdQAAA8o"]
[Tue Jul 21 07:35:56.831269 2026] [security2:error] [pid 255769:tid 255788] [remote 41.76.214.143:40600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinadona.com"] [uri "/wp-login.php"] [unique_id "al9LjLxMYwyVGnfuwsKPdgAD1BI"]
[Tue Jul 21 07:35:56.992921 2026] [security2:error] [pid 255769:tid 256014] [client 20.206.105.145:38478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/ups.php"] [unique_id "al9LjLxMYwyVGnfuwsKPeQAABBQ"]
[Tue Jul 21 07:35:57.271134 2026] [security2:error] [pid 255769:tid 255935] [client 122.186.204.214:52386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LjbxMYwyVGnfuwsKPfAAAA8c"]
[Tue Jul 21 07:35:57.271257 2026] [security2:error] [pid 255769:tid 255935] [client 122.186.204.214:52386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LjbxMYwyVGnfuwsKPfAAAA8c"]
[Tue Jul 21 07:35:57.402009 2026] [security2:error] [pid 255769:tid 256028] [client 82.102.28.107:39710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9LjbxMYwyVGnfuwsKPfQAABCI"]
[Tue Jul 21 07:35:57.402118 2026] [security2:error] [pid 255769:tid 256028] [client 82.102.28.107:39710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9LjbxMYwyVGnfuwsKPfQAABCI"]
[Tue Jul 21 07:35:57.418793 2026] [security2:error] [pid 255769:tid 255944] [client 20.197.195.24:62648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/177.php"] [unique_id "al9LjbxMYwyVGnfuwsKPfgAAA9A"]
[Tue Jul 21 07:35:57.490995 2026] [security2:error] [pid 254995:tid 255222] [client 20.197.195.24:62606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/config.php"] [unique_id "al9Ljf7v0rlcEGmVraE0iQAAA34"]
[Tue Jul 21 07:35:57.613663 2026] [security2:error] [pid 254995:tid 255148] [client 173.252.95.41:51124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Ljf7v0rlcEGmVraE0igAAAzU"]
[Tue Jul 21 07:35:57.678091 2026] [security2:error] [pid 255769:tid 256013] [client 45.8.17.135:32019] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/assets/index.php"] [unique_id "al9LjbxMYwyVGnfuwsKPhAAABBM"]
[Tue Jul 21 07:35:57.686953 2026] [security2:error] [pid 255769:tid 255926] [client 117.217.38.194:63873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LjbxMYwyVGnfuwsKPhQAAA74"]
[Tue Jul 21 07:35:57.687062 2026] [security2:error] [pid 255769:tid 255926] [client 117.217.38.194:63873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LjbxMYwyVGnfuwsKPhQAAA74"]
[Tue Jul 21 07:35:57.795653 2026] [security2:error] [pid 254995:tid 255151] [client 20.206.105.145:37902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/k.php"] [unique_id "al9Ljf7v0rlcEGmVraE0jQAAAzg"]
[Tue Jul 21 07:35:57.834528 2026] [security2:error] [pid 255769:tid 255920] [client 20.197.195.24:62632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/gettest.php"] [unique_id "al9LjbxMYwyVGnfuwsKPhwAAA7g"]
[Tue Jul 21 07:35:58.122997 2026] [security2:error] [pid 255769:tid 255890] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LjrxMYwyVGnfuwsKPiwAD03g"]
[Tue Jul 21 07:35:58.123188 2026] [security2:error] [pid 255769:tid 255947] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LjrxMYwyVGnfuwsKPiwAD03g"]
[Tue Jul 21 07:35:58.339501 2026] [security2:error] [pid 254995:tid 255161] [client 136.144.33.98:24731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Ljv7v0rlcEGmVraE0mgAAA0I"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:58.393494 2026] [security2:error] [pid 254995:tid 255177] [client 20.197.195.24:62639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/min.php"] [unique_id "al9Ljv7v0rlcEGmVraE0nAAAA1I"]
[Tue Jul 21 07:35:58.400645 2026] [security2:error] [pid 254995:tid 255196] [client 175.45.70.82:58069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ljv7v0rlcEGmVraE0nQAAA2U"]
[Tue Jul 21 07:35:58.400762 2026] [security2:error] [pid 254995:tid 255196] [client 175.45.70.82:58069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ljv7v0rlcEGmVraE0nQAAA2U"]
[Tue Jul 21 07:35:58.404638 2026] [security2:error] [pid 254995:tid 255184] [client 20.206.105.145:38952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9Ljv7v0rlcEGmVraE0ngAAA1k"]
[Tue Jul 21 07:35:58.581522 2026] [security2:error] [pid 254995:tid 255133] [client 45.8.17.117:53445] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/news-portal/error.php"] [unique_id "al9Ljv7v0rlcEGmVraE0pwAAAyY"]
[Tue Jul 21 07:35:58.677517 2026] [security2:error] [pid 254995:tid 255194] [client 122.162.144.145:24465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Ljv7v0rlcEGmVraE0qgAAA2M"]
[Tue Jul 21 07:35:58.677624 2026] [security2:error] [pid 254995:tid 255194] [client 122.162.144.145:24465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Ljv7v0rlcEGmVraE0qgAAA2M"]
[Tue Jul 21 07:35:58.927715 2026] [security2:error] [pid 254995:tid 255219] [client 20.197.195.24:62663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/dvjul.php"] [unique_id "al9Ljv7v0rlcEGmVraE0tAAAA3s"]
[Tue Jul 21 07:35:59.312847 2026] [security2:error] [pid 254995:tid 255145] [client 103.106.20.201:62862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lj_7v0rlcEGmVraE0vQAAAzI"]
[Tue Jul 21 07:35:59.313057 2026] [security2:error] [pid 254995:tid 255145] [client 103.106.20.201:62862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lj_7v0rlcEGmVraE0vQAAAzI"]
[Tue Jul 21 07:35:59.444970 2026] [security2:error] [pid 255769:tid 255929] [client 20.197.195.24:62633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/biufile.php"] [unique_id "al9Lj7xMYwyVGnfuwsKPlwAAA8E"]
[Tue Jul 21 07:35:59.475638 2026] [security2:error] [pid 255769:tid 255984] [client 45.8.17.107:31875] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/load.php"] [unique_id "al9Lj7xMYwyVGnfuwsKPmAAAA_g"]
[Tue Jul 21 07:35:59.635692 2026] [security2:error] [pid 255769:tid 255986] [client 20.220.225.223:31168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/ee.php"] [unique_id "al9Lj7xMYwyVGnfuwsKPnAAAA_o"]
[Tue Jul 21 07:35:59.665540 2026] [proxy:error] [pid 254995:tid 255157] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:35:59.665600 2026] [proxy_http:error] [pid 254995:tid 255157] [client 20.206.105.145:39106] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:35:59.666090 2026] [proxy:error] [pid 254995:tid 255157] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:35:59.666120 2026] [proxy_http:error] [pid 254995:tid 255157] [client 20.206.105.145:39106] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:35:59.754706 2026] [security2:error] [pid 255769:tid 255827] [remote 103.82.22.235:54362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9LjrxMYwyVGnfuwsKPkAAEDDk"]
[Tue Jul 21 07:35:59.896175 2026] [security2:error] [pid 255769:tid 255775] [remote 132.148.72.88:56946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9Lj7xMYwyVGnfuwsKPoQADpgU"]
[Tue Jul 21 07:36:00.145001 2026] [security2:error] [pid 255769:tid 255901] [client 37.140.223.157:62359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LjbxMYwyVGnfuwsKPigAAA6U"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:36:00.175212 2026] [autoindex:error] [pid 255769:tid 255810] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:00.407240 2026] [security2:error] [pid 254995:tid 255213] [client 45.8.17.114:35573] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/index.php"] [unique_id "al9LkP7v0rlcEGmVraE00QAAA3U"]
[Tue Jul 21 07:36:00.705623 2026] [security2:error] [pid 254995:tid 255146] [client 20.197.195.24:50335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/av.php"] [unique_id "al9LkP7v0rlcEGmVraE01gAAAzM"]
[Tue Jul 21 07:36:00.764366 2026] [proxy:error] [pid 255769:tid 255921] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:00.764430 2026] [proxy_http:error] [pid 255769:tid 255921] [client 20.206.105.145:39008] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:00.764952 2026] [proxy:error] [pid 255769:tid 255921] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:00.764976 2026] [proxy_http:error] [pid 255769:tid 255921] [client 20.206.105.145:39008] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:00.985291 2026] [security2:error] [pid 255769:tid 255878] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LkLxMYwyVGnfuwsKPrgAEH2w"]
[Tue Jul 21 07:36:00.985456 2026] [security2:error] [pid 255769:tid 256025] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LkLxMYwyVGnfuwsKPrgAEH2w"]
[Tue Jul 21 07:36:01.249010 2026] [security2:error] [pid 255769:tid 255985] [client 122.164.127.47:50188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LkbxMYwyVGnfuwsKPtAAAA_k"]
[Tue Jul 21 07:36:01.249154 2026] [security2:error] [pid 255769:tid 255985] [client 122.164.127.47:50188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LkbxMYwyVGnfuwsKPtAAAA_k"]
[Tue Jul 21 07:36:01.281468 2026] [security2:error] [pid 254995:tid 255168] [client 45.8.17.119:50495] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/k.php"] [unique_id "al9Lkf7v0rlcEGmVraE03wAAA0k"]
[Tue Jul 21 07:36:01.366249 2026] [security2:error] [pid 255769:tid 255860] [remote 195.211.44.104:57384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.44.211.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "issimastore.com"] [uri "/wp-login.php"] [unique_id "al9Lj7xMYwyVGnfuwsKPlAADtFo"]
[Tue Jul 21 07:36:01.508894 2026] [security2:error] [pid 255769:tid 255994] [client 20.220.225.223:24272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/dragonshell.php"] [unique_id "al9LkbxMYwyVGnfuwsKPuQAABAE"]
[Tue Jul 21 07:36:01.690968 2026] [security2:error] [pid 255769:tid 255905] [client 103.174.34.15:54726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LkbxMYwyVGnfuwsKPwAAAA6k"]
[Tue Jul 21 07:36:01.691080 2026] [security2:error] [pid 255769:tid 255905] [client 103.174.34.15:54726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LkbxMYwyVGnfuwsKPwAAAA6k"]
[Tue Jul 21 07:36:02.029335 2026] [security2:error] [pid 255769:tid 255802] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LkrxMYwyVGnfuwsKPxwAD-CA"]
[Tue Jul 21 07:36:02.029597 2026] [security2:error] [pid 255769:tid 255984] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LkrxMYwyVGnfuwsKPxwAD-CA"]
[Tue Jul 21 07:36:02.044204 2026] [security2:error] [pid 254995:tid 255193] [client 136.144.33.108:53639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Lkv7v0rlcEGmVraE06wAAA2I"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:02.160537 2026] [security2:error] [pid 254995:tid 255156] [client 20.197.195.24:62671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/coffexium.php"] [unique_id "al9Lkv7v0rlcEGmVraE07wAAAz0"]
[Tue Jul 21 07:36:02.180409 2026] [security2:error] [pid 255769:tid 255957] [client 45.8.17.48:35327] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-conflg.php"] [unique_id "al9LkrxMYwyVGnfuwsKPzwAAA90"]
[Tue Jul 21 07:36:02.414781 2026] [security2:error] [pid 254995:tid 255218] [client 173.252.95.38:43320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Lkv7v0rlcEGmVraE08AAAA3o"]
[Tue Jul 21 07:36:02.841884 2026] [security2:error] [pid 255769:tid 256008] [client 20.206.105.145:37929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/k2.php"] [unique_id "al9LkbxMYwyVGnfuwsKPwwAABA4"]
[Tue Jul 21 07:36:02.877563 2026] [security2:error] [pid 255769:tid 255811] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LkrxMYwyVGnfuwsKP1gAEBCk"]
[Tue Jul 21 07:36:02.877725 2026] [security2:error] [pid 255769:tid 255998] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LkrxMYwyVGnfuwsKP1gAEBCk"]
[Tue Jul 21 07:36:03.082278 2026] [security2:error] [pid 255769:tid 255892] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Lk7xMYwyVGnfuwsKP2AAD-Xo"]
[Tue Jul 21 07:36:03.082414 2026] [security2:error] [pid 255769:tid 255985] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Lk7xMYwyVGnfuwsKP2AAD-Xo"]
[Tue Jul 21 07:36:03.134783 2026] [security2:error] [pid 255769:tid 255916] [client 20.220.225.223:24232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/wp-mt.php"] [unique_id "al9Lk7xMYwyVGnfuwsKP8gAAA7Q"]
[Tue Jul 21 07:36:03.177736 2026] [security2:error] [pid 255769:tid 256012] [client 45.8.17.106:30475] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/block-bindings/"] [unique_id "al9Lk7xMYwyVGnfuwsKP_AAABBI"]
[Tue Jul 21 07:36:03.235937 2026] [security2:error] [pid 255769:tid 255951] [client 37.140.223.50:53805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LkrxMYwyVGnfuwsKPywAAA9c"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:36:03.247581 2026] [security2:error] [pid 254995:tid 255090] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lk_7v0rlcEGmVraE0_gADMl4"]
[Tue Jul 21 07:36:03.247768 2026] [security2:error] [pid 254995:tid 255145] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lk_7v0rlcEGmVraE0_gADMl4"]
[Tue Jul 21 07:36:03.465889 2026] [security2:error] [pid 254995:tid 255148] [client 20.197.195.24:50318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/core.php"] [unique_id "al9Lk_7v0rlcEGmVraE1AAAAAzU"]
[Tue Jul 21 07:36:03.615311 2026] [proxy:error] [pid 255769:tid 256016] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:03.615378 2026] [proxy_http:error] [pid 255769:tid 256016] [client 20.206.105.145:38931] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:03.615915 2026] [proxy:error] [pid 255769:tid 256016] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:03.615943 2026] [proxy_http:error] [pid 255769:tid 256016] [client 20.206.105.145:38931] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:03.851879 2026] [security2:error] [pid 255769:tid 255984] [client 20.206.105.145:38464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/k3.php"] [unique_id "al9Lk7xMYwyVGnfuwsKQCgAAA_g"]
[Tue Jul 21 07:36:03.921876 2026] [security2:error] [pid 255769:tid 255902] [client 20.197.195.24:50314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/als.php"] [unique_id "al9Lk7xMYwyVGnfuwsKQCwAAA6Y"]
[Tue Jul 21 07:36:04.028120 2026] [security2:error] [pid 254995:tid 255162] [client 213.152.162.104:58078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9LlP7v0rlcEGmVraE1CAAAA0M"]
[Tue Jul 21 07:36:04.028211 2026] [security2:error] [pid 254995:tid 255162] [client 213.152.162.104:58078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9LlP7v0rlcEGmVraE1CAAAA0M"]
[Tue Jul 21 07:36:04.097341 2026] [security2:error] [pid 255769:tid 255977] [client 20.52.136.55:1565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/lv.php"] [unique_id "al9LlLxMYwyVGnfuwsKQEwAAA_E"]
[Tue Jul 21 07:36:04.129897 2026] [security2:error] [pid 255769:tid 255901] [client 20.220.225.223:48189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/hp2.php"] [unique_id "al9LlLxMYwyVGnfuwsKQGAAAA6U"]
[Tue Jul 21 07:36:04.176337 2026] [security2:error] [pid 255769:tid 255993] [client 45.8.17.49:63183] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-confiq.php"] [unique_id "al9LlLxMYwyVGnfuwsKQGQAABAA"]
[Tue Jul 21 07:36:04.385018 2026] [security2:error] [pid 255769:tid 255952] [client 20.197.195.24:62698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/simple.php"] [unique_id "al9LlLxMYwyVGnfuwsKQJAAAA9g"]
[Tue Jul 21 07:36:04.866334 2026] [security2:error] [pid 255769:tid 255923] [client 20.197.195.24:62653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/init.php"] [unique_id "al9LlLxMYwyVGnfuwsKQNQAAA7s"]
[Tue Jul 21 07:36:05.077757 2026] [security2:error] [pid 255769:tid 255953] [client 45.8.17.147:46761] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/fm.php/sts.php"] [unique_id "al9LlbxMYwyVGnfuwsKQPgAAA9k"]
[Tue Jul 21 07:36:05.131111 2026] [security2:error] [pid 255769:tid 255975] [client 152.59.154.239:54290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LlbxMYwyVGnfuwsKQPwAAA-8"]
[Tue Jul 21 07:36:05.131208 2026] [security2:error] [pid 255769:tid 255975] [client 152.59.154.239:54290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LlbxMYwyVGnfuwsKQPwAAA-8"]
[Tue Jul 21 07:36:05.452790 2026] [security2:error] [pid 255769:tid 255999] [client 20.197.195.24:49198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/fpwch.php"] [unique_id "al9LlbxMYwyVGnfuwsKQRwAABAU"]
[Tue Jul 21 07:36:05.499099 2026] [security2:error] [pid 255769:tid 256003] [client 20.206.105.145:37940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/k4.php"] [unique_id "al9LlbxMYwyVGnfuwsKQSAAABAk"]
[Tue Jul 21 07:36:05.569272 2026] [security2:error] [pid 255769:tid 255994] [client 122.129.67.13:59133] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9LlbxMYwyVGnfuwsKQSQAABAE"]
[Tue Jul 21 07:36:05.569421 2026] [security2:error] [pid 255769:tid 255994] [client 122.129.67.13:59133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9LlbxMYwyVGnfuwsKQSQAABAE"]
[Tue Jul 21 07:36:05.757492 2026] [security2:error] [pid 255769:tid 256020] [client 20.220.225.223:49545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/hp3.php"] [unique_id "al9LlbxMYwyVGnfuwsKQTQAABBo"]
[Tue Jul 21 07:36:05.784756 2026] [security2:error] [pid 255769:tid 255951] [client 139.167.225.182:58463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LlbxMYwyVGnfuwsKQTgAAA9c"]
[Tue Jul 21 07:36:05.784874 2026] [security2:error] [pid 255769:tid 255951] [client 139.167.225.182:58463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LlbxMYwyVGnfuwsKQTgAAA9c"]
[Tue Jul 21 07:36:05.973887 2026] [security2:error] [pid 254995:tid 255272] [client 59.96.220.140:54918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Llf7v0rlcEGmVraE1JAAAA5Y"]
[Tue Jul 21 07:36:05.975379 2026] [security2:error] [pid 254995:tid 255272] [client 59.96.220.140:54918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Llf7v0rlcEGmVraE1JAAAA5Y"]
[Tue Jul 21 07:36:06.275563 2026] [security2:error] [pid 254995:tid 255218] [client 45.8.17.127:34561] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/upload/index.php"] [unique_id "al9Llv7v0rlcEGmVraE1JwAAA3o"]
[Tue Jul 21 07:36:06.409033 2026] [security2:error] [pid 255769:tid 255921] [client 82.102.28.107:59374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9LlrxMYwyVGnfuwsKQUQAAA7k"]
[Tue Jul 21 07:36:06.409129 2026] [security2:error] [pid 255769:tid 255921] [client 82.102.28.107:59374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9LlrxMYwyVGnfuwsKQUQAAA7k"]
[Tue Jul 21 07:36:06.424306 2026] [security2:error] [pid 255769:tid 255966] [client 20.197.195.24:50323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/domvf.php"] [unique_id "al9LlrxMYwyVGnfuwsKQUgAAA-Y"]
[Tue Jul 21 07:36:06.682401 2026] [security2:error] [pid 255769:tid 255962] [client 45.251.232.145:61101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LlrxMYwyVGnfuwsKQVAAAA-I"]
[Tue Jul 21 07:36:06.682519 2026] [security2:error] [pid 255769:tid 255962] [client 45.251.232.145:61101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LlrxMYwyVGnfuwsKQVAAAA-I"]
[Tue Jul 21 07:36:06.701787 2026] [security2:error] [pid 255769:tid 255969] [client 20.206.105.145:37936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/k5.php"] [unique_id "al9LlrxMYwyVGnfuwsKQVQAAA-k"]
[Tue Jul 21 07:36:06.821019 2026] [security2:error] [pid 255769:tid 255955] [client 136.144.33.97:51763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LlrxMYwyVGnfuwsKQUwAAA9s"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:06.838839 2026] [rewrite:error] [pid 255769:tid 255939] [client 187.49.76.218:20161] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:36:06.841273 2026] [rewrite:error] [pid 255769:tid 256009] [client 187.49.76.218:20193] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:36:06.862565 2026] [rewrite:error] [pid 255769:tid 255976] [client 187.49.76.218:20321] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:36:07.138060 2026] [security2:error] [pid 254995:tid 255276] [client 103.162.129.114:51951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Ll_7v0rlcEGmVraE1MgAAA5o"]
[Tue Jul 21 07:36:07.138211 2026] [security2:error] [pid 254995:tid 255276] [client 103.162.129.114:51951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Ll_7v0rlcEGmVraE1MgAAA5o"]
[Tue Jul 21 07:36:07.168869 2026] [security2:error] [pid 254995:tid 255145] [client 20.220.225.223:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/bscclapb.php"] [unique_id "al9Ll_7v0rlcEGmVraE1MwAAAzI"]
[Tue Jul 21 07:36:07.176590 2026] [security2:error] [pid 254995:tid 255128] [client 45.8.17.113:27227] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/images/index.php"] [unique_id "al9Ll_7v0rlcEGmVraE1NgAAAyE"]
[Tue Jul 21 07:36:07.322711 2026] [security2:error] [pid 255769:tid 255819] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ll7xMYwyVGnfuwsKQYAAEGzE"]
[Tue Jul 21 07:36:07.322856 2026] [security2:error] [pid 255769:tid 256021] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ll7xMYwyVGnfuwsKQYAAEGzE"]
[Tue Jul 21 07:36:07.431407 2026] [security2:error] [pid 254995:tid 255154] [client 37.140.223.191:24821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Ll_7v0rlcEGmVraE1OAAAAzs"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:36:07.449036 2026] [security2:error] [pid 255769:tid 256007] [client 173.24.185.52:52866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Ll7xMYwyVGnfuwsKQYQAABA0"]
[Tue Jul 21 07:36:07.449154 2026] [security2:error] [pid 255769:tid 256007] [client 173.24.185.52:52866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Ll7xMYwyVGnfuwsKQYQAABA0"]
[Tue Jul 21 07:36:07.737372 2026] [security2:error] [pid 254995:tid 255262] [client 20.197.195.24:62649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/wp.php"] [unique_id "al9Ll_7v0rlcEGmVraE1RQAAA4w"]
[Tue Jul 21 07:36:07.972017 2026] [security2:error] [pid 254995:tid 255263] [client 122.186.204.214:52968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ll_7v0rlcEGmVraE1SAAAA40"]
[Tue Jul 21 07:36:07.975752 2026] [security2:error] [pid 254995:tid 255263] [client 122.186.204.214:52968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ll_7v0rlcEGmVraE1SAAAA40"]
[Tue Jul 21 07:36:07.996401 2026] [security2:error] [pid 254995:tid 255136] [client 20.206.105.145:37946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/w.php"] [unique_id "al9Ll_7v0rlcEGmVraE1TAAAAyk"]
[Tue Jul 21 07:36:08.078369 2026] [security2:error] [pid 254995:tid 255134] [client 45.8.17.146:62145] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "al9LmP7v0rlcEGmVraE1TQAAAyc"]
[Tue Jul 21 07:36:08.180649 2026] [security2:error] [pid 255769:tid 256014] [client 117.217.38.194:64346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LmLxMYwyVGnfuwsKQZAAABBQ"]
[Tue Jul 21 07:36:08.180761 2026] [security2:error] [pid 255769:tid 256014] [client 117.217.38.194:64346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LmLxMYwyVGnfuwsKQZAAABBQ"]
[Tue Jul 21 07:36:08.561306 2026] [rewrite:error] [pid 255769:tid 255951] [client 187.49.76.218:20193] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2415
[Tue Jul 21 07:36:08.561306 2026] [rewrite:error] [pid 255769:tid 255924] [client 187.49.76.218:20321] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2415
[Tue Jul 21 07:36:08.563321 2026] [rewrite:error] [pid 255769:tid 255944] [client 187.49.76.218:20161] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2415
[Tue Jul 21 07:36:08.872211 2026] [security2:error] [pid 255769:tid 255899] [client 45.8.17.61:20647] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/autoload_classmap/function.php"] [unique_id "al9LmLxMYwyVGnfuwsKQbwAAA6M"]
[Tue Jul 21 07:36:08.997619 2026] [security2:error] [pid 255769:tid 255788] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LmLxMYwyVGnfuwsKQcwAECxI"]
[Tue Jul 21 07:36:08.997768 2026] [security2:error] [pid 255769:tid 256005] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LmLxMYwyVGnfuwsKQcwAECxI"]
[Tue Jul 21 07:36:09.070528 2026] [security2:error] [pid 255769:tid 255966] [client 20.197.195.24:50358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/class.php"] [unique_id "al9LmbxMYwyVGnfuwsKQdgAAA-Y"]
[Tue Jul 21 07:36:09.149214 2026] [security2:error] [pid 255769:tid 256008] [client 20.206.105.145:39159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/cgi-bin/admin.php"] [unique_id "al9LmbxMYwyVGnfuwsKQeAAABA4"]
[Tue Jul 21 07:36:09.163775 2026] [security2:error] [pid 255769:tid 255992] [client 20.52.136.55:1595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/cong.php"] [unique_id "al9LmbxMYwyVGnfuwsKQeQAAA_8"]
[Tue Jul 21 07:36:09.223217 2026] [security2:error] [pid 254995:tid 255194] [client 175.45.70.82:58654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lmf7v0rlcEGmVraE1WQAAA2M"]
[Tue Jul 21 07:36:09.223368 2026] [security2:error] [pid 254995:tid 255194] [client 175.45.70.82:58654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lmf7v0rlcEGmVraE1WQAAA2M"]
[Tue Jul 21 07:36:09.445651 2026] [autoindex:error] [pid 254995:tid 255212] [client 147.185.132.57:59012] AH01276: Cannot serve directory /home1/taina869/tvexpressiva.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:36:09.450679 2026] [security2:error] [pid 255769:tid 255957] [client 122.162.144.145:21003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LmbxMYwyVGnfuwsKQggAAA90"]
[Tue Jul 21 07:36:09.450788 2026] [security2:error] [pid 255769:tid 255957] [client 122.162.144.145:21003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LmbxMYwyVGnfuwsKQggAAA90"]
[Tue Jul 21 07:36:09.467968 2026] [security2:error] [pid 255769:tid 255930] [client 20.206.105.145:37922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/fpwch.php"] [unique_id "al9LmbxMYwyVGnfuwsKQgwAAA8I"]
[Tue Jul 21 07:36:09.674412 2026] [security2:error] [pid 255769:tid 255978] [client 45.8.17.146:64513] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "al9LmbxMYwyVGnfuwsKQhwAAA_I"]
[Tue Jul 21 07:36:09.898917 2026] [security2:error] [pid 255769:tid 255948] [client 20.197.195.24:62676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/echkm.php"] [unique_id "al9LmbxMYwyVGnfuwsKQjAAAA9Q"]
[Tue Jul 21 07:36:10.045688 2026] [security2:error] [pid 255769:tid 255932] [client 103.106.20.201:63444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LmrxMYwyVGnfuwsKQjwAAA8Q"]
[Tue Jul 21 07:36:10.045849 2026] [security2:error] [pid 255769:tid 255932] [client 103.106.20.201:63444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LmrxMYwyVGnfuwsKQjwAAA8Q"]
[Tue Jul 21 07:36:10.237313 2026] [security2:error] [pid 255769:tid 255905] [client 185.251.19.73:27395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9LmrxMYwyVGnfuwsKQkwAAA6k"]
[Tue Jul 21 07:36:10.479000 2026] [security2:error] [pid 255769:tid 255974] [client 185.251.19.80:26839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9LmbxMYwyVGnfuwsKQiAAAA-4"]
[Tue Jul 21 07:36:10.507133 2026] [security2:error] [pid 255769:tid 255981] [client 193.36.225.67:21923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LmrxMYwyVGnfuwsKQlwAAA_U"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:10.668578 2026] [security2:error] [pid 255769:tid 255920] [client 20.197.195.24:62670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/lib.php"] [unique_id "al9LmrxMYwyVGnfuwsKQmQAAA7g"]
[Tue Jul 21 07:36:10.777206 2026] [security2:error] [pid 254995:tid 255264] [client 45.8.17.125:49537] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/sketch/404.php"] [unique_id "al9Lmv7v0rlcEGmVraE1bQAAA44"]
[Tue Jul 21 07:36:10.902488 2026] [security2:error] [pid 255769:tid 256002] [client 20.206.105.145:37932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/w2025.php"] [unique_id "al9LmrxMYwyVGnfuwsKQmgAABAg"]
[Tue Jul 21 07:36:10.962164 2026] [security2:error] [pid 255769:tid 255786] [remote 124.55.178.99:56036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9LmrxMYwyVGnfuwsKQnQADpRA"]
[Tue Jul 21 07:36:11.444565 2026] [security2:error] [pid 255769:tid 255919] [client 20.197.195.24:50322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/login.php"] [unique_id "al9Lm7xMYwyVGnfuwsKQowAAA7c"]
[Tue Jul 21 07:36:11.507617 2026] [security2:error] [pid 255769:tid 255840] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lm7xMYwyVGnfuwsKQqAAD90Y"]
[Tue Jul 21 07:36:11.507744 2026] [security2:error] [pid 255769:tid 255983] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lm7xMYwyVGnfuwsKQqAAD90Y"]
[Tue Jul 21 07:36:11.736196 2026] [security2:error] [pid 255769:tid 256021] [client 20.220.225.223:24247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/ww.php"] [unique_id "al9Lm7xMYwyVGnfuwsKQqgAABBs"]
[Tue Jul 21 07:36:11.804621 2026] [security2:error] [pid 255769:tid 256012] [client 20.197.195.24:62624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/a2.php"] [unique_id "al9Lm7xMYwyVGnfuwsKQrAAABBI"]
[Tue Jul 21 07:36:12.026227 2026] [security2:error] [pid 254995:tid 255222] [client 122.164.127.47:50698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LnP7v0rlcEGmVraE1fgAAA34"]
[Tue Jul 21 07:36:12.026322 2026] [security2:error] [pid 254995:tid 255222] [client 122.164.127.47:50698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LnP7v0rlcEGmVraE1fgAAA34"]
[Tue Jul 21 07:36:12.274565 2026] [security2:error] [pid 254995:tid 255255] [client 20.197.195.24:62627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/d61.php"] [unique_id "al9LnP7v0rlcEGmVraE1gQAAA4U"]
[Tue Jul 21 07:36:12.373548 2026] [security2:error] [pid 254995:tid 255148] [client 103.174.34.15:55206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LnP7v0rlcEGmVraE1ggAAAzU"]
[Tue Jul 21 07:36:12.374059 2026] [security2:error] [pid 254995:tid 255148] [client 103.174.34.15:55206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LnP7v0rlcEGmVraE1ggAAAzU"]
[Tue Jul 21 07:36:12.531458 2026] [security2:error] [pid 255769:tid 255900] [client 37.140.223.137:64763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LmrxMYwyVGnfuwsKQlAAAA6Q"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:36:12.819202 2026] [security2:error] [pid 255769:tid 255944] [client 20.197.195.24:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/info.php"] [unique_id "al9LnLxMYwyVGnfuwsKQtAAAA9A"]
[Tue Jul 21 07:36:12.902061 2026] [security2:error] [pid 254995:tid 255011] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LnP7v0rlcEGmVraE1igADjQ8"]
[Tue Jul 21 07:36:12.902217 2026] [security2:error] [pid 254995:tid 255263] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LnP7v0rlcEGmVraE1igADjQ8"]
[Tue Jul 21 07:36:12.972646 2026] [security2:error] [pid 254995:tid 255187] [client 45.8.17.146:42073] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/languages/index.php"] [unique_id "al9LnP7v0rlcEGmVraE1jAAAA1w"]
[Tue Jul 21 07:36:13.066974 2026] [security2:error] [pid 254995:tid 255179] [client 20.197.195.24:50324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/11.php"] [unique_id "al9Lnf7v0rlcEGmVraE1jQAAA1Q"]
[Tue Jul 21 07:36:13.075931 2026] [security2:error] [pid 255769:tid 256013] [client 20.52.136.55:1574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/brand.php"] [unique_id "al9LnbxMYwyVGnfuwsKQuAAABBM"]
[Tue Jul 21 07:36:13.197187 2026] [security2:error] [pid 254995:tid 255213] [client 20.206.105.145:38117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/scxy.php"] [unique_id "al9Lnf7v0rlcEGmVraE1kQAAA3U"]
[Tue Jul 21 07:36:13.485091 2026] [security2:error] [pid 255769:tid 256003] [client 20.197.195.24:50353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/v2.php"] [unique_id "al9LnbxMYwyVGnfuwsKQugAABAk"]
[Tue Jul 21 07:36:13.584074 2026] [security2:error] [pid 255769:tid 255802] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LnbxMYwyVGnfuwsKQuwAD5iA"]
[Tue Jul 21 07:36:13.584224 2026] [security2:error] [pid 255769:tid 255966] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LnbxMYwyVGnfuwsKQuwAD5iA"]
[Tue Jul 21 07:36:13.748966 2026] [security2:error] [pid 254995:tid 255167] [client 20.197.195.24:62695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/panel.php"] [unique_id "al9Lnf7v0rlcEGmVraE1nAAAA0g"]
[Tue Jul 21 07:36:13.918120 2026] [security2:error] [pid 255769:tid 255801] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LnbxMYwyVGnfuwsKQvwAD_x8"]
[Tue Jul 21 07:36:13.918282 2026] [security2:error] [pid 255769:tid 255992] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LnbxMYwyVGnfuwsKQvwAD_x8"]
[Tue Jul 21 07:36:14.181684 2026] [security2:error] [pid 255769:tid 255976] [client 45.8.17.129:52867] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/media-new.php"] [unique_id "al9LnrxMYwyVGnfuwsKQwAAAA_A"]
[Tue Jul 21 07:36:14.406594 2026] [security2:error] [pid 254995:tid 255152] [client 59.96.220.140:55668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Lnv7v0rlcEGmVraE1qAAAAzk"]
[Tue Jul 21 07:36:14.406723 2026] [security2:error] [pid 254995:tid 255152] [client 59.96.220.140:55668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Lnv7v0rlcEGmVraE1qAAAAzk"]
[Tue Jul 21 07:36:14.567301 2026] [security2:error] [pid 255769:tid 255937] [client 136.144.33.97:33441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LnrxMYwyVGnfuwsKQxQAAA8k"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:14.630021 2026] [security2:error] [pid 255769:tid 255892] [remote 216.73.216.238:41157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/chales.php"] [unique_id "al9LnrxMYwyVGnfuwsKQxgADtno"]
[Tue Jul 21 07:36:14.636040 2026] [security2:error] [pid 254995:tid 255070] [remote 116.179.37.119:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9Lnf7v0rlcEGmVraE1lwADY0o"], referer: https://androapkmod.com/esposa-de-detetive-lobisomem-apk-mod/
[Tue Jul 21 07:36:15.120888 2026] [security2:error] [pid 255769:tid 255900] [client 20.206.105.145:39158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/gettest.php"] [unique_id "al9Ln7xMYwyVGnfuwsKQzwAAA6Q"]
[Tue Jul 21 07:36:15.205527 2026] [security2:error] [pid 255769:tid 256028] [client 20.197.195.24:62657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/dex.php"] [unique_id "al9Ln7xMYwyVGnfuwsKQ0QAABCI"]
[Tue Jul 21 07:36:15.251116 2026] [security2:error] [pid 255769:tid 255834] [remote 182.77.62.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amandamorau.adv.br"] [uri "/wp-login.php"] [unique_id "al9Ln7xMYwyVGnfuwsKQ0gADqUA"]
[Tue Jul 21 07:36:15.384949 2026] [security2:error] [pid 254995:tid 255153] [client 20.206.105.145:38483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/FWAZ.php"] [unique_id "al9Ln_7v0rlcEGmVraE1uAAAAzo"]
[Tue Jul 21 07:36:15.778881 2026] [security2:error] [pid 254995:tid 255269] [client 45.8.17.130:20057] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/tiny.php"] [unique_id "al9Ln_7v0rlcEGmVraE1uwAAA5M"]
[Tue Jul 21 07:36:16.368845 2026] [security2:error] [pid 255769:tid 255989] [client 152.59.154.239:54785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LoLxMYwyVGnfuwsKQ2wAAA_0"]
[Tue Jul 21 07:36:16.368958 2026] [security2:error] [pid 255769:tid 255989] [client 152.59.154.239:54785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LoLxMYwyVGnfuwsKQ2wAAA_0"]
[Tue Jul 21 07:36:16.509423 2026] [security2:error] [pid 254995:tid 255211] [client 20.197.195.24:49179] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.cmpartners.com.br"] [uri "/1.php"] [unique_id "al9LoP7v0rlcEGmVraE1ygAAA3M"]
[Tue Jul 21 07:36:16.509590 2026] [security2:error] [pid 254995:tid 255211] [client 20.197.195.24:49179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/1.php"] [unique_id "al9LoP7v0rlcEGmVraE1ygAAA3M"]
[Tue Jul 21 07:36:16.939287 2026] [security2:error] [pid 255769:tid 255907] [client 20.52.136.55:1506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/atomlib.php"] [unique_id "al9LoLxMYwyVGnfuwsKQ3wAAA6s"]
[Tue Jul 21 07:36:17.068556 2026] [security2:error] [pid 254995:tid 255146] [client 45.8.17.61:37417] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/license.php"] [unique_id "al9Lof7v0rlcEGmVraE10gAAAzM"]
[Tue Jul 21 07:36:17.144177 2026] [security2:error] [pid 254995:tid 255256] [client 45.251.232.145:61622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lof7v0rlcEGmVraE11AAAA4Y"]
[Tue Jul 21 07:36:17.144317 2026] [security2:error] [pid 254995:tid 255256] [client 45.251.232.145:61622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lof7v0rlcEGmVraE11AAAA4Y"]
[Tue Jul 21 07:36:17.275058 2026] [security2:error] [pid 254995:tid 255268] [client 20.220.225.223:49584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/aa1.php"] [unique_id "al9Lof7v0rlcEGmVraE11QAAA5I"]
[Tue Jul 21 07:36:17.343614 2026] [security2:error] [pid 254995:tid 255155] [client 20.220.225.223:38677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/wp-signup.php"] [unique_id "al9Lof7v0rlcEGmVraE11wAAAzw"]
[Tue Jul 21 07:36:17.597714 2026] [security2:error] [pid 255769:tid 255985] [client 139.167.225.182:59106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LobxMYwyVGnfuwsKQ4wAAA_k"]
[Tue Jul 21 07:36:17.597833 2026] [security2:error] [pid 255769:tid 255985] [client 139.167.225.182:59106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LobxMYwyVGnfuwsKQ4wAAA_k"]
[Tue Jul 21 07:36:17.740918 2026] [security2:error] [pid 255769:tid 256025] [client 117.251.86.144:39874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LobxMYwyVGnfuwsKQ5AAABB8"]
[Tue Jul 21 07:36:17.741049 2026] [security2:error] [pid 255769:tid 256025] [client 117.251.86.144:39874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LobxMYwyVGnfuwsKQ5AAABB8"]
[Tue Jul 21 07:36:17.808800 2026] [security2:error] [pid 255769:tid 255884] [remote 216.73.216.238:61649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/chales.php"] [unique_id "al9LobxMYwyVGnfuwsKQ5QAD2XI"]
[Tue Jul 21 07:36:17.856554 2026] [security2:error] [pid 255769:tid 255996] [client 103.162.129.114:52404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LobxMYwyVGnfuwsKQ5gAABAI"]
[Tue Jul 21 07:36:17.856637 2026] [security2:error] [pid 255769:tid 255996] [client 103.162.129.114:52404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LobxMYwyVGnfuwsKQ5gAABAI"]
[Tue Jul 21 07:36:17.904359 2026] [rewrite:error] [pid 254995:tid 255260] [client 187.49.76.218:20385] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:36:17.907179 2026] [rewrite:error] [pid 255769:tid 256021] [client 187.49.76.218:20417] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:36:17.926594 2026] [rewrite:error] [pid 254995:tid 255160] [client 187.49.76.218:20449] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:36:18.013192 2026] [security2:error] [pid 255769:tid 255975] [client 173.24.185.52:53340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LorxMYwyVGnfuwsKQ6wAAA-8"]
[Tue Jul 21 07:36:18.013331 2026] [security2:error] [pid 255769:tid 255975] [client 173.24.185.52:53340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LorxMYwyVGnfuwsKQ6wAAA-8"]
[Tue Jul 21 07:36:18.071375 2026] [security2:error] [pid 254995:tid 255219] [client 20.197.195.24:50313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/ms.php"] [unique_id "al9Lov7v0rlcEGmVraE16QAAA3s"]
[Tue Jul 21 07:36:18.076055 2026] [security2:error] [pid 255769:tid 255939] [client 45.8.17.148:54915] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/av.php"] [unique_id "al9LorxMYwyVGnfuwsKQ7QAAA8s"]
[Tue Jul 21 07:36:18.087844 2026] [security2:error] [pid 254995:tid 255206] [client 62.102.148.164:47890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Lov7v0rlcEGmVraE16gAAA28"]
[Tue Jul 21 07:36:18.087933 2026] [security2:error] [pid 254995:tid 255206] [client 62.102.148.164:47890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Lov7v0rlcEGmVraE16gAAA28"]
[Tue Jul 21 07:36:18.117154 2026] [security2:error] [pid 254995:tid 255049] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lov7v0rlcEGmVraE16wADizU"]
[Tue Jul 21 07:36:18.117287 2026] [security2:error] [pid 254995:tid 255261] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lov7v0rlcEGmVraE16wADizU"]
[Tue Jul 21 07:36:18.420880 2026] [fcgid:warn] [pid 255769:tid 256020] (70014)End of file found: [client 45.79.115.59:37647] mod_fcgid: can't get data from http client
[Tue Jul 21 07:36:18.565627 2026] [security2:error] [pid 254995:tid 255178] [client 122.186.204.214:53782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lov7v0rlcEGmVraE18wAAA1M"]
[Tue Jul 21 07:36:18.570308 2026] [security2:error] [pid 254995:tid 255178] [client 122.186.204.214:53782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lov7v0rlcEGmVraE18wAAA1M"]
[Tue Jul 21 07:36:18.648532 2026] [security2:error] [pid 255769:tid 256014] [client 117.217.38.194:64813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LorxMYwyVGnfuwsKQ9QAABBQ"]
[Tue Jul 21 07:36:18.648613 2026] [security2:error] [pid 255769:tid 256014] [client 117.217.38.194:64813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LorxMYwyVGnfuwsKQ9QAABBQ"]
[Tue Jul 21 07:36:18.855110 2026] [autoindex:error] [pid 255769:tid 255981] [client 20.197.195.24:50350] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:36:18.877509 2026] [security2:error] [pid 255769:tid 255925] [client 20.197.195.24:50350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/memberfuns.php"] [unique_id "al9LorxMYwyVGnfuwsKQ9wAAA70"]
[Tue Jul 21 07:36:19.117200 2026] [security2:error] [pid 255769:tid 256009] [client 20.206.105.145:38476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/qterm.php"] [unique_id "al9Lo7xMYwyVGnfuwsKQ_gAABA8"]
[Tue Jul 21 07:36:19.136149 2026] [security2:error] [pid 255769:tid 255905] [client 122.129.67.13:59393] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9Lo7xMYwyVGnfuwsKQ_wAAA6k"]
[Tue Jul 21 07:36:19.136262 2026] [security2:error] [pid 255769:tid 255905] [client 122.129.67.13:59393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9Lo7xMYwyVGnfuwsKQ_wAAA6k"]
[Tue Jul 21 07:36:19.180154 2026] [security2:error] [pid 255769:tid 255998] [client 45.8.17.136:44659] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-login-css.php"] [unique_id "al9Lo7xMYwyVGnfuwsKRAAAABAQ"]
[Tue Jul 21 07:36:19.310610 2026] [security2:error] [pid 255769:tid 255785] [remote 154.61.75.100:58612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteoficialgs.com"] [uri "/wp-login.php"] [unique_id "al9Lo7xMYwyVGnfuwsKRAQAD3w8"]
[Tue Jul 21 07:36:19.443004 2026] [rewrite:error] [pid 254995:tid 255182] [client 187.49.76.218:20449] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2417
[Tue Jul 21 07:36:19.443006 2026] [rewrite:error] [pid 255769:tid 255983] [client 187.49.76.218:20417] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2417
[Tue Jul 21 07:36:19.445223 2026] [rewrite:error] [pid 254995:tid 255215] [client 187.49.76.218:20385] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2417
[Tue Jul 21 07:36:19.459256 2026] [proxy:error] [pid 255769:tid 255923] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:19.459335 2026] [proxy_http:error] [pid 255769:tid 255923] [client 20.206.105.145:39135] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:19.459879 2026] [proxy:error] [pid 255769:tid 255923] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:19.459909 2026] [proxy_http:error] [pid 255769:tid 255923] [client 20.206.105.145:39135] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:19.506207 2026] [security2:error] [pid 255769:tid 255795] [remote 45.117.83.212:52014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Lo7xMYwyVGnfuwsKRBwAD3hk"]
[Tue Jul 21 07:36:19.576419 2026] [security2:error] [pid 255769:tid 255772] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lo7xMYwyVGnfuwsKRCQAD2wI"]
[Tue Jul 21 07:36:19.576560 2026] [security2:error] [pid 255769:tid 255955] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lo7xMYwyVGnfuwsKRCQAD2wI"]
[Tue Jul 21 07:36:19.839105 2026] [security2:error] [pid 255769:tid 255953] [client 20.206.105.145:37915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/blurbs.php"] [unique_id "al9Lo7xMYwyVGnfuwsKRDAAAA9k"]
[Tue Jul 21 07:36:19.953064 2026] [security2:error] [pid 255769:tid 255929] [client 20.206.105.145:38496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/v543.php"] [unique_id "al9Lo7xMYwyVGnfuwsKRDwAAA8E"]
[Tue Jul 21 07:36:19.967688 2026] [security2:error] [pid 255769:tid 256007] [client 20.197.195.24:62666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/0.php"] [unique_id "al9Lo7xMYwyVGnfuwsKREAAABA0"]
[Tue Jul 21 07:36:19.969971 2026] [security2:error] [pid 255769:tid 255937] [client 136.144.33.99:25389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Lo7xMYwyVGnfuwsKRCwAAA8k"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:20.024019 2026] [security2:error] [pid 255769:tid 255903] [client 20.206.105.145:37890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/w3lls.php"] [unique_id "al9LpLxMYwyVGnfuwsKRFAAAA6c"]
[Tue Jul 21 07:36:20.040198 2026] [security2:error] [pid 254995:tid 255183] [client 175.45.70.82:59215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LpP7v0rlcEGmVraE2BAAAA1g"]
[Tue Jul 21 07:36:20.040295 2026] [security2:error] [pid 254995:tid 255183] [client 175.45.70.82:59215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LpP7v0rlcEGmVraE2BAAAA1g"]
[Tue Jul 21 07:36:20.168992 2026] [security2:error] [pid 255769:tid 255946] [client 122.162.144.145:3056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LpLxMYwyVGnfuwsKRGAAAA9I"]
[Tue Jul 21 07:36:20.169109 2026] [security2:error] [pid 255769:tid 255946] [client 122.162.144.145:3056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LpLxMYwyVGnfuwsKRGAAAA9I"]
[Tue Jul 21 07:36:20.187839 2026] [security2:error] [pid 255769:tid 255944] [client 45.8.17.103:28105] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/classwithtostring.php"] [unique_id "al9LpLxMYwyVGnfuwsKRGQAAA9A"]
[Tue Jul 21 07:36:20.259405 2026] [security2:error] [pid 255769:tid 255924] [client 62.102.148.164:33090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9LpLxMYwyVGnfuwsKRGwAAA7w"]
[Tue Jul 21 07:36:20.259495 2026] [security2:error] [pid 255769:tid 255924] [client 62.102.148.164:33090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9LpLxMYwyVGnfuwsKRGwAAA7w"]
[Tue Jul 21 07:36:20.692467 2026] [security2:error] [pid 255769:tid 256003] [client 173.252.95.57:58770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LpLxMYwyVGnfuwsKRIQAABAk"]
[Tue Jul 21 07:36:20.813529 2026] [security2:error] [pid 255769:tid 255984] [client 103.106.20.201:64024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LpLxMYwyVGnfuwsKRIgAAA_g"]
[Tue Jul 21 07:36:20.813693 2026] [security2:error] [pid 255769:tid 255984] [client 103.106.20.201:64024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LpLxMYwyVGnfuwsKRIgAAA_g"]
[Tue Jul 21 07:36:20.814698 2026] [security2:error] [pid 254995:tid 255164] [client 213.152.162.104:45462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9LpP7v0rlcEGmVraE2DQAAA0U"]
[Tue Jul 21 07:36:20.814783 2026] [security2:error] [pid 254995:tid 255164] [client 213.152.162.104:45462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9LpP7v0rlcEGmVraE2DQAAA0U"]
[Tue Jul 21 07:36:20.869996 2026] [security2:error] [pid 254995:tid 255196] [client 20.206.105.145:37913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-ws68.php"] [unique_id "al9LpP7v0rlcEGmVraE2DwAAA2U"]
[Tue Jul 21 07:36:21.205088 2026] [security2:error] [pid 255769:tid 255947] [client 20.197.195.24:62697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/BDKR28.php"] [unique_id "al9LpbxMYwyVGnfuwsKRJwAAA9M"]
[Tue Jul 21 07:36:21.586204 2026] [security2:error] [pid 255769:tid 255953] [client 45.8.17.48:36405] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Text/Diff/Engine/template-singl-portfolio.php"] [unique_id "al9LpbxMYwyVGnfuwsKRLwAAA9k"]
[Tue Jul 21 07:36:22.053914 2026] [security2:error] [pid 255769:tid 255776] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LprxMYwyVGnfuwsKRNAAEHAY"]
[Tue Jul 21 07:36:22.054125 2026] [security2:error] [pid 255769:tid 256022] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LprxMYwyVGnfuwsKRNAAEHAY"]
[Tue Jul 21 07:36:22.349945 2026] [security2:error] [pid 254995:tid 255275] [client 20.52.136.55:1586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/0x.php"] [unique_id "al9Lpv7v0rlcEGmVraE2IwAAA5k"]
[Tue Jul 21 07:36:22.352921 2026] [security2:error] [pid 255769:tid 256028] [client 20.197.195.24:50365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/green1.php"] [unique_id "al9LprxMYwyVGnfuwsKRNgAABCI"]
[Tue Jul 21 07:36:22.590297 2026] [security2:error] [pid 255769:tid 255965] [client 193.36.225.143:51567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LpbxMYwyVGnfuwsKRLgAAA-U"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:36:22.728306 2026] [security2:error] [pid 255769:tid 256014] [client 20.220.225.223:51463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/acew67.php"] [unique_id "al9LprxMYwyVGnfuwsKRQAAABBQ"]
[Tue Jul 21 07:36:22.824969 2026] [security2:error] [pid 255769:tid 255973] [client 122.164.127.47:51200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LprxMYwyVGnfuwsKRQwAAA-0"]
[Tue Jul 21 07:36:22.825123 2026] [security2:error] [pid 255769:tid 255973] [client 122.164.127.47:51200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LprxMYwyVGnfuwsKRQwAAA-0"]
[Tue Jul 21 07:36:22.875667 2026] [security2:error] [pid 254995:tid 255221] [client 45.8.17.126:24785] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "al9Lpv7v0rlcEGmVraE2LgAAA30"]
[Tue Jul 21 07:36:23.031644 2026] [security2:error] [pid 254995:tid 255206] [client 20.197.195.24:62636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/nc4.php"] [unique_id "al9Lp_7v0rlcEGmVraE2MQAAA28"]
[Tue Jul 21 07:36:23.094762 2026] [security2:error] [pid 254995:tid 255208] [client 20.220.225.223:31172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/csa.php"] [unique_id "al9Lp_7v0rlcEGmVraE2NgAAA3A"]
[Tue Jul 21 07:36:23.119702 2026] [security2:error] [pid 255769:tid 255915] [client 103.174.34.15:55684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lp7xMYwyVGnfuwsKRRwAAA7M"]
[Tue Jul 21 07:36:23.119881 2026] [security2:error] [pid 255769:tid 255915] [client 103.174.34.15:55684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lp7xMYwyVGnfuwsKRRwAAA7M"]
[Tue Jul 21 07:36:23.162169 2026] [security2:error] [pid 254995:tid 255272] [client 74.7.175.183:40840] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.abrsolar.org.br"] [uri "/index.php"] [unique_id "al9Lp_7v0rlcEGmVraE2NQADlj8"]
[Tue Jul 21 07:36:23.212284 2026] [fcgid:warn] [pid 254995:tid 255205] (70014)End of file found: [client 199.45.154.126:53748] mod_fcgid: can't get data from http client
[Tue Jul 21 07:36:23.355116 2026] [security2:error] [pid 254995:tid 255181] [client 20.104.96.117:59687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Lp_7v0rlcEGmVraE2PAAAA1Y"]
[Tue Jul 21 07:36:23.410896 2026] [security2:error] [pid 254995:tid 255259] [client 20.206.105.145:37933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/xyn.php"] [unique_id "al9Lp_7v0rlcEGmVraE2PQAAA4k"]
[Tue Jul 21 07:36:23.525419 2026] [security2:error] [pid 254995:tid 255123] [remote 216.73.216.238:60084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/chales.php"] [unique_id "al9Lp_7v0rlcEGmVraE2QAADZH8"]
[Tue Jul 21 07:36:23.679958 2026] [security2:error] [pid 255769:tid 255911] [client 136.144.33.108:47377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Lp7xMYwyVGnfuwsKRSQAAA68"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:23.786944 2026] [security2:error] [pid 255769:tid 255784] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lp7xMYwyVGnfuwsKRTQAD0Q4"]
[Tue Jul 21 07:36:23.787099 2026] [security2:error] [pid 255769:tid 255945] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lp7xMYwyVGnfuwsKRTQAD0Q4"]
[Tue Jul 21 07:36:23.876186 2026] [security2:error] [pid 255769:tid 256021] [client 45.8.17.107:35051] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/lock360.php"] [unique_id "al9Lp7xMYwyVGnfuwsKRUQAABBs"]
[Tue Jul 21 07:36:24.097713 2026] [security2:error] [pid 255769:tid 255876] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LqLxMYwyVGnfuwsKRVAADtmo"]
[Tue Jul 21 07:36:24.097932 2026] [security2:error] [pid 255769:tid 255918] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LqLxMYwyVGnfuwsKRVAADtmo"]
[Tue Jul 21 07:36:24.308736 2026] [security2:error] [pid 255769:tid 255982] [client 20.197.195.24:49166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/a1.php"] [unique_id "al9LqLxMYwyVGnfuwsKRWAAAA_Y"]
[Tue Jul 21 07:36:24.405322 2026] [security2:error] [pid 255769:tid 255935] [client 20.206.105.145:39242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/simple.php"] [unique_id "al9LqLxMYwyVGnfuwsKRXgAAA8c"]
[Tue Jul 21 07:36:24.578114 2026] [security2:error] [pid 255769:tid 255814] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LqLxMYwyVGnfuwsKRYgAD7Cw"]
[Tue Jul 21 07:36:24.578256 2026] [security2:error] [pid 255769:tid 255972] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LqLxMYwyVGnfuwsKRYgAD7Cw"]
[Tue Jul 21 07:36:24.685396 2026] [security2:error] [pid 255769:tid 256002] [client 213.152.162.104:45470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9LqLxMYwyVGnfuwsKRZQAABAg"]
[Tue Jul 21 07:36:24.685519 2026] [security2:error] [pid 255769:tid 256002] [client 213.152.162.104:45470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9LqLxMYwyVGnfuwsKRZQAABAg"]
[Tue Jul 21 07:36:24.707615 2026] [security2:error] [pid 255769:tid 255969] [client 82.102.28.107:40380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9LqLxMYwyVGnfuwsKRZgAAA-k"]
[Tue Jul 21 07:36:24.707712 2026] [security2:error] [pid 255769:tid 255969] [client 82.102.28.107:40380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9LqLxMYwyVGnfuwsKRZgAAA-k"]
[Tue Jul 21 07:36:24.718879 2026] [security2:error] [pid 254995:tid 255127] [client 20.104.96.117:59198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9LqP7v0rlcEGmVraE2UQAAAyA"]
[Tue Jul 21 07:36:25.062667 2026] [security2:error] [pid 254995:tid 255197] [client 59.96.220.140:56174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Lqf7v0rlcEGmVraE2VwAAA2Y"]
[Tue Jul 21 07:36:25.063361 2026] [security2:error] [pid 254995:tid 255197] [client 59.96.220.140:56174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Lqf7v0rlcEGmVraE2VwAAA2Y"]
[Tue Jul 21 07:36:25.133313 2026] [security2:error] [pid 255769:tid 255976] [client 20.197.195.24:49213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/eee.php"] [unique_id "al9LqbxMYwyVGnfuwsKRawAAA_A"]
[Tue Jul 21 07:36:25.287215 2026] [security2:error] [pid 255769:tid 255955] [client 20.220.225.223:24201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/cron.php"] [unique_id "al9LqbxMYwyVGnfuwsKRbwAAA9s"]
[Tue Jul 21 07:36:25.467641 2026] [security2:error] [pid 255769:tid 255985] [client 45.8.17.123:29907] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/alfa.php"] [unique_id "al9LqbxMYwyVGnfuwsKRcAAAA_k"]
[Tue Jul 21 07:36:25.599244 2026] [security2:error] [pid 255769:tid 255996] [client 20.206.105.145:37921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/green3.php"] [unique_id "al9LqbxMYwyVGnfuwsKRdQAABAI"]
[Tue Jul 21 07:36:25.657147 2026] [security2:error] [pid 255769:tid 255967] [client 20.197.195.24:50327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/wp-aothait.php"] [unique_id "al9LqbxMYwyVGnfuwsKRdgAAA-c"]
[Tue Jul 21 07:36:26.208080 2026] [core:alert] [pid 255769:tid 255922] [client 57.141.18.102:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:36:26.301722 2026] [security2:error] [pid 254995:tid 255152] [client 20.104.96.117:59169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/xyn.php"] [unique_id "al9Lqv7v0rlcEGmVraE2ygAAAzk"]
[Tue Jul 21 07:36:26.494021 2026] [security2:error] [pid 254995:tid 255150] [client 20.197.195.24:50334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/config.json.php"] [unique_id "al9Lqv7v0rlcEGmVraE2zQAAAzc"]
[Tue Jul 21 07:36:26.711281 2026] [security2:error] [pid 255769:tid 255992] [client 20.206.105.145:37917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/ccs.php"] [unique_id "al9LqrxMYwyVGnfuwsKRiAAAA_8"]
[Tue Jul 21 07:36:26.774972 2026] [security2:error] [pid 255769:tid 255984] [client 45.8.17.124:41265] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "al9LqrxMYwyVGnfuwsKRiQAAA_g"]
[Tue Jul 21 07:36:26.834236 2026] [security2:error] [pid 255769:tid 256024] [client 20.104.96.117:59665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/patie.php"] [unique_id "al9LqrxMYwyVGnfuwsKRjAAABB4"]
[Tue Jul 21 07:36:26.856461 2026] [security2:error] [pid 254995:tid 255153] [client 20.220.225.223:24297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/xxx.php"] [unique_id "al9Lqv7v0rlcEGmVraE20gAAAzo"]
[Tue Jul 21 07:36:27.041004 2026] [security2:error] [pid 254995:tid 255178] [client 139.167.225.182:59742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lq_7v0rlcEGmVraE2_wAAA1M"]
[Tue Jul 21 07:36:27.041141 2026] [security2:error] [pid 254995:tid 255178] [client 139.167.225.182:59742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lq_7v0rlcEGmVraE2_wAAA1M"]
[Tue Jul 21 07:36:27.244696 2026] [security2:error] [pid 255769:tid 255918] [client 20.197.195.24:62694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9Lq7xMYwyVGnfuwsKRnQAAA7Y"]
[Tue Jul 21 07:36:27.344988 2026] [security2:error] [pid 255769:tid 255999] [client 20.104.96.117:59145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/aa.php"] [unique_id "al9Lq7xMYwyVGnfuwsKRoAAABAU"]
[Tue Jul 21 07:36:27.387012 2026] [security2:error] [pid 255769:tid 255948] [client 20.220.225.223:38681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/min.php"] [unique_id "al9Lq7xMYwyVGnfuwsKRoQAAA9Q"]
[Tue Jul 21 07:36:27.595784 2026] [security2:error] [pid 254995:tid 255265] [client 152.59.154.239:55265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lq_7v0rlcEGmVraE3BgAAA48"]
[Tue Jul 21 07:36:27.595931 2026] [security2:error] [pid 254995:tid 255265] [client 152.59.154.239:55265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lq_7v0rlcEGmVraE3BgAAA48"]
[Tue Jul 21 07:36:27.596058 2026] [security2:error] [pid 255769:tid 255974] [client 37.140.223.134:42359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Lq7xMYwyVGnfuwsKRogAAA-4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:36:27.596710 2026] [security2:error] [pid 254995:tid 255145] [client 45.251.232.145:62147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lq_7v0rlcEGmVraE3BwAAAzI"]
[Tue Jul 21 07:36:27.596802 2026] [security2:error] [pid 254995:tid 255145] [client 45.251.232.145:62147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lq_7v0rlcEGmVraE3BwAAAzI"]
[Tue Jul 21 07:36:27.698382 2026] [security2:error] [pid 255769:tid 255970] [client 20.104.96.117:59703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/xwpg.php"] [unique_id "al9Lq7xMYwyVGnfuwsKRpAAAA-o"]
[Tue Jul 21 07:36:27.773511 2026] [security2:error] [pid 255769:tid 255951] [client 20.206.105.145:37900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/ccc.php"] [unique_id "al9Lq7xMYwyVGnfuwsKRpQAAA9c"]
[Tue Jul 21 07:36:27.775657 2026] [security2:error] [pid 255769:tid 255935] [client 45.8.17.118:37715] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/templates/atomic/templates.php"] [unique_id "al9Lq7xMYwyVGnfuwsKRpgAAA8c"]
[Tue Jul 21 07:36:27.966073 2026] [security2:error] [pid 255769:tid 255903] [client 216.73.160.185:55701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reserveseulugar.com.br"] [uri "/wp-login.php"] [unique_id "al9Lq7xMYwyVGnfuwsKRpwAAA6c"]
[Tue Jul 21 07:36:28.181120 2026] [security2:error] [pid 255769:tid 255926] [client 20.104.96.117:59707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/ops.php"] [unique_id "al9LrLxMYwyVGnfuwsKRrgAAA74"]
[Tue Jul 21 07:36:28.187965 2026] [security2:error] [pid 255769:tid 256003] [client 20.197.195.24:62712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/k2.php"] [unique_id "al9LrLxMYwyVGnfuwsKRrwAABAk"]
[Tue Jul 21 07:36:28.205989 2026] [security2:error] [pid 254995:tid 255264] [client 193.36.225.63:31033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LrP7v0rlcEGmVraE3DgAAA44"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:28.233122 2026] [security2:error] [pid 255769:tid 255961] [client 20.206.105.145:38974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/xxx.php"] [unique_id "al9LrLxMYwyVGnfuwsKRsAAAA-E"]
[Tue Jul 21 07:36:28.298177 2026] [security2:error] [pid 255769:tid 255947] [client 20.206.105.145:37924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/get.php"] [unique_id "al9LrLxMYwyVGnfuwsKRsgAAA9M"]
[Tue Jul 21 07:36:28.359509 2026] [security2:error] [pid 255769:tid 255919] [client 20.197.195.24:49208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9LrLxMYwyVGnfuwsKRtQAAA7c"]
[Tue Jul 21 07:36:28.514958 2026] [security2:error] [pid 254995:tid 255211] [client 117.251.86.144:34930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LrP7v0rlcEGmVraE3FwAAA3M"]
[Tue Jul 21 07:36:28.515071 2026] [security2:error] [pid 254995:tid 255211] [client 117.251.86.144:34930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LrP7v0rlcEGmVraE3FwAAA3M"]
[Tue Jul 21 07:36:28.590692 2026] [security2:error] [pid 254995:tid 255136] [client 103.162.129.114:52851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LrP7v0rlcEGmVraE3HAAAAyk"]
[Tue Jul 21 07:36:28.590828 2026] [security2:error] [pid 254995:tid 255136] [client 103.162.129.114:52851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LrP7v0rlcEGmVraE3HAAAAyk"]
[Tue Jul 21 07:36:28.602072 2026] [security2:error] [pid 255769:tid 255994] [client 173.24.185.52:53807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LrLxMYwyVGnfuwsKRugAABAE"]
[Tue Jul 21 07:36:28.602175 2026] [security2:error] [pid 255769:tid 255994] [client 173.24.185.52:53807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LrLxMYwyVGnfuwsKRugAABAE"]
[Tue Jul 21 07:36:28.827111 2026] [security2:error] [pid 254995:tid 255260] [client 20.104.96.117:59688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/mac.php"] [unique_id "al9LrP7v0rlcEGmVraE3HgAAA4o"]
[Tue Jul 21 07:36:28.910776 2026] [security2:error] [pid 255769:tid 255863] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LrLxMYwyVGnfuwsKRvQAD5F0"]
[Tue Jul 21 07:36:28.910915 2026] [security2:error] [pid 255769:tid 255964] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LrLxMYwyVGnfuwsKRvQAD5F0"]
[Tue Jul 21 07:36:29.059964 2026] [security2:error] [pid 255769:tid 255943] [client 109.248.148.246:37606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9LrbxMYwyVGnfuwsKRvgAAA88"]
[Tue Jul 21 07:36:29.060073 2026] [security2:error] [pid 255769:tid 255943] [client 109.248.148.246:37606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9LrbxMYwyVGnfuwsKRvgAAA88"]
[Tue Jul 21 07:36:29.065122 2026] [security2:error] [pid 255769:tid 255999] [client 20.197.195.24:62605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9LrbxMYwyVGnfuwsKRvwAABAU"]
[Tue Jul 21 07:36:29.190673 2026] [security2:error] [pid 254995:tid 255189] [client 117.217.38.194:65289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lrf7v0rlcEGmVraE3JAAAA14"]
[Tue Jul 21 07:36:29.191143 2026] [security2:error] [pid 254995:tid 255189] [client 117.217.38.194:65289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lrf7v0rlcEGmVraE3JAAAA14"]
[Tue Jul 21 07:36:29.228280 2026] [security2:error] [pid 255769:tid 255971] [client 122.186.204.214:54374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LrbxMYwyVGnfuwsKRxAAAA-s"]
[Tue Jul 21 07:36:29.228410 2026] [security2:error] [pid 255769:tid 255971] [client 122.186.204.214:54374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LrbxMYwyVGnfuwsKRxAAAA-s"]
[Tue Jul 21 07:36:29.509327 2026] [security2:error] [pid 255769:tid 255958] [client 20.206.105.145:38494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/images.php"] [unique_id "al9LrbxMYwyVGnfuwsKRzAAAA94"]
[Tue Jul 21 07:36:29.542427 2026] [security2:error] [pid 254995:tid 255171] [client 62.102.148.164:42992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Lrf7v0rlcEGmVraE3KAAAA0w"]
[Tue Jul 21 07:36:29.542501 2026] [security2:error] [pid 254995:tid 255171] [client 62.102.148.164:42992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Lrf7v0rlcEGmVraE3KAAAA0w"]
[Tue Jul 21 07:36:29.572303 2026] [security2:error] [pid 254995:tid 255165] [client 45.8.17.132:40047] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-links.php"] [unique_id "al9Lrf7v0rlcEGmVraE3KQAAA0Y"]
[Tue Jul 21 07:36:29.590483 2026] [security2:error] [pid 255769:tid 255946] [client 69.171.230.15:41182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LrbxMYwyVGnfuwsKRyAAAA9I"]
[Tue Jul 21 07:36:29.635550 2026] [security2:error] [pid 254995:tid 255218] [client 20.104.96.117:59678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/mg.php"] [unique_id "al9Lrf7v0rlcEGmVraE3LQAAA3o"]
[Tue Jul 21 07:36:29.923262 2026] [security2:error] [pid 254995:tid 255192] [client 20.197.195.24:62597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9Lrf7v0rlcEGmVraE3MAAAA2E"]
[Tue Jul 21 07:36:30.031173 2026] [security2:error] [pid 255769:tid 255973] [client 20.104.96.117:59681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-post-data.php"] [unique_id "al9LrrxMYwyVGnfuwsKRzgAAA-0"]
[Tue Jul 21 07:36:30.118282 2026] [security2:error] [pid 254995:tid 255041] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lrv7v0rlcEGmVraE3NAADiS0"]
[Tue Jul 21 07:36:30.118468 2026] [security2:error] [pid 254995:tid 255259] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lrv7v0rlcEGmVraE3NAADiS0"]
[Tue Jul 21 07:36:30.274753 2026] [security2:error] [pid 254995:tid 255178] [client 20.197.195.24:50366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/for.php"] [unique_id "al9Lrv7v0rlcEGmVraE3OQAAA1M"]
[Tue Jul 21 07:36:30.349984 2026] [security2:error] [pid 254995:tid 255269] [client 69.171.230.10:54460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Lrv7v0rlcEGmVraE3OgAAA5M"]
[Tue Jul 21 07:36:30.703657 2026] [security2:error] [pid 254995:tid 255143] [client 175.45.70.82:59761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lrv7v0rlcEGmVraE3QAAAAzA"]
[Tue Jul 21 07:36:30.703765 2026] [security2:error] [pid 254995:tid 255143] [client 175.45.70.82:59761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lrv7v0rlcEGmVraE3QAAAAzA"]
[Tue Jul 21 07:36:30.741946 2026] [security2:error] [pid 255769:tid 255915] [client 20.104.96.117:59183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/pucci.php"] [unique_id "al9LrrxMYwyVGnfuwsKR2wAAA7M"]
[Tue Jul 21 07:36:30.959464 2026] [security2:error] [pid 255769:tid 255984] [client 122.162.144.145:27302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LrrxMYwyVGnfuwsKR4gAAA_g"]
[Tue Jul 21 07:36:30.959601 2026] [security2:error] [pid 255769:tid 255984] [client 122.162.144.145:27302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LrrxMYwyVGnfuwsKR4gAAA_g"]
[Tue Jul 21 07:36:31.070379 2026] [ssl:error] [pid 255769:tid 255945] [client 185.226.197.34:21926] AH02032: Hostname www.gradiente.com.br provided via SNI and hostname gradiente.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.gradiente.com.br/
[Tue Jul 21 07:36:31.165622 2026] [security2:error] [pid 255769:tid 255998] [client 20.206.105.145:38481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/alls.php"] [unique_id "al9Lr7xMYwyVGnfuwsKR5wAABAQ"]
[Tue Jul 21 07:36:31.173720 2026] [security2:error] [pid 255769:tid 255954] [client 69.171.230.27:41044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Lr7xMYwyVGnfuwsKR6QAAA9o"]
[Tue Jul 21 07:36:31.270852 2026] [security2:error] [pid 255769:tid 256028] [client 20.104.96.117:59143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/black.php"] [unique_id "al9Lr7xMYwyVGnfuwsKR6wAABCI"]
[Tue Jul 21 07:36:31.340130 2026] [security2:error] [pid 255769:tid 255971] [client 20.197.195.24:62644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/raw.php"] [unique_id "al9Lr7xMYwyVGnfuwsKR7AAAA-s"]
[Tue Jul 21 07:36:31.474893 2026] [security2:error] [pid 255769:tid 255924] [client 45.8.17.115:24151] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "al9Lr7xMYwyVGnfuwsKR8AAAA7w"]
[Tue Jul 21 07:36:31.668407 2026] [security2:error] [pid 255769:tid 255929] [client 103.106.20.201:64602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lr7xMYwyVGnfuwsKR9AAAA8E"]
[Tue Jul 21 07:36:31.668540 2026] [security2:error] [pid 255769:tid 255929] [client 103.106.20.201:64602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lr7xMYwyVGnfuwsKR9AAAA8E"]
[Tue Jul 21 07:36:31.747803 2026] [security2:error] [pid 255769:tid 255939] [client 185.198.240.12:21195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dener.design"] [uri "/wp-login.php"] [unique_id "al9Lr7xMYwyVGnfuwsKR9gAAA8s"]
[Tue Jul 21 07:36:31.895880 2026] [security2:error] [pid 255769:tid 255903] [client 20.104.96.117:59175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/zlece.php"] [unique_id "al9Lr7xMYwyVGnfuwsKR-AAAA6c"]
[Tue Jul 21 07:36:31.928049 2026] [security2:error] [pid 255769:tid 255969] [client 20.206.105.145:38484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/yyu.php"] [unique_id "al9Lr7xMYwyVGnfuwsKR-gAAA-k"]
[Tue Jul 21 07:36:32.131259 2026] [security2:error] [pid 255769:tid 256025] [client 136.144.33.97:43775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LsLxMYwyVGnfuwsKR_AAABB8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:32.132377 2026] [security2:error] [pid 254995:tid 255199] [client 20.206.105.145:39016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/hypo.php"] [unique_id "al9LsP7v0rlcEGmVraE3TQAAA2g"]
[Tue Jul 21 07:36:32.433323 2026] [security2:error] [pid 254995:tid 255205] [client 20.104.96.117:59137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/vssrs.php"] [unique_id "al9LsP7v0rlcEGmVraE3UwAAA24"]
[Tue Jul 21 07:36:32.446952 2026] [security2:error] [pid 254995:tid 255266] [client 20.220.225.223:51495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/bscclapb.php"] [unique_id "al9LsP7v0rlcEGmVraE3VAAAA5A"]
[Tue Jul 21 07:36:32.471728 2026] [security2:error] [pid 254995:tid 255197] [client 45.8.17.115:52241] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "al9LsP7v0rlcEGmVraE3VgAAA2Y"]
[Tue Jul 21 07:36:32.568041 2026] [security2:error] [pid 255769:tid 255869] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LsLxMYwyVGnfuwsKSAgADtGM"]
[Tue Jul 21 07:36:32.568190 2026] [security2:error] [pid 255769:tid 255916] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LsLxMYwyVGnfuwsKSAgADtGM"]
[Tue Jul 21 07:36:32.781014 2026] [security2:error] [pid 255769:tid 256021] [client 20.206.105.145:37923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/by.php"] [unique_id "al9LsLxMYwyVGnfuwsKSBAAABBs"]
[Tue Jul 21 07:36:32.802234 2026] [security2:error] [pid 255769:tid 255968] [client 20.104.96.117:59182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wicked.php"] [unique_id "al9LsLxMYwyVGnfuwsKSBQAAA-g"]
[Tue Jul 21 07:36:33.138357 2026] [security2:error] [pid 255769:tid 255900] [client 20.104.96.117:59163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/24.php"] [unique_id "al9LsbxMYwyVGnfuwsKSCgAAA6Q"]
[Tue Jul 21 07:36:33.582215 2026] [security2:error] [pid 254995:tid 255158] [client 45.8.17.64:57235] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/new.php"] [unique_id "al9Lsf7v0rlcEGmVraE3ZgAAAz8"]
[Tue Jul 21 07:36:33.693716 2026] [rewrite:error] [pid 255769:tid 255924] [client 187.49.76.218:21057] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:36:33.694654 2026] [rewrite:error] [pid 255769:tid 255974] [client 187.49.76.218:21185] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:36:33.713295 2026] [rewrite:error] [pid 254995:tid 255206] [client 187.49.76.218:21313] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:36:33.733531 2026] [security2:error] [pid 255769:tid 255908] [client 20.104.96.117:59711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/xacs.php"] [unique_id "al9LsbxMYwyVGnfuwsKSDwAAA6w"]
[Tue Jul 21 07:36:33.817731 2026] [security2:error] [pid 255769:tid 255982] [client 103.174.34.15:56167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LsbxMYwyVGnfuwsKSEAAAA_Y"]
[Tue Jul 21 07:36:33.817857 2026] [security2:error] [pid 255769:tid 255982] [client 103.174.34.15:56167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LsbxMYwyVGnfuwsKSEAAAA_Y"]
[Tue Jul 21 07:36:33.989255 2026] [security2:error] [pid 254995:tid 255056] [remote 173.252.87.15:52220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9Lsf7v0rlcEGmVraE3agADRzw"]
[Tue Jul 21 07:36:34.338002 2026] [security2:error] [pid 255769:tid 255988] [client 82.102.28.107:50256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9LsrxMYwyVGnfuwsKSFgAAA_w"]
[Tue Jul 21 07:36:34.338119 2026] [security2:error] [pid 255769:tid 255988] [client 82.102.28.107:50256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9LsrxMYwyVGnfuwsKSFgAAA_w"]
[Tue Jul 21 07:36:34.396381 2026] [security2:error] [pid 254995:tid 255198] [client 20.220.225.223:31176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/echkm.php"] [unique_id "al9Lsv7v0rlcEGmVraE3cgAAA2c"]
[Tue Jul 21 07:36:34.413045 2026] [security2:error] [pid 255769:tid 256002] [client 20.104.96.117:59151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/zildan.php"] [unique_id "al9LsrxMYwyVGnfuwsKSGwAABAg"]
[Tue Jul 21 07:36:34.637471 2026] [security2:error] [pid 255769:tid 255885] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LsrxMYwyVGnfuwsKSHgAD6nM"]
[Tue Jul 21 07:36:34.637602 2026] [security2:error] [pid 255769:tid 255970] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LsrxMYwyVGnfuwsKSHgAD6nM"]
[Tue Jul 21 07:36:34.668735 2026] [security2:error] [pid 254995:tid 255008] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lsv7v0rlcEGmVraE3dgADOAw"]
[Tue Jul 21 07:36:34.668866 2026] [security2:error] [pid 254995:tid 255151] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lsv7v0rlcEGmVraE3dgADOAw"]
[Tue Jul 21 07:36:34.791242 2026] [security2:error] [pid 254995:tid 255071] [remote 18.61.192.253:54146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "limetteodontologia.com.br.draanacarlalima.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lsf7v0rlcEGmVraE3aAADJEs"]
[Tue Jul 21 07:36:34.791422 2026] [security2:error] [pid 254995:tid 255131] [client 18.61.192.253:54146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "limetteodontologia.com.br.draanacarlalima.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lsf7v0rlcEGmVraE3aAADJEs"]
[Tue Jul 21 07:36:34.950932 2026] [security2:error] [pid 255769:tid 256025] [client 20.104.96.117:61123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/csa.php"] [unique_id "al9LsrxMYwyVGnfuwsKSIQAABB8"]
[Tue Jul 21 07:36:34.975136 2026] [security2:error] [pid 255769:tid 255905] [client 45.8.17.121:34761] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "al9LsrxMYwyVGnfuwsKSIgAAA6k"]
[Tue Jul 21 07:36:35.222959 2026] [security2:error] [pid 255769:tid 255870] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Ls7xMYwyVGnfuwsKSJwADwmQ"]
[Tue Jul 21 07:36:35.223181 2026] [security2:error] [pid 255769:tid 255930] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Ls7xMYwyVGnfuwsKSJwADwmQ"]
[Tue Jul 21 07:36:35.258164 2026] [security2:error] [pid 255769:tid 255791] [remote 216.73.216.238:65438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/chales.php"] [unique_id "al9Ls7xMYwyVGnfuwsKSKQADsxU"]
[Tue Jul 21 07:36:35.362977 2026] [security2:error] [pid 254995:tid 255178] [client 20.104.96.117:59675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/w3llscc.php"] [unique_id "al9Ls_7v0rlcEGmVraE3fgAAA1M"]
[Tue Jul 21 07:36:35.759521 2026] [security2:error] [pid 255769:tid 255959] [client 59.96.220.140:56441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Ls7xMYwyVGnfuwsKSNAAAA98"]
[Tue Jul 21 07:36:35.760037 2026] [security2:error] [pid 255769:tid 255959] [client 59.96.220.140:56441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Ls7xMYwyVGnfuwsKSNAAAA98"]
[Tue Jul 21 07:36:36.049991 2026] [proxy:error] [pid 254995:tid 255258] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:36.050078 2026] [proxy_http:error] [pid 254995:tid 255258] [client 20.206.105.145:39250] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:36.050517 2026] [proxy:error] [pid 254995:tid 255258] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:36.050544 2026] [proxy_http:error] [pid 254995:tid 255258] [client 20.206.105.145:39250] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:36.334275 2026] [security2:error] [pid 255769:tid 255972] [client 74.7.175.154:54930] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "getecma.com"] [uri "/cgi-sys/404.html"] [unique_id "al9LtLxMYwyVGnfuwsKSOgAD7BQ"]
[Tue Jul 21 07:36:36.337759 2026] [security2:error] [pid 255769:tid 256026] [client 20.104.96.117:59197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wpx.php"] [unique_id "al9LtLxMYwyVGnfuwsKSOwAABCA"]
[Tue Jul 21 07:36:36.819850 2026] [security2:error] [pid 255769:tid 255927] [client 193.36.225.57:38253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LtLxMYwyVGnfuwsKSPQAAA78"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:36.972001 2026] [security2:error] [pid 255769:tid 256024] [client 45.8.17.126:46809] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-links-opml.php"] [unique_id "al9LtLxMYwyVGnfuwsKSQAAABB4"]
[Tue Jul 21 07:36:37.101423 2026] [security2:error] [pid 255769:tid 256025] [client 20.104.96.117:61150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-css.php"] [unique_id "al9LtbxMYwyVGnfuwsKSQgAABB8"]
[Tue Jul 21 07:36:37.143797 2026] [proxy:error] [pid 254995:tid 255147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:37.143883 2026] [proxy_http:error] [pid 254995:tid 255147] [client 185.93.89.147:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:37.144449 2026] [proxy:error] [pid 254995:tid 255147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:37.144474 2026] [proxy_http:error] [pid 254995:tid 255147] [client 185.93.89.147:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:37.516076 2026] [security2:error] [pid 254995:tid 255196] [client 103.86.117.203:51441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ltf7v0rlcEGmVraE3mQAAA2U"]
[Tue Jul 21 07:36:37.516276 2026] [security2:error] [pid 254995:tid 255196] [client 103.86.117.203:51441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ltf7v0rlcEGmVraE3mQAAA2U"]
[Tue Jul 21 07:36:37.533127 2026] [security2:error] [pid 254995:tid 255214] [client 20.206.105.145:37898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/FAQ.php"] [unique_id "al9Ltf7v0rlcEGmVraE3ngAAA3Y"]
[Tue Jul 21 07:36:37.678158 2026] [security2:error] [pid 255769:tid 255967] [client 20.220.225.223:48138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/else1.php"] [unique_id "al9LtbxMYwyVGnfuwsKSRgAAA-c"]
[Tue Jul 21 07:36:37.691113 2026] [core:error] [pid 255769:tid 255798] [remote 52.167.144.232:10688] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:36:37.691133 2026] [core:error] [pid 255769:tid 255798] [remote 52.167.144.232:10688] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:36:37.765229 2026] [autoindex:error] [pid 254995:tid 255058] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:37.824585 2026] [security2:error] [pid 255769:tid 255900] [client 20.206.105.145:37897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/coffexium.php"] [unique_id "al9LtbxMYwyVGnfuwsKSSgAAA6Q"]
[Tue Jul 21 07:36:37.860594 2026] [security2:error] [pid 255769:tid 255944] [client 20.104.96.117:59648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/ho.php"] [unique_id "al9LtbxMYwyVGnfuwsKSSwAAA9A"]
[Tue Jul 21 07:36:37.875697 2026] [security2:error] [pid 254995:tid 255132] [client 20.206.105.145:37895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/red.php"] [unique_id "al9Ltf7v0rlcEGmVraE3pwAAAyU"]
[Tue Jul 21 07:36:37.972375 2026] [autoindex:error] [pid 254995:tid 255169] [client 20.206.105.145:37896] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:36:37.981288 2026] [security2:error] [pid 254995:tid 255172] [client 20.206.105.145:37896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9Ltf7v0rlcEGmVraE3qgAAA00"]
[Tue Jul 21 07:36:37.982944 2026] [security2:error] [pid 255769:tid 255932] [client 139.167.225.182:60393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LtbxMYwyVGnfuwsKSTgAAA8Q"]
[Tue Jul 21 07:36:37.984696 2026] [security2:error] [pid 255769:tid 255932] [client 139.167.225.182:60393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LtbxMYwyVGnfuwsKSTgAAA8Q"]
[Tue Jul 21 07:36:38.162836 2026] [security2:error] [pid 255769:tid 255984] [client 45.251.232.145:62675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LtrxMYwyVGnfuwsKSUgAAA_g"]
[Tue Jul 21 07:36:38.162985 2026] [security2:error] [pid 255769:tid 255984] [client 45.251.232.145:62675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LtrxMYwyVGnfuwsKSUgAAA_g"]
[Tue Jul 21 07:36:38.165122 2026] [autoindex:error] [pid 254995:tid 255100] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:38.250149 2026] [security2:error] [pid 254995:tid 255181] [client 20.206.105.145:39246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/chosen.php"] [unique_id "al9Ltv7v0rlcEGmVraE3tAAAA1Y"]
[Tue Jul 21 07:36:38.252763 2026] [core:error] [pid 255769:tid 255831] [remote 52.167.144.232:10688] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:36:38.252780 2026] [core:error] [pid 255769:tid 255831] [remote 52.167.144.232:10688] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:36:38.277229 2026] [security2:error] [pid 255769:tid 255908] [client 45.8.17.138:63609] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/revslider/includes/external/page/index.php"] [unique_id "al9LtrxMYwyVGnfuwsKSVAAAA6w"]
[Tue Jul 21 07:36:38.358153 2026] [security2:error] [pid 254995:tid 255151] [client 20.104.96.117:59691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/xy.php"] [unique_id "al9Ltv7v0rlcEGmVraE3tgAAAzg"]
[Tue Jul 21 07:36:38.383454 2026] [autoindex:error] [pid 255769:tid 255919] [client 20.206.105.145:37903] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:36:38.574643 2026] [security2:error] [pid 255769:tid 256013] [client 20.206.105.145:37903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/footer.php"] [unique_id "al9LtrxMYwyVGnfuwsKSWQAABBM"]
[Tue Jul 21 07:36:38.692819 2026] [security2:error] [pid 254995:tid 255182] [client 20.220.225.223:38702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/mac.php"] [unique_id "al9Ltv7v0rlcEGmVraE3uwAAA1c"]
[Tue Jul 21 07:36:38.764572 2026] [security2:error] [pid 255769:tid 255851] [remote 195.26.244.42:57354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pousadanaturalis.com.br"] [uri "/wp-login.php"] [unique_id "al9LtrxMYwyVGnfuwsKSXgAD2VE"]
[Tue Jul 21 07:36:38.776554 2026] [security2:error] [pid 255769:tid 256026] [client 20.52.136.55:1738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/buy.php"] [unique_id "al9LtrxMYwyVGnfuwsKSXwAABCA"]
[Tue Jul 21 07:36:39.018162 2026] [autoindex:error] [pid 254995:tid 255084] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:39.155128 2026] [security2:error] [pid 254995:tid 255131] [client 117.251.86.144:43814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Lt_7v0rlcEGmVraE3xQAAAyQ"]
[Tue Jul 21 07:36:39.155293 2026] [security2:error] [pid 254995:tid 255131] [client 117.251.86.144:43814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Lt_7v0rlcEGmVraE3xQAAAyQ"]
[Tue Jul 21 07:36:39.265585 2026] [security2:error] [pid 254995:tid 255134] [client 20.104.96.117:59167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/loader.php"] [unique_id "al9Lt_7v0rlcEGmVraE3ygAAAyc"]
[Tue Jul 21 07:36:39.305254 2026] [security2:error] [pid 255769:tid 255969] [client 103.162.129.114:53296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Lt7xMYwyVGnfuwsKSYQAAA-k"]
[Tue Jul 21 07:36:39.305381 2026] [security2:error] [pid 255769:tid 255969] [client 103.162.129.114:53296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Lt7xMYwyVGnfuwsKSYQAAA-k"]
[Tue Jul 21 07:36:39.311656 2026] [security2:error] [pid 254995:tid 255150] [client 152.59.154.239:55756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lt_7v0rlcEGmVraE3zQAAAzc"]
[Tue Jul 21 07:36:39.311763 2026] [security2:error] [pid 254995:tid 255150] [client 152.59.154.239:55756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lt_7v0rlcEGmVraE3zQAAAzc"]
[Tue Jul 21 07:36:39.333463 2026] [autoindex:error] [pid 254995:tid 255004] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:39.386723 2026] [security2:error] [pid 254995:tid 255137] [client 45.8.17.64:33633] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/222.php"] [unique_id "al9Lt_7v0rlcEGmVraE30AAAAyo"]
[Tue Jul 21 07:36:39.493516 2026] [autoindex:error] [pid 255769:tid 255961] [client 20.206.105.145:38471] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:36:39.508236 2026] [security2:error] [pid 255769:tid 255966] [client 20.206.105.145:38471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-content/index.php"] [unique_id "al9Lt7xMYwyVGnfuwsKSYwAAA-Y"]
[Tue Jul 21 07:36:39.521867 2026] [security2:error] [pid 255769:tid 255947] [client 20.220.225.223:24268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/hunter.php"] [unique_id "al9Lt7xMYwyVGnfuwsKSZAAAA9M"]
[Tue Jul 21 07:36:39.594258 2026] [security2:error] [pid 254995:tid 255209] [client 173.24.185.52:54286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Lt_7v0rlcEGmVraE30QAAA3E"]
[Tue Jul 21 07:36:39.594356 2026] [security2:error] [pid 254995:tid 255209] [client 173.24.185.52:54286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Lt_7v0rlcEGmVraE30QAAA3E"]
[Tue Jul 21 07:36:39.663600 2026] [security2:error] [pid 254995:tid 255046] [remote 209.97.182.179:43996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.182.97.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "monicamirandapereira1751478737000.bellarthconsultoria.com.br"] [uri "/wp-login.php"] [unique_id "al9Lt_7v0rlcEGmVraE31AADkDI"]
[Tue Jul 21 07:36:39.702323 2026] [security2:error] [pid 254995:tid 255254] [client 117.217.38.194:49376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lt_7v0rlcEGmVraE31gAAA4Q"]
[Tue Jul 21 07:36:39.702498 2026] [security2:error] [pid 254995:tid 255254] [client 117.217.38.194:49376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lt_7v0rlcEGmVraE31gAAA4Q"]
[Tue Jul 21 07:36:39.710207 2026] [security2:error] [pid 255769:tid 255845] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lt7xMYwyVGnfuwsKSaQAECUs"]
[Tue Jul 21 07:36:39.710407 2026] [security2:error] [pid 255769:tid 256003] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lt7xMYwyVGnfuwsKSaQAECUs"]
[Tue Jul 21 07:36:39.792783 2026] [security2:error] [pid 254995:tid 255143] [client 122.186.204.214:54895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lt_7v0rlcEGmVraE32QAAAzA"]
[Tue Jul 21 07:36:39.792914 2026] [security2:error] [pid 254995:tid 255143] [client 122.186.204.214:54895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lt_7v0rlcEGmVraE32QAAAzA"]
[Tue Jul 21 07:36:39.821757 2026] [autoindex:error] [pid 254995:tid 255002] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:40.159883 2026] [security2:error] [pid 255769:tid 256000] [client 45.33.12.214:40856] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "162.241.63.68"] [uri "/index.cgi"] [unique_id "al9LuLxMYwyVGnfuwsKSdQAABAY"]
[Tue Jul 21 07:36:40.253191 2026] [autoindex:error] [pid 254995:tid 255007] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/rest-api/endpoints/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:40.481262 2026] [security2:error] [pid 255769:tid 255946] [client 45.8.17.107:47671] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/about/function.php"] [unique_id "al9LuLxMYwyVGnfuwsKSgQAAA9I"]
[Tue Jul 21 07:36:40.591718 2026] [security2:error] [pid 255769:tid 256026] [client 82.102.28.107:53162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9LuLxMYwyVGnfuwsKSgwAABCA"]
[Tue Jul 21 07:36:40.591828 2026] [security2:error] [pid 255769:tid 256026] [client 82.102.28.107:53162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9LuLxMYwyVGnfuwsKSgwAABCA"]
[Tue Jul 21 07:36:40.671076 2026] [proxy:error] [pid 254995:tid 255189] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:40.671152 2026] [proxy_http:error] [pid 254995:tid 255189] [client 20.206.105.145:39240] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:40.671715 2026] [proxy:error] [pid 254995:tid 255189] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:40.671745 2026] [proxy_http:error] [pid 254995:tid 255189] [client 20.206.105.145:39240] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:40.691005 2026] [security2:error] [pid 255769:tid 255918] [client 20.206.105.145:38486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/zoro.php"] [unique_id "al9LuLxMYwyVGnfuwsKShQAAA7Y"]
[Tue Jul 21 07:36:40.726425 2026] [security2:error] [pid 255769:tid 255926] [client 20.104.96.117:59193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/spadex.php"] [unique_id "al9LuLxMYwyVGnfuwsKShgAAA74"]
[Tue Jul 21 07:36:40.921430 2026] [security2:error] [pid 255769:tid 255858] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LuLxMYwyVGnfuwsKSiwAEFVg"]
[Tue Jul 21 07:36:40.921618 2026] [security2:error] [pid 255769:tid 256015] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LuLxMYwyVGnfuwsKSiwAEFVg"]
[Tue Jul 21 07:36:41.092615 2026] [security2:error] [pid 254995:tid 255204] [client 82.102.28.107:53170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Luf7v0rlcEGmVraE37QAAA20"]
[Tue Jul 21 07:36:41.092714 2026] [security2:error] [pid 254995:tid 255204] [client 82.102.28.107:53170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Luf7v0rlcEGmVraE37QAAA20"]
[Tue Jul 21 07:36:41.138729 2026] [security2:error] [pid 254995:tid 255256] [client 136.144.33.99:60847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Luf7v0rlcEGmVraE37gAAA4Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:41.292845 2026] [security2:error] [pid 255769:tid 255907] [client 20.104.96.117:59161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/2x.php"] [unique_id "al9LubxMYwyVGnfuwsKSjgAAA6s"]
[Tue Jul 21 07:36:41.295849 2026] [security2:error] [pid 255769:tid 255911] [client 62.102.148.164:40504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LubxMYwyVGnfuwsKSjwAAA68"]
[Tue Jul 21 07:36:41.295948 2026] [security2:error] [pid 255769:tid 255911] [client 62.102.148.164:40504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LubxMYwyVGnfuwsKSjwAAA68"]
[Tue Jul 21 07:36:41.357942 2026] [security2:error] [pid 255769:tid 255965] [client 109.248.148.246:53848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9LubxMYwyVGnfuwsKSkAAAA-U"]
[Tue Jul 21 07:36:41.358054 2026] [security2:error] [pid 255769:tid 255965] [client 109.248.148.246:53848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9LubxMYwyVGnfuwsKSkAAAA-U"]
[Tue Jul 21 07:36:41.373200 2026] [autoindex:error] [pid 254995:tid 255068] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:41.521740 2026] [security2:error] [pid 254995:tid 255122] [remote 141.98.11.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.11.98.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9Luf7v0rlcEGmVraE38wADVn4"], referer: https://www.binance.com
[Tue Jul 21 07:36:41.682665 2026] [security2:error] [pid 254995:tid 255149] [client 45.8.17.147:53455] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/maint/about.php"] [unique_id "al9Luf7v0rlcEGmVraE3-QAAAzY"]
[Tue Jul 21 07:36:41.705858 2026] [security2:error] [pid 254995:tid 255166] [client 175.45.70.82:60320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Luf7v0rlcEGmVraE3-wAAA0c"]
[Tue Jul 21 07:36:41.705978 2026] [security2:error] [pid 254995:tid 255166] [client 175.45.70.82:60320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Luf7v0rlcEGmVraE3-wAAA0c"]
[Tue Jul 21 07:36:41.743742 2026] [security2:error] [pid 255769:tid 256025] [client 122.162.144.145:28727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LubxMYwyVGnfuwsKSlQAABB8"]
[Tue Jul 21 07:36:41.743849 2026] [security2:error] [pid 255769:tid 256025] [client 122.162.144.145:28727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LubxMYwyVGnfuwsKSlQAABB8"]
[Tue Jul 21 07:36:41.896764 2026] [security2:error] [pid 254995:tid 255190] [client 20.220.225.223:38695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Luf7v0rlcEGmVraE4AwAAA18"]
[Tue Jul 21 07:36:41.910124 2026] [security2:error] [pid 254995:tid 255216] [client 213.152.162.104:49134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Luf7v0rlcEGmVraE4BQAAA3g"]
[Tue Jul 21 07:36:41.910211 2026] [security2:error] [pid 254995:tid 255216] [client 213.152.162.104:49134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Luf7v0rlcEGmVraE4BQAAA3g"]
[Tue Jul 21 07:36:42.098829 2026] [autoindex:error] [pid 254995:tid 255154] [client 104.236.113.248:60359] AH01276: Cannot serve directory /home2/tamoio74/engeconconstrucoes.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:36:42.156332 2026] [security2:error] [pid 255769:tid 256017] [client 20.104.96.117:59191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/ctex1.php"] [unique_id "al9LurxMYwyVGnfuwsKSlwAABBc"]
[Tue Jul 21 07:36:42.174724 2026] [security2:error] [pid 254995:tid 255222] [client 136.144.33.25:33307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Luv7v0rlcEGmVraE4CwAAA34"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:36:42.212921 2026] [security2:error] [pid 255769:tid 255974] [client 20.206.105.145:37904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/admin.php"] [unique_id "al9LurxMYwyVGnfuwsKSmAAAA-4"]
[Tue Jul 21 07:36:42.271893 2026] [core:error] [pid 254995:tid 255091] [remote 52.167.144.191:38405] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:36:42.271917 2026] [core:error] [pid 254995:tid 255091] [remote 52.167.144.191:38405] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:36:42.325731 2026] [autoindex:error] [pid 254995:tid 255019] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/Text/Diff/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:42.331666 2026] [autoindex:error] [pid 254995:tid 255180] [client 104.236.113.248:60359] AH01276: Cannot serve directory /home2/tamoio74/engeconconstrucoes.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:36:42.356231 2026] [security2:error] [pid 254995:tid 255202] [client 20.220.225.223:24225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/we.php"] [unique_id "al9Luv7v0rlcEGmVraE4FAAAA2s"]
[Tue Jul 21 07:36:42.381199 2026] [security2:error] [pid 254995:tid 255147] [client 20.206.105.145:39257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/als.php"] [unique_id "al9Luv7v0rlcEGmVraE4FgAAAzQ"]
[Tue Jul 21 07:36:42.411031 2026] [security2:error] [pid 254995:tid 255186] [client 103.106.20.201:65209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Luv7v0rlcEGmVraE4FwAAA1s"]
[Tue Jul 21 07:36:42.411189 2026] [security2:error] [pid 254995:tid 255186] [client 103.106.20.201:65209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Luv7v0rlcEGmVraE4FwAAA1s"]
[Tue Jul 21 07:36:42.445262 2026] [security2:error] [pid 254995:tid 255136] [client 104.236.113.248:60359] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9Luv7v0rlcEGmVraE4HAAAAyk"]
[Tue Jul 21 07:36:42.475790 2026] [security2:error] [pid 254995:tid 255212] [client 213.152.162.104:49144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Luv7v0rlcEGmVraE4HQAAA3Q"]
[Tue Jul 21 07:36:42.475938 2026] [security2:error] [pid 254995:tid 255212] [client 213.152.162.104:49144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Luv7v0rlcEGmVraE4HQAAA3Q"]
[Tue Jul 21 07:36:42.697972 2026] [security2:error] [pid 254995:tid 255275] [client 104.236.113.248:61361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.113.236.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Luv7v0rlcEGmVraE4HwAAA5k"]
[Tue Jul 21 07:36:42.947855 2026] [autoindex:error] [pid 255769:tid 255981] [client 104.236.113.248:61953] AH01276: Cannot serve directory /home2/tamoio74/engeconconstrucoes.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:36:43.063820 2026] [security2:error] [pid 254995:tid 255035] [remote 68.178.160.25:55540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agrocibus.com.br"] [uri "/wp-login.php"] [unique_id "al9Lu_7v0rlcEGmVraE4JwADOSc"]
[Tue Jul 21 07:36:43.103299 2026] [security2:error] [pid 254995:tid 255003] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lu_7v0rlcEGmVraE4KAADewc"]
[Tue Jul 21 07:36:43.103412 2026] [security2:error] [pid 254995:tid 255219] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lu_7v0rlcEGmVraE4KAADewc"]
[Tue Jul 21 07:36:43.149586 2026] [security2:error] [pid 254995:tid 255187] [client 20.104.96.117:59168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/edorxrr.php"] [unique_id "al9Lu_7v0rlcEGmVraE4KQAAA1w"]
[Tue Jul 21 07:36:43.153668 2026] [security2:error] [pid 255769:tid 255909] [client 20.220.225.223:38658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/samll.php"] [unique_id "al9Lu7xMYwyVGnfuwsKSogAAA60"]
[Tue Jul 21 07:36:43.173612 2026] [security2:error] [pid 255769:tid 255988] [client 104.236.113.248:61953] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9Lu7xMYwyVGnfuwsKSowAAA_w"]
[Tue Jul 21 07:36:43.225905 2026] [security2:error] [pid 254995:tid 255192] [client 20.226.60.151:27569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Lu_7v0rlcEGmVraE4KwAAA2E"]
[Tue Jul 21 07:36:43.281325 2026] [security2:error] [pid 255769:tid 255903] [client 45.8.17.61:42335] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/upload/upload.php"] [unique_id "al9Lu7xMYwyVGnfuwsKSpAAAA6c"]
[Tue Jul 21 07:36:43.407997 2026] [security2:error] [pid 255769:tid 255972] [client 104.236.113.248:62819] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9Lu7xMYwyVGnfuwsKSpwAAA-w"]
[Tue Jul 21 07:36:43.643421 2026] [security2:error] [pid 255769:tid 255980] [client 104.236.113.248:63300] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9Lu7xMYwyVGnfuwsKSqgAAA_Q"]
[Tue Jul 21 07:36:43.709970 2026] [security2:error] [pid 255769:tid 255966] [client 20.206.105.145:38502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/greap.php"] [unique_id "al9Lu7xMYwyVGnfuwsKSrAAAA-Y"]
[Tue Jul 21 07:36:43.723517 2026] [security2:error] [pid 255769:tid 255841] [remote 51.79.215.219:56910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.215.79.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthsmart.shop"] [uri "/wp-login.php"] [unique_id "al9Lu7xMYwyVGnfuwsKSrgAD80c"]
[Tue Jul 21 07:36:43.876675 2026] [security2:error] [pid 255769:tid 255978] [client 104.236.113.248:63819] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9Lu7xMYwyVGnfuwsKSsQAAA_I"]
[Tue Jul 21 07:36:43.952583 2026] [security2:error] [pid 255769:tid 256021] [client 20.206.105.145:38969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/pol.php"] [unique_id "al9Lu7xMYwyVGnfuwsKStAAABBs"]
[Tue Jul 21 07:36:44.030595 2026] [security2:error] [pid 254995:tid 255165] [client 122.164.127.47:52373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LvP7v0rlcEGmVraE4OAAAA0Y"]
[Tue Jul 21 07:36:44.030714 2026] [security2:error] [pid 254995:tid 255165] [client 122.164.127.47:52373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LvP7v0rlcEGmVraE4OAAAA0Y"]
[Tue Jul 21 07:36:44.113042 2026] [security2:error] [pid 254995:tid 255258] [client 104.236.113.248:64374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9LvP7v0rlcEGmVraE4PAAAA4g"]
[Tue Jul 21 07:36:44.127643 2026] [security2:error] [pid 254995:tid 255193] [client 47.128.40.173:39874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "applarifo.com.br"] [uri "/robots.txt"] [unique_id "al9LvP7v0rlcEGmVraE4PgAAA2I"]
[Tue Jul 21 07:36:44.188707 2026] [security2:error] [pid 254995:tid 255173] [client 45.8.17.140:49351] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wpc.php"] [unique_id "al9LvP7v0rlcEGmVraE4PwAAA04"]
[Tue Jul 21 07:36:44.345388 2026] [security2:error] [pid 254995:tid 255263] [client 20.220.225.223:24228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/phpinfo.php1"] [unique_id "al9LvP7v0rlcEGmVraE4VwAAA40"]
[Tue Jul 21 07:36:44.346354 2026] [security2:error] [pid 254995:tid 255262] [client 104.236.113.248:64933] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9LvP7v0rlcEGmVraE4WAAAA4w"]
[Tue Jul 21 07:36:44.377054 2026] [security2:error] [pid 254995:tid 255146] [client 20.104.96.117:61130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/miru1.php"] [unique_id "al9LvP7v0rlcEGmVraE4WQAAAzM"]
[Tue Jul 21 07:36:44.424512 2026] [security2:error] [pid 254995:tid 255137] [client 20.220.225.223:38684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/abcd.php"] [unique_id "al9LvP7v0rlcEGmVraE4cAAAAyo"]
[Tue Jul 21 07:36:44.471333 2026] [security2:error] [pid 254995:tid 255224] [client 20.197.195.24:13295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9LvP7v0rlcEGmVraE4cQAAA4A"]
[Tue Jul 21 07:36:44.492550 2026] [security2:error] [pid 254995:tid 255190] [client 103.174.34.15:56649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LvP7v0rlcEGmVraE4cgAAA18"]
[Tue Jul 21 07:36:44.492974 2026] [security2:error] [pid 254995:tid 255190] [client 103.174.34.15:56649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LvP7v0rlcEGmVraE4cgAAA18"]
[Tue Jul 21 07:36:44.613075 2026] [security2:error] [pid 254995:tid 255141] [client 104.236.113.248:49259] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9LvP7v0rlcEGmVraE4dwAAAy4"]
[Tue Jul 21 07:36:44.710520 2026] [security2:error] [pid 255769:tid 255860] [remote 8.217.108.67:31338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9LvLxMYwyVGnfuwsKSwQADwFo"]
[Tue Jul 21 07:36:44.830065 2026] [security2:error] [pid 254995:tid 255260] [client 20.220.225.223:38671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/xyn.php"] [unique_id "al9LvP7v0rlcEGmVraE4fwAAA4o"]
[Tue Jul 21 07:36:44.845990 2026] [security2:error] [pid 255769:tid 255960] [client 104.236.113.248:49873] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9LvLxMYwyVGnfuwsKSxQAAA-A"]
[Tue Jul 21 07:36:44.949126 2026] [security2:error] [pid 255769:tid 256009] [client 20.206.105.145:38995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file5.php"] [unique_id "al9LvLxMYwyVGnfuwsKSxgAABA8"]
[Tue Jul 21 07:36:44.973805 2026] [security2:error] [pid 255769:tid 255944] [client 74.7.175.138:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.luminabeauty.com.br"] [uri "/index.php"] [unique_id "al9LurxMYwyVGnfuwsKSngAD0Cs"]
[Tue Jul 21 07:36:44.987585 2026] [security2:error] [pid 254995:tid 255127] [client 20.197.195.24:13209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9LvP7v0rlcEGmVraE4gAAAAyA"]
[Tue Jul 21 07:36:44.994589 2026] [security2:error] [pid 254995:tid 255142] [client 20.226.60.151:27561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9LvP7v0rlcEGmVraE4gQAAAy8"]
[Tue Jul 21 07:36:45.017086 2026] [security2:error] [pid 254995:tid 255197] [client 20.206.105.145:38917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Lvf7v0rlcEGmVraE4gwAAA2Y"]
[Tue Jul 21 07:36:45.056782 2026] [security2:error] [pid 254995:tid 255090] [remote 141.98.11.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.11.98.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9Lvf7v0rlcEGmVraE4hAADcl4"], referer: https://www.binance.com
[Tue Jul 21 07:36:45.080642 2026] [security2:error] [pid 254995:tid 255189] [client 104.236.113.248:50549] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Lvf7v0rlcEGmVraE4hQAAA14"]
[Tue Jul 21 07:36:45.083892 2026] [security2:error] [pid 255769:tid 255903] [client 20.206.105.145:39263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file.php"] [unique_id "al9LvbxMYwyVGnfuwsKSyAAAA6c"]
[Tue Jul 21 07:36:45.177540 2026] [security2:error] [pid 255769:tid 255811] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LvbxMYwyVGnfuwsKSzgAD3ik"]
[Tue Jul 21 07:36:45.177689 2026] [security2:error] [pid 255769:tid 255958] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LvbxMYwyVGnfuwsKSzgAD3ik"]
[Tue Jul 21 07:36:45.316363 2026] [security2:error] [pid 254995:tid 255169] [client 104.236.113.248:51156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Lvf7v0rlcEGmVraE4igAAA0o"]
[Tue Jul 21 07:36:45.317091 2026] [security2:error] [pid 255769:tid 256026] [client 20.206.105.145:39270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/cfile.php"] [unique_id "al9LvbxMYwyVGnfuwsKSzwAABCA"]
[Tue Jul 21 07:36:45.462915 2026] [security2:error] [pid 255769:tid 255976] [client 20.206.105.145:39162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/class-wp.php"] [unique_id "al9LvbxMYwyVGnfuwsKS0gAAA_A"]
[Tue Jul 21 07:36:45.493889 2026] [security2:error] [pid 254995:tid 255099] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lvf7v0rlcEGmVraE4jgADP2c"]
[Tue Jul 21 07:36:45.494069 2026] [security2:error] [pid 254995:tid 255158] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lvf7v0rlcEGmVraE4jgADP2c"]
[Tue Jul 21 07:36:45.548717 2026] [security2:error] [pid 254995:tid 255181] [client 104.236.113.248:51676] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Lvf7v0rlcEGmVraE4kAAAA1Y"]
[Tue Jul 21 07:36:45.665191 2026] [security2:error] [pid 254995:tid 255276] [client 20.206.105.145:39011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/admin.php"] [unique_id "al9Lvf7v0rlcEGmVraE4lAAAA5o"]
[Tue Jul 21 07:36:45.675738 2026] [security2:error] [pid 254995:tid 255149] [client 45.8.17.58:22767] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "al9Lvf7v0rlcEGmVraE4lQAAAzY"]
[Tue Jul 21 07:36:45.687355 2026] [autoindex:error] [pid 254995:tid 255081] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:45.718233 2026] [security2:error] [pid 254995:tid 255267] [client 20.206.105.145:37912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/177.php"] [unique_id "al9Lvf7v0rlcEGmVraE4lwAAA5E"]
[Tue Jul 21 07:36:45.783332 2026] [security2:error] [pid 255769:tid 256003] [client 104.236.113.248:52200] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9LvbxMYwyVGnfuwsKS1gAABAk"]
[Tue Jul 21 07:36:45.783719 2026] [security2:error] [pid 254995:tid 255269] [client 20.104.96.117:61129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/sump1.php"] [unique_id "al9Lvf7v0rlcEGmVraE4mQAAA5M"]
[Tue Jul 21 07:36:45.815277 2026] [security2:error] [pid 254995:tid 255279] [client 20.206.105.145:39292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/aa2.php"] [unique_id "al9Lvf7v0rlcEGmVraE4mgAAA50"]
[Tue Jul 21 07:36:45.827121 2026] [security2:error] [pid 255769:tid 255773] [remote 81.173.115.7:58786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "link.aede.com.br"] [uri "/wp-login.php"] [unique_id "al9LvbxMYwyVGnfuwsKS1wAD8wM"]
[Tue Jul 21 07:36:45.849783 2026] [autoindex:error] [pid 254995:tid 255046] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:45.852946 2026] [security2:error] [pid 254995:tid 255194] [client 20.197.195.24:13194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/media.php"] [unique_id "al9Lvf7v0rlcEGmVraE4nAAAA2M"]
[Tue Jul 21 07:36:45.939329 2026] [security2:error] [pid 254995:tid 255093] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lvf7v0rlcEGmVraE4nwADd2E"]
[Tue Jul 21 07:36:45.939420 2026] [security2:error] [pid 254995:tid 255215] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lvf7v0rlcEGmVraE4nwADd2E"]
[Tue Jul 21 07:36:45.954564 2026] [security2:error] [pid 255769:tid 255920] [client 136.144.33.100:24443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LvbxMYwyVGnfuwsKS2QAAA7g"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:46.017807 2026] [security2:error] [pid 254995:tid 255145] [client 104.236.113.248:52629] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9Lvv7v0rlcEGmVraE4owAAAzI"]
[Tue Jul 21 07:36:46.089551 2026] [security2:error] [pid 254995:tid 255178] [client 20.206.105.145:39109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ccou.php"] [unique_id "al9Lvv7v0rlcEGmVraE4pgAAA1M"]
[Tue Jul 21 07:36:46.140741 2026] [security2:error] [pid 255769:tid 255954] [client 20.226.60.151:27603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/media.php"] [unique_id "al9LvrxMYwyVGnfuwsKS3AAAA9o"]
[Tue Jul 21 07:36:46.252666 2026] [security2:error] [pid 255769:tid 255900] [client 104.236.113.248:53094] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9LvrxMYwyVGnfuwsKS3gAAA6Q"]
[Tue Jul 21 07:36:46.431180 2026] [security2:error] [pid 255769:tid 256025] [client 20.206.105.145:37949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/199.php"] [unique_id "al9LvrxMYwyVGnfuwsKS4AAABB8"]
[Tue Jul 21 07:36:46.476697 2026] [security2:error] [pid 255769:tid 255977] [client 20.197.195.24:13297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/images.php"] [unique_id "al9LvrxMYwyVGnfuwsKS5AAAA_E"]
[Tue Jul 21 07:36:46.479698 2026] [security2:error] [pid 255769:tid 255934] [client 59.96.220.140:56948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LvrxMYwyVGnfuwsKS5QAAA8Y"]
[Tue Jul 21 07:36:46.480282 2026] [security2:error] [pid 255769:tid 255934] [client 59.96.220.140:56948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LvrxMYwyVGnfuwsKS5QAAA8Y"]
[Tue Jul 21 07:36:46.488906 2026] [security2:error] [pid 255769:tid 255932] [client 104.236.113.248:53656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9LvrxMYwyVGnfuwsKS5gAAA8Q"]
[Tue Jul 21 07:36:46.689359 2026] [security2:error] [pid 255769:tid 255908] [client 20.206.105.145:38960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/dr.php"] [unique_id "al9LvrxMYwyVGnfuwsKS6QAAA6w"]
[Tue Jul 21 07:36:46.721128 2026] [security2:error] [pid 255769:tid 255960] [client 104.236.113.248:54134] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9LvrxMYwyVGnfuwsKS7QAAA-A"]
[Tue Jul 21 07:36:46.866372 2026] [autoindex:error] [pid 254995:tid 255075] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:46.866692 2026] [autoindex:error] [pid 254995:tid 255010] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:46.899443 2026] [security2:error] [pid 254995:tid 255143] [client 20.104.96.117:59158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/file5.php"] [unique_id "al9Lvv7v0rlcEGmVraE4swAAAzA"]
[Tue Jul 21 07:36:47.207067 2026] [security2:error] [pid 255769:tid 255972] [client 20.206.105.145:38987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/xamp.php"] [unique_id "al9Lv7xMYwyVGnfuwsKS9QAAA-w"]
[Tue Jul 21 07:36:47.211889 2026] [security2:error] [pid 254995:tid 255175] [client 20.220.225.223:38658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Lv_7v0rlcEGmVraE4uQAAA1A"]
[Tue Jul 21 07:36:47.279458 2026] [security2:error] [pid 255769:tid 255918] [client 20.197.195.24:13258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/gecko.php"] [unique_id "al9Lv7xMYwyVGnfuwsKS9gAAA7Y"]
[Tue Jul 21 07:36:47.474014 2026] [security2:error] [pid 255769:tid 256024] [client 45.8.17.49:42479] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/as.php"] [unique_id "al9Lv7xMYwyVGnfuwsKS-gAABB4"]
[Tue Jul 21 07:36:47.498098 2026] [security2:error] [pid 254995:tid 255205] [client 103.86.117.203:52031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lv_7v0rlcEGmVraE4vAAAA24"]
[Tue Jul 21 07:36:47.498225 2026] [security2:error] [pid 254995:tid 255205] [client 103.86.117.203:52031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lv_7v0rlcEGmVraE4vAAAA24"]
[Tue Jul 21 07:36:47.642805 2026] [security2:error] [pid 255769:tid 255961] [client 20.104.96.117:59651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/0xD.php"] [unique_id "al9Lv7xMYwyVGnfuwsKS-wAAA-E"]
[Tue Jul 21 07:36:47.658335 2026] [security2:error] [pid 255769:tid 255973] [client 20.226.60.151:27542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/images.php"] [unique_id "al9Lv7xMYwyVGnfuwsKS_AAAA-0"]
[Tue Jul 21 07:36:47.681291 2026] [security2:error] [pid 255769:tid 255992] [client 20.206.105.145:38469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/file52.php"] [unique_id "al9Lv7xMYwyVGnfuwsKS_gAAA_8"]
[Tue Jul 21 07:36:47.802000 2026] [autoindex:error] [pid 254995:tid 255028] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/rest-api/endpoints/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:47.808231 2026] [autoindex:error] [pid 254995:tid 255122] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:48.152469 2026] [autoindex:error] [pid 254995:tid 255182] [client 147.185.132.58:60746] AH01276: Cannot serve directory /home3/agroci73/agrocibus.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:36:48.175976 2026] [security2:error] [pid 255769:tid 255952] [client 20.104.96.117:59653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/fnstall.php"] [unique_id "al9LwLxMYwyVGnfuwsKTBwAAA9g"]
[Tue Jul 21 07:36:48.216016 2026] [security2:error] [pid 255769:tid 255944] [client 37.140.223.163:55933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Lv7xMYwyVGnfuwsKS8QAAA9A"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:36:48.242195 2026] [security2:error] [pid 254995:tid 255267] [client 20.197.195.24:13271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/82.php"] [unique_id "al9LwP7v0rlcEGmVraE4zgAAA5E"]
[Tue Jul 21 07:36:48.607462 2026] [autoindex:error] [pid 254995:tid 255019] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:48.610481 2026] [autoindex:error] [pid 254995:tid 255055] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:48.615484 2026] [security2:error] [pid 254995:tid 255134] [client 20.206.105.145:39161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/bless.php"] [unique_id "al9LwP7v0rlcEGmVraE41wAAAyc"]
[Tue Jul 21 07:36:48.644892 2026] [security2:error] [pid 255769:tid 255945] [client 45.251.232.145:63201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LwLxMYwyVGnfuwsKTDAAAA9E"]
[Tue Jul 21 07:36:48.645020 2026] [security2:error] [pid 255769:tid 255945] [client 45.251.232.145:63201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LwLxMYwyVGnfuwsKTDAAAA9E"]
[Tue Jul 21 07:36:48.753954 2026] [security2:error] [pid 255769:tid 255785] [remote 81.173.115.7:50276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autoq.com.br"] [uri "/wp-login.php"] [unique_id "al9LwLxMYwyVGnfuwsKTEAAD-Q8"]
[Tue Jul 21 07:36:48.873867 2026] [security2:error] [pid 254995:tid 255276] [client 139.167.225.182:61029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LwP7v0rlcEGmVraE42wAAA5o"]
[Tue Jul 21 07:36:48.873960 2026] [security2:error] [pid 254995:tid 255276] [client 139.167.225.182:61029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LwP7v0rlcEGmVraE42wAAA5o"]
[Tue Jul 21 07:36:48.886517 2026] [security2:error] [pid 255769:tid 255943] [client 20.206.105.145:38480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/122.php"] [unique_id "al9LwLxMYwyVGnfuwsKTEQAAA88"]
[Tue Jul 21 07:36:48.976718 2026] [security2:error] [pid 254995:tid 255138] [client 45.8.17.65:52017] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentyfive/patterns/template-singl-portfolio.php"] [unique_id "al9LwP7v0rlcEGmVraE43AAAAys"]
[Tue Jul 21 07:36:48.991781 2026] [autoindex:error] [pid 254995:tid 255032] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/Text/Diff/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:48.993945 2026] [autoindex:error] [pid 254995:tid 255030] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/Text/Diff/Engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:49.029046 2026] [security2:error] [pid 255769:tid 256026] [client 20.197.195.24:13193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/admin.php"] [unique_id "al9LwbxMYwyVGnfuwsKTEwAABCA"]
[Tue Jul 21 07:36:49.063655 2026] [security2:error] [pid 255769:tid 255993] [client 20.226.60.151:27543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/gecko.php"] [unique_id "al9LwbxMYwyVGnfuwsKTFgAABAA"]
[Tue Jul 21 07:36:49.091110 2026] [security2:error] [pid 255769:tid 256024] [client 20.206.105.145:39269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file46.php"] [unique_id "al9LwbxMYwyVGnfuwsKTFwAABB4"]
[Tue Jul 21 07:36:49.323685 2026] [security2:error] [pid 255769:tid 255989] [client 20.206.105.145:39255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/eee.php"] [unique_id "al9LwbxMYwyVGnfuwsKTGAAAA_0"]
[Tue Jul 21 07:36:49.350560 2026] [autoindex:error] [pid 254995:tid 255057] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:49.351427 2026] [autoindex:error] [pid 254995:tid 255053] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:49.425659 2026] [security2:error] [pid 255769:tid 255979] [client 20.206.105.145:38942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file25.php"] [unique_id "al9LwbxMYwyVGnfuwsKTHgAAA_M"]
[Tue Jul 21 07:36:49.505486 2026] [security2:error] [pid 254995:tid 255160] [client 20.206.105.145:39237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file48.php"] [unique_id "al9Lwf7v0rlcEGmVraE47QAAA0E"]
[Tue Jul 21 07:36:49.613417 2026] [security2:error] [pid 255769:tid 255942] [client 20.197.195.24:13272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/adminner.php"] [unique_id "al9LwbxMYwyVGnfuwsKTIQAAA84"]
[Tue Jul 21 07:36:49.678586 2026] [security2:error] [pid 254995:tid 255179] [client 20.206.105.145:37937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/green1.php"] [unique_id "al9Lwf7v0rlcEGmVraE48gAAA1Q"]
[Tue Jul 21 07:36:49.721892 2026] [security2:error] [pid 255769:tid 256014] [client 20.104.96.117:59185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/acp.php"] [unique_id "al9LwbxMYwyVGnfuwsKTKAAABBQ"]
[Tue Jul 21 07:36:49.763801 2026] [security2:error] [pid 254995:tid 255200] [client 20.206.105.145:39282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file6.php"] [unique_id "al9Lwf7v0rlcEGmVraE4-wAAA2k"]
[Tue Jul 21 07:36:49.767958 2026] [autoindex:error] [pid 254995:tid 255039] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:49.768810 2026] [autoindex:error] [pid 254995:tid 255087] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:49.805565 2026] [security2:error] [pid 255769:tid 255929] [client 193.36.225.63:58105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LwbxMYwyVGnfuwsKTKgAAA8E"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:49.817066 2026] [security2:error] [pid 254995:tid 255127] [client 173.24.185.52:54750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Lwf7v0rlcEGmVraE4_AAAAyA"]
[Tue Jul 21 07:36:49.817165 2026] [security2:error] [pid 254995:tid 255127] [client 173.24.185.52:54750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Lwf7v0rlcEGmVraE4_AAAAyA"]
[Tue Jul 21 07:36:49.909074 2026] [security2:error] [pid 254995:tid 255133] [client 117.251.86.144:35550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Lwf7v0rlcEGmVraE4_gAAAyY"]
[Tue Jul 21 07:36:49.909208 2026] [security2:error] [pid 254995:tid 255133] [client 117.251.86.144:35550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Lwf7v0rlcEGmVraE4_gAAAyY"]
[Tue Jul 21 07:36:50.012924 2026] [security2:error] [pid 255769:tid 255927] [client 103.162.129.114:53737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LwrxMYwyVGnfuwsKTLwAAA78"]
[Tue Jul 21 07:36:50.013065 2026] [security2:error] [pid 255769:tid 255927] [client 103.162.129.114:53737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LwrxMYwyVGnfuwsKTLwAAA78"]
[Tue Jul 21 07:36:50.055903 2026] [security2:error] [pid 255769:tid 256022] [client 20.226.60.151:27600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/82.php"] [unique_id "al9LwrxMYwyVGnfuwsKTMQAABBw"]
[Tue Jul 21 07:36:50.174559 2026] [security2:error] [pid 255769:tid 255935] [client 20.206.105.145:38930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/a2.php"] [unique_id "al9LwrxMYwyVGnfuwsKTNQAAA8c"]
[Tue Jul 21 07:36:50.206246 2026] [security2:error] [pid 254995:tid 255197] [client 117.217.38.194:49961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lwv7v0rlcEGmVraE5BAAAA2Y"]
[Tue Jul 21 07:36:50.206406 2026] [security2:error] [pid 254995:tid 255197] [client 117.217.38.194:49961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lwv7v0rlcEGmVraE5BAAAA2Y"]
[Tue Jul 21 07:36:50.275403 2026] [security2:error] [pid 255769:tid 255903] [client 45.8.17.148:43391] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wso.php"] [unique_id "al9LwrxMYwyVGnfuwsKTOQAAA6c"]
[Tue Jul 21 07:36:50.349548 2026] [security2:error] [pid 255769:tid 255784] [remote 173.252.87.35:40842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9LwrxMYwyVGnfuwsKTOgADzA4"]
[Tue Jul 21 07:36:50.436296 2026] [security2:error] [pid 255769:tid 255962] [client 20.197.195.24:13287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/admin.php"] [unique_id "al9LwrxMYwyVGnfuwsKTPwAAA-I"]
[Tue Jul 21 07:36:50.502430 2026] [security2:error] [pid 255769:tid 255989] [client 20.104.96.117:61127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/mosty.php"] [unique_id "al9LwrxMYwyVGnfuwsKTQAAAA_0"]
[Tue Jul 21 07:36:50.565943 2026] [security2:error] [pid 255769:tid 255928] [client 122.186.204.214:55427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LwrxMYwyVGnfuwsKTQgAAA8A"]
[Tue Jul 21 07:36:50.566081 2026] [security2:error] [pid 255769:tid 255928] [client 122.186.204.214:55427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LwrxMYwyVGnfuwsKTQgAAA8A"]
[Tue Jul 21 07:36:50.807323 2026] [security2:error] [pid 255769:tid 255859] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LwrxMYwyVGnfuwsKTSAAEBFk"]
[Tue Jul 21 07:36:50.807504 2026] [security2:error] [pid 255769:tid 255998] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LwrxMYwyVGnfuwsKTSAAEBFk"]
[Tue Jul 21 07:36:50.813832 2026] [security2:error] [pid 255769:tid 255919] [client 20.197.195.24:51812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9LwrxMYwyVGnfuwsKTSQAAA7c"]
[Tue Jul 21 07:36:50.838982 2026] [security2:error] [pid 254995:tid 255274] [client 20.197.195.24:13212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/k.php"] [unique_id "al9Lwv7v0rlcEGmVraE5EQAAA5g"]
[Tue Jul 21 07:36:50.867859 2026] [security2:error] [pid 254995:tid 255217] [client 151.241.100.27:57852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.100.241.151.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/phpMyAdmin/index.php"] [unique_id "al9Lwv7v0rlcEGmVraE5FAAAA3k"]
[Tue Jul 21 07:36:50.880858 2026] [proxy_http:error] [pid 255769:tid 255830] (20014)Internal error (specific information not available): [remote 185.93.89.147:0] AH01102: error reading status line from remote server 127.0.0.1:2082
[Tue Jul 21 07:36:50.899833 2026] [security2:error] [pid 254995:tid 255258] [client 151.241.100.27:57854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.100.241.151.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/phpmyadmin/index.php"] [unique_id "al9Lwv7v0rlcEGmVraE5FgAAA4g"]
[Tue Jul 21 07:36:51.128305 2026] [autoindex:error] [pid 254995:tid 255047] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:51.136577 2026] [autoindex:error] [pid 254995:tid 254998] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:51.259921 2026] [security2:error] [pid 255769:tid 255976] [client 20.206.105.145:39019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file15.php"] [unique_id "al9Lw7xMYwyVGnfuwsKTVQAAA_A"]
[Tue Jul 21 07:36:51.303992 2026] [security2:error] [pid 255769:tid 255968] [client 20.197.195.24:13276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/blurbs.php"] [unique_id "al9Lw7xMYwyVGnfuwsKTVwAAA-g"]
[Tue Jul 21 07:36:51.322627 2026] [security2:error] [pid 255769:tid 255974] [client 20.104.96.117:59660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/6.php"] [unique_id "al9Lw7xMYwyVGnfuwsKTWAAAA-4"]
[Tue Jul 21 07:36:51.322977 2026] [security2:error] [pid 255769:tid 255933] [client 20.197.195.24:51722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Lw7xMYwyVGnfuwsKTWQAAA8U"]
[Tue Jul 21 07:36:51.419553 2026] [security2:error] [pid 255769:tid 255938] [client 62.102.148.164:52900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Lw7xMYwyVGnfuwsKTXgAAA8o"]
[Tue Jul 21 07:36:51.419667 2026] [security2:error] [pid 255769:tid 255938] [client 62.102.148.164:52900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Lw7xMYwyVGnfuwsKTXgAAA8o"]
[Tue Jul 21 07:36:51.442465 2026] [security2:error] [pid 255769:tid 255943] [client 20.206.105.145:37944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/biufile.php"] [unique_id "al9Lw7xMYwyVGnfuwsKTXwAAA88"]
[Tue Jul 21 07:36:51.475141 2026] [security2:error] [pid 255769:tid 255935] [client 45.8.17.105:42453] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-info.php"] [unique_id "al9Lw7xMYwyVGnfuwsKTYAAAA8c"]
[Tue Jul 21 07:36:51.557571 2026] [security2:error] [pid 255769:tid 255847] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lw7xMYwyVGnfuwsKTYgADxk0"]
[Tue Jul 21 07:36:51.557798 2026] [security2:error] [pid 255769:tid 255934] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lw7xMYwyVGnfuwsKTYgADxk0"]
[Tue Jul 21 07:36:51.633774 2026] [security2:error] [pid 254995:tid 255213] [client 20.197.195.24:13259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/bajah.php"] [unique_id "al9Lw_7v0rlcEGmVraE5IwAAA3U"]
[Tue Jul 21 07:36:52.043120 2026] [security2:error] [pid 255769:tid 255962] [client 20.197.195.24:51815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/media.php"] [unique_id "al9LxLxMYwyVGnfuwsKTaQAAA-I"]
[Tue Jul 21 07:36:52.078624 2026] [security2:error] [pid 255769:tid 255956] [client 20.104.96.117:59680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9LxLxMYwyVGnfuwsKTagAAA9w"]
[Tue Jul 21 07:36:52.109337 2026] [security2:error] [pid 254995:tid 255190] [client 20.197.195.24:13299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/a.php"] [unique_id "al9LxP7v0rlcEGmVraE5KwAAA18"]
[Tue Jul 21 07:36:52.309039 2026] [security2:error] [pid 255769:tid 255992] [client 20.206.105.145:39277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/jp.php"] [unique_id "al9LxLxMYwyVGnfuwsKTbAAAA_8"]
[Tue Jul 21 07:36:52.345121 2026] [security2:error] [pid 254995:tid 255195] [client 20.206.105.145:38465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wpconf.php"] [unique_id "al9LxP7v0rlcEGmVraE5MQAAA2Q"]
[Tue Jul 21 07:36:52.349983 2026] [security2:error] [pid 254995:tid 255169] [client 20.226.60.151:27578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/admin.php"] [unique_id "al9LxP7v0rlcEGmVraE5MgAAA0o"]
[Tue Jul 21 07:36:52.399075 2026] [access_compat:error] [pid 254995:tid 255131] [client 162.241.63.68:10780] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:36:52.409209 2026] [security2:error] [pid 254995:tid 255193] [client 175.45.70.82:60894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LxP7v0rlcEGmVraE5NAAAA2I"]
[Tue Jul 21 07:36:52.409301 2026] [security2:error] [pid 254995:tid 255193] [client 175.45.70.82:60894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LxP7v0rlcEGmVraE5NAAAA2I"]
[Tue Jul 21 07:36:52.487456 2026] [security2:error] [pid 254995:tid 255272] [client 20.197.195.24:13187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/edit.php"] [unique_id "al9LxP7v0rlcEGmVraE5OAAAA5Y"]
[Tue Jul 21 07:36:52.574046 2026] [security2:error] [pid 254995:tid 255212] [client 122.162.144.145:31421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LxP7v0rlcEGmVraE5OwAAA3Q"]
[Tue Jul 21 07:36:52.574172 2026] [security2:error] [pid 254995:tid 255212] [client 122.162.144.145:31421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LxP7v0rlcEGmVraE5OwAAA3Q"]
[Tue Jul 21 07:36:52.680130 2026] [security2:error] [pid 254995:tid 255267] [client 20.197.195.24:13200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/hosty.php"] [unique_id "al9LxP7v0rlcEGmVraE5PwAAA5E"]
[Tue Jul 21 07:36:52.680278 2026] [security2:error] [pid 255769:tid 255916] [client 45.8.17.138:39685] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/s.php"] [unique_id "al9LxLxMYwyVGnfuwsKTcAAAA7Q"]
[Tue Jul 21 07:36:52.703105 2026] [security2:error] [pid 255769:tid 256021] [client 20.104.96.117:59657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/qqqa.php"] [unique_id "al9LxLxMYwyVGnfuwsKTcQAABBs"]
[Tue Jul 21 07:36:52.714654 2026] [security2:error] [pid 254995:tid 255125] [client 20.226.60.151:51273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9LxP7v0rlcEGmVraE5QAAAAx4"]
[Tue Jul 21 07:36:52.877823 2026] [security2:error] [pid 255769:tid 256004] [client 20.197.195.24:13249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/k.php"] [unique_id "al9LxLxMYwyVGnfuwsKTcgAABAo"]
[Tue Jul 21 07:36:52.981986 2026] [security2:error] [pid 254995:tid 255274] [client 20.197.195.24:13264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/aaa.php"] [unique_id "al9LxP7v0rlcEGmVraE5QwAAA5g"]
[Tue Jul 21 07:36:53.012437 2026] [security2:error] [pid 255769:tid 255942] [client 20.197.195.24:51734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/images.php"] [unique_id "al9LxbxMYwyVGnfuwsKTcwAAA84"]
[Tue Jul 21 07:36:53.057354 2026] [autoindex:error] [pid 254995:tid 255001] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:53.062504 2026] [autoindex:error] [pid 254995:tid 255077] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:53.083984 2026] [security2:error] [pid 255769:tid 255930] [client 151.241.100.27:57853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.100.241.151.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/adminer.php"] [unique_id "al9LxbxMYwyVGnfuwsKTdAAAA8I"]
[Tue Jul 21 07:36:53.084164 2026] [security2:error] [pid 254995:tid 255020] [remote 74.7.243.250:49658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orixmed.com.inlaudo.com.br"] [uri "/blog/index.php"] [unique_id "al9Lxf7v0rlcEGmVraE5SAADIhg"], referer: https://orixmed.com.inlaudo.com.br/blog/
[Tue Jul 21 07:36:53.123438 2026] [security2:error] [pid 254995:tid 255263] [client 20.197.195.24:13277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/file5.php"] [unique_id "al9Lxf7v0rlcEGmVraE5SwAAA40"]
[Tue Jul 21 07:36:53.148417 2026] [security2:error] [pid 254995:tid 255152] [client 154.192.233.199:59824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lxf7v0rlcEGmVraE5TAAAAzk"]
[Tue Jul 21 07:36:53.148558 2026] [security2:error] [pid 254995:tid 255152] [client 154.192.233.199:59824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lxf7v0rlcEGmVraE5TAAAAzk"]
[Tue Jul 21 07:36:53.160049 2026] [security2:error] [pid 254995:tid 255197] [client 103.106.20.201:49405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lxf7v0rlcEGmVraE5TQAAA2Y"]
[Tue Jul 21 07:36:53.160162 2026] [security2:error] [pid 254995:tid 255197] [client 103.106.20.201:49405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lxf7v0rlcEGmVraE5TQAAA2Y"]
[Tue Jul 21 07:36:53.338216 2026] [security2:error] [pid 255769:tid 255929] [client 20.104.96.117:59654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/aunmc.php"] [unique_id "al9LxbxMYwyVGnfuwsKTewAAA8E"]
[Tue Jul 21 07:36:53.425949 2026] [security2:error] [pid 255769:tid 255977] [client 20.197.195.24:13270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/222.php"] [unique_id "al9LxbxMYwyVGnfuwsKTgAAAA_E"]
[Tue Jul 21 07:36:53.501828 2026] [security2:error] [pid 254995:tid 255213] [client 20.226.60.151:61197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Lxf7v0rlcEGmVraE5iAAAA3U"]
[Tue Jul 21 07:36:53.588596 2026] [security2:error] [pid 254995:tid 255148] [client 62.102.148.164:52906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Lxf7v0rlcEGmVraE5iQAAAzU"]
[Tue Jul 21 07:36:53.588717 2026] [security2:error] [pid 254995:tid 255148] [client 62.102.148.164:52906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Lxf7v0rlcEGmVraE5iQAAAzU"]
[Tue Jul 21 07:36:53.649010 2026] [security2:error] [pid 254995:tid 255141] [client 20.206.105.145:37908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/mosty.php"] [unique_id "al9Lxf7v0rlcEGmVraE5iwAAAy4"]
[Tue Jul 21 07:36:53.664937 2026] [security2:error] [pid 254995:tid 255051] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lxf7v0rlcEGmVraE5jAADRzc"]
[Tue Jul 21 07:36:53.665056 2026] [security2:error] [pid 254995:tid 255166] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lxf7v0rlcEGmVraE5jAADRzc"]
[Tue Jul 21 07:36:53.680397 2026] [security2:error] [pid 254995:tid 255160] [client 20.197.195.24:13215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/test.php"] [unique_id "al9Lxf7v0rlcEGmVraE5kgAAA0E"]
[Tue Jul 21 07:36:53.867008 2026] [security2:error] [pid 255769:tid 256028] [client 20.104.96.117:59195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/uoocf.php"] [unique_id "al9LxbxMYwyVGnfuwsKTkgAABCI"]
[Tue Jul 21 07:36:53.998792 2026] [autoindex:error] [pid 254995:tid 255100] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/Text/Diff/Engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:54.000782 2026] [autoindex:error] [pid 254995:tid 255060] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/js/jcrop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:54.177284 2026] [security2:error] [pid 255769:tid 255916] [client 45.8.17.103:57999] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/69.php"] [unique_id "al9LxrxMYwyVGnfuwsKTlgAAA7Q"]
[Tue Jul 21 07:36:54.265172 2026] [security2:error] [pid 255769:tid 255941] [client 20.197.195.24:13266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/aaa.php"] [unique_id "al9LxrxMYwyVGnfuwsKTlwAAA80"]
[Tue Jul 21 07:36:54.437532 2026] [security2:error] [pid 255769:tid 255967] [client 20.197.195.24:51808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/gecko.php"] [unique_id "al9LxrxMYwyVGnfuwsKTngAAA-c"]
[Tue Jul 21 07:36:54.438289 2026] [security2:error] [pid 254995:tid 255194] [client 20.104.96.117:59697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/iywwi.php"] [unique_id "al9Lxv7v0rlcEGmVraE5_QAAA2M"]
[Tue Jul 21 07:36:54.593172 2026] [security2:error] [pid 255769:tid 255880] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LxrxMYwyVGnfuwsKTogAECW4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:54.595743 2026] [security2:error] [pid 254995:tid 255159] [client 20.197.195.24:13265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/11.php"] [unique_id "al9Lxv7v0rlcEGmVraE6AQAAA0A"]
[Tue Jul 21 07:36:54.602038 2026] [security2:error] [pid 255769:tid 255846] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LxrxMYwyVGnfuwsKTowAD00w"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:54.607336 2026] [security2:error] [pid 255769:tid 255815] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LxrxMYwyVGnfuwsKTpAAEBC0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:54.607497 2026] [security2:error] [pid 255769:tid 255790] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LxrxMYwyVGnfuwsKTpQADrRQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:54.646415 2026] [security2:error] [pid 255769:tid 255956] [client 122.164.127.47:52940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LxrxMYwyVGnfuwsKTqAAAA9w"]
[Tue Jul 21 07:36:54.646549 2026] [security2:error] [pid 255769:tid 255956] [client 122.164.127.47:52940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LxrxMYwyVGnfuwsKTqAAAA9w"]
[Tue Jul 21 07:36:54.877010 2026] [security2:error] [pid 255769:tid 255984] [client 20.197.195.24:13303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/mac.php"] [unique_id "al9LxrxMYwyVGnfuwsKTqQAAA_g"]
[Tue Jul 21 07:36:54.922258 2026] [security2:error] [pid 255769:tid 255945] [client 20.197.195.24:13224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/chosen.php"] [unique_id "al9LxrxMYwyVGnfuwsKTqgAAA9E"]
[Tue Jul 21 07:36:54.943850 2026] [security2:error] [pid 255769:tid 255901] [client 20.197.195.24:13296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/cream1.php"] [unique_id "al9LxrxMYwyVGnfuwsKTqwAAA6U"]
[Tue Jul 21 07:36:54.947738 2026] [autoindex:error] [pid 254995:tid 255044] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:54.959578 2026] [security2:error] [pid 255769:tid 255831] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LxrxMYwyVGnfuwsKTrAADyD0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:54.964019 2026] [security2:error] [pid 255769:tid 255828] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LxrxMYwyVGnfuwsKTrQAD6Do"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:54.968569 2026] [security2:error] [pid 255769:tid 255972] [client 20.206.105.145:38477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/dejavu.php"] [unique_id "al9LxrxMYwyVGnfuwsKTrgAAA-w"]
[Tue Jul 21 07:36:54.990452 2026] [autoindex:error] [pid 255769:tid 255927] [client 20.197.195.24:13196] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:36:54.998795 2026] [security2:error] [pid 255769:tid 255938] [client 20.197.195.24:51759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/82.php"] [unique_id "al9LxrxMYwyVGnfuwsKTsQAAA8o"]
[Tue Jul 21 07:36:55.011310 2026] [autoindex:error] [pid 255769:tid 255948] [client 20.197.195.24:13196] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:36:55.020033 2026] [security2:error] [pid 255769:tid 255888] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTswADzHY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:55.034162 2026] [security2:error] [pid 255769:tid 255926] [client 20.197.195.24:13196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/dr.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTtAAAA74"]
[Tue Jul 21 07:36:55.059854 2026] [security2:error] [pid 255769:tid 255990] [client 20.226.60.151:51316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/xyn.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTtQAAA_4"]
[Tue Jul 21 07:36:55.084596 2026] [security2:error] [pid 254995:tid 255266] [client 20.197.195.24:13226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/x.php"] [unique_id "al9Lx_7v0rlcEGmVraE6EwAAA5A"]
[Tue Jul 21 07:36:55.125546 2026] [security2:error] [pid 255769:tid 255935] [client 20.151.10.161:45953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTtwAAA8c"]
[Tue Jul 21 07:36:55.186177 2026] [security2:error] [pid 255769:tid 255980] [client 20.206.105.145:38472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/aaf.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTuAAAA_Q"]
[Tue Jul 21 07:36:55.203750 2026] [security2:error] [pid 254995:tid 255222] [client 20.197.195.24:51823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/admin.php"] [unique_id "al9Lx_7v0rlcEGmVraE6FAAAA34"]
[Tue Jul 21 07:36:55.274950 2026] [security2:error] [pid 254995:tid 255147] [client 20.206.105.145:38479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/term.php"] [unique_id "al9Lx_7v0rlcEGmVraE6FgAAAzQ"]
[Tue Jul 21 07:36:55.283318 2026] [security2:error] [pid 254995:tid 255136] [client 20.197.195.24:13251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/155.php"] [unique_id "al9Lx_7v0rlcEGmVraE6FwAAAyk"]
[Tue Jul 21 07:36:55.313681 2026] [security2:error] [pid 255769:tid 255857] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTuQADw1c"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:55.334749 2026] [security2:error] [pid 255769:tid 255851] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTvAAEE1E"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:55.356059 2026] [security2:error] [pid 254995:tid 255129] [client 103.174.34.15:57134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lx_7v0rlcEGmVraE6GwAAAyI"]
[Tue Jul 21 07:36:55.356482 2026] [security2:error] [pid 254995:tid 255129] [client 103.174.34.15:57134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lx_7v0rlcEGmVraE6GwAAAyI"]
[Tue Jul 21 07:36:55.365636 2026] [security2:error] [pid 255769:tid 255867] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTvgAEHmE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:55.384772 2026] [security2:error] [pid 254995:tid 255275] [client 20.197.195.24:51829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/adminner.php"] [unique_id "al9Lx_7v0rlcEGmVraE6NwAAA5k"]
[Tue Jul 21 07:36:55.423605 2026] [security2:error] [pid 255769:tid 255920] [client 193.36.225.56:23885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTwgAAA7g"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:55.469372 2026] [security2:error] [pid 255769:tid 255979] [client 20.104.96.117:59674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/gqgsa.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTxAAAA_M"]
[Tue Jul 21 07:36:55.556995 2026] [security2:error] [pid 254995:tid 255075] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Lx_7v0rlcEGmVraE6SAADbk8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:55.566032 2026] [autoindex:error] [pid 254995:tid 254998] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:55.611225 2026] [security2:error] [pid 255769:tid 255930] [client 20.197.195.24:51787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/admin.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTxwAAA8I"]
[Tue Jul 21 07:36:55.667741 2026] [security2:error] [pid 255769:tid 255864] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTyAADpF4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:55.686512 2026] [security2:error] [pid 255769:tid 256025] [client 45.8.17.103:42933] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-crom.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTyQAABB8"]
[Tue Jul 21 07:36:55.691080 2026] [security2:error] [pid 255769:tid 255821] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTygAEFDM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:55.698598 2026] [security2:error] [pid 254995:tid 255056] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Lx_7v0rlcEGmVraE6TAADSTw"]
[Tue Jul 21 07:36:55.698736 2026] [security2:error] [pid 254995:tid 255168] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Lx_7v0rlcEGmVraE6TAADSTw"]
[Tue Jul 21 07:36:55.719640 2026] [security2:error] [pid 255769:tid 255782] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTzAAD0ww"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:55.744604 2026] [security2:error] [pid 255769:tid 255970] [client 20.206.105.145:37938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/ha.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTzgAAA-o"]
[Tue Jul 21 07:36:55.950539 2026] [autoindex:error] [pid 254995:tid 255012] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:56.027449 2026] [security2:error] [pid 255769:tid 255918] [client 20.197.195.24:13282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/ops.php"] [unique_id "al9LyLxMYwyVGnfuwsKT_gAAA7Y"]
[Tue Jul 21 07:36:56.040207 2026] [security2:error] [pid 255769:tid 255965] [client 20.226.60.151:27339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/adminner.php"] [unique_id "al9LyLxMYwyVGnfuwsKUAAAAA-U"]
[Tue Jul 21 07:36:56.101980 2026] [security2:error] [pid 255769:tid 255966] [client 20.206.105.145:39286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/f35.php"] [unique_id "al9LyLxMYwyVGnfuwsKUAQAAA-Y"]
[Tue Jul 21 07:36:56.122953 2026] [security2:error] [pid 255769:tid 255961] [client 20.197.195.24:51796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/k.php"] [unique_id "al9LyLxMYwyVGnfuwsKUAgAAA-E"]
[Tue Jul 21 07:36:56.147735 2026] [security2:error] [pid 255769:tid 255780] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LyLxMYwyVGnfuwsKUAwAEDgo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:56.191098 2026] [security2:error] [pid 255769:tid 255941] [client 20.104.96.117:59685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/elbzl.php"] [unique_id "al9LyLxMYwyVGnfuwsKUBAAAA80"]
[Tue Jul 21 07:36:56.313874 2026] [autoindex:error] [pid 254995:tid 255097] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:56.351423 2026] [autoindex:error] [pid 254995:tid 255116] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/sitemaps/providers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:56.364738 2026] [security2:error] [pid 255769:tid 255891] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LyLxMYwyVGnfuwsKUBQADw3k"]
[Tue Jul 21 07:36:56.364910 2026] [security2:error] [pid 255769:tid 255931] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LyLxMYwyVGnfuwsKUBQADw3k"]
[Tue Jul 21 07:36:56.534582 2026] [security2:error] [pid 255769:tid 255971] [client 20.220.225.223:38675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/byp8.php"] [unique_id "al9LyLxMYwyVGnfuwsKUCQAAA-s"]
[Tue Jul 21 07:36:56.646721 2026] [security2:error] [pid 255769:tid 255781] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LyLxMYwyVGnfuwsKUCwADzgs"]
[Tue Jul 21 07:36:56.646875 2026] [security2:error] [pid 255769:tid 255942] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LyLxMYwyVGnfuwsKUCwADzgs"]
[Tue Jul 21 07:36:56.729481 2026] [security2:error] [pid 255769:tid 255947] [client 20.197.195.24:51780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/blurbs.php"] [unique_id "al9LyLxMYwyVGnfuwsKUDQAAA9M"]
[Tue Jul 21 07:36:56.813910 2026] [security2:error] [pid 255769:tid 255909] [client 20.220.225.223:38673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/wander.php"] [unique_id "al9LyLxMYwyVGnfuwsKUDwAAA60"]
[Tue Jul 21 07:36:56.847898 2026] [security2:error] [pid 255769:tid 255934] [client 193.36.225.151:50405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LyLxMYwyVGnfuwsKUDAAAA8Y"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:36:56.885149 2026] [security2:error] [pid 255769:tid 255956] [client 20.206.105.145:38085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/hur.php"] [unique_id "al9LyLxMYwyVGnfuwsKUEAAAA9w"]
[Tue Jul 21 07:36:57.064546 2026] [security2:error] [pid 255769:tid 255779] [remote 154.61.75.100:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/wp-login.php"] [unique_id "al9LybxMYwyVGnfuwsKUFQAEGgk"]
[Tue Jul 21 07:36:57.175621 2026] [security2:error] [pid 255769:tid 255950] [client 45.8.17.65:61415] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9LybxMYwyVGnfuwsKUFgAAA9Y"]
[Tue Jul 21 07:36:57.380503 2026] [security2:error] [pid 255769:tid 255980] [client 74.7.230.23:53482] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "zooparquevet.com.br"] [uri "/index.php"] [unique_id "al9LyLxMYwyVGnfuwsKT_wAAA_Q"]
[Tue Jul 21 07:36:57.386211 2026] [security2:error] [pid 255769:tid 255948] [client 20.151.10.161:46016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9LybxMYwyVGnfuwsKUGAAAA9Q"]
[Tue Jul 21 07:36:57.406298 2026] [autoindex:error] [pid 254995:tid 255010] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/js/jcrop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:57.425094 2026] [autoindex:error] [pid 254995:tid 255014] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:57.480153 2026] [security2:error] [pid 254995:tid 255130] [client 20.226.60.151:61191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/patie.php"] [unique_id "al9Lyf7v0rlcEGmVraE6bAAAAyM"]
[Tue Jul 21 07:36:57.523198 2026] [security2:error] [pid 255769:tid 255958] [client 20.206.105.145:39273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-load.php"] [unique_id "al9LybxMYwyVGnfuwsKUGgAAA94"]
[Tue Jul 21 07:36:57.565261 2026] [security2:error] [pid 255769:tid 255935] [client 20.197.195.24:51712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/bajah.php"] [unique_id "al9LybxMYwyVGnfuwsKUGwAAA8c"]
[Tue Jul 21 07:36:57.566982 2026] [security2:error] [pid 254995:tid 255137] [client 20.104.96.117:59172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/adjig.php"] [unique_id "al9Lyf7v0rlcEGmVraE6cQAAAyo"]
[Tue Jul 21 07:36:57.596038 2026] [core:error] [pid 255769:tid 255940] [client 66.249.66.67:50562] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:36:57.596056 2026] [core:error] [pid 255769:tid 255940] [client 66.249.66.67:50562] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:36:57.753002 2026] [security2:error] [pid 255769:tid 256013] [client 20.197.195.24:62423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/file31.php"] [unique_id "al9LybxMYwyVGnfuwsKUHQAABBM"]
[Tue Jul 21 07:36:57.879837 2026] [security2:error] [pid 255769:tid 255916] [client 59.96.220.140:57678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LybxMYwyVGnfuwsKUHwAAA7Q"]
[Tue Jul 21 07:36:57.880016 2026] [security2:error] [pid 255769:tid 255916] [client 59.96.220.140:57678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LybxMYwyVGnfuwsKUHwAAA7Q"]
[Tue Jul 21 07:36:57.982655 2026] [security2:error] [pid 255769:tid 255981] [client 103.86.117.203:52545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LybxMYwyVGnfuwsKUIAAAA_U"]
[Tue Jul 21 07:36:57.982766 2026] [security2:error] [pid 255769:tid 255981] [client 103.86.117.203:52545] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LybxMYwyVGnfuwsKUIAAAA_U"]
[Tue Jul 21 07:36:58.023646 2026] [autoindex:error] [pid 254995:tid 255045] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:58.215104 2026] [security2:error] [pid 254995:tid 255190] [client 20.197.195.24:51773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/a.php"] [unique_id "al9Lyv7v0rlcEGmVraE6gQAAA18"]
[Tue Jul 21 07:36:58.337829 2026] [security2:error] [pid 254995:tid 255195] [client 20.220.225.223:38694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/jga.php"] [unique_id "al9Lyv7v0rlcEGmVraE6gwAAA2Q"]
[Tue Jul 21 07:36:58.371723 2026] [security2:error] [pid 254995:tid 255146] [client 20.226.60.151:27618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/admin.php"] [unique_id "al9Lyv7v0rlcEGmVraE6hAAAAzM"]
[Tue Jul 21 07:36:58.413161 2026] [security2:error] [pid 255769:tid 255954] [client 20.104.96.117:59149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/byp.php"] [unique_id "al9LyrxMYwyVGnfuwsKUJwAAA9o"]
[Tue Jul 21 07:36:58.413203 2026] [security2:error] [pid 255769:tid 255925] [client 20.206.105.145:38083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/h02ugyh.php"] [unique_id "al9LyrxMYwyVGnfuwsKUKAAAA70"]
[Tue Jul 21 07:36:58.472017 2026] [security2:error] [pid 254995:tid 255061] [remote 119.195.102.159:38504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/wp-login.php"] [unique_id "al9Lyv7v0rlcEGmVraE6hgADVUE"]
[Tue Jul 21 07:36:58.625192 2026] [core:error] [pid 254995:tid 255131] [client 66.249.66.68:40130] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:36:58.625210 2026] [core:error] [pid 254995:tid 255131] [client 66.249.66.68:40130] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:36:58.700796 2026] [autoindex:error] [pid 254995:tid 255001] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/css/dist/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:58.749535 2026] [autoindex:error] [pid 254995:tid 255020] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/sitemaps/providers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:58.754147 2026] [security2:error] [pid 254995:tid 255223] [client 20.197.195.24:51755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/edit.php"] [unique_id "al9Lyv7v0rlcEGmVraE6jAAAA38"]
[Tue Jul 21 07:36:58.771343 2026] [security2:error] [pid 255769:tid 255947] [client 45.8.17.59:29489] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/click.php"] [unique_id "al9LyrxMYwyVGnfuwsKULwAAA9M"]
[Tue Jul 21 07:36:58.843678 2026] [security2:error] [pid 255769:tid 255929] [client 20.197.195.24:51719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/hosty.php"] [unique_id "al9LyrxMYwyVGnfuwsKUMgAAA8E"]
[Tue Jul 21 07:36:58.874160 2026] [security2:error] [pid 255769:tid 255970] [client 20.197.195.24:51743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/k.php"] [unique_id "al9LyrxMYwyVGnfuwsKUMwAAA-o"]
[Tue Jul 21 07:36:58.995737 2026] [security2:error] [pid 255769:tid 255988] [client 20.197.195.24:62891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/file6.php"] [unique_id "al9LyrxMYwyVGnfuwsKUNAAAA_w"]
[Tue Jul 21 07:36:59.074730 2026] [security2:error] [pid 255769:tid 255972] [client 20.197.195.24:51776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/aaa.php"] [unique_id "al9Ly7xMYwyVGnfuwsKUOAAAA-w"]
[Tue Jul 21 07:36:59.099294 2026] [security2:error] [pid 255769:tid 256004] [client 45.251.232.145:63733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ly7xMYwyVGnfuwsKUOQAABAo"]
[Tue Jul 21 07:36:59.099367 2026] [security2:error] [pid 255769:tid 256004] [client 45.251.232.145:63733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ly7xMYwyVGnfuwsKUOQAABAo"]
[Tue Jul 21 07:36:59.110189 2026] [security2:error] [pid 254995:tid 255163] [client 139.167.225.182:61670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ly_7v0rlcEGmVraE6kgAAA0Q"]
[Tue Jul 21 07:36:59.110262 2026] [security2:error] [pid 254995:tid 255163] [client 139.167.225.182:61670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ly_7v0rlcEGmVraE6kgAAA0Q"]
[Tue Jul 21 07:36:59.173035 2026] [security2:error] [pid 255769:tid 256018] [client 20.220.225.223:31192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/user.php"] [unique_id "al9Ly7xMYwyVGnfuwsKUPQAABBg"]
[Tue Jul 21 07:36:59.192925 2026] [security2:error] [pid 255769:tid 255958] [client 20.197.195.24:51822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/file5.php"] [unique_id "al9Ly7xMYwyVGnfuwsKUPgAAA94"]
[Tue Jul 21 07:36:59.228159 2026] [security2:error] [pid 255769:tid 255990] [client 20.206.105.145:39287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/xwpg.php"] [unique_id "al9Ly7xMYwyVGnfuwsKUPwAAA_4"]
[Tue Jul 21 07:36:59.323060 2026] [security2:error] [pid 255769:tid 255918] [client 85.204.70.100:43192] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9Ly7xMYwyVGnfuwsKUQAAAA7Y"]
[Tue Jul 21 07:36:59.364227 2026] [security2:error] [pid 255769:tid 255940] [client 20.226.60.151:51283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/aa.php"] [unique_id "al9Ly7xMYwyVGnfuwsKUQQAAA8w"]
[Tue Jul 21 07:36:59.376965 2026] [security2:error] [pid 255769:tid 255983] [client 20.104.96.117:59140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9Ly7xMYwyVGnfuwsKUQgAAA_c"]
[Tue Jul 21 07:36:59.418197 2026] [security2:error] [pid 255769:tid 255915] [client 20.197.195.24:51718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/222.php"] [unique_id "al9Ly7xMYwyVGnfuwsKURAAAA7M"]
[Tue Jul 21 07:36:59.531911 2026] [security2:error] [pid 255769:tid 256015] [client 20.197.195.24:51818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/test.php"] [unique_id "al9Ly7xMYwyVGnfuwsKURwAABBU"]
[Tue Jul 21 07:36:59.672784 2026] [security2:error] [pid 254995:tid 255264] [client 37.140.223.50:58719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Ly_7v0rlcEGmVraE6mAAAA44"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:36:59.679461 2026] [security2:error] [pid 254995:tid 255126] [client 45.8.17.145:56365] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/byp.php"] [unique_id "al9Ly_7v0rlcEGmVraE6mQAAAx8"]
[Tue Jul 21 07:36:59.723595 2026] [security2:error] [pid 255769:tid 255954] [client 20.197.195.24:51814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/aaa.php"] [unique_id "al9Ly7xMYwyVGnfuwsKUTgAAA9o"]
[Tue Jul 21 07:36:59.779345 2026] [security2:error] [pid 254995:tid 255161] [client 20.206.105.145:37892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/seiso.php"] [unique_id "al9Ly_7v0rlcEGmVraE6mwAAA0I"]
[Tue Jul 21 07:36:59.791110 2026] [security2:error] [pid 254995:tid 255170] [client 193.36.225.67:59871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Ly_7v0rlcEGmVraE6nAAAA0s"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:59.837655 2026] [autoindex:error] [pid 254995:tid 255118] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:59.837759 2026] [autoindex:error] [pid 254995:tid 255006] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:59.991376 2026] [proxy:error] [pid 255769:tid 256006] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:59.991449 2026] [proxy_http:error] [pid 255769:tid 256006] [client 20.206.105.145:39266] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:59.992070 2026] [proxy:error] [pid 255769:tid 256006] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:59.992102 2026] [proxy_http:error] [pid 255769:tid 256006] [client 20.206.105.145:39266] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:37:00.081172 2026] [security2:error] [pid 255769:tid 255976] [client 85.204.70.100:43206] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9LzLxMYwyVGnfuwsKUVgAAA_A"]
[Tue Jul 21 07:37:00.107180 2026] [security2:error] [pid 255769:tid 255988] [client 20.197.195.24:51775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/11.php"] [unique_id "al9LzLxMYwyVGnfuwsKUVwAAA_w"]
[Tue Jul 21 07:37:00.204331 2026] [autoindex:error] [pid 254995:tid 255028] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:00.207059 2026] [autoindex:error] [pid 254995:tid 255091] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:00.218578 2026] [security2:error] [pid 255769:tid 255979] [client 20.197.195.24:51825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/mac.php"] [unique_id "al9LzLxMYwyVGnfuwsKUXAAAA_M"]
[Tue Jul 21 07:37:00.290426 2026] [security2:error] [pid 255769:tid 256004] [client 20.197.195.24:51765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/chosen.php"] [unique_id "al9LzLxMYwyVGnfuwsKUXgAABAo"]
[Tue Jul 21 07:37:00.368460 2026] [security2:error] [pid 255769:tid 255943] [client 20.197.195.24:51794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/cream1.php"] [unique_id "al9LzLxMYwyVGnfuwsKUXwAAA88"]
[Tue Jul 21 07:37:00.475574 2026] [security2:error] [pid 255769:tid 255980] [client 85.204.70.100:59244] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9LzLxMYwyVGnfuwsKUYgAAA_Q"]
[Tue Jul 21 07:37:00.515213 2026] [security2:error] [pid 255769:tid 256024] [client 173.24.185.52:55217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LzLxMYwyVGnfuwsKUYwAABB4"]
[Tue Jul 21 07:37:00.515347 2026] [security2:error] [pid 255769:tid 256024] [client 173.24.185.52:55217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LzLxMYwyVGnfuwsKUYwAABB4"]
[Tue Jul 21 07:37:00.555225 2026] [proxy:error] [pid 255769:tid 256018] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:37:00.555306 2026] [proxy_http:error] [pid 255769:tid 256018] [client 20.206.105.145:39281] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:37:00.556392 2026] [proxy:error] [pid 255769:tid 256018] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:37:00.556426 2026] [proxy_http:error] [pid 255769:tid 256018] [client 20.206.105.145:39281] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:37:00.576914 2026] [security2:error] [pid 255769:tid 255952] [client 117.251.86.144:38768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LzLxMYwyVGnfuwsKUZgAAA9g"]
[Tue Jul 21 07:37:00.577068 2026] [security2:error] [pid 255769:tid 255952] [client 117.251.86.144:38768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LzLxMYwyVGnfuwsKUZgAAA9g"]
[Tue Jul 21 07:37:00.592102 2026] [security2:error] [pid 255769:tid 255903] [client 20.104.96.117:61066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/classwithtostring.php"] [unique_id "al9LzLxMYwyVGnfuwsKUZwAAA6c"]
[Tue Jul 21 07:37:00.689623 2026] [autoindex:error] [pid 254995:tid 255059] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:00.690382 2026] [autoindex:error] [pid 254995:tid 255032] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/css/dist/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:00.694316 2026] [security2:error] [pid 254995:tid 255151] [client 117.217.38.194:50594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LzP7v0rlcEGmVraE6rgAAAzg"]
[Tue Jul 21 07:37:00.694410 2026] [security2:error] [pid 254995:tid 255151] [client 117.217.38.194:50594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LzP7v0rlcEGmVraE6rgAAAzg"]
[Tue Jul 21 07:37:00.796474 2026] [security2:error] [pid 255769:tid 255911] [client 103.162.129.114:54177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LzLxMYwyVGnfuwsKUbgAAA68"]
[Tue Jul 21 07:37:00.796606 2026] [security2:error] [pid 255769:tid 255911] [client 103.162.129.114:54177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LzLxMYwyVGnfuwsKUbgAAA68"]
[Tue Jul 21 07:37:00.855929 2026] [security2:error] [pid 255769:tid 255951] [client 85.204.70.100:53102] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9LzLxMYwyVGnfuwsKUbwAAA9c"]
[Tue Jul 21 07:37:00.860167 2026] [security2:error] [pid 254995:tid 255213] [client 20.206.105.145:39116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/waf.php"] [unique_id "al9LzP7v0rlcEGmVraE6sAAAA3U"]
[Tue Jul 21 07:37:00.906978 2026] [security2:error] [pid 255769:tid 255974] [client 20.206.105.145:38936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/xstelth.php"] [unique_id "al9LzLxMYwyVGnfuwsKUcQAAA-4"]
[Tue Jul 21 07:37:00.970993 2026] [security2:error] [pid 255769:tid 255925] [client 20.151.10.161:46047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/x.php"] [unique_id "al9LzLxMYwyVGnfuwsKUcwAAA70"]
[Tue Jul 21 07:37:01.028264 2026] [autoindex:error] [pid 255769:tid 255919] [client 20.197.195.24:51751] AH01276: Cannot serve directory /home3/equote29/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:01.049035 2026] [security2:error] [pid 255769:tid 255944] [client 20.104.96.117:61078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/root.php"] [unique_id "al9LzbxMYwyVGnfuwsKUdgAAA9A"]
[Tue Jul 21 07:37:01.085473 2026] [security2:error] [pid 255769:tid 256006] [client 45.8.17.57:33995] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/ateprivacy-policy-guide.php"] [unique_id "al9LzbxMYwyVGnfuwsKUeAAABAw"]
[Tue Jul 21 07:37:01.087780 2026] [autoindex:error] [pid 255769:tid 255910] [client 20.197.195.24:51751] AH01276: Cannot serve directory /home3/equote29/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:01.093360 2026] [security2:error] [pid 255769:tid 255930] [client 20.197.195.24:51751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/dr.php"] [unique_id "al9LzbxMYwyVGnfuwsKUeQAAA8I"]
[Tue Jul 21 07:37:01.155398 2026] [security2:error] [pid 255769:tid 255984] [client 20.206.105.145:39151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-links.php"] [unique_id "al9LzbxMYwyVGnfuwsKUegAAA_g"]
[Tue Jul 21 07:37:01.197515 2026] [security2:error] [pid 255769:tid 255887] [remote 114.34.90.9:33200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.90.34.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9LzbxMYwyVGnfuwsKUfAAEA3U"]
[Tue Jul 21 07:37:01.243796 2026] [security2:error] [pid 255769:tid 255932] [client 85.204.70.100:62449] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9LzbxMYwyVGnfuwsKUfQAAA8Q"]
[Tue Jul 21 07:37:01.262723 2026] [security2:error] [pid 254995:tid 255008] [remote 117.0.21.154:57618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Lzf7v0rlcEGmVraE6uwADdww"]
[Tue Jul 21 07:37:01.265598 2026] [security2:error] [pid 255769:tid 255945] [client 122.186.204.214:55959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LzbxMYwyVGnfuwsKUfgAAA9E"]
[Tue Jul 21 07:37:01.265704 2026] [security2:error] [pid 255769:tid 255945] [client 122.186.204.214:55959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LzbxMYwyVGnfuwsKUfgAAA9E"]
[Tue Jul 21 07:37:01.308631 2026] [autoindex:error] [pid 254995:tid 255191] [client 20.197.195.24:62430] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:01.338932 2026] [security2:error] [pid 254995:tid 255189] [client 20.197.195.24:62430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/adminfuns.php"] [unique_id "al9Lzf7v0rlcEGmVraE6vgAAA14"]
[Tue Jul 21 07:37:01.356536 2026] [security2:error] [pid 255769:tid 255972] [client 82.102.28.107:33010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9LzbxMYwyVGnfuwsKUgwAAA-w"]
[Tue Jul 21 07:37:01.356675 2026] [security2:error] [pid 255769:tid 255972] [client 82.102.28.107:33010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9LzbxMYwyVGnfuwsKUgwAAA-w"]
[Tue Jul 21 07:37:01.626363 2026] [security2:error] [pid 254995:tid 255169] [client 85.204.70.100:53120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9Lzf7v0rlcEGmVraE6wQAAA0o"]
[Tue Jul 21 07:37:01.653852 2026] [security2:error] [pid 255769:tid 255958] [client 20.206.105.145:38093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/155.php"] [unique_id "al9LzbxMYwyVGnfuwsKUhwAAA94"]
[Tue Jul 21 07:37:01.660991 2026] [security2:error] [pid 255769:tid 255903] [client 20.104.96.117:59188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/sym403.php"] [unique_id "al9LzbxMYwyVGnfuwsKUiAAAA6c"]
[Tue Jul 21 07:37:01.751739 2026] [security2:error] [pid 255769:tid 255918] [client 20.197.195.24:51804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/x.php"] [unique_id "al9LzbxMYwyVGnfuwsKUigAAA7Y"]
[Tue Jul 21 07:37:01.858932 2026] [security2:error] [pid 254995:tid 255064] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lzf7v0rlcEGmVraE6ywADi0Q"]
[Tue Jul 21 07:37:01.859088 2026] [security2:error] [pid 254995:tid 255261] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lzf7v0rlcEGmVraE6ywADi0Q"]
[Tue Jul 21 07:37:01.902807 2026] [security2:error] [pid 255769:tid 255992] [client 152.59.154.239:56722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LzbxMYwyVGnfuwsKUjgAAA_8"]
[Tue Jul 21 07:37:01.902925 2026] [security2:error] [pid 255769:tid 255992] [client 152.59.154.239:56722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LzbxMYwyVGnfuwsKUjgAAA_8"]
[Tue Jul 21 07:37:02.000211 2026] [security2:error] [pid 255769:tid 255911] [client 85.204.70.100:53128] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9LzbxMYwyVGnfuwsKUkAAAA68"]
[Tue Jul 21 07:37:02.216299 2026] [security2:error] [pid 254995:tid 255095] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lzv7v0rlcEGmVraE61QADJmM"]
[Tue Jul 21 07:37:02.216420 2026] [security2:error] [pid 254995:tid 255133] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lzv7v0rlcEGmVraE61QADJmM"]
[Tue Jul 21 07:37:02.217177 2026] [security2:error] [pid 255769:tid 255966] [client 20.197.195.24:51805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/155.php"] [unique_id "al9LzrxMYwyVGnfuwsKUkwAAA-Y"]
[Tue Jul 21 07:37:02.218695 2026] [security2:error] [pid 255769:tid 255974] [client 20.226.60.151:27612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/k.php"] [unique_id "al9LzrxMYwyVGnfuwsKUlAAAA-4"]
[Tue Jul 21 07:37:02.233430 2026] [security2:error] [pid 255769:tid 255941] [client 20.151.10.161:45955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/j260624_13.php"] [unique_id "al9LzrxMYwyVGnfuwsKUlgAAA80"]
[Tue Jul 21 07:37:02.234495 2026] [security2:error] [pid 255769:tid 256021] [client 20.226.60.151:51299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/xwpg.php"] [unique_id "al9LzrxMYwyVGnfuwsKUlwAABBs"]
[Tue Jul 21 07:37:02.355841 2026] [security2:error] [pid 254995:tid 255161] [client 20.206.105.145:38943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9Lzv7v0rlcEGmVraE62wAAA0I"]
[Tue Jul 21 07:37:02.374292 2026] [security2:error] [pid 254995:tid 255134] [client 85.204.70.100:53132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9Lzv7v0rlcEGmVraE63AAAAyc"]
[Tue Jul 21 07:37:02.426610 2026] [security2:error] [pid 254995:tid 255145] [client 20.197.195.24:13196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/goods.php"] [unique_id "al9Lzv7v0rlcEGmVraE63gAAAzI"]
[Tue Jul 21 07:37:02.499301 2026] [security2:error] [pid 255769:tid 255956] [client 20.197.195.24:51802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/ops.php"] [unique_id "al9LzrxMYwyVGnfuwsKUnQAAA9w"]
[Tue Jul 21 07:37:02.565647 2026] [autoindex:error] [pid 254995:tid 255053] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:02.581119 2026] [security2:error] [pid 255769:tid 255934] [client 45.8.17.57:38173] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "al9LzrxMYwyVGnfuwsKUngAAA8Y"]
[Tue Jul 21 07:37:02.612502 2026] [security2:error] [pid 254995:tid 255263] [client 20.197.195.24:51736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/file31.php"] [unique_id "al9Lzv7v0rlcEGmVraE66wAAA40"]
[Tue Jul 21 07:37:02.759942 2026] [security2:error] [pid 254995:tid 255213] [client 85.204.70.100:42981] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9Lzv7v0rlcEGmVraE7BgAAA3U"]
[Tue Jul 21 07:37:02.841701 2026] [security2:error] [pid 255769:tid 256014] [client 20.197.195.24:51720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/file6.php"] [unique_id "al9LzrxMYwyVGnfuwsKUoQAABBQ"]
[Tue Jul 21 07:37:02.921244 2026] [security2:error] [pid 254995:tid 255092] [remote 4.205.168.44:58076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/wp-login.php"] [unique_id "al9Lzf7v0rlcEGmVraE6zQADb2A"]
[Tue Jul 21 07:37:03.038340 2026] [security2:error] [pid 254995:tid 255256] [client 20.206.105.145:38943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/aaa.php"] [unique_id "al9Lz_7v0rlcEGmVraE7FAAAA4Y"]
[Tue Jul 21 07:37:03.042179 2026] [security2:error] [pid 254995:tid 255173] [client 20.104.96.117:59187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/v543.php"] [unique_id "al9Lz_7v0rlcEGmVraE7FQAAA04"]
[Tue Jul 21 07:37:03.116651 2026] [security2:error] [pid 254995:tid 255273] [client 20.206.105.145:38527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/ppp.php"] [unique_id "al9Lz_7v0rlcEGmVraE7GwAAA5c"]
[Tue Jul 21 07:37:03.131453 2026] [security2:error] [pid 254995:tid 255177] [client 85.204.70.100:53156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Lz_7v0rlcEGmVraE7HAAAA1I"]
[Tue Jul 21 07:37:03.152678 2026] [security2:error] [pid 254995:tid 255194] [client 175.45.70.82:61404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lz_7v0rlcEGmVraE7HQAAA2M"]
[Tue Jul 21 07:37:03.152782 2026] [security2:error] [pid 254995:tid 255194] [client 175.45.70.82:61404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lz_7v0rlcEGmVraE7HQAAA2M"]
[Tue Jul 21 07:37:03.274733 2026] [security2:error] [pid 255769:tid 255984] [client 122.162.144.145:29071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Lz7xMYwyVGnfuwsKUpwAAA_g"]
[Tue Jul 21 07:37:03.274838 2026] [security2:error] [pid 255769:tid 255984] [client 122.162.144.145:29071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Lz7xMYwyVGnfuwsKUpwAAA_g"]
[Tue Jul 21 07:37:03.459537 2026] [autoindex:error] [pid 254995:tid 255254] [client 20.197.195.24:51837] AH01276: Cannot serve directory /home3/equote29/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:03.469206 2026] [security2:error] [pid 254995:tid 255205] [client 20.197.195.24:51837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/adminfuns.php"] [unique_id "al9Lz_7v0rlcEGmVraE7KQAAA24"]
[Tue Jul 21 07:37:03.512604 2026] [security2:error] [pid 255769:tid 255977] [client 85.204.70.100:1254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Lz7xMYwyVGnfuwsKUqgAAA_E"]
[Tue Jul 21 07:37:03.748533 2026] [security2:error] [pid 255769:tid 255936] [client 154.192.233.199:58615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lz7xMYwyVGnfuwsKUrwAAA8g"]
[Tue Jul 21 07:37:03.748664 2026] [security2:error] [pid 255769:tid 255936] [client 154.192.233.199:58615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lz7xMYwyVGnfuwsKUrwAAA8g"]
[Tue Jul 21 07:37:03.814995 2026] [security2:error] [pid 254995:tid 255190] [client 103.106.20.201:50243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lz_7v0rlcEGmVraE7MAAAA18"]
[Tue Jul 21 07:37:03.815110 2026] [security2:error] [pid 254995:tid 255190] [client 103.106.20.201:50243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lz_7v0rlcEGmVraE7MAAAA18"]
[Tue Jul 21 07:37:03.889349 2026] [security2:error] [pid 255769:tid 255965] [client 85.204.70.100:53200] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9Lz7xMYwyVGnfuwsKUtgAAA-U"]
[Tue Jul 21 07:37:03.922548 2026] [autoindex:error] [pid 254995:tid 254996] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:03.932054 2026] [autoindex:error] [pid 254995:tid 255027] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:04.190924 2026] [security2:error] [pid 255769:tid 255833] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L0LxMYwyVGnfuwsKUvAAEGz8"]
[Tue Jul 21 07:37:04.191094 2026] [security2:error] [pid 255769:tid 256021] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L0LxMYwyVGnfuwsKUvAAEGz8"]
[Tue Jul 21 07:37:04.219748 2026] [security2:error] [pid 255769:tid 255959] [client 20.197.195.24:62862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/100.php"] [unique_id "al9L0LxMYwyVGnfuwsKUvgAAA98"]
[Tue Jul 21 07:37:04.226479 2026] [security2:error] [pid 255769:tid 256009] [client 20.104.96.117:59196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/sixxis.php"] [unique_id "al9L0LxMYwyVGnfuwsKUvwAABA8"]
[Tue Jul 21 07:37:04.273777 2026] [security2:error] [pid 255769:tid 255954] [client 85.204.70.100:53210] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9L0LxMYwyVGnfuwsKUwQAAA9o"]
[Tue Jul 21 07:37:04.310594 2026] [security2:error] [pid 255769:tid 255836] [remote 185.115.217.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.217.115.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9L0LxMYwyVGnfuwsKUxAAD8kI"]
[Tue Jul 21 07:37:04.310784 2026] [security2:error] [pid 255769:tid 255978] [client 185.115.217.185:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9L0LxMYwyVGnfuwsKUxAAD8kI"]
[Tue Jul 21 07:37:04.480407 2026] [security2:error] [pid 255769:tid 255932] [client 20.206.105.145:37926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/201.php"] [unique_id "al9L0LxMYwyVGnfuwsKUyQAAA8Q"]
[Tue Jul 21 07:37:04.545741 2026] [security2:error] [pid 255769:tid 255972] [client 20.197.195.24:51836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/goods.php"] [unique_id "al9L0LxMYwyVGnfuwsKUzAAAA-w"]
[Tue Jul 21 07:37:04.645998 2026] [security2:error] [pid 255769:tid 255921] [client 85.204.70.100:53218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9L0LxMYwyVGnfuwsKUzgAAA7k"]
[Tue Jul 21 07:37:04.678057 2026] [security2:error] [pid 255769:tid 255923] [client 20.151.10.161:45965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/d62.php"] [unique_id "al9L0LxMYwyVGnfuwsKUzwAAA7s"]
[Tue Jul 21 07:37:05.032393 2026] [security2:error] [pid 255769:tid 255940] [client 85.204.70.100:53232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9L0bxMYwyVGnfuwsKU2QAAA8w"]
[Tue Jul 21 07:37:05.100224 2026] [security2:error] [pid 255769:tid 256005] [client 20.226.60.151:27541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/blurbs.php"] [unique_id "al9L0bxMYwyVGnfuwsKU2gAABAs"]
[Tue Jul 21 07:37:05.159656 2026] [security2:error] [pid 255769:tid 255955] [client 122.164.127.47:53445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9L0bxMYwyVGnfuwsKU3QAAA9s"]
[Tue Jul 21 07:37:05.159763 2026] [security2:error] [pid 255769:tid 255955] [client 122.164.127.47:53445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9L0bxMYwyVGnfuwsKU3QAAA9s"]
[Tue Jul 21 07:37:05.237256 2026] [security2:error] [pid 255769:tid 256028] [client 20.197.195.24:51747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/100.php"] [unique_id "al9L0bxMYwyVGnfuwsKU4AAABCI"]
[Tue Jul 21 07:37:05.333474 2026] [security2:error] [pid 254995:tid 255264] [client 173.252.95.7:41270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9L0f7v0rlcEGmVraE7bgAAA44"]
[Tue Jul 21 07:37:05.553458 2026] [security2:error] [pid 254995:tid 255152] [client 20.220.225.223:31190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/ops.php"] [unique_id "al9L0f7v0rlcEGmVraE7kQAAAzk"]
[Tue Jul 21 07:37:05.658018 2026] [security2:error] [pid 254995:tid 255149] [client 173.252.95.37:57544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9L0f7v0rlcEGmVraE7mwAAAzY"]
[Tue Jul 21 07:37:05.751630 2026] [security2:error] [pid 255769:tid 255910] [client 20.197.195.24:51766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/about.php"] [unique_id "al9L0bxMYwyVGnfuwsKU7AAAA64"]
[Tue Jul 21 07:37:05.757266 2026] [security2:error] [pid 255769:tid 256008] [client 20.206.105.145:38081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/ops.php"] [unique_id "al9L0bxMYwyVGnfuwsKU7QAABA4"]
[Tue Jul 21 07:37:05.845633 2026] [security2:error] [pid 255769:tid 255929] [client 20.104.96.117:61146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/ip.php"] [unique_id "al9L0bxMYwyVGnfuwsKU7gAAA8E"]
[Tue Jul 21 07:37:05.856196 2026] [security2:error] [pid 255769:tid 255919] [client 172.245.102.45:39807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Lz7xMYwyVGnfuwsKUrgAAA7c"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:06.015159 2026] [security2:error] [pid 255769:tid 255959] [client 103.174.34.15:57619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L0rxMYwyVGnfuwsKU8QAAA98"]
[Tue Jul 21 07:37:06.015254 2026] [security2:error] [pid 255769:tid 255959] [client 103.174.34.15:57619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L0rxMYwyVGnfuwsKU8QAAA98"]
[Tue Jul 21 07:37:06.124334 2026] [autoindex:error] [pid 254995:tid 255101] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:06.136602 2026] [autoindex:error] [pid 254995:tid 255083] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/blocks/shortcode/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:06.165699 2026] [security2:error] [pid 255769:tid 255908] [client 20.226.60.151:27585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/bajah.php"] [unique_id "al9L0rxMYwyVGnfuwsKU9AAAA6w"]
[Tue Jul 21 07:37:06.219719 2026] [security2:error] [pid 255769:tid 255921] [client 20.151.10.161:46071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ups.php"] [unique_id "al9L0rxMYwyVGnfuwsKU9wAAA7k"]
[Tue Jul 21 07:37:06.238755 2026] [security2:error] [pid 254995:tid 255068] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9L0v7v0rlcEGmVraE7sgADfkg"]
[Tue Jul 21 07:37:06.238889 2026] [security2:error] [pid 254995:tid 255222] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9L0v7v0rlcEGmVraE7sgADfkg"]
[Tue Jul 21 07:37:06.346295 2026] [security2:error] [pid 255769:tid 256015] [client 45.8.17.121:31793] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/bltm/wp-login.php"] [unique_id "al9L0bxMYwyVGnfuwsKU3gAABBU"]
[Tue Jul 21 07:37:06.526112 2026] [security2:error] [pid 255769:tid 255990] [client 20.197.195.24:51793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/about.php"] [unique_id "al9L0rxMYwyVGnfuwsKU_QAAA_4"]
[Tue Jul 21 07:37:06.713496 2026] [security2:error] [pid 255769:tid 255965] [client 20.197.195.24:51776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/admin.php"] [unique_id "al9L0rxMYwyVGnfuwsKVAQAAA-U"]
[Tue Jul 21 07:37:06.967239 2026] [security2:error] [pid 254995:tid 255127] [client 20.226.60.151:51304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ops.php"] [unique_id "al9L0v7v0rlcEGmVraE7vgAAAyA"]
[Tue Jul 21 07:37:07.236906 2026] [security2:error] [pid 255769:tid 255992] [client 20.104.96.117:61077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/kq1.php"] [unique_id "al9L07xMYwyVGnfuwsKVBwAAA_8"]
[Tue Jul 21 07:37:07.258119 2026] [security2:error] [pid 254995:tid 255184] [client 20.197.195.24:51714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/admin.php"] [unique_id "al9L0_7v0rlcEGmVraE7xAAAA1k"]
[Tue Jul 21 07:37:07.267822 2026] [security2:error] [pid 254995:tid 255055] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L0_7v0rlcEGmVraE7xQADbDs"]
[Tue Jul 21 07:37:07.268008 2026] [security2:error] [pid 254995:tid 255203] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L0_7v0rlcEGmVraE7xQADbDs"]
[Tue Jul 21 07:37:07.282042 2026] [autoindex:error] [pid 254995:tid 255044] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:07.336495 2026] [security2:error] [pid 254995:tid 255066] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L0_7v0rlcEGmVraE7yAADmUY"]
[Tue Jul 21 07:37:07.336634 2026] [security2:error] [pid 254995:tid 255275] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L0_7v0rlcEGmVraE7yAADmUY"]
[Tue Jul 21 07:37:07.370548 2026] [security2:error] [pid 254995:tid 255090] [remote 45.90.123.233:34526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "growe-ag.jaypi.com.br"] [uri "/wp-login.php"] [unique_id "al9L0_7v0rlcEGmVraE7yQADiV4"]
[Tue Jul 21 07:37:07.451889 2026] [security2:error] [pid 255769:tid 255944] [client 20.206.105.145:38473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/ingfo.php"] [unique_id "al9L07xMYwyVGnfuwsKVDAAAA9A"]
[Tue Jul 21 07:37:07.573128 2026] [security2:error] [pid 255769:tid 255967] [client 45.8.17.122:35479] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/includes/nav.php"] [unique_id "al9L07xMYwyVGnfuwsKVEAAAA-c"]
[Tue Jul 21 07:37:07.617198 2026] [security2:error] [pid 255769:tid 255988] [client 82.102.28.107:34332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9L07xMYwyVGnfuwsKVEQAAA_w"]
[Tue Jul 21 07:37:07.617294 2026] [security2:error] [pid 255769:tid 255988] [client 82.102.28.107:34332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9L07xMYwyVGnfuwsKVEQAAA_w"]
[Tue Jul 21 07:37:07.619851 2026] [security2:error] [pid 255769:tid 255955] [client 59.96.220.140:58201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9L07xMYwyVGnfuwsKVEgAAA9s"]
[Tue Jul 21 07:37:07.621363 2026] [security2:error] [pid 255769:tid 255955] [client 59.96.220.140:58201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9L07xMYwyVGnfuwsKVEgAAA9s"]
[Tue Jul 21 07:37:07.641451 2026] [security2:error] [pid 254995:tid 255201] [client 20.220.225.223:31110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/term.php"] [unique_id "al9L0_7v0rlcEGmVraE7zgAAA2o"]
[Tue Jul 21 07:37:08.348252 2026] [security2:error] [pid 255769:tid 255921] [client 20.197.195.24:62417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/about.php"] [unique_id "al9L1LxMYwyVGnfuwsKVGwAAA7k"]
[Tue Jul 21 07:37:08.422604 2026] [security2:error] [pid 254995:tid 255145] [client 20.104.96.117:59177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9L1P7v0rlcEGmVraE71AAAAzI"]
[Tue Jul 21 07:37:08.465003 2026] [security2:error] [pid 255769:tid 255929] [client 103.86.117.203:53061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L1LxMYwyVGnfuwsKVHQAAA8E"]
[Tue Jul 21 07:37:08.465172 2026] [security2:error] [pid 255769:tid 255929] [client 103.86.117.203:53061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L1LxMYwyVGnfuwsKVHQAAA8E"]
[Tue Jul 21 07:37:08.476682 2026] [security2:error] [pid 255769:tid 255923] [client 20.226.60.151:27613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/a.php"] [unique_id "al9L1LxMYwyVGnfuwsKVHgAAA7s"]
[Tue Jul 21 07:37:08.492520 2026] [security2:error] [pid 255769:tid 255984] [client 45.8.17.123:65391] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/shell3.php"] [unique_id "al9L1LxMYwyVGnfuwsKVHwAAA_g"]
[Tue Jul 21 07:37:08.619902 2026] [security2:error] [pid 254995:tid 255149] [client 20.197.195.24:21037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/themes.php"] [unique_id "al9L1P7v0rlcEGmVraE72gAAAzY"]
[Tue Jul 21 07:37:08.953402 2026] [security2:error] [pid 255769:tid 255940] [client 20.220.225.223:49564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/tkikikoko.php"] [unique_id "al9L1LxMYwyVGnfuwsKVIwAAA8w"]
[Tue Jul 21 07:37:09.154799 2026] [security2:error] [pid 254995:tid 255274] [client 20.104.96.117:59684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/h02ugyh.php"] [unique_id "al9L1f7v0rlcEGmVraE74gAAA5g"]
[Tue Jul 21 07:37:09.284564 2026] [security2:error] [pid 254995:tid 255164] [client 20.226.60.151:51390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/mac.php"] [unique_id "al9L1f7v0rlcEGmVraE76QAAA0U"]
[Tue Jul 21 07:37:09.363618 2026] [security2:error] [pid 255769:tid 255983] [client 20.197.195.24:62863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/about.php"] [unique_id "al9L1bxMYwyVGnfuwsKVJgAAA_c"]
[Tue Jul 21 07:37:09.429796 2026] [security2:error] [pid 254995:tid 255222] [client 213.152.162.104:56142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9L1f7v0rlcEGmVraE77QAAA34"]
[Tue Jul 21 07:37:09.429898 2026] [security2:error] [pid 254995:tid 255222] [client 213.152.162.104:56142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9L1f7v0rlcEGmVraE77QAAA34"]
[Tue Jul 21 07:37:09.518611 2026] [security2:error] [pid 255769:tid 255985] [client 20.104.96.117:59159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-temp.php"] [unique_id "al9L1bxMYwyVGnfuwsKVKAAAA_k"]
[Tue Jul 21 07:37:09.557520 2026] [security2:error] [pid 255769:tid 256004] [client 45.251.232.145:64262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L1bxMYwyVGnfuwsKVKQAABAo"]
[Tue Jul 21 07:37:09.557617 2026] [security2:error] [pid 255769:tid 256004] [client 45.251.232.145:64262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L1bxMYwyVGnfuwsKVKQAABAo"]
[Tue Jul 21 07:37:09.666183 2026] [autoindex:error] [pid 254995:tid 255169] [client 20.197.195.24:51739] AH01276: Cannot serve directory /home3/equote29/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:09.793553 2026] [security2:error] [pid 254995:tid 255158] [client 20.151.10.161:45954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/k.php"] [unique_id "al9L1f7v0rlcEGmVraE7_QAAAz8"]
[Tue Jul 21 07:37:09.912481 2026] [security2:error] [pid 255769:tid 255915] [client 139.167.225.182:62297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L1bxMYwyVGnfuwsKVKwAAA7M"]
[Tue Jul 21 07:37:09.912596 2026] [security2:error] [pid 255769:tid 255915] [client 139.167.225.182:62297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L1bxMYwyVGnfuwsKVKwAAA7M"]
[Tue Jul 21 07:37:09.926593 2026] [security2:error] [pid 255769:tid 255790] [remote 173.212.252.15:55992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9L1bxMYwyVGnfuwsKVLAADtBQ"]
[Tue Jul 21 07:37:09.974269 2026] [security2:error] [pid 254995:tid 255223] [client 45.8.17.63:33529] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/hplfuns.php"] [unique_id "al9L1f7v0rlcEGmVraE8AwAAA38"]
[Tue Jul 21 07:37:09.982553 2026] [autoindex:error] [pid 254995:tid 255043] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:09.985274 2026] [autoindex:error] [pid 254995:tid 255084] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:10.016506 2026] [security2:error] [pid 255769:tid 255969] [client 20.220.225.223:49555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-Blogs.php"] [unique_id "al9L1rxMYwyVGnfuwsKVLgAAA-k"]
[Tue Jul 21 07:37:10.056363 2026] [security2:error] [pid 255769:tid 255902] [client 20.197.195.24:62857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/admin.php"] [unique_id "al9L1rxMYwyVGnfuwsKVMAAAA6Y"]
[Tue Jul 21 07:37:10.273510 2026] [security2:error] [pid 255769:tid 255910] [client 20.104.96.117:59700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9L1rxMYwyVGnfuwsKVNAAAA64"]
[Tue Jul 21 07:37:10.437767 2026] [security2:error] [pid 255769:tid 255997] [client 20.220.225.223:38667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/ah25.php"] [unique_id "al9L1rxMYwyVGnfuwsKVOgAABAM"]
[Tue Jul 21 07:37:10.462210 2026] [security2:error] [pid 255769:tid 255945] [client 20.197.195.24:62431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/admin.php"] [unique_id "al9L1rxMYwyVGnfuwsKVOwAAA9E"]
[Tue Jul 21 07:37:10.780825 2026] [security2:error] [pid 255769:tid 255927] [client 193.36.225.64:50385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9L1rxMYwyVGnfuwsKVPQAAA78"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:10.962671 2026] [autoindex:error] [pid 254995:tid 255042] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/blocks/shortcode/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:10.963276 2026] [autoindex:error] [pid 254995:tid 255025] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/js/codemirror/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:10.986977 2026] [security2:error] [pid 254995:tid 255185] [client 45.8.17.128:49035] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/admin/index.php"] [unique_id "al9L1v7v0rlcEGmVraE8FQAAA1o"]
[Tue Jul 21 07:37:11.047652 2026] [security2:error] [pid 255769:tid 255980] [client 20.197.195.24:62859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/themes.php"] [unique_id "al9L17xMYwyVGnfuwsKVRAAAA_Q"]
[Tue Jul 21 07:37:11.180913 2026] [security2:error] [pid 255769:tid 255932] [client 117.217.38.194:51216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L17xMYwyVGnfuwsKVRwAAA8Q"]
[Tue Jul 21 07:37:11.181047 2026] [security2:error] [pid 255769:tid 255932] [client 117.217.38.194:51216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L17xMYwyVGnfuwsKVRwAAA8Q"]
[Tue Jul 21 07:37:11.224669 2026] [security2:error] [pid 255769:tid 255918] [client 20.104.96.117:59142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9L17xMYwyVGnfuwsKVSgAAA7Y"]
[Tue Jul 21 07:37:11.242375 2026] [security2:error] [pid 255769:tid 255975] [client 20.226.60.151:51388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/mg.php"] [unique_id "al9L17xMYwyVGnfuwsKVTAAAA-8"]
[Tue Jul 21 07:37:11.309510 2026] [security2:error] [pid 254995:tid 255132] [client 117.251.86.144:54770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9L1_7v0rlcEGmVraE8HQAAAyU"]
[Tue Jul 21 07:37:11.309608 2026] [security2:error] [pid 254995:tid 255132] [client 117.251.86.144:54770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9L1_7v0rlcEGmVraE8HQAAAyU"]
[Tue Jul 21 07:37:11.361286 2026] [security2:error] [pid 254995:tid 255186] [client 173.24.185.52:55698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9L1_7v0rlcEGmVraE8HgAAA1s"]
[Tue Jul 21 07:37:11.361420 2026] [security2:error] [pid 254995:tid 255186] [client 173.24.185.52:55698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9L1_7v0rlcEGmVraE8HgAAA1s"]
[Tue Jul 21 07:37:11.497899 2026] [security2:error] [pid 255769:tid 255923] [client 103.162.129.114:54621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9L17xMYwyVGnfuwsKVTgAAA7s"]
[Tue Jul 21 07:37:11.498057 2026] [security2:error] [pid 255769:tid 255923] [client 103.162.129.114:54621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9L17xMYwyVGnfuwsKVTgAAA7s"]
[Tue Jul 21 07:37:11.659108 2026] [security2:error] [pid 254995:tid 255136] [client 20.226.60.151:27554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/edit.php"] [unique_id "al9L1_7v0rlcEGmVraE8JAAAAyk"]
[Tue Jul 21 07:37:11.699229 2026] [autoindex:error] [pid 254995:tid 255274] [client 20.197.195.24:62897] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:11.864790 2026] [security2:error] [pid 254995:tid 255156] [client 20.104.96.117:59147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/jj.php"] [unique_id "al9L1_7v0rlcEGmVraE8KgAAAz0"]
[Tue Jul 21 07:37:12.055405 2026] [security2:error] [pid 254995:tid 255263] [client 122.186.204.214:56483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L2P7v0rlcEGmVraE8LwAAA40"]
[Tue Jul 21 07:37:12.077564 2026] [security2:error] [pid 254995:tid 255263] [client 122.186.204.214:56483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L2P7v0rlcEGmVraE8LwAAA40"]
[Tue Jul 21 07:37:12.266363 2026] [security2:error] [pid 254995:tid 255215] [client 82.102.28.107:42150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9L2P7v0rlcEGmVraE8MwAAA3c"]
[Tue Jul 21 07:37:12.266455 2026] [security2:error] [pid 254995:tid 255215] [client 82.102.28.107:42150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9L2P7v0rlcEGmVraE8MwAAA3c"]
[Tue Jul 21 07:37:12.337074 2026] [security2:error] [pid 254995:tid 255277] [client 20.104.96.117:61154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9L2P7v0rlcEGmVraE8NgAAA5s"]
[Tue Jul 21 07:37:12.364293 2026] [security2:error] [pid 254995:tid 255076] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9L2P7v0rlcEGmVraE8NwADklA"]
[Tue Jul 21 07:37:12.364468 2026] [security2:error] [pid 254995:tid 255268] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9L2P7v0rlcEGmVraE8NwADklA"]
[Tue Jul 21 07:37:12.633730 2026] [security2:error] [pid 254995:tid 255117] [remote 124.55.178.99:48542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supremaservices.net"] [uri "/wp-login.php"] [unique_id "al9L2P7v0rlcEGmVraE8PQADY3k"]
[Tue Jul 21 07:37:12.661195 2026] [security2:error] [pid 254995:tid 255214] [client 20.197.195.24:51739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/.well-known/about.php"] [unique_id "al9L2P7v0rlcEGmVraE8PgAAA3Y"]
[Tue Jul 21 07:37:12.763575 2026] [security2:error] [pid 255769:tid 255978] [client 20.206.105.145:37950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/error_log.php"] [unique_id "al9L2LxMYwyVGnfuwsKVXgAAA_I"]
[Tue Jul 21 07:37:12.794654 2026] [autoindex:error] [pid 254995:tid 255107] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:12.799190 2026] [security2:error] [pid 254995:tid 255019] [remote 207.180.241.245:45724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "issimastore.com"] [uri "/wp-login.php"] [unique_id "al9L2P7v0rlcEGmVraE8QwADIhc"]
[Tue Jul 21 07:37:12.804369 2026] [autoindex:error] [pid 254995:tid 255072] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/js/plupload/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:13.009578 2026] [security2:error] [pid 255769:tid 255818] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2bxMYwyVGnfuwsKVYQAD_DA"]
[Tue Jul 21 07:37:13.009717 2026] [security2:error] [pid 255769:tid 255988] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2bxMYwyVGnfuwsKVYQAD_DA"]
[Tue Jul 21 07:37:13.066847 2026] [security2:error] [pid 254995:tid 255278] [client 20.104.96.117:61122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/txets.php"] [unique_id "al9L2f7v0rlcEGmVraE8SQAAA5w"]
[Tue Jul 21 07:37:13.072145 2026] [security2:error] [pid 255769:tid 255919] [client 20.220.225.223:38697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/8.php"] [unique_id "al9L2bxMYwyVGnfuwsKVYgAAA7c"]
[Tue Jul 21 07:37:13.177434 2026] [security2:error] [pid 254995:tid 255161] [client 45.8.17.48:55155] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/admin-wolf.php"] [unique_id "al9L2f7v0rlcEGmVraE8TQAAA0I"]
[Tue Jul 21 07:37:13.197606 2026] [security2:error] [pid 254995:tid 255185] [client 20.52.136.55:1589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/article.php"] [unique_id "al9L2f7v0rlcEGmVraE8TgAAA1o"]
[Tue Jul 21 07:37:13.332308 2026] [security2:error] [pid 254995:tid 255130] [client 20.197.195.24:62897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/.well-known/about.php"] [unique_id "al9L2f7v0rlcEGmVraE8UAAAAyM"]
[Tue Jul 21 07:37:13.427980 2026] [security2:error] [pid 255769:tid 255945] [client 20.104.96.117:59170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/dex.php"] [unique_id "al9L2bxMYwyVGnfuwsKVZQAAA9E"]
[Tue Jul 21 07:37:13.472868 2026] [security2:error] [pid 254995:tid 255173] [client 152.59.154.239:57219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2f7v0rlcEGmVraE8UwAAA04"]
[Tue Jul 21 07:37:13.473004 2026] [security2:error] [pid 254995:tid 255173] [client 152.59.154.239:57219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2f7v0rlcEGmVraE8UwAAA04"]
[Tue Jul 21 07:37:13.636891 2026] [security2:error] [pid 255769:tid 256025] [client 20.197.195.24:51748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9L2bxMYwyVGnfuwsKVZwAABB8"]
[Tue Jul 21 07:37:13.906186 2026] [security2:error] [pid 254995:tid 255156] [client 20.104.96.117:61128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/xpwer1.php"] [unique_id "al9L2f7v0rlcEGmVraE8XAAAAz0"]
[Tue Jul 21 07:37:13.961725 2026] [security2:error] [pid 255769:tid 255971] [client 175.45.70.82:61918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2bxMYwyVGnfuwsKVbgAAA-s"]
[Tue Jul 21 07:37:13.961853 2026] [security2:error] [pid 255769:tid 255971] [client 175.45.70.82:61918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2bxMYwyVGnfuwsKVbgAAA-s"]
[Tue Jul 21 07:37:13.967083 2026] [security2:error] [pid 255769:tid 255943] [client 20.197.195.24:62889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9L2bxMYwyVGnfuwsKVbwAAA88"]
[Tue Jul 21 07:37:14.038017 2026] [security2:error] [pid 254995:tid 255152] [client 122.162.144.145:19297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9L2v7v0rlcEGmVraE8ZQAAAzk"]
[Tue Jul 21 07:37:14.038196 2026] [security2:error] [pid 254995:tid 255152] [client 122.162.144.145:19297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9L2v7v0rlcEGmVraE8ZQAAAzk"]
[Tue Jul 21 07:37:14.073001 2026] [security2:error] [pid 254995:tid 255177] [client 45.8.17.135:56087] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "al9L2v7v0rlcEGmVraE8ZgAAA1I"]
[Tue Jul 21 07:37:14.076042 2026] [security2:error] [pid 254995:tid 255195] [client 20.151.10.161:46058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/k2.php"] [unique_id "al9L2v7v0rlcEGmVraE8ZwAAA2Q"]
[Tue Jul 21 07:37:14.340576 2026] [security2:error] [pid 255769:tid 255975] [client 20.197.195.24:62403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wefile.php"] [unique_id "al9L2rxMYwyVGnfuwsKVdgAAA-8"]
[Tue Jul 21 07:37:14.515991 2026] [security2:error] [pid 254995:tid 255143] [client 20.104.96.117:59679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/flox.php"] [unique_id "al9L2v7v0rlcEGmVraE8cAAAAzA"]
[Tue Jul 21 07:37:14.533014 2026] [security2:error] [pid 254995:tid 255147] [client 154.192.233.199:59925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2v7v0rlcEGmVraE8cQAAAzQ"]
[Tue Jul 21 07:37:14.533152 2026] [security2:error] [pid 254995:tid 255147] [client 154.192.233.199:59925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2v7v0rlcEGmVraE8cQAAAzQ"]
[Tue Jul 21 07:37:14.551425 2026] [security2:error] [pid 254995:tid 255180] [client 20.197.195.24:62860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9L2v7v0rlcEGmVraE8cgAAA1U"]
[Tue Jul 21 07:37:14.588993 2026] [security2:error] [pid 255769:tid 255984] [client 103.106.20.201:50826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2rxMYwyVGnfuwsKVdwAAA_g"]
[Tue Jul 21 07:37:14.589133 2026] [security2:error] [pid 255769:tid 255984] [client 103.106.20.201:50826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2rxMYwyVGnfuwsKVdwAAA_g"]
[Tue Jul 21 07:37:14.685477 2026] [security2:error] [pid 254995:tid 255131] [client 20.197.195.24:51740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wefile.php"] [unique_id "al9L2v7v0rlcEGmVraE8cwAAAyQ"]
[Tue Jul 21 07:37:14.697626 2026] [security2:error] [pid 254995:tid 255070] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2v7v0rlcEGmVraE8dAADf0o"]
[Tue Jul 21 07:37:14.697768 2026] [security2:error] [pid 254995:tid 255223] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2v7v0rlcEGmVraE8dAADf0o"]
[Tue Jul 21 07:37:14.703347 2026] [autoindex:error] [pid 255769:tid 255923] [client 104.28.234.178:61991] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/conhecaonordeste.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:14.751888 2026] [autoindex:error] [pid 255769:tid 255906] [client 20.197.195.24:62901] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:14.810125 2026] [autoindex:error] [pid 255769:tid 255958] [client 20.197.195.24:62901] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:14.833488 2026] [security2:error] [pid 255769:tid 255937] [client 20.197.195.24:62901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9L2rxMYwyVGnfuwsKVfwAAA8k"]
[Tue Jul 21 07:37:14.841394 2026] [security2:error] [pid 254995:tid 255168] [client 20.220.225.223:48191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-css.php"] [unique_id "al9L2v7v0rlcEGmVraE8eQAAA0k"]
[Tue Jul 21 07:37:14.927426 2026] [security2:error] [pid 255769:tid 256028] [client 20.197.195.24:62404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/8.php"] [unique_id "al9L2rxMYwyVGnfuwsKVgQAABCI"]
[Tue Jul 21 07:37:14.949130 2026] [security2:error] [pid 255769:tid 256021] [client 20.104.96.117:59694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/popo.php"] [unique_id "al9L2rxMYwyVGnfuwsKVhAAABBs"]
[Tue Jul 21 07:37:14.979310 2026] [security2:error] [pid 255769:tid 255916] [client 45.8.17.115:50243] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/2021/file.php"] [unique_id "al9L2rxMYwyVGnfuwsKVhQAAA7Q"]
[Tue Jul 21 07:37:15.077847 2026] [security2:error] [pid 255769:tid 255902] [client 20.226.60.151:51286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-post-data.php"] [unique_id "al9L27xMYwyVGnfuwsKVhwAAA6Y"]
[Tue Jul 21 07:37:15.124927 2026] [security2:error] [pid 254995:tid 255278] [client 20.197.195.24:51813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9L2_7v0rlcEGmVraE8gQAAA5w"]
[Tue Jul 21 07:37:15.463729 2026] [security2:error] [pid 255769:tid 255988] [client 20.104.96.117:61161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/yas.php"] [unique_id "al9L27xMYwyVGnfuwsKViwAAA_w"]
[Tue Jul 21 07:37:15.547530 2026] [security2:error] [pid 255769:tid 255930] [client 193.36.225.121:35797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9L27xMYwyVGnfuwsKVjQAAA8I"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:37:15.573631 2026] [security2:error] [pid 254995:tid 255165] [client 20.197.195.24:62879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-content/admin.php"] [unique_id "al9L2_7v0rlcEGmVraE8igAAA0Y"]
[Tue Jul 21 07:37:15.635007 2026] [security2:error] [pid 255769:tid 255956] [client 172.245.102.45:21267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9L27xMYwyVGnfuwsKVjgAAA9w"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:15.820506 2026] [security2:error] [pid 255769:tid 255959] [client 20.226.60.151:51323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/pucci.php"] [unique_id "al9L27xMYwyVGnfuwsKVjwAAA98"]
[Tue Jul 21 07:37:15.852079 2026] [security2:error] [pid 255769:tid 255945] [client 20.104.96.117:59139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/file61.php"] [unique_id "al9L27xMYwyVGnfuwsKVkAAAA9E"]
[Tue Jul 21 07:37:15.975527 2026] [security2:error] [pid 255769:tid 256014] [client 20.197.195.24:62866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/f6.php"] [unique_id "al9L27xMYwyVGnfuwsKVkQAABBQ"]
[Tue Jul 21 07:37:16.051769 2026] [security2:error] [pid 254995:tid 255185] [client 122.164.127.47:53950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9L3P7v0rlcEGmVraE8kgAAA1o"]
[Tue Jul 21 07:37:16.051918 2026] [security2:error] [pid 254995:tid 255185] [client 122.164.127.47:53950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9L3P7v0rlcEGmVraE8kgAAA1o"]
[Tue Jul 21 07:37:16.183263 2026] [security2:error] [pid 255769:tid 256016] [client 45.8.17.105:45303] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "al9L3LxMYwyVGnfuwsKVkwAABBY"]
[Tue Jul 21 07:37:16.251314 2026] [autoindex:error] [pid 255769:tid 255922] [client 20.197.195.24:51713] AH01276: Cannot serve directory /home3/equote29/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:16.256040 2026] [security2:error] [pid 255769:tid 255943] [client 20.197.195.24:62890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/inputs.php"] [unique_id "al9L3LxMYwyVGnfuwsKVlQAAA88"]
[Tue Jul 21 07:37:16.306619 2026] [autoindex:error] [pid 255769:tid 256022] [client 20.197.195.24:51713] AH01276: Cannot serve directory /home3/equote29/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:16.341935 2026] [security2:error] [pid 255769:tid 255990] [client 20.226.60.151:27544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/hosty.php"] [unique_id "al9L3LxMYwyVGnfuwsKVmQAAA_4"]
[Tue Jul 21 07:37:16.362712 2026] [security2:error] [pid 255769:tid 255946] [client 20.104.96.117:61171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/water.php"] [unique_id "al9L3LxMYwyVGnfuwsKVmgAAA9I"]
[Tue Jul 21 07:37:16.529667 2026] [security2:error] [pid 254995:tid 255164] [client 20.197.195.24:13246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/inputs.php"] [unique_id "al9L3P7v0rlcEGmVraE8mAAAA0U"]
[Tue Jul 21 07:37:16.763266 2026] [security2:error] [pid 255769:tid 255923] [client 20.197.195.24:51713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9L3LxMYwyVGnfuwsKVnQAAA7s"]
[Tue Jul 21 07:37:16.788469 2026] [security2:error] [pid 255769:tid 255835] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9L3LxMYwyVGnfuwsKVnwAD-UE"]
[Tue Jul 21 07:37:16.788605 2026] [security2:error] [pid 255769:tid 255985] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9L3LxMYwyVGnfuwsKVnwAD-UE"]
[Tue Jul 21 07:37:16.799573 2026] [security2:error] [pid 255769:tid 255937] [client 20.104.96.117:59189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/nano.php"] [unique_id "al9L3LxMYwyVGnfuwsKVoQAAA8k"]
[Tue Jul 21 07:37:16.886775 2026] [security2:error] [pid 255769:tid 256013] [client 20.226.60.151:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/black.php"] [unique_id "al9L3LxMYwyVGnfuwsKVogAABBM"]
[Tue Jul 21 07:37:16.930043 2026] [security2:error] [pid 255769:tid 255960] [client 20.206.105.145:37889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/xenon1337.php"] [unique_id "al9L3LxMYwyVGnfuwsKVowAAA-A"]
[Tue Jul 21 07:37:17.035398 2026] [security2:error] [pid 255769:tid 255941] [client 20.151.10.161:46057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/k3.php"] [unique_id "al9L3bxMYwyVGnfuwsKVpAAAA80"]
[Tue Jul 21 07:37:17.340239 2026] [security2:error] [pid 255769:tid 255978] [client 20.197.195.24:21098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/8.php"] [unique_id "al9L3bxMYwyVGnfuwsKVrAAAA_I"]
[Tue Jul 21 07:37:17.353903 2026] [security2:error] [pid 255769:tid 255961] [client 20.104.96.117:59165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/moon.php"] [unique_id "al9L3bxMYwyVGnfuwsKVrQAAA-E"]
[Tue Jul 21 07:37:17.386341 2026] [security2:error] [pid 255769:tid 255930] [client 45.8.17.108:65069] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/WordPressCore/include.php"] [unique_id "al9L3bxMYwyVGnfuwsKVrgAAA8I"]
[Tue Jul 21 07:37:17.426989 2026] [security2:error] [pid 254995:tid 255190] [client 20.197.195.24:62411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/classwithtostring.php"] [unique_id "al9L3f7v0rlcEGmVraE8pwAAA18"]
[Tue Jul 21 07:37:17.528765 2026] [security2:error] [pid 255769:tid 255858] [remote 124.55.178.99:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samilacalculos.com.br"] [uri "/wp-login.php"] [unique_id "al9L3bxMYwyVGnfuwsKVsQAD3Fg"]
[Tue Jul 21 07:37:17.575333 2026] [security2:error] [pid 254995:tid 255156] [client 103.174.34.15:58106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L3f7v0rlcEGmVraE8qAAAAz0"]
[Tue Jul 21 07:37:17.575432 2026] [security2:error] [pid 254995:tid 255156] [client 103.174.34.15:58106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L3f7v0rlcEGmVraE8qAAAAz0"]
[Tue Jul 21 07:37:17.685432 2026] [security2:error] [pid 254995:tid 255221] [client 20.197.195.24:51744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wp-content/admin.php"] [unique_id "al9L3f7v0rlcEGmVraE8rQAAA30"]
[Tue Jul 21 07:37:17.730522 2026] [security2:error] [pid 254995:tid 255184] [client 20.226.60.151:51382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/zlece.php"] [unique_id "al9L3f7v0rlcEGmVraE8rgAAA1k"]
[Tue Jul 21 07:37:17.829365 2026] [security2:error] [pid 254995:tid 255198] [client 20.197.195.24:51733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/f6.php"] [unique_id "al9L3f7v0rlcEGmVraE8sAAAA2c"]
[Tue Jul 21 07:37:17.888634 2026] [security2:error] [pid 254995:tid 255187] [client 20.197.195.24:51760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/inputs.php"] [unique_id "al9L3f7v0rlcEGmVraE8twAAA1w"]
[Tue Jul 21 07:37:17.949530 2026] [security2:error] [pid 254995:tid 255126] [client 20.104.96.117:61168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-info.php"] [unique_id "al9L3f7v0rlcEGmVraE8uQAAAx8"]
[Tue Jul 21 07:37:17.988810 2026] [security2:error] [pid 255769:tid 255808] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L3bxMYwyVGnfuwsKVtAAEAyY"]
[Tue Jul 21 07:37:17.989003 2026] [security2:error] [pid 255769:tid 255997] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L3bxMYwyVGnfuwsKVtAAEAyY"]
[Tue Jul 21 07:37:17.999729 2026] [security2:error] [pid 254995:tid 255278] [client 20.197.195.24:62408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9L3f7v0rlcEGmVraE8ugAAA5w"]
[Tue Jul 21 07:37:18.012857 2026] [security2:error] [pid 254995:tid 255264] [client 20.197.195.24:21119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/inputs.php"] [unique_id "al9L3v7v0rlcEGmVraE8uwAAA44"]
[Tue Jul 21 07:37:18.122958 2026] [security2:error] [pid 255769:tid 255921] [client 20.220.225.223:38682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9L3rxMYwyVGnfuwsKVtgAAA7k"]
[Tue Jul 21 07:37:18.161278 2026] [security2:error] [pid 254995:tid 255197] [client 20.197.195.24:51726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/classwithtostring.php"] [unique_id "al9L3v7v0rlcEGmVraE8vwAAA2Y"]
[Tue Jul 21 07:37:18.204941 2026] [security2:error] [pid 255769:tid 256015] [client 213.152.162.104:54814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9L3rxMYwyVGnfuwsKVuQAABBU"]
[Tue Jul 21 07:37:18.205056 2026] [security2:error] [pid 255769:tid 256015] [client 213.152.162.104:54814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9L3rxMYwyVGnfuwsKVuQAABBU"]
[Tue Jul 21 07:37:18.222112 2026] [security2:error] [pid 254995:tid 255088] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L3v7v0rlcEGmVraE8wgADIVw"]
[Tue Jul 21 07:37:18.222242 2026] [security2:error] [pid 254995:tid 255128] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L3v7v0rlcEGmVraE8wgADIVw"]
[Tue Jul 21 07:37:18.472240 2026] [security2:error] [pid 255769:tid 255932] [client 20.197.195.24:51789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9L3rxMYwyVGnfuwsKVvAAAA8Q"]
[Tue Jul 21 07:37:18.475955 2026] [security2:error] [pid 255769:tid 255940] [client 45.8.17.57:39033] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/xml.php"] [unique_id "al9L3rxMYwyVGnfuwsKVvQAAA8w"]
[Tue Jul 21 07:37:18.519584 2026] [security2:error] [pid 255769:tid 255918] [client 20.226.60.151:51334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/vssrs.php"] [unique_id "al9L3rxMYwyVGnfuwsKVvgAAA7Y"]
[Tue Jul 21 07:37:18.591245 2026] [security2:error] [pid 255769:tid 255975] [client 20.220.225.223:38698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/ee.php"] [unique_id "al9L3rxMYwyVGnfuwsKVvwAAA-8"]
[Tue Jul 21 07:37:18.610738 2026] [security2:error] [pid 255769:tid 256005] [client 20.197.195.24:51795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wp-blog.php"] [unique_id "al9L3rxMYwyVGnfuwsKVwAAABAs"]
[Tue Jul 21 07:37:18.667219 2026] [security2:error] [pid 254995:tid 255265] [client 74.7.241.135:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.sugar-delete.online"] [uri "/index.php"] [unique_id "al9L3v7v0rlcEGmVraE8wAAAA48"]
[Tue Jul 21 07:37:18.673649 2026] [security2:error] [pid 254995:tid 255133] [client 74.7.241.135:35880] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.sugar-delete.online"] [uri "/robots.txt"] [unique_id "al9L3v7v0rlcEGmVraE8vQADJgw"]
[Tue Jul 21 07:37:18.675599 2026] [autoindex:error] [pid 255769:tid 256004] [client 20.197.195.24:51800] AH01276: Cannot serve directory /home3/equote29/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:18.686429 2026] [security2:error] [pid 255769:tid 255964] [client 20.197.195.24:51800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wp-content/admin.php"] [unique_id "al9L3rxMYwyVGnfuwsKVxwAAA-Q"]
[Tue Jul 21 07:37:18.753990 2026] [security2:error] [pid 255769:tid 255945] [client 59.96.220.140:58713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9L3rxMYwyVGnfuwsKVygAAA9E"]
[Tue Jul 21 07:37:18.754692 2026] [security2:error] [pid 255769:tid 255945] [client 59.96.220.140:58713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9L3rxMYwyVGnfuwsKVygAAA9E"]
[Tue Jul 21 07:37:18.809510 2026] [security2:error] [pid 255769:tid 255938] [client 20.104.96.117:61132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/2000.php"] [unique_id "al9L3rxMYwyVGnfuwsKVzAAAA8o"]
[Tue Jul 21 07:37:18.882212 2026] [security2:error] [pid 255769:tid 255974] [client 20.197.195.24:51749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/ms-edit.php"] [unique_id "al9L3rxMYwyVGnfuwsKVzgAAA-4"]
[Tue Jul 21 07:37:18.940544 2026] [security2:error] [pid 254995:tid 255138] [client 103.86.117.203:53577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L3v7v0rlcEGmVraE8zAAAAys"]
[Tue Jul 21 07:37:18.940641 2026] [security2:error] [pid 254995:tid 255138] [client 103.86.117.203:53577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L3v7v0rlcEGmVraE8zAAAAys"]
[Tue Jul 21 07:37:18.963658 2026] [security2:error] [pid 255769:tid 255925] [client 20.197.195.24:21071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/cgi-bin/index.php"] [unique_id "al9L3rxMYwyVGnfuwsKV0QAAA70"]
[Tue Jul 21 07:37:18.994630 2026] [autoindex:error] [pid 255769:tid 255988] [client 20.197.195.24:51832] AH01276: Cannot serve directory /home3/equote29/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:19.037738 2026] [security2:error] [pid 254995:tid 255273] [client 20.226.60.151:61198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wicked.php"] [unique_id "al9L3_7v0rlcEGmVraE8zgAAA5c"]
[Tue Jul 21 07:37:19.052348 2026] [security2:error] [pid 255769:tid 255919] [client 20.197.195.24:51832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/BDKR28WP.php"] [unique_id "al9L37xMYwyVGnfuwsKV1wAAA7c"]
[Tue Jul 21 07:37:19.115057 2026] [security2:error] [pid 255769:tid 255976] [client 20.197.195.24:62426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-blog.php"] [unique_id "al9L37xMYwyVGnfuwsKV2gAAA_A"]
[Tue Jul 21 07:37:19.116883 2026] [security2:error] [pid 255769:tid 255942] [client 74.7.241.135:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sugar-delete.online"] [uri "/index.php"] [unique_id "al9L37xMYwyVGnfuwsKV2AAAA84"], referer: https://www.sugar-delete.online/robots.txt
[Tue Jul 21 07:37:19.117749 2026] [security2:error] [pid 254995:tid 255212] [client 74.7.241.135:35884] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sugar-delete.online"] [uri "/robots.txt"] [unique_id "al9L3_7v0rlcEGmVraE8zwADdAc"], referer: https://www.sugar-delete.online/robots.txt
[Tue Jul 21 07:37:19.124223 2026] [autoindex:error] [pid 255769:tid 255909] [client 20.197.195.24:51835] AH01276: Cannot serve directory /home3/equote29/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:19.180312 2026] [security2:error] [pid 255769:tid 255908] [client 20.151.10.161:45959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/k4.php"] [unique_id "al9L37xMYwyVGnfuwsKV3gAAA6w"]
[Tue Jul 21 07:37:19.242147 2026] [autoindex:error] [pid 255769:tid 256015] [client 20.197.195.24:51835] AH01276: Cannot serve directory /home3/equote29/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:19.247569 2026] [security2:error] [pid 255769:tid 256016] [client 20.197.195.24:51835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/abcd.php"] [unique_id "al9L37xMYwyVGnfuwsKV4AAABBY"]
[Tue Jul 21 07:37:19.380771 2026] [security2:error] [pid 254995:tid 255255] [client 45.8.17.116:28725] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-conflg/function.php"] [unique_id "al9L3_7v0rlcEGmVraE81gAAA4U"]
[Tue Jul 21 07:37:19.389619 2026] [security2:error] [pid 255769:tid 255927] [client 136.144.33.29:56333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9L37xMYwyVGnfuwsKV5AAAA78"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:19.404742 2026] [security2:error] [pid 255769:tid 256022] [client 20.226.60.151:51277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/24.php"] [unique_id "al9L37xMYwyVGnfuwsKV5QAABBw"]
[Tue Jul 21 07:37:19.478808 2026] [security2:error] [pid 254995:tid 255222] [client 20.197.195.24:51827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/file15.php"] [unique_id "al9L3_7v0rlcEGmVraE81wAAA34"]
[Tue Jul 21 07:37:19.625306 2026] [security2:error] [pid 254995:tid 255147] [client 20.104.96.117:59180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/122.php"] [unique_id "al9L3_7v0rlcEGmVraE82wAAAzQ"]
[Tue Jul 21 07:37:19.771071 2026] [autoindex:error] [pid 254995:tid 255223] [client 20.197.195.24:62856] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:19.781138 2026] [security2:error] [pid 254995:tid 255194] [client 20.197.195.24:62856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-content/admin.php"] [unique_id "al9L3_7v0rlcEGmVraE84QAAA2M"]
[Tue Jul 21 07:37:20.009945 2026] [security2:error] [pid 255769:tid 255945] [client 20.197.195.24:51715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/jp.php"] [unique_id "al9L4LxMYwyVGnfuwsKV7wAAA9E"]
[Tue Jul 21 07:37:20.031496 2026] [security2:error] [pid 255769:tid 256012] [client 45.251.232.145:64787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L4LxMYwyVGnfuwsKV8AAABBI"]
[Tue Jul 21 07:37:20.031623 2026] [security2:error] [pid 255769:tid 256012] [client 45.251.232.145:64787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L4LxMYwyVGnfuwsKV8AAABBI"]
[Tue Jul 21 07:37:20.036863 2026] [security2:error] [pid 254995:tid 255259] [client 193.36.225.141:57207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9L3f7v0rlcEGmVraE8tAAAA4k"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:37:20.101186 2026] [security2:error] [pid 255769:tid 255974] [client 82.102.28.107:54356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9L4LxMYwyVGnfuwsKV8gAAA-4"]
[Tue Jul 21 07:37:20.101281 2026] [security2:error] [pid 255769:tid 255974] [client 82.102.28.107:54356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9L4LxMYwyVGnfuwsKV8gAAA-4"]
[Tue Jul 21 07:37:20.135785 2026] [security2:error] [pid 255769:tid 256000] [client 20.197.195.24:62884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/ms-edit.php"] [unique_id "al9L4LxMYwyVGnfuwsKV8wAABAY"]
[Tue Jul 21 07:37:20.174296 2026] [security2:error] [pid 254995:tid 255125] [client 20.104.96.117:59658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/mds.php"] [unique_id "al9L4P7v0rlcEGmVraE86AAAAx4"]
[Tue Jul 21 07:37:20.375074 2026] [security2:error] [pid 255769:tid 255978] [client 20.226.60.151:61017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/xacs.php"] [unique_id "al9L4LxMYwyVGnfuwsKV9gAAA_I"]
[Tue Jul 21 07:37:20.463455 2026] [security2:error] [pid 255769:tid 255976] [client 20.206.105.145:37909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/test11.php"] [unique_id "al9L4LxMYwyVGnfuwsKV-AAAA_A"]
[Tue Jul 21 07:37:20.553198 2026] [security2:error] [pid 255769:tid 255983] [client 74.7.230.20:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.trab.giovanoniadv.com.br"] [uri "/index.php"] [unique_id "al9L37xMYwyVGnfuwsKV6AAAA_c"]
[Tue Jul 21 07:37:20.553884 2026] [security2:error] [pid 255769:tid 255932] [client 74.7.230.20:42916] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.trab.giovanoniadv.com.br"] [uri "/robots.txt"] [unique_id "al9L37xMYwyVGnfuwsKV5wADxEY"]
[Tue Jul 21 07:37:20.619839 2026] [security2:error] [pid 255769:tid 256015] [client 20.197.195.24:51785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/f35.php"] [unique_id "al9L4LxMYwyVGnfuwsKV_QAABBU"]
[Tue Jul 21 07:37:20.665832 2026] [security2:error] [pid 255769:tid 256006] [client 20.151.10.161:45922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/k5.php"] [unique_id "al9L4LxMYwyVGnfuwsKV_gAABAw"]
[Tue Jul 21 07:37:20.732802 2026] [security2:error] [pid 255769:tid 255922] [client 20.197.195.24:51768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wp-load.php"] [unique_id "al9L4LxMYwyVGnfuwsKV_wAAA7o"]
[Tue Jul 21 07:37:20.788557 2026] [security2:error] [pid 255769:tid 255943] [client 20.197.195.24:62402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/cgi-bin/index.php"] [unique_id "al9L4LxMYwyVGnfuwsKWAgAAA88"]
[Tue Jul 21 07:37:20.849003 2026] [autoindex:error] [pid 255769:tid 255777] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:20.853050 2026] [autoindex:error] [pid 255769:tid 255894] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/blocks/calendar/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:20.874809 2026] [security2:error] [pid 255769:tid 255926] [client 139.167.225.182:62941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L4LxMYwyVGnfuwsKWBQAAA74"]
[Tue Jul 21 07:37:20.874909 2026] [security2:error] [pid 255769:tid 255926] [client 139.167.225.182:62941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L4LxMYwyVGnfuwsKWBQAAA74"]
[Tue Jul 21 07:37:20.967777 2026] [security2:error] [pid 255769:tid 255946] [client 20.104.96.117:61126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-blink.php"] [unique_id "al9L4LxMYwyVGnfuwsKWCAAAA9I"]
[Tue Jul 21 07:37:20.971285 2026] [security2:error] [pid 255769:tid 255918] [client 45.8.17.123:25369] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/network_xo.php"] [unique_id "al9L4LxMYwyVGnfuwsKWCQAAA7Y"]
[Tue Jul 21 07:37:21.164895 2026] [security2:error] [pid 255769:tid 256020] [client 20.197.195.24:51754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/xyn.php"] [unique_id "al9L4bxMYwyVGnfuwsKWDAAABBo"]
[Tue Jul 21 07:37:21.174481 2026] [security2:error] [pid 255769:tid 255962] [client 74.7.230.20:42932] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "trab.giovanoniadv.com.br"] [uri "/robots.txt"] [unique_id "al9L4bxMYwyVGnfuwsKWCwAD4i4"], referer: https://www.trab.giovanoniadv.com.br/robots.txt
[Tue Jul 21 07:37:21.318223 2026] [security2:error] [pid 255769:tid 256021] [client 213.152.162.104:59154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9L4bxMYwyVGnfuwsKWEQAABBs"]
[Tue Jul 21 07:37:21.318315 2026] [security2:error] [pid 255769:tid 256021] [client 213.152.162.104:59154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9L4bxMYwyVGnfuwsKWEQAABBs"]
[Tue Jul 21 07:37:21.325150 2026] [autoindex:error] [pid 255769:tid 255931] [client 20.197.195.24:62868] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:21.373095 2026] [security2:error] [pid 255769:tid 255947] [client 20.197.195.24:62868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/BDKR28WP.php"] [unique_id "al9L4bxMYwyVGnfuwsKWEwAAA9M"]
[Tue Jul 21 07:37:21.437707 2026] [security2:error] [pid 255769:tid 256013] [client 20.220.225.223:51496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-Blogs.php"] [unique_id "al9L4bxMYwyVGnfuwsKWFQAABBM"]
[Tue Jul 21 07:37:21.618209 2026] [security2:error] [pid 254995:tid 255144] [client 20.226.60.151:51380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/zildan.php"] [unique_id "al9L4f7v0rlcEGmVraE8-wAAAzE"]
[Tue Jul 21 07:37:21.665781 2026] [security2:error] [pid 255769:tid 255975] [client 117.217.38.194:51737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L4bxMYwyVGnfuwsKWGQAAA-8"]
[Tue Jul 21 07:37:21.665961 2026] [security2:error] [pid 255769:tid 255975] [client 117.217.38.194:51737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L4bxMYwyVGnfuwsKWGQAAA-8"]
[Tue Jul 21 07:37:21.678809 2026] [autoindex:error] [pid 254995:tid 255132] [client 20.197.195.24:21057] AH01276: Cannot serve directory /home3/equote29/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:21.762085 2026] [autoindex:error] [pid 254995:tid 255186] [client 20.197.195.24:21057] AH01276: Cannot serve directory /home3/equote29/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:21.767133 2026] [security2:error] [pid 254995:tid 255208] [client 20.197.195.24:21057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/ccc.php"] [unique_id "al9L4f7v0rlcEGmVraE8_wAAA3A"]
[Tue Jul 21 07:37:21.796057 2026] [security2:error] [pid 254995:tid 255265] [client 20.151.10.161:46050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/w.php"] [unique_id "al9L4f7v0rlcEGmVraE9AAAAA48"]
[Tue Jul 21 07:37:21.883029 2026] [security2:error] [pid 255769:tid 255917] [client 45.8.17.59:48789] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/sitemaps/"] [unique_id "al9L4bxMYwyVGnfuwsKWGgAAA7U"]
[Tue Jul 21 07:37:21.889741 2026] [security2:error] [pid 255769:tid 255985] [client 173.24.185.52:56165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9L4bxMYwyVGnfuwsKWGwAAA_k"]
[Tue Jul 21 07:37:21.889846 2026] [security2:error] [pid 255769:tid 255985] [client 173.24.185.52:56165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9L4bxMYwyVGnfuwsKWGwAAA_k"]
[Tue Jul 21 07:37:22.193314 2026] [security2:error] [pid 254995:tid 255269] [client 117.251.86.144:43792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9L4v7v0rlcEGmVraE9CAAAA5M"]
[Tue Jul 21 07:37:22.193431 2026] [security2:error] [pid 254995:tid 255269] [client 117.251.86.144:43792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9L4v7v0rlcEGmVraE9CAAAA5M"]
[Tue Jul 21 07:37:22.297347 2026] [autoindex:error] [pid 255769:tid 255932] [client 20.197.195.24:62898] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:22.317693 2026] [autoindex:error] [pid 255769:tid 255929] [client 20.197.195.24:62898] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:22.322267 2026] [security2:error] [pid 255769:tid 256015] [client 20.151.10.161:46022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/fpwch.php"] [unique_id "al9L4rxMYwyVGnfuwsKWIwAABBU"]
[Tue Jul 21 07:37:22.342875 2026] [security2:error] [pid 255769:tid 256016] [client 20.197.195.24:62898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/abcd.php"] [unique_id "al9L4rxMYwyVGnfuwsKWJAAABBY"]
[Tue Jul 21 07:37:22.466044 2026] [security2:error] [pid 255769:tid 255922] [client 20.220.225.223:49853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-explorer.php"] [unique_id "al9L4rxMYwyVGnfuwsKWJQAAA7o"]
[Tue Jul 21 07:37:22.474244 2026] [security2:error] [pid 254995:tid 255178] [client 20.104.96.117:61165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/zc-208.php"] [unique_id "al9L4v7v0rlcEGmVraE9DQAAA1M"]
[Tue Jul 21 07:37:22.568354 2026] [security2:error] [pid 254995:tid 255255] [client 20.226.60.151:61190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/csa.php"] [unique_id "al9L4v7v0rlcEGmVraE9DgAAA4U"]
[Tue Jul 21 07:37:22.578846 2026] [security2:error] [pid 254995:tid 255148] [client 20.197.195.24:20998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/w.php"] [unique_id "al9L4v7v0rlcEGmVraE9DwAAAzU"]
[Tue Jul 21 07:37:22.854514 2026] [security2:error] [pid 255769:tid 255892] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9L4rxMYwyVGnfuwsKWKQAD0Ho"]
[Tue Jul 21 07:37:22.854662 2026] [security2:error] [pid 255769:tid 255944] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9L4rxMYwyVGnfuwsKWKQAD0Ho"]
[Tue Jul 21 07:37:22.872980 2026] [security2:error] [pid 255769:tid 255926] [client 20.197.195.24:51745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9L4rxMYwyVGnfuwsKWKgAAA74"]
[Tue Jul 21 07:37:22.972613 2026] [security2:error] [pid 254995:tid 255212] [client 103.162.129.114:55081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9L4v7v0rlcEGmVraE9GAAAA3Q"]
[Tue Jul 21 07:37:22.972730 2026] [security2:error] [pid 254995:tid 255212] [client 103.162.129.114:55081] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9L4v7v0rlcEGmVraE9GAAAA3Q"]
[Tue Jul 21 07:37:22.995078 2026] [security2:error] [pid 255769:tid 256022] [client 20.197.195.24:62457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/file15.php"] [unique_id "al9L4rxMYwyVGnfuwsKWKwAABBw"]
[Tue Jul 21 07:37:22.999094 2026] [security2:error] [pid 255769:tid 255940] [client 20.104.96.117:59686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/sid4.php"] [unique_id "al9L4rxMYwyVGnfuwsKWLAAAA8w"]
[Tue Jul 21 07:37:23.075610 2026] [security2:error] [pid 255769:tid 255953] [client 45.8.17.117:63733] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/pomo/index.php"] [unique_id "al9L47xMYwyVGnfuwsKWLwAAA9k"]
[Tue Jul 21 07:37:23.115587 2026] [security2:error] [pid 255769:tid 255911] [client 20.206.105.145:38086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/koala.php"] [unique_id "al9L47xMYwyVGnfuwsKWMAAAA68"]
[Tue Jul 21 07:37:23.211368 2026] [security2:error] [pid 255769:tid 255965] [client 20.197.195.24:51732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/FWAZ.php"] [unique_id "al9L47xMYwyVGnfuwsKWNAAAA-U"]
[Tue Jul 21 07:37:23.227841 2026] [security2:error] [pid 255769:tid 255979] [client 122.186.204.214:57017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L47xMYwyVGnfuwsKWNQAAA_M"]
[Tue Jul 21 07:37:23.227959 2026] [security2:error] [pid 255769:tid 255979] [client 122.186.204.214:57017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L47xMYwyVGnfuwsKWNQAAA_M"]
[Tue Jul 21 07:37:23.327865 2026] [security2:error] [pid 255769:tid 255984] [client 107.189.6.149:58031] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "portalrepercutnews.com.br"] [uri "/"] [unique_id "al9L47xMYwyVGnfuwsKWOAAAA_g"]
[Tue Jul 21 07:37:23.332396 2026] [autoindex:error] [pid 255769:tid 255822] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/js/codemirror/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:23.332707 2026] [autoindex:error] [pid 255769:tid 255852] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:23.483063 2026] [security2:error] [pid 254995:tid 255213] [client 136.144.33.101:39193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9L4_7v0rlcEGmVraE9HAAAA3U"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:23.523611 2026] [security2:error] [pid 254995:tid 255209] [client 107.189.6.149:58030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "portalrepercutnews.com.br"] [uri "/"] [unique_id "al9L4_7v0rlcEGmVraE9HgAAA3E"]
[Tue Jul 21 07:37:23.722555 2026] [security2:error] [pid 255769:tid 255996] [client 20.197.195.24:62909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/jp.php"] [unique_id "al9L47xMYwyVGnfuwsKWPgAABAI"]
[Tue Jul 21 07:37:23.724702 2026] [security2:error] [pid 254995:tid 255198] [client 107.189.6.149:58088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "portalrepercutnews.com.br"] [uri "/"] [unique_id "al9L4_7v0rlcEGmVraE9IgAAA2c"]
[Tue Jul 21 07:37:23.735469 2026] [security2:error] [pid 255769:tid 255773] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L47xMYwyVGnfuwsKWQQAD0wM"]
[Tue Jul 21 07:37:23.735673 2026] [security2:error] [pid 255769:tid 255947] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L47xMYwyVGnfuwsKWQQAD0wM"]
[Tue Jul 21 07:37:23.751366 2026] [autoindex:error] [pid 255769:tid 255778] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/js/plupload/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:23.752948 2026] [autoindex:error] [pid 255769:tid 255872] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:23.858867 2026] [security2:error] [pid 255769:tid 255969] [client 34.91.119.153:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.barcob.com"] [uri "/"] [unique_id "al9L47xMYwyVGnfuwsKWRQAAA-k"]
[Tue Jul 21 07:37:23.858965 2026] [security2:error] [pid 255769:tid 255969] [client 34.91.119.153:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.barcob.com"] [uri "/"] [unique_id "al9L47xMYwyVGnfuwsKWRQAAA-k"]
[Tue Jul 21 07:37:23.926567 2026] [security2:error] [pid 255769:tid 255902] [client 35.226.57.170:56758] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "adifarmabella.com"] [uri "/"] [unique_id "al9L47xMYwyVGnfuwsKWRgAAA6Y"]
[Tue Jul 21 07:37:23.951222 2026] [security2:error] [pid 254995:tid 255211] [client 20.197.195.24:51809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/miru1.php"] [unique_id "al9L4_7v0rlcEGmVraE9JQAAA3M"]
[Tue Jul 21 07:37:23.966582 2026] [security2:error] [pid 255769:tid 255983] [client 20.151.10.161:46062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/w2025.php"] [unique_id "al9L47xMYwyVGnfuwsKWRwAAA_c"]
[Tue Jul 21 07:37:24.017798 2026] [security2:error] [pid 255769:tid 255942] [client 20.104.96.117:59199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wmore1.php"] [unique_id "al9L5LxMYwyVGnfuwsKWSAAAA84"]
[Tue Jul 21 07:37:24.112853 2026] [security2:error] [pid 255769:tid 255909] [client 107.189.6.149:58120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "portalrepercutnews.com.br"] [uri "/"] [unique_id "al9L5LxMYwyVGnfuwsKWSwAAA60"]
[Tue Jul 21 07:37:24.174351 2026] [security2:error] [pid 255769:tid 255943] [client 45.8.17.112:20821] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/revslider/includes/external/page/"] [unique_id "al9L5LxMYwyVGnfuwsKWTQAAA88"]
[Tue Jul 21 07:37:24.193728 2026] [security2:error] [pid 255769:tid 255908] [client 20.197.195.24:62446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/f35.php"] [unique_id "al9L5LxMYwyVGnfuwsKWTgAAA6w"]
[Tue Jul 21 07:37:24.209370 2026] [security2:error] [pid 255769:tid 255992] [client 20.226.60.151:51358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/w3llscc.php"] [unique_id "al9L5LxMYwyVGnfuwsKWTwAAA_8"]
[Tue Jul 21 07:37:24.242900 2026] [autoindex:error] [pid 255769:tid 255829] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/blocks/calendar/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:24.257368 2026] [security2:error] [pid 255769:tid 255990] [client 20.197.195.24:62420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-load.php"] [unique_id "al9L5LxMYwyVGnfuwsKWVAAAA_4"]
[Tue Jul 21 07:37:24.269924 2026] [security2:error] [pid 255769:tid 255940] [client 20.197.195.24:62895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/xyn.php"] [unique_id "al9L5LxMYwyVGnfuwsKWVQAAA8w"]
[Tue Jul 21 07:37:24.286138 2026] [security2:error] [pid 255769:tid 255889] [remote 97.74.93.24:35940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp-login.php"] [unique_id "al9L5LxMYwyVGnfuwsKWVwADo3c"]
[Tue Jul 21 07:37:24.332434 2026] [autoindex:error] [pid 255769:tid 255923] [client 20.197.195.24:62441] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:24.395704 2026] [autoindex:error] [pid 255769:tid 255906] [client 20.197.195.24:62441] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:24.401096 2026] [security2:error] [pid 255769:tid 255952] [client 20.197.195.24:62441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/ccc.php"] [unique_id "al9L5LxMYwyVGnfuwsKWXAAAA9g"]
[Tue Jul 21 07:37:24.439275 2026] [security2:error] [pid 255769:tid 256004] [client 20.197.195.24:62434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/w.php"] [unique_id "al9L5LxMYwyVGnfuwsKWXQAABAo"]
[Tue Jul 21 07:37:24.492905 2026] [security2:error] [pid 255769:tid 255965] [client 20.197.195.24:51820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/aa.php"] [unique_id "al9L5LxMYwyVGnfuwsKWYAAAA-U"]
[Tue Jul 21 07:37:24.519685 2026] [security2:error] [pid 255769:tid 255946] [client 185.213.175.37:50398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.175.213.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "applarifo.com.br"] [uri "/tabela.php"] [unique_id "al9L5LxMYwyVGnfuwsKWYgAAA9I"]
[Tue Jul 21 07:37:24.543539 2026] [security2:error] [pid 255769:tid 255931] [client 20.197.195.24:62908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9L5LxMYwyVGnfuwsKWZAAAA8M"]
[Tue Jul 21 07:37:24.563643 2026] [security2:error] [pid 255769:tid 255976] [client 175.45.70.82:62431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5LxMYwyVGnfuwsKWZgAAA_A"]
[Tue Jul 21 07:37:24.563759 2026] [security2:error] [pid 255769:tid 255976] [client 175.45.70.82:62431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5LxMYwyVGnfuwsKWZgAAA_A"]
[Tue Jul 21 07:37:24.773215 2026] [security2:error] [pid 255769:tid 255903] [client 20.52.136.55:1765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/bootstrap.php"] [unique_id "al9L5LxMYwyVGnfuwsKWbQAAA6c"]
[Tue Jul 21 07:37:24.789259 2026] [security2:error] [pid 255769:tid 255975] [client 20.197.195.24:62410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/FWAZ.php"] [unique_id "al9L5LxMYwyVGnfuwsKWbgAAA-8"]
[Tue Jul 21 07:37:24.812066 2026] [security2:error] [pid 255769:tid 255956] [client 152.59.154.239:57715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5LxMYwyVGnfuwsKWbwAAA9w"]
[Tue Jul 21 07:37:24.812188 2026] [security2:error] [pid 255769:tid 255956] [client 152.59.154.239:57715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5LxMYwyVGnfuwsKWbwAAA9w"]
[Tue Jul 21 07:37:24.891873 2026] [security2:error] [pid 255769:tid 255935] [client 20.197.195.24:51716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/122.php"] [unique_id "al9L5LxMYwyVGnfuwsKWcQAAA8c"]
[Tue Jul 21 07:37:24.909101 2026] [security2:error] [pid 255769:tid 255997] [client 20.197.195.24:62871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/miru1.php"] [unique_id "al9L5LxMYwyVGnfuwsKWcgAABAM"]
[Tue Jul 21 07:37:24.937623 2026] [security2:error] [pid 255769:tid 255968] [client 122.162.144.145:26937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9L5LxMYwyVGnfuwsKWcwAAA-g"]
[Tue Jul 21 07:37:24.937727 2026] [security2:error] [pid 255769:tid 255968] [client 122.162.144.145:26937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9L5LxMYwyVGnfuwsKWcwAAA-g"]
[Tue Jul 21 07:37:24.941529 2026] [security2:error] [pid 255769:tid 255907] [client 74.7.230.29:38242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "admin.powerflats.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9L5LxMYwyVGnfuwsKWdAADqwo"]
[Tue Jul 21 07:37:24.948533 2026] [autoindex:error] [pid 254995:tid 255031] [remote 74.7.241.53:37634] AH01276: Cannot serve directory /home4/fabi0417/admin.powerflats.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:24.997598 2026] [security2:error] [pid 255769:tid 255901] [client 109.248.148.246:49000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9L5LxMYwyVGnfuwsKWdQAAA6U"]
[Tue Jul 21 07:37:24.997736 2026] [security2:error] [pid 255769:tid 255901] [client 109.248.148.246:49000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9L5LxMYwyVGnfuwsKWdQAAA6U"]
[Tue Jul 21 07:37:25.015970 2026] [security2:error] [pid 255769:tid 255919] [client 20.220.225.223:31220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/red.php"] [unique_id "al9L5bxMYwyVGnfuwsKWdgAAA7c"]
[Tue Jul 21 07:37:25.028663 2026] [autoindex:error] [pid 255769:tid 255850] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:25.036478 2026] [autoindex:error] [pid 255769:tid 255891] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-content/languages/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:25.130648 2026] [security2:error] [pid 255769:tid 255908] [client 20.197.195.24:13197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/aa.php"] [unique_id "al9L5bxMYwyVGnfuwsKWewAAA6w"]
[Tue Jul 21 07:37:25.216038 2026] [security2:error] [pid 255769:tid 255779] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5bxMYwyVGnfuwsKWgAAD6wk"]
[Tue Jul 21 07:37:25.216187 2026] [security2:error] [pid 255769:tid 255971] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5bxMYwyVGnfuwsKWgAAD6wk"]
[Tue Jul 21 07:37:25.260447 2026] [security2:error] [pid 254995:tid 255179] [client 154.192.233.199:60508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5f7v0rlcEGmVraE9PwAAA1Q"]
[Tue Jul 21 07:37:25.260595 2026] [security2:error] [pid 254995:tid 255179] [client 154.192.233.199:60508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5f7v0rlcEGmVraE9PwAAA1Q"]
[Tue Jul 21 07:37:25.318211 2026] [security2:error] [pid 254995:tid 255136] [client 20.226.60.151:51267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wpx.php"] [unique_id "al9L5f7v0rlcEGmVraE9RAAAAyk"]
[Tue Jul 21 07:37:25.318485 2026] [security2:error] [pid 255769:tid 256000] [client 103.106.20.201:51413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5bxMYwyVGnfuwsKWgQAABAY"]
[Tue Jul 21 07:37:25.319187 2026] [security2:error] [pid 255769:tid 256000] [client 103.106.20.201:51413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5bxMYwyVGnfuwsKWgQAABAY"]
[Tue Jul 21 07:37:25.579460 2026] [security2:error] [pid 254995:tid 255191] [client 45.8.17.64:21745] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "al9L5f7v0rlcEGmVraE9SgAAA2A"]
[Tue Jul 21 07:37:25.650624 2026] [security2:error] [pid 254995:tid 255217] [client 20.220.225.223:48166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-css.php"] [unique_id "al9L5f7v0rlcEGmVraE9TgAAA3k"]
[Tue Jul 21 07:37:25.701128 2026] [security2:error] [pid 255769:tid 255979] [client 20.226.60.151:27371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/k.php"] [unique_id "al9L5bxMYwyVGnfuwsKWhAAAA_M"]
[Tue Jul 21 07:37:25.714234 2026] [security2:error] [pid 254995:tid 255164] [client 20.206.105.145:38487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/mac.php"] [unique_id "al9L5f7v0rlcEGmVraE9TwAAA0U"]
[Tue Jul 21 07:37:25.767187 2026] [security2:error] [pid 254995:tid 255190] [client 20.197.195.24:62437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/122.php"] [unique_id "al9L5f7v0rlcEGmVraE9UAAAA18"]
[Tue Jul 21 07:37:25.999600 2026] [autoindex:error] [pid 255769:tid 255823] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:26.014223 2026] [security2:error] [pid 255769:tid 255903] [client 20.151.10.161:46060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/scxy.php"] [unique_id "al9L5rxMYwyVGnfuwsKWjgAAA6c"]
[Tue Jul 21 07:37:26.014712 2026] [security2:error] [pid 255769:tid 255937] [client 20.197.195.24:51779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/get.php"] [unique_id "al9L5rxMYwyVGnfuwsKWjwAAA8k"]
[Tue Jul 21 07:37:26.103766 2026] [security2:error] [pid 254995:tid 255206] [client 20.197.195.24:62854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/get.php"] [unique_id "al9L5v7v0rlcEGmVraE9WQAAA28"]
[Tue Jul 21 07:37:26.137507 2026] [security2:error] [pid 255769:tid 255955] [client 49.47.154.42:55907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.154.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiadeoferta.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5bxMYwyVGnfuwsKWfAAAA9s"]
[Tue Jul 21 07:37:26.137710 2026] [security2:error] [pid 255769:tid 255955] [client 49.47.154.42:55907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "guiadeoferta.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5bxMYwyVGnfuwsKWfAAAA9s"]
[Tue Jul 21 07:37:26.326175 2026] [security2:error] [pid 255769:tid 256028] [client 122.164.127.47:54457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9L5rxMYwyVGnfuwsKWkwAABCI"]
[Tue Jul 21 07:37:26.326282 2026] [security2:error] [pid 255769:tid 256028] [client 122.164.127.47:54457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9L5rxMYwyVGnfuwsKWkwAABCI"]
[Tue Jul 21 07:37:26.371097 2026] [security2:error] [pid 255769:tid 256009] [client 20.197.195.24:51752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/as.php"] [unique_id "al9L5rxMYwyVGnfuwsKWlAAABA8"]
[Tue Jul 21 07:37:26.384099 2026] [security2:error] [pid 254995:tid 255129] [client 20.104.96.117:59677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/solo1.php"] [unique_id "al9L5v7v0rlcEGmVraE9XwAAAyI"]
[Tue Jul 21 07:37:26.385067 2026] [security2:error] [pid 254995:tid 255260] [client 20.197.195.24:62861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/as.php"] [unique_id "al9L5v7v0rlcEGmVraE9YAAAA4o"]
[Tue Jul 21 07:37:26.492005 2026] [security2:error] [pid 255769:tid 255942] [client 20.226.60.151:61203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-css.php"] [unique_id "al9L5rxMYwyVGnfuwsKWlQAAA84"]
[Tue Jul 21 07:37:26.574827 2026] [security2:error] [pid 255769:tid 255784] [remote 104.207.32.246:63573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.32.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9L5rxMYwyVGnfuwsKWlwAD4Q4"]
[Tue Jul 21 07:37:26.683999 2026] [security2:error] [pid 255769:tid 255982] [client 45.8.17.145:20425] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/nrhogjyecktixbal0fnt5Cakc.php"] [unique_id "al9L5rxMYwyVGnfuwsKWngAAA_Y"]
[Tue Jul 21 07:37:26.777384 2026] [security2:error] [pid 255769:tid 255996] [client 103.177.242.200:64921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.242.177.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiferreira.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5rxMYwyVGnfuwsKWrQAABAI"]
[Tue Jul 21 07:37:26.777507 2026] [security2:error] [pid 255769:tid 255996] [client 103.177.242.200:64921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "guiferreira.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5rxMYwyVGnfuwsKWrQAABAI"]
[Tue Jul 21 07:37:26.881597 2026] [security2:error] [pid 255769:tid 256025] [client 20.197.195.24:62905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/ccou.php"] [unique_id "al9L5rxMYwyVGnfuwsKWrwAABB8"]
[Tue Jul 21 07:37:27.028431 2026] [security2:error] [pid 254995:tid 255176] [client 20.206.105.145:38464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9L5_7v0rlcEGmVraE9agAAA1E"]
[Tue Jul 21 07:37:27.190991 2026] [autoindex:error] [pid 255769:tid 255930] [client 16.163.108.56:0] AH01276: Cannot serve directory /home2/senatr95/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:27.192178 2026] [security2:error] [pid 255769:tid 255930] [client 16.163.108.56:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "senatruckdiesel.com.br"] [uri "/cgi-sys/403.html"] [unique_id "al9L57xMYwyVGnfuwsKW2QAAA8I"]
[Tue Jul 21 07:37:27.192800 2026] [security2:error] [pid 255769:tid 255980] [client 16.163.108.56:52886] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "senatruckdiesel.com.br"] [uri "/"] [unique_id "al9L57xMYwyVGnfuwsKW1gAAA_Q"]
[Tue Jul 21 07:37:27.519919 2026] [security2:error] [pid 254995:tid 255156] [client 103.174.34.15:58586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5_7v0rlcEGmVraE9egAAAz0"]
[Tue Jul 21 07:37:27.520058 2026] [security2:error] [pid 254995:tid 255156] [client 103.174.34.15:58586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5_7v0rlcEGmVraE9egAAAz0"]
[Tue Jul 21 07:37:27.599970 2026] [security2:error] [pid 255769:tid 255961] [client 20.220.225.223:38673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/fffm.php"] [unique_id "al9L57xMYwyVGnfuwsKXBgAAA-E"]
[Tue Jul 21 07:37:27.645077 2026] [security2:error] [pid 255769:tid 255943] [client 20.197.195.24:51757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/ccou.php"] [unique_id "al9L57xMYwyVGnfuwsKXBwAAA88"]
[Tue Jul 21 07:37:27.778295 2026] [security2:error] [pid 254995:tid 255178] [client 45.8.17.60:62635] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-trackback.php"] [unique_id "al9L5_7v0rlcEGmVraE9gQAAA1M"]
[Tue Jul 21 07:37:27.782652 2026] [security2:error] [pid 254995:tid 255151] [client 20.151.10.161:46068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/FWAZ.php"] [unique_id "al9L5_7v0rlcEGmVraE9ggAAAzg"]
[Tue Jul 21 07:37:27.855415 2026] [security2:error] [pid 255769:tid 256000] [client 20.104.96.117:59683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/cong.php"] [unique_id "al9L57xMYwyVGnfuwsKXGwAABAY"]
[Tue Jul 21 07:37:28.117967 2026] [security2:error] [pid 255769:tid 256021] [client 20.226.60.151:51287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ho.php"] [unique_id "al9L6LxMYwyVGnfuwsKXKAAABBs"]
[Tue Jul 21 07:37:28.295368 2026] [core:error] [pid 255769:tid 255776] [remote 52.167.144.232:64872] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:37:28.295394 2026] [core:error] [pid 255769:tid 255776] [remote 52.167.144.232:64872] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:37:28.385200 2026] [security2:error] [pid 255769:tid 256028] [client 20.197.195.24:51742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/w3lls.php"] [unique_id "al9L6LxMYwyVGnfuwsKXOwAABCI"]
[Tue Jul 21 07:37:28.399401 2026] [security2:error] [pid 255769:tid 256020] [client 20.197.195.24:63651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/w3lls.php"] [unique_id "al9L6LxMYwyVGnfuwsKXPAAABBo"]
[Tue Jul 21 07:37:28.436223 2026] [security2:error] [pid 255769:tid 255983] [client 20.220.225.223:49804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/akismet.php"] [unique_id "al9L6LxMYwyVGnfuwsKXPQAAA_c"]
[Tue Jul 21 07:37:28.465327 2026] [security2:error] [pid 255769:tid 255907] [client 20.104.96.117:59192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/public/css.php"] [unique_id "al9L6LxMYwyVGnfuwsKXQQAAA6s"]
[Tue Jul 21 07:37:28.534701 2026] [security2:error] [pid 254995:tid 255221] [client 193.36.225.68:63433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9L6P7v0rlcEGmVraE9hwAAA30"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:28.551955 2026] [security2:error] [pid 255769:tid 256012] [client 20.151.10.161:45978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/qterm.php"] [unique_id "al9L6LxMYwyVGnfuwsKXSAAABBI"]
[Tue Jul 21 07:37:28.657402 2026] [security2:error] [pid 255769:tid 255863] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L6LxMYwyVGnfuwsKXUAAED10"]
[Tue Jul 21 07:37:28.657521 2026] [security2:error] [pid 255769:tid 256009] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L6LxMYwyVGnfuwsKXUAAED10"]
[Tue Jul 21 07:37:28.764331 2026] [security2:error] [pid 255769:tid 255923] [client 20.220.225.223:38700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/blue.php"] [unique_id "al9L6LxMYwyVGnfuwsKXWAAAA7s"]
[Tue Jul 21 07:37:28.834116 2026] [security2:error] [pid 255769:tid 255833] [remote 104.207.35.166:27173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.35.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9L6LxMYwyVGnfuwsKXUwADvT8"]
[Tue Jul 21 07:37:28.881755 2026] [security2:error] [pid 255769:tid 255807] [remote 41.186.86.12:21414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colegioperseveranca.com"] [uri "/wp-login.php"] [unique_id "al9L6LxMYwyVGnfuwsKXWgADtSU"]
[Tue Jul 21 07:37:28.885880 2026] [security2:error] [pid 255769:tid 255804] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9L6LxMYwyVGnfuwsKXWwAD_CI"]
[Tue Jul 21 07:37:28.885988 2026] [security2:error] [pid 255769:tid 255988] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9L6LxMYwyVGnfuwsKXWwAD_CI"]
[Tue Jul 21 07:37:28.950604 2026] [security2:error] [pid 255769:tid 255999] [client 20.197.195.24:51769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/test1.php"] [unique_id "al9L6LxMYwyVGnfuwsKXXQAABAU"]
[Tue Jul 21 07:37:28.989871 2026] [security2:error] [pid 255769:tid 255936] [client 20.206.105.145:38515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wefile.php"] [unique_id "al9L6LxMYwyVGnfuwsKXYAAAA8g"]
[Tue Jul 21 07:37:29.082662 2026] [security2:error] [pid 255769:tid 255973] [client 20.220.225.223:48140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-explorer.php"] [unique_id "al9L6bxMYwyVGnfuwsKXcgAAA-0"]
[Tue Jul 21 07:37:29.136760 2026] [security2:error] [pid 254995:tid 255066] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L6f7v0rlcEGmVraE9lAADdUY"]
[Tue Jul 21 07:37:29.136883 2026] [security2:error] [pid 254995:tid 255213] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L6f7v0rlcEGmVraE9lAADdUY"]
[Tue Jul 21 07:37:29.403837 2026] [security2:error] [pid 255769:tid 256019] [client 20.197.195.24:21095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/database.php"] [unique_id "al9L6bxMYwyVGnfuwsKXfgAABBk"]
[Tue Jul 21 07:37:29.411607 2026] [security2:error] [pid 255769:tid 256012] [client 20.104.96.117:59650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/output.php"] [unique_id "al9L6bxMYwyVGnfuwsKXhAAABBI"]
[Tue Jul 21 07:37:29.426903 2026] [security2:error] [pid 254995:tid 255212] [client 103.86.117.203:54100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L6f7v0rlcEGmVraE9mwAAA3Q"]
[Tue Jul 21 07:37:29.427013 2026] [security2:error] [pid 254995:tid 255212] [client 103.86.117.203:54100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L6f7v0rlcEGmVraE9mwAAA3Q"]
[Tue Jul 21 07:37:29.676016 2026] [security2:error] [pid 255769:tid 255996] [client 45.8.17.148:24627] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/ty.php"] [unique_id "al9L6bxMYwyVGnfuwsKXjAAABAI"]
[Tue Jul 21 07:37:29.840225 2026] [security2:error] [pid 255769:tid 255921] [client 20.151.10.161:45979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/blurbs.php"] [unique_id "al9L6bxMYwyVGnfuwsKXlQAAA7k"]
[Tue Jul 21 07:37:29.894370 2026] [autoindex:error] [pid 255769:tid 256000] [client 20.206.105.145:37939] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:30.041973 2026] [security2:error] [pid 255769:tid 255917] [client 20.104.96.117:61138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-file-120.php"] [unique_id "al9L6rxMYwyVGnfuwsKXngAAA7U"]
[Tue Jul 21 07:37:30.081295 2026] [autoindex:error] [pid 255769:tid 255993] [client 20.206.105.145:37939] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:30.092302 2026] [security2:error] [pid 255769:tid 255999] [client 20.206.105.145:37939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9L6rxMYwyVGnfuwsKXoQAABAU"]
[Tue Jul 21 07:37:30.223880 2026] [security2:error] [pid 254995:tid 255186] [client 20.220.225.223:49851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/akismet.php"] [unique_id "al9L6v7v0rlcEGmVraE9qAAAA1s"]
[Tue Jul 21 07:37:30.283055 2026] [security2:error] [pid 254995:tid 255265] [client 20.197.195.24:51771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/file.php"] [unique_id "al9L6v7v0rlcEGmVraE9qQAAA48"]
[Tue Jul 21 07:37:30.353972 2026] [security2:error] [pid 254995:tid 255257] [client 20.151.10.161:46049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/v543.php"] [unique_id "al9L6v7v0rlcEGmVraE9qwAAA4c"]
[Tue Jul 21 07:37:30.411060 2026] [security2:error] [pid 255769:tid 255958] [client 20.197.195.24:63624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/test1.php"] [unique_id "al9L6rxMYwyVGnfuwsKXpwAAA94"]
[Tue Jul 21 07:37:30.509996 2026] [security2:error] [pid 255769:tid 255905] [client 45.251.232.145:65314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L6rxMYwyVGnfuwsKXqgAAA6k"]
[Tue Jul 21 07:37:30.510151 2026] [security2:error] [pid 255769:tid 255905] [client 45.251.232.145:65314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L6rxMYwyVGnfuwsKXqgAAA6k"]
[Tue Jul 21 07:37:30.741348 2026] [security2:error] [pid 255769:tid 255918] [client 20.197.195.24:51717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/file.php"] [unique_id "al9L6rxMYwyVGnfuwsKX1AAAA7Y"]
[Tue Jul 21 07:37:30.762414 2026] [security2:error] [pid 255769:tid 255935] [client 20.104.96.117:61120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/special.php"] [unique_id "al9L6rxMYwyVGnfuwsKX1QAAA8c"]
[Tue Jul 21 07:37:30.934037 2026] [autoindex:error] [pid 255769:tid 255776] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-content/languages/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:30.982091 2026] [security2:error] [pid 255769:tid 255964] [client 139.167.225.182:63581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L6rxMYwyVGnfuwsKX2gAAA-Q"]
[Tue Jul 21 07:37:30.982193 2026] [security2:error] [pid 255769:tid 255964] [client 139.167.225.182:63581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L6rxMYwyVGnfuwsKX2gAAA-Q"]
[Tue Jul 21 07:37:31.222571 2026] [security2:error] [pid 255769:tid 256006] [client 20.151.10.161:46026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/w3lls.php"] [unique_id "al9L67xMYwyVGnfuwsKX3gAABAw"]
[Tue Jul 21 07:37:31.243339 2026] [security2:error] [pid 255769:tid 255959] [client 20.226.60.151:51295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/xy.php"] [unique_id "al9L67xMYwyVGnfuwsKX3wAAA98"]
[Tue Jul 21 07:37:31.458771 2026] [security2:error] [pid 255769:tid 255859] [remote 202.51.202.242:48588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/wp-login.php"] [unique_id "al9L67xMYwyVGnfuwsKX5gAD-Vk"]
[Tue Jul 21 07:37:31.542976 2026] [security2:error] [pid 254995:tid 255195] [client 20.104.96.117:61134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/as.php"] [unique_id "al9L6_7v0rlcEGmVraE9vAAAA2Q"]
[Tue Jul 21 07:37:31.584162 2026] [security2:error] [pid 255769:tid 255917] [client 45.8.17.139:40709] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/default.php"] [unique_id "al9L67xMYwyVGnfuwsKX6QAAA7U"]
[Tue Jul 21 07:37:31.637121 2026] [security2:error] [pid 254995:tid 255222] [client 20.197.195.24:51772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/777.php"] [unique_id "al9L6_7v0rlcEGmVraE9vQAAA34"]
[Tue Jul 21 07:37:31.649603 2026] [security2:error] [pid 255769:tid 255988] [client 20.197.195.24:63662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/database.php"] [unique_id "al9L67xMYwyVGnfuwsKX6gAAA_w"]
[Tue Jul 21 07:37:31.768531 2026] [security2:error] [pid 254995:tid 255148] [client 20.206.105.145:38507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/2P.php"] [unique_id "al9L6_7v0rlcEGmVraE9vwAAAzU"]
[Tue Jul 21 07:37:31.780156 2026] [security2:error] [pid 255769:tid 255916] [client 20.151.10.161:46024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-ws68.php"] [unique_id "al9L67xMYwyVGnfuwsKX7wAAA7Q"]
[Tue Jul 21 07:37:31.965046 2026] [security2:error] [pid 254995:tid 255217] [client 20.104.96.117:59154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9L6_7v0rlcEGmVraE9wQAAA3k"]
[Tue Jul 21 07:37:32.103827 2026] [security2:error] [pid 255769:tid 255931] [client 20.197.195.24:51790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/ssixta.php"] [unique_id "al9L7LxMYwyVGnfuwsKX8gAAA8M"]
[Tue Jul 21 07:37:32.146091 2026] [security2:error] [pid 255769:tid 256003] [client 117.217.38.194:52239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L7LxMYwyVGnfuwsKX8wAABAk"]
[Tue Jul 21 07:37:32.146470 2026] [security2:error] [pid 255769:tid 256003] [client 117.217.38.194:52239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L7LxMYwyVGnfuwsKX8wAABAk"]
[Tue Jul 21 07:37:32.281515 2026] [security2:error] [pid 254995:tid 255194] [client 59.96.220.140:59541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9L7P7v0rlcEGmVraE9yAAAA2M"]
[Tue Jul 21 07:37:32.281635 2026] [security2:error] [pid 254995:tid 255194] [client 59.96.220.140:59541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9L7P7v0rlcEGmVraE9yAAAA2M"]
[Tue Jul 21 07:37:32.326270 2026] [security2:error] [pid 255769:tid 255932] [client 136.144.33.112:37401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9L7LxMYwyVGnfuwsKX9QAAA8Q"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:32.344626 2026] [security2:error] [pid 254995:tid 255084] [remote 38.242.157.30:40806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9L7P7v0rlcEGmVraE9ygADRVg"]
[Tue Jul 21 07:37:32.378546 2026] [security2:error] [pid 254995:tid 255155] [client 45.8.17.113:48793] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/SimplePie/font-editor.php"] [unique_id "al9L7P7v0rlcEGmVraE9zAAAAzw"]
[Tue Jul 21 07:37:32.454069 2026] [security2:error] [pid 255769:tid 255997] [client 173.24.185.52:56634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9L7LxMYwyVGnfuwsKX9wAABAM"]
[Tue Jul 21 07:37:32.454235 2026] [security2:error] [pid 255769:tid 255997] [client 173.24.185.52:56634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9L7LxMYwyVGnfuwsKX9wAABAM"]
[Tue Jul 21 07:37:32.480564 2026] [security2:error] [pid 255769:tid 255937] [client 20.104.96.117:61121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/w1px.php"] [unique_id "al9L7LxMYwyVGnfuwsKX-AAAA8k"]
[Tue Jul 21 07:37:32.694506 2026] [core:alert] [pid 254995:tid 255214] [client 57.141.18.46:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:37:32.820909 2026] [security2:error] [pid 254995:tid 255225] [client 20.226.60.151:51270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/loader.php"] [unique_id "al9L7P7v0rlcEGmVraE92AAAA4E"]
[Tue Jul 21 07:37:32.883799 2026] [security2:error] [pid 254995:tid 255204] [client 20.151.10.161:46030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xyn.php"] [unique_id "al9L7P7v0rlcEGmVraE92gAAA20"]
[Tue Jul 21 07:37:32.884583 2026] [security2:error] [pid 254995:tid 255143] [client 117.251.86.144:36992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9L7P7v0rlcEGmVraE92QAAAzA"]
[Tue Jul 21 07:37:32.884734 2026] [security2:error] [pid 254995:tid 255143] [client 117.251.86.144:36992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9L7P7v0rlcEGmVraE92QAAAzA"]
[Tue Jul 21 07:37:32.889216 2026] [security2:error] [pid 254995:tid 255264] [client 20.104.96.117:61081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/yawa.php"] [unique_id "al9L7P7v0rlcEGmVraE92wAAA44"]
[Tue Jul 21 07:37:32.890895 2026] [autoindex:error] [pid 255769:tid 255863] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-content/cache/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:32.925319 2026] [security2:error] [pid 254995:tid 255140] [client 20.197.195.24:21102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/1c.php"] [unique_id "al9L7P7v0rlcEGmVraE93AAAAy0"]
[Tue Jul 21 07:37:33.084272 2026] [security2:error] [pid 254995:tid 255256] [client 103.162.129.114:55503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9L7f7v0rlcEGmVraE94QAAA4Y"]
[Tue Jul 21 07:37:33.084414 2026] [security2:error] [pid 254995:tid 255256] [client 103.162.129.114:55503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9L7f7v0rlcEGmVraE94QAAA4Y"]
[Tue Jul 21 07:37:33.177173 2026] [security2:error] [pid 254995:tid 255208] [client 45.8.17.121:54239] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "al9L7f7v0rlcEGmVraE94gAAA3A"]
[Tue Jul 21 07:37:33.258042 2026] [security2:error] [pid 254995:tid 255170] [client 20.197.195.24:63308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/file.php"] [unique_id "al9L7f7v0rlcEGmVraE95wAAA0s"]
[Tue Jul 21 07:37:33.468132 2026] [security2:error] [pid 254995:tid 255133] [client 20.104.96.117:59166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/js.php"] [unique_id "al9L7f7v0rlcEGmVraE96wAAAyY"]
[Tue Jul 21 07:37:33.493316 2026] [security2:error] [pid 254995:tid 255193] [client 122.186.204.214:57538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L7f7v0rlcEGmVraE97AAAA2I"]
[Tue Jul 21 07:37:33.493444 2026] [security2:error] [pid 254995:tid 255193] [client 122.186.204.214:57538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L7f7v0rlcEGmVraE97AAAA2I"]
[Tue Jul 21 07:37:33.735527 2026] [security2:error] [pid 255769:tid 256006] [client 20.197.195.24:51784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/test2.php"] [unique_id "al9L7bxMYwyVGnfuwsKYBAAABAw"]
[Tue Jul 21 07:37:33.822490 2026] [security2:error] [pid 254995:tid 255062] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9L7f7v0rlcEGmVraE9_AADWkI"]
[Tue Jul 21 07:37:33.822598 2026] [security2:error] [pid 254995:tid 255185] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9L7f7v0rlcEGmVraE9_AADWkI"]
[Tue Jul 21 07:37:33.834473 2026] [security2:error] [pid 254995:tid 255215] [client 20.151.10.161:45963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/green3.php"] [unique_id "al9L7f7v0rlcEGmVraE9_QAAA3c"]
[Tue Jul 21 07:37:33.898696 2026] [security2:error] [pid 255769:tid 256000] [client 20.197.195.24:63631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/file.php"] [unique_id "al9L7bxMYwyVGnfuwsKYEgAABAY"]
[Tue Jul 21 07:37:33.942395 2026] [security2:error] [pid 255769:tid 255934] [client 20.104.96.117:59181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/core.php"] [unique_id "al9L7bxMYwyVGnfuwsKYEwAAA8Y"]
[Tue Jul 21 07:37:34.020101 2026] [security2:error] [pid 255769:tid 255988] [client 20.197.195.24:51799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/buy.php"] [unique_id "al9L7rxMYwyVGnfuwsKYFQAAA_w"]
[Tue Jul 21 07:37:34.176142 2026] [security2:error] [pid 255769:tid 255939] [client 45.8.17.147:42781] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "al9L7rxMYwyVGnfuwsKYGwAAA8s"]
[Tue Jul 21 07:37:34.372715 2026] [autoindex:error] [pid 255769:tid 255864] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-content/languages/themes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:34.422190 2026] [security2:error] [pid 255769:tid 255954] [client 20.220.225.223:49792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/ace2.php"] [unique_id "al9L7rxMYwyVGnfuwsKYLAAAA9o"]
[Tue Jul 21 07:37:34.460959 2026] [security2:error] [pid 255769:tid 255818] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L7rxMYwyVGnfuwsKYLQAD8zA"]
[Tue Jul 21 07:37:34.461094 2026] [security2:error] [pid 255769:tid 255979] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L7rxMYwyVGnfuwsKYLQAD8zA"]
[Tue Jul 21 07:37:34.663749 2026] [security2:error] [pid 255769:tid 255960] [client 20.197.195.24:63329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/777.php"] [unique_id "al9L7rxMYwyVGnfuwsKYMQAAA-A"]
[Tue Jul 21 07:37:34.714226 2026] [security2:error] [pid 255769:tid 255902] [client 20.104.96.117:61112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/19.php"] [unique_id "al9L7rxMYwyVGnfuwsKYMgAAA6Y"]
[Tue Jul 21 07:37:34.727218 2026] [security2:error] [pid 254995:tid 255259] [client 20.206.105.145:38485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/.well-known/about.php"] [unique_id "al9L7v7v0rlcEGmVraE-EQAAA4k"]
[Tue Jul 21 07:37:34.734577 2026] [security2:error] [pid 254995:tid 255225] [client 20.226.60.151:51309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/spadex.php"] [unique_id "al9L7v7v0rlcEGmVraE-EgAAA4E"]
[Tue Jul 21 07:37:34.745414 2026] [security2:error] [pid 254995:tid 255125] [client 20.197.195.24:51737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/ssend.php"] [unique_id "al9L7v7v0rlcEGmVraE-EwAAAx4"]
[Tue Jul 21 07:37:35.086734 2026] [security2:error] [pid 255769:tid 255992] [client 20.197.195.24:51807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/item.php"] [unique_id "al9L77xMYwyVGnfuwsKYNwAAA_8"]
[Tue Jul 21 07:37:35.150025 2026] [security2:error] [pid 255769:tid 255990] [client 20.197.195.24:63343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/ssixta.php"] [unique_id "al9L77xMYwyVGnfuwsKYOQAAA_4"]
[Tue Jul 21 07:37:35.171381 2026] [security2:error] [pid 255769:tid 255982] [client 20.151.10.161:45995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ccs.php"] [unique_id "al9L77xMYwyVGnfuwsKYOwAAA_Y"]
[Tue Jul 21 07:37:35.252660 2026] [security2:error] [pid 255769:tid 255921] [client 20.197.195.24:51782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/ss.php"] [unique_id "al9L77xMYwyVGnfuwsKYPAAAA7k"]
[Tue Jul 21 07:37:35.288887 2026] [security2:error] [pid 254995:tid 255265] [client 20.104.96.117:59662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/inc.php"] [unique_id "al9L7_7v0rlcEGmVraE-HQAAA48"]
[Tue Jul 21 07:37:35.291045 2026] [security2:error] [pid 255769:tid 255935] [client 175.45.70.82:62946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L77xMYwyVGnfuwsKYPQAAA8c"]
[Tue Jul 21 07:37:35.291130 2026] [security2:error] [pid 255769:tid 255935] [client 175.45.70.82:62946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L77xMYwyVGnfuwsKYPQAAA8c"]
[Tue Jul 21 07:37:35.373480 2026] [security2:error] [pid 255769:tid 255934] [client 45.8.17.131:57067] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-atom.php"] [unique_id "al9L77xMYwyVGnfuwsKYPwAAA8Y"]
[Tue Jul 21 07:37:35.445895 2026] [security2:error] [pid 255769:tid 255999] [client 20.197.195.24:21089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/hypo.php"] [unique_id "al9L77xMYwyVGnfuwsKYSQAABAU"]
[Tue Jul 21 07:37:35.504706 2026] [autoindex:error] [pid 255769:tid 255808] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:35.548497 2026] [security2:error] [pid 255769:tid 255975] [client 20.197.195.24:63339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/1c.php"] [unique_id "al9L77xMYwyVGnfuwsKYTwAAA-8"]
[Tue Jul 21 07:37:35.571224 2026] [security2:error] [pid 255769:tid 255978] [client 20.197.195.24:51767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/users.php"] [unique_id "al9L77xMYwyVGnfuwsKYUgAAA_I"]
[Tue Jul 21 07:37:35.637186 2026] [security2:error] [pid 254995:tid 255153] [client 20.197.195.24:21011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/177.php"] [unique_id "al9L7_7v0rlcEGmVraE-IwAAAzo"]
[Tue Jul 21 07:37:35.710568 2026] [security2:error] [pid 255769:tid 255901] [client 122.162.144.145:9884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9L77xMYwyVGnfuwsKYVQAAA6U"]
[Tue Jul 21 07:37:35.712946 2026] [security2:error] [pid 255769:tid 255901] [client 122.162.144.145:9884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9L77xMYwyVGnfuwsKYVQAAA6U"]
[Tue Jul 21 07:37:35.734127 2026] [security2:error] [pid 255769:tid 255775] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L77xMYwyVGnfuwsKYVgAECQU"]
[Tue Jul 21 07:37:35.734304 2026] [security2:error] [pid 255769:tid 256003] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L77xMYwyVGnfuwsKYVgAECQU"]
[Tue Jul 21 07:37:35.807526 2026] [security2:error] [pid 254995:tid 255183] [client 20.104.96.117:59693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9L7_7v0rlcEGmVraE-JgAAA1g"]
[Tue Jul 21 07:37:35.819109 2026] [autoindex:error] [pid 255769:tid 255894] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:35.867655 2026] [security2:error] [pid 254995:tid 255208] [client 154.192.233.199:59381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L7_7v0rlcEGmVraE-JwAAA3A"]
[Tue Jul 21 07:37:35.867808 2026] [security2:error] [pid 254995:tid 255208] [client 154.192.233.199:59381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L7_7v0rlcEGmVraE-JwAAA3A"]
[Tue Jul 21 07:37:35.975252 2026] [security2:error] [pid 254995:tid 255188] [client 152.59.154.239:58204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L7_7v0rlcEGmVraE-LQAAA10"]
[Tue Jul 21 07:37:35.975367 2026] [security2:error] [pid 254995:tid 255188] [client 152.59.154.239:58204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L7_7v0rlcEGmVraE-LQAAA10"]
[Tue Jul 21 07:37:35.999181 2026] [security2:error] [pid 254995:tid 255195] [client 20.197.195.24:51763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/config.php"] [unique_id "al9L7_7v0rlcEGmVraE-LgAAA2Q"]
[Tue Jul 21 07:37:36.052947 2026] [security2:error] [pid 255769:tid 255993] [client 103.106.20.201:51991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L8LxMYwyVGnfuwsKYWQAABAA"]
[Tue Jul 21 07:37:36.053068 2026] [security2:error] [pid 255769:tid 255993] [client 103.106.20.201:51991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L8LxMYwyVGnfuwsKYWQAABAA"]
[Tue Jul 21 07:37:36.192041 2026] [autoindex:error] [pid 255769:tid 255788] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:36.211278 2026] [security2:error] [pid 254995:tid 255158] [client 20.197.195.24:51810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/gettest.php"] [unique_id "al9L8P7v0rlcEGmVraE-SAAAAz8"]
[Tue Jul 21 07:37:36.313396 2026] [security2:error] [pid 254995:tid 255152] [client 20.220.225.223:51399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/ms.php"] [unique_id "al9L8P7v0rlcEGmVraE-TQAAAzk"]
[Tue Jul 21 07:37:36.357296 2026] [security2:error] [pid 255769:tid 256005] [client 20.197.195.24:51821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/min.php"] [unique_id "al9L8LxMYwyVGnfuwsKYXgAABAs"]
[Tue Jul 21 07:37:36.491419 2026] [security2:error] [pid 254995:tid 255198] [client 20.197.195.24:51817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/dvjul.php"] [unique_id "al9L8P7v0rlcEGmVraE-VgAAA2c"]
[Tue Jul 21 07:37:36.526096 2026] [core:error] [pid 254995:tid 255147] [client 164.92.100.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:37:36.526130 2026] [core:error] [pid 254995:tid 255147] [client 164.92.100.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:37:36.706318 2026] [security2:error] [pid 255769:tid 256019] [client 20.104.96.117:59144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9L8LxMYwyVGnfuwsKYZQAABBk"]
[Tue Jul 21 07:37:36.834026 2026] [security2:error] [pid 255769:tid 255929] [client 20.197.195.24:51828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/biufile.php"] [unique_id "al9L8LxMYwyVGnfuwsKYZwAAA8E"]
[Tue Jul 21 07:37:36.877746 2026] [security2:error] [pid 254995:tid 255126] [client 45.8.17.147:30403] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/tinymce/themes/inlite/"] [unique_id "al9L8P7v0rlcEGmVraE-YQAAAx8"]
[Tue Jul 21 07:37:36.938997 2026] [security2:error] [pid 254995:tid 255175] [client 122.164.127.47:54966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9L8P7v0rlcEGmVraE-YgAAA1A"]
[Tue Jul 21 07:37:36.939168 2026] [security2:error] [pid 254995:tid 255175] [client 122.164.127.47:54966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9L8P7v0rlcEGmVraE-YgAAA1A"]
[Tue Jul 21 07:37:36.958108 2026] [security2:error] [pid 254995:tid 255204] [client 20.197.195.24:63300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/test2.php"] [unique_id "al9L8P7v0rlcEGmVraE-YwAAA20"]
[Tue Jul 21 07:37:37.122667 2026] [security2:error] [pid 255769:tid 255816] [remote 210.211.113.135:60520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.113.211.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9L8LxMYwyVGnfuwsKYWgAD0y4"]
[Tue Jul 21 07:37:37.310823 2026] [security2:error] [pid 254995:tid 255256] [client 20.197.195.24:21016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/av.php"] [unique_id "al9L8f7v0rlcEGmVraE-aQAAA4Y"]
[Tue Jul 21 07:37:37.326598 2026] [security2:error] [pid 254995:tid 255265] [client 20.206.105.145:37951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9L8f7v0rlcEGmVraE-agAAA48"]
[Tue Jul 21 07:37:37.443657 2026] [security2:error] [pid 255769:tid 255988] [client 20.104.96.117:59672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/ss.php"] [unique_id "al9L8bxMYwyVGnfuwsKYdgAAA_w"]
[Tue Jul 21 07:37:37.479582 2026] [security2:error] [pid 255769:tid 255940] [client 136.144.33.109:49501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9L8bxMYwyVGnfuwsKYdwAAA8w"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:37.565516 2026] [security2:error] [pid 255769:tid 255930] [client 20.151.10.161:45895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ccc.php"] [unique_id "al9L8bxMYwyVGnfuwsKYeQAAA8I"]
[Tue Jul 21 07:37:37.609792 2026] [security2:error] [pid 255769:tid 255923] [client 16.163.108.56:48810] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "senatruckdiesel.com.br"] [uri "/cgi-sys/js/jquery-1.11.2.min.js"] [unique_id "al9L8bxMYwyVGnfuwsKYegAAA7s"]
[Tue Jul 21 07:37:37.626228 2026] [security2:error] [pid 255769:tid 255941] [client 20.197.195.24:63341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/buy.php"] [unique_id "al9L8bxMYwyVGnfuwsKYewAAA80"]
[Tue Jul 21 07:37:37.652556 2026] [security2:error] [pid 255769:tid 255976] [client 16.163.108.56:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "senatruckdiesel.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9L8bxMYwyVGnfuwsKYfgAAA_A"]
[Tue Jul 21 07:37:37.653204 2026] [security2:error] [pid 255769:tid 256000] [client 16.163.108.56:48826] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "senatruckdiesel.com.br"] [uri "/CHANGELOG.txt"] [unique_id "al9L8bxMYwyVGnfuwsKYfAAABAY"]
[Tue Jul 21 07:37:37.826482 2026] [security2:error] [pid 255769:tid 255834] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9L8bxMYwyVGnfuwsKYhQADv0A"]
[Tue Jul 21 07:37:37.826639 2026] [security2:error] [pid 255769:tid 255927] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9L8bxMYwyVGnfuwsKYhQADv0A"]
[Tue Jul 21 07:37:38.089678 2026] [security2:error] [pid 254995:tid 255136] [client 20.197.192.193:6365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9L8v7v0rlcEGmVraE-kgAAAyk"]
[Tue Jul 21 07:37:38.100829 2026] [security2:error] [pid 255769:tid 255980] [client 103.174.34.15:59063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L8rxMYwyVGnfuwsKYkAAAA_Q"]
[Tue Jul 21 07:37:38.100978 2026] [security2:error] [pid 255769:tid 255980] [client 103.174.34.15:59063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L8rxMYwyVGnfuwsKYkAAAA_Q"]
[Tue Jul 21 07:37:38.131942 2026] [security2:error] [pid 254995:tid 255178] [client 20.52.136.55:1743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/config-backup.php"] [unique_id "al9L8v7v0rlcEGmVraE-kwAAA1M"]
[Tue Jul 21 07:37:38.177722 2026] [security2:error] [pid 255769:tid 255929] [client 20.197.195.24:51723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/coffexium.php"] [unique_id "al9L8rxMYwyVGnfuwsKYlwAAA8E"]
[Tue Jul 21 07:37:38.275247 2026] [security2:error] [pid 255769:tid 255909] [client 45.8.17.145:37815] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/about.php"] [unique_id "al9L8rxMYwyVGnfuwsKYmAAAA60"]
[Tue Jul 21 07:37:38.450324 2026] [security2:error] [pid 255769:tid 255957] [client 173.252.95.54:47874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9L8bxMYwyVGnfuwsKYcgAAA90"]
[Tue Jul 21 07:37:38.602345 2026] [security2:error] [pid 255769:tid 255982] [client 20.151.10.161:46001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/get.php"] [unique_id "al9L8rxMYwyVGnfuwsKYngAAA_Y"]
[Tue Jul 21 07:37:38.650668 2026] [security2:error] [pid 254995:tid 255002] [remote 212.47.76.178:50412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.76.47.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dscbrasil.com.br"] [uri "/wp-login.php"] [unique_id "al9L8v7v0rlcEGmVraE-ogADMgY"]
[Tue Jul 21 07:37:38.803204 2026] [autoindex:error] [pid 255769:tid 255785] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:38.891321 2026] [security2:error] [pid 254995:tid 255175] [client 20.197.195.24:63655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/ssend.php"] [unique_id "al9L8v7v0rlcEGmVraE-pQAAA1A"]
[Tue Jul 21 07:37:38.939898 2026] [security2:error] [pid 254995:tid 255143] [client 20.197.195.24:21060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/core.php"] [unique_id "al9L8v7v0rlcEGmVraE-pgAAAzA"]
[Tue Jul 21 07:37:38.990858 2026] [security2:error] [pid 255769:tid 255961] [client 20.206.105.145:37947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/bob.php"] [unique_id "al9L8rxMYwyVGnfuwsKYpwAAA-E"]
[Tue Jul 21 07:37:39.107416 2026] [autoindex:error] [pid 255769:tid 255778] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:39.279906 2026] [security2:error] [pid 254995:tid 255276] [client 45.8.17.117:28163] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/covr-wpcom/assets/fonts/manrope_normal.php"] [unique_id "al9L8_7v0rlcEGmVraE-qgAAA5o"]
[Tue Jul 21 07:37:39.357247 2026] [security2:error] [pid 255769:tid 255889] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L87xMYwyVGnfuwsKYrAAD_3c"]
[Tue Jul 21 07:37:39.357447 2026] [security2:error] [pid 255769:tid 255992] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L87xMYwyVGnfuwsKYrAAD_3c"]
[Tue Jul 21 07:37:39.364717 2026] [security2:error] [pid 255769:tid 255922] [client 59.96.220.140:60111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9L87xMYwyVGnfuwsKYrQAAA7o"]
[Tue Jul 21 07:37:39.365421 2026] [security2:error] [pid 255769:tid 255922] [client 59.96.220.140:60111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9L87xMYwyVGnfuwsKYrQAAA7o"]
[Tue Jul 21 07:37:39.374129 2026] [security2:error] [pid 254995:tid 255161] [client 20.197.195.24:23410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/als.php"] [unique_id "al9L8_7v0rlcEGmVraE-rAAAA0I"]
[Tue Jul 21 07:37:39.466270 2026] [security2:error] [pid 254995:tid 255212] [client 89.124.113.107:59452] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "89.124.113.107" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "trconsultcontabilidade.com"] [uri "/wp-comments-post.php"] [unique_id "al9L8_7v0rlcEGmVraE-sAAAA3Q"], referer: https://trconsultcontabilidade.com/2023/06/02/ola-mundo/
[Tue Jul 21 07:37:39.466366 2026] [security2:error] [pid 254995:tid 255212] [client 89.124.113.107:59452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "trconsultcontabilidade.com"] [uri "/wp-comments-post.php"] [unique_id "al9L8_7v0rlcEGmVraE-sAAAA3Q"], referer: https://trconsultcontabilidade.com/2023/06/02/ola-mundo/
[Tue Jul 21 07:37:39.517396 2026] [security2:error] [pid 254995:tid 255178] [client 20.151.10.161:46051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/images.php"] [unique_id "al9L8_7v0rlcEGmVraE-uQAAA1M"]
[Tue Jul 21 07:37:39.583609 2026] [security2:error] [pid 255769:tid 256018] [client 185.198.240.95:35187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "imperdivelbestpromotionofthedaytodayonly.com"] [uri "/wp-login.php"] [unique_id "al9L8rxMYwyVGnfuwsKYnAAABBg"]
[Tue Jul 21 07:37:39.699649 2026] [security2:error] [pid 255769:tid 256028] [client 20.226.60.151:51331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/2x.php"] [unique_id "al9L87xMYwyVGnfuwsKYsgAABCI"]
[Tue Jul 21 07:37:39.721075 2026] [security2:error] [pid 254995:tid 255151] [client 20.104.96.117:59676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/min.php"] [unique_id "al9L8_7v0rlcEGmVraE-vQAAAzg"]
[Tue Jul 21 07:37:39.739568 2026] [security2:error] [pid 254995:tid 255217] [client 20.197.192.193:6393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9L8_7v0rlcEGmVraE-vgAAA3k"]
[Tue Jul 21 07:37:39.825249 2026] [security2:error] [pid 254995:tid 255166] [client 20.197.195.24:63346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/item.php"] [unique_id "al9L8_7v0rlcEGmVraE-wAAAA0c"]
[Tue Jul 21 07:37:39.910944 2026] [security2:error] [pid 254995:tid 255252] [client 103.86.117.203:54623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L8_7v0rlcEGmVraE-xAAAA4M"]
[Tue Jul 21 07:37:39.911056 2026] [security2:error] [pid 254995:tid 255252] [client 103.86.117.203:54623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L8_7v0rlcEGmVraE-xAAAA4M"]
[Tue Jul 21 07:37:39.992567 2026] [security2:error] [pid 254995:tid 255013] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L8_7v0rlcEGmVraE-xgADYBE"]
[Tue Jul 21 07:37:39.992717 2026] [security2:error] [pid 254995:tid 255191] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L8_7v0rlcEGmVraE-xgADYBE"]
[Tue Jul 21 07:37:40.030060 2026] [security2:error] [pid 254995:tid 255145] [client 20.151.10.161:46038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/alls.php"] [unique_id "al9L9P7v0rlcEGmVraE-xwAAAzI"]
[Tue Jul 21 07:37:40.054049 2026] [security2:error] [pid 254995:tid 255167] [client 20.197.195.24:21076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/simple.php"] [unique_id "al9L9P7v0rlcEGmVraE-yAAAA0g"]
[Tue Jul 21 07:37:40.191912 2026] [security2:error] [pid 255769:tid 255955] [client 20.197.195.24:63334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/ss.php"] [unique_id "al9L9LxMYwyVGnfuwsKYtQAAA9s"]
[Tue Jul 21 07:37:40.338158 2026] [autoindex:error] [pid 254995:tid 255223] [client 20.206.105.145:38466] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:40.360836 2026] [security2:error] [pid 255769:tid 255865] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-includes/woocommerce-call.php"] [unique_id "al9L9LxMYwyVGnfuwsKYuAAD118"], referer: http://aud-7.com/wp-includes/woocommerce-call.php
[Tue Jul 21 07:37:40.413718 2026] [autoindex:error] [pid 254995:tid 255142] [client 20.206.105.145:38466] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:40.419046 2026] [security2:error] [pid 254995:tid 255218] [client 20.206.105.145:38466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/crgio.php"] [unique_id "al9L9P7v0rlcEGmVraE-0AAAA3o"]
[Tue Jul 21 07:37:40.601442 2026] [security2:error] [pid 254995:tid 255127] [client 20.151.10.161:46078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/yyu.php"] [unique_id "al9L9P7v0rlcEGmVraE-1AAAAyA"]
[Tue Jul 21 07:37:40.783257 2026] [security2:error] [pid 255769:tid 255947] [client 45.8.17.137:48737] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/js/privacy-tools.min.php"] [unique_id "al9L9LxMYwyVGnfuwsKYvwAAA9M"]
[Tue Jul 21 07:37:40.831381 2026] [security2:error] [pid 254995:tid 255023] [remote 45.132.115.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.115.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lunarium.tec.br"] [uri "/wp-login.php"] [unique_id "al9L9P7v0rlcEGmVraE-2gADXhs"]
[Tue Jul 21 07:37:40.871955 2026] [security2:error] [pid 254995:tid 255267] [client 20.197.195.24:63635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/hypo.php"] [unique_id "al9L9P7v0rlcEGmVraE-3AAAA5E"]
[Tue Jul 21 07:37:40.874058 2026] [security2:error] [pid 255769:tid 255881] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/wordpress-seo/wp-seo-main-float.php"] [unique_id "al9L9LxMYwyVGnfuwsKYwgADxm8"], referer: http://aud-7.com/wp-content/plugins/wordpress-seo/wp-seo-main-float.php
[Tue Jul 21 07:37:40.903058 2026] [core:error] [pid 254995:tid 255265] [client 164.92.100.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.health-24.shop/
[Tue Jul 21 07:37:40.903078 2026] [core:error] [pid 254995:tid 255265] [client 164.92.100.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.health-24.shop/
[Tue Jul 21 07:37:41.059990 2026] [security2:error] [pid 255769:tid 255902] [client 45.251.232.145:49376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L9bxMYwyVGnfuwsKYxQAAA6Y"]
[Tue Jul 21 07:37:41.060115 2026] [security2:error] [pid 255769:tid 255902] [client 45.251.232.145:49376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L9bxMYwyVGnfuwsKYxQAAA6Y"]
[Tue Jul 21 07:37:41.111767 2026] [security2:error] [pid 255769:tid 255952] [client 20.151.10.161:45992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/by.php"] [unique_id "al9L9bxMYwyVGnfuwsKYxwAAA9g"]
[Tue Jul 21 07:37:41.188280 2026] [security2:error] [pid 255769:tid 256000] [client 20.197.195.24:63674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/users.php"] [unique_id "al9L9bxMYwyVGnfuwsKYyQAABAY"]
[Tue Jul 21 07:37:41.217007 2026] [security2:error] [pid 255769:tid 255931] [client 20.104.96.117:59659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9L9bxMYwyVGnfuwsKYygAAA8M"]
[Tue Jul 21 07:37:41.324179 2026] [security2:error] [pid 254995:tid 255208] [client 20.197.195.24:51830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/init.php"] [unique_id "al9L9f7v0rlcEGmVraE_AAAAA3A"]
[Tue Jul 21 07:37:41.399691 2026] [security2:error] [pid 255769:tid 256020] [client 136.144.33.108:42883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9L9bxMYwyVGnfuwsKYywAABBo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:41.539221 2026] [security2:error] [pid 255769:tid 255940] [client 139.167.225.182:64222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L9bxMYwyVGnfuwsKY0AAAA8w"]
[Tue Jul 21 07:37:41.539349 2026] [security2:error] [pid 255769:tid 255940] [client 139.167.225.182:64222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L9bxMYwyVGnfuwsKY0AAAA8w"]
[Tue Jul 21 07:37:41.573427 2026] [security2:error] [pid 254995:tid 255273] [client 20.197.195.24:21025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/fpwch.php"] [unique_id "al9L9f7v0rlcEGmVraE_BAAAA5c"]
[Tue Jul 21 07:37:41.634144 2026] [security2:error] [pid 254995:tid 255212] [client 20.197.195.24:63650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/177.php"] [unique_id "al9L9f7v0rlcEGmVraE_BQAAA3Q"]
[Tue Jul 21 07:37:41.733909 2026] [security2:error] [pid 255769:tid 255887] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/enhanced-text-widget/analyst/src/403x.php"] [unique_id "al9L9bxMYwyVGnfuwsKY0QAECXU"], referer: http://aud-7.com/wp-content/plugins/enhanced-text-widget/analyst/src/403x.php
[Tue Jul 21 07:37:41.760883 2026] [security2:error] [pid 254995:tid 255148] [client 20.151.10.161:46018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/FAQ.php"] [unique_id "al9L9f7v0rlcEGmVraE_CgAAAzU"]
[Tue Jul 21 07:37:41.906660 2026] [security2:error] [pid 254995:tid 255144] [client 20.104.96.117:61125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9L9f7v0rlcEGmVraE_DAAAAzE"]
[Tue Jul 21 07:37:42.075255 2026] [security2:error] [pid 255769:tid 255955] [client 45.8.17.118:59965] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/options.php"] [unique_id "al9L9rxMYwyVGnfuwsKY1wAAA9s"]
[Tue Jul 21 07:37:42.249076 2026] [security2:error] [pid 255769:tid 255869] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/news-portal/error.php"] [unique_id "al9L9rxMYwyVGnfuwsKY2gAD4GM"], referer: http://aud-7.com/wp-content/themes/news-portal/error.php
[Tue Jul 21 07:37:42.362835 2026] [security2:error] [pid 255769:tid 256021] [client 20.220.225.223:49558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/ace2.php"] [unique_id "al9L9rxMYwyVGnfuwsKY3QAABBs"]
[Tue Jul 21 07:37:42.383381 2026] [security2:error] [pid 254995:tid 255167] [client 20.197.195.24:63303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/config.php"] [unique_id "al9L9v7v0rlcEGmVraE_GwAAA0g"]
[Tue Jul 21 07:37:42.424488 2026] [autoindex:error] [pid 254995:tid 255213] [client 43.165.125.66:54716] AH01276: Cannot serve directory /home3/lianem44/ubaloc.store/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:42.595056 2026] [security2:error] [pid 254995:tid 255262] [client 173.252.95.18:49814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9L9v7v0rlcEGmVraE_JQAAA4w"]
[Tue Jul 21 07:37:42.608151 2026] [security2:error] [pid 254995:tid 255217] [client 117.217.38.194:52713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L9v7v0rlcEGmVraE_JgAAA3k"]
[Tue Jul 21 07:37:42.608248 2026] [security2:error] [pid 254995:tid 255217] [client 117.217.38.194:52713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L9v7v0rlcEGmVraE_JgAAA3k"]
[Tue Jul 21 07:37:42.629134 2026] [security2:error] [pid 255769:tid 255859] [remote 45.3.49.137:46551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.49.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9L9rxMYwyVGnfuwsKY4QAEFlk"]
[Tue Jul 21 07:37:42.658383 2026] [security2:error] [pid 254995:tid 255182] [client 20.151.10.161:45968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/coffexium.php"] [unique_id "al9L9v7v0rlcEGmVraE_JwAAA1c"]
[Tue Jul 21 07:37:42.711786 2026] [security2:error] [pid 255769:tid 255909] [client 20.197.195.24:51834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/domvf.php"] [unique_id "al9L9rxMYwyVGnfuwsKY4gAAA60"]
[Tue Jul 21 07:37:42.767283 2026] [security2:error] [pid 255769:tid 255856] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/fukasawa/inc/classes/403.php"] [unique_id "al9L9rxMYwyVGnfuwsKY4wAD5FY"], referer: http://aud-7.com/wp-content/themes/fukasawa/inc/classes/403.php
[Tue Jul 21 07:37:42.787894 2026] [security2:error] [pid 254995:tid 255127] [client 20.104.96.117:61079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9L9v7v0rlcEGmVraE_KwAAAyA"]
[Tue Jul 21 07:37:42.836093 2026] [security2:error] [pid 255769:tid 255866] [remote 217.182.128.41:43374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bellascleaningsolutionsllc.com"] [uri "/wp-login.php"] [unique_id "al9L9rxMYwyVGnfuwsKY5QAD4WA"]
[Tue Jul 21 07:37:42.899657 2026] [security2:error] [pid 254995:tid 255176] [client 20.197.195.24:63315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/gettest.php"] [unique_id "al9L9v7v0rlcEGmVraE_LgAAA1E"]
[Tue Jul 21 07:37:43.039533 2026] [security2:error] [pid 255769:tid 256002] [client 20.206.105.145:37906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/pucci.php"] [unique_id "al9L97xMYwyVGnfuwsKY5wAABAg"]
[Tue Jul 21 07:37:43.176381 2026] [security2:error] [pid 255769:tid 255900] [client 45.8.17.121:29303] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/user/wp-conflg.php"] [unique_id "al9L97xMYwyVGnfuwsKY6QAAA6Q"]
[Tue Jul 21 07:37:43.179987 2026] [security2:error] [pid 255769:tid 255917] [client 20.197.195.24:63621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/min.php"] [unique_id "al9L97xMYwyVGnfuwsKY6gAAA7U"]
[Tue Jul 21 07:37:43.229305 2026] [security2:error] [pid 254995:tid 255189] [client 173.24.185.52:57106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9L9_7v0rlcEGmVraE_NAAAA14"]
[Tue Jul 21 07:37:43.229464 2026] [security2:error] [pid 254995:tid 255189] [client 173.24.185.52:57106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9L9_7v0rlcEGmVraE_NAAAA14"]
[Tue Jul 21 07:37:43.284705 2026] [security2:error] [pid 255769:tid 255873] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/hello-plus/classes/ehp-sarang.php"] [unique_id "al9L97xMYwyVGnfuwsKY6wAD_Wc"], referer: http://aud-7.com/wp-content/plugins/hello-plus/classes/ehp-sarang.php
[Tue Jul 21 07:37:43.330450 2026] [security2:error] [pid 255769:tid 255895] [remote 173.252.95.20:43756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9L97xMYwyVGnfuwsKY6AAEFH0"]
[Tue Jul 21 07:37:43.441800 2026] [security2:error] [pid 255769:tid 255958] [client 20.197.195.24:21105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wp.php"] [unique_id "al9L97xMYwyVGnfuwsKY8gAAA94"]
[Tue Jul 21 07:37:43.480879 2026] [security2:error] [pid 255769:tid 255911] [client 20.151.10.161:46077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/red.php"] [unique_id "al9L97xMYwyVGnfuwsKY8wAAA68"]
[Tue Jul 21 07:37:43.530183 2026] [security2:error] [pid 254995:tid 255275] [client 20.197.195.24:63314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/dvjul.php"] [unique_id "al9L9_7v0rlcEGmVraE_OAAAA5k"]
[Tue Jul 21 07:37:43.600846 2026] [security2:error] [pid 254995:tid 255204] [client 117.251.86.144:35610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9L9_7v0rlcEGmVraE_PQAAA20"]
[Tue Jul 21 07:37:43.600967 2026] [security2:error] [pid 254995:tid 255204] [client 117.251.86.144:35610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9L9_7v0rlcEGmVraE_PQAAA20"]
[Tue Jul 21 07:37:43.791244 2026] [security2:error] [pid 255769:tid 255943] [client 103.162.129.114:55940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9L97xMYwyVGnfuwsKY9AAAA88"]
[Tue Jul 21 07:37:43.791409 2026] [security2:error] [pid 255769:tid 255943] [client 103.162.129.114:55940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9L97xMYwyVGnfuwsKY9AAAA88"]
[Tue Jul 21 07:37:43.800362 2026] [security2:error] [pid 255769:tid 255863] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/so-pinyin-slugs/inc/main_json.php"] [unique_id "al9L97xMYwyVGnfuwsKY9gADxF0"], referer: http://aud-7.com/wp-content/plugins/so-pinyin-slugs/inc/main_json.php
[Tue Jul 21 07:37:43.909187 2026] [autoindex:error] [pid 254995:tid 255112] [remote 49.234.192.248:0] AH01276: Cannot serve directory /home1/tavar035/brasilcertdigital.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://brasilcertdigital.online
[Tue Jul 21 07:37:43.959596 2026] [security2:error] [pid 254995:tid 255114] [remote 103.112.62.59:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.62.112.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9L9_7v0rlcEGmVraE_RQADIXY"]
[Tue Jul 21 07:37:44.091745 2026] [security2:error] [pid 255769:tid 255966] [client 20.197.195.24:63309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/biufile.php"] [unique_id "al9L-LxMYwyVGnfuwsKY_QAAA-Y"]
[Tue Jul 21 07:37:44.182787 2026] [security2:error] [pid 254995:tid 255170] [client 122.186.204.214:58069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L-P7v0rlcEGmVraE_SQAAA0s"]
[Tue Jul 21 07:37:44.182951 2026] [security2:error] [pid 254995:tid 255170] [client 122.186.204.214:58069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L-P7v0rlcEGmVraE_SQAAA0s"]
[Tue Jul 21 07:37:44.319808 2026] [security2:error] [pid 255769:tid 255833] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/filester/assets/css/404.php"] [unique_id "al9L-LxMYwyVGnfuwsKZBAAD6T8"], referer: http://aud-7.com/wp-content/plugins/filester/assets/css/404.php
[Tue Jul 21 07:37:44.363483 2026] [security2:error] [pid 254995:tid 255257] [client 20.104.96.117:59173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9L-P7v0rlcEGmVraE_TgAAA4c"]
[Tue Jul 21 07:37:44.369905 2026] [security2:error] [pid 254995:tid 255158] [client 45.8.17.144:40257] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/.well-known/"] [unique_id "al9L-P7v0rlcEGmVraE_TwAAAz8"]
[Tue Jul 21 07:37:44.417909 2026] [security2:error] [pid 255769:tid 255993] [client 193.36.225.152:49257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9L-LxMYwyVGnfuwsKZAgAABAA"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:37:44.574367 2026] [security2:error] [pid 254995:tid 255167] [client 20.226.60.151:51369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ctex1.php"] [unique_id "al9L-P7v0rlcEGmVraE_UwAAA0g"]
[Tue Jul 21 07:37:44.584645 2026] [security2:error] [pid 254995:tid 255017] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9L-P7v0rlcEGmVraE_VAADQxU"]
[Tue Jul 21 07:37:44.584846 2026] [security2:error] [pid 254995:tid 255162] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9L-P7v0rlcEGmVraE_VAADQxU"]
[Tue Jul 21 07:37:44.608830 2026] [security2:error] [pid 254995:tid 255169] [client 20.197.195.24:21021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/class.php"] [unique_id "al9L-P7v0rlcEGmVraE_VgAAA0o"]
[Tue Jul 21 07:37:44.811905 2026] [core:error] [pid 255769:tid 255964] [client 119.3.162.103:33358] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Tue Jul 21 07:37:44.841945 2026] [security2:error] [pid 255769:tid 255854] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/neve/assets/apps/dashboard/build/index.php"] [unique_id "al9L-LxMYwyVGnfuwsKZDAAD1lQ"], referer: http://aud-7.com/wp-content/themes/neve/assets/apps/dashboard/build/index.php
[Tue Jul 21 07:37:44.934939 2026] [autoindex:error] [pid 255769:tid 255985] [client 20.206.105.145:37945] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:44.939316 2026] [security2:error] [pid 255769:tid 255847] [remote 141.98.11.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.11.98.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9L-LxMYwyVGnfuwsKZEQAECE0"], referer: https://www.binance.com
[Tue Jul 21 07:37:44.941795 2026] [security2:error] [pid 255769:tid 255843] [remote 141.98.11.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.11.98.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9L-LxMYwyVGnfuwsKZEgAD_0k"], referer: https://www.binance.com
[Tue Jul 21 07:37:44.963294 2026] [autoindex:error] [pid 255769:tid 255922] [client 20.206.105.145:37945] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:44.969002 2026] [security2:error] [pid 255769:tid 255994] [client 20.206.105.145:37945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-temp.php"] [unique_id "al9L-LxMYwyVGnfuwsKZFQAABAE"]
[Tue Jul 21 07:37:45.103213 2026] [security2:error] [pid 255769:tid 255934] [client 20.151.10.161:46055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9L-bxMYwyVGnfuwsKZGwAAA8Y"]
[Tue Jul 21 07:37:45.116043 2026] [security2:error] [pid 255769:tid 255803] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-bxMYwyVGnfuwsKZHAAD_iE"]
[Tue Jul 21 07:37:45.116196 2026] [security2:error] [pid 255769:tid 255990] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-bxMYwyVGnfuwsKZHAAD_iE"]
[Tue Jul 21 07:37:45.230325 2026] [security2:error] [pid 255769:tid 255902] [client 20.197.195.24:21008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/echkm.php"] [unique_id "al9L-bxMYwyVGnfuwsKZHgAAA6Y"]
[Tue Jul 21 07:37:45.242653 2026] [security2:error] [pid 255769:tid 255956] [client 20.197.195.24:63305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/av.php"] [unique_id "al9L-bxMYwyVGnfuwsKZIAAAA9w"]
[Tue Jul 21 07:37:45.264154 2026] [security2:error] [pid 255769:tid 255951] [client 34.14.85.22:64969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.85.14.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seguryredes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-LxMYwyVGnfuwsKZAwAAA9c"]
[Tue Jul 21 07:37:45.329138 2026] [core:crit] [pid 255769:tid 255817] (13)Permission denied: [remote 141.98.11.42:0] AH00529: /home2/androa31/public_html/cgi-bin/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home2/androa31/public_html/cgi-bin/' is executable, referer: https://www.binance.com
[Tue Jul 21 07:37:45.331468 2026] [core:crit] [pid 255769:tid 255862] (13)Permission denied: [remote 141.98.11.42:0] AH00529: /home2/androa31/public_html/cgi-bin/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home2/androa31/public_html/cgi-bin/' is executable, referer: https://www.binance.com
[Tue Jul 21 07:37:45.355210 2026] [security2:error] [pid 255769:tid 255821] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/theme-check/main.php"] [unique_id "al9L-bxMYwyVGnfuwsKZIwAD7zM"], referer: http://aud-7.com/wp-content/themes/theme-check/main.php
[Tue Jul 21 07:37:45.503928 2026] [security2:error] [pid 254995:tid 255186] [client 20.197.195.24:20995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/lib.php"] [unique_id "al9L-f7v0rlcEGmVraE_jAAAA1s"]
[Tue Jul 21 07:37:45.575259 2026] [security2:error] [pid 254995:tid 255161] [client 45.8.17.105:56461] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-configs.php"] [unique_id "al9L-f7v0rlcEGmVraE_jgAAA0I"]
[Tue Jul 21 07:37:45.608884 2026] [security2:error] [pid 254995:tid 255137] [client 193.36.225.64:60837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9L-f7v0rlcEGmVraE_kAAAAyo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:45.661098 2026] [security2:error] [pid 254995:tid 255204] [client 34.14.85.22:62496] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9L-f7v0rlcEGmVraE_kwAAA20"]
[Tue Jul 21 07:37:45.775598 2026] [security2:error] [pid 254995:tid 255272] [client 20.197.195.24:21063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/login.php"] [unique_id "al9L-f7v0rlcEGmVraE_lQAAA5Y"]
[Tue Jul 21 07:37:45.877574 2026] [security2:error] [pid 255769:tid 255798] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/elementor/includes/interfaces/about.php"] [unique_id "al9L-bxMYwyVGnfuwsKZLAAD8xw"], referer: http://aud-7.com/wp-content/plugins/elementor/includes/interfaces/about.php
[Tue Jul 21 07:37:45.993847 2026] [security2:error] [pid 255769:tid 255955] [client 20.220.225.223:49809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/ms.php"] [unique_id "al9L-bxMYwyVGnfuwsKZMAAAA9s"]
[Tue Jul 21 07:37:45.997909 2026] [security2:error] [pid 254995:tid 255176] [client 175.45.70.82:63461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-f7v0rlcEGmVraE_mgAAA1E"]
[Tue Jul 21 07:37:45.998044 2026] [security2:error] [pid 254995:tid 255176] [client 175.45.70.82:63461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-f7v0rlcEGmVraE_mgAAA1E"]
[Tue Jul 21 07:37:46.115805 2026] [security2:error] [pid 255769:tid 255993] [client 20.151.10.161:46046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/footer.php"] [unique_id "al9L-rxMYwyVGnfuwsKZMgAABAA"]
[Tue Jul 21 07:37:46.151358 2026] [security2:error] [pid 254995:tid 255177] [client 34.14.85.22:57030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9L-v7v0rlcEGmVraE_nQAAA1I"]
[Tue Jul 21 07:37:46.247144 2026] [security2:error] [pid 255769:tid 255796] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-rxMYwyVGnfuwsKZNgADrRo"]
[Tue Jul 21 07:37:46.247267 2026] [security2:error] [pid 255769:tid 255909] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-rxMYwyVGnfuwsKZNgADrRo"]
[Tue Jul 21 07:37:46.272207 2026] [security2:error] [pid 255769:tid 256019] [client 20.104.96.117:61067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/albin.php"] [unique_id "al9L-rxMYwyVGnfuwsKZOAAABBk"]
[Tue Jul 21 07:37:46.383506 2026] [autoindex:error] [pid 254995:tid 255170] [client 20.206.105.145:37942] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/blocks/buttons/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:46.391754 2026] [security2:error] [pid 255769:tid 255864] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/wp-cache-sys/index.php"] [unique_id "al9L-rxMYwyVGnfuwsKZOgAD-V4"], referer: http://aud-7.com/wp-content/plugins/wp-cache-sys/index.php
[Tue Jul 21 07:37:46.393894 2026] [security2:error] [pid 254995:tid 255144] [client 20.206.105.145:37942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9L-v7v0rlcEGmVraE_owAAAzE"]
[Tue Jul 21 07:37:46.483498 2026] [security2:error] [pid 255769:tid 255835] [remote 184.168.124.4:33290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.124.168.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "frsadvocacia.net"] [uri "/wp-login.php"] [unique_id "al9L-rxMYwyVGnfuwsKZPgAD_EE"]
[Tue Jul 21 07:37:46.533282 2026] [security2:error] [pid 255769:tid 255986] [client 154.192.233.199:59926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-rxMYwyVGnfuwsKZPwAAA_o"]
[Tue Jul 21 07:37:46.533383 2026] [security2:error] [pid 255769:tid 255986] [client 154.192.233.199:59926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-rxMYwyVGnfuwsKZPwAAA_o"]
[Tue Jul 21 07:37:46.550657 2026] [security2:error] [pid 255769:tid 256022] [client 122.162.144.145:32394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9L-rxMYwyVGnfuwsKZQQAABBw"]
[Tue Jul 21 07:37:46.550853 2026] [security2:error] [pid 255769:tid 256022] [client 122.162.144.145:32394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9L-rxMYwyVGnfuwsKZQQAABBw"]
[Tue Jul 21 07:37:46.580546 2026] [security2:error] [pid 255769:tid 255900] [client 45.8.17.125:35681] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/class.php"] [unique_id "al9L-rxMYwyVGnfuwsKZQgAAA6Q"]
[Tue Jul 21 07:37:46.642381 2026] [security2:error] [pid 254995:tid 255266] [client 34.14.85.22:63445] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9L-v7v0rlcEGmVraE_qQAAA5A"]
[Tue Jul 21 07:37:46.718941 2026] [security2:error] [pid 255769:tid 255939] [client 20.197.195.24:21107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/a2.php"] [unique_id "al9L-rxMYwyVGnfuwsKZRQAAA8s"]
[Tue Jul 21 07:37:46.798977 2026] [security2:error] [pid 255769:tid 255956] [client 20.197.195.24:63663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/coffexium.php"] [unique_id "al9L-rxMYwyVGnfuwsKZSAAAA9w"]
[Tue Jul 21 07:37:46.816327 2026] [security2:error] [pid 255769:tid 256009] [client 103.106.20.201:52583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-rxMYwyVGnfuwsKZTQAABA8"]
[Tue Jul 21 07:37:46.816451 2026] [security2:error] [pid 255769:tid 256009] [client 103.106.20.201:52583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-rxMYwyVGnfuwsKZTQAABA8"]
[Tue Jul 21 07:37:46.909616 2026] [security2:error] [pid 255769:tid 255799] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/aatdgetgdg/main.php"] [unique_id "al9L-rxMYwyVGnfuwsKZTgAD3h0"], referer: http://aud-7.com/wp-content/plugins/aatdgetgdg/main.php
[Tue Jul 21 07:37:47.000310 2026] [core:error] [pid 254995:tid 255102] [remote 95.108.213.234:52058] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:37:47.000342 2026] [core:error] [pid 254995:tid 255102] [remote 95.108.213.234:52058] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:37:47.062477 2026] [security2:error] [pid 255769:tid 255943] [client 34.14.85.22:56528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9L-7xMYwyVGnfuwsKZUwAAA88"]
[Tue Jul 21 07:37:47.076754 2026] [security2:error] [pid 255769:tid 255969] [client 152.59.154.239:14080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-7xMYwyVGnfuwsKZVAAAA-k"]
[Tue Jul 21 07:37:47.076897 2026] [security2:error] [pid 255769:tid 255969] [client 152.59.154.239:14080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-7xMYwyVGnfuwsKZVAAAA-k"]
[Tue Jul 21 07:37:47.423605 2026] [security2:error] [pid 255769:tid 255771] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/pwnd/pwnd.php"] [unique_id "al9L-7xMYwyVGnfuwsKZXAAD8gE"], referer: http://aud-7.com/wp-content/plugins/pwnd/pwnd.php
[Tue Jul 21 07:37:47.466834 2026] [security2:error] [pid 255769:tid 255905] [client 20.197.195.24:63323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/core.php"] [unique_id "al9L-7xMYwyVGnfuwsKZXQAAA6k"]
[Tue Jul 21 07:37:47.471520 2026] [security2:error] [pid 254995:tid 255261] [client 34.14.85.22:62837] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9L-_7v0rlcEGmVraE_uAAAA4s"]
[Tue Jul 21 07:37:47.516909 2026] [security2:error] [pid 255769:tid 255930] [client 122.164.127.47:55475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9L-7xMYwyVGnfuwsKZXwAAA8I"]
[Tue Jul 21 07:37:47.517052 2026] [security2:error] [pid 255769:tid 255930] [client 122.164.127.47:55475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9L-7xMYwyVGnfuwsKZXwAAA8I"]
[Tue Jul 21 07:37:47.673197 2026] [security2:error] [pid 255769:tid 255980] [client 20.197.195.24:51758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/d61.php"] [unique_id "al9L-7xMYwyVGnfuwsKZYQAAA_Q"]
[Tue Jul 21 07:37:47.887835 2026] [security2:error] [pid 255769:tid 255954] [client 45.8.17.103:54447] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Text/Diff/Engine/"] [unique_id "al9L-7xMYwyVGnfuwsKZZAAAA9o"]
[Tue Jul 21 07:37:47.939264 2026] [security2:error] [pid 255769:tid 255890] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/StylePlugin/up.php"] [unique_id "al9L-7xMYwyVGnfuwsKZZQAEGXg"], referer: http://aud-7.com/wp-content/plugins/StylePlugin/up.php
[Tue Jul 21 07:37:47.941342 2026] [security2:error] [pid 254995:tid 255276] [client 34.14.85.22:58108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9L-_7v0rlcEGmVraE_wQAAA5o"]
[Tue Jul 21 07:37:47.987966 2026] [security2:error] [pid 255769:tid 255867] [remote 178.18.124.148:22066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.124.18.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/xmlrpc.php"] [unique_id "al9L-7xMYwyVGnfuwsKZZgAEG2E"]
[Tue Jul 21 07:37:47.988178 2026] [security2:error] [pid 255769:tid 256021] [client 178.18.124.148:22066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rlvmultiofertas.com"] [uri "/xmlrpc.php"] [unique_id "al9L-7xMYwyVGnfuwsKZZgAEG2E"]
[Tue Jul 21 07:37:48.092626 2026] [security2:error] [pid 255769:tid 255985] [client 20.220.225.223:38660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/yup.php"] [unique_id "al9L_LxMYwyVGnfuwsKZagAAA_k"]
[Tue Jul 21 07:37:48.280540 2026] [security2:error] [pid 255769:tid 255992] [client 173.252.95.20:45736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9L_LxMYwyVGnfuwsKZbwAAA_8"]
[Tue Jul 21 07:37:48.326430 2026] [security2:error] [pid 255769:tid 255899] [client 20.151.10.161:45970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-content/index.php"] [unique_id "al9L_LxMYwyVGnfuwsKZcQAAA6M"]
[Tue Jul 21 07:37:48.392691 2026] [security2:error] [pid 255769:tid 255827] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9L_LxMYwyVGnfuwsKZcgADzTk"]
[Tue Jul 21 07:37:48.392886 2026] [security2:error] [pid 255769:tid 255941] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9L_LxMYwyVGnfuwsKZcgADzTk"]
[Tue Jul 21 07:37:48.399273 2026] [security2:error] [pid 255769:tid 255923] [client 34.14.85.22:62733] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9L_LxMYwyVGnfuwsKZcwAAA7s"]
[Tue Jul 21 07:37:48.454889 2026] [security2:error] [pid 255769:tid 255813] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/semrush/x.php"] [unique_id "al9L_LxMYwyVGnfuwsKZdAAD6ys"], referer: http://aud-7.com/wp-content/plugins/semrush/x.php
[Tue Jul 21 07:37:48.655445 2026] [security2:error] [pid 254995:tid 255133] [client 20.197.195.24:51762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/info.php"] [unique_id "al9L_P7v0rlcEGmVraE_zQAAAyY"]
[Tue Jul 21 07:37:48.664059 2026] [security2:error] [pid 255769:tid 255975] [client 20.226.60.151:51351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/edorxrr.php"] [unique_id "al9L_LxMYwyVGnfuwsKZegAAA-8"]
[Tue Jul 21 07:37:48.761037 2026] [security2:error] [pid 255769:tid 256002] [client 103.174.34.15:59545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L_LxMYwyVGnfuwsKZhAAABAg"]
[Tue Jul 21 07:37:48.761174 2026] [security2:error] [pid 255769:tid 256002] [client 103.174.34.15:59545] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L_LxMYwyVGnfuwsKZhAAABAg"]
[Tue Jul 21 07:37:48.849336 2026] [security2:error] [pid 254995:tid 255212] [client 34.14.85.22:54253] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9L_P7v0rlcEGmVraE_0QAAA3Q"]
[Tue Jul 21 07:37:48.941305 2026] [security2:error] [pid 255769:tid 255946] [client 20.197.195.24:63325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/als.php"] [unique_id "al9L_LxMYwyVGnfuwsKZoQAAA9I"]
[Tue Jul 21 07:37:48.970320 2026] [security2:error] [pid 255769:tid 255993] [client 45.8.17.137:39579] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/content.php"] [unique_id "al9L_LxMYwyVGnfuwsKZpAAABAA"]
[Tue Jul 21 07:37:48.974955 2026] [security2:error] [pid 255769:tid 255881] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al9L_LxMYwyVGnfuwsKZpQAD9G8"], referer: http://aud-7.com/wp-content/plugins/fix/up.php
[Tue Jul 21 07:37:49.319973 2026] [security2:error] [pid 254995:tid 255177] [client 34.14.85.22:49167] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9L_f7v0rlcEGmVraE_1wAAA1I"]
[Tue Jul 21 07:37:49.475673 2026] [security2:error] [pid 255769:tid 255917] [client 20.197.195.24:63649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/simple.php"] [unique_id "al9L_bxMYwyVGnfuwsKZuAAAA7U"]
[Tue Jul 21 07:37:49.489951 2026] [security2:error] [pid 255769:tid 255877] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/wpcall-button/button-image.php"] [unique_id "al9L_bxMYwyVGnfuwsKZuQADpGs"], referer: http://aud-7.com/wp-content/plugins/wpcall-button/button-image.php
[Tue Jul 21 07:37:49.723654 2026] [security2:error] [pid 255769:tid 255915] [client 20.197.195.24:63297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/init.php"] [unique_id "al9L_bxMYwyVGnfuwsKZyAAAA7M"]
[Tue Jul 21 07:37:49.742067 2026] [security2:error] [pid 255769:tid 255975] [client 34.14.85.22:56857] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9L_bxMYwyVGnfuwsKZygAAA-8"]
[Tue Jul 21 07:37:49.791640 2026] [security2:error] [pid 255769:tid 255982] [client 173.252.95.40:50200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9L_LxMYwyVGnfuwsKZeQAAA_Y"]
[Tue Jul 21 07:37:49.907264 2026] [security2:error] [pid 255769:tid 255935] [client 136.144.33.97:44455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9L_bxMYwyVGnfuwsKZyQAAA8c"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:49.953455 2026] [security2:error] [pid 255769:tid 255964] [client 59.96.220.140:60576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9L_bxMYwyVGnfuwsKZ2wAAA-Q"]
[Tue Jul 21 07:37:49.954219 2026] [security2:error] [pid 255769:tid 255964] [client 59.96.220.140:60576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9L_bxMYwyVGnfuwsKZ2wAAA-Q"]
[Tue Jul 21 07:37:49.964778 2026] [security2:error] [pid 255769:tid 255951] [client 20.206.105.145:37907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/puc.php"] [unique_id "al9L_bxMYwyVGnfuwsKZ3AAAA9c"]
[Tue Jul 21 07:37:49.984875 2026] [security2:error] [pid 255769:tid 255901] [client 20.220.225.223:38659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/csa.php"] [unique_id "al9L_bxMYwyVGnfuwsKZ3wAAA6U"]
[Tue Jul 21 07:37:49.985635 2026] [security2:error] [pid 255769:tid 255953] [client 45.8.17.119:47463] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/css/dist/block-library/"] [unique_id "al9L_bxMYwyVGnfuwsKZ4AAAA9k"]
[Tue Jul 21 07:37:50.003936 2026] [security2:error] [pid 255769:tid 255798] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L_rxMYwyVGnfuwsKZ4gAEIhw"]
[Tue Jul 21 07:37:50.004067 2026] [security2:error] [pid 255769:tid 256028] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L_rxMYwyVGnfuwsKZ4gAEIhw"]
[Tue Jul 21 07:37:50.148977 2026] [security2:error] [pid 255769:tid 255796] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/index.php"] [unique_id "al9L_rxMYwyVGnfuwsKZ8AADtxo"], referer: http://aud-7.com/wp-content/plugins/index.php
[Tue Jul 21 07:37:50.234254 2026] [security2:error] [pid 255769:tid 255960] [client 34.14.85.22:57848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9L_rxMYwyVGnfuwsKZ8wAAA-A"]
[Tue Jul 21 07:37:50.238388 2026] [security2:error] [pid 255769:tid 256019] [client 37.140.223.119:53321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9L_bxMYwyVGnfuwsKZqgAABBk"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:37:50.239042 2026] [security2:error] [pid 254995:tid 255206] [client 20.197.195.24:63324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/fpwch.php"] [unique_id "al9L_v7v0rlcEGmVraE_4gAAA28"]
[Tue Jul 21 07:37:50.253026 2026] [security2:error] [pid 255769:tid 255965] [client 20.197.195.24:21067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/11.php"] [unique_id "al9L_rxMYwyVGnfuwsKZ9AAAA-U"]
[Tue Jul 21 07:37:50.303036 2026] [security2:error] [pid 255769:tid 255983] [client 20.104.96.117:61179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/cilus.php"] [unique_id "al9L_rxMYwyVGnfuwsKZ-QAAA_c"]
[Tue Jul 21 07:37:50.408215 2026] [security2:error] [pid 255769:tid 255944] [client 103.86.117.203:55141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L_rxMYwyVGnfuwsKZ-gAAA9A"]
[Tue Jul 21 07:37:50.408344 2026] [security2:error] [pid 255769:tid 255944] [client 103.86.117.203:55141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L_rxMYwyVGnfuwsKZ-gAAA9A"]
[Tue Jul 21 07:37:50.655990 2026] [security2:error] [pid 254995:tid 255252] [client 20.197.192.193:6339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/dp.php"] [unique_id "al9L_v7v0rlcEGmVraE_6wAAA4M"]
[Tue Jul 21 07:37:50.674509 2026] [security2:error] [pid 255769:tid 255800] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/advanced-llms-txt-generator/assets/css/css_json.php"] [unique_id "al9L_rxMYwyVGnfuwsKZ_AADpB4"], referer: http://aud-7.com/wp-content/plugins/advanced-llms-txt-generator/assets/css/css_json.php
[Tue Jul 21 07:37:50.686487 2026] [security2:error] [pid 255769:tid 255990] [client 34.14.85.22:62674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9L_rxMYwyVGnfuwsKZ_QAAA_4"]
[Tue Jul 21 07:37:50.725453 2026] [security2:error] [pid 255769:tid 255945] [client 20.206.105.145:38503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/themes.php"] [unique_id "al9L_rxMYwyVGnfuwsKZ_gAAA9E"]
[Tue Jul 21 07:37:50.798697 2026] [security2:error] [pid 255769:tid 255902] [client 20.52.136.55:1585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/goods.php"] [unique_id "al9L_rxMYwyVGnfuwsKaAQAAA6Y"]
[Tue Jul 21 07:37:50.861187 2026] [security2:error] [pid 254995:tid 255050] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L_v7v0rlcEGmVraE_7wADSDY"]
[Tue Jul 21 07:37:50.861322 2026] [security2:error] [pid 254995:tid 255167] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L_v7v0rlcEGmVraE_7wADSDY"]
[Tue Jul 21 07:37:50.887096 2026] [security2:error] [pid 254995:tid 255056] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9L_v7v0rlcEGmVraE_8QADdjw"]
[Tue Jul 21 07:37:51.195848 2026] [security2:error] [pid 255769:tid 255818] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "al9L_7xMYwyVGnfuwsKaCAAD6DA"], referer: http://aud-7.com/wp-content/plugins/linkpreview/index.php
[Tue Jul 21 07:37:51.320095 2026] [security2:error] [pid 254995:tid 255053] [remote 82.102.18.188:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L__7v0rlcEGmVraE_-QADbjk"]
[Tue Jul 21 07:37:51.384862 2026] [security2:error] [pid 255769:tid 255901] [client 20.197.195.24:63620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/domvf.php"] [unique_id "al9L_7xMYwyVGnfuwsKaCwAAA6U"]
[Tue Jul 21 07:37:51.386455 2026] [security2:error] [pid 254995:tid 255126] [client 20.104.96.117:59160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/gptsh.php"] [unique_id "al9L__7v0rlcEGmVraE_-wAAAx8"]
[Tue Jul 21 07:37:51.427087 2026] [security2:error] [pid 254995:tid 255129] [client 20.197.195.24:21054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/v2.php"] [unique_id "al9L__7v0rlcEGmVraE__gAAAyI"]
[Tue Jul 21 07:37:51.491243 2026] [security2:error] [pid 254995:tid 255276] [client 20.197.195.24:13286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp.php"] [unique_id "al9L__7v0rlcEGmVraFAAAAAA5o"]
[Tue Jul 21 07:37:51.554405 2026] [security2:error] [pid 254995:tid 255154] [client 20.197.195.24:63665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/class.php"] [unique_id "al9L__7v0rlcEGmVraFAAgAAAzs"]
[Tue Jul 21 07:37:51.555868 2026] [security2:error] [pid 255769:tid 256026] [client 20.206.105.145:38474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/dx.php"] [unique_id "al9L_7xMYwyVGnfuwsKaDgAABCA"]
[Tue Jul 21 07:37:51.593805 2026] [security2:error] [pid 255769:tid 255905] [client 20.197.195.24:62873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/echkm.php"] [unique_id "al9L_7xMYwyVGnfuwsKaDwAAA6k"]
[Tue Jul 21 07:37:51.636798 2026] [security2:error] [pid 254995:tid 255117] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9L__7v0rlcEGmVraFABAADgnk"]
[Tue Jul 21 07:37:51.705830 2026] [security2:error] [pid 255769:tid 255867] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9L_7xMYwyVGnfuwsKaFAADt2E"], referer: http://aud-7.com/wp-content/themes/index.php
[Tue Jul 21 07:37:51.769539 2026] [security2:error] [pid 254995:tid 255204] [client 20.197.195.24:62858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/lib.php"] [unique_id "al9L__7v0rlcEGmVraFABwAAA20"]
[Tue Jul 21 07:37:51.791646 2026] [security2:error] [pid 254995:tid 255111] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9L__7v0rlcEGmVraFACQADLXM"]
[Tue Jul 21 07:37:51.946029 2026] [security2:error] [pid 254995:tid 255069] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9L__7v0rlcEGmVraFADAADREk"]
[Tue Jul 21 07:37:52.045335 2026] [security2:error] [pid 255769:tid 255979] [client 20.104.96.117:61147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/rithin.php"] [unique_id "al9MALxMYwyVGnfuwsKaHgAAA_M"]
[Tue Jul 21 07:37:52.100123 2026] [security2:error] [pid 254995:tid 255107] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9MAP7v0rlcEGmVraFADwADTm8"]
[Tue Jul 21 07:37:52.176738 2026] [security2:error] [pid 255769:tid 255928] [client 20.197.195.24:63638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/login.php"] [unique_id "al9MALxMYwyVGnfuwsKaIAAAA8A"]
[Tue Jul 21 07:37:52.231197 2026] [security2:error] [pid 255769:tid 255808] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/builder-and-developer/inc/tgm/error.php"] [unique_id "al9MALxMYwyVGnfuwsKaIwAD1iY"], referer: http://aud-7.com/wp-content/themes/builder-and-developer/inc/tgm/error.php
[Tue Jul 21 07:37:52.254805 2026] [security2:error] [pid 254995:tid 255093] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9MAP7v0rlcEGmVraFAEgADYWE"]
[Tue Jul 21 07:37:52.266097 2026] [security2:error] [pid 254995:tid 255269] [client 20.197.195.24:21012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/panel.php"] [unique_id "al9MAP7v0rlcEGmVraFAEwAAA5M"]
[Tue Jul 21 07:37:52.311417 2026] [security2:error] [pid 255769:tid 255988] [client 20.151.10.161:46040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/zoro.php"] [unique_id "al9MALxMYwyVGnfuwsKaJAAAA_w"]
[Tue Jul 21 07:37:52.409919 2026] [security2:error] [pid 254995:tid 255013] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9MAP7v0rlcEGmVraFAFQADKhE"]
[Tue Jul 21 07:37:52.512617 2026] [security2:error] [pid 254995:tid 255131] [client 128.127.105.184:37736] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9L__7v0rlcEGmVraFAAQAAAyQ"]
[Tue Jul 21 07:37:52.512749 2026] [security2:error] [pid 254995:tid 255131] [client 128.127.105.184:37736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9L__7v0rlcEGmVraFAAQAAAyQ"]
[Tue Jul 21 07:37:52.525295 2026] [access_compat:error] [pid 254995:tid 255277] [client 162.241.63.68:30522] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:37:52.564949 2026] [security2:error] [pid 254995:tid 255024] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9MAP7v0rlcEGmVraFAGQADVBw"]
[Tue Jul 21 07:37:52.600827 2026] [security2:error] [pid 255769:tid 255945] [client 20.206.105.145:37943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/p.php"] [unique_id "al9MALxMYwyVGnfuwsKaJwAAA9E"]
[Tue Jul 21 07:37:52.661124 2026] [security2:error] [pid 255769:tid 255947] [client 20.220.225.223:38661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/min.php"] [unique_id "al9MALxMYwyVGnfuwsKaKgAAA9M"]
[Tue Jul 21 07:37:52.661158 2026] [security2:error] [pid 255769:tid 255902] [client 20.104.96.117:61148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/fffm.php"] [unique_id "al9MALxMYwyVGnfuwsKaKQAAA6Y"]
[Tue Jul 21 07:37:52.719829 2026] [security2:error] [pid 254995:tid 255015] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9MAP7v0rlcEGmVraFAGwADNhM"]
[Tue Jul 21 07:37:52.749701 2026] [security2:error] [pid 255769:tid 255839] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "al9MALxMYwyVGnfuwsKaKwADo0U"], referer: http://aud-7.com/wp-content/themes/pridmag/db.php?u
[Tue Jul 21 07:37:52.794062 2026] [security2:error] [pid 255769:tid 255987] [client 194.99.104.35:33212] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MALxMYwyVGnfuwsKaKAAAA_s"]
[Tue Jul 21 07:37:52.794156 2026] [security2:error] [pid 255769:tid 255987] [client 194.99.104.35:33212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MALxMYwyVGnfuwsKaKAAAA_s"]
[Tue Jul 21 07:37:52.873667 2026] [security2:error] [pid 254995:tid 255116] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9MAP7v0rlcEGmVraFAHwADU3g"]
[Tue Jul 21 07:37:52.909866 2026] [security2:error] [pid 255769:tid 256014] [client 20.197.195.24:21013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/dex.php"] [unique_id "al9MALxMYwyVGnfuwsKaLwAABBQ"]
[Tue Jul 21 07:37:53.028932 2026] [security2:error] [pid 254995:tid 255010] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9MAf7v0rlcEGmVraFAIQADTw4"]
[Tue Jul 21 07:37:53.112068 2026] [security2:error] [pid 255769:tid 255999] [client 20.104.96.117:59136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/dfre.php"] [unique_id "al9MAbxMYwyVGnfuwsKaMQAABAU"]
[Tue Jul 21 07:37:53.157468 2026] [autoindex:error] [pid 255769:tid 255943] [client 20.206.105.145:38504] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:53.162904 2026] [security2:error] [pid 255769:tid 255932] [client 117.217.38.194:53190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MAbxMYwyVGnfuwsKaMwAAA8Q"]
[Tue Jul 21 07:37:53.163008 2026] [security2:error] [pid 255769:tid 255932] [client 117.217.38.194:53190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MAbxMYwyVGnfuwsKaMwAAA8Q"]
[Tue Jul 21 07:37:53.167503 2026] [security2:error] [pid 255769:tid 255982] [client 20.206.105.145:38504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/bthil.php"] [unique_id "al9MAbxMYwyVGnfuwsKaNAAAA_Y"]
[Tue Jul 21 07:37:53.203138 2026] [security2:error] [pid 254995:tid 255058] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9MAf7v0rlcEGmVraFAJgADKT4"]
[Tue Jul 21 07:37:53.274394 2026] [security2:error] [pid 255769:tid 255840] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/theme-check/theme-check.php"] [unique_id "al9MAbxMYwyVGnfuwsKaNQAEGkY"], referer: http://aud-7.com/wp-content/themes/theme-check/theme-check.php
[Tue Jul 21 07:37:53.334254 2026] [security2:error] [pid 255769:tid 256006] [client 193.36.225.63:61157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MAbxMYwyVGnfuwsKaNwAABAw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:53.359131 2026] [security2:error] [pid 254995:tid 255104] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9MAf7v0rlcEGmVraFAKgADb2w"]
[Tue Jul 21 07:37:53.418125 2026] [security2:error] [pid 255769:tid 255920] [client 20.104.96.117:59178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-happy.php"] [unique_id "al9MAbxMYwyVGnfuwsKaOQAAA7g"]
[Tue Jul 21 07:37:53.460373 2026] [security2:error] [pid 254995:tid 255141] [client 20.226.60.151:51314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/miru1.php"] [unique_id "al9MAf7v0rlcEGmVraFALAAAAy4"]
[Tue Jul 21 07:37:53.513519 2026] [security2:error] [pid 254995:tid 255045] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9MAf7v0rlcEGmVraFALQADYjE"]
[Tue Jul 21 07:37:53.514152 2026] [security2:error] [pid 254995:tid 255023] [remote 104.207.54.136:30305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.54.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9MAf7v0rlcEGmVraFAKQADVhs"]
[Tue Jul 21 07:37:53.667973 2026] [security2:error] [pid 254995:tid 255021] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9MAf7v0rlcEGmVraFAMgADQxk"]
[Tue Jul 21 07:37:53.788144 2026] [security2:error] [pid 255769:tid 255949] [client 173.24.185.52:57573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MAbxMYwyVGnfuwsKaQAAAA9U"]
[Tue Jul 21 07:37:53.788265 2026] [security2:error] [pid 255769:tid 255949] [client 173.24.185.52:57573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MAbxMYwyVGnfuwsKaQAAAA9U"]
[Tue Jul 21 07:37:53.790029 2026] [security2:error] [pid 255769:tid 255802] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/Divi/404.php"] [unique_id "al9MAbxMYwyVGnfuwsKaQQAD0iA"], referer: http://aud-7.com/wp-content/themes/Divi/404.php
[Tue Jul 21 07:37:53.822172 2026] [security2:error] [pid 254995:tid 255001] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9MAf7v0rlcEGmVraFAMwADXAU"]
[Tue Jul 21 07:37:53.879066 2026] [security2:error] [pid 255769:tid 255998] [client 45.8.17.146:62463] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/post-terms/"] [unique_id "al9MAbxMYwyVGnfuwsKaQwAABAQ"]
[Tue Jul 21 07:37:53.970936 2026] [security2:error] [pid 255769:tid 255962] [client 20.206.105.145:38492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/7.php"] [unique_id "al9MAbxMYwyVGnfuwsKaRAAAA-I"]
[Tue Jul 21 07:37:53.975948 2026] [security2:error] [pid 254995:tid 255065] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9MAf7v0rlcEGmVraFANgADSEU"]
[Tue Jul 21 07:37:54.050539 2026] [security2:error] [pid 255769:tid 255966] [client 20.104.96.117:61145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/fpr4.php"] [unique_id "al9MArxMYwyVGnfuwsKaSAAAA-Y"]
[Tue Jul 21 07:37:54.245589 2026] [security2:error] [pid 255769:tid 256024] [client 20.197.195.24:51770] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "equoterapiaprosseguir.com"] [uri "/1.php"] [unique_id "al9MArxMYwyVGnfuwsKaSgAABB4"]
[Tue Jul 21 07:37:54.245703 2026] [security2:error] [pid 255769:tid 256024] [client 20.197.195.24:51770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/1.php"] [unique_id "al9MArxMYwyVGnfuwsKaSgAABB4"]
[Tue Jul 21 07:37:54.256875 2026] [security2:error] [pid 255769:tid 256016] [client 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/wp-admin/install.php"] [unique_id "al9MArxMYwyVGnfuwsKaSwAABBY"]
[Tue Jul 21 07:37:54.334001 2026] [security2:error] [pid 255769:tid 255953] [client 117.251.86.144:48168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MArxMYwyVGnfuwsKaTwAAA9k"]
[Tue Jul 21 07:37:54.334135 2026] [security2:error] [pid 255769:tid 255953] [client 117.251.86.144:48168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MArxMYwyVGnfuwsKaTwAAA9k"]
[Tue Jul 21 07:37:54.386886 2026] [security2:error] [pid 255769:tid 255922] [client 173.252.95.12:39850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9MArxMYwyVGnfuwsKaUgAAA7o"]
[Tue Jul 21 07:37:54.391190 2026] [security2:error] [pid 255769:tid 255990] [client 20.197.195.24:62867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/a2.php"] [unique_id "al9MArxMYwyVGnfuwsKaUwAAA_4"]
[Tue Jul 21 07:37:54.424355 2026] [security2:error] [pid 255769:tid 255902] [client 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9MArxMYwyVGnfuwsKaVAAAA6Y"]
[Tue Jul 21 07:37:54.521096 2026] [security2:error] [pid 254995:tid 255210] [client 20.206.105.145:37930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/8.php"] [unique_id "al9MAv7v0rlcEGmVraFAPwAAA3I"]
[Tue Jul 21 07:37:54.552134 2026] [security2:error] [pid 255769:tid 255967] [client 20.151.10.161:45981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/admin.php"] [unique_id "al9MArxMYwyVGnfuwsKaVQAAA-c"]
[Tue Jul 21 07:37:54.674393 2026] [security2:error] [pid 255769:tid 255912] [client 20.104.96.117:59179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/file88.php"] [unique_id "al9MArxMYwyVGnfuwsKaWQAAA7A"]
[Tue Jul 21 07:37:54.733203 2026] [security2:error] [pid 255769:tid 255952] [client 62.102.148.187:58438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9MArxMYwyVGnfuwsKaWgAAA9g"]
[Tue Jul 21 07:37:54.733328 2026] [security2:error] [pid 255769:tid 255952] [client 62.102.148.187:58438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9MArxMYwyVGnfuwsKaWgAAA9g"]
[Tue Jul 21 07:37:54.778656 2026] [security2:error] [pid 255769:tid 256021] [client 103.162.129.114:56385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9MArxMYwyVGnfuwsKaWwAABBs"]
[Tue Jul 21 07:37:54.778793 2026] [security2:error] [pid 255769:tid 256021] [client 103.162.129.114:56385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9MArxMYwyVGnfuwsKaWwAABBs"]
[Tue Jul 21 07:37:54.916773 2026] [security2:error] [pid 255769:tid 255950] [client 122.186.204.214:58596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MArxMYwyVGnfuwsKaXQAAA9Y"]
[Tue Jul 21 07:37:54.916889 2026] [security2:error] [pid 255769:tid 255950] [client 122.186.204.214:58596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MArxMYwyVGnfuwsKaXQAAA9Y"]
[Tue Jul 21 07:37:54.934706 2026] [security2:error] [pid 255769:tid 255956] [client 172.245.102.34:38685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MArxMYwyVGnfuwsKaXgAAA9w"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:37:54.975275 2026] [security2:error] [pid 255769:tid 255964] [client 45.8.17.122:22549] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/b.php"] [unique_id "al9MArxMYwyVGnfuwsKaXwAAA-Q"]
[Tue Jul 21 07:37:55.062516 2026] [security2:error] [pid 254995:tid 255265] [client 20.206.105.145:38089] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.liranesuliano.com.br"] [uri "/1.php"] [unique_id "al9MA_7v0rlcEGmVraFARgAAA48"]
[Tue Jul 21 07:37:55.062633 2026] [security2:error] [pid 254995:tid 255265] [client 20.206.105.145:38089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/1.php"] [unique_id "al9MA_7v0rlcEGmVraFARgAAA48"]
[Tue Jul 21 07:37:55.074819 2026] [security2:error] [pid 255769:tid 256017] [client 20.197.195.24:63672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/d61.php"] [unique_id "al9MA7xMYwyVGnfuwsKaYAAABBc"]
[Tue Jul 21 07:37:55.082030 2026] [security2:error] [pid 255769:tid 255884] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MA7xMYwyVGnfuwsKaYQADv3I"]
[Tue Jul 21 07:37:55.082178 2026] [security2:error] [pid 255769:tid 255927] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MA7xMYwyVGnfuwsKaYQADv3I"]
[Tue Jul 21 07:37:55.136026 2026] [security2:error] [pid 255769:tid 255968] [client 20.104.96.117:61109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/ccc.php"] [unique_id "al9MA7xMYwyVGnfuwsKaZQAAA-g"]
[Tue Jul 21 07:37:55.161345 2026] [security2:error] [pid 254995:tid 255262] [client 20.220.225.223:38690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/jj.php"] [unique_id "al9MA_7v0rlcEGmVraFASAAAA4w"]
[Tue Jul 21 07:37:55.268420 2026] [security2:error] [pid 254995:tid 255083] [remote 152.42.137.70:32984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.137.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wp-login.php"] [unique_id "al9MA_7v0rlcEGmVraFASgADOVc"]
[Tue Jul 21 07:37:55.278936 2026] [security2:error] [pid 255769:tid 255928] [client 20.197.195.24:51791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/ms.php"] [unique_id "al9MA7xMYwyVGnfuwsKabgAAA8A"]
[Tue Jul 21 07:37:55.307057 2026] [security2:error] [pid 255769:tid 255970] [client 139.167.225.182:64867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MA7xMYwyVGnfuwsKaZgAAA-o"]
[Tue Jul 21 07:37:55.307156 2026] [security2:error] [pid 255769:tid 255970] [client 139.167.225.182:64867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MA7xMYwyVGnfuwsKaZgAAA-o"]
[Tue Jul 21 07:37:55.481835 2026] [security2:error] [pid 255769:tid 255816] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/bltm/wp-login.php"] [unique_id "al9MArxMYwyVGnfuwsKaTgAD_C4"], referer: http://aud-7.com/wp-content/themes/bltm/wp-login.php
[Tue Jul 21 07:37:55.653934 2026] [security2:error] [pid 255769:tid 255852] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MA7xMYwyVGnfuwsKadQAD6VI"]
[Tue Jul 21 07:37:55.654127 2026] [security2:error] [pid 255769:tid 255969] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MA7xMYwyVGnfuwsKadQAD6VI"]
[Tue Jul 21 07:37:55.888917 2026] [security2:error] [pid 255769:tid 255951] [client 20.226.60.151:51281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/sump1.php"] [unique_id "al9MA7xMYwyVGnfuwsKaegAAA9c"]
[Tue Jul 21 07:37:55.934140 2026] [security2:error] [pid 255769:tid 255910] [client 20.206.105.145:38491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/100.php"] [unique_id "al9MA7xMYwyVGnfuwsKafAAAA64"]
[Tue Jul 21 07:37:55.961178 2026] [security2:error] [pid 255769:tid 256020] [client 20.104.96.117:61087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/777.php"] [unique_id "al9MA7xMYwyVGnfuwsKafgAABBo"]
[Tue Jul 21 07:37:55.996893 2026] [security2:error] [pid 255769:tid 255777] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al9MA7xMYwyVGnfuwsKafwADuwc"], referer: http://aud-7.com/wp-content/themes/seotheme/db.php?u
[Tue Jul 21 07:37:56.008439 2026] [security2:error] [pid 255769:tid 256021] [client 20.197.195.24:63641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/info.php"] [unique_id "al9MBLxMYwyVGnfuwsKagAAABBs"]
[Tue Jul 21 07:37:56.091093 2026] [security2:error] [pid 255769:tid 255956] [client 20.151.10.161:45991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/greap.php"] [unique_id "al9MBLxMYwyVGnfuwsKaggAAA9w"]
[Tue Jul 21 07:37:56.184002 2026] [security2:error] [pid 255769:tid 255964] [client 45.8.17.137:41093] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/audio/"] [unique_id "al9MBLxMYwyVGnfuwsKagwAAA-Q"]
[Tue Jul 21 07:37:56.232186 2026] [autoindex:error] [pid 254995:tid 255273] [client 20.197.195.24:21103] AH01276: Cannot serve directory /home3/equote29/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:56.241312 2026] [security2:error] [pid 254995:tid 255274] [client 20.197.195.24:21103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/memberfuns.php"] [unique_id "al9MBP7v0rlcEGmVraFAXQAAA5g"]
[Tue Jul 21 07:37:56.315105 2026] [security2:error] [pid 254995:tid 255171] [client 128.127.105.184:37750] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MBP7v0rlcEGmVraFAXgAAA0w"]
[Tue Jul 21 07:37:56.315215 2026] [security2:error] [pid 254995:tid 255171] [client 128.127.105.184:37750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MBP7v0rlcEGmVraFAXgAAA0w"]
[Tue Jul 21 07:37:56.364919 2026] [http2:info] [pid 255769:tid 255968] [client 162.158.163.150:14241] AH10180: h2_stream(255769-1264-1,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 07:37:56.513841 2026] [security2:error] [pid 255769:tid 255905] [client 74.7.241.178:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "eltonrpferreira1782856652665.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9MBLxMYwyVGnfuwsKaigADqUc"]
[Tue Jul 21 07:37:56.516616 2026] [security2:error] [pid 255769:tid 255891] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/twentytwentythree/patterns/index.php"] [unique_id "al9MBLxMYwyVGnfuwsKaiwAECXk"], referer: http://aud-7.com/wp-content/themes/twentytwentythree/patterns/index.php
[Tue Jul 21 07:37:56.685905 2026] [security2:error] [pid 255769:tid 255926] [client 20.220.225.223:38703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/dragonshell.php"] [unique_id "al9MBLxMYwyVGnfuwsKakAAAA74"]
[Tue Jul 21 07:37:56.692182 2026] [http2:info] [pid 255769:tid 255966] [client 162.158.163.150:14241] AH10180: h2_stream(255769-1264-3,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 07:37:56.767965 2026] [security2:error] [pid 255769:tid 255970] [client 20.104.96.117:61092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/for.php"] [unique_id "al9MBLxMYwyVGnfuwsKalAAAA-o"]
[Tue Jul 21 07:37:56.783038 2026] [security2:error] [pid 255769:tid 255875] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MBLxMYwyVGnfuwsKalgADt2k"]
[Tue Jul 21 07:37:56.783231 2026] [security2:error] [pid 255769:tid 255919] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MBLxMYwyVGnfuwsKalgADt2k"]
[Tue Jul 21 07:37:56.784169 2026] [security2:error] [pid 254995:tid 255137] [client 175.45.70.82:63975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MBP7v0rlcEGmVraFAZQAAAyo"]
[Tue Jul 21 07:37:56.784264 2026] [security2:error] [pid 254995:tid 255137] [client 175.45.70.82:63975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MBP7v0rlcEGmVraFAZQAAAyo"]
[Tue Jul 21 07:37:56.871366 2026] [security2:error] [pid 254995:tid 255156] [client 20.151.10.161:46056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/177.php"] [unique_id "al9MBP7v0rlcEGmVraFAZwAAAz0"]
[Tue Jul 21 07:37:56.934791 2026] [security2:error] [pid 254995:tid 255215] [client 20.197.195.24:63322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/11.php"] [unique_id "al9MBP7v0rlcEGmVraFAaAAAA3c"]
[Tue Jul 21 07:37:57.013721 2026] [http2:info] [pid 255769:tid 255934] [client 162.158.163.150:14241] AH10180: h2_stream(255769-1264-5,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 07:37:57.030038 2026] [security2:error] [pid 255769:tid 255809] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/SecurityFin/SecurityFin.php"] [unique_id "al9MBbxMYwyVGnfuwsKamAAD0Sc"], referer: http://aud-7.com/wp-content/plugins/SecurityFin/SecurityFin.php
[Tue Jul 21 07:37:57.225910 2026] [security2:error] [pid 254995:tid 255160] [client 20.206.105.145:38516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/about.php"] [unique_id "al9MBf7v0rlcEGmVraFAbgAAA0E"]
[Tue Jul 21 07:37:57.260902 2026] [security2:error] [pid 254995:tid 255170] [client 122.162.144.145:4708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MBf7v0rlcEGmVraFAbwAAA0s"]
[Tue Jul 21 07:37:57.261005 2026] [security2:error] [pid 254995:tid 255170] [client 122.162.144.145:4708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MBf7v0rlcEGmVraFAbwAAA0s"]
[Tue Jul 21 07:37:57.263214 2026] [security2:error] [pid 254995:tid 255144] [client 154.192.233.199:59837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MBf7v0rlcEGmVraFAcAAAAzE"]
[Tue Jul 21 07:37:57.263336 2026] [security2:error] [pid 254995:tid 255144] [client 154.192.233.199:59837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MBf7v0rlcEGmVraFAcAAAAzE"]
[Tue Jul 21 07:37:57.275201 2026] [security2:error] [pid 254995:tid 255130] [client 45.8.17.141:37499] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/class-db.php"] [unique_id "al9MBf7v0rlcEGmVraFAcgAAAyM"]
[Tue Jul 21 07:37:57.282092 2026] [security2:error] [pid 254995:tid 255217] [client 20.197.195.24:51746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/0.php"] [unique_id "al9MBf7v0rlcEGmVraFAcwAAA3k"]
[Tue Jul 21 07:37:57.340375 2026] [http2:info] [pid 255769:tid 255911] [client 162.158.163.150:14241] AH10180: h2_stream(255769-1264-7,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 07:37:57.391261 2026] [security2:error] [pid 254995:tid 255147] [client 20.226.60.151:27595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/file5.php"] [unique_id "al9MBf7v0rlcEGmVraFAdQAAAzQ"]
[Tue Jul 21 07:37:57.487082 2026] [security2:error] [pid 255769:tid 255915] [client 20.197.195.24:63664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/v2.php"] [unique_id "al9MBbxMYwyVGnfuwsKangAAA7M"]
[Tue Jul 21 07:37:57.556288 2026] [security2:error] [pid 255769:tid 255939] [client 184.75.223.211:58094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MBbxMYwyVGnfuwsKaoAAAA8s"]
[Tue Jul 21 07:37:57.556424 2026] [security2:error] [pid 255769:tid 255939] [client 184.75.223.211:58094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MBbxMYwyVGnfuwsKaoAAAA8s"]
[Tue Jul 21 07:37:57.562162 2026] [security2:error] [pid 255769:tid 255846] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/file-upload-types/assets/css/403x.php"] [unique_id "al9MBbxMYwyVGnfuwsKaogAEFEw"], referer: http://aud-7.com/wp-content/plugins/file-upload-types/assets/css/403x.php
[Tue Jul 21 07:37:57.608639 2026] [security2:error] [pid 254995:tid 255257] [client 103.106.20.201:53166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MBf7v0rlcEGmVraFAfwAAA4c"]
[Tue Jul 21 07:37:57.609309 2026] [security2:error] [pid 254995:tid 255257] [client 103.106.20.201:53166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MBf7v0rlcEGmVraFAfwAAA4c"]
[Tue Jul 21 07:37:57.670766 2026] [http2:info] [pid 255769:tid 255912] [client 162.158.163.150:14241] AH10180: h2_stream(255769-1264-9,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 07:37:57.674027 2026] [security2:error] [pid 255769:tid 255981] [client 20.104.96.117:59701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/ssla.php"] [unique_id "al9MBbxMYwyVGnfuwsKapgAAA_U"]
[Tue Jul 21 07:37:57.769003 2026] [security2:error] [pid 255769:tid 255921] [client 20.226.60.151:51374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/file5.php"] [unique_id "al9MBbxMYwyVGnfuwsKapwAAA7k"]
[Tue Jul 21 07:37:57.955571 2026] [security2:error] [pid 254995:tid 255208] [client 20.151.10.161:46044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/199.php"] [unique_id "al9MBf7v0rlcEGmVraFAhwAAA3A"]
[Tue Jul 21 07:37:58.100258 2026] [security2:error] [pid 255769:tid 255869] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/penci-bookmark-follow/inc/admin/forms/penci-bf-users-logs-profile.php"] [unique_id "al9MBrxMYwyVGnfuwsKaqwAEImM"], referer: http://aud-7.com/wp-content/plugins/penci-bookmark-follow/inc/admin/forms/penci-bf-users-logs-profile.php
[Tue Jul 21 07:37:58.192706 2026] [security2:error] [pid 255769:tid 255937] [client 20.197.195.24:20993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/BDKR28.php"] [unique_id "al9MBrxMYwyVGnfuwsKargAAA8k"]
[Tue Jul 21 07:37:58.298429 2026] [security2:error] [pid 255769:tid 255950] [client 193.36.225.10:64369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MBrxMYwyVGnfuwsKarQAAA9Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:58.372317 2026] [security2:error] [pid 254995:tid 255131] [client 45.8.17.117:39225] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/readme.php"] [unique_id "al9MBv7v0rlcEGmVraFAjgAAAyQ"]
[Tue Jul 21 07:37:58.530276 2026] [security2:error] [pid 254995:tid 255254] [client 20.104.96.117:59176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/zc-131.php"] [unique_id "al9MBv7v0rlcEGmVraFAkAAAA4Q"]
[Tue Jul 21 07:37:58.620765 2026] [security2:error] [pid 255769:tid 255866] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/penci-mobile-templates/functions.php"] [unique_id "al9MBrxMYwyVGnfuwsKasQADqWA"], referer: http://aud-7.com/wp-content/plugins/penci-mobile-templates/functions.php
[Tue Jul 21 07:37:58.741198 2026] [security2:error] [pid 255769:tid 255971] [client 20.206.105.145:38226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/admin.php"] [unique_id "al9MBrxMYwyVGnfuwsKaswAAA-s"]
[Tue Jul 21 07:37:58.763166 2026] [security2:error] [pid 255769:tid 255982] [client 152.59.154.239:59194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MBrxMYwyVGnfuwsKatAAAA_Y"]
[Tue Jul 21 07:37:58.767876 2026] [security2:error] [pid 255769:tid 255982] [client 152.59.154.239:59194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MBrxMYwyVGnfuwsKatAAAA_Y"]
[Tue Jul 21 07:37:58.897384 2026] [security2:error] [pid 255769:tid 255979] [client 20.151.10.161:46067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file52.php"] [unique_id "al9MBrxMYwyVGnfuwsKatwAAA_M"]
[Tue Jul 21 07:37:58.901170 2026] [security2:error] [pid 254995:tid 255052] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MBv7v0rlcEGmVraFAlwADTTg"]
[Tue Jul 21 07:37:58.901372 2026] [security2:error] [pid 254995:tid 255172] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MBv7v0rlcEGmVraFAlwADTTg"]
[Tue Jul 21 07:37:58.966751 2026] [security2:error] [pid 255769:tid 255970] [client 20.197.195.24:63328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/panel.php"] [unique_id "al9MBrxMYwyVGnfuwsKaugAAA-o"]
[Tue Jul 21 07:37:59.084834 2026] [security2:error] [pid 255769:tid 255969] [client 122.164.127.47:55979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MB7xMYwyVGnfuwsKauwAAA-k"]
[Tue Jul 21 07:37:59.086670 2026] [security2:error] [pid 255769:tid 255969] [client 122.164.127.47:55979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MB7xMYwyVGnfuwsKauwAAA-k"]
[Tue Jul 21 07:37:59.143775 2026] [security2:error] [pid 255769:tid 255848] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "al9MB7xMYwyVGnfuwsKavAAEFk4"], referer: http://aud-7.com/wp-content/plugins/dummyyummy/wp-signup.php
[Tue Jul 21 07:37:59.182487 2026] [security2:error] [pid 255769:tid 255986] [client 45.8.17.135:45339] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/files/index.php"] [unique_id "al9MB7xMYwyVGnfuwsKavQAAA_o"]
[Tue Jul 21 07:37:59.199759 2026] [security2:error] [pid 255769:tid 255859] [remote 45.3.41.202:33757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.41.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9MBrxMYwyVGnfuwsKarwAD2Fk"]
[Tue Jul 21 07:37:59.245181 2026] [security2:error] [pid 254995:tid 255137] [client 193.36.225.118:43843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MB_7v0rlcEGmVraFAmQAAAyo"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:37:59.371983 2026] [security2:error] [pid 254995:tid 255174] [client 20.197.195.24:21073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/green1.php"] [unique_id "al9MB_7v0rlcEGmVraFAoAAAA08"]
[Tue Jul 21 07:37:59.428249 2026] [security2:error] [pid 255769:tid 255899] [client 20.197.192.193:6341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/old.php"] [unique_id "al9MB7xMYwyVGnfuwsKaxAAAA6M"]
[Tue Jul 21 07:37:59.511570 2026] [security2:error] [pid 255769:tid 255926] [client 103.174.34.15:60035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MB7xMYwyVGnfuwsKayAAAA74"]
[Tue Jul 21 07:37:59.511675 2026] [security2:error] [pid 255769:tid 255926] [client 103.174.34.15:60035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MB7xMYwyVGnfuwsKayAAAA74"]
[Tue Jul 21 07:37:59.586430 2026] [security2:error] [pid 255769:tid 255987] [client 20.220.225.223:38693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/echkm.php"] [unique_id "al9MB7xMYwyVGnfuwsKaywAAA_s"]
[Tue Jul 21 07:37:59.651524 2026] [security2:error] [pid 255769:tid 255912] [client 4.204.201.85:55495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MB7xMYwyVGnfuwsKazgAAA7A"]
[Tue Jul 21 07:37:59.661151 2026] [security2:error] [pid 255769:tid 255886] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/core/core.php"] [unique_id "al9MB7xMYwyVGnfuwsKazwAD9XQ"], referer: http://aud-7.com/wp-content/plugins/core/core.php
[Tue Jul 21 07:37:59.869328 2026] [security2:error] [pid 255769:tid 255935] [client 184.75.223.211:46002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9MB7xMYwyVGnfuwsKa1gAAA8c"]
[Tue Jul 21 07:37:59.869415 2026] [security2:error] [pid 255769:tid 255935] [client 184.75.223.211:46002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9MB7xMYwyVGnfuwsKa1gAAA8c"]
[Tue Jul 21 07:37:59.937508 2026] [security2:error] [pid 255769:tid 255990] [client 184.154.139.46:36456] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "diskvidros.com.br"] [uri "/index.php"] [unique_id "al9MB7xMYwyVGnfuwsKayQAAA_4"]
[Tue Jul 21 07:37:59.958144 2026] [security2:error] [pid 254995:tid 255194] [client 20.52.136.55:1567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/init.php"] [unique_id "al9MB_7v0rlcEGmVraFAqAAAA2M"]
[Tue Jul 21 07:37:59.961996 2026] [security2:error] [pid 254995:tid 255223] [client 4.204.201.85:55991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MB_7v0rlcEGmVraFAqgAAA38"]
[Tue Jul 21 07:37:59.997898 2026] [security2:error] [pid 255769:tid 255937] [client 20.197.195.24:63669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/dex.php"] [unique_id "al9MB7xMYwyVGnfuwsKa1wAAA8k"]
[Tue Jul 21 07:38:00.176521 2026] [security2:error] [pid 255769:tid 255833] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/schema/yanz.php"] [unique_id "al9MCLxMYwyVGnfuwsKa2QAD1T8"], referer: http://aud-7.com/wp-content/plugins/schema/yanz.php
[Tue Jul 21 07:38:00.276760 2026] [security2:error] [pid 254995:tid 255144] [client 45.8.17.123:49431] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "al9MCP7v0rlcEGmVraFArgAAAzE"]
[Tue Jul 21 07:38:00.347100 2026] [security2:error] [pid 255769:tid 255965] [client 20.226.60.151:51268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/0xD.php"] [unique_id "al9MCLxMYwyVGnfuwsKa2wAAA-U"]
[Tue Jul 21 07:38:00.347624 2026] [security2:error] [pid 254995:tid 255261] [client 4.204.201.85:57100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/x.php"] [unique_id "al9MCP7v0rlcEGmVraFAsQAAA4s"]
[Tue Jul 21 07:38:00.372081 2026] [security2:error] [pid 254995:tid 255150] [client 20.197.192.193:6347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/ms-new.php"] [unique_id "al9MCP7v0rlcEGmVraFAsgAAAzc"]
[Tue Jul 21 07:38:00.593616 2026] [security2:error] [pid 255769:tid 256016] [client 20.197.195.24:51764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/nc4.php"] [unique_id "al9MCLxMYwyVGnfuwsKa4wAABBY"]
[Tue Jul 21 07:38:00.664915 2026] [security2:error] [pid 255769:tid 255954] [client 4.204.201.85:57123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/mgrr.php"] [unique_id "al9MCLxMYwyVGnfuwsKbCQAAA9o"]
[Tue Jul 21 07:38:00.682102 2026] [security2:error] [pid 255769:tid 255810] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MCLxMYwyVGnfuwsKbCgAD4Sg"]
[Tue Jul 21 07:38:00.682265 2026] [security2:error] [pid 255769:tid 255961] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MCLxMYwyVGnfuwsKbCgAD4Sg"]
[Tue Jul 21 07:38:00.826054 2026] [security2:error] [pid 255769:tid 255894] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/pwnd-1/pwnd.php"] [unique_id "al9MCLxMYwyVGnfuwsKbGAAD3Xw"], referer: http://aud-7.com/wp-content/plugins/pwnd-1/pwnd.php
[Tue Jul 21 07:38:00.868012 2026] [security2:error] [pid 255769:tid 255946] [client 103.86.117.203:55662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MCLxMYwyVGnfuwsKbHgAAA9I"]
[Tue Jul 21 07:38:00.868173 2026] [security2:error] [pid 255769:tid 255946] [client 103.86.117.203:55662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MCLxMYwyVGnfuwsKbHgAAA9I"]
[Tue Jul 21 07:38:00.888108 2026] [security2:error] [pid 255769:tid 255936] [client 20.151.10.161:46021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/122.php"] [unique_id "al9MCLxMYwyVGnfuwsKbHwAAA8g"]
[Tue Jul 21 07:38:00.932718 2026] [security2:error] [pid 254995:tid 255266] [client 20.197.192.193:6870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/track.php"] [unique_id "al9MCP7v0rlcEGmVraFAuAAAA5A"]
[Tue Jul 21 07:38:00.974485 2026] [security2:error] [pid 254995:tid 255211] [client 4.204.201.85:57167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/stdin.php"] [unique_id "al9MCP7v0rlcEGmVraFAugAAA3M"]
[Tue Jul 21 07:38:01.260740 2026] [security2:error] [pid 255769:tid 255922] [client 4.204.201.85:57180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/BDKR28.php"] [unique_id "al9MCbxMYwyVGnfuwsKbKQAAA7o"]
[Tue Jul 21 07:38:01.343000 2026] [security2:error] [pid 255769:tid 255872] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/init-help/init.php"] [unique_id "al9MCbxMYwyVGnfuwsKbLAAED2Y"], referer: http://aud-7.com/wp-content/plugins/init-help/init.php
[Tue Jul 21 07:38:01.476238 2026] [security2:error] [pid 254995:tid 255208] [client 45.8.17.60:21087] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/"] [unique_id "al9MCf7v0rlcEGmVraFAwQAAA3A"]
[Tue Jul 21 07:38:01.481419 2026] [security2:error] [pid 255769:tid 256021] [client 20.197.192.193:6370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/2352356666.php"] [unique_id "al9MCbxMYwyVGnfuwsKbLwAABBs"]
[Tue Jul 21 07:38:01.539792 2026] [security2:error] [pid 254995:tid 255140] [client 4.204.201.85:57206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/001.php"] [unique_id "al9MCf7v0rlcEGmVraFAwgAAAy0"]
[Tue Jul 21 07:38:01.590377 2026] [security2:error] [pid 254995:tid 255173] [client 20.197.195.24:63348] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "evelinemilfontadv.com"] [uri "/1.php"] [unique_id "al9MCf7v0rlcEGmVraFAxAAAA04"]
[Tue Jul 21 07:38:01.590496 2026] [security2:error] [pid 254995:tid 255173] [client 20.197.195.24:63348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/1.php"] [unique_id "al9MCf7v0rlcEGmVraFAxAAAA04"]
[Tue Jul 21 07:38:01.605562 2026] [security2:error] [pid 255769:tid 255901] [client 59.96.220.140:61087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MCbxMYwyVGnfuwsKbNAAAA6U"]
[Tue Jul 21 07:38:01.606091 2026] [security2:error] [pid 255769:tid 255901] [client 59.96.220.140:61087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MCbxMYwyVGnfuwsKbNAAAA6U"]
[Tue Jul 21 07:38:01.648703 2026] [security2:error] [pid 254995:tid 255094] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MCf7v0rlcEGmVraFAxgADQmI"]
[Tue Jul 21 07:38:01.649046 2026] [security2:error] [pid 254995:tid 255161] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MCf7v0rlcEGmVraFAxgADQmI"]
[Tue Jul 21 07:38:01.720795 2026] [security2:error] [pid 255769:tid 255970] [client 20.206.105.145:37916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/edit.php"] [unique_id "al9MCbxMYwyVGnfuwsKbOAAAA-o"]
[Tue Jul 21 07:38:01.830885 2026] [security2:error] [pid 254995:tid 255202] [client 4.204.201.85:57213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/dZ3wP5.php"] [unique_id "al9MCf7v0rlcEGmVraFAygAAA2s"]
[Tue Jul 21 07:38:01.859535 2026] [security2:error] [pid 255769:tid 255850] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/languages/index.php"] [unique_id "al9MCbxMYwyVGnfuwsKbPAADwFA"], referer: http://aud-7.com/wp-content/languages/index.php
[Tue Jul 21 07:38:01.894286 2026] [security2:error] [pid 255769:tid 255969] [client 20.197.195.24:51811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/a1.php"] [unique_id "al9MCbxMYwyVGnfuwsKbPQAAA-k"]
[Tue Jul 21 07:38:01.946313 2026] [security2:error] [pid 255769:tid 255962] [client 193.36.225.62:44783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MCbxMYwyVGnfuwsKbPgAAA-I"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:01.987992 2026] [security2:error] [pid 255769:tid 255953] [client 20.52.136.55:1747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/settings.php"] [unique_id "al9MCbxMYwyVGnfuwsKbQQAAA9k"]
[Tue Jul 21 07:38:02.097986 2026] [security2:error] [pid 254995:tid 255263] [client 194.99.104.35:53842] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9MCv7v0rlcEGmVraFA0AAAA40"]
[Tue Jul 21 07:38:02.098146 2026] [security2:error] [pid 254995:tid 255263] [client 194.99.104.35:53842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9MCv7v0rlcEGmVraFA0AAAA40"]
[Tue Jul 21 07:38:02.117497 2026] [security2:error] [pid 255769:tid 255976] [client 4.204.201.85:55543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/yup.php"] [unique_id "al9MCrxMYwyVGnfuwsKbQwAAA_A"]
[Tue Jul 21 07:38:02.226145 2026] [security2:error] [pid 255769:tid 255967] [client 194.99.104.35:53858] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MCrxMYwyVGnfuwsKbRgAAA-c"]
[Tue Jul 21 07:38:02.226232 2026] [security2:error] [pid 255769:tid 255967] [client 194.99.104.35:53858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MCrxMYwyVGnfuwsKbRgAAA-c"]
[Tue Jul 21 07:38:02.235075 2026] [security2:error] [pid 255769:tid 255992] [client 20.197.195.24:21066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/eee.php"] [unique_id "al9MCrxMYwyVGnfuwsKbSAAAA_8"]
[Tue Jul 21 07:38:02.327273 2026] [security2:error] [pid 255769:tid 255951] [client 20.220.225.223:38716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/wp-mt.php"] [unique_id "al9MCrxMYwyVGnfuwsKbSgAAA9c"]
[Tue Jul 21 07:38:02.376356 2026] [security2:error] [pid 255769:tid 255910] [client 45.8.17.112:36029] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Requests/library/"] [unique_id "al9MCrxMYwyVGnfuwsKbTQAAA64"]
[Tue Jul 21 07:38:02.379565 2026] [security2:error] [pid 255769:tid 255891] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/languages/plugins/index.php"] [unique_id "al9MCrxMYwyVGnfuwsKbTgAD4Hk"], referer: http://aud-7.com/wp-content/languages/plugins/index.php
[Tue Jul 21 07:38:02.395650 2026] [security2:error] [pid 254995:tid 255268] [client 20.197.195.24:21072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wp-aothait.php"] [unique_id "al9MCv7v0rlcEGmVraFA2QAAA5I"]
[Tue Jul 21 07:38:02.400344 2026] [security2:error] [pid 254995:tid 255206] [client 4.204.201.85:55999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/X.php"] [unique_id "al9MCv7v0rlcEGmVraFA2gAAA28"]
[Tue Jul 21 07:38:02.449463 2026] [security2:error] [pid 255769:tid 255948] [client 20.226.60.151:27540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/222.php"] [unique_id "al9MCrxMYwyVGnfuwsKbUwAAA9Q"]
[Tue Jul 21 07:38:02.691480 2026] [security2:error] [pid 254995:tid 255174] [client 4.204.201.85:55527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/1polka.php"] [unique_id "al9MCv7v0rlcEGmVraFA4AAAA08"]
[Tue Jul 21 07:38:02.694828 2026] [security2:error] [pid 254995:tid 255255] [client 20.197.195.24:21047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/config.json.php"] [unique_id "al9MCv7v0rlcEGmVraFA4QAAA4U"]
[Tue Jul 21 07:38:02.820440 2026] [security2:error] [pid 254995:tid 255176] [client 139.167.225.182:65520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MCv7v0rlcEGmVraFA4gAAA1E"]
[Tue Jul 21 07:38:02.820571 2026] [security2:error] [pid 254995:tid 255176] [client 139.167.225.182:65520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MCv7v0rlcEGmVraFA4gAAA1E"]
[Tue Jul 21 07:38:02.897977 2026] [security2:error] [pid 255769:tid 255779] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/languages/themes/index.php"] [unique_id "al9MCrxMYwyVGnfuwsKbWAAD1gk"], referer: http://aud-7.com/wp-content/languages/themes/index.php
[Tue Jul 21 07:38:02.973531 2026] [security2:error] [pid 255769:tid 256003] [client 4.204.201.85:57165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/gec.php"] [unique_id "al9MCrxMYwyVGnfuwsKbWgAABAk"]
[Tue Jul 21 07:38:03.089060 2026] [security2:error] [pid 255769:tid 255965] [client 20.52.136.55:1597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/g.php"] [unique_id "al9MC7xMYwyVGnfuwsKbXgAAA-U"]
[Tue Jul 21 07:38:03.252391 2026] [security2:error] [pid 254995:tid 255198] [client 4.204.201.85:55986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/sky.php"] [unique_id "al9MC_7v0rlcEGmVraFA6QAAA2c"]
[Tue Jul 21 07:38:03.358800 2026] [security2:error] [pid 255769:tid 255958] [client 20.206.105.145:38513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MC7xMYwyVGnfuwsKbYwAAA94"]
[Tue Jul 21 07:38:03.412112 2026] [security2:error] [pid 255769:tid 255783] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/fonts/index.php"] [unique_id "al9MC7xMYwyVGnfuwsKbZAADxg0"], referer: http://aud-7.com/wp-content/fonts/index.php
[Tue Jul 21 07:38:03.543547 2026] [security2:error] [pid 255769:tid 255957] [client 4.204.201.85:57183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/fffm.php"] [unique_id "al9MC7xMYwyVGnfuwsKbZgAAA90"]
[Tue Jul 21 07:38:03.572820 2026] [security2:error] [pid 255769:tid 255944] [client 45.8.17.57:36553] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentyfour/"] [unique_id "al9MC7xMYwyVGnfuwsKbZwAAA9A"]
[Tue Jul 21 07:38:03.626528 2026] [security2:error] [pid 255769:tid 255925] [client 117.217.38.194:53666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MC7xMYwyVGnfuwsKbaAAAA70"]
[Tue Jul 21 07:38:03.626657 2026] [security2:error] [pid 255769:tid 255925] [client 117.217.38.194:53666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MC7xMYwyVGnfuwsKbaAAAA70"]
[Tue Jul 21 07:38:03.707443 2026] [security2:error] [pid 255769:tid 255936] [client 20.197.195.24:63619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/ms.php"] [unique_id "al9MC7xMYwyVGnfuwsKbbAAAA8g"]
[Tue Jul 21 07:38:03.834880 2026] [security2:error] [pid 255769:tid 255992] [client 4.204.201.85:55977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/sixxis.php"] [unique_id "al9MC7xMYwyVGnfuwsKbbgAAA_8"]
[Tue Jul 21 07:38:03.935366 2026] [security2:error] [pid 255769:tid 255881] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/index.php"] [unique_id "al9MC7xMYwyVGnfuwsKbcAADuW8"], referer: http://aud-7.com/wp-content/index.php
[Tue Jul 21 07:38:03.956411 2026] [security2:error] [pid 255769:tid 255960] [client 20.226.60.151:61185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/fnstall.php"] [unique_id "al9MC7xMYwyVGnfuwsKbcQAAA-A"]
[Tue Jul 21 07:38:03.993166 2026] [security2:error] [pid 255769:tid 255922] [client 20.226.60.151:27573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/test.php"] [unique_id "al9MC7xMYwyVGnfuwsKbcgAAA7o"]
[Tue Jul 21 07:38:04.031464 2026] [security2:error] [pid 254995:tid 255225] [client 31.14.72.5:58059] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9MDP7v0rlcEGmVraFA9AAAA4E"]
[Tue Jul 21 07:38:04.115030 2026] [security2:error] [pid 255769:tid 255943] [client 4.204.201.85:57175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/yj09.php"] [unique_id "al9MDLxMYwyVGnfuwsKbfQAAA88"]
[Tue Jul 21 07:38:04.334521 2026] [security2:error] [pid 255769:tid 255964] [client 173.24.185.52:58041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MDLxMYwyVGnfuwsKbjQAAA-Q"]
[Tue Jul 21 07:38:04.334698 2026] [security2:error] [pid 255769:tid 255964] [client 173.24.185.52:58041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MDLxMYwyVGnfuwsKbjQAAA-Q"]
[Tue Jul 21 07:38:04.406777 2026] [security2:error] [pid 255769:tid 256014] [client 4.204.201.85:55980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/f900.php"] [unique_id "al9MDLxMYwyVGnfuwsKbkgAABBQ"]
[Tue Jul 21 07:38:04.452934 2026] [security2:error] [pid 255769:tid 255820] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-admin/fmadmin.php"] [unique_id "al9MDLxMYwyVGnfuwsKblAAD9DI"], referer: http://aud-7.com/wp-admin/fmadmin.php
[Tue Jul 21 07:38:04.528399 2026] [security2:error] [pid 254995:tid 255186] [client 20.197.192.193:6375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/pn.php"] [unique_id "al9MDP7v0rlcEGmVraFA-wAAA1s"]
[Tue Jul 21 07:38:04.626480 2026] [security2:error] [pid 254995:tid 255127] [client 20.151.10.161:46005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/green1.php"] [unique_id "al9MDP7v0rlcEGmVraFA_QAAAyA"]
[Tue Jul 21 07:38:04.697832 2026] [security2:error] [pid 255769:tid 255928] [client 4.204.201.85:55948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/ups.php"] [unique_id "al9MDLxMYwyVGnfuwsKblwAAA8A"]
[Tue Jul 21 07:38:04.776849 2026] [security2:error] [pid 254995:tid 255195] [client 45.8.17.106:34723] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/radio.php"] [unique_id "al9MDP7v0rlcEGmVraFBAQAAA2Q"]
[Tue Jul 21 07:38:04.868636 2026] [security2:error] [pid 255769:tid 255962] [client 20.206.105.145:37888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/f6.php"] [unique_id "al9MDLxMYwyVGnfuwsKbmQAAA-I"]
[Tue Jul 21 07:38:04.901868 2026] [security2:error] [pid 255769:tid 255942] [client 20.197.195.24:51803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9MDLxMYwyVGnfuwsKbmwAAA84"]
[Tue Jul 21 07:38:04.969009 2026] [security2:error] [pid 255769:tid 255849] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-admin/images/index.php"] [unique_id "al9MDLxMYwyVGnfuwsKbnAAD2U8"], referer: http://aud-7.com/wp-admin/images/index.php
[Tue Jul 21 07:38:04.971418 2026] [security2:error] [pid 255769:tid 255954] [client 4.204.201.85:55508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/k.php"] [unique_id "al9MDLxMYwyVGnfuwsKbnQAAA9o"]
[Tue Jul 21 07:38:04.985845 2026] [security2:error] [pid 255769:tid 256022] [client 117.251.86.144:39060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MDLxMYwyVGnfuwsKbngAABBw"]
[Tue Jul 21 07:38:04.985947 2026] [security2:error] [pid 255769:tid 256022] [client 117.251.86.144:39060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MDLxMYwyVGnfuwsKbngAABBw"]
[Tue Jul 21 07:38:05.081299 2026] [security2:error] [pid 254995:tid 255202] [client 20.151.10.161:46054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/biufile.php"] [unique_id "al9MDf7v0rlcEGmVraFBBgAAA2s"]
[Tue Jul 21 07:38:05.140603 2026] [security2:error] [pid 254995:tid 255131] [client 20.220.225.223:38676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/mac.php"] [unique_id "al9MDf7v0rlcEGmVraFBCAAAAyQ"]
[Tue Jul 21 07:38:05.175074 2026] [autoindex:error] [pid 254995:tid 255168] [client 20.197.195.24:63330] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:05.187284 2026] [security2:error] [pid 254995:tid 255192] [client 20.197.195.24:63330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/memberfuns.php"] [unique_id "al9MDf7v0rlcEGmVraFBCQAAA2E"]
[Tue Jul 21 07:38:05.245120 2026] [security2:error] [pid 254995:tid 255259] [client 4.204.201.85:55512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/k2.php"] [unique_id "al9MDf7v0rlcEGmVraFBCwAAA4k"]
[Tue Jul 21 07:38:05.360245 2026] [security2:error] [pid 255769:tid 255899] [client 20.197.195.24:21096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/k2.php"] [unique_id "al9MDbxMYwyVGnfuwsKbowAAA6M"]
[Tue Jul 21 07:38:05.366296 2026] [security2:error] [pid 255769:tid 255902] [client 20.52.136.55:1759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/403.php"] [unique_id "al9MDbxMYwyVGnfuwsKbpAAAA6Y"]
[Tue Jul 21 07:38:05.404050 2026] [security2:error] [pid 254995:tid 255125] [client 20.197.195.24:21001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/uiuvs58l.php"] [unique_id "al9MDf7v0rlcEGmVraFBDAAAAx4"]
[Tue Jul 21 07:38:05.479558 2026] [security2:error] [pid 254995:tid 255269] [client 20.220.225.223:38216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MDf7v0rlcEGmVraFBDwAAA5M"]
[Tue Jul 21 07:38:05.483927 2026] [security2:error] [pid 255769:tid 255870] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-admin/maint/index.php"] [unique_id "al9MDbxMYwyVGnfuwsKbqAAD52Q"], referer: http://aud-7.com/wp-admin/maint/index.php
[Tue Jul 21 07:38:05.520723 2026] [security2:error] [pid 255769:tid 255973] [client 4.204.201.85:55997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/w.php"] [unique_id "al9MDbxMYwyVGnfuwsKbqQAAA-0"]
[Tue Jul 21 07:38:05.557276 2026] [security2:error] [pid 254995:tid 255275] [client 103.162.129.114:56808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9MDf7v0rlcEGmVraFBEgAAA5k"]
[Tue Jul 21 07:38:05.557420 2026] [security2:error] [pid 254995:tid 255275] [client 103.162.129.114:56808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9MDf7v0rlcEGmVraFBEgAAA5k"]
[Tue Jul 21 07:38:05.559739 2026] [security2:error] [pid 254995:tid 255171] [client 20.197.195.24:21094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/40p9ixjd.php"] [unique_id "al9MDf7v0rlcEGmVraFBEwAAA0w"]
[Tue Jul 21 07:38:05.584255 2026] [security2:error] [pid 254995:tid 255268] [client 20.226.60.151:27627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/aaa.php"] [unique_id "al9MDf7v0rlcEGmVraFBFAAAA5I"]
[Tue Jul 21 07:38:05.592887 2026] [security2:error] [pid 254995:tid 255163] [client 122.186.204.214:59133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MDf7v0rlcEGmVraFBFQAAA0Q"]
[Tue Jul 21 07:38:05.593034 2026] [security2:error] [pid 254995:tid 255163] [client 122.186.204.214:59133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MDf7v0rlcEGmVraFBFQAAA0Q"]
[Tue Jul 21 07:38:05.776940 2026] [security2:error] [pid 255769:tid 256009] [client 45.8.17.64:29899] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/shell.php"] [unique_id "al9MDbxMYwyVGnfuwsKbtQAABA8"]
[Tue Jul 21 07:38:05.800542 2026] [security2:error] [pid 254995:tid 255169] [client 4.204.201.85:57164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/fpwch.php"] [unique_id "al9MDf7v0rlcEGmVraFBGgAAA0o"]
[Tue Jul 21 07:38:05.833532 2026] [security2:error] [pid 255769:tid 255968] [client 20.197.195.24:62906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/0.php"] [unique_id "al9MDbxMYwyVGnfuwsKbtgAAA-g"]
[Tue Jul 21 07:38:05.883739 2026] [security2:error] [pid 255769:tid 255908] [client 20.206.105.145:38210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/inputs.php"] [unique_id "al9MDbxMYwyVGnfuwsKbuQAAA6w"]
[Tue Jul 21 07:38:06.005233 2026] [security2:error] [pid 255769:tid 255814] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-admin/js/index.php"] [unique_id "al9MDrxMYwyVGnfuwsKbugAEEyw"], referer: http://aud-7.com/wp-admin/js/index.php
[Tue Jul 21 07:38:06.077052 2026] [security2:error] [pid 255769:tid 255901] [client 4.204.201.85:55540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/w2025.php"] [unique_id "al9MDrxMYwyVGnfuwsKbvAAAA6U"]
[Tue Jul 21 07:38:06.260884 2026] [security2:error] [pid 255769:tid 255867] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MDrxMYwyVGnfuwsKb2AAECWE"]
[Tue Jul 21 07:38:06.261058 2026] [security2:error] [pid 255769:tid 256003] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MDrxMYwyVGnfuwsKb2AAECWE"]
[Tue Jul 21 07:38:06.281567 2026] [security2:error] [pid 255769:tid 255983] [client 20.197.195.24:21111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/uiuvs58l.update.php"] [unique_id "al9MDrxMYwyVGnfuwsKb2wAAA_c"]
[Tue Jul 21 07:38:06.325821 2026] [security2:error] [pid 255769:tid 255942] [client 20.220.225.223:31231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/samll.php"] [unique_id "al9MDrxMYwyVGnfuwsKb3AAAA84"]
[Tue Jul 21 07:38:06.363503 2026] [security2:error] [pid 254995:tid 255167] [client 4.204.201.85:57108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/FWAZ.php"] [unique_id "al9MDv7v0rlcEGmVraFBIwAAA0g"]
[Tue Jul 21 07:38:06.524128 2026] [security2:error] [pid 255769:tid 255801] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-admin/css/index.php"] [unique_id "al9MDrxMYwyVGnfuwsKb6QAD6x8"], referer: http://aud-7.com/wp-admin/css/index.php
[Tue Jul 21 07:38:06.530156 2026] [security2:error] [pid 255769:tid 255925] [client 20.151.10.161:46041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wpconf.php"] [unique_id "al9MDrxMYwyVGnfuwsKb6gAAA70"]
[Tue Jul 21 07:38:06.546450 2026] [security2:error] [pid 255769:tid 255969] [client 31.14.72.5:58788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.14.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "psiqueflix.online"] [uri "/xmlrpc.php"] [unique_id "al9MDbxMYwyVGnfuwsKbpQAAA-k"]
[Tue Jul 21 07:38:06.652495 2026] [security2:error] [pid 254995:tid 255130] [client 4.204.201.85:57215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/qterm.php"] [unique_id "al9MDv7v0rlcEGmVraFBKQAAAyM"]
[Tue Jul 21 07:38:06.788175 2026] [security2:error] [pid 254995:tid 255261] [client 20.197.195.24:21010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/for.php"] [unique_id "al9MDv7v0rlcEGmVraFBKgAAA4s"]
[Tue Jul 21 07:38:06.814703 2026] [security2:error] [pid 255769:tid 255934] [client 20.226.60.151:51319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/acp.php"] [unique_id "al9MDrxMYwyVGnfuwsKb7AAAA8Y"]
[Tue Jul 21 07:38:06.929761 2026] [security2:error] [pid 255769:tid 255902] [client 4.204.201.85:55514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/blurbs.php"] [unique_id "al9MDrxMYwyVGnfuwsKb7gAAA6Y"]
[Tue Jul 21 07:38:06.977031 2026] [security2:error] [pid 254995:tid 255225] [client 45.8.17.117:50187] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "al9MDv7v0rlcEGmVraFBLgAAA4E"]
[Tue Jul 21 07:38:07.040741 2026] [security2:error] [pid 255769:tid 255860] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-includes/assets/index.php"] [unique_id "al9MD7xMYwyVGnfuwsKb7wADyFo"], referer: http://aud-7.com/wp-includes/assets/index.php
[Tue Jul 21 07:38:07.067777 2026] [security2:error] [pid 255769:tid 255915] [client 20.206.105.145:37948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/av.php"] [unique_id "al9MD7xMYwyVGnfuwsKb8QAAA7M"]
[Tue Jul 21 07:38:07.103204 2026] [security2:error] [pid 255769:tid 255912] [client 20.151.10.161:46073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/mosty.php"] [unique_id "al9MD7xMYwyVGnfuwsKb9AAAA7A"]
[Tue Jul 21 07:38:07.208549 2026] [security2:error] [pid 254995:tid 255266] [client 4.204.201.85:57126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/v543.php"] [unique_id "al9MD_7v0rlcEGmVraFBNAAAA5A"]
[Tue Jul 21 07:38:07.244259 2026] [security2:error] [pid 254995:tid 255006] [remote 69.171.234.8:42018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.234.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9MD_7v0rlcEGmVraFBMgADbgo"]
[Tue Jul 21 07:38:07.290745 2026] [security2:error] [pid 255769:tid 255788] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MD7xMYwyVGnfuwsKb9wAD3BI"]
[Tue Jul 21 07:38:07.290892 2026] [security2:error] [pid 255769:tid 255956] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MD7xMYwyVGnfuwsKb9wAD3BI"]
[Tue Jul 21 07:38:07.384031 2026] [security2:error] [pid 255769:tid 256005] [client 20.197.195.24:63629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/BDKR28.php"] [unique_id "al9MD7xMYwyVGnfuwsKb_AAABAs"]
[Tue Jul 21 07:38:07.469783 2026] [security2:error] [pid 255769:tid 256013] [client 184.75.223.211:44032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9MD7xMYwyVGnfuwsKcAgAABBM"]
[Tue Jul 21 07:38:07.469902 2026] [security2:error] [pid 255769:tid 256013] [client 184.75.223.211:44032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9MD7xMYwyVGnfuwsKcAgAABBM"]
[Tue Jul 21 07:38:07.472336 2026] [security2:error] [pid 255769:tid 255905] [client 20.220.225.223:31184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/abcd.php"] [unique_id "al9MD7xMYwyVGnfuwsKcAwAAA6k"]
[Tue Jul 21 07:38:07.486843 2026] [security2:error] [pid 255769:tid 255980] [client 4.204.201.85:57129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/w3lls.php"] [unique_id "al9MD7xMYwyVGnfuwsKcBAAAA_Q"]
[Tue Jul 21 07:38:07.563106 2026] [security2:error] [pid 255769:tid 255825] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-includes/Requests/src/Auth/index.php"] [unique_id "al9MD7xMYwyVGnfuwsKcBQADpTc"], referer: http://aud-7.com/wp-includes/Requests/src/Auth/index.php
[Tue Jul 21 07:38:07.621331 2026] [security2:error] [pid 254995:tid 255155] [client 175.45.70.82:64489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MD_7v0rlcEGmVraFBPQAAAzw"]
[Tue Jul 21 07:38:07.621486 2026] [security2:error] [pid 254995:tid 255155] [client 175.45.70.82:64489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MD_7v0rlcEGmVraFBPQAAAzw"]
[Tue Jul 21 07:38:07.760534 2026] [security2:error] [pid 255769:tid 255966] [client 20.197.195.24:21082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/raw.php"] [unique_id "al9MD7xMYwyVGnfuwsKcCwAAA-Y"]
[Tue Jul 21 07:38:07.770823 2026] [security2:error] [pid 255769:tid 255962] [client 4.204.201.85:55506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-ws68.php"] [unique_id "al9MD7xMYwyVGnfuwsKcDAAAA-I"]
[Tue Jul 21 07:38:07.781333 2026] [security2:error] [pid 255769:tid 255978] [client 20.151.10.161:45989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/dejavu.php"] [unique_id "al9MD7xMYwyVGnfuwsKcDQAAA_I"]
[Tue Jul 21 07:38:07.850290 2026] [security2:error] [pid 254995:tid 255191] [client 154.192.233.199:59967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MD_7v0rlcEGmVraFBPwAAA2A"]
[Tue Jul 21 07:38:07.850518 2026] [security2:error] [pid 254995:tid 255191] [client 154.192.233.199:59967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MD_7v0rlcEGmVraFBPwAAA2A"]
[Tue Jul 21 07:38:07.887757 2026] [security2:error] [pid 255769:tid 255953] [client 20.226.60.151:51368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/mosty.php"] [unique_id "al9MD7xMYwyVGnfuwsKcDgAAA9k"]
[Tue Jul 21 07:38:07.960782 2026] [security2:error] [pid 255769:tid 255914] [client 20.220.225.223:31196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/ww.php"] [unique_id "al9MD7xMYwyVGnfuwsKcEQAAA7I"]
[Tue Jul 21 07:38:08.013570 2026] [security2:error] [pid 254995:tid 255186] [client 122.162.144.145:17356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MEP7v0rlcEGmVraFBQgAAA1s"]
[Tue Jul 21 07:38:08.013661 2026] [security2:error] [pid 254995:tid 255186] [client 122.162.144.145:17356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MEP7v0rlcEGmVraFBQgAAA1s"]
[Tue Jul 21 07:38:08.044979 2026] [security2:error] [pid 254995:tid 255037] [remote 88.99.30.91:44016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.30.99.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9MEP7v0rlcEGmVraFBQwADdCk"]
[Tue Jul 21 07:38:08.048196 2026] [security2:error] [pid 255769:tid 255957] [client 4.204.201.85:57156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/xyn.php"] [unique_id "al9MELxMYwyVGnfuwsKcEgAAA90"]
[Tue Jul 21 07:38:08.089890 2026] [security2:error] [pid 255769:tid 255785] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-includes/core.php"] [unique_id "al9MELxMYwyVGnfuwsKcFQAD6Q8"], referer: http://aud-7.com/wp-includes/core.php
[Tue Jul 21 07:38:08.229229 2026] [security2:error] [pid 255769:tid 255952] [client 193.36.225.57:33339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MDrxMYwyVGnfuwsKbuwAAA9g"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:08.242822 2026] [security2:error] [pid 254995:tid 255179] [client 31.14.72.5:59987] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9MEP7v0rlcEGmVraFBRwAAA1Q"]
[Tue Jul 21 07:38:08.285249 2026] [security2:error] [pid 254995:tid 255165] [client 20.226.60.151:27619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/11.php"] [unique_id "al9MEP7v0rlcEGmVraFBSAAAA0Y"]
[Tue Jul 21 07:38:08.323364 2026] [security2:error] [pid 255769:tid 255986] [client 103.106.20.201:53749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MELxMYwyVGnfuwsKcGAAAA_o"]
[Tue Jul 21 07:38:08.324167 2026] [security2:error] [pid 255769:tid 255986] [client 103.106.20.201:53749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MELxMYwyVGnfuwsKcGAAAA_o"]
[Tue Jul 21 07:38:08.324242 2026] [security2:error] [pid 255769:tid 255912] [client 4.204.201.85:55541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/green3.php"] [unique_id "al9MELxMYwyVGnfuwsKcGQAAA7A"]
[Tue Jul 21 07:38:08.417226 2026] [security2:error] [pid 255769:tid 255956] [client 20.206.105.145:38508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/classwithtostring.php"] [unique_id "al9MELxMYwyVGnfuwsKcHAAAA9w"]
[Tue Jul 21 07:38:08.525051 2026] [security2:error] [pid 255769:tid 255891] [remote 192.241.143.148:52784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/wp-login.php"] [unique_id "al9MELxMYwyVGnfuwsKcIAADs3k"]
[Tue Jul 21 07:38:08.562793 2026] [autoindex:error] [pid 255769:tid 255793] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:38:08.564541 2026] [autoindex:error] [pid 255769:tid 255878] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:38:08.583548 2026] [security2:error] [pid 255769:tid 255832] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MELxMYwyVGnfuwsKcIwAEGj4"]
[Tue Jul 21 07:38:08.583700 2026] [security2:error] [pid 255769:tid 256020] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MELxMYwyVGnfuwsKcIwAEGj4"]
[Tue Jul 21 07:38:08.609568 2026] [security2:error] [pid 255769:tid 255875] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-includes/Text/Diff/Engine/template-singl-portfolio.php"] [unique_id "al9MELxMYwyVGnfuwsKcJAAEF2k"], referer: http://aud-7.com/wp-includes/Text/Diff/Engine/template-singl-portfolio.php
[Tue Jul 21 07:38:08.619576 2026] [security2:error] [pid 255769:tid 255900] [client 4.204.201.85:57099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/ccc.php"] [unique_id "al9MELxMYwyVGnfuwsKcJgAAA6Q"]
[Tue Jul 21 07:38:08.642479 2026] [security2:error] [pid 255769:tid 255908] [client 20.197.195.24:63327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/green1.php"] [unique_id "al9MELxMYwyVGnfuwsKcKAAAA6w"]
[Tue Jul 21 07:38:08.685267 2026] [security2:error] [pid 255769:tid 255919] [client 122.164.127.47:56485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MELxMYwyVGnfuwsKcKwAAA7c"]
[Tue Jul 21 07:38:08.685362 2026] [security2:error] [pid 255769:tid 255919] [client 122.164.127.47:56485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MELxMYwyVGnfuwsKcKwAAA7c"]
[Tue Jul 21 07:38:08.763326 2026] [security2:error] [pid 255769:tid 255987] [client 20.226.60.151:61184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/6.php"] [unique_id "al9MELxMYwyVGnfuwsKcLQAAA_s"]
[Tue Jul 21 07:38:08.913533 2026] [security2:error] [pid 254995:tid 255137] [client 4.204.201.85:55944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/get.php"] [unique_id "al9MEP7v0rlcEGmVraFBVAAAAyo"]
[Tue Jul 21 07:38:09.080504 2026] [security2:error] [pid 254995:tid 255252] [client 20.151.10.161:46072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/aaf.php"] [unique_id "al9MEf7v0rlcEGmVraFBVwAAA4M"]
[Tue Jul 21 07:38:09.096266 2026] [security2:error] [pid 254995:tid 255174] [client 62.102.148.187:40906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9MEf7v0rlcEGmVraFBWAAAA08"]
[Tue Jul 21 07:38:09.096358 2026] [security2:error] [pid 254995:tid 255174] [client 62.102.148.187:40906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9MEf7v0rlcEGmVraFBWAAAA08"]
[Tue Jul 21 07:38:09.141192 2026] [security2:error] [pid 255769:tid 255776] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "al9MEbxMYwyVGnfuwsKcMgAD5gY"], referer: http://aud-7.com/wp-includes/ID3/index.php
[Tue Jul 21 07:38:09.177186 2026] [security2:error] [pid 254995:tid 255209] [client 20.197.195.24:63331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/nc4.php"] [unique_id "al9MEf7v0rlcEGmVraFBXAAAA3E"]
[Tue Jul 21 07:38:09.194524 2026] [security2:error] [pid 254995:tid 255256] [client 4.204.201.85:57203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/images.php"] [unique_id "al9MEf7v0rlcEGmVraFBXQAAA4Y"]
[Tue Jul 21 07:38:09.269563 2026] [security2:error] [pid 255769:tid 255954] [client 194.99.104.35:56540] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9MEbxMYwyVGnfuwsKcNAAAA9o"]
[Tue Jul 21 07:38:09.269641 2026] [security2:error] [pid 255769:tid 255954] [client 194.99.104.35:56540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9MEbxMYwyVGnfuwsKcNAAAA9o"]
[Tue Jul 21 07:38:09.432503 2026] [security2:error] [pid 255769:tid 255927] [client 152.59.154.239:59681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MEbxMYwyVGnfuwsKcPQAAA78"]
[Tue Jul 21 07:38:09.432859 2026] [security2:error] [pid 255769:tid 255881] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MEbxMYwyVGnfuwsKcPgADxm8"]
[Tue Jul 21 07:38:09.432970 2026] [security2:error] [pid 255769:tid 255934] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MEbxMYwyVGnfuwsKcPgADxm8"]
[Tue Jul 21 07:38:09.435060 2026] [security2:error] [pid 255769:tid 255925] [client 20.206.105.145:37901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9MEbxMYwyVGnfuwsKcPwAAA70"]
[Tue Jul 21 07:38:09.437172 2026] [security2:error] [pid 255769:tid 255927] [client 152.59.154.239:59681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MEbxMYwyVGnfuwsKcPQAAA78"]
[Tue Jul 21 07:38:09.489676 2026] [security2:error] [pid 255769:tid 255936] [client 4.204.201.85:55490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/alls.php"] [unique_id "al9MEbxMYwyVGnfuwsKcQQAAA8g"]
[Tue Jul 21 07:38:09.611703 2026] [security2:error] [pid 254995:tid 255172] [client 31.14.72.5:60713] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9MEf7v0rlcEGmVraFBYgAAA00"]
[Tue Jul 21 07:38:09.679879 2026] [security2:error] [pid 255769:tid 255856] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-includes/js/index.php"] [unique_id "al9MEbxMYwyVGnfuwsKcQwAEDFY"], referer: http://aud-7.com/wp-includes/js/index.php
[Tue Jul 21 07:38:09.710587 2026] [security2:error] [pid 255769:tid 255920] [client 20.197.195.24:63643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/a1.php"] [unique_id "al9MEbxMYwyVGnfuwsKcRQAAA7g"]
[Tue Jul 21 07:38:09.719285 2026] [security2:error] [pid 255769:tid 255981] [client 20.226.60.151:61193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9MEbxMYwyVGnfuwsKcRgAAA_U"]
[Tue Jul 21 07:38:09.766144 2026] [security2:error] [pid 255769:tid 255915] [client 4.204.201.85:60616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/coffexium.php"] [unique_id "al9MEbxMYwyVGnfuwsKcRwAAA7M"]
[Tue Jul 21 07:38:09.963304 2026] [security2:error] [pid 254995:tid 255039] [remote 69.171.234.112:57540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.234.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9MEf7v0rlcEGmVraFBaAADiys"]
[Tue Jul 21 07:38:10.042569 2026] [security2:error] [pid 255769:tid 255908] [client 4.204.201.85:55492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/red.php"] [unique_id "al9MErxMYwyVGnfuwsKcTAAAA6w"]
[Tue Jul 21 07:38:10.124992 2026] [security2:error] [pid 255769:tid 255964] [client 20.220.225.223:22471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MErxMYwyVGnfuwsKcTQAAA-Q"]
[Tue Jul 21 07:38:10.199530 2026] [security2:error] [pid 255769:tid 255823] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9MErxMYwyVGnfuwsKcUAAD0zU"], referer: http://aud-7.com/modules/mod_simplefileuploadv1.3/elements/filemanager.php
[Tue Jul 21 07:38:10.211707 2026] [security2:error] [pid 255769:tid 255905] [client 20.197.195.24:63345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/eee.php"] [unique_id "al9MErxMYwyVGnfuwsKcUQAAA6k"]
[Tue Jul 21 07:38:10.251165 2026] [security2:error] [pid 255769:tid 256024] [client 20.226.60.151:61230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/qqqa.php"] [unique_id "al9MErxMYwyVGnfuwsKcUgAABB4"]
[Tue Jul 21 07:38:10.272075 2026] [security2:error] [pid 255769:tid 255989] [client 20.151.10.161:46042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/term.php"] [unique_id "al9MErxMYwyVGnfuwsKcVAAAA_0"]
[Tue Jul 21 07:38:10.356930 2026] [security2:error] [pid 255769:tid 255912] [client 103.174.34.15:60520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MErxMYwyVGnfuwsKcVwAAA7A"]
[Tue Jul 21 07:38:10.357182 2026] [security2:error] [pid 255769:tid 255912] [client 103.174.34.15:60520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MErxMYwyVGnfuwsKcVwAAA7A"]
[Tue Jul 21 07:38:10.362676 2026] [autoindex:error] [pid 255769:tid 255966] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:10.498341 2026] [security2:error] [pid 255769:tid 255951] [client 184.75.223.211:50280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MErxMYwyVGnfuwsKcWAAAA9c"]
[Tue Jul 21 07:38:10.498440 2026] [security2:error] [pid 255769:tid 255951] [client 184.75.223.211:50280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MErxMYwyVGnfuwsKcWAAAA9c"]
[Tue Jul 21 07:38:10.515791 2026] [security2:error] [pid 254995:tid 255210] [client 20.226.60.151:51353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/aunmc.php"] [unique_id "al9MEv7v0rlcEGmVraFBbwAAA3I"]
[Tue Jul 21 07:38:10.576444 2026] [security2:error] [pid 254995:tid 255143] [client 20.226.60.151:51356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/uoocf.php"] [unique_id "al9MEv7v0rlcEGmVraFBcQAAAzA"]
[Tue Jul 21 07:38:10.638798 2026] [security2:error] [pid 254995:tid 255189] [client 4.204.201.85:57127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9MEv7v0rlcEGmVraFBcgAAA14"]
[Tue Jul 21 07:38:10.715171 2026] [security2:error] [pid 255769:tid 255866] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/.well-known/index.php"] [unique_id "al9MErxMYwyVGnfuwsKcXAAD3WA"], referer: http://aud-7.com/.well-known/index.php
[Tue Jul 21 07:38:10.756455 2026] [security2:error] [pid 254995:tid 255142] [client 20.226.60.151:51338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/iywwi.php"] [unique_id "al9MEv7v0rlcEGmVraFBdgAAAy8"]
[Tue Jul 21 07:38:10.943517 2026] [security2:error] [pid 254995:tid 255222] [client 20.226.60.151:27596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/mac.php"] [unique_id "al9MEv7v0rlcEGmVraFBegAAA34"]
[Tue Jul 21 07:38:10.950700 2026] [autoindex:error] [pid 254995:tid 255208] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:10.959851 2026] [security2:error] [pid 255769:tid 255984] [client 31.14.72.5:61400] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9MErxMYwyVGnfuwsKcYAAAA_g"]
[Tue Jul 21 07:38:11.025563 2026] [security2:error] [pid 255769:tid 255942] [client 20.226.60.151:51359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/gqgsa.php"] [unique_id "al9ME7xMYwyVGnfuwsKcYQAAA84"]
[Tue Jul 21 07:38:11.209285 2026] [security2:error] [pid 255769:tid 255978] [client 59.96.220.140:61601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9ME7xMYwyVGnfuwsKcZAAAA_I"]
[Tue Jul 21 07:38:11.209408 2026] [security2:error] [pid 255769:tid 255978] [client 59.96.220.140:61601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9ME7xMYwyVGnfuwsKcZAAAA_I"]
[Tue Jul 21 07:38:11.232604 2026] [security2:error] [pid 255769:tid 255895] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/classwithtostring.php"] [unique_id "al9ME7xMYwyVGnfuwsKcaAADtH0"], referer: http://aud-7.com/classwithtostring.php
[Tue Jul 21 07:38:11.235920 2026] [authz_core:error] [pid 255769:tid 255952] [client 4.204.201.85:0] AH01630: client denied by server configuration: /home1/ofic8899/qcharge.tryhealth.shop/wp-content/uploads/index.php
[Tue Jul 21 07:38:11.270662 2026] [security2:error] [pid 254995:tid 255168] [client 20.226.60.151:61209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/elbzl.php"] [unique_id "al9ME_7v0rlcEGmVraFBgQAAA0k"]
[Tue Jul 21 07:38:11.278010 2026] [security2:error] [pid 254995:tid 255211] [client 20.220.225.223:31881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/dp.php"] [unique_id "al9ME_7v0rlcEGmVraFBggAAA3M"]
[Tue Jul 21 07:38:11.351877 2026] [security2:error] [pid 255769:tid 255859] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9ME7xMYwyVGnfuwsKcaQAD6Vk"]
[Tue Jul 21 07:38:11.352031 2026] [security2:error] [pid 255769:tid 255969] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9ME7xMYwyVGnfuwsKcaQAD6Vk"]
[Tue Jul 21 07:38:11.365643 2026] [security2:error] [pid 255769:tid 255914] [client 103.86.117.203:56184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9ME7xMYwyVGnfuwsKcagAAA7I"]
[Tue Jul 21 07:38:11.365781 2026] [security2:error] [pid 255769:tid 255914] [client 103.86.117.203:56184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9ME7xMYwyVGnfuwsKcagAAA7I"]
[Tue Jul 21 07:38:11.376357 2026] [security2:error] [pid 255769:tid 255922] [client 4.204.201.85:57112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-content/index.php"] [unique_id "al9ME7xMYwyVGnfuwsKcawAAA7o"]
[Tue Jul 21 07:38:11.406438 2026] [security2:error] [pid 255769:tid 255899] [client 20.197.195.24:63644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-aothait.php"] [unique_id "al9ME7xMYwyVGnfuwsKcbAAAA6M"]
[Tue Jul 21 07:38:11.548280 2026] [security2:error] [pid 255769:tid 255920] [client 20.226.60.151:51288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/adjig.php"] [unique_id "al9ME7xMYwyVGnfuwsKcbQAAA7g"]
[Tue Jul 21 07:38:11.597596 2026] [proxy:error] [pid 255769:tid 255950] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.597645 2026] [proxy_http:error] [pid 255769:tid 255950] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.598110 2026] [proxy:error] [pid 255769:tid 255950] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.598136 2026] [proxy_http:error] [pid 255769:tid 255950] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.628302 2026] [proxy:error] [pid 255769:tid 255908] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.628373 2026] [proxy_http:error] [pid 255769:tid 255908] [client 2604:a880:4:1d0::36c:6000:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.628992 2026] [proxy:error] [pid 255769:tid 255908] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.629032 2026] [proxy_http:error] [pid 255769:tid 255908] [client 2604:a880:4:1d0::36c:6000:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.630672 2026] [proxy:error] [pid 254995:tid 255165] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.630734 2026] [proxy_http:error] [pid 254995:tid 255165] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.631314 2026] [proxy:error] [pid 254995:tid 255165] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.631347 2026] [proxy_http:error] [pid 254995:tid 255165] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.651170 2026] [security2:error] [pid 255769:tid 255964] [client 20.197.192.193:6353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/wp-wpbak.php"] [unique_id "al9ME7xMYwyVGnfuwsKcdgAAA-Q"]
[Tue Jul 21 07:38:11.667477 2026] [security2:error] [pid 255769:tid 256015] [client 4.204.201.85:57119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/admin.php"] [unique_id "al9ME7xMYwyVGnfuwsKceAAABBU"]
[Tue Jul 21 07:38:11.726494 2026] [proxy:error] [pid 255769:tid 256024] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.726550 2026] [proxy_http:error] [pid 255769:tid 256024] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.727005 2026] [proxy:error] [pid 255769:tid 256024] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.727047 2026] [proxy_http:error] [pid 255769:tid 256024] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.745512 2026] [security2:error] [pid 255769:tid 255877] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/filemanager.php"] [unique_id "al9ME7xMYwyVGnfuwsKcgAAD9Gs"], referer: http://aud-7.com/filemanager.php
[Tue Jul 21 07:38:11.746997 2026] [proxy:error] [pid 254995:tid 255177] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.747056 2026] [proxy_http:error] [pid 254995:tid 255177] [client 2a03:b0c0:2:d0::1737:1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.747566 2026] [proxy:error] [pid 254995:tid 255177] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.747588 2026] [proxy_http:error] [pid 254995:tid 255177] [client 2a03:b0c0:2:d0::1737:1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.753551 2026] [security2:error] [pid 255769:tid 255901] [client 20.151.10.161:46037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ha.php"] [unique_id "al9ME7xMYwyVGnfuwsKcgQAAA6U"]
[Tue Jul 21 07:38:11.804411 2026] [security2:error] [pid 255769:tid 255979] [client 20.226.60.151:51327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/byp.php"] [unique_id "al9ME7xMYwyVGnfuwsKchAAAA_M"]
[Tue Jul 21 07:38:11.809864 2026] [proxy:error] [pid 254995:tid 255268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.809914 2026] [proxy_http:error] [pid 254995:tid 255268] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.810386 2026] [proxy:error] [pid 254995:tid 255268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.810405 2026] [proxy_http:error] [pid 254995:tid 255268] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.847422 2026] [proxy:error] [pid 254995:tid 255166] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.847499 2026] [proxy_http:error] [pid 254995:tid 255166] [client 2400:6180:0:d0::13e9:e001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.848527 2026] [proxy:error] [pid 254995:tid 255166] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.848562 2026] [proxy_http:error] [pid 254995:tid 255166] [client 2400:6180:0:d0::13e9:e001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.875406 2026] [security2:error] [pid 255769:tid 255954] [client 20.197.195.24:63319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/config.json.php"] [unique_id "al9ME7xMYwyVGnfuwsKciAAAA9o"]
[Tue Jul 21 07:38:11.903095 2026] [proxy:error] [pid 255769:tid 255957] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.903162 2026] [proxy_http:error] [pid 255769:tid 255957] [client 2a03:b0c0:3:d0::12f7:9001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.903592 2026] [proxy:error] [pid 255769:tid 255957] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.903617 2026] [proxy_http:error] [pid 255769:tid 255957] [client 2a03:b0c0:3:d0::12f7:9001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.942077 2026] [security2:error] [pid 255769:tid 255927] [client 4.204.201.85:57187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/177.php"] [unique_id "al9ME7xMYwyVGnfuwsKcjgAAA78"]
[Tue Jul 21 07:38:11.942750 2026] [security2:error] [pid 254995:tid 255157] [client 20.206.105.145:38519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-blog.php"] [unique_id "al9ME_7v0rlcEGmVraFBlgAAAz4"]
[Tue Jul 21 07:38:12.148684 2026] [security2:error] [pid 255769:tid 255916] [client 20.197.195.24:63358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9MFLxMYwyVGnfuwsKckwAAA7Q"]
[Tue Jul 21 07:38:12.218255 2026] [security2:error] [pid 255769:tid 255932] [client 4.204.201.85:55989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/199.php"] [unique_id "al9MFLxMYwyVGnfuwsKclAAAA8Q"]
[Tue Jul 21 07:38:12.259032 2026] [security2:error] [pid 255769:tid 255936] [client 20.197.195.24:63312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/k2.php"] [unique_id "al9MFLxMYwyVGnfuwsKclQAAA8g"]
[Tue Jul 21 07:38:12.259642 2026] [security2:error] [pid 255769:tid 255873] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9MFLxMYwyVGnfuwsKclgAD_2c"], referer: http://aud-7.com/4PJcpMFsD8B.php
[Tue Jul 21 07:38:12.292685 2026] [security2:error] [pid 254995:tid 255125] [client 31.14.72.5:62591] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9MFP7v0rlcEGmVraFBoAAAAx4"]
[Tue Jul 21 07:38:12.491128 2026] [security2:error] [pid 254995:tid 255214] [client 4.204.201.85:60548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/file52.php"] [unique_id "al9MFP7v0rlcEGmVraFBpgAAA3Y"]
[Tue Jul 21 07:38:12.591037 2026] [security2:error] [pid 255769:tid 255848] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MFLxMYwyVGnfuwsKcnAADyk4"]
[Tue Jul 21 07:38:12.591175 2026] [security2:error] [pid 255769:tid 255938] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MFLxMYwyVGnfuwsKcnAADyk4"]
[Tue Jul 21 07:38:12.592142 2026] [proxy:error] [pid 255769:tid 255964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:12.592188 2026] [proxy_http:error] [pid 255769:tid 255964] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:12.592746 2026] [proxy:error] [pid 255769:tid 255964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:12.592768 2026] [proxy_http:error] [pid 255769:tid 255964] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:12.601098 2026] [security2:error] [pid 254995:tid 255216] [client 20.226.60.151:51308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9MFP7v0rlcEGmVraFBqwAAA3g"]
[Tue Jul 21 07:38:12.610102 2026] [security2:error] [pid 255769:tid 256005] [client 20.151.10.161:2946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MFLxMYwyVGnfuwsKcngAABAs"]
[Tue Jul 21 07:38:12.619973 2026] [security2:error] [pid 255769:tid 255918] [client 20.52.136.55:1540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/api.php"] [unique_id "al9MFLxMYwyVGnfuwsKcnwAAA7Y"]
[Tue Jul 21 07:38:12.627241 2026] [security2:error] [pid 254995:tid 255049] [remote 45.150.79.142:42632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9MFP7v0rlcEGmVraFBrAADfzU"]
[Tue Jul 21 07:38:12.724524 2026] [proxy:error] [pid 255769:tid 255970] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:12.724583 2026] [proxy_http:error] [pid 255769:tid 255970] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:12.724652 2026] [proxy:error] [pid 255769:tid 256013] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:12.724700 2026] [proxy_http:error] [pid 255769:tid 256013] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:12.725042 2026] [proxy:error] [pid 255769:tid 255970] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:12.725067 2026] [proxy_http:error] [pid 255769:tid 255970] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:12.725142 2026] [proxy:error] [pid 255769:tid 256013] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:12.725164 2026] [proxy_http:error] [pid 255769:tid 256013] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:12.731340 2026] [security2:error] [pid 255769:tid 256009] [client 157.90.155.240:29986] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9MFLxMYwyVGnfuwsKcpgAABA8"], referer: https://artetoner.com.br
[Tue Jul 21 07:38:12.776803 2026] [security2:error] [pid 255769:tid 255901] [client 4.204.201.85:57191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/geck.php"] [unique_id "al9MFLxMYwyVGnfuwsKcqQAAA6U"]
[Tue Jul 21 07:38:12.782110 2026] [security2:error] [pid 255769:tid 255833] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "al9MFLxMYwyVGnfuwsKcqgAD_T8"], referer: http://aud-7.com/3PJcpMFsD8B.php
[Tue Jul 21 07:38:12.789578 2026] [proxy:error] [pid 255769:tid 255912] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:12.789633 2026] [proxy_http:error] [pid 255769:tid 255912] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:12.790245 2026] [proxy:error] [pid 255769:tid 255912] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:12.790272 2026] [proxy_http:error] [pid 255769:tid 255912] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:12.868995 2026] [autoindex:error] [pid 255769:tid 255953] [client 198.235.24.155:61912] AH01276: Cannot serve directory /home4/ciclod61/bahinternet.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:12.878721 2026] [security2:error] [pid 255769:tid 255902] [client 136.144.33.99:55013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MFLxMYwyVGnfuwsKcrwAAA6Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:12.885300 2026] [security2:error] [pid 255769:tid 255917] [client 20.151.10.161:2698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MFLxMYwyVGnfuwsKcsAAAA7U"]
[Tue Jul 21 07:38:13.019061 2026] [autoindex:error] [pid 255769:tid 255978] [client 20.206.105.145:38080] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:13.029189 2026] [security2:error] [pid 255769:tid 255946] [client 20.206.105.145:38080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MFbxMYwyVGnfuwsKctwAAA9I"]
[Tue Jul 21 07:38:13.043827 2026] [security2:error] [pid 254995:tid 255276] [client 20.197.195.24:13311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/uiuvs58l.php"] [unique_id "al9MFf7v0rlcEGmVraFBsQAAA5o"]
[Tue Jul 21 07:38:13.056647 2026] [security2:error] [pid 254995:tid 255210] [client 4.204.201.85:55954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/biufile.php"] [unique_id "al9MFf7v0rlcEGmVraFBsgAAA3I"]
[Tue Jul 21 07:38:13.167733 2026] [security2:error] [pid 255769:tid 255923] [client 20.151.10.161:2735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/images.php"] [unique_id "al9MFbxMYwyVGnfuwsKcvwAAA7s"]
[Tue Jul 21 07:38:13.245165 2026] [security2:error] [pid 254995:tid 255213] [client 139.167.225.182:49789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MFf7v0rlcEGmVraFBuAAAA3U"]
[Tue Jul 21 07:38:13.245350 2026] [security2:error] [pid 254995:tid 255213] [client 139.167.225.182:49789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MFf7v0rlcEGmVraFBuAAAA3U"]
[Tue Jul 21 07:38:13.287254 2026] [security2:error] [pid 254995:tid 255175] [client 20.226.60.151:51305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/classwithtostring.php"] [unique_id "al9MFf7v0rlcEGmVraFBuQAAA1A"]
[Tue Jul 21 07:38:13.295657 2026] [security2:error] [pid 255769:tid 255853] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "al9MFbxMYwyVGnfuwsKcxAADuFM"], referer: http://aud-7.com/5PJcpMFsD8B.php
[Tue Jul 21 07:38:13.348943 2026] [security2:error] [pid 255769:tid 255915] [client 4.204.201.85:57102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/mosty.php"] [unique_id "al9MFbxMYwyVGnfuwsKcxwAAA7M"]
[Tue Jul 21 07:38:13.446971 2026] [security2:error] [pid 255769:tid 256028] [client 20.151.10.161:2740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/for.php"] [unique_id "al9MFbxMYwyVGnfuwsKcygAABCI"]
[Tue Jul 21 07:38:13.586587 2026] [security2:error] [pid 255769:tid 255905] [client 194.99.104.35:46680] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MFbxMYwyVGnfuwsKczgAAA6k"]
[Tue Jul 21 07:38:13.586711 2026] [security2:error] [pid 255769:tid 255905] [client 194.99.104.35:46680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MFbxMYwyVGnfuwsKczgAAA6k"]
[Tue Jul 21 07:38:13.592191 2026] [proxy:error] [pid 254995:tid 255173] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:13.592242 2026] [proxy_http:error] [pid 254995:tid 255173] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:13.592870 2026] [proxy:error] [pid 254995:tid 255173] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:13.592892 2026] [proxy_http:error] [pid 254995:tid 255173] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:13.631379 2026] [security2:error] [pid 255769:tid 255976] [client 31.14.72.5:63929] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9MFbxMYwyVGnfuwsKc0AAAA_A"]
[Tue Jul 21 07:38:13.635483 2026] [security2:error] [pid 255769:tid 256009] [client 4.204.201.85:60613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/dejavu.php"] [unique_id "al9MFbxMYwyVGnfuwsKc0gAABA8"]
[Tue Jul 21 07:38:13.666550 2026] [proxy:error] [pid 254995:tid 255168] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:13.666606 2026] [proxy_http:error] [pid 254995:tid 255168] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:13.667222 2026] [proxy:error] [pid 254995:tid 255168] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:13.667259 2026] [proxy_http:error] [pid 254995:tid 255168] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:13.726019 2026] [proxy:error] [pid 254995:tid 255153] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:13.726078 2026] [proxy_http:error] [pid 254995:tid 255153] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:13.726582 2026] [proxy:error] [pid 254995:tid 255153] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:13.726610 2026] [proxy_http:error] [pid 254995:tid 255153] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:13.727240 2026] [security2:error] [pid 255769:tid 255966] [client 20.151.10.161:2724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/2larp.php"] [unique_id "al9MFbxMYwyVGnfuwsKc1wAAA-Y"]
[Tue Jul 21 07:38:13.773549 2026] [security2:error] [pid 255769:tid 255990] [client 20.226.60.151:61192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/root.php"] [unique_id "al9MFbxMYwyVGnfuwsKc2AAAA_4"]
[Tue Jul 21 07:38:13.792046 2026] [proxy:error] [pid 255769:tid 255929] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:13.792109 2026] [proxy_http:error] [pid 255769:tid 255929] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:13.793063 2026] [proxy:error] [pid 255769:tid 255929] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:13.793107 2026] [proxy_http:error] [pid 255769:tid 255929] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:13.796458 2026] [security2:error] [pid 254995:tid 255179] [client 20.206.105.145:38230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/adminfuns.php"] [unique_id "al9MFf7v0rlcEGmVraFBygAAA1Q"]
[Tue Jul 21 07:38:13.918925 2026] [security2:error] [pid 255769:tid 255807] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/dropdown.php"] [unique_id "al9MFbxMYwyVGnfuwsKc5AAD3iU"], referer: http://aud-7.com/dropdown.php
[Tue Jul 21 07:38:13.934460 2026] [security2:error] [pid 255769:tid 255928] [client 4.204.201.85:55544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/aaf.php"] [unique_id "al9MFbxMYwyVGnfuwsKc5QAAA8A"]
[Tue Jul 21 07:38:14.000066 2026] [fcgid:warn] [pid 254995:tid 255268] (70014)End of file found: [client 184.154.139.46:42706] mod_fcgid: can't get data from http client
[Tue Jul 21 07:38:14.004651 2026] [security2:error] [pid 255769:tid 255913] [client 20.151.10.161:2717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/adminner.php"] [unique_id "al9MFrxMYwyVGnfuwsKc5gAAA7E"]
[Tue Jul 21 07:38:14.012388 2026] [security2:error] [pid 255769:tid 255942] [client 20.220.225.223:38669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/cron.php"] [unique_id "al9MFrxMYwyVGnfuwsKc6AAAA84"]
[Tue Jul 21 07:38:14.059248 2026] [security2:error] [pid 255769:tid 256012] [client 20.197.195.24:63639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/40p9ixjd.php"] [unique_id "al9MFrxMYwyVGnfuwsKc6gAABBI"]
[Tue Jul 21 07:38:14.193609 2026] [security2:error] [pid 255769:tid 256005] [client 117.217.38.194:54144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MFrxMYwyVGnfuwsKc8AAABAs"]
[Tue Jul 21 07:38:14.193720 2026] [security2:error] [pid 255769:tid 256005] [client 117.217.38.194:54144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MFrxMYwyVGnfuwsKc8AAABAs"]
[Tue Jul 21 07:38:14.218300 2026] [security2:error] [pid 255769:tid 255920] [client 4.204.201.85:55981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/ha.php"] [unique_id "al9MFrxMYwyVGnfuwsKc8QAAA7g"]
[Tue Jul 21 07:38:14.233534 2026] [security2:error] [pid 255769:tid 256021] [client 20.226.60.151:51297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/sym403.php"] [unique_id "al9MFrxMYwyVGnfuwsKc8gAABBs"]
[Tue Jul 21 07:38:14.266568 2026] [security2:error] [pid 255769:tid 255915] [client 20.151.10.161:45988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/hur.php"] [unique_id "al9MFrxMYwyVGnfuwsKc8wAAA7M"]
[Tue Jul 21 07:38:14.284608 2026] [security2:error] [pid 255769:tid 255950] [client 20.151.10.161:2715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/82.php"] [unique_id "al9MFrxMYwyVGnfuwsKc9AAAA9Y"]
[Tue Jul 21 07:38:14.435989 2026] [security2:error] [pid 255769:tid 255790] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-admin.php"] [unique_id "al9MFrxMYwyVGnfuwsKc-AAD6hQ"], referer: http://aud-7.com/wp-admin.php
[Tue Jul 21 07:38:14.480207 2026] [access_compat:error] [pid 254995:tid 255163] [client 165.227.39.235:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:38:14.496809 2026] [security2:error] [pid 254995:tid 255209] [client 4.204.201.85:57135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/hur.php"] [unique_id "al9MFv7v0rlcEGmVraFB4QAAA3E"]
[Tue Jul 21 07:38:14.529367 2026] [security2:error] [pid 255769:tid 255919] [client 138.197.191.87:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webmail.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/server-status"] [unique_id "al9MFrxMYwyVGnfuwsKc-wAAA7c"]
[Tue Jul 21 07:38:14.557620 2026] [security2:error] [pid 255769:tid 256024] [client 20.151.10.161:2959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/kir.php"] [unique_id "al9MFrxMYwyVGnfuwsKc_QAABB4"]
[Tue Jul 21 07:38:14.559849 2026] [security2:error] [pid 255769:tid 255987] [client 20.220.225.223:31187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/xyn.php"] [unique_id "al9MFrxMYwyVGnfuwsKc_gAAA_s"]
[Tue Jul 21 07:38:14.596979 2026] [security2:error] [pid 255769:tid 255900] [client 157.245.36.108:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcontacts.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/server-status"] [unique_id "al9MFrxMYwyVGnfuwsKc_wAAA6Q"]
[Tue Jul 21 07:38:14.615146 2026] [security2:error] [pid 255769:tid 255989] [client 178.128.207.138:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webdisk.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/server-status"] [unique_id "al9MFrxMYwyVGnfuwsKdAAAAA_0"]
[Tue Jul 21 07:38:14.642293 2026] [security2:error] [pid 255769:tid 255918] [client 147.182.149.75:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcalendars.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/server-status"] [unique_id "al9MFrxMYwyVGnfuwsKdAQAAA7Y"]
[Tue Jul 21 07:38:14.702617 2026] [security2:error] [pid 254995:tid 255138] [client 146.190.63.248:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpanel.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/server-status"] [unique_id "al9MFv7v0rlcEGmVraFB5gAAAys"]
[Tue Jul 21 07:38:14.720239 2026] [security2:error] [pid 254995:tid 255160] [client 46.101.1.225:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcontacts.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/server-status"] [unique_id "al9MFv7v0rlcEGmVraFB5wAAA0E"]
[Tue Jul 21 07:38:14.785855 2026] [security2:error] [pid 255769:tid 255967] [client 4.204.201.85:57117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/h02ugyh.php"] [unique_id "al9MFrxMYwyVGnfuwsKdAwAAA-c"]
[Tue Jul 21 07:38:14.860558 2026] [security2:error] [pid 255769:tid 255901] [client 173.24.185.52:58509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MFrxMYwyVGnfuwsKdBQAAA6U"]
[Tue Jul 21 07:38:14.860665 2026] [security2:error] [pid 255769:tid 255901] [client 173.24.185.52:58509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MFrxMYwyVGnfuwsKdBQAAA6U"]
[Tue Jul 21 07:38:14.864183 2026] [security2:error] [pid 255769:tid 255990] [client 20.226.60.151:61199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/v543.php"] [unique_id "al9MFrxMYwyVGnfuwsKdBwAAA_4"]
[Tue Jul 21 07:38:14.864237 2026] [security2:error] [pid 255769:tid 255983] [client 138.68.82.23:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcalendars.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/server-status"] [unique_id "al9MFrxMYwyVGnfuwsKdBgAAA_c"]
[Tue Jul 21 07:38:14.922490 2026] [security2:error] [pid 255769:tid 255932] [client 128.199.182.55:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpanel.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/server-status"] [unique_id "al9MFrxMYwyVGnfuwsKdCQAAA8Q"]
[Tue Jul 21 07:38:14.950407 2026] [security2:error] [pid 255769:tid 255821] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/license.php"] [unique_id "al9MFrxMYwyVGnfuwsKdDAAD3jM"], referer: http://aud-7.com/license.php
[Tue Jul 21 07:38:14.975462 2026] [security2:error] [pid 254995:tid 255220] [client 31.14.72.5:65218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9MFv7v0rlcEGmVraFB6QAAA3w"]
[Tue Jul 21 07:38:14.988469 2026] [access_compat:error] [pid 255769:tid 256004] [client 167.99.210.137:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:38:15.017129 2026] [access_compat:error] [pid 255769:tid 255951] [client 165.227.173.41:0] AH01797: client denied by server configuration: proxy:http://127.0.0.1/cgi-sys/autodiscover.cgi
[Tue Jul 21 07:38:15.064271 2026] [security2:error] [pid 254995:tid 255182] [client 4.204.201.85:55547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/155.php"] [unique_id "al9MF_7v0rlcEGmVraFB7AAAA1c"]
[Tue Jul 21 07:38:15.067021 2026] [access_compat:error] [pid 255769:tid 255912] [client 64.226.65.160:0] AH01797: client denied by server configuration: proxy:http://127.0.0.1/cgi-sys/autodiscover.cgi
[Tue Jul 21 07:38:15.089170 2026] [security2:error] [pid 255769:tid 255913] [client 20.197.195.24:62425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/uiuvs58l.update.php"] [unique_id "al9MF7xMYwyVGnfuwsKdEAAAA7E"]
[Tue Jul 21 07:38:15.097279 2026] [security2:error] [pid 254995:tid 255223] [client 165.227.173.41:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webmail.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/server-status"] [unique_id "al9MF_7v0rlcEGmVraFB7QAAA38"]
[Tue Jul 21 07:38:15.188184 2026] [security2:error] [pid 254995:tid 255129] [client 139.59.143.102:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webdisk.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/server-status"] [unique_id "al9MF_7v0rlcEGmVraFB8AAAAyI"]
[Tue Jul 21 07:38:15.325063 2026] [security2:error] [pid 255769:tid 255936] [client 62.102.148.187:56938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MF7xMYwyVGnfuwsKdEwAAA8g"]
[Tue Jul 21 07:38:15.325185 2026] [security2:error] [pid 255769:tid 255936] [client 62.102.148.187:56938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MF7xMYwyVGnfuwsKdEwAAA8g"]
[Tue Jul 21 07:38:15.347130 2026] [security2:error] [pid 254995:tid 255136] [client 4.204.201.85:61309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/pp.php"] [unique_id "al9MF_7v0rlcEGmVraFB8wAAAyk"]
[Tue Jul 21 07:38:15.374507 2026] [security2:error] [pid 254995:tid 255217] [client 20.226.60.151:51272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/sixxis.php"] [unique_id "al9MF_7v0rlcEGmVraFB9QAAA3k"]
[Tue Jul 21 07:38:15.462636 2026] [security2:error] [pid 255769:tid 255890] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/content.php"] [unique_id "al9MF7xMYwyVGnfuwsKdGwADung"], referer: http://aud-7.com/content.php
[Tue Jul 21 07:38:15.485598 2026] [access_compat:error] [pid 255769:tid 255923] [client 138.68.86.32:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:38:15.543721 2026] [access_compat:error] [pid 254995:tid 255010] [remote 159.65.144.72:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:38:15.584101 2026] [access_compat:error] [pid 254995:tid 255149] [client 138.68.86.32:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:38:15.623348 2026] [access_compat:error] [pid 254995:tid 255116] [remote 159.65.144.72:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:38:15.637755 2026] [security2:error] [pid 254995:tid 255144] [client 4.204.201.85:57205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/ops.php"] [unique_id "al9MF_7v0rlcEGmVraFB-gAAAzE"]
[Tue Jul 21 07:38:15.733038 2026] [security2:error] [pid 255769:tid 255897] [remote 202.51.202.242:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-login.php"] [unique_id "al9MF7xMYwyVGnfuwsKdIwAD-38"]
[Tue Jul 21 07:38:15.836468 2026] [access_compat:error] [pid 255769:tid 255976] [client 46.101.111.185:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:38:15.853022 2026] [security2:error] [pid 255769:tid 256017] [client 117.251.86.144:45980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MF7xMYwyVGnfuwsKdJgAABBc"]
[Tue Jul 21 07:38:15.853125 2026] [security2:error] [pid 255769:tid 256017] [client 117.251.86.144:45980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MF7xMYwyVGnfuwsKdJgAABBc"]
[Tue Jul 21 07:38:15.941603 2026] [access_compat:error] [pid 255769:tid 256005] [client 64.227.70.2:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:38:15.945482 2026] [security2:error] [pid 255769:tid 255955] [client 4.204.201.85:55937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/ingfo.php"] [unique_id "al9MF7xMYwyVGnfuwsKdJwAAA9s"]
[Tue Jul 21 07:38:15.973357 2026] [security2:error] [pid 255769:tid 255858] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/install.php"] [unique_id "al9MF7xMYwyVGnfuwsKdKgAD91g"], referer: http://aud-7.com/install.php
[Tue Jul 21 07:38:16.060785 2026] [security2:error] [pid 255769:tid 255902] [client 20.197.195.24:63648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/for.php"] [unique_id "al9MGLxMYwyVGnfuwsKdKwAAA6Y"]
[Tue Jul 21 07:38:16.202330 2026] [security2:error] [pid 255769:tid 255957] [client 20.226.60.151:27634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/chosen.php"] [unique_id "al9MGLxMYwyVGnfuwsKdLQAAA90"]
[Tue Jul 21 07:38:16.242614 2026] [security2:error] [pid 255769:tid 255928] [client 4.204.201.85:57193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/error_log.php"] [unique_id "al9MGLxMYwyVGnfuwsKdLwAAA8A"]
[Tue Jul 21 07:38:16.259748 2026] [security2:error] [pid 254995:tid 255210] [client 103.162.129.114:56999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9MGP7v0rlcEGmVraFCBAAAA3I"]
[Tue Jul 21 07:38:16.259881 2026] [security2:error] [pid 254995:tid 255210] [client 103.162.129.114:56999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9MGP7v0rlcEGmVraFCBAAAA3I"]
[Tue Jul 21 07:38:16.272335 2026] [security2:error] [pid 254995:tid 255266] [client 122.186.204.214:59654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MGP7v0rlcEGmVraFCBgAAA5A"]
[Tue Jul 21 07:38:16.272445 2026] [security2:error] [pid 254995:tid 255266] [client 122.186.204.214:59654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MGP7v0rlcEGmVraFCBgAAA5A"]
[Tue Jul 21 07:38:16.325565 2026] [security2:error] [pid 254995:tid 255154] [client 31.14.72.5:50129] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9MGP7v0rlcEGmVraFCCAAAAzs"]
[Tue Jul 21 07:38:16.343769 2026] [security2:error] [pid 255769:tid 255942] [client 20.226.60.151:51370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ip.php"] [unique_id "al9MGLxMYwyVGnfuwsKdMgAAA84"]
[Tue Jul 21 07:38:16.397929 2026] [security2:error] [pid 254995:tid 255140] [client 20.197.195.24:62883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/raw.php"] [unique_id "al9MGP7v0rlcEGmVraFCCgAAAy0"]
[Tue Jul 21 07:38:16.482632 2026] [security2:error] [pid 255769:tid 255787] [remote 124.55.178.99:40832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9MF7xMYwyVGnfuwsKdHAADwRE"]
[Tue Jul 21 07:38:16.493476 2026] [security2:error] [pid 255769:tid 255797] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/inputs.php"] [unique_id "al9MGLxMYwyVGnfuwsKdOQAD4Bs"], referer: http://aud-7.com/inputs.php
[Tue Jul 21 07:38:16.493748 2026] [security2:error] [pid 255769:tid 255992] [client 20.206.105.145:38500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/goods.php"] [unique_id "al9MGLxMYwyVGnfuwsKdOgAAA_8"]
[Tue Jul 21 07:38:16.531321 2026] [security2:error] [pid 255769:tid 255899] [client 4.204.201.85:57210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/test10.php"] [unique_id "al9MGLxMYwyVGnfuwsKdPAAAA6M"]
[Tue Jul 21 07:38:16.592739 2026] [proxy:error] [pid 254995:tid 255219] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:16.592805 2026] [proxy_http:error] [pid 254995:tid 255219] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:16.593714 2026] [proxy:error] [pid 254995:tid 255219] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:16.593755 2026] [proxy_http:error] [pid 254995:tid 255219] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:16.641128 2026] [proxy:error] [pid 254995:tid 255274] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:16.641206 2026] [proxy_http:error] [pid 254995:tid 255274] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:16.642118 2026] [proxy:error] [pid 254995:tid 255274] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:16.642165 2026] [proxy_http:error] [pid 254995:tid 255274] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:16.723978 2026] [proxy:error] [pid 254995:tid 255177] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:16.724051 2026] [proxy_http:error] [pid 254995:tid 255177] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:16.724739 2026] [proxy:error] [pid 254995:tid 255177] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:16.724769 2026] [proxy_http:error] [pid 254995:tid 255177] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:16.767778 2026] [security2:error] [pid 255769:tid 256028] [client 20.220.225.223:31183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/xxx.php"] [unique_id "al9MGLxMYwyVGnfuwsKdQAAABCI"]
[Tue Jul 21 07:38:16.786959 2026] [proxy:error] [pid 254995:tid 255159] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:16.787036 2026] [proxy_http:error] [pid 254995:tid 255159] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:16.787692 2026] [proxy:error] [pid 254995:tid 255159] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:16.787739 2026] [proxy_http:error] [pid 254995:tid 255159] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:16.812619 2026] [security2:error] [pid 255769:tid 255935] [client 4.204.201.85:57092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/koala.php"] [unique_id "al9MGLxMYwyVGnfuwsKdQgAAA8c"]
[Tue Jul 21 07:38:16.881726 2026] [security2:error] [pid 255769:tid 255987] [client 20.226.60.151:51363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/kq1.php"] [unique_id "al9MGLxMYwyVGnfuwsKdRAAAA_s"]
[Tue Jul 21 07:38:16.995371 2026] [security2:error] [pid 254995:tid 255067] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MGP7v0rlcEGmVraFCGgADk0c"]
[Tue Jul 21 07:38:16.995502 2026] [security2:error] [pid 254995:tid 255269] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MGP7v0rlcEGmVraFCGgADk0c"]
[Tue Jul 21 07:38:17.010468 2026] [security2:error] [pid 255769:tid 255893] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/style2.php"] [unique_id "al9MGbxMYwyVGnfuwsKdTgAD5Xs"], referer: http://aud-7.com/style2.php
[Tue Jul 21 07:38:17.152925 2026] [security2:error] [pid 255769:tid 256022] [client 4.204.201.85:55979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/mac.php"] [unique_id "al9MGbxMYwyVGnfuwsKdUQAABBw"]
[Tue Jul 21 07:38:17.177117 2026] [security2:error] [pid 255769:tid 255970] [client 193.36.225.152:54549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MGbxMYwyVGnfuwsKdUgAAA-o"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:38:17.459202 2026] [security2:error] [pid 254995:tid 255162] [client 4.204.201.85:55939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wefile.php"] [unique_id "al9MGf7v0rlcEGmVraFCIwAAA0M"]
[Tue Jul 21 07:38:17.522909 2026] [security2:error] [pid 255769:tid 255802] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/simple.php"] [unique_id "al9MGbxMYwyVGnfuwsKdXAADtCA"], referer: http://aud-7.com/simple.php
[Tue Jul 21 07:38:17.608636 2026] [proxy:error] [pid 255769:tid 255960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:17.608709 2026] [proxy_http:error] [pid 255769:tid 255960] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:17.609272 2026] [proxy:error] [pid 255769:tid 255960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:17.609309 2026] [proxy_http:error] [pid 255769:tid 255960] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:17.628315 2026] [proxy:error] [pid 255769:tid 255992] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:17.628380 2026] [proxy_http:error] [pid 255769:tid 255992] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:17.628830 2026] [proxy:error] [pid 255769:tid 255992] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:17.628856 2026] [proxy_http:error] [pid 255769:tid 255992] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:17.700967 2026] [security2:error] [pid 255769:tid 255990] [client 31.14.72.5:51353] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9MGbxMYwyVGnfuwsKdYwAAA_4"]
[Tue Jul 21 07:38:17.777540 2026] [proxy:error] [pid 254995:tid 255214] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:17.777608 2026] [proxy_http:error] [pid 254995:tid 255214] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:17.778292 2026] [proxy:error] [pid 254995:tid 255214] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:17.778324 2026] [proxy_http:error] [pid 254995:tid 255214] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:17.831369 2026] [security2:error] [pid 255769:tid 255855] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MGbxMYwyVGnfuwsKdZgAD2FU"]
[Tue Jul 21 07:38:17.831547 2026] [security2:error] [pid 255769:tid 255952] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MGbxMYwyVGnfuwsKdZgAD2FU"]
[Tue Jul 21 07:38:17.873774 2026] [security2:error] [pid 255769:tid 255932] [client 20.226.60.151:51378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9MGbxMYwyVGnfuwsKdZwAAA8Q"]
[Tue Jul 21 07:38:17.915042 2026] [proxy:error] [pid 255769:tid 255908] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:17.915107 2026] [proxy_http:error] [pid 255769:tid 255908] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:17.915843 2026] [proxy:error] [pid 255769:tid 255908] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:17.915872 2026] [proxy_http:error] [pid 255769:tid 255908] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:17.916370 2026] [security2:error] [pid 254995:tid 255182] [client 20.226.60.151:27587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/cream1.php"] [unique_id "al9MGf7v0rlcEGmVraFCLgAAA1c"]
[Tue Jul 21 07:38:17.958145 2026] [autoindex:error] [pid 255769:tid 256020] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:18.034773 2026] [security2:error] [pid 255769:tid 255801] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/chosen.php"] [unique_id "al9MGrxMYwyVGnfuwsKdbwAD6R8"], referer: http://aud-7.com/chosen.php
[Tue Jul 21 07:38:18.131915 2026] [security2:error] [pid 254995:tid 255225] [client 20.151.10.161:45915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/h02ugyh.php"] [unique_id "al9MGv7v0rlcEGmVraFCMQAAA4E"]
[Tue Jul 21 07:38:18.150328 2026] [security2:error] [pid 254995:tid 255178] [client 20.206.105.145:37928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/ms-edit.php"] [unique_id "al9MGv7v0rlcEGmVraFCMwAAA1M"]
[Tue Jul 21 07:38:18.243176 2026] [proxy:error] [pid 255769:tid 255951] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.243241 2026] [proxy_http:error] [pid 255769:tid 255951] [client 159.203.172.133:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.243807 2026] [proxy:error] [pid 255769:tid 255951] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.243858 2026] [proxy_http:error] [pid 255769:tid 255951] [client 159.203.172.133:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.311275 2026] [security2:error] [pid 254995:tid 255279] [client 175.45.70.82:64999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MGv7v0rlcEGmVraFCOAAAA50"]
[Tue Jul 21 07:38:18.311396 2026] [security2:error] [pid 254995:tid 255279] [client 175.45.70.82:64999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MGv7v0rlcEGmVraFCOAAAA50"]
[Tue Jul 21 07:38:18.328618 2026] [autoindex:error] [pid 255769:tid 256012] [client 4.204.201.85:55949] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:18.457516 2026] [security2:error] [pid 255769:tid 255906] [client 154.192.233.199:60146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MGrxMYwyVGnfuwsKdgQAAA6o"]
[Tue Jul 21 07:38:18.457712 2026] [security2:error] [pid 255769:tid 255906] [client 154.192.233.199:60146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MGrxMYwyVGnfuwsKdgQAAA6o"]
[Tue Jul 21 07:38:18.466643 2026] [security2:error] [pid 255769:tid 255899] [client 4.204.201.85:55949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/makeasmtp.php"] [unique_id "al9MGrxMYwyVGnfuwsKdggAAA6M"]
[Tue Jul 21 07:38:18.504240 2026] [proxy:error] [pid 255769:tid 255914] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.504302 2026] [proxy_http:error] [pid 255769:tid 255914] [client 159.203.172.133:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.reginaldomilagresrei1755908069857.0721679.meusitehostgator.com.br/
[Tue Jul 21 07:38:18.505380 2026] [proxy:error] [pid 255769:tid 255914] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.505413 2026] [proxy_http:error] [pid 255769:tid 255914] [client 159.203.172.133:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.reginaldomilagresrei1755908069857.0721679.meusitehostgator.com.br/
[Tue Jul 21 07:38:18.548553 2026] [security2:error] [pid 255769:tid 255816] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/bypass.php"] [unique_id "al9MGrxMYwyVGnfuwsKdiAAD1i4"], referer: http://aud-7.com/bypass.php
[Tue Jul 21 07:38:18.601501 2026] [proxy:error] [pid 254995:tid 255142] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.601570 2026] [proxy_http:error] [pid 254995:tid 255142] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.602238 2026] [proxy:error] [pid 254995:tid 255142] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.602270 2026] [proxy_http:error] [pid 254995:tid 255142] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.636416 2026] [proxy:error] [pid 255769:tid 255974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.636469 2026] [proxy_http:error] [pid 255769:tid 255974] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.636973 2026] [proxy:error] [pid 255769:tid 255974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.637001 2026] [proxy_http:error] [pid 255769:tid 255974] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.768308 2026] [proxy:error] [pid 254995:tid 255145] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.768371 2026] [proxy_http:error] [pid 254995:tid 255145] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.768911 2026] [proxy:error] [pid 254995:tid 255145] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.768936 2026] [proxy_http:error] [pid 254995:tid 255145] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.785408 2026] [security2:error] [pid 255769:tid 255955] [client 122.162.144.145:22758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MGrxMYwyVGnfuwsKdkQAAA9s"]
[Tue Jul 21 07:38:18.785511 2026] [security2:error] [pid 255769:tid 255955] [client 122.162.144.145:22758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MGrxMYwyVGnfuwsKdkQAAA9s"]
[Tue Jul 21 07:38:18.882566 2026] [proxy:error] [pid 254995:tid 255272] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.882636 2026] [proxy_http:error] [pid 254995:tid 255272] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.883652 2026] [proxy:error] [pid 254995:tid 255272] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.883700 2026] [proxy_http:error] [pid 254995:tid 255272] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.917214 2026] [proxy:error] [pid 255769:tid 255976] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.917278 2026] [proxy_http:error] [pid 255769:tid 255976] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.917808 2026] [proxy:error] [pid 255769:tid 255976] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.917853 2026] [proxy_http:error] [pid 255769:tid 255976] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.989153 2026] [security2:error] [pid 254995:tid 255144] [client 103.106.20.201:54356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MGv7v0rlcEGmVraFCTAAAAzE"]
[Tue Jul 21 07:38:18.989273 2026] [security2:error] [pid 254995:tid 255144] [client 103.106.20.201:54356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MGv7v0rlcEGmVraFCTAAAAzE"]
[Tue Jul 21 07:38:18.989285 2026] [proxy:error] [pid 255769:tid 255917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.989325 2026] [proxy_http:error] [pid 255769:tid 255917] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.989780 2026] [proxy:error] [pid 255769:tid 255917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.989801 2026] [proxy_http:error] [pid 255769:tid 255917] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.043496 2026] [security2:error] [pid 255769:tid 255968] [client 4.204.201.85:55551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/2P.php"] [unique_id "al9MG7xMYwyVGnfuwsKduAAAA-g"]
[Tue Jul 21 07:38:19.050887 2026] [security2:error] [pid 254995:tid 255180] [client 31.14.72.5:52036] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9MG_7v0rlcEGmVraFCTgAAA1U"]
[Tue Jul 21 07:38:19.060340 2026] [security2:error] [pid 255769:tid 255887] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/config.php"] [unique_id "al9MG7xMYwyVGnfuwsKduQAEE3U"], referer: http://aud-7.com/config.php
[Tue Jul 21 07:38:19.107591 2026] [security2:error] [pid 255769:tid 255996] [client 122.164.127.47:56990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MG7xMYwyVGnfuwsKdugAABAI"]
[Tue Jul 21 07:38:19.109131 2026] [security2:error] [pid 255769:tid 255996] [client 122.164.127.47:56990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MG7xMYwyVGnfuwsKdugAABAI"]
[Tue Jul 21 07:38:19.146841 2026] [security2:error] [pid 255769:tid 256012] [client 20.206.105.145:38090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/222.php"] [unique_id "al9MG7xMYwyVGnfuwsKdvQAABBI"]
[Tue Jul 21 07:38:19.207050 2026] [proxy:error] [pid 255769:tid 255929] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.207110 2026] [proxy_http:error] [pid 255769:tid 255929] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.207676 2026] [proxy:error] [pid 255769:tid 255929] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.207701 2026] [proxy_http:error] [pid 255769:tid 255929] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.211193 2026] [security2:error] [pid 254995:tid 255275] [client 20.226.60.151:51373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/h02ugyh.php"] [unique_id "al9MG_7v0rlcEGmVraFCUQAAA5k"]
[Tue Jul 21 07:38:19.250117 2026] [proxy:error] [pid 255769:tid 255960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.250187 2026] [proxy_http:error] [pid 255769:tid 255960] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.250614 2026] [proxy:error] [pid 255769:tid 255960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.250638 2026] [proxy_http:error] [pid 255769:tid 255960] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.324572 2026] [proxy:error] [pid 255769:tid 255978] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.324652 2026] [proxy_http:error] [pid 255769:tid 255978] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.325446 2026] [proxy:error] [pid 255769:tid 255978] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.325487 2026] [proxy_http:error] [pid 255769:tid 255978] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.376057 2026] [proxy:error] [pid 254995:tid 255188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.376113 2026] [proxy_http:error] [pid 254995:tid 255188] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.376610 2026] [proxy:error] [pid 254995:tid 255188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.376634 2026] [proxy_http:error] [pid 254995:tid 255188] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.381538 2026] [security2:error] [pid 254995:tid 255215] [client 4.204.201.85:57140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/.well-known/about.php"] [unique_id "al9MG_7v0rlcEGmVraFCWAAAA3c"]
[Tue Jul 21 07:38:19.505181 2026] [proxy:error] [pid 255769:tid 255949] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.505255 2026] [proxy_http:error] [pid 255769:tid 255949] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.505803 2026] [proxy:error] [pid 255769:tid 255949] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.505847 2026] [proxy_http:error] [pid 255769:tid 255949] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.538515 2026] [proxy:error] [pid 255769:tid 255987] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.538590 2026] [proxy_http:error] [pid 255769:tid 255987] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.539222 2026] [proxy:error] [pid 255769:tid 255987] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.539250 2026] [proxy_http:error] [pid 255769:tid 255987] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.575002 2026] [security2:error] [pid 255769:tid 255829] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/themes.php"] [unique_id "al9MG7xMYwyVGnfuwsKd0gAD-js"], referer: http://aud-7.com/themes.php
[Tue Jul 21 07:38:19.703343 2026] [security2:error] [pid 255769:tid 255869] [remote 72.167.132.114:35372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/wp-login.php"] [unique_id "al9MG7xMYwyVGnfuwsKd1wADo2M"]
[Tue Jul 21 07:38:19.765321 2026] [proxy:error] [pid 254995:tid 255156] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.765393 2026] [proxy_http:error] [pid 254995:tid 255156] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.766011 2026] [proxy:error] [pid 254995:tid 255156] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.766055 2026] [proxy_http:error] [pid 254995:tid 255156] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.776211 2026] [security2:error] [pid 255769:tid 255921] [client 20.220.225.223:31173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/hunter.php"] [unique_id "al9MG7xMYwyVGnfuwsKd2gAAA7k"]
[Tue Jul 21 07:38:19.856261 2026] [security2:error] [pid 254995:tid 255172] [client 172.245.102.43:22279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.102.245.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MG_7v0rlcEGmVraFCZAAAA00"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:19.928066 2026] [proxy:error] [pid 255769:tid 255941] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.928130 2026] [proxy_http:error] [pid 255769:tid 255941] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.928615 2026] [proxy:error] [pid 255769:tid 255941] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.928653 2026] [proxy_http:error] [pid 255769:tid 255941] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.977729 2026] [security2:error] [pid 255769:tid 255913] [client 20.206.105.145:38112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9MG7xMYwyVGnfuwsKd6QAAA7E"]
[Tue Jul 21 07:38:19.983008 2026] [security2:error] [pid 254995:tid 255039] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MG_7v0rlcEGmVraFCbgADZys"]
[Tue Jul 21 07:38:19.983147 2026] [security2:error] [pid 254995:tid 255198] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MG_7v0rlcEGmVraFCbgADZys"]
[Tue Jul 21 07:38:20.030242 2026] [proxy:error] [pid 255769:tid 256017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:20.030306 2026] [proxy_http:error] [pid 255769:tid 256017] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:20.030770 2026] [proxy:error] [pid 255769:tid 256017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:20.030806 2026] [proxy_http:error] [pid 255769:tid 256017] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:20.049666 2026] [security2:error] [pid 255769:tid 255859] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MHLxMYwyVGnfuwsKd7gAD01k"]
[Tue Jul 21 07:38:20.049807 2026] [security2:error] [pid 255769:tid 255947] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MHLxMYwyVGnfuwsKd7gAD01k"]
[Tue Jul 21 07:38:20.096249 2026] [security2:error] [pid 255769:tid 255877] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/admin.php"] [unique_id "al9MHLxMYwyVGnfuwsKd8AAD4ms"], referer: http://aud-7.com/admin.php
[Tue Jul 21 07:38:20.116233 2026] [security2:error] [pid 254995:tid 255273] [client 4.204.201.85:57159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9MHP7v0rlcEGmVraFCcgAAA5c"]
[Tue Jul 21 07:38:20.172032 2026] [security2:error] [pid 255769:tid 256021] [client 20.226.60.151:27593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/dr.php"] [unique_id "al9MHLxMYwyVGnfuwsKd9gAABBs"]
[Tue Jul 21 07:38:20.218823 2026] [security2:error] [pid 255769:tid 255908] [client 20.226.60.151:56217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MHLxMYwyVGnfuwsKd-QAAA6w"]
[Tue Jul 21 07:38:20.400481 2026] [security2:error] [pid 255769:tid 255966] [client 31.14.72.5:52728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9MHLxMYwyVGnfuwsKd_QAAA-Y"]
[Tue Jul 21 07:38:20.411083 2026] [proxy:error] [pid 255769:tid 255935] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:20.411152 2026] [proxy_http:error] [pid 255769:tid 255935] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:20.411667 2026] [proxy:error] [pid 255769:tid 255935] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:20.411691 2026] [proxy_http:error] [pid 255769:tid 255935] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:20.448406 2026] [security2:error] [pid 255769:tid 255914] [client 20.197.192.193:59959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MHLxMYwyVGnfuwsKeAQAAA7I"]
[Tue Jul 21 07:38:20.468400 2026] [security2:error] [pid 254995:tid 255224] [client 20.197.192.193:59912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MHP7v0rlcEGmVraFCfAAAA4A"]
[Tue Jul 21 07:38:20.479211 2026] [security2:error] [pid 255769:tid 255954] [client 20.197.192.193:20768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/dp.php"] [unique_id "al9MHLxMYwyVGnfuwsKeBQAAA9o"]
[Tue Jul 21 07:38:20.495654 2026] [proxy:error] [pid 255769:tid 255917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:20.495723 2026] [proxy_http:error] [pid 255769:tid 255917] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:20.496435 2026] [proxy:error] [pid 255769:tid 255917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:20.496468 2026] [proxy_http:error] [pid 255769:tid 255917] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:20.498649 2026] [security2:error] [pid 255769:tid 255984] [client 20.197.192.193:59937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/old.php"] [unique_id "al9MHLxMYwyVGnfuwsKeBwAAA_g"]
[Tue Jul 21 07:38:20.545988 2026] [security2:error] [pid 255769:tid 255953] [client 20.197.192.193:20755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/ms-new.php"] [unique_id "al9MHLxMYwyVGnfuwsKeCQAAA9k"]
[Tue Jul 21 07:38:20.609264 2026] [security2:error] [pid 255769:tid 255873] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/about.php"] [unique_id "al9MHLxMYwyVGnfuwsKeCgADpWc"], referer: http://aud-7.com/about.php
[Tue Jul 21 07:38:20.618289 2026] [security2:error] [pid 254995:tid 255173] [client 20.197.192.193:59909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/track.php"] [unique_id "al9MHP7v0rlcEGmVraFCgQAAA04"]
[Tue Jul 21 07:38:20.618587 2026] [security2:error] [pid 254995:tid 255257] [client 4.204.201.85:55960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/system_log.php"] [unique_id "al9MHP7v0rlcEGmVraFCggAAA4c"]
[Tue Jul 21 07:38:20.630087 2026] [security2:error] [pid 255769:tid 255932] [client 20.197.192.193:20766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/2352356666.php"] [unique_id "al9MHLxMYwyVGnfuwsKeDAAAA8Q"]
[Tue Jul 21 07:38:20.639948 2026] [security2:error] [pid 255769:tid 255989] [client 152.59.154.239:1099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MHLxMYwyVGnfuwsKeDQAAA_0"]
[Tue Jul 21 07:38:20.640050 2026] [security2:error] [pid 255769:tid 255989] [client 152.59.154.239:1099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MHLxMYwyVGnfuwsKeDQAAA_0"]
[Tue Jul 21 07:38:20.641058 2026] [security2:error] [pid 255769:tid 256013] [client 20.197.192.193:20756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/pn.php"] [unique_id "al9MHLxMYwyVGnfuwsKeDgAABBM"]
[Tue Jul 21 07:38:20.650962 2026] [security2:error] [pid 254995:tid 255217] [client 20.197.192.193:59954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9MHP7v0rlcEGmVraFCgwAAA3k"]
[Tue Jul 21 07:38:20.660602 2026] [security2:error] [pid 254995:tid 255168] [client 20.197.192.193:20743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/dr.php"] [unique_id "al9MHP7v0rlcEGmVraFChAAAA0k"]
[Tue Jul 21 07:38:20.668274 2026] [security2:error] [pid 254995:tid 255272] [client 138.197.191.87:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "al9MHP7v0rlcEGmVraFChQAAA5Y"]
[Tue Jul 21 07:38:20.672451 2026] [security2:error] [pid 254995:tid 255153] [client 20.197.192.193:20780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/2x.php"] [unique_id "al9MHP7v0rlcEGmVraFChgAAAzo"]
[Tue Jul 21 07:38:20.686257 2026] [security2:error] [pid 254995:tid 255254] [client 20.197.192.193:59932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/kq1.php"] [unique_id "al9MHP7v0rlcEGmVraFChwAAA4Q"]
[Tue Jul 21 07:38:20.697417 2026] [security2:error] [pid 254995:tid 255179] [client 20.197.192.193:20797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/zzz.php"] [unique_id "al9MHP7v0rlcEGmVraFCiAAAA1Q"]
[Tue Jul 21 07:38:20.701336 2026] [security2:error] [pid 254995:tid 255126] [client 184.154.139.46:44982] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "diskvidros.com.br"] [uri "/wp-content/plugins/woocommerce/readme.txt"] [unique_id "al9MHP7v0rlcEGmVraFCiQAAAx8"]
[Tue Jul 21 07:38:20.710732 2026] [security2:error] [pid 254995:tid 255144] [client 20.197.192.193:59925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/wicked.php"] [unique_id "al9MHP7v0rlcEGmVraFCigAAAzE"]
[Tue Jul 21 07:38:20.725483 2026] [security2:error] [pid 255769:tid 255979] [client 20.197.192.193:59908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/edit.php"] [unique_id "al9MHLxMYwyVGnfuwsKeEAAAA_M"]
[Tue Jul 21 07:38:20.736505 2026] [security2:error] [pid 254995:tid 255165] [client 20.197.192.193:59931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/kua.php"] [unique_id "al9MHP7v0rlcEGmVraFCiwAAA0Y"]
[Tue Jul 21 07:38:20.746904 2026] [security2:error] [pid 254995:tid 255155] [client 20.197.192.193:59949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/ez.php"] [unique_id "al9MHP7v0rlcEGmVraFCjAAAAzw"]
[Tue Jul 21 07:38:20.759771 2026] [security2:error] [pid 254995:tid 255275] [client 20.197.192.193:20772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/fz.php"] [unique_id "al9MHP7v0rlcEGmVraFCjQAAA5k"]
[Tue Jul 21 07:38:20.774973 2026] [proxy:error] [pid 254995:tid 255190] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:20.775029 2026] [proxy_http:error] [pid 254995:tid 255190] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:20.775471 2026] [proxy:error] [pid 254995:tid 255190] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:20.775492 2026] [proxy_http:error] [pid 254995:tid 255190] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:20.777589 2026] [security2:error] [pid 254995:tid 255159] [client 20.226.60.151:51379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-temp.php"] [unique_id "al9MHP7v0rlcEGmVraFCkAAAA0A"]
[Tue Jul 21 07:38:20.778144 2026] [security2:error] [pid 254995:tid 255212] [client 20.197.192.193:20742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/la.php"] [unique_id "al9MHP7v0rlcEGmVraFCkQAAA3Q"]
[Tue Jul 21 07:38:20.795510 2026] [security2:error] [pid 254995:tid 255171] [client 20.197.192.193:59905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9MHP7v0rlcEGmVraFCkgAAA0w"]
[Tue Jul 21 07:38:20.807177 2026] [security2:error] [pid 254995:tid 255137] [client 20.197.192.193:59961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/inso.php"] [unique_id "al9MHP7v0rlcEGmVraFCkwAAAyo"]
[Tue Jul 21 07:38:20.824573 2026] [security2:error] [pid 255769:tid 256012] [client 20.151.10.161:46000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/seiso.php"] [unique_id "al9MHLxMYwyVGnfuwsKeEgAABBI"]
[Tue Jul 21 07:38:20.837337 2026] [security2:error] [pid 254995:tid 255188] [client 20.197.192.193:20753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/wpx.php"] [unique_id "al9MHP7v0rlcEGmVraFClQAAA10"]
[Tue Jul 21 07:38:20.849598 2026] [security2:error] [pid 255769:tid 255957] [client 20.197.192.193:59921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/berlin.php"] [unique_id "al9MHLxMYwyVGnfuwsKeFAAAA90"]
[Tue Jul 21 07:38:20.859655 2026] [security2:error] [pid 254995:tid 255252] [client 165.227.39.235:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MHP7v0rlcEGmVraFClgAAA4M"]
[Tue Jul 21 07:38:20.860847 2026] [security2:error] [pid 254995:tid 255200] [client 20.197.192.193:20745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/billur.php"] [unique_id "al9MHP7v0rlcEGmVraFClwAAA2k"]
[Tue Jul 21 07:38:20.878197 2026] [security2:error] [pid 254995:tid 255211] [client 20.197.192.193:59924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/mimpi.php"] [unique_id "al9MHP7v0rlcEGmVraFCmQAAA3M"]
[Tue Jul 21 07:38:20.888325 2026] [security2:error] [pid 255769:tid 255997] [client 20.197.192.193:59933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/dp.php"] [unique_id "al9MHLxMYwyVGnfuwsKeFgAABAM"]
[Tue Jul 21 07:38:20.899641 2026] [security2:error] [pid 255769:tid 255996] [client 20.197.192.193:20744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/bootstrap.php"] [unique_id "al9MHLxMYwyVGnfuwsKeFwAABAI"]
[Tue Jul 21 07:38:20.911050 2026] [security2:error] [pid 254995:tid 255271] [client 20.197.192.193:20740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/wp-editor.php"] [unique_id "al9MHP7v0rlcEGmVraFCmwAAA5U"]
[Tue Jul 21 07:38:20.922540 2026] [security2:error] [pid 254995:tid 255183] [client 20.197.192.193:59957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/cro.php"] [unique_id "al9MHP7v0rlcEGmVraFCnAAAA1g"]
[Tue Jul 21 07:38:20.927121 2026] [proxy:error] [pid 255769:tid 255967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:20.927167 2026] [proxy_http:error] [pid 255769:tid 255967] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:20.927706 2026] [proxy:error] [pid 255769:tid 255967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:20.927730 2026] [proxy_http:error] [pid 255769:tid 255967] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:20.933035 2026] [security2:error] [pid 254995:tid 255196] [client 20.197.192.193:20826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/cron-tab.php"] [unique_id "al9MHP7v0rlcEGmVraFCnQAAA2U"]
[Tue Jul 21 07:38:20.933542 2026] [security2:error] [pid 255769:tid 255962] [client 62.102.148.187:41936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9MHLxMYwyVGnfuwsKeGgAAA-I"]
[Tue Jul 21 07:38:20.933617 2026] [security2:error] [pid 255769:tid 255962] [client 62.102.148.187:41936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9MHLxMYwyVGnfuwsKeGgAAA-I"]
[Tue Jul 21 07:38:20.942676 2026] [security2:error] [pid 254995:tid 255184] [client 20.197.192.193:59926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/koiy.php"] [unique_id "al9MHP7v0rlcEGmVraFCngAAA1k"]
[Tue Jul 21 07:38:20.953345 2026] [security2:error] [pid 255769:tid 255944] [client 20.197.192.193:59922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/hp2.php"] [unique_id "al9MHLxMYwyVGnfuwsKeGwAAA9A"]
[Tue Jul 21 07:38:20.963511 2026] [security2:error] [pid 255769:tid 255906] [client 20.197.192.193:20769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/hp3.php"] [unique_id "al9MHLxMYwyVGnfuwsKeHQAAA6o"]
[Tue Jul 21 07:38:20.974343 2026] [security2:error] [pid 255769:tid 256021] [client 20.197.192.193:59907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/aa1.php"] [unique_id "al9MHLxMYwyVGnfuwsKeHwAABBs"]
[Tue Jul 21 07:38:20.989165 2026] [security2:error] [pid 255769:tid 255956] [client 20.197.192.193:59939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/acew67.php"] [unique_id "al9MHLxMYwyVGnfuwsKeIAAAA9w"]
[Tue Jul 21 07:38:21.000750 2026] [security2:error] [pid 255769:tid 255910] [client 20.197.192.193:20737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/bscclapb.php"] [unique_id "al9MHLxMYwyVGnfuwsKeIQAAA64"]
[Tue Jul 21 07:38:21.012886 2026] [security2:error] [pid 255769:tid 255961] [client 20.197.192.193:59938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/else1.php"] [unique_id "al9MHbxMYwyVGnfuwsKeIgAAA-E"]
[Tue Jul 21 07:38:21.013390 2026] [security2:error] [pid 255769:tid 255986] [client 103.174.34.15:60990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MHbxMYwyVGnfuwsKeJAAAA_o"]
[Tue Jul 21 07:38:21.013473 2026] [security2:error] [pid 255769:tid 255986] [client 103.174.34.15:60990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MHbxMYwyVGnfuwsKeJAAAA_o"]
[Tue Jul 21 07:38:21.027430 2026] [security2:error] [pid 255769:tid 256000] [client 20.197.192.193:20764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/tkikikoko.php"] [unique_id "al9MHbxMYwyVGnfuwsKeJQAABAY"]
[Tue Jul 21 07:38:21.037712 2026] [security2:error] [pid 254995:tid 255135] [client 20.197.192.193:59956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9MHf7v0rlcEGmVraFCoQAAAyg"]
[Tue Jul 21 07:38:21.049495 2026] [security2:error] [pid 255769:tid 255935] [client 20.197.192.193:20855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/wp-css.php"] [unique_id "al9MHbxMYwyVGnfuwsKeJgAAA8c"]
[Tue Jul 21 07:38:21.061425 2026] [security2:error] [pid 254995:tid 255269] [client 20.197.192.193:59916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/wp-explorer.php"] [unique_id "al9MHf7v0rlcEGmVraFCogAAA5M"]
[Tue Jul 21 07:38:21.072975 2026] [security2:error] [pid 255769:tid 255905] [client 20.197.192.193:59934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/akismet.php"] [unique_id "al9MHbxMYwyVGnfuwsKeJwAAA6k"]
[Tue Jul 21 07:38:21.087444 2026] [security2:error] [pid 255769:tid 255981] [client 20.197.192.193:20823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/ace2.php"] [unique_id "al9MHbxMYwyVGnfuwsKeKAAAA_U"]
[Tue Jul 21 07:38:21.105860 2026] [security2:error] [pid 254995:tid 255256] [client 20.197.192.193:59941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/ms.php"] [unique_id "al9MHf7v0rlcEGmVraFCowAAA4Y"]
[Tue Jul 21 07:38:21.112436 2026] [security2:error] [pid 254995:tid 255043] [remote 104.193.142.247:46438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.142.193.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/wp-login.php"] [unique_id "al9MHf7v0rlcEGmVraFCpAADbS8"]
[Tue Jul 21 07:38:21.127260 2026] [security2:error] [pid 255769:tid 255863] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/style.php"] [unique_id "al9MHbxMYwyVGnfuwsKeKgAD-F0"], referer: http://aud-7.com/style.php
[Tue Jul 21 07:38:21.142574 2026] [autoindex:error] [pid 255769:tid 255900] [client 4.204.201.85:55493] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:21.162984 2026] [security2:error] [pid 255769:tid 255921] [client 37.140.223.117:50435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MHbxMYwyVGnfuwsKeLAAAA7k"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:38:21.322672 2026] [security2:error] [pid 254995:tid 255150] [client 178.128.207.138:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "al9MHf7v0rlcEGmVraFCqgAAAzc"]
[Tue Jul 21 07:38:21.353107 2026] [security2:error] [pid 255769:tid 255932] [client 20.226.60.151:56296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MHbxMYwyVGnfuwsKeMQAAA8Q"]
[Tue Jul 21 07:38:21.378574 2026] [proxy:error] [pid 255769:tid 255928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:21.378635 2026] [proxy_http:error] [pid 255769:tid 255928] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:21.379233 2026] [proxy:error] [pid 255769:tid 255928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:21.379260 2026] [proxy_http:error] [pid 255769:tid 255928] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:21.470827 2026] [autoindex:error] [pid 255769:tid 255989] [client 4.204.201.85:55493] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:21.493051 2026] [security2:error] [pid 255769:tid 255975] [client 147.182.149.75:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al9MHbxMYwyVGnfuwsKeNgAAA-8"]
[Tue Jul 21 07:38:21.520538 2026] [security2:error] [pid 255769:tid 255792] [remote 62.60.130.235:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bomnegociopromotora.com.br"] [uri "/wp-includes/id3/license.txt/"] [unique_id "al9MHbxMYwyVGnfuwsKeOgADsxY"]
[Tue Jul 21 07:38:21.587494 2026] [autoindex:error] [pid 255769:tid 256012] [client 20.206.105.145:38493] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:21.588471 2026] [security2:error] [pid 255769:tid 256003] [client 20.226.60.151:51280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9MHbxMYwyVGnfuwsKePgAABAk"]
[Tue Jul 21 07:38:21.597357 2026] [security2:error] [pid 255769:tid 255997] [client 20.206.105.145:38493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9MHbxMYwyVGnfuwsKeQAAABAM"]
[Tue Jul 21 07:38:21.630610 2026] [security2:error] [pid 255769:tid 255947] [client 64.226.65.160:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MHbxMYwyVGnfuwsKeQgAAA9M"]
[Tue Jul 21 07:38:21.638720 2026] [security2:error] [pid 255769:tid 255879] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/file2.php"] [unique_id "al9MHbxMYwyVGnfuwsKeQwAD520"], referer: http://aud-7.com/file2.php
[Tue Jul 21 07:38:21.644610 2026] [security2:error] [pid 255769:tid 255962] [client 4.204.201.85:55493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/crgio.php"] [unique_id "al9MHbxMYwyVGnfuwsKeRAAAA-I"]
[Tue Jul 21 07:38:21.695210 2026] [security2:error] [pid 254995:tid 255277] [client 20.226.60.151:27545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/x.php"] [unique_id "al9MHf7v0rlcEGmVraFCsAAAA5s"]
[Tue Jul 21 07:38:21.777870 2026] [security2:error] [pid 255769:tid 255849] [remote 62.60.130.235:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bomnegociopromotora.com.br"] [uri "/wp-includes/id3/license.txt/wp-json/batch/v1"] [unique_id "al9MHbxMYwyVGnfuwsKeSQADuE8"]
[Tue Jul 21 07:38:21.779549 2026] [security2:error] [pid 255769:tid 255992] [client 157.245.36.108:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "al9MHbxMYwyVGnfuwsKeSgAAA_8"]
[Tue Jul 21 07:38:21.785298 2026] [security2:error] [pid 255769:tid 256028] [client 31.14.72.5:53384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9MHbxMYwyVGnfuwsKeSwAABCI"]
[Tue Jul 21 07:38:21.840567 2026] [security2:error] [pid 255769:tid 255944] [client 74.7.244.3:44416] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "eduhenmac.com.br"] [uri "/robots.txt"] [unique_id "al9MHbxMYwyVGnfuwsKeTQAD0FM"]
[Tue Jul 21 07:38:21.844320 2026] [security2:error] [pid 255769:tid 255983] [client 103.86.117.203:56708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MHbxMYwyVGnfuwsKeTgAAA_c"]
[Tue Jul 21 07:38:21.844475 2026] [security2:error] [pid 255769:tid 255983] [client 103.86.117.203:56708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MHbxMYwyVGnfuwsKeTgAAA_c"]
[Tue Jul 21 07:38:21.915915 2026] [security2:error] [pid 254995:tid 255175] [client 165.227.173.41:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "al9MHf7v0rlcEGmVraFCtQAAA1A"]
[Tue Jul 21 07:38:21.920316 2026] [security2:error] [pid 255769:tid 255910] [client 46.101.1.225:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "al9MHbxMYwyVGnfuwsKeTwAAA64"]
[Tue Jul 21 07:38:21.926819 2026] [security2:error] [pid 255769:tid 256022] [client 59.96.220.140:62085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MHbxMYwyVGnfuwsKeUAAABBw"]
[Tue Jul 21 07:38:21.926960 2026] [security2:error] [pid 255769:tid 256022] [client 59.96.220.140:62085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MHbxMYwyVGnfuwsKeUAAABBw"]
[Tue Jul 21 07:38:22.011391 2026] [security2:error] [pid 254995:tid 255049] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MHv7v0rlcEGmVraFCtgADnTU"]
[Tue Jul 21 07:38:22.011529 2026] [security2:error] [pid 254995:tid 255279] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MHv7v0rlcEGmVraFCtgADnTU"]
[Tue Jul 21 07:38:22.022012 2026] [security2:error] [pid 254995:tid 255133] [client 64.227.70.2:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MHv7v0rlcEGmVraFCtwAAAyY"]
[Tue Jul 21 07:38:22.135867 2026] [security2:error] [pid 254995:tid 255224] [client 4.204.201.85:57152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/pucci.php"] [unique_id "al9MHv7v0rlcEGmVraFCugAAA4A"]
[Tue Jul 21 07:38:22.152702 2026] [security2:error] [pid 255769:tid 255845] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/jsonq.php"] [unique_id "al9MHrxMYwyVGnfuwsKeVAADsks"], referer: http://aud-7.com/jsonq.php
[Tue Jul 21 07:38:22.194204 2026] [security2:error] [pid 254995:tid 254999] [remote 159.65.144.72:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MHv7v0rlcEGmVraFCvgADLwM"]
[Tue Jul 21 07:38:22.268085 2026] [security2:error] [pid 254995:tid 255154] [client 20.151.10.161:45900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/155.php"] [unique_id "al9MHv7v0rlcEGmVraFCvwAAAzs"]
[Tue Jul 21 07:38:22.343152 2026] [security2:error] [pid 254995:tid 255056] [remote 159.65.144.72:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MHv7v0rlcEGmVraFCwgADeTw"]
[Tue Jul 21 07:38:22.343198 2026] [security2:error] [pid 254995:tid 255145] [client 138.68.86.32:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MHv7v0rlcEGmVraFCwwAAAzI"]
[Tue Jul 21 07:38:22.363991 2026] [security2:error] [pid 254995:tid 255168] [client 167.99.210.137:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MHv7v0rlcEGmVraFCxAAAA0k"]
[Tue Jul 21 07:38:22.364389 2026] [security2:error] [pid 254995:tid 255222] [client 139.59.143.102:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "al9MHv7v0rlcEGmVraFCxQAAA34"]
[Tue Jul 21 07:38:22.368841 2026] [security2:error] [pid 255769:tid 255917] [client 184.154.139.46:45254] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "diskvidros.com.br"] [uri "/index.php"] [unique_id "al9MHbxMYwyVGnfuwsKeMwAAA7U"]
[Tue Jul 21 07:38:22.399195 2026] [security2:error] [pid 254995:tid 255272] [client 138.68.86.32:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MHv7v0rlcEGmVraFCxgAAA5Y"]
[Tue Jul 21 07:38:22.420362 2026] [security2:error] [pid 255769:tid 256004] [client 138.68.82.23:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al9MHrxMYwyVGnfuwsKeWAAABAo"]
[Tue Jul 21 07:38:22.578477 2026] [autoindex:error] [pid 254995:tid 255191] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:22.618192 2026] [security2:error] [pid 255769:tid 255970] [client 46.101.111.185:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MHrxMYwyVGnfuwsKeXwAAA-o"]
[Tue Jul 21 07:38:22.715426 2026] [security2:error] [pid 255769:tid 255814] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/gel4y.php"] [unique_id "al9MHrxMYwyVGnfuwsKeYwAD0yw"], referer: http://aud-7.com/gel4y.php
[Tue Jul 21 07:38:22.751713 2026] [security2:error] [pid 254995:tid 255180] [client 146.190.63.248:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "al9MHv7v0rlcEGmVraFCzAAAA1U"]
[Tue Jul 21 07:38:22.775127 2026] [security2:error] [pid 255769:tid 255967] [client 165.227.173.41:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MHrxMYwyVGnfuwsKeZAAAA-c"]
[Tue Jul 21 07:38:22.824398 2026] [security2:error] [pid 254995:tid 255177] [client 20.226.60.151:27553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/155.php"] [unique_id "al9MHv7v0rlcEGmVraFCzgAAA1I"]
[Tue Jul 21 07:38:22.857403 2026] [autoindex:error] [pid 255769:tid 255960] [client 20.206.105.145:38108] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:22.878545 2026] [autoindex:error] [pid 255769:tid 255952] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:22.884450 2026] [autoindex:error] [pid 255769:tid 256021] [client 20.206.105.145:38108] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:22.890348 2026] [security2:error] [pid 255769:tid 255992] [client 20.206.105.145:38108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp.php"] [unique_id "al9MHrxMYwyVGnfuwsKeaQAAA_8"]
[Tue Jul 21 07:38:22.981453 2026] [security2:error] [pid 255769:tid 255943] [client 128.127.105.184:49584] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MHrxMYwyVGnfuwsKebgAAA88"]
[Tue Jul 21 07:38:22.981545 2026] [security2:error] [pid 255769:tid 255943] [client 128.127.105.184:49584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MHrxMYwyVGnfuwsKebgAAA88"]
[Tue Jul 21 07:38:23.018083 2026] [security2:error] [pid 255769:tid 255994] [client 4.204.201.85:55960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-temp.php"] [unique_id "al9MH7xMYwyVGnfuwsKebwAABAE"]
[Tue Jul 21 07:38:23.136969 2026] [security2:error] [pid 255769:tid 255901] [client 31.14.72.5:54037] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9MH7xMYwyVGnfuwsKecgAAA6U"]
[Tue Jul 21 07:38:23.218050 2026] [security2:error] [pid 254995:tid 255157] [client 184.154.139.46:45966] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "diskvidros.com.br"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "al9MH_7v0rlcEGmVraFC2AAAAz4"]
[Tue Jul 21 07:38:23.226690 2026] [security2:error] [pid 255769:tid 255799] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/tiny.php"] [unique_id "al9MH7xMYwyVGnfuwsKedAADyB0"], referer: http://aud-7.com/tiny.php
[Tue Jul 21 07:38:23.362734 2026] [proxy:error] [pid 255769:tid 255981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:23.362796 2026] [proxy_http:error] [pid 255769:tid 255981] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:23.363427 2026] [proxy:error] [pid 255769:tid 255981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:23.363453 2026] [proxy_http:error] [pid 255769:tid 255981] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:23.537334 2026] [security2:error] [pid 254995:tid 255013] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MH_7v0rlcEGmVraFC4AADZBE"]
[Tue Jul 21 07:38:23.537547 2026] [security2:error] [pid 254995:tid 255195] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MH_7v0rlcEGmVraFC4AADZBE"]
[Tue Jul 21 07:38:23.742379 2026] [security2:error] [pid 255769:tid 255857] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/file.php"] [unique_id "al9MH7xMYwyVGnfuwsKeeQAEClc"], referer: http://aud-7.com/file.php
[Tue Jul 21 07:38:23.772459 2026] [proxy:error] [pid 255769:tid 255907] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:23.772531 2026] [proxy_http:error] [pid 255769:tid 255907] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:23.773234 2026] [proxy:error] [pid 255769:tid 255907] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:23.773265 2026] [proxy_http:error] [pid 255769:tid 255907] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:23.841696 2026] [security2:error] [pid 254995:tid 255256] [client 20.151.10.161:45967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ppp.php"] [unique_id "al9MH_7v0rlcEGmVraFC5wAAA4Y"]
[Tue Jul 21 07:38:23.903788 2026] [security2:error] [pid 255769:tid 255975] [client 20.226.60.151:27599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ops.php"] [unique_id "al9MH7xMYwyVGnfuwsKefQAAA-8"]
[Tue Jul 21 07:38:23.930901 2026] [proxy:error] [pid 255769:tid 255979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:23.930990 2026] [proxy_http:error] [pid 255769:tid 255979] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:23.932215 2026] [proxy:error] [pid 255769:tid 255979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:23.932281 2026] [proxy_http:error] [pid 255769:tid 255979] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:23.963112 2026] [security2:error] [pid 254995:tid 255204] [client 20.226.60.151:56297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/xyn.php"] [unique_id "al9MH_7v0rlcEGmVraFC6QAAA20"]
[Tue Jul 21 07:38:24.260646 2026] [security2:error] [pid 255769:tid 255810] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/alfa.php"] [unique_id "al9MILxMYwyVGnfuwsKehgAD_ig"], referer: http://aud-7.com/alfa.php
[Tue Jul 21 07:38:24.289834 2026] [security2:error] [pid 254995:tid 255132] [client 184.154.139.46:46192] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "diskvidros.com.br"] [uri "/index.php"] [unique_id "al9MH_7v0rlcEGmVraFC6AAAAyU"]
[Tue Jul 21 07:38:24.410863 2026] [proxy:error] [pid 255769:tid 255910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:24.410924 2026] [proxy_http:error] [pid 255769:tid 255910] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:24.411352 2026] [proxy:error] [pid 255769:tid 255910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:24.411375 2026] [proxy_http:error] [pid 255769:tid 255910] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:24.499127 2026] [security2:error] [pid 254995:tid 255172] [client 31.14.72.5:54692] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9MIP7v0rlcEGmVraFC9wAAA00"]
[Tue Jul 21 07:38:24.535354 2026] [security2:error] [pid 255769:tid 255972] [client 4.204.201.85:55501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-admin/js/index.php"] [unique_id "al9MILxMYwyVGnfuwsKekQAAA-w"]
[Tue Jul 21 07:38:24.651501 2026] [security2:error] [pid 255769:tid 255956] [client 20.206.105.145:38475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/abcd.php"] [unique_id "al9MILxMYwyVGnfuwsKelQAAA9w"]
[Tue Jul 21 07:38:24.658759 2026] [security2:error] [pid 255769:tid 256013] [client 117.217.38.194:54623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MILxMYwyVGnfuwsKelwAABBM"]
[Tue Jul 21 07:38:24.658882 2026] [security2:error] [pid 255769:tid 256013] [client 117.217.38.194:54623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MILxMYwyVGnfuwsKelwAABBM"]
[Tue Jul 21 07:38:24.693906 2026] [security2:error] [pid 255769:tid 255932] [client 128.199.182.55:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "al9MILxMYwyVGnfuwsKemQAAA8Q"]
[Tue Jul 21 07:38:24.774083 2026] [security2:error] [pid 255769:tid 255807] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/403.php"] [unique_id "al9MILxMYwyVGnfuwsKemwAD_SU"], referer: http://aud-7.com/403.php
[Tue Jul 21 07:38:24.969089 2026] [security2:error] [pid 255769:tid 255953] [client 193.36.225.69:42903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MILxMYwyVGnfuwsKenQAAA9k"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:25.261039 2026] [security2:error] [pid 254995:tid 255058] [remote 41.76.214.143:51408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9MIf7v0rlcEGmVraFDDQADbD4"]
[Tue Jul 21 07:38:25.287739 2026] [security2:error] [pid 255769:tid 255782] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/m.php"] [unique_id "al9MIbxMYwyVGnfuwsKeywAEBgw"], referer: http://aud-7.com/m.php
[Tue Jul 21 07:38:25.454478 2026] [security2:error] [pid 255769:tid 255912] [client 20.226.60.151:27617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/file31.php"] [unique_id "al9MIbxMYwyVGnfuwsKe1gAAA7A"]
[Tue Jul 21 07:38:25.502144 2026] [proxy:error] [pid 255769:tid 255956] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:25.502219 2026] [proxy_http:error] [pid 255769:tid 255956] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:25.502774 2026] [proxy:error] [pid 255769:tid 255956] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:25.502807 2026] [proxy_http:error] [pid 255769:tid 255956] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:25.570379 2026] [security2:error] [pid 255769:tid 255950] [client 173.24.185.52:58984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MIbxMYwyVGnfuwsKe4QAAA9Y"]
[Tue Jul 21 07:38:25.570468 2026] [security2:error] [pid 255769:tid 255950] [client 173.24.185.52:58984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MIbxMYwyVGnfuwsKe4QAAA9Y"]
[Tue Jul 21 07:38:25.584199 2026] [security2:error] [pid 255769:tid 255964] [client 4.204.201.85:60621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/puc.php"] [unique_id "al9MIbxMYwyVGnfuwsKe4wAAA-Q"]
[Tue Jul 21 07:38:25.776758 2026] [proxy:error] [pid 255769:tid 255979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:25.776835 2026] [proxy_http:error] [pid 255769:tid 255979] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:25.777506 2026] [proxy:error] [pid 255769:tid 255979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:25.777533 2026] [proxy_http:error] [pid 255769:tid 255979] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:25.797842 2026] [security2:error] [pid 255769:tid 255887] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/a.php"] [unique_id "al9MIbxMYwyVGnfuwsKe6wADs3U"], referer: http://aud-7.com/a.php
[Tue Jul 21 07:38:25.832195 2026] [security2:error] [pid 255769:tid 256021] [client 31.14.72.5:55372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9MIbxMYwyVGnfuwsKe7QAABBs"]
[Tue Jul 21 07:38:25.935183 2026] [proxy:error] [pid 255769:tid 255981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:25.935256 2026] [proxy_http:error] [pid 255769:tid 255981] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:25.935810 2026] [proxy:error] [pid 255769:tid 255981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:25.935845 2026] [proxy_http:error] [pid 255769:tid 255981] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:26.146062 2026] [security2:error] [pid 254995:tid 255162] [client 62.102.148.187:41940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9MIv7v0rlcEGmVraFDIQAAA0M"]
[Tue Jul 21 07:38:26.146151 2026] [security2:error] [pid 254995:tid 255162] [client 62.102.148.187:41940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9MIv7v0rlcEGmVraFDIQAAA0M"]
[Tue Jul 21 07:38:26.311534 2026] [security2:error] [pid 255769:tid 255885] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/1.php"] [unique_id "al9MIrxMYwyVGnfuwsKe9QAD-3M"], referer: http://aud-7.com/1.php
[Tue Jul 21 07:38:26.406881 2026] [security2:error] [pid 254995:tid 255172] [client 20.226.60.151:27588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/file6.php"] [unique_id "al9MIv7v0rlcEGmVraFDMAAAA00"]
[Tue Jul 21 07:38:26.441300 2026] [security2:error] [pid 255769:tid 255904] [client 20.206.105.145:38517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/a1.php"] [unique_id "al9MIrxMYwyVGnfuwsKe-AAAA6g"]
[Tue Jul 21 07:38:26.446572 2026] [security2:error] [pid 254995:tid 255277] [client 20.220.225.223:38688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/byp8.php"] [unique_id "al9MIv7v0rlcEGmVraFDMQAAA5s"]
[Tue Jul 21 07:38:26.500268 2026] [proxy:error] [pid 254995:tid 255223] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:26.500335 2026] [proxy_http:error] [pid 254995:tid 255223] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:26.500921 2026] [proxy:error] [pid 254995:tid 255223] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:26.500952 2026] [proxy_http:error] [pid 254995:tid 255223] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:26.504055 2026] [proxy:error] [pid 254995:tid 255128] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:26.504100 2026] [proxy_http:error] [pid 254995:tid 255128] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:26.504525 2026] [proxy:error] [pid 254995:tid 255128] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:26.504546 2026] [proxy_http:error] [pid 254995:tid 255128] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:26.622726 2026] [security2:error] [pid 255769:tid 255957] [client 37.140.223.190:57951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MILxMYwyVGnfuwsKekAAAA90"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:38:26.692949 2026] [security2:error] [pid 255769:tid 255970] [client 117.251.86.144:34794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MIrxMYwyVGnfuwsKfAgAAA-o"]
[Tue Jul 21 07:38:26.693067 2026] [security2:error] [pid 255769:tid 255970] [client 117.251.86.144:34794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MIrxMYwyVGnfuwsKfAgAAA-o"]
[Tue Jul 21 07:38:26.700366 2026] [security2:error] [pid 254995:tid 255257] [client 20.226.60.151:27564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/adminfuns.php"] [unique_id "al9MIv7v0rlcEGmVraFDPQAAA4c"]
[Tue Jul 21 07:38:26.748414 2026] [proxy:error] [pid 255769:tid 255956] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:26.748476 2026] [proxy_http:error] [pid 255769:tid 255956] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:26.748978 2026] [proxy:error] [pid 255769:tid 255956] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:26.749000 2026] [proxy_http:error] [pid 255769:tid 255956] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:26.776712 2026] [proxy:error] [pid 254995:tid 255143] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:26.776774 2026] [proxy_http:error] [pid 254995:tid 255143] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:26.777237 2026] [proxy:error] [pid 254995:tid 255143] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:26.777263 2026] [proxy_http:error] [pid 254995:tid 255143] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:26.785599 2026] [proxy:error] [pid 254995:tid 255140] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:26.785671 2026] [proxy_http:error] [pid 254995:tid 255140] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:26.786552 2026] [proxy:error] [pid 254995:tid 255140] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:26.786603 2026] [proxy_http:error] [pid 254995:tid 255140] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:26.822464 2026] [security2:error] [pid 255769:tid 255984] [client 4.204.201.85:57201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/dx.php"] [unique_id "al9MIrxMYwyVGnfuwsKfBwAAA_g"]
[Tue Jul 21 07:38:26.825831 2026] [security2:error] [pid 255769:tid 255784] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/x.php"] [unique_id "al9MIrxMYwyVGnfuwsKfCAAD_Q4"], referer: http://aud-7.com/x.php
[Tue Jul 21 07:38:26.893370 2026] [security2:error] [pid 255769:tid 255928] [client 122.186.204.214:60176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MIrxMYwyVGnfuwsKfCgAAA8A"]
[Tue Jul 21 07:38:26.893546 2026] [security2:error] [pid 255769:tid 255928] [client 122.186.204.214:60176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MIrxMYwyVGnfuwsKfCgAAA8A"]
[Tue Jul 21 07:38:27.081604 2026] [proxy:error] [pid 254995:tid 255179] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.081681 2026] [proxy_http:error] [pid 254995:tid 255179] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.082254 2026] [proxy:error] [pid 254995:tid 255179] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.082288 2026] [proxy_http:error] [pid 254995:tid 255179] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.131247 2026] [proxy:error] [pid 255769:tid 255960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.131312 2026] [proxy_http:error] [pid 255769:tid 255960] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.131989 2026] [proxy:error] [pid 255769:tid 255960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.132024 2026] [proxy_http:error] [pid 255769:tid 255960] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.161806 2026] [proxy:error] [pid 255769:tid 255952] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.161865 2026] [proxy_http:error] [pid 255769:tid 255952] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.162371 2026] [proxy:error] [pid 255769:tid 255952] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.162403 2026] [proxy_http:error] [pid 255769:tid 255952] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.171028 2026] [security2:error] [pid 255769:tid 255966] [client 31.14.72.5:56040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9MI7xMYwyVGnfuwsKfGwAAA-Y"]
[Tue Jul 21 07:38:27.205634 2026] [security2:error] [pid 254995:tid 255278] [client 20.226.60.151:61004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9MI_7v0rlcEGmVraFDTQAAA5w"]
[Tue Jul 21 07:38:27.216387 2026] [security2:error] [pid 255769:tid 255990] [client 20.226.60.151:27575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/goods.php"] [unique_id "al9MI7xMYwyVGnfuwsKfHAAAA_4"]
[Tue Jul 21 07:38:27.329748 2026] [security2:error] [pid 255769:tid 255922] [client 20.226.60.151:27526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/100.php"] [unique_id "al9MI7xMYwyVGnfuwsKfHwAAA7o"]
[Tue Jul 21 07:38:27.335987 2026] [security2:error] [pid 255769:tid 255824] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/ws.php"] [unique_id "al9MI7xMYwyVGnfuwsKfIAAEIjY"], referer: http://aud-7.com/ws.php
[Tue Jul 21 07:38:27.373673 2026] [proxy:error] [pid 255769:tid 255904] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.373736 2026] [proxy_http:error] [pid 255769:tid 255904] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.374256 2026] [proxy:error] [pid 255769:tid 255904] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.374280 2026] [proxy_http:error] [pid 255769:tid 255904] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.378805 2026] [security2:error] [pid 254995:tid 255252] [client 20.226.60.151:56193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/patie.php"] [unique_id "al9MI_7v0rlcEGmVraFDVAAAA4M"]
[Tue Jul 21 07:38:27.387789 2026] [proxy:error] [pid 255769:tid 256010] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.387869 2026] [proxy_http:error] [pid 255769:tid 256010] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.388339 2026] [proxy:error] [pid 255769:tid 256010] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.388374 2026] [proxy_http:error] [pid 255769:tid 256010] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.511429 2026] [proxy:error] [pid 254995:tid 255195] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.511483 2026] [proxy_http:error] [pid 254995:tid 255195] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.511906 2026] [proxy:error] [pid 254995:tid 255195] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.511927 2026] [proxy_http:error] [pid 254995:tid 255195] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.543326 2026] [proxy:error] [pid 254995:tid 255184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.543396 2026] [proxy_http:error] [pid 254995:tid 255184] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.543957 2026] [proxy:error] [pid 254995:tid 255184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.543987 2026] [proxy_http:error] [pid 254995:tid 255184] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.643035 2026] [security2:error] [pid 255769:tid 255826] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MI7xMYwyVGnfuwsKfNwADzzg"]
[Tue Jul 21 07:38:27.643158 2026] [security2:error] [pid 255769:tid 255943] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MI7xMYwyVGnfuwsKfNwADzzg"]
[Tue Jul 21 07:38:27.664418 2026] [proxy:error] [pid 255769:tid 255981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.664492 2026] [proxy_http:error] [pid 255769:tid 255981] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.664933 2026] [proxy:error] [pid 255769:tid 255981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.664958 2026] [proxy_http:error] [pid 255769:tid 255981] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.681031 2026] [autoindex:error] [pid 255769:tid 255962] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:27.742401 2026] [proxy:error] [pid 254995:tid 255273] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.742470 2026] [proxy_http:error] [pid 254995:tid 255273] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.743114 2026] [proxy:error] [pid 254995:tid 255273] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.743152 2026] [proxy_http:error] [pid 254995:tid 255273] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.795786 2026] [security2:error] [pid 254995:tid 255223] [client 20.226.60.151:27583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/about.php"] [unique_id "al9MI_7v0rlcEGmVraFDbgAAA38"]
[Tue Jul 21 07:38:27.896269 2026] [proxy:error] [pid 255769:tid 255925] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.896357 2026] [proxy_http:error] [pid 255769:tid 255925] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.897375 2026] [proxy:error] [pid 255769:tid 255925] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.897427 2026] [proxy_http:error] [pid 255769:tid 255925] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.939546 2026] [proxy:error] [pid 255769:tid 255944] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.939595 2026] [proxy_http:error] [pid 255769:tid 255944] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.940101 2026] [proxy:error] [pid 255769:tid 255944] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.940127 2026] [proxy_http:error] [pid 255769:tid 255944] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.953438 2026] [proxy:error] [pid 255769:tid 256028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.953489 2026] [proxy_http:error] [pid 255769:tid 256028] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.953954 2026] [proxy:error] [pid 255769:tid 256028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.953990 2026] [proxy_http:error] [pid 255769:tid 256028] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.009768 2026] [security2:error] [pid 255769:tid 255836] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp.php"] [unique_id "al9MJLxMYwyVGnfuwsKfUgAEAUI"], referer: http://aud-7.com/wp.php
[Tue Jul 21 07:38:28.035684 2026] [security2:error] [pid 255769:tid 255923] [client 20.151.10.161:45982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/201.php"] [unique_id "al9MJLxMYwyVGnfuwsKfVAAAA7s"]
[Tue Jul 21 07:38:28.084997 2026] [security2:error] [pid 255769:tid 255959] [client 4.204.201.85:55530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/bthil.php"] [unique_id "al9MJLxMYwyVGnfuwsKfVQAAA98"]
[Tue Jul 21 07:38:28.096634 2026] [proxy:error] [pid 255769:tid 255921] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.096697 2026] [proxy_http:error] [pid 255769:tid 255921] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.097368 2026] [proxy:error] [pid 255769:tid 255921] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.097397 2026] [proxy_http:error] [pid 255769:tid 255921] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.135901 2026] [security2:error] [pid 255769:tid 255997] [client 20.206.105.145:38096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9MJLxMYwyVGnfuwsKfWAAABAM"]
[Tue Jul 21 07:38:28.207362 2026] [security2:error] [pid 255769:tid 255910] [client 20.226.60.151:27620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/about.php"] [unique_id "al9MJLxMYwyVGnfuwsKfWwAAA64"]
[Tue Jul 21 07:38:28.280355 2026] [proxy:error] [pid 255769:tid 255913] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.280409 2026] [proxy_http:error] [pid 255769:tid 255913] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.280898 2026] [proxy:error] [pid 255769:tid 255913] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.280926 2026] [proxy_http:error] [pid 255769:tid 255913] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.332738 2026] [security2:error] [pid 255769:tid 255848] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJLxMYwyVGnfuwsKfZgAD4U4"]
[Tue Jul 21 07:38:28.332879 2026] [security2:error] [pid 255769:tid 255961] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJLxMYwyVGnfuwsKfZgAD4U4"]
[Tue Jul 21 07:38:28.387692 2026] [proxy:error] [pid 255769:tid 255916] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.387760 2026] [proxy_http:error] [pid 255769:tid 255916] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.388260 2026] [proxy:error] [pid 255769:tid 255916] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.388292 2026] [proxy_http:error] [pid 255769:tid 255916] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.459477 2026] [proxy:error] [pid 255769:tid 255967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.459541 2026] [proxy_http:error] [pid 255769:tid 255967] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.460239 2026] [proxy:error] [pid 255769:tid 255967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.460264 2026] [proxy_http:error] [pid 255769:tid 255967] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.514311 2026] [security2:error] [pid 254995:tid 255224] [client 31.14.72.5:56788] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9MJP7v0rlcEGmVraFDhwAAA4A"]
[Tue Jul 21 07:38:28.526541 2026] [security2:error] [pid 255769:tid 255880] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/modules/scrollbottom/anamama-2.php"] [unique_id "al9MJLxMYwyVGnfuwsKfcAAEGG4"], referer: http://aud-7.com/modules/scrollbottom/anamama-2.php
[Tue Jul 21 07:38:28.571745 2026] [security2:error] [pid 255769:tid 255990] [client 20.226.60.151:27568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/admin.php"] [unique_id "al9MJLxMYwyVGnfuwsKfcgAAA_4"]
[Tue Jul 21 07:38:28.637709 2026] [security2:error] [pid 255769:tid 255974] [client 193.36.225.58:23787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MJLxMYwyVGnfuwsKfdAAAA-4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:28.638343 2026] [security2:error] [pid 255769:tid 255992] [client 20.226.60.151:27347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/admin.php"] [unique_id "al9MJLxMYwyVGnfuwsKfdQAAA_8"]
[Tue Jul 21 07:38:28.671966 2026] [proxy:error] [pid 255769:tid 256017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.672041 2026] [proxy_http:error] [pid 255769:tid 256017] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.672514 2026] [proxy:error] [pid 255769:tid 256017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.672543 2026] [proxy_http:error] [pid 255769:tid 256017] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.684821 2026] [security2:error] [pid 255769:tid 255944] [client 4.204.201.85:61218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/7.php"] [unique_id "al9MJLxMYwyVGnfuwsKfeAAAA9A"]
[Tue Jul 21 07:38:28.824287 2026] [proxy:error] [pid 255769:tid 255947] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.824362 2026] [proxy_http:error] [pid 255769:tid 255947] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.825090 2026] [proxy:error] [pid 255769:tid 255947] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.825131 2026] [proxy_http:error] [pid 255769:tid 255947] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.836645 2026] [security2:error] [pid 255769:tid 255863] [remote 192.249.127.213:45386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.127.249.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "woma.com.br"] [uri "/wp-login.php"] [unique_id "al9MJLxMYwyVGnfuwsKffwAD810"]
[Tue Jul 21 07:38:28.841171 2026] [proxy:error] [pid 254995:tid 255190] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.841232 2026] [proxy_http:error] [pid 254995:tid 255190] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.841855 2026] [proxy:error] [pid 254995:tid 255190] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.841891 2026] [proxy_http:error] [pid 254995:tid 255190] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.917692 2026] [security2:error] [pid 254995:tid 255176] [client 139.167.225.182:50433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJP7v0rlcEGmVraFDmAAAA1E"]
[Tue Jul 21 07:38:28.917837 2026] [security2:error] [pid 254995:tid 255176] [client 139.167.225.182:50433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJP7v0rlcEGmVraFDmAAAA1E"]
[Tue Jul 21 07:38:28.929740 2026] [security2:error] [pid 254995:tid 255209] [client 20.226.60.151:27365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/themes.php"] [unique_id "al9MJP7v0rlcEGmVraFDmQAAA3E"]
[Tue Jul 21 07:38:28.957603 2026] [proxy:error] [pid 254995:tid 255268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.957671 2026] [proxy_http:error] [pid 254995:tid 255268] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.958325 2026] [proxy:error] [pid 254995:tid 255268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.958361 2026] [proxy_http:error] [pid 254995:tid 255268] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:29.041718 2026] [security2:error] [pid 255769:tid 255895] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "al9MJbxMYwyVGnfuwsKfggAD3X0"], referer: http://aud-7.com/modules/ets_whatsapp/security.php
[Tue Jul 21 07:38:29.075715 2026] [security2:error] [pid 254995:tid 255184] [client 20.226.60.151:27581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/.well-known/about.php"] [unique_id "al9MJf7v0rlcEGmVraFDoQAAA1k"]
[Tue Jul 21 07:38:29.136800 2026] [security2:error] [pid 255769:tid 255960] [client 175.45.70.82:65523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJbxMYwyVGnfuwsKfhAAAA-A"]
[Tue Jul 21 07:38:29.136907 2026] [security2:error] [pid 255769:tid 255960] [client 175.45.70.82:65523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJbxMYwyVGnfuwsKfhAAAA-A"]
[Tue Jul 21 07:38:29.148212 2026] [security2:error] [pid 255769:tid 255918] [client 154.192.233.199:59306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJbxMYwyVGnfuwsKfhQAAA7Y"]
[Tue Jul 21 07:38:29.148319 2026] [security2:error] [pid 255769:tid 255918] [client 154.192.233.199:59306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJbxMYwyVGnfuwsKfhQAAA7Y"]
[Tue Jul 21 07:38:29.186570 2026] [proxy:error] [pid 254995:tid 255201] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:29.186629 2026] [proxy_http:error] [pid 254995:tid 255201] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:29.187175 2026] [proxy:error] [pid 254995:tid 255201] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:29.187202 2026] [proxy_http:error] [pid 254995:tid 255201] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:29.233052 2026] [ssl:error] [pid 255769:tid 255936] [client 2.192.64.45:46454] AH02032: Hostname www.quietum-plus.tryhealth.shop provided via SNI and hostname www.bbcgoodfood.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue Jul 21 07:38:29.251972 2026] [security2:error] [pid 254995:tid 255169] [client 4.204.201.85:57142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/8.php"] [unique_id "al9MJf7v0rlcEGmVraFDqQAAA0o"]
[Tue Jul 21 07:38:29.290494 2026] [security2:error] [pid 254995:tid 255274] [client 20.226.60.151:27537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9MJf7v0rlcEGmVraFDqgAAA5g"]
[Tue Jul 21 07:38:29.507445 2026] [security2:error] [pid 255769:tid 255902] [client 20.226.60.151:27591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wefile.php"] [unique_id "al9MJbxMYwyVGnfuwsKfkAAAA6Y"]
[Tue Jul 21 07:38:29.516617 2026] [security2:error] [pid 255769:tid 255986] [client 122.164.127.47:57492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MJbxMYwyVGnfuwsKfkgAAA_o"]
[Tue Jul 21 07:38:29.516734 2026] [security2:error] [pid 255769:tid 255986] [client 122.164.127.47:57492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MJbxMYwyVGnfuwsKfkgAAA_o"]
[Tue Jul 21 07:38:29.543553 2026] [security2:error] [pid 254995:tid 255202] [client 122.162.144.145:23167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MJf7v0rlcEGmVraFDswAAA2s"]
[Tue Jul 21 07:38:29.543685 2026] [security2:error] [pid 254995:tid 255202] [client 122.162.144.145:23167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MJf7v0rlcEGmVraFDswAAA2s"]
[Tue Jul 21 07:38:29.555848 2026] [security2:error] [pid 255769:tid 255879] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/templates/cassiopeia/error.php"] [unique_id "al9MJbxMYwyVGnfuwsKfkwAD4W0"], referer: http://aud-7.com/templates/cassiopeia/error.php
[Tue Jul 21 07:38:29.560608 2026] [security2:error] [pid 254995:tid 255223] [client 20.226.60.151:27584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9MJf7v0rlcEGmVraFDtwAAA38"]
[Tue Jul 21 07:38:29.661455 2026] [security2:error] [pid 255769:tid 255916] [client 4.204.201.85:55525] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "qcharge.tryhealth.shop"] [uri "/1.php"] [unique_id "al9MJbxMYwyVGnfuwsKflwAAA7Q"]
[Tue Jul 21 07:38:29.661556 2026] [security2:error] [pid 255769:tid 255916] [client 4.204.201.85:55525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/1.php"] [unique_id "al9MJbxMYwyVGnfuwsKflwAAA7Q"]
[Tue Jul 21 07:38:29.664348 2026] [proxy:error] [pid 255769:tid 255962] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:29.664415 2026] [proxy_http:error] [pid 255769:tid 255962] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:29.665503 2026] [proxy:error] [pid 255769:tid 255962] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:29.665552 2026] [proxy_http:error] [pid 255769:tid 255962] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:29.674786 2026] [security2:error] [pid 254995:tid 255129] [client 37.140.223.117:64573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MJf7v0rlcEGmVraFDuQAAAyI"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:38:29.753854 2026] [security2:error] [pid 254995:tid 255269] [client 103.106.20.201:54933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJf7v0rlcEGmVraFDwAAAA5M"]
[Tue Jul 21 07:38:29.753978 2026] [security2:error] [pid 254995:tid 255269] [client 103.106.20.201:54933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJf7v0rlcEGmVraFDwAAAA5M"]
[Tue Jul 21 07:38:29.763704 2026] [security2:error] [pid 254995:tid 255143] [client 20.226.60.151:27525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9MJf7v0rlcEGmVraFDwgAAAzA"]
[Tue Jul 21 07:38:29.787248 2026] [security2:error] [pid 254995:tid 255087] [remote 124.55.178.99:45726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tempex.com.br"] [uri "/wp-login.php"] [unique_id "al9MJf7v0rlcEGmVraFDwwADZ1s"]
[Tue Jul 21 07:38:29.795190 2026] [proxy:error] [pid 254995:tid 255222] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:29.795237 2026] [proxy_http:error] [pid 254995:tid 255222] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:29.795713 2026] [proxy:error] [pid 254995:tid 255222] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:29.795736 2026] [proxy_http:error] [pid 254995:tid 255222] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:29.944367 2026] [security2:error] [pid 255769:tid 255971] [client 20.151.10.161:45976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ops.php"] [unique_id "al9MJbxMYwyVGnfuwsKfnAAAA-s"]
[Tue Jul 21 07:38:30.071144 2026] [security2:error] [pid 255769:tid 255849] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/templates/ja_purity/index.php"] [unique_id "al9MJrxMYwyVGnfuwsKfnwAD3k8"], referer: http://aud-7.com/templates/ja_purity/index.php
[Tue Jul 21 07:38:30.087098 2026] [security2:error] [pid 255769:tid 255946] [client 20.226.60.151:27616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/8.php"] [unique_id "al9MJrxMYwyVGnfuwsKfowAAA9I"]
[Tue Jul 21 07:38:30.139646 2026] [security2:error] [pid 255769:tid 255906] [client 20.197.192.193:42194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MJrxMYwyVGnfuwsKfpAAAA6o"]
[Tue Jul 21 07:38:30.146000 2026] [security2:error] [pid 254995:tid 255146] [client 4.204.201.85:61263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/100.php"] [unique_id "al9MJv7v0rlcEGmVraFD1wAAAzM"]
[Tue Jul 21 07:38:30.181751 2026] [security2:error] [pid 254995:tid 255224] [client 20.197.192.193:42230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MJv7v0rlcEGmVraFD2QAAA4A"]
[Tue Jul 21 07:38:30.208197 2026] [proxy:error] [pid 254995:tid 255144] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:30.208255 2026] [proxy_http:error] [pid 254995:tid 255144] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:30.208727 2026] [proxy:error] [pid 254995:tid 255144] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:30.208749 2026] [proxy_http:error] [pid 254995:tid 255144] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:30.245308 2026] [security2:error] [pid 255769:tid 255951] [client 20.197.192.193:41570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/dp.php"] [unique_id "al9MJrxMYwyVGnfuwsKfqAAAA9c"]
[Tue Jul 21 07:38:30.321260 2026] [security2:error] [pid 255769:tid 255921] [client 20.197.192.193:41583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/old.php"] [unique_id "al9MJrxMYwyVGnfuwsKfrgAAA7k"]
[Tue Jul 21 07:38:30.399556 2026] [security2:error] [pid 255769:tid 255936] [client 20.197.192.193:41565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/ms-new.php"] [unique_id "al9MJrxMYwyVGnfuwsKfsAAAA8g"]
[Tue Jul 21 07:38:30.432761 2026] [security2:error] [pid 255769:tid 255964] [client 20.197.192.193:48899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/track.php"] [unique_id "al9MJrxMYwyVGnfuwsKftAAAA-Q"]
[Tue Jul 21 07:38:30.452155 2026] [security2:error] [pid 255769:tid 256005] [client 20.197.192.193:60458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/2352356666.php"] [unique_id "al9MJrxMYwyVGnfuwsKftgAABAs"]
[Tue Jul 21 07:38:30.473634 2026] [security2:error] [pid 255769:tid 256021] [client 20.197.192.193:42186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/pn.php"] [unique_id "al9MJrxMYwyVGnfuwsKfugAABBs"]
[Tue Jul 21 07:38:30.480248 2026] [security2:error] [pid 255769:tid 255932] [client 4.204.201.85:55945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/about.php"] [unique_id "al9MJrxMYwyVGnfuwsKfuwAAA8Q"]
[Tue Jul 21 07:38:30.500802 2026] [security2:error] [pid 255769:tid 255901] [client 20.197.192.193:41560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9MJrxMYwyVGnfuwsKfvQAAA6U"]
[Tue Jul 21 07:38:30.519787 2026] [security2:error] [pid 255769:tid 255870] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MJrxMYwyVGnfuwsKfwAADo2Q"]
[Tue Jul 21 07:38:30.519918 2026] [security2:error] [pid 255769:tid 255899] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MJrxMYwyVGnfuwsKfwAADo2Q"]
[Tue Jul 21 07:38:30.534296 2026] [security2:error] [pid 255769:tid 255916] [client 20.197.192.193:42192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/dr.php"] [unique_id "al9MJrxMYwyVGnfuwsKfwQAAA7Q"]
[Tue Jul 21 07:38:30.546268 2026] [security2:error] [pid 255769:tid 255871] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MJrxMYwyVGnfuwsKfwgADs2U"]
[Tue Jul 21 07:38:30.546411 2026] [security2:error] [pid 255769:tid 255915] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MJrxMYwyVGnfuwsKfwgADs2U"]
[Tue Jul 21 07:38:30.553609 2026] [security2:error] [pid 255769:tid 255996] [client 138.197.191.87:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.191.197.138.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MJrxMYwyVGnfuwsKfwwAABAI"]
[Tue Jul 21 07:38:30.561837 2026] [security2:error] [pid 254995:tid 255268] [client 20.197.192.193:42219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/2x.php"] [unique_id "al9MJv7v0rlcEGmVraFD_AAAA5I"]
[Tue Jul 21 07:38:30.571829 2026] [security2:error] [pid 255769:tid 255917] [client 162.241.63.68:33560] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "liranesuliano.com.br"] [uri "/index.php"] [unique_id "al9MJrxMYwyVGnfuwsKfvAAAA7U"], referer: http://liranesuliano.com.br/wp-cron.php?doing_wp_cron=1784630310.2090170383453369140625
[Tue Jul 21 07:38:30.588914 2026] [security2:error] [pid 255769:tid 255796] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/templates/protostar/error.php"] [unique_id "al9MJrxMYwyVGnfuwsKfxQAD5xo"], referer: http://aud-7.com/templates/protostar/error.php
[Tue Jul 21 07:38:30.634104 2026] [security2:error] [pid 255769:tid 255950] [client 20.226.60.151:27361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MJrxMYwyVGnfuwsKfyAAAA9Y"]
[Tue Jul 21 07:38:30.644966 2026] [security2:error] [pid 254995:tid 255196] [client 20.197.192.193:41594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/kq1.php"] [unique_id "al9MJv7v0rlcEGmVraFD_gAAA2U"]
[Tue Jul 21 07:38:30.669460 2026] [security2:error] [pid 255769:tid 256012] [client 20.197.192.193:42190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/zzz.php"] [unique_id "al9MJrxMYwyVGnfuwsKfywAABBI"]
[Tue Jul 21 07:38:30.694248 2026] [security2:error] [pid 255769:tid 255983] [client 20.197.192.193:41563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/wicked.php"] [unique_id "al9MJrxMYwyVGnfuwsKfzAAAA_c"]
[Tue Jul 21 07:38:30.712758 2026] [security2:error] [pid 255769:tid 256022] [client 20.197.192.193:41547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/edit.php"] [unique_id "al9MJrxMYwyVGnfuwsKfzQAABBw"]
[Tue Jul 21 07:38:30.732251 2026] [security2:error] [pid 255769:tid 255947] [client 20.197.192.193:42231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/kua.php"] [unique_id "al9MJrxMYwyVGnfuwsKfzgAAA9M"]
[Tue Jul 21 07:38:30.777630 2026] [security2:error] [pid 255769:tid 255994] [client 20.197.192.193:42225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/ez.php"] [unique_id "al9MJrxMYwyVGnfuwsKfzwAABAE"]
[Tue Jul 21 07:38:30.794236 2026] [security2:error] [pid 255769:tid 255968] [client 162.241.63.68:33560] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "liranesuliano.com.br"] [uri "/index.php"] [unique_id "al9MJrxMYwyVGnfuwsKfxAAAA-g"], referer: http://liranesuliano.com.br/wp-cron.php?doing_wp_cron=1784630310.2090170383453369140625
[Tue Jul 21 07:38:30.830516 2026] [security2:error] [pid 255769:tid 256028] [client 20.197.192.193:41592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/fz.php"] [unique_id "al9MJrxMYwyVGnfuwsKf0QAABCI"]
[Tue Jul 21 07:38:30.864309 2026] [security2:error] [pid 255769:tid 255918] [client 20.197.192.193:42209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/la.php"] [unique_id "al9MJrxMYwyVGnfuwsKf0gAAA7Y"]
[Tue Jul 21 07:38:30.899050 2026] [security2:error] [pid 255769:tid 256017] [client 20.197.192.193:41545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9MJrxMYwyVGnfuwsKf0wAABBc"]
[Tue Jul 21 07:38:30.903683 2026] [security2:error] [pid 255769:tid 256025] [client 4.204.201.85:55528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/admin.php"] [unique_id "al9MJrxMYwyVGnfuwsKf1AAABB8"]
[Tue Jul 21 07:38:30.921915 2026] [security2:error] [pid 255769:tid 255936] [client 20.197.192.193:48949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/inso.php"] [unique_id "al9MJrxMYwyVGnfuwsKf1QAAA8g"]
[Tue Jul 21 07:38:30.935196 2026] [security2:error] [pid 255769:tid 255940] [client 20.197.192.193:42188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/wpx.php"] [unique_id "al9MJrxMYwyVGnfuwsKf1gAAA8w"]
[Tue Jul 21 07:38:30.950797 2026] [security2:error] [pid 255769:tid 255957] [client 20.197.192.193:41541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/berlin.php"] [unique_id "al9MJrxMYwyVGnfuwsKf1wAAA90"]
[Tue Jul 21 07:38:30.956524 2026] [proxy:error] [pid 255769:tid 255964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:30.956571 2026] [proxy_http:error] [pid 255769:tid 255964] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:30.957028 2026] [proxy:error] [pid 255769:tid 255964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:30.957048 2026] [proxy_http:error] [pid 255769:tid 255964] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:30.964556 2026] [security2:error] [pid 255769:tid 255984] [client 20.197.192.193:41597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/billur.php"] [unique_id "al9MJrxMYwyVGnfuwsKf2gAAA_g"]
[Tue Jul 21 07:38:30.980894 2026] [security2:error] [pid 255769:tid 256021] [client 20.197.192.193:42177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/mimpi.php"] [unique_id "al9MJrxMYwyVGnfuwsKf3AAABBs"]
[Tue Jul 21 07:38:30.990054 2026] [security2:error] [pid 255769:tid 255907] [client 20.206.105.145:38498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9MJrxMYwyVGnfuwsKf3gAAA6s"]
[Tue Jul 21 07:38:30.993342 2026] [security2:error] [pid 254995:tid 255135] [client 178.128.207.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.207.128.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MJv7v0rlcEGmVraFEEAAAAyg"]
[Tue Jul 21 07:38:31.005542 2026] [security2:error] [pid 255769:tid 255961] [client 20.197.192.193:41556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/dp.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf3wAAA-E"]
[Tue Jul 21 07:38:31.049838 2026] [security2:error] [pid 254995:tid 255156] [client 20.197.192.193:42224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/bootstrap.php"] [unique_id "al9MJ_7v0rlcEGmVraFEFAAAAz0"]
[Tue Jul 21 07:38:31.101213 2026] [security2:error] [pid 254995:tid 255169] [client 20.197.192.193:41543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/wp-editor.php"] [unique_id "al9MJ_7v0rlcEGmVraFEFwAAA0o"]
[Tue Jul 21 07:38:31.105635 2026] [security2:error] [pid 255769:tid 255781] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/templates/beez3/jsstrings.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf4gADtAs"], referer: http://aud-7.com/templates/beez3/jsstrings.php
[Tue Jul 21 07:38:31.115661 2026] [security2:error] [pid 255769:tid 255962] [client 20.197.192.193:41595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/cro.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf4wAAA-I"]
[Tue Jul 21 07:38:31.133404 2026] [security2:error] [pid 255769:tid 255923] [client 20.197.192.193:42226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/cron-tab.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf5AAAA7s"]
[Tue Jul 21 07:38:31.189400 2026] [security2:error] [pid 255769:tid 255950] [client 20.197.192.193:42195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/koiy.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf6QAAA9Y"]
[Tue Jul 21 07:38:31.247228 2026] [security2:error] [pid 254995:tid 255177] [client 147.182.149.75:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.149.182.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MJ_7v0rlcEGmVraFEGwAAA1I"]
[Tue Jul 21 07:38:31.332945 2026] [security2:error] [pid 254995:tid 255150] [client 20.197.192.193:42199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/hp2.php"] [unique_id "al9MJ_7v0rlcEGmVraFEHgAAAzc"]
[Tue Jul 21 07:38:31.365061 2026] [security2:error] [pid 255769:tid 256012] [client 20.197.192.193:42179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/hp3.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf7AAABBI"]
[Tue Jul 21 07:38:31.415315 2026] [security2:error] [pid 254995:tid 255197] [client 4.204.201.85:57104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/edit.php"] [unique_id "al9MJ_7v0rlcEGmVraFEIwAAA2Y"]
[Tue Jul 21 07:38:31.419970 2026] [security2:error] [pid 254995:tid 255223] [client 20.197.192.193:41546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/aa1.php"] [unique_id "al9MJ_7v0rlcEGmVraFEJAAAA38"]
[Tue Jul 21 07:38:31.469268 2026] [security2:error] [pid 254995:tid 255128] [client 20.197.192.193:41555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/acew67.php"] [unique_id "al9MJ_7v0rlcEGmVraFEJQAAAyE"]
[Tue Jul 21 07:38:31.493056 2026] [security2:error] [pid 254995:tid 255151] [client 20.197.192.193:48897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/bscclapb.php"] [unique_id "al9MJ_7v0rlcEGmVraFEJgAAAzg"]
[Tue Jul 21 07:38:31.504606 2026] [security2:error] [pid 255769:tid 255944] [client 64.226.65.160:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.65.226.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf7QAAA9A"]
[Tue Jul 21 07:38:31.524483 2026] [security2:error] [pid 254995:tid 255163] [client 20.197.192.193:41539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/else1.php"] [unique_id "al9MJ_7v0rlcEGmVraFEKQAAA0Q"]
[Tue Jul 21 07:38:31.541735 2026] [security2:error] [pid 255769:tid 255992] [client 20.197.192.193:42239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/tkikikoko.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf7wAAA_8"]
[Tue Jul 21 07:38:31.592102 2026] [security2:error] [pid 255769:tid 255951] [client 20.197.192.193:42222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf8QAAA9c"]
[Tue Jul 21 07:38:31.620492 2026] [security2:error] [pid 255769:tid 255817] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/templates/atomic/index.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf8wAEGC8"], referer: http://aud-7.com/templates/atomic/index.php
[Tue Jul 21 07:38:31.631211 2026] [security2:error] [pid 255769:tid 255910] [client 20.197.192.193:48932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/wp-css.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf9AAAA64"]
[Tue Jul 21 07:38:31.644856 2026] [security2:error] [pid 255769:tid 255959] [client 20.197.192.193:42228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/wp-explorer.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf9QAAA98"]
[Tue Jul 21 07:38:31.662316 2026] [proxy:error] [pid 255769:tid 256028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:31.662384 2026] [proxy_http:error] [pid 255769:tid 256028] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:31.663020 2026] [proxy:error] [pid 255769:tid 256028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:31.663048 2026] [proxy_http:error] [pid 255769:tid 256028] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:31.663173 2026] [security2:error] [pid 254995:tid 255143] [client 20.197.192.193:48941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/akismet.php"] [unique_id "al9MJ_7v0rlcEGmVraFELAAAAzA"]
[Tue Jul 21 07:38:31.675051 2026] [security2:error] [pid 255769:tid 255918] [client 20.197.192.193:42234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/ace2.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf-QAAA7Y"]
[Tue Jul 21 07:38:31.676927 2026] [security2:error] [pid 255769:tid 255960] [client 165.227.173.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.173.227.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf-AAAA-A"]
[Tue Jul 21 07:38:31.690822 2026] [security2:error] [pid 255769:tid 255999] [client 20.197.192.193:41554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/ms.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf-gAABAU"]
[Tue Jul 21 07:38:31.741000 2026] [security2:error] [pid 254995:tid 255140] [client 4.204.201.85:61227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-content/admin.php"] [unique_id "al9MJ_7v0rlcEGmVraFELgAAAy0"]
[Tue Jul 21 07:38:31.806708 2026] [proxy:error] [pid 255769:tid 256019] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:31.806770 2026] [proxy_http:error] [pid 255769:tid 256019] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:31.807296 2026] [proxy:error] [pid 255769:tid 256019] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:31.807322 2026] [proxy_http:error] [pid 255769:tid 256019] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:31.927898 2026] [security2:error] [pid 255769:tid 255941] [client 103.174.34.15:61480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJ7xMYwyVGnfuwsKgEAAAA80"]
[Tue Jul 21 07:38:31.928027 2026] [security2:error] [pid 255769:tid 255941] [client 103.174.34.15:61480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJ7xMYwyVGnfuwsKgEAAAA80"]
[Tue Jul 21 07:38:31.938733 2026] [security2:error] [pid 255769:tid 255984] [client 139.59.143.102:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.143.59.139.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MJ7xMYwyVGnfuwsKgAwAAA_g"]
[Tue Jul 21 07:38:31.968700 2026] [security2:error] [pid 255769:tid 255902] [client 20.206.105.145:38099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/gettest.php"] [unique_id "al9MJ7xMYwyVGnfuwsKgEgAAA6Y"]
[Tue Jul 21 07:38:32.046257 2026] [security2:error] [pid 255769:tid 255949] [client 46.101.1.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.1.101.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKLxMYwyVGnfuwsKgFgAAA9U"]
[Tue Jul 21 07:38:32.114468 2026] [security2:error] [pid 255769:tid 256008] [client 20.226.60.151:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/jj.php"] [unique_id "al9MKLxMYwyVGnfuwsKgGwAABA4"]
[Tue Jul 21 07:38:32.132440 2026] [security2:error] [pid 255769:tid 255786] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/templates/beez3/error.php"] [unique_id "al9MKLxMYwyVGnfuwsKgIgAD5hA"], referer: http://aud-7.com/templates/beez3/error.php
[Tue Jul 21 07:38:32.180621 2026] [proxy:error] [pid 255769:tid 255928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:32.180683 2026] [proxy_http:error] [pid 255769:tid 255928] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:32.181294 2026] [proxy:error] [pid 255769:tid 255928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:32.181325 2026] [proxy_http:error] [pid 255769:tid 255928] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:32.187235 2026] [security2:error] [pid 255769:tid 256012] [client 20.226.60.151:27520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/f6.php"] [unique_id "al9MKLxMYwyVGnfuwsKgNQAABBI"]
[Tue Jul 21 07:38:32.198018 2026] [security2:error] [pid 255769:tid 255917] [client 157.245.36.108:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.36.245.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKLxMYwyVGnfuwsKgNgAAA7U"]
[Tue Jul 21 07:38:32.251607 2026] [proxy:error] [pid 255769:tid 255925] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:32.251674 2026] [proxy_http:error] [pid 255769:tid 255925] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:32.252152 2026] [proxy:error] [pid 255769:tid 255925] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:32.252182 2026] [proxy_http:error] [pid 255769:tid 255925] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:32.253541 2026] [security2:error] [pid 254995:tid 255153] [client 4.204.201.85:55961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/ss.php"] [unique_id "al9MKP7v0rlcEGmVraFENQAAAzo"]
[Tue Jul 21 07:38:32.310803 2026] [security2:error] [pid 255769:tid 256018] [client 167.99.210.137:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.210.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKLxMYwyVGnfuwsKgOgAABBg"]
[Tue Jul 21 07:38:32.329144 2026] [security2:error] [pid 255769:tid 255914] [client 103.86.117.203:57234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MKLxMYwyVGnfuwsKgOwAAA7I"]
[Tue Jul 21 07:38:32.329231 2026] [security2:error] [pid 255769:tid 255914] [client 103.86.117.203:57234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MKLxMYwyVGnfuwsKgOwAAA7I"]
[Tue Jul 21 07:38:32.398757 2026] [security2:error] [pid 254995:tid 255172] [client 165.227.39.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.39.227.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MJ_7v0rlcEGmVraFEIgAAA00"]
[Tue Jul 21 07:38:32.498541 2026] [security2:error] [pid 254995:tid 255165] [client 165.227.173.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.173.227.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKP7v0rlcEGmVraFEPQAAA0Y"]
[Tue Jul 21 07:38:32.511207 2026] [security2:error] [pid 254995:tid 255189] [client 59.96.220.140:62568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MKP7v0rlcEGmVraFEPgAAA14"]
[Tue Jul 21 07:38:32.511323 2026] [security2:error] [pid 254995:tid 255189] [client 59.96.220.140:62568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MKP7v0rlcEGmVraFEPgAAA14"]
[Tue Jul 21 07:38:32.534486 2026] [security2:error] [pid 255769:tid 255939] [client 138.68.82.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.82.68.138.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKLxMYwyVGnfuwsKgRAAAA8s"]
[Tue Jul 21 07:38:32.574636 2026] [security2:error] [pid 255769:tid 255975] [client 4.204.201.85:55491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/inputs.php"] [unique_id "al9MKLxMYwyVGnfuwsKgRgAAA-8"]
[Tue Jul 21 07:38:32.646409 2026] [security2:error] [pid 255769:tid 255816] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/templates/beez3/index.php"] [unique_id "al9MKLxMYwyVGnfuwsKgSAADpS4"], referer: http://aud-7.com/templates/beez3/index.php
[Tue Jul 21 07:38:32.655583 2026] [security2:error] [pid 255769:tid 255981] [client 20.226.60.151:27594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/inputs.php"] [unique_id "al9MKLxMYwyVGnfuwsKgSQAAA_U"]
[Tue Jul 21 07:38:32.674389 2026] [security2:error] [pid 255769:tid 255916] [client 146.190.63.248:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.63.190.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKLxMYwyVGnfuwsKgSgAAA7Q"]
[Tue Jul 21 07:38:32.773590 2026] [security2:error] [pid 255769:tid 255892] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MKLxMYwyVGnfuwsKgTgAD2no"]
[Tue Jul 21 07:38:32.773690 2026] [security2:error] [pid 255769:tid 255954] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MKLxMYwyVGnfuwsKgTgAD2no"]
[Tue Jul 21 07:38:32.783093 2026] [security2:error] [pid 255769:tid 255966] [client 184.75.223.211:46732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9MKLxMYwyVGnfuwsKgUAAAA-Y"]
[Tue Jul 21 07:38:32.783198 2026] [security2:error] [pid 255769:tid 255966] [client 184.75.223.211:46732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9MKLxMYwyVGnfuwsKgUAAAA-Y"]
[Tue Jul 21 07:38:32.854126 2026] [security2:error] [pid 255769:tid 256012] [client 20.151.10.161:45917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ingfo.php"] [unique_id "al9MKLxMYwyVGnfuwsKgUwAABBI"]
[Tue Jul 21 07:38:32.889986 2026] [security2:error] [pid 254995:tid 255137] [client 20.220.225.223:38690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/user.php"] [unique_id "al9MKP7v0rlcEGmVraFESAAAAyo"]
[Tue Jul 21 07:38:33.063705 2026] [proxy:error] [pid 255769:tid 255996] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:33.063783 2026] [proxy_http:error] [pid 255769:tid 255996] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:33.064359 2026] [proxy:error] [pid 255769:tid 255996] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:33.064402 2026] [proxy_http:error] [pid 255769:tid 255996] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:33.072290 2026] [security2:error] [pid 255769:tid 255972] [client 138.68.86.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.86.68.138.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKbxMYwyVGnfuwsKgWQAAA-w"]
[Tue Jul 21 07:38:33.105519 2026] [security2:error] [pid 254995:tid 255100] [remote 159.65.144.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.144.65.159.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKf7v0rlcEGmVraFEUAADTGg"]
[Tue Jul 21 07:38:33.147342 2026] [security2:error] [pid 254995:tid 255275] [client 4.204.201.85:57177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/av.php"] [unique_id "al9MKf7v0rlcEGmVraFEUQAAA5k"]
[Tue Jul 21 07:38:33.160558 2026] [security2:error] [pid 255769:tid 255959] [client 138.68.86.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.86.68.138.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKbxMYwyVGnfuwsKgXAAAA98"]
[Tue Jul 21 07:38:33.162353 2026] [security2:error] [pid 255769:tid 255777] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/modules/mod%20ariimageslidersa/mod%20ariimageslidersa.php"] [unique_id "al9MKbxMYwyVGnfuwsKgXQADtgc"], referer: http://aud-7.com/modules/mod%20ariimageslidersa/mod%20ariimageslidersa.php
[Tue Jul 21 07:38:33.191073 2026] [proxy:error] [pid 255769:tid 255955] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:33.191137 2026] [proxy_http:error] [pid 255769:tid 255955] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:33.191792 2026] [proxy:error] [pid 255769:tid 255955] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:33.191835 2026] [proxy_http:error] [pid 255769:tid 255955] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:33.225744 2026] [security2:error] [pid 255769:tid 255921] [client 20.206.105.145:38470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/simple.php"] [unique_id "al9MKbxMYwyVGnfuwsKgYQAAA7k"]
[Tue Jul 21 07:38:33.249610 2026] [proxy:error] [pid 254995:tid 255183] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:33.249693 2026] [proxy_http:error] [pid 254995:tid 255183] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:33.250559 2026] [proxy:error] [pid 254995:tid 255183] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:33.250609 2026] [proxy_http:error] [pid 254995:tid 255183] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:33.331487 2026] [security2:error] [pid 255769:tid 255939] [client 20.220.225.223:38705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/we.php"] [unique_id "al9MKbxMYwyVGnfuwsKgZAAAA8s"]
[Tue Jul 21 07:38:33.366204 2026] [security2:error] [pid 255769:tid 255975] [client 20.197.192.193:6387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/2x.php"] [unique_id "al9MKbxMYwyVGnfuwsKgZQAAA-8"]
[Tue Jul 21 07:38:33.372993 2026] [security2:error] [pid 254995:tid 255060] [remote 159.65.144.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.144.65.159.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKf7v0rlcEGmVraFEVwADiEA"]
[Tue Jul 21 07:38:33.466720 2026] [security2:error] [pid 255769:tid 255956] [client 4.204.201.85:57196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/classwithtostring.php"] [unique_id "al9MKbxMYwyVGnfuwsKgaQAAA9w"]
[Tue Jul 21 07:38:33.491547 2026] [security2:error] [pid 255769:tid 255936] [client 172.245.102.45:48195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MKbxMYwyVGnfuwsKgYwAAA8g"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:33.513785 2026] [security2:error] [pid 255769:tid 255902] [client 20.226.60.151:56288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/aa.php"] [unique_id "al9MKbxMYwyVGnfuwsKgawAAA6Y"]
[Tue Jul 21 07:38:33.533451 2026] [security2:error] [pid 255769:tid 255961] [client 20.226.60.151:8606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MKbxMYwyVGnfuwsKgbQAAA-E"]
[Tue Jul 21 07:38:33.535392 2026] [proxy:error] [pid 255769:tid 255899] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:33.535446 2026] [proxy_http:error] [pid 255769:tid 255899] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:33.535947 2026] [proxy:error] [pid 255769:tid 255899] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:33.535974 2026] [proxy_http:error] [pid 255769:tid 255899] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:33.616018 2026] [security2:error] [pid 255769:tid 256008] [client 20.226.60.151:51386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9MKbxMYwyVGnfuwsKgcQAABA4"]
[Tue Jul 21 07:38:33.677141 2026] [security2:error] [pid 255769:tid 255832] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/templates/beez/index.php"] [unique_id "al9MKbxMYwyVGnfuwsKgeAAEDD4"], referer: http://aud-7.com/templates/beez/index.php
[Tue Jul 21 07:38:33.774138 2026] [security2:error] [pid 255769:tid 255958] [client 20.197.192.193:6356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/kq1.php"] [unique_id "al9MKbxMYwyVGnfuwsKgegAAA94"]
[Tue Jul 21 07:38:33.795995 2026] [security2:error] [pid 255769:tid 255942] [client 4.204.201.85:57109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-content/themes/index.php"] [unique_id "al9MKbxMYwyVGnfuwsKgewAAA84"]
[Tue Jul 21 07:38:33.884675 2026] [security2:error] [pid 255769:tid 255944] [client 46.101.111.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.111.101.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKbxMYwyVGnfuwsKgfwAAA9A"]
[Tue Jul 21 07:38:33.998793 2026] [security2:error] [pid 255769:tid 256018] [client 20.226.60.151:27358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/inputs.php"] [unique_id "al9MKbxMYwyVGnfuwsKggwAABBg"]
[Tue Jul 21 07:38:34.065300 2026] [proxy:error] [pid 255769:tid 255959] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:34.065364 2026] [proxy_http:error] [pid 255769:tid 255959] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:34.065805 2026] [proxy:error] [pid 255769:tid 255959] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:34.065840 2026] [proxy_http:error] [pid 255769:tid 255959] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:34.190594 2026] [proxy:error] [pid 255769:tid 256001] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:34.190660 2026] [proxy_http:error] [pid 255769:tid 256001] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:34.191255 2026] [proxy:error] [pid 255769:tid 256001] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:34.191280 2026] [proxy_http:error] [pid 255769:tid 256001] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:34.245679 2026] [security2:error] [pid 254995:tid 255125] [client 64.227.70.2:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.70.227.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKf7v0rlcEGmVraFETgAAAx4"]
[Tue Jul 21 07:38:34.251368 2026] [proxy:error] [pid 255769:tid 255997] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:34.251442 2026] [proxy_http:error] [pid 255769:tid 255997] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:34.252569 2026] [proxy:error] [pid 255769:tid 255997] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:34.252613 2026] [proxy_http:error] [pid 255769:tid 255997] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:34.363068 2026] [security2:error] [pid 255769:tid 256021] [client 4.204.201.85:57190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-blog.php"] [unique_id "al9MKrxMYwyVGnfuwsKgjgAABBs"]
[Tue Jul 21 07:38:34.432533 2026] [security2:error] [pid 255769:tid 255952] [client 193.36.225.152:46105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MKrxMYwyVGnfuwsKgkwAAA9g"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:38:34.509129 2026] [security2:error] [pid 255769:tid 255846] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MKrxMYwyVGnfuwsKglgADuEw"]
[Tue Jul 21 07:38:34.509302 2026] [security2:error] [pid 255769:tid 255920] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MKrxMYwyVGnfuwsKglgADuEw"]
[Tue Jul 21 07:38:34.510558 2026] [security2:error] [pid 255769:tid 255961] [client 20.226.60.151:56261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/xwpg.php"] [unique_id "al9MKrxMYwyVGnfuwsKglwAAA-E"]
[Tue Jul 21 07:38:34.544837 2026] [proxy:error] [pid 255769:tid 255923] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:34.544905 2026] [proxy_http:error] [pid 255769:tid 255923] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:34.545362 2026] [proxy:error] [pid 255769:tid 255923] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:34.545388 2026] [proxy_http:error] [pid 255769:tid 255923] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:34.665378 2026] [security2:error] [pid 255769:tid 255971] [client 20.226.60.151:8623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MKrxMYwyVGnfuwsKgnQAAA-s"]
[Tue Jul 21 07:38:34.817649 2026] [autoindex:error] [pid 255769:tid 255944] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:34.986145 2026] [security2:error] [pid 255769:tid 255957] [client 62.102.148.187:34608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9MKrxMYwyVGnfuwsKgpwAAA90"]
[Tue Jul 21 07:38:34.986232 2026] [security2:error] [pid 255769:tid 255957] [client 62.102.148.187:34608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9MKrxMYwyVGnfuwsKgpwAAA90"]
[Tue Jul 21 07:38:35.049550 2026] [security2:error] [pid 255769:tid 255785] [remote 37.60.226.168:54094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.226.60.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moneyclass.com.br"] [uri "/wp-login.php"] [unique_id "al9MK7xMYwyVGnfuwsKgqQADqA8"]
[Tue Jul 21 07:38:35.065018 2026] [proxy:error] [pid 255769:tid 255922] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:35.065070 2026] [proxy_http:error] [pid 255769:tid 255922] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:35.065648 2026] [proxy:error] [pid 255769:tid 255922] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:35.065672 2026] [proxy_http:error] [pid 255769:tid 255922] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:35.097663 2026] [security2:error] [pid 255769:tid 255968] [client 4.204.201.85:57212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-content/admin.php"] [unique_id "al9MK7xMYwyVGnfuwsKgrAAAA-g"]
[Tue Jul 21 07:38:35.110302 2026] [security2:error] [pid 254995:tid 255133] [client 20.206.105.145:38128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/xxx.php"] [unique_id "al9MK_7v0rlcEGmVraFEeQAAAyY"]
[Tue Jul 21 07:38:35.166615 2026] [security2:error] [pid 255769:tid 255912] [client 117.217.38.194:55099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MK7xMYwyVGnfuwsKgrQAAA7A"]
[Tue Jul 21 07:38:35.166929 2026] [security2:error] [pid 255769:tid 255912] [client 117.217.38.194:55099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MK7xMYwyVGnfuwsKgrQAAA7A"]
[Tue Jul 21 07:38:35.191031 2026] [proxy:error] [pid 254995:tid 255255] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:35.191096 2026] [proxy_http:error] [pid 254995:tid 255255] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:35.191534 2026] [proxy:error] [pid 254995:tid 255255] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:35.191561 2026] [proxy_http:error] [pid 254995:tid 255255] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:35.209788 2026] [security2:error] [pid 255769:tid 255989] [client 20.226.60.151:8658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/media.php"] [unique_id "al9MK7xMYwyVGnfuwsKgrwAAA_0"]
[Tue Jul 21 07:38:35.229572 2026] [security2:error] [pid 254995:tid 255208] [client 152.59.154.239:60616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MK_7v0rlcEGmVraFEfwAAA3A"]
[Tue Jul 21 07:38:35.229668 2026] [security2:error] [pid 254995:tid 255208] [client 152.59.154.239:60616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MK_7v0rlcEGmVraFEfwAAA3A"]
[Tue Jul 21 07:38:35.243186 2026] [proxy:error] [pid 255769:tid 255987] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:35.243238 2026] [proxy_http:error] [pid 255769:tid 255987] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:35.243804 2026] [proxy:error] [pid 255769:tid 255987] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:35.243834 2026] [proxy_http:error] [pid 255769:tid 255987] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:35.267551 2026] [security2:error] [pid 255769:tid 255947] [client 139.167.225.182:51075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MK7xMYwyVGnfuwsKgsgAAA9M"]
[Tue Jul 21 07:38:35.267681 2026] [security2:error] [pid 255769:tid 255947] [client 139.167.225.182:51075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MK7xMYwyVGnfuwsKgsgAAA9M"]
[Tue Jul 21 07:38:35.320310 2026] [security2:error] [pid 255769:tid 256025] [client 20.226.60.151:61186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/txets.php"] [unique_id "al9MK7xMYwyVGnfuwsKgtgAABB8"]
[Tue Jul 21 07:38:35.451971 2026] [security2:error] [pid 255769:tid 255920] [client 20.226.60.151:8730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/images.php"] [unique_id "al9MK7xMYwyVGnfuwsKgvgAAA7g"]
[Tue Jul 21 07:38:35.534085 2026] [proxy:error] [pid 255769:tid 255984] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:35.534144 2026] [proxy_http:error] [pid 255769:tid 255984] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:35.534595 2026] [proxy:error] [pid 255769:tid 255984] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:35.534618 2026] [proxy_http:error] [pid 255769:tid 255984] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:35.565269 2026] [security2:error] [pid 255769:tid 255910] [client 4.204.201.85:55976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/adminfuns.php"] [unique_id "al9MK7xMYwyVGnfuwsKgwAAAA64"]
[Tue Jul 21 07:38:35.965050 2026] [security2:error] [pid 255769:tid 255951] [client 4.204.201.85:55978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/goods.php"] [unique_id "al9MK7xMYwyVGnfuwsKgzwAAA9c"]
[Tue Jul 21 07:38:36.063500 2026] [proxy:error] [pid 254995:tid 255215] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:36.063572 2026] [proxy_http:error] [pid 254995:tid 255215] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:36.064195 2026] [proxy:error] [pid 254995:tid 255215] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:36.064227 2026] [proxy_http:error] [pid 254995:tid 255215] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:36.164736 2026] [security2:error] [pid 255769:tid 255912] [client 172.245.102.34:35667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MLLxMYwyVGnfuwsKg0gAAA7A"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:38:36.194262 2026] [proxy:error] [pid 255769:tid 255981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:36.194330 2026] [proxy_http:error] [pid 255769:tid 255981] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:36.195003 2026] [proxy:error] [pid 255769:tid 255981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:36.195045 2026] [proxy_http:error] [pid 255769:tid 255981] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:36.223558 2026] [security2:error] [pid 254995:tid 255003] [remote 173.252.82.112:38496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.82.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9MLP7v0rlcEGmVraFElQADkgc"]
[Tue Jul 21 07:38:36.261280 2026] [proxy:error] [pid 254995:tid 255135] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:36.261352 2026] [proxy_http:error] [pid 254995:tid 255135] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:36.261946 2026] [proxy:error] [pid 254995:tid 255135] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:36.261973 2026] [proxy_http:error] [pid 254995:tid 255135] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:36.283540 2026] [security2:error] [pid 255769:tid 255987] [client 20.226.60.151:8637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/gecko.php"] [unique_id "al9MLLxMYwyVGnfuwsKg1gAAA_s"]
[Tue Jul 21 07:38:36.352789 2026] [security2:error] [pid 254995:tid 255258] [client 20.226.60.151:27582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/classwithtostring.php"] [unique_id "al9MLP7v0rlcEGmVraFEmwAAA4g"]
[Tue Jul 21 07:38:36.370555 2026] [security2:error] [pid 255769:tid 255932] [client 128.199.182.55:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.182.199.128.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MK7xMYwyVGnfuwsKguAAAA8Q"]
[Tue Jul 21 07:38:36.404107 2026] [security2:error] [pid 254995:tid 255142] [client 4.204.201.85:55523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/ms-edit.php"] [unique_id "al9MLP7v0rlcEGmVraFEnQAAAy8"]
[Tue Jul 21 07:38:36.534820 2026] [proxy:error] [pid 254995:tid 255136] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:36.534882 2026] [proxy_http:error] [pid 254995:tid 255136] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:36.535344 2026] [proxy:error] [pid 254995:tid 255136] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:36.535370 2026] [proxy_http:error] [pid 254995:tid 255136] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:36.693526 2026] [security2:error] [pid 254995:tid 255147] [client 173.24.185.52:59463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MLP7v0rlcEGmVraFEpQAAAzQ"]
[Tue Jul 21 07:38:36.693641 2026] [security2:error] [pid 254995:tid 255147] [client 173.24.185.52:59463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MLP7v0rlcEGmVraFEpQAAAzQ"]
[Tue Jul 21 07:38:36.707808 2026] [security2:error] [pid 254995:tid 255202] [client 4.204.201.85:57111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/222.php"] [unique_id "al9MLP7v0rlcEGmVraFEpgAAA2s"]
[Tue Jul 21 07:38:36.708909 2026] [security2:error] [pid 255769:tid 255964] [client 20.226.60.151:8610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/82.php"] [unique_id "al9MLLxMYwyVGnfuwsKg3wAAA-Q"]
[Tue Jul 21 07:38:36.967517 2026] [security2:error] [pid 254995:tid 255277] [client 20.226.60.151:8643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/admin.php"] [unique_id "al9MLP7v0rlcEGmVraFErgAAA5s"]
[Tue Jul 21 07:38:37.039491 2026] [security2:error] [pid 255769:tid 255944] [client 37.140.223.69:57211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MLbxMYwyVGnfuwsKg5QAAA9A"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:37.061927 2026] [proxy:error] [pid 254995:tid 255198] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:37.061990 2026] [proxy_http:error] [pid 254995:tid 255198] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:37.062570 2026] [proxy:error] [pid 254995:tid 255198] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:37.062599 2026] [proxy_http:error] [pid 254995:tid 255198] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:37.100037 2026] [security2:error] [pid 254995:tid 255140] [client 4.204.201.85:55990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/cgi-bin/index.php"] [unique_id "al9MLf7v0rlcEGmVraFEtAAAAy0"]
[Tue Jul 21 07:38:37.127444 2026] [security2:error] [pid 255769:tid 255949] [client 20.226.60.151:8598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/adminner.php"] [unique_id "al9MLbxMYwyVGnfuwsKg5gAAA9U"]
[Tue Jul 21 07:38:37.152034 2026] [security2:error] [pid 255769:tid 255989] [client 106.215.181.8:17504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MLLxMYwyVGnfuwsKg4gAAA_0"]
[Tue Jul 21 07:38:37.152176 2026] [security2:error] [pid 255769:tid 255989] [client 106.215.181.8:17504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MLLxMYwyVGnfuwsKg4gAAA_0"]
[Tue Jul 21 07:38:37.168593 2026] [security2:error] [pid 255769:tid 256016] [client 184.75.223.211:46736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9MLbxMYwyVGnfuwsKg6wAABBY"]
[Tue Jul 21 07:38:37.168662 2026] [security2:error] [pid 255769:tid 256016] [client 184.75.223.211:46736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9MLbxMYwyVGnfuwsKg6wAABBY"]
[Tue Jul 21 07:38:37.194511 2026] [proxy:error] [pid 255769:tid 255990] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:37.194573 2026] [proxy_http:error] [pid 255769:tid 255990] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:37.195102 2026] [proxy:error] [pid 255769:tid 255990] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:37.195130 2026] [proxy_http:error] [pid 255769:tid 255990] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:37.249719 2026] [proxy:error] [pid 255769:tid 256008] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:37.249780 2026] [proxy_http:error] [pid 255769:tid 256008] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:37.250507 2026] [proxy:error] [pid 255769:tid 256008] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:37.250547 2026] [proxy_http:error] [pid 255769:tid 256008] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:37.386731 2026] [security2:error] [pid 255769:tid 256003] [client 20.197.192.193:6855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/zzz.php"] [unique_id "al9MLbxMYwyVGnfuwsKg9AAABAk"]
[Tue Jul 21 07:38:37.424794 2026] [security2:error] [pid 255769:tid 255909] [client 20.226.60.151:51282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/dex.php"] [unique_id "al9MLbxMYwyVGnfuwsKg9QAAA60"]
[Tue Jul 21 07:38:37.439880 2026] [security2:error] [pid 255769:tid 255962] [client 20.226.60.151:8665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/admin.php"] [unique_id "al9MLbxMYwyVGnfuwsKg9gAAA-I"]
[Tue Jul 21 07:38:37.460113 2026] [security2:error] [pid 254995:tid 255149] [client 20.226.60.151:8590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/k.php"] [unique_id "al9MLf7v0rlcEGmVraFEuQAAAzY"]
[Tue Jul 21 07:38:37.475567 2026] [autoindex:error] [pid 254995:tid 255260] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:37.551449 2026] [security2:error] [pid 255769:tid 255912] [client 20.226.60.151:8627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/blurbs.php"] [unique_id "al9MLbxMYwyVGnfuwsKg_QAAA7A"]
[Tue Jul 21 07:38:37.557666 2026] [proxy:error] [pid 255769:tid 255981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:37.557735 2026] [proxy_http:error] [pid 255769:tid 255981] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:37.558271 2026] [proxy:error] [pid 255769:tid 255981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:37.558298 2026] [proxy_http:error] [pid 255769:tid 255981] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:37.613513 2026] [security2:error] [pid 254995:tid 255217] [client 20.226.60.151:8626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/bajah.php"] [unique_id "al9MLf7v0rlcEGmVraFEwQAAA3k"]
[Tue Jul 21 07:38:37.633390 2026] [security2:error] [pid 255769:tid 256019] [client 122.186.204.214:60700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MLbxMYwyVGnfuwsKhAwAABBk"]
[Tue Jul 21 07:38:37.633535 2026] [security2:error] [pid 255769:tid 256019] [client 122.186.204.214:60700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MLbxMYwyVGnfuwsKhAwAABBk"]
[Tue Jul 21 07:38:37.653927 2026] [security2:error] [pid 255769:tid 256005] [client 117.251.86.144:49744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MLbxMYwyVGnfuwsKhBAAABAs"]
[Tue Jul 21 07:38:37.654090 2026] [security2:error] [pid 255769:tid 256005] [client 117.251.86.144:49744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MLbxMYwyVGnfuwsKhBAAABAs"]
[Tue Jul 21 07:38:37.679639 2026] [security2:error] [pid 255769:tid 255932] [client 20.226.60.151:8624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/a.php"] [unique_id "al9MLbxMYwyVGnfuwsKhBwAAA8Q"]
[Tue Jul 21 07:38:37.721717 2026] [security2:error] [pid 255769:tid 256028] [client 20.206.105.145:38082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/hypo.php"] [unique_id "al9MLbxMYwyVGnfuwsKhCQAABCI"]
[Tue Jul 21 07:38:37.739081 2026] [security2:error] [pid 254995:tid 255144] [client 20.151.10.161:45990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/error_log.php"] [unique_id "al9MLf7v0rlcEGmVraFEwwAAAzE"]
[Tue Jul 21 07:38:37.754229 2026] [security2:error] [pid 255769:tid 256021] [client 4.204.201.85:57153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/BDKR28WP.php"] [unique_id "al9MLbxMYwyVGnfuwsKhCgAABBs"]
[Tue Jul 21 07:38:37.767125 2026] [security2:error] [pid 254995:tid 255210] [client 20.226.60.151:8655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/edit.php"] [unique_id "al9MLf7v0rlcEGmVraFExAAAA3I"]
[Tue Jul 21 07:38:37.833106 2026] [security2:error] [pid 255769:tid 255944] [client 20.226.60.151:8669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/hosty.php"] [unique_id "al9MLbxMYwyVGnfuwsKhDwAAA9A"]
[Tue Jul 21 07:38:37.878365 2026] [security2:error] [pid 255769:tid 255984] [client 20.226.60.151:51292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/xpwer1.php"] [unique_id "al9MLbxMYwyVGnfuwsKhEQAAA_g"]
[Tue Jul 21 07:38:37.924974 2026] [security2:error] [pid 255769:tid 256022] [client 20.226.60.151:8690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/k.php"] [unique_id "al9MLbxMYwyVGnfuwsKhFAAABBw"]
[Tue Jul 21 07:38:37.955948 2026] [security2:error] [pid 254995:tid 255206] [client 20.226.60.151:8628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/aaa.php"] [unique_id "al9MLf7v0rlcEGmVraFExwAAA28"]
[Tue Jul 21 07:38:38.027065 2026] [security2:error] [pid 254995:tid 255145] [client 20.226.60.151:8584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/file5.php"] [unique_id "al9MLv7v0rlcEGmVraFEyAAAAzI"]
[Tue Jul 21 07:38:38.064270 2026] [proxy:error] [pid 255769:tid 256008] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.064354 2026] [proxy_http:error] [pid 255769:tid 256008] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.065483 2026] [proxy:error] [pid 255769:tid 256008] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.065527 2026] [proxy_http:error] [pid 255769:tid 256008] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.096329 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.096425 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.096534 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.096576 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.096633 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.096740 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.096836 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.096910 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.096973 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097019 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097055 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097090 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097138 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097191 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097228 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097262 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097317 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097370 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097412 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097464 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097518 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097572 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097621 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097663 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097698 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097734 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097769 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097804 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097916 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097982 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098050 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098084 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098119 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098173 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098250 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098296 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098336 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098374 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098425 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098460 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098510 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098551 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098590 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098666 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098711 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098746 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098780 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098823 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098874 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098947 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098982 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099028 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099064 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099100 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099147 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099186 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099240 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099314 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099349 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099400 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099458 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099511 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099557 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099618 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099689 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099741 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099809 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099891 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099954 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100001 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100061 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100099 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100141 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100176 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100211 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100246 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100280 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100314 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100355 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100389 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100425 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100477 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100520 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100554 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100589 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100623 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100658 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100705 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100744 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100779 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100825 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100861 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100925 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100967 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.101019 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning: Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.129178 2026] [security2:error] [pid 255769:tid 256012] [client 20.226.60.151:8639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/222.php"] [unique_id "al9MLrxMYwyVGnfuwsKhGAAABBI"]
[Tue Jul 21 07:38:38.177545 2026] [security2:error] [pid 255769:tid 255958] [client 20.226.60.151:8654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/test.php"] [unique_id "al9MLrxMYwyVGnfuwsKhGgAAA94"]
[Tue Jul 21 07:38:38.191929 2026] [proxy:error] [pid 255769:tid 255942] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.191991 2026] [proxy_http:error] [pid 255769:tid 255942] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.192444 2026] [proxy:error] [pid 255769:tid 255942] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.192469 2026] [proxy_http:error] [pid 255769:tid 255942] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.207739 2026] [security2:error] [pid 255769:tid 255988] [client 20.226.60.151:8599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/aaa.php"] [unique_id "al9MLrxMYwyVGnfuwsKhHgAAA_w"]
[Tue Jul 21 07:38:38.215057 2026] [autoindex:error] [pid 254995:tid 255275] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:38.233658 2026] [security2:error] [pid 255769:tid 255829] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MLrxMYwyVGnfuwsKhHwADuzs"]
[Tue Jul 21 07:38:38.233836 2026] [security2:error] [pid 255769:tid 255923] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MLrxMYwyVGnfuwsKhHwADuzs"]
[Tue Jul 21 07:38:38.251669 2026] [proxy:error] [pid 255769:tid 255940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.251768 2026] [proxy_http:error] [pid 255769:tid 255940] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.252941 2026] [proxy:error] [pid 255769:tid 255940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.253000 2026] [proxy_http:error] [pid 255769:tid 255940] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.255001 2026] [security2:error] [pid 254995:tid 255174] [client 20.226.60.151:8609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/11.php"] [unique_id "al9MLv7v0rlcEGmVraFE0gAAA08"]
[Tue Jul 21 07:38:38.275602 2026] [security2:error] [pid 254995:tid 255268] [client 20.226.60.151:8676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/mac.php"] [unique_id "al9MLv7v0rlcEGmVraFE0wAAA5I"]
[Tue Jul 21 07:38:38.332684 2026] [security2:error] [pid 255769:tid 255922] [client 184.75.223.211:37940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MLrxMYwyVGnfuwsKhIgAAA7o"]
[Tue Jul 21 07:38:38.332790 2026] [security2:error] [pid 255769:tid 255922] [client 184.75.223.211:37940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MLrxMYwyVGnfuwsKhIgAAA7o"]
[Tue Jul 21 07:38:38.367825 2026] [security2:error] [pid 255769:tid 255918] [client 20.220.225.223:32312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/ms-new.php"] [unique_id "al9MLrxMYwyVGnfuwsKhJgAAA7Y"]
[Tue Jul 21 07:38:38.435223 2026] [security2:error] [pid 254995:tid 255271] [client 20.226.60.151:8579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/chosen.php"] [unique_id "al9MLv7v0rlcEGmVraFE1wAAA5U"]
[Tue Jul 21 07:38:38.506586 2026] [authz_core:error] [pid 255769:tid 255932] [client 4.204.201.85:0] AH01630: client denied by server configuration: /home1/ofic8899/qcharge.tryhealth.shop/wp-content/uploads/index.php
[Tue Jul 21 07:38:38.518476 2026] [security2:error] [pid 255769:tid 256013] [client 20.226.60.151:8649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/cream1.php"] [unique_id "al9MLrxMYwyVGnfuwsKhKwAABBM"]
[Tue Jul 21 07:38:38.534094 2026] [proxy:error] [pid 255769:tid 255994] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.534164 2026] [proxy_http:error] [pid 255769:tid 255994] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.534880 2026] [proxy:error] [pid 255769:tid 255994] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.534922 2026] [proxy_http:error] [pid 255769:tid 255994] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.596608 2026] [proxy:error] [pid 255769:tid 256025] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.596684 2026] [proxy_http:error] [pid 255769:tid 256025] [client 20.226.60.151:8604] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.597305 2026] [proxy:error] [pid 255769:tid 256025] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.597343 2026] [proxy_http:error] [pid 255769:tid 256025] [client 20.226.60.151:8604] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.649666 2026] [security2:error] [pid 255769:tid 255907] [client 4.204.201.85:57174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp.php"] [unique_id "al9MLrxMYwyVGnfuwsKhMQAAA6s"]
[Tue Jul 21 07:38:38.701868 2026] [proxy:error] [pid 255769:tid 255983] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.701915 2026] [proxy_http:error] [pid 255769:tid 255983] [client 20.226.60.151:8648] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.702344 2026] [proxy:error] [pid 255769:tid 255983] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.702366 2026] [proxy_http:error] [pid 255769:tid 255983] [client 20.226.60.151:8648] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.857202 2026] [security2:error] [pid 255769:tid 255824] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MLrxMYwyVGnfuwsKhOwAD_TY"]
[Tue Jul 21 07:38:38.857386 2026] [security2:error] [pid 255769:tid 255989] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MLrxMYwyVGnfuwsKhOwAD_TY"]
[Tue Jul 21 07:38:38.863461 2026] [security2:error] [pid 255769:tid 255971] [client 20.226.60.151:8661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/dr.php"] [unique_id "al9MLrxMYwyVGnfuwsKhPAAAA-s"]
[Tue Jul 21 07:38:38.935001 2026] [security2:error] [pid 255769:tid 256012] [client 4.204.201.85:57094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/abcd.php"] [unique_id "al9MLrxMYwyVGnfuwsKhQAAABBI"]
[Tue Jul 21 07:38:38.981120 2026] [autoindex:error] [pid 255769:tid 256008] [client 20.206.105.145:38499] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:38.987712 2026] [security2:error] [pid 255769:tid 255934] [client 20.226.60.151:8660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/x.php"] [unique_id "al9MLrxMYwyVGnfuwsKhRAAAA8Y"]
[Tue Jul 21 07:38:38.992654 2026] [security2:error] [pid 255769:tid 255936] [client 20.206.105.145:38499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/chosen.php"] [unique_id "al9MLrxMYwyVGnfuwsKhRQAAA8g"]
[Tue Jul 21 07:38:39.051700 2026] [proxy:error] [pid 255769:tid 255953] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:39.051764 2026] [proxy_http:error] [pid 255769:tid 255953] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:39.052203 2026] [proxy:error] [pid 255769:tid 255953] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:39.052227 2026] [proxy_http:error] [pid 255769:tid 255953] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:39.060307 2026] [autoindex:error] [pid 255769:tid 256010] [client 20.206.105.145:37941] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:39.064212 2026] [core:alert] [pid 254995:tid 255200] [client 57.141.18.45:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:38:39.072953 2026] [security2:error] [pid 255769:tid 256003] [client 20.206.105.145:37941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/als.php"] [unique_id "al9ML7xMYwyVGnfuwsKhTAAABAk"]
[Tue Jul 21 07:38:39.082358 2026] [security2:error] [pid 255769:tid 255911] [client 20.226.60.151:8629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/155.php"] [unique_id "al9ML7xMYwyVGnfuwsKhTQAAA68"]
[Tue Jul 21 07:38:39.193883 2026] [proxy:error] [pid 255769:tid 255959] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:39.193953 2026] [proxy_http:error] [pid 255769:tid 255959] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:39.194443 2026] [proxy:error] [pid 255769:tid 255959] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:39.194465 2026] [proxy_http:error] [pid 255769:tid 255959] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:39.226061 2026] [security2:error] [pid 255769:tid 255918] [client 20.151.10.161:46066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xenon1337.php"] [unique_id "al9ML7xMYwyVGnfuwsKhUQAAA7Y"]
[Tue Jul 21 07:38:39.232055 2026] [security2:error] [pid 255769:tid 255794] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ML7xMYwyVGnfuwsKhSwAD_Bg"]
[Tue Jul 21 07:38:39.232300 2026] [security2:error] [pid 255769:tid 255988] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ML7xMYwyVGnfuwsKhSwAD_Bg"]
[Tue Jul 21 07:38:39.241587 2026] [security2:error] [pid 255769:tid 255912] [client 4.204.201.85:55496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/a1.php"] [unique_id "al9ML7xMYwyVGnfuwsKhUgAAA7A"]
[Tue Jul 21 07:38:39.251796 2026] [proxy:error] [pid 254995:tid 255181] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:39.251846 2026] [proxy_http:error] [pid 254995:tid 255181] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:39.252307 2026] [proxy:error] [pid 254995:tid 255181] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:39.252327 2026] [proxy_http:error] [pid 254995:tid 255181] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:39.283939 2026] [security2:error] [pid 255769:tid 256000] [client 20.226.60.151:8594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/ops.php"] [unique_id "al9ML7xMYwyVGnfuwsKhVAAABAY"]
[Tue Jul 21 07:38:39.434870 2026] [security2:error] [pid 254995:tid 255154] [client 20.226.60.151:8668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/file31.php"] [unique_id "al9ML_7v0rlcEGmVraFE8AAAAzs"]
[Tue Jul 21 07:38:39.485224 2026] [security2:error] [pid 255769:tid 255915] [client 20.226.60.151:8702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/file6.php"] [unique_id "al9ML7xMYwyVGnfuwsKhVgAAA7M"]
[Tue Jul 21 07:38:39.489751 2026] [security2:error] [pid 255769:tid 255941] [client 74.7.230.27:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tryhealth.shop"] [uri "/index.php"] [unique_id "al9MLrxMYwyVGnfuwsKhQwAAA80"]
[Tue Jul 21 07:38:39.490834 2026] [security2:error] [pid 255769:tid 255935] [client 74.7.230.27:34028] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tryhealth.shop"] [uri "/robots.txt"] [unique_id "al9MLrxMYwyVGnfuwsKhQQADx2A"]
[Tue Jul 21 07:38:39.499555 2026] [proxy:error] [pid 254995:tid 255140] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:39.499628 2026] [proxy_http:error] [pid 254995:tid 255140] [client 20.226.60.151:8697] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:39.500103 2026] [proxy:error] [pid 254995:tid 255140] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:39.500128 2026] [proxy_http:error] [pid 254995:tid 255140] [client 20.226.60.151:8697] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:39.501574 2026] [security2:error] [pid 254995:tid 255272] [client 20.226.60.151:60995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/flox.php"] [unique_id "al9ML_7v0rlcEGmVraFE9AAAA5Y"]
[Tue Jul 21 07:38:39.537361 2026] [security2:error] [pid 254995:tid 255219] [client 20.226.60.151:8646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/adminfuns.php"] [unique_id "al9ML_7v0rlcEGmVraFE9gAAA3s"]
[Tue Jul 21 07:38:39.537511 2026] [security2:error] [pid 254995:tid 255178] [client 4.204.201.85:60622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9ML_7v0rlcEGmVraFE9wAAA1M"]
[Tue Jul 21 07:38:39.563301 2026] [proxy:error] [pid 254995:tid 255269] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:39.563371 2026] [proxy_http:error] [pid 254995:tid 255269] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:39.564100 2026] [proxy:error] [pid 254995:tid 255269] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:39.564131 2026] [proxy_http:error] [pid 254995:tid 255269] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:39.564224 2026] [security2:error] [pid 254995:tid 255149] [client 20.206.105.145:38105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/pol.php"] [unique_id "al9ML_7v0rlcEGmVraFE-QAAAzY"]
[Tue Jul 21 07:38:39.587693 2026] [security2:error] [pid 255769:tid 255964] [client 20.226.60.151:8602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/goods.php"] [unique_id "al9ML7xMYwyVGnfuwsKhWAAAA-Q"]
[Tue Jul 21 07:38:39.605537 2026] [security2:error] [pid 254995:tid 255260] [client 20.197.192.193:6882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/wicked.php"] [unique_id "al9ML_7v0rlcEGmVraFE-gAAA4o"]
[Tue Jul 21 07:38:39.620239 2026] [security2:error] [pid 254995:tid 255213] [client 20.226.60.151:8652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/100.php"] [unique_id "al9ML_7v0rlcEGmVraFE-wAAA3U"]
[Tue Jul 21 07:38:39.670400 2026] [security2:error] [pid 254995:tid 255217] [client 20.226.60.151:8596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/about.php"] [unique_id "al9ML_7v0rlcEGmVraFFAAAAA3k"]
[Tue Jul 21 07:38:39.734899 2026] [security2:error] [pid 254995:tid 255210] [client 194.99.104.35:49696] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ML_7v0rlcEGmVraFFAQAAA3I"]
[Tue Jul 21 07:38:39.734998 2026] [security2:error] [pid 254995:tid 255210] [client 194.99.104.35:49696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ML_7v0rlcEGmVraFFAQAAA3I"]
[Tue Jul 21 07:38:39.809767 2026] [security2:error] [pid 255769:tid 255940] [client 175.45.70.82:49645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ML7xMYwyVGnfuwsKhXQAAA8w"]
[Tue Jul 21 07:38:39.809917 2026] [security2:error] [pid 255769:tid 255940] [client 175.45.70.82:49645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ML7xMYwyVGnfuwsKhXQAAA8w"]
[Tue Jul 21 07:38:39.815239 2026] [security2:error] [pid 254995:tid 255189] [client 4.204.201.85:61193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/cgi-bin/admin.php"] [unique_id "al9ML_7v0rlcEGmVraFFBQAAA14"]
[Tue Jul 21 07:38:39.827854 2026] [security2:error] [pid 255769:tid 255949] [client 20.220.225.223:31185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/phpinfo.php1"] [unique_id "al9ML7xMYwyVGnfuwsKhXgAAA9U"]
[Tue Jul 21 07:38:39.882495 2026] [security2:error] [pid 255769:tid 255922] [client 154.192.233.199:59278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ML7xMYwyVGnfuwsKhYAAAA7o"]
[Tue Jul 21 07:38:39.882640 2026] [security2:error] [pid 255769:tid 255922] [client 154.192.233.199:59278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ML7xMYwyVGnfuwsKhYAAAA7o"]
[Tue Jul 21 07:38:39.965818 2026] [security2:error] [pid 254995:tid 255148] [client 20.226.60.151:8642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/about.php"] [unique_id "al9ML_7v0rlcEGmVraFFCAAAAzU"]
[Tue Jul 21 07:38:40.034051 2026] [security2:error] [pid 254995:tid 255166] [client 20.206.105.145:37893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/file5.php"] [unique_id "al9MMP7v0rlcEGmVraFFCgAAA0c"]
[Tue Jul 21 07:38:40.051305 2026] [security2:error] [pid 255769:tid 255947] [client 122.164.127.47:57997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MMLxMYwyVGnfuwsKhZAAAA9M"]
[Tue Jul 21 07:38:40.052881 2026] [security2:error] [pid 255769:tid 255947] [client 122.164.127.47:57997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MMLxMYwyVGnfuwsKhZAAAA9M"]
[Tue Jul 21 07:38:40.066731 2026] [proxy:error] [pid 254995:tid 255278] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:40.066791 2026] [proxy_http:error] [pid 254995:tid 255278] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:40.067492 2026] [proxy:error] [pid 254995:tid 255278] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:40.067521 2026] [proxy_http:error] [pid 254995:tid 255278] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:40.086085 2026] [security2:error] [pid 254995:tid 255145] [client 20.226.60.151:27556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9MMP7v0rlcEGmVraFFDAAAAzI"]
[Tue Jul 21 07:38:40.106531 2026] [security2:error] [pid 255769:tid 255943] [client 4.204.201.85:60544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/gettest.php"] [unique_id "al9MMLxMYwyVGnfuwsKhZQAAA88"]
[Tue Jul 21 07:38:40.162479 2026] [security2:error] [pid 255769:tid 256001] [client 122.162.144.145:17350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MMLxMYwyVGnfuwsKhZgAABAc"]
[Tue Jul 21 07:38:40.162614 2026] [security2:error] [pid 255769:tid 256001] [client 122.162.144.145:17350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MMLxMYwyVGnfuwsKhZgAABAc"]
[Tue Jul 21 07:38:40.207278 2026] [proxy:error] [pid 254995:tid 255171] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:40.207347 2026] [proxy_http:error] [pid 254995:tid 255171] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:40.207894 2026] [proxy:error] [pid 254995:tid 255171] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:40.207916 2026] [proxy_http:error] [pid 254995:tid 255171] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:40.336745 2026] [security2:error] [pid 254995:tid 255135] [client 20.226.60.151:8597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/admin.php"] [unique_id "al9MMP7v0rlcEGmVraFFGQAAAyg"]
[Tue Jul 21 07:38:40.392949 2026] [security2:error] [pid 254995:tid 255215] [client 20.226.60.151:8650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/admin.php"] [unique_id "al9MMP7v0rlcEGmVraFFIAAAA3c"]
[Tue Jul 21 07:38:40.452228 2026] [security2:error] [pid 255769:tid 255942] [client 20.226.60.151:8592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/themes.php"] [unique_id "al9MMLxMYwyVGnfuwsKhbAAAA84"]
[Tue Jul 21 07:38:40.463104 2026] [security2:error] [pid 255769:tid 255899] [client 103.106.20.201:55515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MMLxMYwyVGnfuwsKhbwAAA6M"]
[Tue Jul 21 07:38:40.463200 2026] [security2:error] [pid 255769:tid 255899] [client 103.106.20.201:55515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MMLxMYwyVGnfuwsKhbwAAA6M"]
[Tue Jul 21 07:38:40.494894 2026] [security2:error] [pid 255769:tid 255967] [client 20.197.192.193:6391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/edit.php"] [unique_id "al9MMLxMYwyVGnfuwsKhcgAAA-c"]
[Tue Jul 21 07:38:40.499043 2026] [proxy:error] [pid 255769:tid 255959] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:40.499105 2026] [proxy_http:error] [pid 255769:tid 255959] [client 20.226.60.151:8641] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:40.499733 2026] [proxy:error] [pid 255769:tid 255959] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:40.499760 2026] [proxy_http:error] [pid 255769:tid 255959] [client 20.226.60.151:8641] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:40.501020 2026] [security2:error] [pid 255769:tid 255917] [client 20.10.88.227:9795] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tryhealth.shop"] [uri "/robots.txt"] [unique_id "al9MMLxMYwyVGnfuwsKhcQAAA7U"]
[Tue Jul 21 07:38:40.537643 2026] [proxy:error] [pid 255769:tid 255986] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:40.537721 2026] [proxy_http:error] [pid 255769:tid 255986] [client 20.226.60.151:8683] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:40.538062 2026] [proxy:error] [pid 254995:tid 255138] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:40.538112 2026] [proxy_http:error] [pid 254995:tid 255138] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:40.538528 2026] [proxy:error] [pid 255769:tid 255986] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:40.538531 2026] [proxy:error] [pid 254995:tid 255138] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:40.538564 2026] [proxy_http:error] [pid 254995:tid 255138] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:40.538568 2026] [proxy_http:error] [pid 255769:tid 255986] [client 20.226.60.151:8683] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:40.553126 2026] [security2:error] [pid 254995:tid 255185] [client 4.204.201.85:57122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/simple.php"] [unique_id "al9MMP7v0rlcEGmVraFFJgAAA1o"]
[Tue Jul 21 07:38:40.597160 2026] [security2:error] [pid 254995:tid 255142] [client 20.220.225.223:22492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/track.php"] [unique_id "al9MMP7v0rlcEGmVraFFJwAAAy8"]
[Tue Jul 21 07:38:40.644235 2026] [security2:error] [pid 254995:tid 255273] [client 20.226.60.151:8587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/.well-known/about.php"] [unique_id "al9MMP7v0rlcEGmVraFFKQAAA5c"]
[Tue Jul 21 07:38:40.903781 2026] [security2:error] [pid 254995:tid 255163] [client 4.204.201.85:61310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/xxx.php"] [unique_id "al9MMP7v0rlcEGmVraFFLgAAA0Q"]
[Tue Jul 21 07:38:40.914783 2026] [security2:error] [pid 255769:tid 255994] [client 20.226.60.151:8731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9MMLxMYwyVGnfuwsKhewAABAE"]
[Tue Jul 21 07:38:40.979625 2026] [security2:error] [pid 255769:tid 255836] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MMLxMYwyVGnfuwsKhfQADzUI"]
[Tue Jul 21 07:38:40.979776 2026] [security2:error] [pid 255769:tid 255941] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MMLxMYwyVGnfuwsKhfQADzUI"]
[Tue Jul 21 07:38:41.019283 2026] [security2:error] [pid 254995:tid 255057] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MMf7v0rlcEGmVraFFMwADOz0"]
[Tue Jul 21 07:38:41.019441 2026] [security2:error] [pid 254995:tid 255154] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MMf7v0rlcEGmVraFFMwADOz0"]
[Tue Jul 21 07:38:41.062551 2026] [security2:error] [pid 255769:tid 255982] [client 20.151.10.161:45896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/test11.php"] [unique_id "al9MMbxMYwyVGnfuwsKhgQAAA_Y"]
[Tue Jul 21 07:38:41.111590 2026] [security2:error] [pid 255769:tid 255955] [client 20.226.60.151:8612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/wefile.php"] [unique_id "al9MMbxMYwyVGnfuwsKhggAAA9s"]
[Tue Jul 21 07:38:41.219969 2026] [security2:error] [pid 255769:tid 255960] [client 128.127.105.184:37040] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MMbxMYwyVGnfuwsKhhAAAA-A"]
[Tue Jul 21 07:38:41.220096 2026] [security2:error] [pid 255769:tid 255960] [client 128.127.105.184:37040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MMbxMYwyVGnfuwsKhhAAAA-A"]
[Tue Jul 21 07:38:41.222389 2026] [security2:error] [pid 255769:tid 255998] [client 4.204.201.85:55994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/hypo.php"] [unique_id "al9MMbxMYwyVGnfuwsKhhQAABAQ"]
[Tue Jul 21 07:38:41.271382 2026] [security2:error] [pid 254995:tid 255129] [client 20.226.60.151:8640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9MMf7v0rlcEGmVraFFOAAAAyI"]
[Tue Jul 21 07:38:41.297039 2026] [security2:error] [pid 254995:tid 255266] [client 20.226.60.151:56222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/ops.php"] [unique_id "al9MMf7v0rlcEGmVraFFOQAAA5A"]
[Tue Jul 21 07:38:41.358948 2026] [security2:error] [pid 255769:tid 255902] [client 136.144.33.108:34009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MMbxMYwyVGnfuwsKhiAAAA6Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:41.465960 2026] [proxy:error] [pid 255769:tid 255943] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:41.466046 2026] [proxy_http:error] [pid 255769:tid 255943] [client 20.226.60.151:8737] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:41.466709 2026] [proxy:error] [pid 255769:tid 255943] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:41.466742 2026] [proxy_http:error] [pid 255769:tid 255943] [client 20.226.60.151:8737] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:41.472257 2026] [security2:error] [pid 255769:tid 255975] [client 20.197.192.193:6880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/kua.php"] [unique_id "al9MMbxMYwyVGnfuwsKhigAAA-8"]
[Tue Jul 21 07:38:41.519330 2026] [security2:error] [pid 255769:tid 256001] [client 20.226.60.151:61194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/popo.php"] [unique_id "al9MMbxMYwyVGnfuwsKhiwAABAc"]
[Tue Jul 21 07:38:41.590761 2026] [proxy:error] [pid 255769:tid 255934] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:41.590835 2026] [proxy_http:error] [pid 255769:tid 255934] [client 20.226.60.151:8657] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:41.591277 2026] [proxy:error] [pid 255769:tid 255934] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:41.591299 2026] [proxy_http:error] [pid 255769:tid 255934] [client 20.226.60.151:8657] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:41.641327 2026] [autoindex:error] [pid 255769:tid 255936] [client 4.204.201.85:55950] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:41.719085 2026] [security2:error] [pid 254995:tid 255173] [client 20.226.60.151:8631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9MMf7v0rlcEGmVraFFQQAAA04"]
[Tue Jul 21 07:38:41.783967 2026] [security2:error] [pid 255769:tid 256010] [client 20.226.60.151:8638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/8.php"] [unique_id "al9MMbxMYwyVGnfuwsKhkQAABBA"]
[Tue Jul 21 07:38:41.792918 2026] [security2:error] [pid 254995:tid 255179] [client 20.206.105.145:38506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9MMf7v0rlcEGmVraFFRAAAA1Q"]
[Tue Jul 21 07:38:41.827235 2026] [security2:error] [pid 255769:tid 255899] [client 20.226.60.151:8607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MMbxMYwyVGnfuwsKhlAAAA6M"]
[Tue Jul 21 07:38:41.893295 2026] [security2:error] [pid 255769:tid 255906] [client 20.151.10.161:46059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/koala.php"] [unique_id "al9MMbxMYwyVGnfuwsKhlgAAA6o"]
[Tue Jul 21 07:38:41.914161 2026] [security2:error] [pid 255769:tid 255967] [client 4.204.201.85:55950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/chosen.php"] [unique_id "al9MMbxMYwyVGnfuwsKhlwAAA-c"]
[Tue Jul 21 07:38:41.938106 2026] [security2:error] [pid 255769:tid 255959] [client 20.226.60.151:8578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/f6.php"] [unique_id "al9MMbxMYwyVGnfuwsKhmAAAA98"]
[Tue Jul 21 07:38:42.027968 2026] [security2:error] [pid 254995:tid 255206] [client 20.226.60.151:27369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-blog.php"] [unique_id "al9MMv7v0rlcEGmVraFFSAAAA28"]
[Tue Jul 21 07:38:42.030059 2026] [security2:error] [pid 255769:tid 255923] [client 20.226.60.151:8600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/inputs.php"] [unique_id "al9MMrxMYwyVGnfuwsKhmQAAA7s"]
[Tue Jul 21 07:38:42.085403 2026] [security2:error] [pid 254995:tid 255137] [client 20.220.225.223:38713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/ops.php"] [unique_id "al9MMv7v0rlcEGmVraFFSQAAAyo"]
[Tue Jul 21 07:38:42.162688 2026] [security2:error] [pid 255769:tid 256018] [client 20.226.60.151:8616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/inputs.php"] [unique_id "al9MMrxMYwyVGnfuwsKhmwAABBg"]
[Tue Jul 21 07:38:42.205124 2026] [security2:error] [pid 255769:tid 256005] [client 20.226.60.151:8662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/classwithtostring.php"] [unique_id "al9MMrxMYwyVGnfuwsKhnAAABAs"]
[Tue Jul 21 07:38:42.220631 2026] [security2:error] [pid 254995:tid 255176] [client 20.226.60.151:8576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9MMv7v0rlcEGmVraFFTQAAA1E"]
[Tue Jul 21 07:38:42.247345 2026] [security2:error] [pid 255769:tid 255999] [client 20.226.60.151:8644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/wp-blog.php"] [unique_id "al9MMrxMYwyVGnfuwsKhnQAABAU"]
[Tue Jul 21 07:38:42.274630 2026] [proxy:error] [pid 254995:tid 255127] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.274708 2026] [proxy_http:error] [pid 254995:tid 255127] [client 20.226.60.151:8705] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.275265 2026] [proxy:error] [pid 254995:tid 255127] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.275292 2026] [proxy_http:error] [pid 254995:tid 255127] [client 20.226.60.151:8705] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.296327 2026] [security2:error] [pid 254995:tid 255141] [client 20.226.60.151:8677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MMv7v0rlcEGmVraFFTwAAAy4"]
[Tue Jul 21 07:38:42.322142 2026] [security2:error] [pid 255769:tid 256028] [client 20.226.60.151:8667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/ms-edit.php"] [unique_id "al9MMrxMYwyVGnfuwsKhngAABCI"]
[Tue Jul 21 07:38:42.341205 2026] [security2:error] [pid 254995:tid 255216] [client 20.226.60.151:8591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9MMv7v0rlcEGmVraFFUQAAA3g"]
[Tue Jul 21 07:38:42.387609 2026] [proxy:error] [pid 254995:tid 255162] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.387683 2026] [proxy_http:error] [pid 254995:tid 255162] [client 20.226.60.151:8674] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.388305 2026] [proxy:error] [pid 254995:tid 255162] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.388331 2026] [proxy_http:error] [pid 254995:tid 255162] [client 20.226.60.151:8674] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.408859 2026] [security2:error] [pid 254995:tid 255258] [client 20.226.60.151:8738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9MMv7v0rlcEGmVraFFVgAAA4g"]
[Tue Jul 21 07:38:42.427436 2026] [proxy:error] [pid 254995:tid 255184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.427513 2026] [proxy_http:error] [pid 254995:tid 255184] [client 20.226.60.151:8711] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.428195 2026] [proxy:error] [pid 254995:tid 255184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.428229 2026] [proxy_http:error] [pid 254995:tid 255184] [client 20.226.60.151:8711] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.433282 2026] [security2:error] [pid 255769:tid 256025] [client 20.151.10.161:45964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/mac.php"] [unique_id "al9MMrxMYwyVGnfuwsKhoAAABB8"]
[Tue Jul 21 07:38:42.450117 2026] [proxy:error] [pid 255769:tid 255982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.450201 2026] [proxy_http:error] [pid 255769:tid 255982] [client 20.226.60.151:8603] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.451254 2026] [proxy:error] [pid 255769:tid 255982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.451310 2026] [proxy_http:error] [pid 255769:tid 255982] [client 20.226.60.151:8603] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.469771 2026] [security2:error] [pid 255769:tid 256004] [client 20.226.60.151:8718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/abcd.php"] [unique_id "al9MMrxMYwyVGnfuwsKhogAABAo"]
[Tue Jul 21 07:38:42.485051 2026] [autoindex:error] [pid 255769:tid 255940] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:42.507519 2026] [security2:error] [pid 255769:tid 255998] [client 20.226.60.151:8608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/file15.php"] [unique_id "al9MMrxMYwyVGnfuwsKhpgAABAQ"]
[Tue Jul 21 07:38:42.554507 2026] [security2:error] [pid 255769:tid 255984] [client 20.226.60.151:8671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/jp.php"] [unique_id "al9MMrxMYwyVGnfuwsKhqQAAA_g"]
[Tue Jul 21 07:38:42.573041 2026] [security2:error] [pid 254995:tid 255195] [client 128.127.105.184:60942] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MMv7v0rlcEGmVraFFWAAAA2Q"]
[Tue Jul 21 07:38:42.573122 2026] [security2:error] [pid 254995:tid 255195] [client 128.127.105.184:60942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MMv7v0rlcEGmVraFFWAAAA2Q"]
[Tue Jul 21 07:38:42.580635 2026] [security2:error] [pid 254995:tid 255214] [client 20.226.60.151:8647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/f35.php"] [unique_id "al9MMv7v0rlcEGmVraFFWQAAA3Y"]
[Tue Jul 21 07:38:42.597995 2026] [security2:error] [pid 254995:tid 255138] [client 20.226.60.151:8672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/wp-load.php"] [unique_id "al9MMv7v0rlcEGmVraFFWgAAAys"]
[Tue Jul 21 07:38:42.651768 2026] [security2:error] [pid 255769:tid 255918] [client 103.174.34.15:61959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MMrxMYwyVGnfuwsKhqgAAA7Y"]
[Tue Jul 21 07:38:42.651926 2026] [security2:error] [pid 255769:tid 255918] [client 103.174.34.15:61959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MMrxMYwyVGnfuwsKhqgAAA7Y"]
[Tue Jul 21 07:38:42.654272 2026] [security2:error] [pid 255769:tid 256016] [client 20.226.60.151:8706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/xyn.php"] [unique_id "al9MMrxMYwyVGnfuwsKhqwAABBY"]
[Tue Jul 21 07:38:42.680279 2026] [proxy:error] [pid 255769:tid 256001] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.680364 2026] [proxy_http:error] [pid 255769:tid 256001] [client 20.226.60.151:8714] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.681453 2026] [proxy:error] [pid 255769:tid 256001] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.681516 2026] [proxy_http:error] [pid 255769:tid 256001] [client 20.226.60.151:8714] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.753526 2026] [proxy:error] [pid 255769:tid 256012] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.753621 2026] [proxy_http:error] [pid 255769:tid 256012] [client 20.226.60.151:8582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.754937 2026] [proxy:error] [pid 255769:tid 256012] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.754994 2026] [proxy_http:error] [pid 255769:tid 256012] [client 20.226.60.151:8582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.759777 2026] [security2:error] [pid 255769:tid 255934] [client 4.204.201.85:55965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/als.php"] [unique_id "al9MMrxMYwyVGnfuwsKhrgAAA8Y"]
[Tue Jul 21 07:38:42.800651 2026] [security2:error] [pid 254995:tid 255261] [client 20.226.60.151:8653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/ccc.php"] [unique_id "al9MMv7v0rlcEGmVraFFXwAAA4s"]
[Tue Jul 21 07:38:42.822140 2026] [security2:error] [pid 254995:tid 255155] [client 103.86.117.203:57762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MMv7v0rlcEGmVraFFYAAAAzw"]
[Tue Jul 21 07:38:42.822294 2026] [security2:error] [pid 254995:tid 255155] [client 103.86.117.203:57762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MMv7v0rlcEGmVraFFYAAAAzw"]
[Tue Jul 21 07:38:42.934093 2026] [security2:error] [pid 255769:tid 255942] [client 20.226.60.151:8675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/w.php"] [unique_id "al9MMrxMYwyVGnfuwsKhsQAAA84"]
[Tue Jul 21 07:38:42.971533 2026] [security2:error] [pid 254995:tid 255181] [client 128.127.105.184:60948] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MMv7v0rlcEGmVraFFZQAAA1Y"]
[Tue Jul 21 07:38:42.971649 2026] [security2:error] [pid 254995:tid 255181] [client 128.127.105.184:60948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MMv7v0rlcEGmVraFFZQAAA1Y"]
[Tue Jul 21 07:38:42.974692 2026] [security2:error] [pid 255769:tid 255911] [client 20.226.60.151:8625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9MMrxMYwyVGnfuwsKhsgAAA68"]
[Tue Jul 21 07:38:43.022124 2026] [security2:error] [pid 255769:tid 255958] [client 20.226.60.151:8611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/FWAZ.php"] [unique_id "al9MM7xMYwyVGnfuwsKhtQAAA94"]
[Tue Jul 21 07:38:43.037491 2026] [security2:error] [pid 255769:tid 255972] [client 4.204.201.85:57168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/pol.php"] [unique_id "al9MM7xMYwyVGnfuwsKhtgAAA-w"]
[Tue Jul 21 07:38:43.054475 2026] [security2:error] [pid 255769:tid 255917] [client 20.226.60.151:8743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/miru1.php"] [unique_id "al9MM7xMYwyVGnfuwsKhtwAAA7U"]
[Tue Jul 21 07:38:43.072259 2026] [security2:error] [pid 254995:tid 255259] [client 59.96.220.140:63065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MM_7v0rlcEGmVraFFZgAAA4k"]
[Tue Jul 21 07:38:43.072846 2026] [security2:error] [pid 254995:tid 255259] [client 59.96.220.140:63065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MM_7v0rlcEGmVraFFZgAAA4k"]
[Tue Jul 21 07:38:43.164412 2026] [security2:error] [pid 254995:tid 255150] [client 20.226.60.151:8613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/aa.php"] [unique_id "al9MM_7v0rlcEGmVraFFaAAAAzc"]
[Tue Jul 21 07:38:43.226668 2026] [security2:error] [pid 255769:tid 256005] [client 20.226.60.151:27535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MM7xMYwyVGnfuwsKhvQAABAs"]
[Tue Jul 21 07:38:43.241650 2026] [security2:error] [pid 254995:tid 255154] [client 20.226.60.151:8636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/122.php"] [unique_id "al9MM_7v0rlcEGmVraFFaQAAAzs"]
[Tue Jul 21 07:38:43.319195 2026] [security2:error] [pid 254995:tid 255140] [client 4.204.201.85:57089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/file5.php"] [unique_id "al9MM_7v0rlcEGmVraFFagAAAy0"]
[Tue Jul 21 07:38:43.344243 2026] [security2:error] [pid 255769:tid 256013] [client 20.226.60.151:8726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/get.php"] [unique_id "al9MM7xMYwyVGnfuwsKhvgAABBM"]
[Tue Jul 21 07:38:43.407859 2026] [security2:error] [pid 255769:tid 255941] [client 20.226.60.151:8750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/as.php"] [unique_id "al9MM7xMYwyVGnfuwsKhwAAAA80"]
[Tue Jul 21 07:38:43.418972 2026] [security2:error] [pid 255769:tid 256025] [client 20.151.10.161:45983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9MM7xMYwyVGnfuwsKhwgAABB8"]
[Tue Jul 21 07:38:43.462218 2026] [security2:error] [pid 254995:tid 255219] [client 20.226.60.151:51296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/yas.php"] [unique_id "al9MM_7v0rlcEGmVraFFbQAAA3s"]
[Tue Jul 21 07:38:43.489793 2026] [security2:error] [pid 255769:tid 255940] [client 20.226.60.151:8689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/ccou.php"] [unique_id "al9MM7xMYwyVGnfuwsKhxAAAA8w"]
[Tue Jul 21 07:38:43.521054 2026] [security2:error] [pid 254995:tid 255014] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MM_7v0rlcEGmVraFFbgADjhI"]
[Tue Jul 21 07:38:43.521168 2026] [security2:error] [pid 254995:tid 255264] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MM_7v0rlcEGmVraFFbgADjhI"]
[Tue Jul 21 07:38:43.526525 2026] [security2:error] [pid 254995:tid 255149] [client 20.206.105.145:38522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/file.php"] [unique_id "al9MM_7v0rlcEGmVraFFbwAAAzY"]
[Tue Jul 21 07:38:43.660247 2026] [security2:error] [pid 255769:tid 255984] [client 20.226.60.151:8586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/w3lls.php"] [unique_id "al9MM7xMYwyVGnfuwsKhyAAAA_g"]
[Tue Jul 21 07:38:43.761246 2026] [security2:error] [pid 255769:tid 255971] [client 20.226.60.151:27374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ms-edit.php"] [unique_id "al9MM7xMYwyVGnfuwsKhygAAA-s"]
[Tue Jul 21 07:38:43.804757 2026] [security2:error] [pid 255769:tid 255943] [client 4.204.201.85:55539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/file.php"] [unique_id "al9MM7xMYwyVGnfuwsKhywAAA88"]
[Tue Jul 21 07:38:43.882054 2026] [security2:error] [pid 255769:tid 255966] [client 20.226.60.151:8716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/test1.php"] [unique_id "al9MM7xMYwyVGnfuwsKhzAAAA-Y"]
[Tue Jul 21 07:38:44.004803 2026] [security2:error] [pid 255769:tid 255901] [client 20.226.60.151:8708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/database.php"] [unique_id "al9MNLxMYwyVGnfuwsKh0AAAA6U"]
[Tue Jul 21 07:38:44.029872 2026] [security2:error] [pid 255769:tid 255974] [client 82.169.226.84:62889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.226.169.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "heyidiomas.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MM7xMYwyVGnfuwsKhtAAAA-4"]
[Tue Jul 21 07:38:44.030042 2026] [security2:error] [pid 255769:tid 255974] [client 82.169.226.84:62889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "heyidiomas.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MM7xMYwyVGnfuwsKhtAAAA-4"]
[Tue Jul 21 07:38:44.089739 2026] [security2:error] [pid 255769:tid 255942] [client 4.204.201.85:55953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/cfile.php"] [unique_id "al9MNLxMYwyVGnfuwsKh1AAAA84"]
[Tue Jul 21 07:38:44.103882 2026] [core:error] [pid 255769:tid 255979] [client 66.249.66.67:60864] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:38:44.103904 2026] [core:error] [pid 255769:tid 255979] [client 66.249.66.67:60864] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:38:44.167765 2026] [security2:error] [pid 254995:tid 255192] [client 20.151.10.161:45986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wefile.php"] [unique_id "al9MNP7v0rlcEGmVraFFfAAAA2E"]
[Tue Jul 21 07:38:44.216344 2026] [security2:error] [pid 255769:tid 255917] [client 20.226.60.151:27390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9MNLxMYwyVGnfuwsKh2gAAA7U"]
[Tue Jul 21 07:38:44.247244 2026] [security2:error] [pid 255769:tid 256018] [client 20.226.60.151:8729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/file.php"] [unique_id "al9MNLxMYwyVGnfuwsKh3gAABBg"]
[Tue Jul 21 07:38:44.326237 2026] [security2:error] [pid 254995:tid 255137] [client 20.226.60.151:8663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/file.php"] [unique_id "al9MNP7v0rlcEGmVraFFgQAAAyo"]
[Tue Jul 21 07:38:44.371705 2026] [security2:error] [pid 255769:tid 255994] [client 4.204.201.85:55995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/admin.php"] [unique_id "al9MNLxMYwyVGnfuwsKh4AAABAE"]
[Tue Jul 21 07:38:44.377438 2026] [security2:error] [pid 254995:tid 255209] [client 20.226.60.151:8698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/777.php"] [unique_id "al9MNP7v0rlcEGmVraFFhAAAA3E"]
[Tue Jul 21 07:38:44.430470 2026] [security2:error] [pid 254995:tid 255180] [client 20.226.60.151:8622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/ssixta.php"] [unique_id "al9MNP7v0rlcEGmVraFFhwAAA1U"]
[Tue Jul 21 07:38:44.446880 2026] [security2:error] [pid 254995:tid 255256] [client 20.226.60.151:8684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/1c.php"] [unique_id "al9MNP7v0rlcEGmVraFFiAAAA4Y"]
[Tue Jul 21 07:38:44.511355 2026] [security2:error] [pid 255769:tid 255982] [client 20.226.60.151:8740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/test2.php"] [unique_id "al9MNLxMYwyVGnfuwsKh4gAAA_Y"]
[Tue Jul 21 07:38:44.580474 2026] [security2:error] [pid 254995:tid 255193] [client 20.226.60.151:8686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/buy.php"] [unique_id "al9MNP7v0rlcEGmVraFFjgAAA2I"]
[Tue Jul 21 07:38:44.672619 2026] [security2:error] [pid 254995:tid 255188] [client 4.204.201.85:57147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/aa2.php"] [unique_id "al9MNP7v0rlcEGmVraFFkwAAA10"]
[Tue Jul 21 07:38:44.715855 2026] [security2:error] [pid 254995:tid 255271] [client 20.226.60.151:9043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/ssend.php"] [unique_id "al9MNP7v0rlcEGmVraFFmAAAA5U"]
[Tue Jul 21 07:38:44.768334 2026] [security2:error] [pid 254995:tid 255156] [client 20.226.60.151:8760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/item.php"] [unique_id "al9MNP7v0rlcEGmVraFFmwAAAz0"]
[Tue Jul 21 07:38:44.795161 2026] [security2:error] [pid 254995:tid 255273] [client 20.226.60.151:8759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/ss.php"] [unique_id "al9MNP7v0rlcEGmVraFFnQAAA5c"]
[Tue Jul 21 07:38:44.837846 2026] [security2:error] [pid 254995:tid 255229] [client 20.226.60.151:8619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/hypo.php"] [unique_id "al9MNP7v0rlcEGmVraFFngAAA4I"]
[Tue Jul 21 07:38:44.897469 2026] [security2:error] [pid 255769:tid 255902] [client 20.226.60.151:9052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/users.php"] [unique_id "al9MNLxMYwyVGnfuwsKh4wAAA6Y"]
[Tue Jul 21 07:38:44.915423 2026] [security2:error] [pid 254995:tid 255265] [client 20.226.60.151:27579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9MNP7v0rlcEGmVraFFvwAAA48"]
[Tue Jul 21 07:38:44.923470 2026] [autoindex:error] [pid 255769:tid 255961] [client 195.154.254.70:60568] AH01276: Cannot serve directory /home2/onfiel33/kotovicz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:44.948273 2026] [security2:error] [pid 255769:tid 256001] [client 20.226.60.151:8727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/177.php"] [unique_id "al9MNLxMYwyVGnfuwsKh5wAABAc"]
[Tue Jul 21 07:38:44.970805 2026] [security2:error] [pid 254995:tid 255181] [client 4.204.201.85:61265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/ccou.php"] [unique_id "al9MNP7v0rlcEGmVraFFwQAAA1Y"]
[Tue Jul 21 07:38:44.985882 2026] [security2:error] [pid 255769:tid 255928] [client 20.226.60.151:8717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/config.php"] [unique_id "al9MNLxMYwyVGnfuwsKh6AAAA8A"]
[Tue Jul 21 07:38:45.026344 2026] [security2:error] [pid 255769:tid 255908] [client 20.226.60.151:8635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/gettest.php"] [unique_id "al9MNbxMYwyVGnfuwsKh6QAAA6w"]
[Tue Jul 21 07:38:45.116515 2026] [security2:error] [pid 254995:tid 255277] [client 20.151.10.161:46017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9MNf7v0rlcEGmVraFFwgAAA5s"]
[Tue Jul 21 07:38:45.141080 2026] [security2:error] [pid 255769:tid 255918] [client 193.36.225.57:22003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MNbxMYwyVGnfuwsKh6gAAA7Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:45.162873 2026] [security2:error] [pid 255769:tid 255974] [client 20.226.60.151:8693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/min.php"] [unique_id "al9MNbxMYwyVGnfuwsKh6wAAA-4"]
[Tue Jul 21 07:38:45.196458 2026] [security2:error] [pid 255769:tid 255899] [client 20.226.60.151:8691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/dvjul.php"] [unique_id "al9MNbxMYwyVGnfuwsKh7AAAA6M"]
[Tue Jul 21 07:38:45.249352 2026] [security2:error] [pid 254995:tid 255199] [client 20.226.60.151:8618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/biufile.php"] [unique_id "al9MNf7v0rlcEGmVraFFxQAAA2g"]
[Tue Jul 21 07:38:45.267857 2026] [security2:error] [pid 255769:tid 255911] [client 4.204.201.85:55995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/dr.php"] [unique_id "al9MNbxMYwyVGnfuwsKh7gAAA68"]
[Tue Jul 21 07:38:45.280480 2026] [security2:error] [pid 255769:tid 255958] [client 20.226.60.151:8682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/av.php"] [unique_id "al9MNbxMYwyVGnfuwsKh7wAAA94"]
[Tue Jul 21 07:38:45.345476 2026] [security2:error] [pid 255769:tid 255870] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MNbxMYwyVGnfuwsKh8AAD9WQ"]
[Tue Jul 21 07:38:45.345645 2026] [security2:error] [pid 255769:tid 255981] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MNbxMYwyVGnfuwsKh8AAD9WQ"]
[Tue Jul 21 07:38:45.365212 2026] [security2:error] [pid 254995:tid 255140] [client 20.226.60.151:8710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/coffexium.php"] [unique_id "al9MNf7v0rlcEGmVraFFywAAAy0"]
[Tue Jul 21 07:38:45.498374 2026] [security2:error] [pid 255769:tid 256018] [client 20.206.105.145:38094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/cfile.php"] [unique_id "al9MNbxMYwyVGnfuwsKh8wAABBg"]
[Tue Jul 21 07:38:45.505186 2026] [security2:error] [pid 255769:tid 256005] [client 20.226.60.151:8735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/core.php"] [unique_id "al9MNbxMYwyVGnfuwsKh9AAABAs"]
[Tue Jul 21 07:38:45.515721 2026] [autoindex:error] [pid 255769:tid 255946] [client 195.154.254.70:35984] AH01276: Cannot serve directory /home2/onfiel33/kotovicz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:45.535982 2026] [security2:error] [pid 255769:tid 255932] [client 139.167.225.182:51718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MNbxMYwyVGnfuwsKh9gAAA8Q"]
[Tue Jul 21 07:38:45.536116 2026] [security2:error] [pid 255769:tid 255932] [client 139.167.225.182:51718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MNbxMYwyVGnfuwsKh9gAAA8Q"]
[Tue Jul 21 07:38:45.576586 2026] [security2:error] [pid 255769:tid 255997] [client 194.99.104.35:46542] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MNbxMYwyVGnfuwsKh-AAABAM"]
[Tue Jul 21 07:38:45.576681 2026] [security2:error] [pid 255769:tid 255997] [client 194.99.104.35:46542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MNbxMYwyVGnfuwsKh-AAABAM"]
[Tue Jul 21 07:38:45.596570 2026] [security2:error] [pid 255769:tid 255871] [remote 72.167.132.114:48850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9MNbxMYwyVGnfuwsKh-QADzmU"]
[Tue Jul 21 07:38:45.645110 2026] [security2:error] [pid 255769:tid 255941] [client 4.204.201.85:57116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/xamp.php"] [unique_id "al9MNbxMYwyVGnfuwsKh-gAAA80"]
[Tue Jul 21 07:38:45.657840 2026] [security2:error] [pid 255769:tid 255966] [client 117.217.38.194:55572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MNbxMYwyVGnfuwsKh-wAAA-Y"]
[Tue Jul 21 07:38:45.657964 2026] [security2:error] [pid 255769:tid 255966] [client 117.217.38.194:55572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MNbxMYwyVGnfuwsKh-wAAA-Y"]
[Tue Jul 21 07:38:45.660493 2026] [security2:error] [pid 255769:tid 255983] [client 20.226.60.151:9082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/als.php"] [unique_id "al9MNbxMYwyVGnfuwsKh_AAAA_c"]
[Tue Jul 21 07:38:45.776312 2026] [security2:error] [pid 255769:tid 255938] [client 20.226.60.151:8601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/simple.php"] [unique_id "al9MNbxMYwyVGnfuwsKh_wAAA8o"]
[Tue Jul 21 07:38:45.853061 2026] [security2:error] [pid 255769:tid 255944] [client 20.226.60.151:56225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/mac.php"] [unique_id "al9MNbxMYwyVGnfuwsKiAAAAA9A"]
[Tue Jul 21 07:38:45.859589 2026] [security2:error] [pid 255769:tid 255907] [client 20.151.10.161:45997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/2P.php"] [unique_id "al9MNbxMYwyVGnfuwsKiAQAAA6s"]
[Tue Jul 21 07:38:45.933901 2026] [security2:error] [pid 255769:tid 256022] [client 4.204.201.85:57115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/bless.php"] [unique_id "al9MNbxMYwyVGnfuwsKiAwAABBw"]
[Tue Jul 21 07:38:45.978046 2026] [security2:error] [pid 255769:tid 255930] [client 20.226.60.151:8673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/init.php"] [unique_id "al9MNbxMYwyVGnfuwsKiBQAAA8I"]
[Tue Jul 21 07:38:46.036399 2026] [security2:error] [pid 255769:tid 255908] [client 20.226.60.151:51389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/file61.php"] [unique_id "al9MNrxMYwyVGnfuwsKiBwAAA6w"]
[Tue Jul 21 07:38:46.118208 2026] [security2:error] [pid 255769:tid 255831] [remote 212.47.76.178:50774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.76.47.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "domuscondominios.com.br"] [uri "/wp-login.php"] [unique_id "al9MNrxMYwyVGnfuwsKiCQAD-z0"]
[Tue Jul 21 07:38:46.246607 2026] [security2:error] [pid 254995:tid 255268] [client 74.7.175.145:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.polianoduarteramos1782911169000.lojaracompressores.com.br"] [uri "/index.php"] [unique_id "al9MNP7v0rlcEGmVraFFjAAAA5I"]
[Tue Jul 21 07:38:46.247421 2026] [security2:error] [pid 254995:tid 255166] [client 74.7.175.145:55402] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.polianoduarteramos1782911169000.lojaracompressores.com.br"] [uri "/robots.txt"] [unique_id "al9MNP7v0rlcEGmVraFFiQADRys"]
[Tue Jul 21 07:38:46.266298 2026] [security2:error] [pid 254995:tid 255203] [client 20.226.60.151:8666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/fpwch.php"] [unique_id "al9MNv7v0rlcEGmVraFF2QAAA2w"]
[Tue Jul 21 07:38:46.274448 2026] [security2:error] [pid 254995:tid 255278] [client 20.226.60.151:27555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/abcd.php"] [unique_id "al9MNv7v0rlcEGmVraFF2wAAA5w"]
[Tue Jul 21 07:38:46.306099 2026] [security2:error] [pid 255769:tid 256000] [client 4.204.201.85:57192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/file25.php"] [unique_id "al9MNrxMYwyVGnfuwsKiEgAABAY"]
[Tue Jul 21 07:38:46.390858 2026] [security2:error] [pid 255769:tid 256015] [client 20.226.60.151:55308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/water.php"] [unique_id "al9MNrxMYwyVGnfuwsKiEwAABBU"]
[Tue Jul 21 07:38:46.536169 2026] [security2:error] [pid 255769:tid 256013] [client 20.226.60.151:8614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/domvf.php"] [unique_id "al9MNrxMYwyVGnfuwsKiFQAABBM"]
[Tue Jul 21 07:38:46.563979 2026] [security2:error] [pid 255769:tid 255994] [client 20.151.10.161:46035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/.well-known/about.php"] [unique_id "al9MNrxMYwyVGnfuwsKiFgAABAE"]
[Tue Jul 21 07:38:46.615033 2026] [security2:error] [pid 255769:tid 255941] [client 4.204.201.85:57197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/file6.php"] [unique_id "al9MNrxMYwyVGnfuwsKiGQAAA80"]
[Tue Jul 21 07:38:46.757656 2026] [security2:error] [pid 255769:tid 256026] [client 20.206.105.145:37891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/class-wp.php"] [unique_id "al9MNrxMYwyVGnfuwsKiHgAABCA"]
[Tue Jul 21 07:38:46.789171 2026] [security2:error] [pid 254995:tid 255138] [client 20.226.60.151:8679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/wp.php"] [unique_id "al9MNv7v0rlcEGmVraFF5QAAAys"]
[Tue Jul 21 07:38:46.848325 2026] [security2:error] [pid 254995:tid 255142] [client 20.220.225.223:31198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/term.php"] [unique_id "al9MNv7v0rlcEGmVraFF6AAAAy8"]
[Tue Jul 21 07:38:46.925730 2026] [security2:error] [pid 254995:tid 255212] [client 4.204.201.85:55497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/a2.php"] [unique_id "al9MNv7v0rlcEGmVraFF6QAAA3Q"]
[Tue Jul 21 07:38:46.975277 2026] [security2:error] [pid 254995:tid 255215] [client 173.24.185.52:59932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MNv7v0rlcEGmVraFF6gAAA3c"]
[Tue Jul 21 07:38:46.975424 2026] [security2:error] [pid 254995:tid 255215] [client 173.24.185.52:59932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MNv7v0rlcEGmVraFF6gAAA3c"]
[Tue Jul 21 07:38:47.052370 2026] [security2:error] [pid 254995:tid 255174] [client 74.7.244.49:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "polianoduarteramos1782911169000.0721679.meusitehostgator.com.br"] [uri "/index.php"] [unique_id "al9MNv7v0rlcEGmVraFF4AADTyg"]
[Tue Jul 21 07:38:47.060348 2026] [security2:error] [pid 255769:tid 255914] [client 106.215.181.8:22574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MN7xMYwyVGnfuwsKiIgAAA7I"]
[Tue Jul 21 07:38:47.060540 2026] [security2:error] [pid 255769:tid 255914] [client 106.215.181.8:22574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MN7xMYwyVGnfuwsKiIgAAA7I"]
[Tue Jul 21 07:38:47.076532 2026] [security2:error] [pid 254995:tid 255155] [client 20.226.60.151:51328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/nano.php"] [unique_id "al9MN_7v0rlcEGmVraFF7gAAAzw"]
[Tue Jul 21 07:38:47.192320 2026] [security2:error] [pid 254995:tid 255128] [client 20.226.60.151:9058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/class.php"] [unique_id "al9MN_7v0rlcEGmVraFF8wAAAyE"]
[Tue Jul 21 07:38:47.208129 2026] [security2:error] [pid 254995:tid 255187] [client 4.204.201.85:57107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/file15.php"] [unique_id "al9MN_7v0rlcEGmVraFF9AAAA1w"]
[Tue Jul 21 07:38:47.452218 2026] [security2:error] [pid 255769:tid 255901] [client 20.226.60.151:27337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/file15.php"] [unique_id "al9MN7xMYwyVGnfuwsKiKgAAA6U"]
[Tue Jul 21 07:38:47.504836 2026] [security2:error] [pid 255769:tid 255974] [client 4.204.201.85:57176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/f35.php"] [unique_id "al9MN7xMYwyVGnfuwsKiKwAAA-4"]
[Tue Jul 21 07:38:47.590420 2026] [security2:error] [pid 254995:tid 255254] [client 20.226.60.151:8709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/echkm.php"] [unique_id "al9MN_7v0rlcEGmVraFGBQAAA4Q"]
[Tue Jul 21 07:38:47.782386 2026] [security2:error] [pid 255769:tid 255911] [client 4.204.201.85:57154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-load.php"] [unique_id "al9MN7xMYwyVGnfuwsKiLAAAA68"]
[Tue Jul 21 07:38:47.834702 2026] [security2:error] [pid 255769:tid 255987] [client 20.226.60.151:56226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/mg.php"] [unique_id "al9MN7xMYwyVGnfuwsKiLQAAA_s"]
[Tue Jul 21 07:38:48.001022 2026] [security2:error] [pid 255769:tid 255950] [client 20.151.10.161:46043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9MOLxMYwyVGnfuwsKiMAAAA9Y"]
[Tue Jul 21 07:38:48.032483 2026] [security2:error] [pid 255769:tid 256003] [client 20.206.105.145:37914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/admin.php"] [unique_id "al9MOLxMYwyVGnfuwsKiMgAABAk"]
[Tue Jul 21 07:38:48.037312 2026] [security2:error] [pid 254995:tid 255143] [client 216.24.219.119:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "naldoinvest.com.br"] [uri "/wp-login.php"] [unique_id "al9MNf7v0rlcEGmVraFFzAADMCU"]
[Tue Jul 21 07:38:48.079584 2026] [security2:error] [pid 255769:tid 255986] [client 20.226.60.151:9037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/lib.php"] [unique_id "al9MOLxMYwyVGnfuwsKiMwAAA_o"]
[Tue Jul 21 07:38:48.093248 2026] [security2:error] [pid 255769:tid 255857] [remote 41.76.214.143:37238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lp.agenciawats.com.br"] [uri "/wp-login.php"] [unique_id "al9MOLxMYwyVGnfuwsKiNAADtlc"]
[Tue Jul 21 07:38:48.108378 2026] [security2:error] [pid 255769:tid 255937] [client 4.204.201.85:55535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/xwpg.php"] [unique_id "al9MOLxMYwyVGnfuwsKiOAAAA8k"]
[Tue Jul 21 07:38:48.176660 2026] [security2:error] [pid 254995:tid 255204] [client 122.186.204.214:61221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MOP7v0rlcEGmVraFGDAAAA20"]
[Tue Jul 21 07:38:48.176801 2026] [security2:error] [pid 254995:tid 255204] [client 122.186.204.214:61221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MOP7v0rlcEGmVraFGDAAAA20"]
[Tue Jul 21 07:38:48.337314 2026] [security2:error] [pid 255769:tid 255807] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MOLxMYwyVGnfuwsKiPgAD_iU"]
[Tue Jul 21 07:38:48.337486 2026] [security2:error] [pid 255769:tid 255990] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MOLxMYwyVGnfuwsKiPgAD_iU"]
[Tue Jul 21 07:38:48.338990 2026] [security2:error] [pid 255769:tid 255994] [client 20.226.60.151:8725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/login.php"] [unique_id "al9MOLxMYwyVGnfuwsKiPwAABAE"]
[Tue Jul 21 07:38:48.384173 2026] [security2:error] [pid 255769:tid 255932] [client 20.226.60.151:61213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/moon.php"] [unique_id "al9MOLxMYwyVGnfuwsKiQQAAA8Q"]
[Tue Jul 21 07:38:48.399980 2026] [security2:error] [pid 255769:tid 255979] [client 152.59.154.239:61176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MOLxMYwyVGnfuwsKiRQAAA_M"]
[Tue Jul 21 07:38:48.400131 2026] [security2:error] [pid 255769:tid 255979] [client 152.59.154.239:61176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MOLxMYwyVGnfuwsKiRQAAA_M"]
[Tue Jul 21 07:38:48.403154 2026] [autoindex:error] [pid 255769:tid 255941] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:48.443052 2026] [security2:error] [pid 254995:tid 255206] [client 20.197.192.193:6866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/ez.php"] [unique_id "al9MOP7v0rlcEGmVraFGEAAAA28"]
[Tue Jul 21 07:38:48.449965 2026] [security2:error] [pid 255769:tid 255899] [client 117.251.86.144:55810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MOLxMYwyVGnfuwsKiRgAAA6M"]
[Tue Jul 21 07:38:48.450079 2026] [security2:error] [pid 255769:tid 255899] [client 117.251.86.144:55810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MOLxMYwyVGnfuwsKiRgAAA6M"]
[Tue Jul 21 07:38:48.578868 2026] [security2:error] [pid 255769:tid 255973] [client 20.226.60.151:8597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/a2.php"] [unique_id "al9MOLxMYwyVGnfuwsKiSAAAA-0"]
[Tue Jul 21 07:38:48.761789 2026] [autoindex:error] [pid 255769:tid 255907] [client 4.204.201.85:61297] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:48.802109 2026] [security2:error] [pid 255769:tid 255830] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MOLxMYwyVGnfuwsKiTwAEGzw"]
[Tue Jul 21 07:38:48.802260 2026] [security2:error] [pid 255769:tid 256021] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MOLxMYwyVGnfuwsKiTwAEGzw"]
[Tue Jul 21 07:38:48.899983 2026] [security2:error] [pid 255769:tid 255920] [client 4.204.201.85:61297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/xstelth.php"] [unique_id "al9MOLxMYwyVGnfuwsKiUQAAA7g"]
[Tue Jul 21 07:38:49.060088 2026] [security2:error] [pid 255769:tid 255971] [client 20.226.60.151:8699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/d61.php"] [unique_id "al9MObxMYwyVGnfuwsKiVAAAA-s"]
[Tue Jul 21 07:38:49.193793 2026] [security2:error] [pid 255769:tid 255900] [client 4.204.201.85:57172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9MObxMYwyVGnfuwsKiVwAAA6Q"]
[Tue Jul 21 07:38:49.358466 2026] [security2:error] [pid 255769:tid 255838] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MObxMYwyVGnfuwsKiWQADpUQ"]
[Tue Jul 21 07:38:49.358629 2026] [security2:error] [pid 255769:tid 255901] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MObxMYwyVGnfuwsKiWQADpUQ"]
[Tue Jul 21 07:38:49.406215 2026] [security2:error] [pid 254995:tid 255168] [client 20.197.192.193:6850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/fz.php"] [unique_id "al9MOf7v0rlcEGmVraFGGwAAA0k"]
[Tue Jul 21 07:38:49.411962 2026] [security2:error] [pid 254995:tid 255135] [client 20.226.60.151:9066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/info.php"] [unique_id "al9MOf7v0rlcEGmVraFGHAAAAyg"]
[Tue Jul 21 07:38:49.523753 2026] [security2:error] [pid 254995:tid 255258] [client 4.204.201.85:57130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/aaa.php"] [unique_id "al9MOf7v0rlcEGmVraFGIAAAA4g"]
[Tue Jul 21 07:38:49.570147 2026] [security2:error] [pid 254995:tid 255208] [client 20.226.60.151:27562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/jp.php"] [unique_id "al9MOf7v0rlcEGmVraFGIgAAA3A"]
[Tue Jul 21 07:38:49.715536 2026] [security2:error] [pid 254995:tid 255210] [client 193.36.225.69:51325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MOf7v0rlcEGmVraFGKQAAA3I"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:49.843618 2026] [security2:error] [pid 255769:tid 255968] [client 4.204.201.85:57128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/gecko.php"] [unique_id "al9MObxMYwyVGnfuwsKiXAAAA-g"]
[Tue Jul 21 07:38:49.907891 2026] [security2:error] [pid 254995:tid 255275] [client 20.226.60.151:8633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/11.php"] [unique_id "al9MOf7v0rlcEGmVraFGKgAAA5k"]
[Tue Jul 21 07:38:50.258047 2026] [security2:error] [pid 255769:tid 255934] [client 4.204.201.85:57186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/sh3ll.php"] [unique_id "al9MOrxMYwyVGnfuwsKiXwAAA8Y"]
[Tue Jul 21 07:38:50.283298 2026] [security2:error] [pid 255769:tid 256005] [client 20.226.60.151:8589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/v2.php"] [unique_id "al9MOrxMYwyVGnfuwsKiYAAABAs"]
[Tue Jul 21 07:38:50.320102 2026] [security2:error] [pid 255769:tid 255858] [remote 45.90.123.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "printcom.com.br"] [uri "/wp-login.php"] [unique_id "al9MOrxMYwyVGnfuwsKiYQADqlg"]
[Tue Jul 21 07:38:50.497732 2026] [security2:error] [pid 255769:tid 255918] [client 154.192.233.199:59484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MOrxMYwyVGnfuwsKiZAAAA7Y"]
[Tue Jul 21 07:38:50.497845 2026] [security2:error] [pid 255769:tid 255918] [client 154.192.233.199:59484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MOrxMYwyVGnfuwsKiZAAAA7Y"]
[Tue Jul 21 07:38:50.499096 2026] [security2:error] [pid 255769:tid 255986] [client 175.45.70.82:50161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MOrxMYwyVGnfuwsKiZQAAA_o"]
[Tue Jul 21 07:38:50.499205 2026] [security2:error] [pid 255769:tid 255986] [client 175.45.70.82:50161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MOrxMYwyVGnfuwsKiZQAAA_o"]
[Tue Jul 21 07:38:50.552682 2026] [security2:error] [pid 254995:tid 255222] [client 4.204.201.85:61303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/pbck.php"] [unique_id "al9MOv7v0rlcEGmVraFGOAAAA34"]
[Tue Jul 21 07:38:50.710404 2026] [security2:error] [pid 255769:tid 255937] [client 122.164.127.47:58508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MOrxMYwyVGnfuwsKiZgAAA8k"]
[Tue Jul 21 07:38:50.710564 2026] [security2:error] [pid 255769:tid 255937] [client 122.164.127.47:58508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MOrxMYwyVGnfuwsKiZgAAA8k"]
[Tue Jul 21 07:38:50.756893 2026] [security2:error] [pid 254995:tid 255202] [client 20.226.60.151:8728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/panel.php"] [unique_id "al9MOv7v0rlcEGmVraFGPgAAA2s"]
[Tue Jul 21 07:38:50.843718 2026] [security2:error] [pid 254995:tid 255221] [client 4.204.201.85:57163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/xiugai.php"] [unique_id "al9MOv7v0rlcEGmVraFGPwAAA30"]
[Tue Jul 21 07:38:50.855804 2026] [security2:error] [pid 255769:tid 256019] [client 122.162.144.145:20853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MOrxMYwyVGnfuwsKiZwAABBk"]
[Tue Jul 21 07:38:50.855953 2026] [security2:error] [pid 255769:tid 256019] [client 122.162.144.145:20853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MOrxMYwyVGnfuwsKiZwAABBk"]
[Tue Jul 21 07:38:50.999360 2026] [security2:error] [pid 255769:tid 255914] [client 20.220.225.223:38678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/ah25.php"] [unique_id "al9MOrxMYwyVGnfuwsKibAAAA7I"]
[Tue Jul 21 07:38:51.114787 2026] [security2:error] [pid 255769:tid 255943] [client 20.226.60.151:8749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/dex.php"] [unique_id "al9MO7xMYwyVGnfuwsKibwAAA88"]
[Tue Jul 21 07:38:51.140227 2026] [security2:error] [pid 255769:tid 256021] [client 4.204.201.85:60645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/e.php"] [unique_id "al9MO7xMYwyVGnfuwsKicAAABBs"]
[Tue Jul 21 07:38:51.244626 2026] [security2:error] [pid 254995:tid 255169] [client 103.106.20.201:56240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MO_7v0rlcEGmVraFGRQAAA0o"]
[Tue Jul 21 07:38:51.244750 2026] [security2:error] [pid 254995:tid 255169] [client 103.106.20.201:56240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MO_7v0rlcEGmVraFGRQAAA0o"]
[Tue Jul 21 07:38:51.440029 2026] [security2:error] [pid 255769:tid 255911] [client 20.206.105.145:38102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/aa2.php"] [unique_id "al9MO7xMYwyVGnfuwsKieQAAA68"]
[Tue Jul 21 07:38:51.468022 2026] [security2:error] [pid 255769:tid 255972] [client 4.204.201.85:61244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/for.php"] [unique_id "al9MO7xMYwyVGnfuwsKiewAAA-w"]
[Tue Jul 21 07:38:51.499892 2026] [security2:error] [pid 254995:tid 255123] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MO_7v0rlcEGmVraFGSwADVH8"]
[Tue Jul 21 07:38:51.500045 2026] [security2:error] [pid 254995:tid 255179] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MO_7v0rlcEGmVraFGSwADVH8"]
[Tue Jul 21 07:38:51.560169 2026] [security2:error] [pid 255769:tid 255867] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MO7xMYwyVGnfuwsKifwAEFWE"]
[Tue Jul 21 07:38:51.560310 2026] [security2:error] [pid 255769:tid 256015] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MO7xMYwyVGnfuwsKifwAEFWE"]
[Tue Jul 21 07:38:51.571695 2026] [security2:error] [pid 255769:tid 255917] [client 20.226.60.151:27604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/f35.php"] [unique_id "al9MO7xMYwyVGnfuwsKigAAAA7U"]
[Tue Jul 21 07:38:51.670118 2026] [security2:error] [pid 255769:tid 255968] [client 20.226.60.151:9046] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/1.php"] [unique_id "al9MO7xMYwyVGnfuwsKiggAAA-g"]
[Tue Jul 21 07:38:51.670194 2026] [security2:error] [pid 255769:tid 255968] [client 20.226.60.151:9046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/1.php"] [unique_id "al9MO7xMYwyVGnfuwsKiggAAA-g"]
[Tue Jul 21 07:38:51.802968 2026] [security2:error] [pid 254995:tid 255216] [client 4.204.201.85:60617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/ssh3ll.php"] [unique_id "al9MO_7v0rlcEGmVraFGTQAAA3g"]
[Tue Jul 21 07:38:51.829695 2026] [security2:error] [pid 255769:tid 255804] [remote 65.111.1.237:26997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.1.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9MO7xMYwyVGnfuwsKigQAD2iI"]
[Tue Jul 21 07:38:52.024842 2026] [security2:error] [pid 255769:tid 255999] [client 20.151.10.161:46019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/bob.php"] [unique_id "al9MPLxMYwyVGnfuwsKihQAABAU"]
[Tue Jul 21 07:38:52.076390 2026] [security2:error] [pid 255769:tid 256005] [client 20.226.60.151:8685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/ms.php"] [unique_id "al9MPLxMYwyVGnfuwsKihwAABAs"]
[Tue Jul 21 07:38:52.092201 2026] [security2:error] [pid 255769:tid 255906] [client 4.204.201.85:55962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/adminner.php"] [unique_id "al9MPLxMYwyVGnfuwsKiiAAAA6o"]
[Tue Jul 21 07:38:52.213527 2026] [security2:error] [pid 254995:tid 255268] [client 193.36.225.105:57725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MPP7v0rlcEGmVraFGVAAAA5I"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:38:52.238986 2026] [security2:error] [pid 255769:tid 255947] [client 184.75.223.211:48820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MPLxMYwyVGnfuwsKiiQAAA9M"]
[Tue Jul 21 07:38:52.239105 2026] [security2:error] [pid 255769:tid 255947] [client 184.75.223.211:48820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MPLxMYwyVGnfuwsKiiQAAA9M"]
[Tue Jul 21 07:38:52.380443 2026] [security2:error] [pid 255769:tid 255997] [client 20.226.60.151:51325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-info.php"] [unique_id "al9MPLxMYwyVGnfuwsKiiwAABAM"]
[Tue Jul 21 07:38:52.409002 2026] [security2:error] [pid 255769:tid 255994] [client 4.204.201.85:57132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/82.php"] [unique_id "al9MPLxMYwyVGnfuwsKijAAABAE"]
[Tue Jul 21 07:38:52.453822 2026] [security2:error] [pid 254995:tid 255193] [client 20.226.60.151:56283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-post-data.php"] [unique_id "al9MPP7v0rlcEGmVraFGWwAAA2I"]
[Tue Jul 21 07:38:52.571643 2026] [proxy:error] [pid 254995:tid 255195] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:52.571712 2026] [proxy_http:error] [pid 254995:tid 255195] [client 20.226.60.151:8617] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:52.572186 2026] [proxy:error] [pid 254995:tid 255195] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:52.572210 2026] [proxy_http:error] [pid 254995:tid 255195] [client 20.226.60.151:8617] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:52.703938 2026] [security2:error] [pid 255769:tid 256004] [client 4.204.201.85:55504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/kir.php"] [unique_id "al9MPLxMYwyVGnfuwsKikwAABAo"]
[Tue Jul 21 07:38:52.827328 2026] [access_compat:error] [pid 255769:tid 255907] [client 162.241.63.68:56988] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:38:52.848469 2026] [security2:error] [pid 255769:tid 255956] [client 20.226.60.151:27388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-load.php"] [unique_id "al9MPLxMYwyVGnfuwsKimAAAA9w"]
[Tue Jul 21 07:38:52.985122 2026] [security2:error] [pid 255769:tid 255969] [client 4.204.201.85:55963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/up4.php"] [unique_id "al9MPLxMYwyVGnfuwsKinAAAA-k"]
[Tue Jul 21 07:38:53.045179 2026] [security2:error] [pid 255769:tid 255901] [client 20.206.105.145:38095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/ccou.php"] [unique_id "al9MPbxMYwyVGnfuwsKioAAAA6U"]
[Tue Jul 21 07:38:53.248204 2026] [security2:error] [pid 254995:tid 255152] [client 20.197.192.193:6374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/la.php"] [unique_id "al9MPf7v0rlcEGmVraFGdgAAAzk"]
[Tue Jul 21 07:38:53.290732 2026] [security2:error] [pid 255769:tid 255990] [client 4.204.201.85:57134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/xhar.php"] [unique_id "al9MPbxMYwyVGnfuwsKiqAAAA_4"]
[Tue Jul 21 07:38:53.298465 2026] [security2:error] [pid 255769:tid 255944] [client 103.86.117.203:58286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MPbxMYwyVGnfuwsKiqQAAA9A"]
[Tue Jul 21 07:38:53.298581 2026] [security2:error] [pid 255769:tid 255944] [client 103.86.117.203:58286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MPbxMYwyVGnfuwsKiqQAAA9A"]
[Tue Jul 21 07:38:53.348685 2026] [security2:error] [pid 255769:tid 255984] [client 103.174.34.15:62456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MPbxMYwyVGnfuwsKiqgAAA_g"]
[Tue Jul 21 07:38:53.348823 2026] [security2:error] [pid 255769:tid 255984] [client 103.174.34.15:62456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MPbxMYwyVGnfuwsKiqgAAA_g"]
[Tue Jul 21 07:38:53.401747 2026] [security2:error] [pid 254995:tid 255179] [client 20.226.60.151:8712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/memberfuns.php"] [unique_id "al9MPf7v0rlcEGmVraFGewAAA1Q"]
[Tue Jul 21 07:38:53.455326 2026] [security2:error] [pid 254995:tid 255166] [client 20.226.60.151:8766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/0.php"] [unique_id "al9MPf7v0rlcEGmVraFGfQAAA0c"]
[Tue Jul 21 07:38:53.499044 2026] [security2:error] [pid 254995:tid 255206] [client 20.226.60.151:9054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/BDKR28.php"] [unique_id "al9MPf7v0rlcEGmVraFGfwAAA28"]
[Tue Jul 21 07:38:53.541901 2026] [security2:error] [pid 254995:tid 255161] [client 20.226.60.151:8693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/green1.php"] [unique_id "al9MPf7v0rlcEGmVraFGgAAAA0I"]
[Tue Jul 21 07:38:53.665503 2026] [security2:error] [pid 254995:tid 255209] [client 20.220.225.223:31209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/8.php"] [unique_id "al9MPf7v0rlcEGmVraFGhAAAA3E"]
[Tue Jul 21 07:38:53.784543 2026] [security2:error] [pid 254995:tid 255128] [client 59.96.220.140:63560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MPf7v0rlcEGmVraFGiAAAAyE"]
[Tue Jul 21 07:38:53.787252 2026] [security2:error] [pid 254995:tid 255128] [client 59.96.220.140:63560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MPf7v0rlcEGmVraFGiAAAAyE"]
[Tue Jul 21 07:38:53.804572 2026] [security2:error] [pid 254995:tid 255137] [client 20.226.60.151:8878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/nc4.php"] [unique_id "al9MPf7v0rlcEGmVraFGiQAAAyo"]
[Tue Jul 21 07:38:53.865558 2026] [security2:error] [pid 255769:tid 255955] [client 4.204.201.85:57209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/file1221.php"] [unique_id "al9MPbxMYwyVGnfuwsKitQAAA9s"]
[Tue Jul 21 07:38:53.907205 2026] [security2:error] [pid 255769:tid 255910] [client 20.206.105.145:38139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/dr.php"] [unique_id "al9MPbxMYwyVGnfuwsKiuAAAA64"]
[Tue Jul 21 07:38:54.119364 2026] [security2:error] [pid 254995:tid 255168] [client 20.226.60.151:8593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/a1.php"] [unique_id "al9MPv7v0rlcEGmVraFGjAAAA0k"]
[Tue Jul 21 07:38:54.251051 2026] [security2:error] [pid 255769:tid 255968] [client 37.140.223.157:30327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MPrxMYwyVGnfuwsKivwAAA-g"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:38:54.263604 2026] [security2:error] [pid 255769:tid 255846] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MPrxMYwyVGnfuwsKiwAAD_0w"]
[Tue Jul 21 07:38:54.263780 2026] [security2:error] [pid 255769:tid 255992] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MPrxMYwyVGnfuwsKiwAAD_0w"]
[Tue Jul 21 07:38:54.267292 2026] [security2:error] [pid 254995:tid 255265] [client 20.197.192.193:6889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/nhvoanpl.php"] [unique_id "al9MPv7v0rlcEGmVraFGkQAAA48"]
[Tue Jul 21 07:38:54.311880 2026] [security2:error] [pid 255769:tid 255962] [client 20.226.60.151:8744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/eee.php"] [unique_id "al9MPrxMYwyVGnfuwsKiwwAAA-I"]
[Tue Jul 21 07:38:54.322233 2026] [security2:error] [pid 255769:tid 255999] [client 74.7.228.10:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.healthsmart.shop.oficialwebsite.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9MPrxMYwyVGnfuwsKixAAABAU"]
[Tue Jul 21 07:38:54.324046 2026] [security2:error] [pid 255769:tid 255904] [client 74.7.228.10:38762] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.healthsmart.shop.oficialwebsite.com.br"] [uri "/robots.txt"] [unique_id "al9MPrxMYwyVGnfuwsKiwQADqAU"]
[Tue Jul 21 07:38:54.362000 2026] [security2:error] [pid 255769:tid 256018] [client 4.204.201.85:57183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/inx.php"] [unique_id "al9MPrxMYwyVGnfuwsKixQAABBg"]
[Tue Jul 21 07:38:54.521467 2026] [security2:error] [pid 255769:tid 255984] [client 20.206.105.145:38087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/xamp.php"] [unique_id "al9MPrxMYwyVGnfuwsKiyQAAA_g"]
[Tue Jul 21 07:38:54.597363 2026] [security2:error] [pid 254995:tid 255160] [client 20.226.60.151:8630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/wp-aothait.php"] [unique_id "al9MPv7v0rlcEGmVraFGmQAAA0E"]
[Tue Jul 21 07:38:54.613385 2026] [security2:error] [pid 255769:tid 256013] [client 193.36.225.65:23235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MPrxMYwyVGnfuwsKiyAAABBM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:54.661378 2026] [security2:error] [pid 254995:tid 255026] [remote 192.241.143.148:37234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "robertaramos.com.br"] [uri "/wp-login.php"] [unique_id "al9MPv7v0rlcEGmVraFGnAADdx4"]
[Tue Jul 21 07:38:54.751182 2026] [security2:error] [pid 255769:tid 256019] [client 20.226.60.151:60998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/2000.php"] [unique_id "al9MPrxMYwyVGnfuwsKizwAABBk"]
[Tue Jul 21 07:38:54.751322 2026] [security2:error] [pid 255769:tid 255964] [client 20.197.192.193:6362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/inso.php"] [unique_id "al9MPrxMYwyVGnfuwsKi0AAAA-Q"]
[Tue Jul 21 07:38:54.755630 2026] [security2:error] [pid 254995:tid 255229] [client 4.204.201.85:55515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/qqqa.php"] [unique_id "al9MPv7v0rlcEGmVraFGnwAAA4I"]
[Tue Jul 21 07:38:54.846925 2026] [security2:error] [pid 254995:tid 255132] [client 20.151.10.161:46076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/crgio.php"] [unique_id "al9MPv7v0rlcEGmVraFGogAAAyU"]
[Tue Jul 21 07:38:54.862337 2026] [security2:error] [pid 255769:tid 255942] [client 20.226.60.151:9081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/config.json.php"] [unique_id "al9MPrxMYwyVGnfuwsKi0QAAA84"]
[Tue Jul 21 07:38:54.978125 2026] [security2:error] [pid 254995:tid 255140] [client 184.75.223.211:48832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MPv7v0rlcEGmVraFGpwAAAy0"]
[Tue Jul 21 07:38:54.978229 2026] [security2:error] [pid 254995:tid 255140] [client 184.75.223.211:48832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MPv7v0rlcEGmVraFGpwAAAy0"]
[Tue Jul 21 07:38:55.025471 2026] [security2:error] [pid 254995:tid 255181] [client 20.226.60.151:27611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/xyn.php"] [unique_id "al9MP_7v0rlcEGmVraFGqQAAA1Y"]
[Tue Jul 21 07:38:55.054989 2026] [security2:error] [pid 254995:tid 255201] [client 20.197.192.193:6376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/wpx.php"] [unique_id "al9MP_7v0rlcEGmVraFGqgAAA2o"]
[Tue Jul 21 07:38:55.056753 2026] [security2:error] [pid 254995:tid 255175] [client 4.204.201.85:55987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/ffffile.php"] [unique_id "al9MP_7v0rlcEGmVraFGqwAAA1A"]
[Tue Jul 21 07:38:55.396087 2026] [security2:error] [pid 255769:tid 255907] [client 20.226.60.151:27635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ccc.php"] [unique_id "al9MP7xMYwyVGnfuwsKi1gAAA6s"]
[Tue Jul 21 07:38:55.473539 2026] [security2:error] [pid 255769:tid 255930] [client 20.226.60.151:8621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9MP7xMYwyVGnfuwsKi2AAAA8I"]
[Tue Jul 21 07:38:55.500246 2026] [security2:error] [pid 254995:tid 255133] [client 4.204.201.85:55538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-firewall.php"] [unique_id "al9MP_7v0rlcEGmVraFGsgAAAyY"]
[Tue Jul 21 07:38:55.501355 2026] [security2:error] [pid 255769:tid 255955] [client 20.197.192.193:6361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/berlin.php"] [unique_id "al9MP7xMYwyVGnfuwsKi2wAAA9s"]
[Tue Jul 21 07:38:55.711163 2026] [security2:error] [pid 254995:tid 255053] [remote 104.207.63.248:55115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.63.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9MPf7v0rlcEGmVraFGgQADnTk"]
[Tue Jul 21 07:38:55.719114 2026] [security2:error] [pid 254995:tid 255275] [client 139.167.225.182:52363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MP_7v0rlcEGmVraFGuwAAA5k"]
[Tue Jul 21 07:38:55.720871 2026] [security2:error] [pid 254995:tid 255275] [client 139.167.225.182:52363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MP_7v0rlcEGmVraFGuwAAA5k"]
[Tue Jul 21 07:38:55.834969 2026] [security2:error] [pid 254995:tid 255263] [client 20.206.105.145:38134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/bless.php"] [unique_id "al9MP_7v0rlcEGmVraFGvgAAA40"]
[Tue Jul 21 07:38:56.001136 2026] [security2:error] [pid 255769:tid 255920] [client 4.204.201.85:61251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/reviall.php"] [unique_id "al9MQLxMYwyVGnfuwsKi4QAAA7g"]
[Tue Jul 21 07:38:56.006961 2026] [core:error] [pid 254995:tid 255061] [remote 34.182.235.64:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:38:56.006980 2026] [core:error] [pid 254995:tid 255061] [remote 34.182.235.64:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:38:56.080555 2026] [security2:error] [pid 255769:tid 256000] [client 20.226.60.151:27563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/w.php"] [unique_id "al9MQLxMYwyVGnfuwsKi4wAABAY"]
[Tue Jul 21 07:38:56.116114 2026] [security2:error] [pid 255769:tid 256021] [client 117.217.38.194:56051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MQLxMYwyVGnfuwsKi5QAABBs"]
[Tue Jul 21 07:38:56.116716 2026] [security2:error] [pid 255769:tid 256021] [client 117.217.38.194:56051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MQLxMYwyVGnfuwsKi5QAABBs"]
[Tue Jul 21 07:38:56.171467 2026] [security2:error] [pid 254995:tid 255001] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MQP7v0rlcEGmVraFGxwADIQU"]
[Tue Jul 21 07:38:56.171660 2026] [security2:error] [pid 254995:tid 255128] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MQP7v0rlcEGmVraFGxwADIQU"]
[Tue Jul 21 07:38:56.178534 2026] [security2:error] [pid 255769:tid 255975] [client 20.226.60.151:8694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/k2.php"] [unique_id "al9MQLxMYwyVGnfuwsKi5wAAA-8"]
[Tue Jul 21 07:38:56.215492 2026] [security2:error] [pid 255769:tid 255936] [client 20.197.192.193:6373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/billur.php"] [unique_id "al9MQLxMYwyVGnfuwsKi6AAAA8g"]
[Tue Jul 21 07:38:56.576753 2026] [core:error] [pid 254995:tid 255115] [remote 34.182.235.64:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:38:56.576777 2026] [core:error] [pid 254995:tid 255115] [remote 34.182.235.64:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:38:56.622525 2026] [security2:error] [pid 254995:tid 255273] [client 20.226.60.151:8840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9MQP7v0rlcEGmVraFG0AAAA5c"]
[Tue Jul 21 07:38:56.780830 2026] [security2:error] [pid 254995:tid 255021] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9MQP7v0rlcEGmVraFG1AADixk"]
[Tue Jul 21 07:38:56.905064 2026] [security2:error] [pid 254995:tid 255122] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9MQP7v0rlcEGmVraFG1gADPX4"]
[Tue Jul 21 07:38:56.934890 2026] [security2:error] [pid 254995:tid 255142] [client 20.197.192.193:6385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/mimpi.php"] [unique_id "al9MQP7v0rlcEGmVraFG2AAAAy8"]
[Tue Jul 21 07:38:56.982123 2026] [security2:error] [pid 255769:tid 255947] [client 20.226.60.151:56302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/pucci.php"] [unique_id "al9MQLxMYwyVGnfuwsKi7wAAA9M"]
[Tue Jul 21 07:38:56.982386 2026] [security2:error] [pid 255769:tid 255990] [client 20.206.105.145:38509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/file46.php"] [unique_id "al9MQLxMYwyVGnfuwsKi8AAAA_4"]
[Tue Jul 21 07:38:57.069869 2026] [security2:error] [pid 254995:tid 255092] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9MQf7v0rlcEGmVraFG3AADf2A"]
[Tue Jul 21 07:38:57.115733 2026] [security2:error] [pid 255769:tid 255979] [client 20.226.60.151:27629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9MQbxMYwyVGnfuwsKi8gAAA_M"]
[Tue Jul 21 07:38:57.135034 2026] [security2:error] [pid 255769:tid 256013] [client 20.151.10.161:46020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/pucci.php"] [unique_id "al9MQbxMYwyVGnfuwsKi8wAABBM"]
[Tue Jul 21 07:38:57.240751 2026] [security2:error] [pid 254995:tid 255074] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9MQf7v0rlcEGmVraFG3wADIk4"]
[Tue Jul 21 07:38:57.393275 2026] [security2:error] [pid 254995:tid 255101] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9MQf7v0rlcEGmVraFG4QADamk"]
[Tue Jul 21 07:38:57.573461 2026] [security2:error] [pid 254995:tid 255102] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9MQf7v0rlcEGmVraFG5QADdWo"]
[Tue Jul 21 07:38:57.574179 2026] [security2:error] [pid 255769:tid 255944] [client 173.24.185.52:60607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MQbxMYwyVGnfuwsKi-gAAA9A"]
[Tue Jul 21 07:38:57.574271 2026] [security2:error] [pid 255769:tid 255944] [client 173.24.185.52:60607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MQbxMYwyVGnfuwsKi-gAAA9A"]
[Tue Jul 21 07:38:57.605372 2026] [security2:error] [pid 254995:tid 255205] [client 106.215.181.8:28503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MQf7v0rlcEGmVraFG6AAAA24"]
[Tue Jul 21 07:38:57.605484 2026] [security2:error] [pid 254995:tid 255205] [client 106.215.181.8:28503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MQf7v0rlcEGmVraFG6AAAA24"]
[Tue Jul 21 07:38:57.613885 2026] [security2:error] [pid 254995:tid 255185] [client 20.226.60.151:61019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/122.php"] [unique_id "al9MQf7v0rlcEGmVraFG6QAAA1o"]
[Tue Jul 21 07:38:57.713121 2026] [security2:error] [pid 254995:tid 255099] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9MQf7v0rlcEGmVraFG6gADimc"]
[Tue Jul 21 07:38:57.883421 2026] [security2:error] [pid 255769:tid 255961] [client 20.226.60.151:8733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9MQbxMYwyVGnfuwsKjAQAAA-E"]
[Tue Jul 21 07:38:58.087421 2026] [security2:error] [pid 255769:tid 255823] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9MQrxMYwyVGnfuwsKjBQAEEDU"]
[Tue Jul 21 07:38:58.198383 2026] [security2:error] [pid 255769:tid 255971] [client 20.197.192.193:6366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/dp.php"] [unique_id "al9MQrxMYwyVGnfuwsKjBgAAA-s"]
[Tue Jul 21 07:38:58.245855 2026] [security2:error] [pid 254995:tid 255109] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9MQv7v0rlcEGmVraFG8QADjnE"]
[Tue Jul 21 07:38:58.369981 2026] [security2:error] [pid 255769:tid 255824] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9MQrxMYwyVGnfuwsKjCwADpDY"]
[Tue Jul 21 07:38:58.376325 2026] [security2:error] [pid 255769:tid 255954] [client 20.226.60.151:27549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/FWAZ.php"] [unique_id "al9MQrxMYwyVGnfuwsKjDAAAA9o"]
[Tue Jul 21 07:38:58.443837 2026] [security2:error] [pid 255769:tid 255966] [client 136.144.33.106:51463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MQrxMYwyVGnfuwsKjDwAAA-Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:58.617383 2026] [security2:error] [pid 255769:tid 255927] [client 20.226.60.151:56231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/black.php"] [unique_id "al9MQrxMYwyVGnfuwsKjEQAAA78"]
[Tue Jul 21 07:38:58.628210 2026] [security2:error] [pid 255769:tid 255947] [client 20.226.60.151:8724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9MQrxMYwyVGnfuwsKjEgAAA9M"]
[Tue Jul 21 07:38:58.632825 2026] [security2:error] [pid 254995:tid 255118] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9MQv7v0rlcEGmVraFG9gADb3o"]
[Tue Jul 21 07:38:58.730172 2026] [security2:error] [pid 254995:tid 255275] [client 20.206.105.145:37911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/eee.php"] [unique_id "al9MQv7v0rlcEGmVraFG-QAAA5k"]
[Tue Jul 21 07:38:58.780996 2026] [security2:error] [pid 255769:tid 255882] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9MQrxMYwyVGnfuwsKjFAADzXA"]
[Tue Jul 21 07:38:58.852935 2026] [security2:error] [pid 255769:tid 256021] [client 122.186.204.214:61744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MQrxMYwyVGnfuwsKjFQAABBs"]
[Tue Jul 21 07:38:58.853062 2026] [security2:error] [pid 255769:tid 256021] [client 122.186.204.214:61744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MQrxMYwyVGnfuwsKjFQAABBs"]
[Tue Jul 21 07:38:58.903121 2026] [security2:error] [pid 255769:tid 256013] [client 20.226.60.151:27646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/miru1.php"] [unique_id "al9MQrxMYwyVGnfuwsKjFwAABBM"]
[Tue Jul 21 07:38:59.259833 2026] [security2:error] [pid 255769:tid 255942] [client 20.197.192.193:6894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/bootstrap.php"] [unique_id "al9MQ7xMYwyVGnfuwsKjGwAAA84"]
[Tue Jul 21 07:38:59.287067 2026] [security2:error] [pid 255769:tid 255999] [client 117.251.86.144:36988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MQ7xMYwyVGnfuwsKjHAAABAU"]
[Tue Jul 21 07:38:59.287171 2026] [security2:error] [pid 255769:tid 255999] [client 117.251.86.144:36988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MQ7xMYwyVGnfuwsKjHAAABAU"]
[Tue Jul 21 07:38:59.334244 2026] [security2:error] [pid 255769:tid 255869] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MQ7xMYwyVGnfuwsKjHQAEHmM"]
[Tue Jul 21 07:38:59.334408 2026] [security2:error] [pid 255769:tid 256024] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MQ7xMYwyVGnfuwsKjHQAEHmM"]
[Tue Jul 21 07:38:59.341411 2026] [security2:error] [pid 255769:tid 255866] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MQ7xMYwyVGnfuwsKjHgADvGA"]
[Tue Jul 21 07:38:59.341536 2026] [security2:error] [pid 255769:tid 255924] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MQ7xMYwyVGnfuwsKjHgADvGA"]
[Tue Jul 21 07:38:59.553204 2026] [security2:error] [pid 255769:tid 255922] [client 20.226.60.151:27356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/aa.php"] [unique_id "al9MQ7xMYwyVGnfuwsKjIwAAA7o"]
[Tue Jul 21 07:38:59.813612 2026] [security2:error] [pid 255769:tid 255908] [client 20.151.10.161:45897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-temp.php"] [unique_id "al9MQ7xMYwyVGnfuwsKjLQAAA6w"]
[Tue Jul 21 07:38:59.893473 2026] [security2:error] [pid 255769:tid 255971] [client 20.226.60.151:8700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/for.php"] [unique_id "al9MQ7xMYwyVGnfuwsKjLgAAA-s"]
[Tue Jul 21 07:39:00.000794 2026] [security2:error] [pid 255769:tid 255900] [client 20.226.60.151:51278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/mds.php"] [unique_id "al9MRLxMYwyVGnfuwsKjNAAAA6Q"]
[Tue Jul 21 07:39:00.392310 2026] [security2:error] [pid 254995:tid 255265] [client 74.7.175.177:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "roanalacerda.com.br"] [uri "/index.php"] [unique_id "al9MRP7v0rlcEGmVraFHCwAAA48"]
[Tue Jul 21 07:39:00.393819 2026] [security2:error] [pid 255769:tid 255988] [client 74.7.175.177:54586] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "roanalacerda.com.br"] [uri "/robots.txt"] [unique_id "al9MRLxMYwyVGnfuwsKjPQAD_F0"]
[Tue Jul 21 07:39:00.505178 2026] [security2:error] [pid 255769:tid 255997] [client 194.99.104.35:43342] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9MRLxMYwyVGnfuwsKjQQAABAM"]
[Tue Jul 21 07:39:00.505282 2026] [security2:error] [pid 255769:tid 255997] [client 194.99.104.35:43342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9MRLxMYwyVGnfuwsKjQQAABAM"]
[Tue Jul 21 07:39:00.750299 2026] [security2:error] [pid 255769:tid 256019] [client 20.226.60.151:56265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/zlece.php"] [unique_id "al9MRLxMYwyVGnfuwsKjRAAABBk"]
[Tue Jul 21 07:39:00.812206 2026] [security2:error] [pid 255769:tid 255906] [client 20.226.60.151:27592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/122.php"] [unique_id "al9MRLxMYwyVGnfuwsKjRgAAA6o"]
[Tue Jul 21 07:39:01.093782 2026] [security2:error] [pid 254995:tid 255156] [client 20.197.192.193:6394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/wp-editor.php"] [unique_id "al9MRf7v0rlcEGmVraFHFwAAAz0"]
[Tue Jul 21 07:39:01.095834 2026] [security2:error] [pid 255769:tid 256003] [client 154.192.233.199:59044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MRbxMYwyVGnfuwsKjSgAABAk"]
[Tue Jul 21 07:39:01.096103 2026] [security2:error] [pid 255769:tid 256003] [client 154.192.233.199:59044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MRbxMYwyVGnfuwsKjSgAABAk"]
[Tue Jul 21 07:39:01.117323 2026] [security2:error] [pid 254995:tid 255182] [client 62.102.148.187:55790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9MRf7v0rlcEGmVraFHGAAAA1c"]
[Tue Jul 21 07:39:01.117429 2026] [security2:error] [pid 254995:tid 255182] [client 62.102.148.187:55790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9MRf7v0rlcEGmVraFHGAAAA1c"]
[Tue Jul 21 07:39:01.177041 2026] [security2:error] [pid 255769:tid 255943] [client 20.151.10.161:45980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9MRbxMYwyVGnfuwsKjSwAAA88"]
[Tue Jul 21 07:39:01.192048 2026] [security2:error] [pid 255769:tid 255990] [client 175.45.70.82:50673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MRbxMYwyVGnfuwsKjTAAAA_4"]
[Tue Jul 21 07:39:01.192152 2026] [security2:error] [pid 255769:tid 255990] [client 175.45.70.82:50673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MRbxMYwyVGnfuwsKjTAAAA_4"]
[Tue Jul 21 07:39:01.233773 2026] [security2:error] [pid 255769:tid 255947] [client 122.164.127.47:59014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MRbxMYwyVGnfuwsKjTQAAA9M"]
[Tue Jul 21 07:39:01.233961 2026] [security2:error] [pid 255769:tid 255947] [client 122.164.127.47:59014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MRbxMYwyVGnfuwsKjTQAAA9M"]
[Tue Jul 21 07:39:01.356029 2026] [core:error] [pid 254995:tid 255073] [remote 5.255.231.176:55980] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:39:01.356055 2026] [core:error] [pid 254995:tid 255073] [remote 5.255.231.176:55980] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:39:01.548719 2026] [security2:error] [pid 255769:tid 255912] [client 74.7.175.162:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.psicologafernandaguedes.com"] [uri "/___proxy_subdomain_webmail/cgi-sys/404.html"] [unique_id "al9MRbxMYwyVGnfuwsKjUwAAA7A"]
[Tue Jul 21 07:39:01.550651 2026] [security2:error] [pid 254995:tid 255211] [client 74.7.175.162:35476] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.psicologafernandaguedes.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "al9MRf7v0rlcEGmVraFHKgADc0Y"]
[Tue Jul 21 07:39:01.636086 2026] [security2:error] [pid 255769:tid 255999] [client 122.162.144.145:13927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MRbxMYwyVGnfuwsKjVwAABAU"]
[Tue Jul 21 07:39:01.636244 2026] [security2:error] [pid 255769:tid 255999] [client 122.162.144.145:13927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MRbxMYwyVGnfuwsKjVwAABAU"]
[Tue Jul 21 07:39:01.784947 2026] [security2:error] [pid 254995:tid 255153] [client 20.151.10.161:45934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/puc.php"] [unique_id "al9MRf7v0rlcEGmVraFHLwAAAzo"]
[Tue Jul 21 07:39:01.891285 2026] [security2:error] [pid 254995:tid 255279] [client 20.226.60.151:27605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/get.php"] [unique_id "al9MRf7v0rlcEGmVraFHMQAAA50"]
[Tue Jul 21 07:39:01.953770 2026] [security2:error] [pid 255769:tid 256020] [client 103.106.20.201:56946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MRbxMYwyVGnfuwsKjXQAABBo"]
[Tue Jul 21 07:39:01.953936 2026] [security2:error] [pid 255769:tid 256020] [client 103.106.20.201:56946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MRbxMYwyVGnfuwsKjXQAABBo"]
[Tue Jul 21 07:39:02.010288 2026] [security2:error] [pid 255769:tid 255886] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MRrxMYwyVGnfuwsKjXwAD43Q"]
[Tue Jul 21 07:39:02.010447 2026] [security2:error] [pid 255769:tid 255963] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MRrxMYwyVGnfuwsKjXwAD43Q"]
[Tue Jul 21 07:39:02.106486 2026] [security2:error] [pid 255769:tid 255853] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MRrxMYwyVGnfuwsKjYQADxlM"]
[Tue Jul 21 07:39:02.106660 2026] [security2:error] [pid 255769:tid 255934] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MRrxMYwyVGnfuwsKjYQADxlM"]
[Tue Jul 21 07:39:02.131972 2026] [security2:error] [pid 255769:tid 255936] [client 193.36.225.139:55279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MRbxMYwyVGnfuwsKjXgAAA8g"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:39:02.177909 2026] [security2:error] [pid 254995:tid 255252] [client 20.226.60.151:8651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/raw.php"] [unique_id "al9MRv7v0rlcEGmVraFHNgAAA4M"]
[Tue Jul 21 07:39:02.262131 2026] [security2:error] [pid 255769:tid 256013] [client 4.204.201.85:49904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MRrxMYwyVGnfuwsKjZwAABBM"]
[Tue Jul 21 07:39:02.362529 2026] [security2:error] [pid 255769:tid 256026] [client 20.226.60.151:56271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/vssrs.php"] [unique_id "al9MRrxMYwyVGnfuwsKjagAABCA"]
[Tue Jul 21 07:39:02.375490 2026] [security2:error] [pid 255769:tid 255919] [client 20.226.60.151:27372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/as.php"] [unique_id "al9MRrxMYwyVGnfuwsKjawAAA7c"]
[Tue Jul 21 07:39:02.416592 2026] [security2:error] [pid 255769:tid 255964] [client 20.226.60.151:61055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-blink.php"] [unique_id "al9MRrxMYwyVGnfuwsKjbAAAA-Q"]
[Tue Jul 21 07:39:02.542643 2026] [security2:error] [pid 255769:tid 255942] [client 4.204.201.85:49820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MRrxMYwyVGnfuwsKjbQAAA84"]
[Tue Jul 21 07:39:02.605828 2026] [security2:error] [pid 254995:tid 255172] [client 20.197.192.193:6890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/cro.php"] [unique_id "al9MRv7v0rlcEGmVraFHPwAAA00"]
[Tue Jul 21 07:39:02.672240 2026] [security2:error] [pid 255769:tid 255986] [client 20.151.10.161:45987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/themes.php"] [unique_id "al9MRrxMYwyVGnfuwsKjbwAAA_o"]
[Tue Jul 21 07:39:02.718901 2026] [security2:error] [pid 254995:tid 255183] [client 193.36.225.62:25667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MRv7v0rlcEGmVraFHOgAAA1g"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:02.949358 2026] [security2:error] [pid 255769:tid 255935] [client 20.226.60.151:27571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ccou.php"] [unique_id "al9MRrxMYwyVGnfuwsKjdgAAA8c"]
[Tue Jul 21 07:39:03.019888 2026] [security2:error] [pid 255769:tid 255910] [client 4.204.201.85:4464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/x.php"] [unique_id "al9MR7xMYwyVGnfuwsKjdwAAA64"]
[Tue Jul 21 07:39:03.097907 2026] [security2:error] [pid 255769:tid 255998] [client 20.226.60.151:27532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/w3lls.php"] [unique_id "al9MR7xMYwyVGnfuwsKjeAAABAQ"]
[Tue Jul 21 07:39:03.217113 2026] [security2:error] [pid 254995:tid 255130] [client 20.206.105.145:38219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/file25.php"] [unique_id "al9MR_7v0rlcEGmVraFHRwAAAyM"]
[Tue Jul 21 07:39:03.397198 2026] [security2:error] [pid 255769:tid 255911] [client 4.204.201.85:49813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/mgrr.php"] [unique_id "al9MR7xMYwyVGnfuwsKjgAAAA68"]
[Tue Jul 21 07:39:03.472374 2026] [security2:error] [pid 254995:tid 255160] [client 20.226.60.151:27546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/test1.php"] [unique_id "al9MR_7v0rlcEGmVraFHTQAAA0E"]
[Tue Jul 21 07:39:03.534322 2026] [security2:error] [pid 254995:tid 255126] [client 20.226.60.151:61224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/zc-208.php"] [unique_id "al9MR_7v0rlcEGmVraFHTgAAAx8"]
[Tue Jul 21 07:39:03.669365 2026] [security2:error] [pid 254995:tid 255156] [client 20.226.60.151:27522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/database.php"] [unique_id "al9MR_7v0rlcEGmVraFHUgAAAz0"]
[Tue Jul 21 07:39:03.749684 2026] [security2:error] [pid 255769:tid 256009] [client 4.204.201.85:4419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/stdin.php"] [unique_id "al9MR7xMYwyVGnfuwsKjhQAABA8"]
[Tue Jul 21 07:39:03.788160 2026] [security2:error] [pid 254995:tid 255195] [client 103.86.117.203:58808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MR_7v0rlcEGmVraFHUwAAA2Q"]
[Tue Jul 21 07:39:03.788250 2026] [security2:error] [pid 254995:tid 255195] [client 103.86.117.203:58808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MR_7v0rlcEGmVraFHUwAAA2Q"]
[Tue Jul 21 07:39:03.942147 2026] [security2:error] [pid 255769:tid 255992] [client 20.151.10.161:45913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/dx.php"] [unique_id "al9MR7xMYwyVGnfuwsKjiQAAA_8"]
[Tue Jul 21 07:39:04.034882 2026] [security2:error] [pid 255769:tid 255985] [client 4.204.201.85:49908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/BDKR28.php"] [unique_id "al9MSLxMYwyVGnfuwsKjigAAA_k"]
[Tue Jul 21 07:39:04.038267 2026] [security2:error] [pid 255769:tid 255934] [client 20.226.60.151:27565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/file.php"] [unique_id "al9MSLxMYwyVGnfuwsKjiwAAA8Y"]
[Tue Jul 21 07:39:04.050488 2026] [security2:error] [pid 254995:tid 255273] [client 103.174.34.15:62971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MSP7v0rlcEGmVraFHWQAAA5c"]
[Tue Jul 21 07:39:04.050780 2026] [security2:error] [pid 254995:tid 255273] [client 103.174.34.15:62971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MSP7v0rlcEGmVraFHWQAAA5c"]
[Tue Jul 21 07:39:04.320792 2026] [security2:error] [pid 255769:tid 256021] [client 4.204.201.85:4524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/001.php"] [unique_id "al9MSLxMYwyVGnfuwsKjlAAABBs"]
[Tue Jul 21 07:39:04.570462 2026] [security2:error] [pid 255769:tid 255986] [client 37.140.223.117:52783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MSLxMYwyVGnfuwsKjmAAAA_o"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:39:04.708656 2026] [security2:error] [pid 255769:tid 255907] [client 4.204.201.85:49869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/dZ3wP5.php"] [unique_id "al9MSLxMYwyVGnfuwsKjnAAAA6s"]
[Tue Jul 21 07:39:04.736780 2026] [security2:error] [pid 255769:tid 255990] [client 20.226.60.151:27550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/file.php"] [unique_id "al9MSLxMYwyVGnfuwsKjnQAAA_4"]
[Tue Jul 21 07:39:04.775518 2026] [security2:error] [pid 255769:tid 255910] [client 20.206.105.145:38084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/file48.php"] [unique_id "al9MSLxMYwyVGnfuwsKjngAAA64"]
[Tue Jul 21 07:39:04.790226 2026] [security2:error] [pid 255769:tid 255938] [client 20.151.10.161:45971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/p.php"] [unique_id "al9MSLxMYwyVGnfuwsKjnwAAA8o"]
[Tue Jul 21 07:39:04.882889 2026] [security2:error] [pid 255769:tid 255789] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MSLxMYwyVGnfuwsKjoAADqBM"]
[Tue Jul 21 07:39:04.883105 2026] [security2:error] [pid 255769:tid 255904] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MSLxMYwyVGnfuwsKjoAADqBM"]
[Tue Jul 21 07:39:05.052934 2026] [security2:error] [pid 254995:tid 255254] [client 4.204.201.85:4467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/yup.php"] [unique_id "al9MSf7v0rlcEGmVraFHZwAAA4Q"]
[Tue Jul 21 07:39:05.116800 2026] [security2:error] [pid 254995:tid 255211] [client 20.226.60.151:51301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/sid4.php"] [unique_id "al9MSf7v0rlcEGmVraFHaAAAA3M"]
[Tue Jul 21 07:39:05.288169 2026] [security2:error] [pid 254995:tid 255036] [remote 8.217.108.67:5594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/wp-login.php"] [unique_id "al9MSf7v0rlcEGmVraFHbgADmCg"]
[Tue Jul 21 07:39:05.324862 2026] [security2:error] [pid 254995:tid 255153] [client 20.226.60.151:27534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/777.php"] [unique_id "al9MSf7v0rlcEGmVraFHbwAAAzo"]
[Tue Jul 21 07:39:05.360033 2026] [security2:error] [pid 254995:tid 255267] [client 4.204.201.85:4439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/X.php"] [unique_id "al9MSf7v0rlcEGmVraFHcAAAA5E"]
[Tue Jul 21 07:39:05.397632 2026] [security2:error] [pid 254995:tid 255166] [client 20.220.225.223:31177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/red.php"] [unique_id "al9MSf7v0rlcEGmVraFHdAAAA0c"]
[Tue Jul 21 07:39:05.545771 2026] [security2:error] [pid 255769:tid 255976] [client 20.151.10.161:46013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/bthil.php"] [unique_id "al9MSbxMYwyVGnfuwsKjqQAAA_A"]
[Tue Jul 21 07:39:05.763000 2026] [security2:error] [pid 255769:tid 255985] [client 4.204.201.85:49881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/1polka.php"] [unique_id "al9MSbxMYwyVGnfuwsKjrQAAA_k"]
[Tue Jul 21 07:39:05.776882 2026] [security2:error] [pid 255769:tid 255999] [client 59.96.220.140:64043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MSbxMYwyVGnfuwsKjrgAABAU"]
[Tue Jul 21 07:39:05.777638 2026] [security2:error] [pid 255769:tid 255999] [client 59.96.220.140:64043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MSbxMYwyVGnfuwsKjrgAABAU"]
[Tue Jul 21 07:39:06.017773 2026] [security2:error] [pid 254995:tid 255190] [client 20.226.60.151:27524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ssixta.php"] [unique_id "al9MSv7v0rlcEGmVraFHfAAAA18"]
[Tue Jul 21 07:39:06.079995 2026] [security2:error] [pid 254995:tid 255203] [client 4.204.201.85:49914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/gec.php"] [unique_id "al9MSv7v0rlcEGmVraFHfgAAA2w"]
[Tue Jul 21 07:39:06.194058 2026] [security2:error] [pid 255769:tid 256009] [client 139.167.225.182:53006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MSrxMYwyVGnfuwsKjtQAABA8"]
[Tue Jul 21 07:39:06.194191 2026] [security2:error] [pid 255769:tid 256009] [client 139.167.225.182:53006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MSrxMYwyVGnfuwsKjtQAABA8"]
[Tue Jul 21 07:39:06.268950 2026] [security2:error] [pid 255769:tid 256026] [client 20.151.10.161:46048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/7.php"] [unique_id "al9MSrxMYwyVGnfuwsKjtgAABCA"]
[Tue Jul 21 07:39:06.281902 2026] [autoindex:error] [pid 255769:tid 255946] [client 20.226.60.151:61196] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:06.294747 2026] [security2:error] [pid 255769:tid 255919] [client 20.206.105.145:38130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/file6.php"] [unique_id "al9MSrxMYwyVGnfuwsKjuQAAA7c"]
[Tue Jul 21 07:39:06.298608 2026] [security2:error] [pid 255769:tid 255905] [client 20.226.60.151:61196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wmore1.php"] [unique_id "al9MSrxMYwyVGnfuwsKjugAAA6k"]
[Tue Jul 21 07:39:06.369811 2026] [security2:error] [pid 255769:tid 255899] [client 4.204.201.85:49814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/sky.php"] [unique_id "al9MSrxMYwyVGnfuwsKjvAAAA6M"]
[Tue Jul 21 07:39:06.535616 2026] [security2:error] [pid 255769:tid 255986] [client 20.226.60.151:56218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wicked.php"] [unique_id "al9MSrxMYwyVGnfuwsKjvgAAA_o"]
[Tue Jul 21 07:39:06.585375 2026] [security2:error] [pid 254995:tid 255220] [client 117.217.38.194:56530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MSv7v0rlcEGmVraFHiAAAA3w"]
[Tue Jul 21 07:39:06.585524 2026] [security2:error] [pid 254995:tid 255220] [client 117.217.38.194:56530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MSv7v0rlcEGmVraFHiAAAA3w"]
[Tue Jul 21 07:39:06.637566 2026] [security2:error] [pid 255769:tid 256015] [client 193.36.225.62:53151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MSrxMYwyVGnfuwsKjwAAABBU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:06.653730 2026] [security2:error] [pid 254995:tid 255156] [client 4.204.201.85:49815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/fffm.php"] [unique_id "al9MSv7v0rlcEGmVraFHiQAAAz0"]
[Tue Jul 21 07:39:06.718207 2026] [security2:error] [pid 255769:tid 256005] [client 20.197.192.193:6848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/cron-tab.php"] [unique_id "al9MSrxMYwyVGnfuwsKjwwAABAs"]
[Tue Jul 21 07:39:06.732439 2026] [autoindex:error] [pid 255769:tid 255943] [client 34.26.20.91:52252] AH01276: Cannot serve directory /home3/sabri472/evolvaa.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:06.846429 2026] [security2:error] [pid 254995:tid 255273] [client 20.226.60.151:51269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/solo1.php"] [unique_id "al9MSv7v0rlcEGmVraFHiwAAA5c"]
[Tue Jul 21 07:39:06.934356 2026] [security2:error] [pid 255769:tid 255934] [client 152.59.154.239:61658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MSrxMYwyVGnfuwsKjyQAAA8Y"]
[Tue Jul 21 07:39:06.934487 2026] [security2:error] [pid 255769:tid 255934] [client 152.59.154.239:61658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MSrxMYwyVGnfuwsKjyQAAA8Y"]
[Tue Jul 21 07:39:06.955801 2026] [security2:error] [pid 254995:tid 255201] [client 20.220.225.223:38687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/fffm.php"] [unique_id "al9MSv7v0rlcEGmVraFHjAAAA2o"]
[Tue Jul 21 07:39:06.958763 2026] [security2:error] [pid 255769:tid 255902] [client 4.204.201.85:4454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/sixxis.php"] [unique_id "al9MSrxMYwyVGnfuwsKjygAAA6Y"]
[Tue Jul 21 07:39:07.075112 2026] [security2:error] [pid 254995:tid 255140] [client 20.226.60.151:27530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/1c.php"] [unique_id "al9MS_7v0rlcEGmVraFHjwAAAy0"]
[Tue Jul 21 07:39:07.147926 2026] [security2:error] [pid 255769:tid 255897] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MS7xMYwyVGnfuwsKjywAEEH8"]
[Tue Jul 21 07:39:07.148108 2026] [security2:error] [pid 255769:tid 256010] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MS7xMYwyVGnfuwsKjywAEEH8"]
[Tue Jul 21 07:39:07.211631 2026] [security2:error] [pid 255769:tid 255955] [client 20.151.10.161:45914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/8.php"] [unique_id "al9MS7xMYwyVGnfuwsKjzwAAA9s"]
[Tue Jul 21 07:39:07.241581 2026] [security2:error] [pid 255769:tid 256000] [client 4.204.201.85:49845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/yj09.php"] [unique_id "al9MS7xMYwyVGnfuwsKj0gAABAY"]
[Tue Jul 21 07:39:07.497864 2026] [autoindex:error] [pid 255769:tid 255999] [client 20.226.60.151:51318] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:07.527510 2026] [security2:error] [pid 255769:tid 255959] [client 20.226.60.151:51318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/cong.php"] [unique_id "al9MS7xMYwyVGnfuwsKj2AAAA98"]
[Tue Jul 21 07:39:07.527525 2026] [security2:error] [pid 255769:tid 255974] [client 4.204.201.85:4475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/f900.php"] [unique_id "al9MS7xMYwyVGnfuwsKj1wAAA-4"]
[Tue Jul 21 07:39:07.608466 2026] [security2:error] [pid 255769:tid 255941] [client 20.151.10.161:46003] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "prospecta.agendaclique.com.br"] [uri "/1.php"] [unique_id "al9MS7xMYwyVGnfuwsKj3AAAA80"]
[Tue Jul 21 07:39:07.608551 2026] [security2:error] [pid 255769:tid 255941] [client 20.151.10.161:46003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/1.php"] [unique_id "al9MS7xMYwyVGnfuwsKj3AAAA80"]
[Tue Jul 21 07:39:07.831594 2026] [security2:error] [pid 255769:tid 255899] [client 4.204.201.85:49806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/ups.php"] [unique_id "al9MS7xMYwyVGnfuwsKj4QAAA6M"]
[Tue Jul 21 07:39:07.939798 2026] [security2:error] [pid 255769:tid 256023] [client 106.215.181.8:8593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MS7xMYwyVGnfuwsKj4gAABB0"]
[Tue Jul 21 07:39:07.939923 2026] [security2:error] [pid 255769:tid 256023] [client 106.215.181.8:8593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MS7xMYwyVGnfuwsKj4gAABB0"]
[Tue Jul 21 07:39:07.978174 2026] [fcgid:warn] [pid 255769:tid 255960] (70014)End of file found: [client 66.132.186.182:61094] mod_fcgid: can't get data from http client
[Tue Jul 21 07:39:07.980128 2026] [security2:error] [pid 255769:tid 255925] [client 20.226.60.151:27538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/test2.php"] [unique_id "al9MS7xMYwyVGnfuwsKj5AAAA70"]
[Tue Jul 21 07:39:08.026858 2026] [security2:error] [pid 255769:tid 256015] [client 20.206.105.145:38118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/a2.php"] [unique_id "al9MTLxMYwyVGnfuwsKj5wAABBU"]
[Tue Jul 21 07:39:08.130240 2026] [security2:error] [pid 254995:tid 255208] [client 4.204.201.85:4429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/k.php"] [unique_id "al9MTP7v0rlcEGmVraFHnQAAA3A"]
[Tue Jul 21 07:39:08.146740 2026] [security2:error] [pid 254995:tid 255175] [client 20.151.10.161:46036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/100.php"] [unique_id "al9MTP7v0rlcEGmVraFHnwAAA1A"]
[Tue Jul 21 07:39:08.158170 2026] [security2:error] [pid 255769:tid 255970] [client 173.24.185.52:61072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MTLxMYwyVGnfuwsKj6QAAA-o"]
[Tue Jul 21 07:39:08.158271 2026] [security2:error] [pid 255769:tid 255970] [client 173.24.185.52:61072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MTLxMYwyVGnfuwsKj6QAAA-o"]
[Tue Jul 21 07:39:08.252021 2026] [autoindex:error] [pid 255769:tid 255903] [client 20.226.60.151:51315] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:08.269617 2026] [security2:error] [pid 255769:tid 255990] [client 20.226.60.151:51315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/public/css.php"] [unique_id "al9MTLxMYwyVGnfuwsKj7QAAA_4"]
[Tue Jul 21 07:39:08.408344 2026] [security2:error] [pid 255769:tid 255928] [client 4.204.201.85:4505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/k2.php"] [unique_id "al9MTLxMYwyVGnfuwsKj8AAAA8A"]
[Tue Jul 21 07:39:08.576342 2026] [security2:error] [pid 255769:tid 256010] [client 20.226.60.151:27614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/buy.php"] [unique_id "al9MTLxMYwyVGnfuwsKj8QAABBA"]
[Tue Jul 21 07:39:08.730109 2026] [security2:error] [pid 254995:tid 255263] [client 20.220.225.223:38262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/pn.php"] [unique_id "al9MTP7v0rlcEGmVraFHvQAAA40"]
[Tue Jul 21 07:39:08.732899 2026] [security2:error] [pid 254995:tid 255275] [client 62.102.148.187:60000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MTP7v0rlcEGmVraFHvgAAA5k"]
[Tue Jul 21 07:39:08.732972 2026] [security2:error] [pid 254995:tid 255275] [client 62.102.148.187:60000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MTP7v0rlcEGmVraFHvgAAA5k"]
[Tue Jul 21 07:39:08.744689 2026] [security2:error] [pid 254995:tid 255206] [client 4.204.201.85:4441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/w.php"] [unique_id "al9MTP7v0rlcEGmVraFHvwAAA28"]
[Tue Jul 21 07:39:08.779135 2026] [security2:error] [pid 254995:tid 255159] [client 20.151.10.161:46053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/about.php"] [unique_id "al9MTP7v0rlcEGmVraFHwgAAA0A"]
[Tue Jul 21 07:39:08.889088 2026] [security2:error] [pid 255769:tid 255921] [client 20.220.225.223:38686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/ftde.php"] [unique_id "al9MTLxMYwyVGnfuwsKj9QAAA7k"]
[Tue Jul 21 07:39:08.909797 2026] [security2:error] [pid 255769:tid 255900] [client 20.226.60.151:51311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/output.php"] [unique_id "al9MTLxMYwyVGnfuwsKj9gAAA6Q"]
[Tue Jul 21 07:39:09.022692 2026] [security2:error] [pid 255769:tid 255931] [client 20.226.60.151:56300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/24.php"] [unique_id "al9MTbxMYwyVGnfuwsKj-AAAA8M"]
[Tue Jul 21 07:39:09.088966 2026] [security2:error] [pid 254995:tid 255135] [client 4.204.201.85:4534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/fpwch.php"] [unique_id "al9MTf7v0rlcEGmVraFH0QAAAyg"]
[Tue Jul 21 07:39:09.394189 2026] [security2:error] [pid 254995:tid 255184] [client 4.204.201.85:4510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/w2025.php"] [unique_id "al9MTf7v0rlcEGmVraFH2wAAA1k"]
[Tue Jul 21 07:39:09.508322 2026] [security2:error] [pid 255769:tid 255985] [client 20.226.60.151:51302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-file-120.php"] [unique_id "al9MTbxMYwyVGnfuwsKj-wAAA_k"]
[Tue Jul 21 07:39:09.535949 2026] [security2:error] [pid 255769:tid 256017] [client 122.186.204.214:62273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MTbxMYwyVGnfuwsKj_AAABBc"]
[Tue Jul 21 07:39:09.536074 2026] [security2:error] [pid 255769:tid 256017] [client 122.186.204.214:62273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MTbxMYwyVGnfuwsKj_AAABBc"]
[Tue Jul 21 07:39:09.726960 2026] [security2:error] [pid 255769:tid 255959] [client 4.204.201.85:4466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/FWAZ.php"] [unique_id "al9MTbxMYwyVGnfuwsKj_gAAA98"]
[Tue Jul 21 07:39:09.907463 2026] [security2:error] [pid 254995:tid 255157] [client 117.251.86.144:49470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MTf7v0rlcEGmVraFH5wAAAz4"]
[Tue Jul 21 07:39:09.907597 2026] [security2:error] [pid 254995:tid 255157] [client 117.251.86.144:49470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MTf7v0rlcEGmVraFH5wAAAz4"]
[Tue Jul 21 07:39:09.944602 2026] [security2:error] [pid 254995:tid 255069] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MTf7v0rlcEGmVraFH6AADbkk"]
[Tue Jul 21 07:39:09.944769 2026] [security2:error] [pid 254995:tid 255205] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MTf7v0rlcEGmVraFH6AADbkk"]
[Tue Jul 21 07:39:10.069474 2026] [security2:error] [pid 254995:tid 255199] [client 4.204.201.85:49817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/qterm.php"] [unique_id "al9MTv7v0rlcEGmVraFH6gAAA2g"]
[Tue Jul 21 07:39:10.075349 2026] [security2:error] [pid 254995:tid 255042] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MTv7v0rlcEGmVraFH6wADmi4"]
[Tue Jul 21 07:39:10.075485 2026] [security2:error] [pid 254995:tid 255276] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MTv7v0rlcEGmVraFH6wADmi4"]
[Tue Jul 21 07:39:10.119742 2026] [security2:error] [pid 254995:tid 255129] [client 20.226.60.151:27354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ssend.php"] [unique_id "al9MTv7v0rlcEGmVraFH7wAAAyI"]
[Tue Jul 21 07:39:10.120310 2026] [security2:error] [pid 254995:tid 255169] [client 20.226.60.151:56309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/xacs.php"] [unique_id "al9MTv7v0rlcEGmVraFH8AAAA0o"]
[Tue Jul 21 07:39:10.133225 2026] [security2:error] [pid 254995:tid 255255] [client 20.206.105.145:38467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/file15.php"] [unique_id "al9MTv7v0rlcEGmVraFH8gAAA4U"]
[Tue Jul 21 07:39:10.366219 2026] [security2:error] [pid 255769:tid 256025] [client 20.226.60.151:51347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/special.php"] [unique_id "al9MTrxMYwyVGnfuwsKkWgAABB8"]
[Tue Jul 21 07:39:10.406520 2026] [security2:error] [pid 255769:tid 255928] [client 4.204.201.85:49884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/blurbs.php"] [unique_id "al9MTrxMYwyVGnfuwsKkrwAAA8A"]
[Tue Jul 21 07:39:10.449849 2026] [qos:error] [pid 255769:tid 256021] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.100.222, id=al9MTrxMYwyVGnfuwsKk9gAABBs, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.449870 2026] [qos:error] [pid 254995:tid 255273] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.100.222, id=al9MTv7v0rlcEGmVraFIJAAAA5c, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.449878 2026] [qos:error] [pid 255769:tid 255951] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.6.100.222, id=al9MTrxMYwyVGnfuwsKk9wAAA9c, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.450119 2026] [qos:error] [pid 255769:tid 255916] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.6.100.222, id=al9MTrxMYwyVGnfuwsKlCwAAA7Q, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.450130 2026] [qos:error] [pid 254995:tid 255222] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=50.6.100.222, id=al9MTv7v0rlcEGmVraFIJgAAA34, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.450156 2026] [qos:error] [pid 254995:tid 255201] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=50.6.100.222, id=al9MTv7v0rlcEGmVraFIKAAAA2o, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.450277 2026] [qos:error] [pid 255769:tid 256018] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.100.222, id=al9MTrxMYwyVGnfuwsKk-QAABBg, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.450466 2026] [qos:error] [pid 254995:tid 255157] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.100.222, id=al9MTv7v0rlcEGmVraFIJwAAAz4, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.450669 2026] [qos:error] [pid 255769:tid 255937] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.100.222, id=al9MTrxMYwyVGnfuwsKk-gAAA8k, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.450679 2026] [qos:error] [pid 255769:tid 255971] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.100.222, id=al9MTrxMYwyVGnfuwsKk_AAAA-s, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.451260 2026] [qos:error] [pid 255769:tid 255932] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.100.222, id=al9MTrxMYwyVGnfuwsKk_gAAA8Q, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.451269 2026] [qos:error] [pid 255769:tid 255899] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.100.222, id=al9MTrxMYwyVGnfuwsKk_QAAA6M, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.452162 2026] [security2:error] [pid 254995:tid 255260] [client 20.151.10.161:46069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/admin.php"] [unique_id "al9MTv7v0rlcEGmVraFILgAAA4o"]
[Tue Jul 21 07:39:10.452944 2026] [qos:error] [pid 255769:tid 255923] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.100.222, id=al9MTrxMYwyVGnfuwsKlDAAAA7s, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.795923 2026] [security2:error] [pid 255769:tid 255986] [client 4.204.201.85:4449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/v543.php"] [unique_id "al9MTrxMYwyVGnfuwsKlGAAAA_o"]
[Tue Jul 21 07:39:11.040597 2026] [autoindex:error] [pid 254995:tid 255138] [client 66.132.186.182:61114] AH01276: Cannot serve directory /home2/rica0429/gradiente.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:11.094826 2026] [security2:error] [pid 254995:tid 255217] [client 4.204.201.85:49816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/w3lls.php"] [unique_id "al9MT_7v0rlcEGmVraFIPwAAA3k"]
[Tue Jul 21 07:39:11.338286 2026] [security2:error] [pid 254995:tid 255132] [client 193.36.225.58:60707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MT_7v0rlcEGmVraFIRAAAAyU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:11.505748 2026] [security2:error] [pid 254995:tid 255177] [client 4.204.201.85:49840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-ws68.php"] [unique_id "al9MT_7v0rlcEGmVraFISQAAA1I"]
[Tue Jul 21 07:39:11.672147 2026] [security2:error] [pid 255769:tid 255937] [client 194.99.104.35:40302] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MT7xMYwyVGnfuwsKlIgAAA8k"]
[Tue Jul 21 07:39:11.672273 2026] [security2:error] [pid 255769:tid 255937] [client 194.99.104.35:40302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MT7xMYwyVGnfuwsKlIgAAA8k"]
[Tue Jul 21 07:39:11.741636 2026] [security2:error] [pid 255769:tid 255997] [client 20.226.60.151:27576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/item.php"] [unique_id "al9MT7xMYwyVGnfuwsKlJQAABAM"]
[Tue Jul 21 07:39:11.776803 2026] [security2:error] [pid 255769:tid 255922] [client 154.192.233.199:59259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MT7xMYwyVGnfuwsKlKAAAA7o"]
[Tue Jul 21 07:39:11.776947 2026] [security2:error] [pid 255769:tid 255922] [client 154.192.233.199:59259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MT7xMYwyVGnfuwsKlKAAAA7o"]
[Tue Jul 21 07:39:11.778993 2026] [security2:error] [pid 255769:tid 255984] [client 20.151.10.161:46079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/edit.php"] [unique_id "al9MT7xMYwyVGnfuwsKlKQAAA_g"]
[Tue Jul 21 07:39:11.829617 2026] [security2:error] [pid 254995:tid 255198] [client 4.204.201.85:49796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/xyn.php"] [unique_id "al9MT_7v0rlcEGmVraFITAAAA2c"]
[Tue Jul 21 07:39:11.893714 2026] [security2:error] [pid 255769:tid 255935] [client 20.226.60.151:56200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/zildan.php"] [unique_id "al9MT7xMYwyVGnfuwsKlLAAAA8c"]
[Tue Jul 21 07:39:11.970317 2026] [security2:error] [pid 255769:tid 255996] [client 20.226.60.151:51349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/as.php"] [unique_id "al9MT7xMYwyVGnfuwsKlLwAABAI"]
[Tue Jul 21 07:39:12.058846 2026] [security2:error] [pid 255769:tid 255925] [client 175.45.70.82:51194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKlMQAAA70"]
[Tue Jul 21 07:39:12.058964 2026] [security2:error] [pid 255769:tid 255925] [client 175.45.70.82:51194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKlMQAAA70"]
[Tue Jul 21 07:39:12.096483 2026] [security2:error] [pid 255769:tid 256013] [client 122.164.127.47:59522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKlMgAABBM"]
[Tue Jul 21 07:39:12.096600 2026] [security2:error] [pid 255769:tid 256013] [client 122.164.127.47:59522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKlMgAABBM"]
[Tue Jul 21 07:39:12.135128 2026] [security2:error] [pid 255769:tid 255901] [client 4.204.201.85:49900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/green3.php"] [unique_id "al9MULxMYwyVGnfuwsKlNgAAA6U"]
[Tue Jul 21 07:39:12.387729 2026] [security2:error] [pid 254995:tid 255160] [client 20.226.60.151:56220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/csa.php"] [unique_id "al9MUP7v0rlcEGmVraFIXwAAA0E"]
[Tue Jul 21 07:39:12.390208 2026] [security2:error] [pid 254995:tid 255142] [client 20.206.105.145:38091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/jp.php"] [unique_id "al9MUP7v0rlcEGmVraFIYAAAAy8"]
[Tue Jul 21 07:39:12.399451 2026] [security2:error] [pid 255769:tid 256003] [client 122.162.144.145:9947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKlcgAABAk"]
[Tue Jul 21 07:39:12.399544 2026] [security2:error] [pid 255769:tid 256003] [client 122.162.144.145:9947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKlcgAABAk"]
[Tue Jul 21 07:39:12.439433 2026] [security2:error] [pid 254995:tid 255181] [client 20.226.60.151:51340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9MUP7v0rlcEGmVraFIdgAAA1Y"]
[Tue Jul 21 07:39:12.482989 2026] [security2:error] [pid 255769:tid 255980] [client 4.204.201.85:4485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/ccc.php"] [unique_id "al9MULxMYwyVGnfuwsKldwAAA_Q"]
[Tue Jul 21 07:39:12.568555 2026] [security2:error] [pid 255769:tid 255956] [client 103.106.20.201:57525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKlkwAAA9w"]
[Tue Jul 21 07:39:12.568642 2026] [security2:error] [pid 255769:tid 255956] [client 103.106.20.201:57525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKlkwAAA9w"]
[Tue Jul 21 07:39:12.569298 2026] [security2:error] [pid 255769:tid 255888] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKllAAD13Y"]
[Tue Jul 21 07:39:12.569382 2026] [security2:error] [pid 255769:tid 255951] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKllAAD13Y"]
[Tue Jul 21 07:39:12.629367 2026] [security2:error] [pid 255769:tid 255790] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKlqQAD_xQ"]
[Tue Jul 21 07:39:12.629509 2026] [security2:error] [pid 255769:tid 255992] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKlqQAD_xQ"]
[Tue Jul 21 07:39:12.727266 2026] [security2:error] [pid 255769:tid 256012] [client 20.197.192.193:6883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/koiy.php"] [unique_id "al9MULxMYwyVGnfuwsKlrQAABBI"]
[Tue Jul 21 07:39:12.847364 2026] [security2:error] [pid 255769:tid 255985] [client 20.226.60.151:61005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/w1px.php"] [unique_id "al9MULxMYwyVGnfuwsKltAAAA_k"]
[Tue Jul 21 07:39:12.859376 2026] [security2:error] [pid 254995:tid 255162] [client 20.226.60.151:27572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ss.php"] [unique_id "al9MUP7v0rlcEGmVraFIwgAAA0M"]
[Tue Jul 21 07:39:12.942208 2026] [security2:error] [pid 255769:tid 255930] [client 4.204.201.85:4520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/get.php"] [unique_id "al9MULxMYwyVGnfuwsKlwQAAA8I"]
[Tue Jul 21 07:39:13.297254 2026] [security2:error] [pid 254995:tid 255258] [client 20.226.60.151:61239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/yawa.php"] [unique_id "al9MUf7v0rlcEGmVraFIyQAAA4g"]
[Tue Jul 21 07:39:13.319983 2026] [security2:error] [pid 254995:tid 255220] [client 4.204.201.85:4496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/images.php"] [unique_id "al9MUf7v0rlcEGmVraFIygAAA3w"]
[Tue Jul 21 07:39:13.348366 2026] [security2:error] [pid 255769:tid 255909] [client 20.151.10.161:46032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MUbxMYwyVGnfuwsKlxAAAA60"]
[Tue Jul 21 07:39:13.641674 2026] [security2:error] [pid 255769:tid 256003] [client 20.220.225.223:22502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9MUbxMYwyVGnfuwsKlygAABAk"]
[Tue Jul 21 07:39:13.691929 2026] [security2:error] [pid 255769:tid 255983] [client 20.197.192.193:7021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/hp2.php"] [unique_id "al9MUbxMYwyVGnfuwsKlzAAAA_c"]
[Tue Jul 21 07:39:13.716379 2026] [security2:error] [pid 255769:tid 255906] [client 20.226.60.151:51385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/js.php"] [unique_id "al9MUbxMYwyVGnfuwsKlzQAAA6o"]
[Tue Jul 21 07:39:13.719058 2026] [security2:error] [pid 255769:tid 255932] [client 4.204.201.85:4487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/alls.php"] [unique_id "al9MUbxMYwyVGnfuwsKlzgAAA8Q"]
[Tue Jul 21 07:39:14.036901 2026] [security2:error] [pid 254995:tid 255275] [client 4.204.201.85:21823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/coffexium.php"] [unique_id "al9MUv7v0rlcEGmVraFI1QAAA5k"]
[Tue Jul 21 07:39:14.075800 2026] [security2:error] [pid 255769:tid 255956] [client 20.226.60.151:51355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/core.php"] [unique_id "al9MUrxMYwyVGnfuwsKl_AAAA9w"]
[Tue Jul 21 07:39:14.153051 2026] [security2:error] [pid 254995:tid 255177] [client 20.226.60.151:51369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/19.php"] [unique_id "al9MUv7v0rlcEGmVraFI2gAAA1I"]
[Tue Jul 21 07:39:14.209474 2026] [security2:error] [pid 255769:tid 255999] [client 20.226.60.151:51322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/inc.php"] [unique_id "al9MUrxMYwyVGnfuwsKmBAAABAU"]
[Tue Jul 21 07:39:14.272122 2026] [security2:error] [pid 255769:tid 255942] [client 103.86.117.203:59333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MUrxMYwyVGnfuwsKmBQAAA84"]
[Tue Jul 21 07:39:14.272270 2026] [security2:error] [pid 255769:tid 255942] [client 103.86.117.203:59333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MUrxMYwyVGnfuwsKmBQAAA84"]
[Tue Jul 21 07:39:14.295265 2026] [security2:error] [pid 254995:tid 255201] [client 20.226.60.151:61214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9MUv7v0rlcEGmVraFI2wAAA2o"]
[Tue Jul 21 07:39:14.338222 2026] [security2:error] [pid 254995:tid 255262] [client 4.204.201.85:49793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/red.php"] [unique_id "al9MUv7v0rlcEGmVraFI3AAAA4w"]
[Tue Jul 21 07:39:14.427529 2026] [security2:error] [pid 255769:tid 255946] [client 20.226.60.151:27377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/hypo.php"] [unique_id "al9MUrxMYwyVGnfuwsKmBgAAA9I"]
[Tue Jul 21 07:39:14.438324 2026] [security2:error] [pid 255769:tid 255992] [client 20.226.60.151:61187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9MUrxMYwyVGnfuwsKmCAAAA_8"]
[Tue Jul 21 07:39:14.442875 2026] [security2:error] [pid 255769:tid 255958] [client 20.226.60.151:56304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/w3llscc.php"] [unique_id "al9MUrxMYwyVGnfuwsKmCQAAA94"]
[Tue Jul 21 07:39:14.493130 2026] [security2:error] [pid 255769:tid 256028] [client 20.206.105.145:38097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/f35.php"] [unique_id "al9MUrxMYwyVGnfuwsKmCwAABCI"]
[Tue Jul 21 07:39:14.601507 2026] [security2:error] [pid 255769:tid 255974] [client 20.226.60.151:51348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ss.php"] [unique_id "al9MUrxMYwyVGnfuwsKmDwAAA-4"]
[Tue Jul 21 07:39:14.689922 2026] [security2:error] [pid 255769:tid 255943] [client 20.226.60.151:51343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/min.php"] [unique_id "al9MUrxMYwyVGnfuwsKmEwAAA88"]
[Tue Jul 21 07:39:14.758979 2026] [security2:error] [pid 255769:tid 256013] [client 20.220.225.223:31190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/yup.php"] [unique_id "al9MUrxMYwyVGnfuwsKmFQAABBM"]
[Tue Jul 21 07:39:14.785989 2026] [autoindex:error] [pid 255769:tid 256000] [client 4.204.201.85:49883] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:14.908218 2026] [security2:error] [pid 255769:tid 255920] [client 103.174.34.15:63565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MUrxMYwyVGnfuwsKmFwAAA7g"]
[Tue Jul 21 07:39:14.908371 2026] [security2:error] [pid 255769:tid 255920] [client 103.174.34.15:63565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MUrxMYwyVGnfuwsKmFwAAA7g"]
[Tue Jul 21 07:39:14.989573 2026] [security2:error] [pid 254995:tid 255219] [client 59.96.220.140:64528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MUv7v0rlcEGmVraFI5wAAA3s"]
[Tue Jul 21 07:39:14.990189 2026] [security2:error] [pid 254995:tid 255219] [client 59.96.220.140:64528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MUv7v0rlcEGmVraFI5wAAA3s"]
[Tue Jul 21 07:39:15.060280 2026] [security2:error] [pid 255769:tid 255901] [client 4.204.201.85:49883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9MU7xMYwyVGnfuwsKmGwAAA6U"]
[Tue Jul 21 07:39:15.153264 2026] [security2:error] [pid 254995:tid 255279] [client 194.99.104.35:40318] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9MU_7v0rlcEGmVraFI6wAAA50"]
[Tue Jul 21 07:39:15.153383 2026] [security2:error] [pid 254995:tid 255279] [client 194.99.104.35:40318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9MU_7v0rlcEGmVraFI6wAAA50"]
[Tue Jul 21 07:39:15.254450 2026] [security2:error] [pid 255769:tid 255987] [client 193.36.225.69:36737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MU7xMYwyVGnfuwsKmHAAAA_s"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:15.385463 2026] [security2:error] [pid 255769:tid 255968] [client 20.151.10.161:45985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/f6.php"] [unique_id "al9MU7xMYwyVGnfuwsKmMQAAA-g"]
[Tue Jul 21 07:39:15.387671 2026] [autoindex:error] [pid 255769:tid 255963] [client 4.204.201.85:4503] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:15.546389 2026] [security2:error] [pid 255769:tid 255954] [client 20.226.60.151:27642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/users.php"] [unique_id "al9MU7xMYwyVGnfuwsKmNgAAA9o"]
[Tue Jul 21 07:39:15.548278 2026] [security2:error] [pid 254995:tid 255010] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MU_7v0rlcEGmVraFJVQADjg4"]
[Tue Jul 21 07:39:15.548413 2026] [security2:error] [pid 254995:tid 255264] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MU_7v0rlcEGmVraFJVQADjg4"]
[Tue Jul 21 07:39:15.685683 2026] [autoindex:error] [pid 255769:tid 256010] [client 4.204.201.85:4503] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:15.825946 2026] [security2:error] [pid 255769:tid 255958] [client 4.204.201.85:4503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-content/index.php"] [unique_id "al9MU7xMYwyVGnfuwsKmOgAAA94"]
[Tue Jul 21 07:39:15.825996 2026] [security2:error] [pid 255769:tid 255992] [client 20.226.60.151:61033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9MU7xMYwyVGnfuwsKmOwAAA_8"]
[Tue Jul 21 07:39:15.867739 2026] [security2:error] [pid 254995:tid 255225] [client 62.102.148.187:48566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MU_7v0rlcEGmVraFJWwAAA4E"]
[Tue Jul 21 07:39:15.867853 2026] [security2:error] [pid 254995:tid 255225] [client 62.102.148.187:48566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MU_7v0rlcEGmVraFJWwAAA4E"]
[Tue Jul 21 07:39:15.936463 2026] [security2:error] [pid 254995:tid 255196] [client 20.206.105.145:38140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-load.php"] [unique_id "al9MU_7v0rlcEGmVraFJXQAAA2U"]
[Tue Jul 21 07:39:15.950668 2026] [security2:error] [pid 255769:tid 255907] [client 193.36.225.152:33441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MU7xMYwyVGnfuwsKmPQAAA6s"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:39:16.150207 2026] [security2:error] [pid 255769:tid 255922] [client 4.204.201.85:4476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/admin.php"] [unique_id "al9MVLxMYwyVGnfuwsKmQAAAA7o"]
[Tue Jul 21 07:39:16.521268 2026] [security2:error] [pid 255769:tid 256013] [client 20.226.60.151:61232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9MVLxMYwyVGnfuwsKmRAAABBM"]
[Tue Jul 21 07:39:16.526655 2026] [security2:error] [pid 255769:tid 256000] [client 4.204.201.85:4486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/177.php"] [unique_id "al9MVLxMYwyVGnfuwsKmRQAABAY"]
[Tue Jul 21 07:39:16.551080 2026] [security2:error] [pid 254995:tid 255217] [client 20.220.225.223:31174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/jj.php"] [unique_id "al9MVP7v0rlcEGmVraFJbgAAA3k"]
[Tue Jul 21 07:39:16.726047 2026] [security2:error] [pid 255769:tid 256021] [client 139.167.225.182:53648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MVLxMYwyVGnfuwsKmSAAABBs"]
[Tue Jul 21 07:39:16.726237 2026] [security2:error] [pid 255769:tid 256021] [client 139.167.225.182:53648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MVLxMYwyVGnfuwsKmSAAABBs"]
[Tue Jul 21 07:39:16.875231 2026] [security2:error] [pid 254995:tid 255132] [client 4.204.201.85:49847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/199.php"] [unique_id "al9MVP7v0rlcEGmVraFJcwAAAyU"]
[Tue Jul 21 07:39:16.895922 2026] [security2:error] [pid 254995:tid 255206] [client 20.151.10.161:45904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/inputs.php"] [unique_id "al9MVP7v0rlcEGmVraFJdAAAA28"]
[Tue Jul 21 07:39:17.014176 2026] [security2:error] [pid 254995:tid 255178] [client 20.226.60.151:61205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9MVf7v0rlcEGmVraFJeQAAA1M"]
[Tue Jul 21 07:39:17.069482 2026] [security2:error] [pid 255769:tid 255935] [client 117.217.38.194:57000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MVbxMYwyVGnfuwsKmSQAAA8c"]
[Tue Jul 21 07:39:17.069839 2026] [security2:error] [pid 255769:tid 255935] [client 117.217.38.194:57000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MVbxMYwyVGnfuwsKmSQAAA8c"]
[Tue Jul 21 07:39:17.193559 2026] [security2:error] [pid 255769:tid 255920] [client 4.204.201.85:4427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/file52.php"] [unique_id "al9MVbxMYwyVGnfuwsKmSgAAA7g"]
[Tue Jul 21 07:39:17.199769 2026] [security2:error] [pid 255769:tid 255931] [client 20.226.60.151:51330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9MVbxMYwyVGnfuwsKmTAAAA8M"]
[Tue Jul 21 07:39:17.240196 2026] [security2:error] [pid 255769:tid 256004] [client 20.226.60.151:51371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/albin.php"] [unique_id "al9MVbxMYwyVGnfuwsKmTgAABAo"]
[Tue Jul 21 07:39:17.303864 2026] [security2:error] [pid 255769:tid 255987] [client 20.226.60.151:61233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/cilus.php"] [unique_id "al9MVbxMYwyVGnfuwsKmTwAAA_s"]
[Tue Jul 21 07:39:17.403903 2026] [security2:error] [pid 255769:tid 256014] [client 20.226.60.151:55347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/gptsh.php"] [unique_id "al9MVbxMYwyVGnfuwsKmUQAABBQ"]
[Tue Jul 21 07:39:17.489895 2026] [security2:error] [pid 255769:tid 255990] [client 20.226.60.151:51391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/rithin.php"] [unique_id "al9MVbxMYwyVGnfuwsKmUwAAA_4"]
[Tue Jul 21 07:39:17.565229 2026] [security2:error] [pid 254995:tid 255160] [client 4.204.201.85:49894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/geck.php"] [unique_id "al9MVf7v0rlcEGmVraFJggAAA0E"]
[Tue Jul 21 07:39:17.755087 2026] [security2:error] [pid 254995:tid 255193] [client 20.226.60.151:51290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/fffm.php"] [unique_id "al9MVf7v0rlcEGmVraFJiwAAA2I"]
[Tue Jul 21 07:39:17.852662 2026] [security2:error] [pid 255769:tid 255902] [client 4.204.201.85:49794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/biufile.php"] [unique_id "al9MVbxMYwyVGnfuwsKmVAAAA6Y"]
[Tue Jul 21 07:39:17.896435 2026] [security2:error] [pid 255769:tid 256017] [client 20.226.60.151:51312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/dfre.php"] [unique_id "al9MVbxMYwyVGnfuwsKmVQAABBc"]
[Tue Jul 21 07:39:17.902139 2026] [security2:error] [pid 254995:tid 255254] [client 20.151.10.161:45969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/av.php"] [unique_id "al9MVf7v0rlcEGmVraFJjgAAA4Q"]
[Tue Jul 21 07:39:17.956994 2026] [security2:error] [pid 255769:tid 255872] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MVbxMYwyVGnfuwsKmVgADrWY"]
[Tue Jul 21 07:39:17.957171 2026] [security2:error] [pid 255769:tid 255909] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MVbxMYwyVGnfuwsKmVgADrWY"]
[Tue Jul 21 07:39:17.970340 2026] [security2:error] [pid 255769:tid 255981] [client 20.206.105.145:38114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/xwpg.php"] [unique_id "al9MVbxMYwyVGnfuwsKmVwAAA_U"]
[Tue Jul 21 07:39:18.173446 2026] [security2:error] [pid 255769:tid 255959] [client 4.204.201.85:4488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/mosty.php"] [unique_id "al9MVrxMYwyVGnfuwsKmWwAAA98"]
[Tue Jul 21 07:39:18.218234 2026] [security2:error] [pid 255769:tid 255946] [client 20.226.60.151:27531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/177.php"] [unique_id "al9MVrxMYwyVGnfuwsKmXgAAA9I"]
[Tue Jul 21 07:39:18.257872 2026] [security2:error] [pid 255769:tid 255907] [client 20.226.60.151:61012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-happy.php"] [unique_id "al9MVrxMYwyVGnfuwsKmXwAAA6s"]
[Tue Jul 21 07:39:18.358687 2026] [security2:error] [pid 254995:tid 255221] [client 20.226.60.151:56211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wpx.php"] [unique_id "al9MVv7v0rlcEGmVraFJlAAAA30"]
[Tue Jul 21 07:39:18.491287 2026] [security2:error] [pid 254995:tid 255225] [client 4.204.201.85:4442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/dejavu.php"] [unique_id "al9MVv7v0rlcEGmVraFJlwAAA4E"]
[Tue Jul 21 07:39:18.517995 2026] [security2:error] [pid 255769:tid 255957] [client 20.197.195.24:13167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MVrxMYwyVGnfuwsKmYQAAA90"]
[Tue Jul 21 07:39:18.532176 2026] [security2:error] [pid 254995:tid 255266] [client 106.215.181.8:29618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MVv7v0rlcEGmVraFJmAAAA5A"]
[Tue Jul 21 07:39:18.532341 2026] [security2:error] [pid 254995:tid 255266] [client 106.215.181.8:29618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MVv7v0rlcEGmVraFJmAAAA5A"]
[Tue Jul 21 07:39:18.533168 2026] [security2:error] [pid 255769:tid 256005] [client 20.197.192.193:6860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/hp3.php"] [unique_id "al9MVrxMYwyVGnfuwsKmYgAABAs"]
[Tue Jul 21 07:39:18.607278 2026] [security2:error] [pid 255769:tid 256013] [client 20.226.60.151:55300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/fpr4.php"] [unique_id "al9MVrxMYwyVGnfuwsKmYwAABBM"]
[Tue Jul 21 07:39:18.887449 2026] [security2:error] [pid 255769:tid 255939] [client 173.24.185.52:61544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MVrxMYwyVGnfuwsKmaQAAA8s"]
[Tue Jul 21 07:39:18.887588 2026] [security2:error] [pid 255769:tid 255939] [client 173.24.185.52:61544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MVrxMYwyVGnfuwsKmaQAAA8s"]
[Tue Jul 21 07:39:18.941961 2026] [security2:error] [pid 254995:tid 255209] [client 117.132.188.205:32974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.188.132.117.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/produtos-higiene.php"] [unique_id "al9MVv7v0rlcEGmVraFJngAAA3E"]
[Tue Jul 21 07:39:18.971882 2026] [security2:error] [pid 254995:tid 255272] [client 4.204.201.85:4506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/aaf.php"] [unique_id "al9MVv7v0rlcEGmVraFJoAAAA5Y"]
[Tue Jul 21 07:39:18.987561 2026] [security2:error] [pid 255769:tid 255987] [client 20.226.60.151:61038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/file88.php"] [unique_id "al9MVrxMYwyVGnfuwsKmagAAA_s"]
[Tue Jul 21 07:39:19.036258 2026] [security2:error] [pid 254995:tid 255277] [client 136.144.33.29:39051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MV_7v0rlcEGmVraFJpAAAA5s"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:19.339616 2026] [security2:error] [pid 255769:tid 255941] [client 4.204.201.85:49797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/ha.php"] [unique_id "al9MV7xMYwyVGnfuwsKmcAAAA80"]
[Tue Jul 21 07:39:19.591420 2026] [security2:error] [pid 255769:tid 256003] [client 184.75.223.211:40304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MV7xMYwyVGnfuwsKmdAAABAk"]
[Tue Jul 21 07:39:19.591542 2026] [security2:error] [pid 255769:tid 256003] [client 184.75.223.211:40304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MV7xMYwyVGnfuwsKmdAAABAk"]
[Tue Jul 21 07:39:19.620678 2026] [security2:error] [pid 254995:tid 255164] [client 20.226.60.151:61189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ccc.php"] [unique_id "al9MV_7v0rlcEGmVraFJtAAAA0U"]
[Tue Jul 21 07:39:19.665126 2026] [security2:error] [pid 255769:tid 255902] [client 4.204.201.85:4527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/hur.php"] [unique_id "al9MV7xMYwyVGnfuwsKmdgAAA6Y"]
[Tue Jul 21 07:39:19.737347 2026] [security2:error] [pid 255769:tid 255919] [client 20.197.195.24:13145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MV7xMYwyVGnfuwsKmeQAAA7c"]
[Tue Jul 21 07:39:19.838340 2026] [security2:error] [pid 255769:tid 255956] [client 193.36.225.105:47497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MV7xMYwyVGnfuwsKmewAAA9w"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:39:19.903927 2026] [security2:error] [pid 254995:tid 255199] [client 20.226.60.151:51294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/777.php"] [unique_id "al9MV_7v0rlcEGmVraFJvgAAA2g"]
[Tue Jul 21 07:39:19.949878 2026] [security2:error] [pid 255769:tid 255979] [client 4.204.201.85:49856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/h02ugyh.php"] [unique_id "al9MV7xMYwyVGnfuwsKmfAAAA_M"]
[Tue Jul 21 07:39:20.044792 2026] [security2:error] [pid 255769:tid 255967] [client 20.226.60.151:27633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/config.php"] [unique_id "al9MWLxMYwyVGnfuwsKmfQAAA-c"]
[Tue Jul 21 07:39:20.102477 2026] [security2:error] [pid 255769:tid 255976] [client 20.197.192.193:6891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/aa1.php"] [unique_id "al9MWLxMYwyVGnfuwsKmfgAAA_A"]
[Tue Jul 21 07:39:20.266142 2026] [security2:error] [pid 255769:tid 255992] [client 4.204.201.85:4530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/155.php"] [unique_id "al9MWLxMYwyVGnfuwsKmgAAAA_8"]
[Tue Jul 21 07:39:20.281306 2026] [security2:error] [pid 255769:tid 255960] [client 122.186.204.214:62803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MWLxMYwyVGnfuwsKmgQAAA-A"]
[Tue Jul 21 07:39:20.281447 2026] [security2:error] [pid 255769:tid 255960] [client 122.186.204.214:62803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MWLxMYwyVGnfuwsKmgQAAA-A"]
[Tue Jul 21 07:39:20.368616 2026] [security2:error] [pid 255769:tid 255927] [client 20.220.225.223:38668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/dragonshell.php"] [unique_id "al9MWLxMYwyVGnfuwsKmhAAAA78"]
[Tue Jul 21 07:39:20.376470 2026] [security2:error] [pid 254995:tid 255160] [client 20.151.10.161:45962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/classwithtostring.php"] [unique_id "al9MWP7v0rlcEGmVraFJyQAAA0E"]
[Tue Jul 21 07:39:20.442880 2026] [security2:error] [pid 255769:tid 255999] [client 20.226.60.151:61011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/for.php"] [unique_id "al9MWLxMYwyVGnfuwsKmhQAABAU"]
[Tue Jul 21 07:39:20.574227 2026] [security2:error] [pid 255769:tid 255982] [client 20.226.60.151:27598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/gettest.php"] [unique_id "al9MWLxMYwyVGnfuwsKmhgAAA_Y"]
[Tue Jul 21 07:39:20.577466 2026] [security2:error] [pid 254995:tid 255157] [client 4.204.201.85:56660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/pp.php"] [unique_id "al9MWP7v0rlcEGmVraFJzAAAAz4"]
[Tue Jul 21 07:39:20.617032 2026] [security2:error] [pid 255769:tid 255965] [client 117.251.86.144:33500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MWLxMYwyVGnfuwsKmhwAAA-U"]
[Tue Jul 21 07:39:20.617165 2026] [security2:error] [pid 255769:tid 255965] [client 117.251.86.144:33500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MWLxMYwyVGnfuwsKmhwAAA-U"]
[Tue Jul 21 07:39:20.631626 2026] [security2:error] [pid 254995:tid 255140] [client 20.197.195.24:13084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/media.php"] [unique_id "al9MWP7v0rlcEGmVraFJzgAAAy0"]
[Tue Jul 21 07:39:20.667399 2026] [security2:error] [pid 255769:tid 255858] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MWLxMYwyVGnfuwsKmiAADq1g"]
[Tue Jul 21 07:39:20.667582 2026] [security2:error] [pid 255769:tid 255907] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MWLxMYwyVGnfuwsKmiAADq1g"]
[Tue Jul 21 07:39:20.790623 2026] [security2:error] [pid 255769:tid 256013] [client 20.220.225.223:31192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/wp-mt.php"] [unique_id "al9MWLxMYwyVGnfuwsKmigAABBM"]
[Tue Jul 21 07:39:20.791430 2026] [security2:error] [pid 255769:tid 255909] [client 152.59.154.239:62233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MWLxMYwyVGnfuwsKmiwAAA60"]
[Tue Jul 21 07:39:20.791567 2026] [security2:error] [pid 255769:tid 255909] [client 152.59.154.239:62233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MWLxMYwyVGnfuwsKmiwAAA60"]
[Tue Jul 21 07:39:20.791618 2026] [security2:error] [pid 255769:tid 255788] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MWLxMYwyVGnfuwsKmjAADuhI"]
[Tue Jul 21 07:39:20.791737 2026] [security2:error] [pid 255769:tid 255922] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MWLxMYwyVGnfuwsKmjAADuhI"]
[Tue Jul 21 07:39:20.861513 2026] [security2:error] [pid 254995:tid 255149] [client 4.204.201.85:49858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/ops.php"] [unique_id "al9MWP7v0rlcEGmVraFJ0gAAAzY"]
[Tue Jul 21 07:39:21.026611 2026] [security2:error] [pid 255769:tid 255935] [client 20.226.60.151:27350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/min.php"] [unique_id "al9MWbxMYwyVGnfuwsKmkAAAA8c"]
[Tue Jul 21 07:39:21.115389 2026] [security2:error] [pid 254995:tid 255193] [client 117.132.188.205:32975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.188.132.117.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/produtos-fast.php"] [unique_id "al9MWf7v0rlcEGmVraFJ1wAAA2I"]
[Tue Jul 21 07:39:21.130409 2026] [security2:error] [pid 255769:tid 255908] [client 20.226.60.151:27386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/dvjul.php"] [unique_id "al9MWbxMYwyVGnfuwsKmkQAAA6w"]
[Tue Jul 21 07:39:21.157903 2026] [security2:error] [pid 254995:tid 255264] [client 20.226.60.151:27529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/biufile.php"] [unique_id "al9MWf7v0rlcEGmVraFJ2AAAA44"]
[Tue Jul 21 07:39:21.159925 2026] [security2:error] [pid 255769:tid 255901] [client 4.204.201.85:21759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/ingfo.php"] [unique_id "al9MWbxMYwyVGnfuwsKmkgAAA6U"]
[Tue Jul 21 07:39:21.207983 2026] [autoindex:error] [pid 255769:tid 255934] [client 20.206.105.145:38511] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:21.272300 2026] [autoindex:error] [pid 255769:tid 255996] [client 20.206.105.145:38511] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:21.278254 2026] [security2:error] [pid 255769:tid 255921] [client 20.206.105.145:38511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/waf.php"] [unique_id "al9MWbxMYwyVGnfuwsKmlwAAA7k"]
[Tue Jul 21 07:39:21.400773 2026] [security2:error] [pid 255769:tid 256014] [client 20.197.195.24:13133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/images.php"] [unique_id "al9MWbxMYwyVGnfuwsKmmAAABBQ"]
[Tue Jul 21 07:39:21.438489 2026] [security2:error] [pid 254995:tid 255185] [client 4.204.201.85:49835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/error_log.php"] [unique_id "al9MWf7v0rlcEGmVraFJ3wAAA1o"]
[Tue Jul 21 07:39:21.662698 2026] [security2:error] [pid 254995:tid 255004] [remote 45.79.123.44:46224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9MWf7v0rlcEGmVraFJ4gADnQg"]
[Tue Jul 21 07:39:21.713871 2026] [security2:error] [pid 254995:tid 255209] [client 74.7.244.16:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "maikikaufmann1781880068561.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9MWf7v0rlcEGmVraFJ5AADcVs"]
[Tue Jul 21 07:39:21.716634 2026] [security2:error] [pid 255769:tid 255953] [client 4.204.201.85:49841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/test10.php"] [unique_id "al9MWbxMYwyVGnfuwsKmmwAAA9k"]
[Tue Jul 21 07:39:21.847046 2026] [security2:error] [pid 255769:tid 255978] [client 20.226.60.151:56235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-css.php"] [unique_id "al9MWbxMYwyVGnfuwsKmnQAAA_I"]
[Tue Jul 21 07:39:21.914274 2026] [security2:error] [pid 255769:tid 255928] [client 20.151.10.161:46075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9MWbxMYwyVGnfuwsKmngAAA8A"]
[Tue Jul 21 07:39:21.930935 2026] [security2:error] [pid 255769:tid 255918] [client 20.226.60.151:27533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/av.php"] [unique_id "al9MWbxMYwyVGnfuwsKmoQAAA7Y"]
[Tue Jul 21 07:39:21.968590 2026] [security2:error] [pid 255769:tid 255919] [client 20.226.60.151:51366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ssla.php"] [unique_id "al9MWbxMYwyVGnfuwsKmogAAA7c"]
[Tue Jul 21 07:39:22.004920 2026] [security2:error] [pid 255769:tid 255988] [client 4.204.201.85:4540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/koala.php"] [unique_id "al9MWrxMYwyVGnfuwsKmowAAA_w"]
[Tue Jul 21 07:39:22.242819 2026] [security2:error] [pid 255769:tid 255910] [client 117.132.188.205:32976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.188.132.117.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/produtos-confeitaria.php"] [unique_id "al9MWrxMYwyVGnfuwsKmpAAAA64"]
[Tue Jul 21 07:39:22.274848 2026] [security2:error] [pid 255769:tid 255973] [client 20.197.195.24:13166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/gecko.php"] [unique_id "al9MWrxMYwyVGnfuwsKmpQAAA-0"]
[Tue Jul 21 07:39:22.282713 2026] [security2:error] [pid 254995:tid 255192] [client 4.204.201.85:49895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/mac.php"] [unique_id "al9MWv7v0rlcEGmVraFJ7wAAA2E"]
[Tue Jul 21 07:39:22.426782 2026] [autoindex:error] [pid 255769:tid 255983] [client 85.204.70.114:48888] AH01276: Cannot serve directory /home1/guiiaz25/werneckepereiraadvogados.guiiaz.com.br/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:22.493865 2026] [security2:error] [pid 255769:tid 255990] [client 154.192.233.199:58603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MWrxMYwyVGnfuwsKmqQAAA_4"]
[Tue Jul 21 07:39:22.494000 2026] [security2:error] [pid 255769:tid 255990] [client 154.192.233.199:58603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MWrxMYwyVGnfuwsKmqQAAA_4"]
[Tue Jul 21 07:39:22.563269 2026] [security2:error] [pid 254995:tid 255184] [client 4.204.201.85:4529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wefile.php"] [unique_id "al9MWv7v0rlcEGmVraFJ9QAAA1k"]
[Tue Jul 21 07:39:22.611631 2026] [security2:error] [pid 254995:tid 255176] [client 122.164.127.47:60027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MWv7v0rlcEGmVraFJ9wAAA1E"]
[Tue Jul 21 07:39:22.611741 2026] [security2:error] [pid 254995:tid 255176] [client 122.164.127.47:60027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MWv7v0rlcEGmVraFJ9wAAA1E"]
[Tue Jul 21 07:39:22.649132 2026] [security2:error] [pid 254995:tid 255178] [client 128.127.105.184:35676] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MWv7v0rlcEGmVraFJ-AAAA1M"]
[Tue Jul 21 07:39:22.649226 2026] [security2:error] [pid 254995:tid 255178] [client 128.127.105.184:35676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MWv7v0rlcEGmVraFJ-AAAA1M"]
[Tue Jul 21 07:39:22.687398 2026] [security2:error] [pid 254995:tid 255199] [client 20.226.60.151:27590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/coffexium.php"] [unique_id "al9MWv7v0rlcEGmVraFJ-gAAA2g"]
[Tue Jul 21 07:39:22.857986 2026] [autoindex:error] [pid 254995:tid 255195] [client 4.204.201.85:4536] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:22.875045 2026] [security2:error] [pid 255769:tid 255968] [client 175.45.70.82:51704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MWrxMYwyVGnfuwsKmrAAAA-g"]
[Tue Jul 21 07:39:22.875152 2026] [security2:error] [pid 255769:tid 255968] [client 175.45.70.82:51704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MWrxMYwyVGnfuwsKmrAAAA-g"]
[Tue Jul 21 07:39:22.922486 2026] [security2:error] [pid 254995:tid 255162] [client 136.144.33.99:26145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MWv7v0rlcEGmVraFKAAAAA0M"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:23.046872 2026] [security2:error] [pid 254995:tid 255200] [client 20.226.60.151:27589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/core.php"] [unique_id "al9MW_7v0rlcEGmVraFKBAAAA2k"]
[Tue Jul 21 07:39:23.118153 2026] [security2:error] [pid 254995:tid 255019] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MW_7v0rlcEGmVraFKBgADexc"]
[Tue Jul 21 07:39:23.118360 2026] [security2:error] [pid 254995:tid 255219] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MW_7v0rlcEGmVraFKBgADexc"]
[Tue Jul 21 07:39:23.163320 2026] [security2:error] [pid 254995:tid 255187] [client 122.162.144.145:32578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MW_7v0rlcEGmVraFKCQAAA1w"]
[Tue Jul 21 07:39:23.163462 2026] [security2:error] [pid 254995:tid 255187] [client 122.162.144.145:32578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MW_7v0rlcEGmVraFKCQAAA1w"]
[Tue Jul 21 07:39:23.163870 2026] [security2:error] [pid 254995:tid 255175] [client 20.220.225.223:34260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MW_7v0rlcEGmVraFKCgAAA1A"]
[Tue Jul 21 07:39:23.181314 2026] [autoindex:error] [pid 254995:tid 255148] [client 4.204.201.85:4536] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:23.184418 2026] [security2:error] [pid 254995:tid 255260] [client 20.197.195.24:13179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/82.php"] [unique_id "al9MW_7v0rlcEGmVraFKCwAAA4o"]
[Tue Jul 21 07:39:23.233302 2026] [security2:error] [pid 254995:tid 255276] [client 103.106.20.201:58108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MW_7v0rlcEGmVraFKDQAAA5o"]
[Tue Jul 21 07:39:23.233991 2026] [security2:error] [pid 254995:tid 255276] [client 103.106.20.201:58108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MW_7v0rlcEGmVraFKDQAAA5o"]
[Tue Jul 21 07:39:23.239094 2026] [security2:error] [pid 254995:tid 255088] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MW_7v0rlcEGmVraFKDgADLVw"]
[Tue Jul 21 07:39:23.239299 2026] [security2:error] [pid 254995:tid 255140] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MW_7v0rlcEGmVraFKDgADLVw"]
[Tue Jul 21 07:39:23.251404 2026] [security2:error] [pid 254995:tid 255045] [remote 41.186.86.12:1565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.site"] [uri "/wp-login.php"] [unique_id "al9MW_7v0rlcEGmVraFKDwADYDE"]
[Tue Jul 21 07:39:23.320431 2026] [security2:error] [pid 254995:tid 255179] [client 4.204.201.85:4536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/makeasmtp.php"] [unique_id "al9MW_7v0rlcEGmVraFKEwAAA1Q"]
[Tue Jul 21 07:39:23.336866 2026] [security2:error] [pid 255769:tid 255984] [client 20.226.60.151:61215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/zc-131.php"] [unique_id "al9MW7xMYwyVGnfuwsKmsgAAA_g"]
[Tue Jul 21 07:39:23.388254 2026] [security2:error] [pid 254995:tid 255151] [client 117.132.188.205:32977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.188.132.117.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/produtos-oriental.php"] [unique_id "al9MW_7v0rlcEGmVraFKFAAAAzg"]
[Tue Jul 21 07:39:23.431128 2026] [security2:error] [pid 255769:tid 255943] [client 20.226.60.151:27552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/als.php"] [unique_id "al9MW7xMYwyVGnfuwsKmtQAAA88"]
[Tue Jul 21 07:39:23.448652 2026] [security2:error] [pid 254995:tid 255193] [client 20.151.10.161:45961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-blog.php"] [unique_id "al9MW_7v0rlcEGmVraFKFgAAA2I"]
[Tue Jul 21 07:39:23.604020 2026] [security2:error] [pid 255769:tid 255962] [client 4.204.201.85:4507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/2P.php"] [unique_id "al9MW7xMYwyVGnfuwsKmuAAAA-I"]
[Tue Jul 21 07:39:23.803183 2026] [security2:error] [pid 254995:tid 255208] [client 20.226.60.151:9360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/simple.php"] [unique_id "al9MW_7v0rlcEGmVraFKGAAAA3A"]
[Tue Jul 21 07:39:23.896997 2026] [security2:error] [pid 255769:tid 255923] [client 4.204.201.85:49890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/.well-known/about.php"] [unique_id "al9MW7xMYwyVGnfuwsKmvAAAA7s"]
[Tue Jul 21 07:39:24.012801 2026] [autoindex:error] [pid 255769:tid 255939] [client 147.185.132.171:57906] AH01276: Cannot serve directory /home2/supr7264/monalizacleaning.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:24.020190 2026] [security2:error] [pid 255769:tid 255974] [client 20.226.60.151:27334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/init.php"] [unique_id "al9MXLxMYwyVGnfuwsKmwAAAA-4"]
[Tue Jul 21 07:39:24.027299 2026] [security2:error] [pid 255769:tid 255987] [client 20.197.195.24:13152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/admin.php"] [unique_id "al9MXLxMYwyVGnfuwsKmwQAAA_s"]
[Tue Jul 21 07:39:24.179419 2026] [security2:error] [pid 255769:tid 255970] [client 4.204.201.85:49843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9MXLxMYwyVGnfuwsKmxAAAA-o"]
[Tue Jul 21 07:39:24.420201 2026] [security2:error] [pid 255769:tid 255918] [client 20.220.225.223:38656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/ww.php"] [unique_id "al9MXLxMYwyVGnfuwsKmyAAAA7Y"]
[Tue Jul 21 07:39:24.470589 2026] [security2:error] [pid 255769:tid 255899] [client 4.204.201.85:49819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/system_log.php"] [unique_id "al9MXLxMYwyVGnfuwsKmyQAAA6M"]
[Tue Jul 21 07:39:24.535552 2026] [security2:error] [pid 255769:tid 256014] [client 117.132.188.205:32978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.188.132.117.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/faleconosco.php"] [unique_id "al9MXLxMYwyVGnfuwsKmygAABBQ"]
[Tue Jul 21 07:39:24.554699 2026] [security2:error] [pid 255769:tid 255980] [client 20.206.105.145:38133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/xstelth.php"] [unique_id "al9MXLxMYwyVGnfuwsKmywAAA_Q"]
[Tue Jul 21 07:39:24.576544 2026] [security2:error] [pid 254995:tid 255147] [client 20.226.60.151:27615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/fpwch.php"] [unique_id "al9MXP7v0rlcEGmVraFKJAAAAzQ"]
[Tue Jul 21 07:39:24.590932 2026] [security2:error] [pid 255769:tid 255936] [client 20.197.195.24:13172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/adminner.php"] [unique_id "al9MXLxMYwyVGnfuwsKmzAAAA8g"]
[Tue Jul 21 07:39:24.637986 2026] [security2:error] [pid 255769:tid 255912] [client 20.197.195.24:13071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/admin.php"] [unique_id "al9MXLxMYwyVGnfuwsKmzgAAA7A"]
[Tue Jul 21 07:39:24.686693 2026] [security2:error] [pid 255769:tid 255988] [client 20.197.195.24:13122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/k.php"] [unique_id "al9MXLxMYwyVGnfuwsKmzwAAA_w"]
[Tue Jul 21 07:39:24.731217 2026] [security2:error] [pid 255769:tid 255951] [client 20.197.195.24:13151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/blurbs.php"] [unique_id "al9MXLxMYwyVGnfuwsKm0AAAA9c"]
[Tue Jul 21 07:39:24.755749 2026] [security2:error] [pid 255769:tid 255950] [client 103.86.117.203:59855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MXLxMYwyVGnfuwsKm0gAAA9Y"]
[Tue Jul 21 07:39:24.755900 2026] [security2:error] [pid 255769:tid 255950] [client 103.86.117.203:59855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MXLxMYwyVGnfuwsKm0gAAA9Y"]
[Tue Jul 21 07:39:24.770200 2026] [security2:error] [pid 255769:tid 255983] [client 20.220.225.223:31885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/dr.php"] [unique_id "al9MXLxMYwyVGnfuwsKm0wAAA_c"]
[Tue Jul 21 07:39:24.801393 2026] [autoindex:error] [pid 255769:tid 255973] [client 4.204.201.85:4519] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:24.900157 2026] [security2:error] [pid 255769:tid 255889] [remote 124.55.178.99:59622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9MXLxMYwyVGnfuwsKm2wAD8nc"]
[Tue Jul 21 07:39:24.960895 2026] [security2:error] [pid 254995:tid 255275] [client 20.226.60.151:9347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/domvf.php"] [unique_id "al9MXP7v0rlcEGmVraFKLwAAA5k"]
[Tue Jul 21 07:39:25.001989 2026] [security2:error] [pid 255769:tid 255927] [client 20.197.195.24:13180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/bajah.php"] [unique_id "al9MXbxMYwyVGnfuwsKm3AAAA78"]
[Tue Jul 21 07:39:25.130729 2026] [autoindex:error] [pid 255769:tid 255999] [client 4.204.201.85:4519] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:25.269038 2026] [security2:error] [pid 255769:tid 256025] [client 4.204.201.85:4519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/crgio.php"] [unique_id "al9MXbxMYwyVGnfuwsKm4AAABB8"]
[Tue Jul 21 07:39:25.269663 2026] [security2:error] [pid 255769:tid 255833] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MXbxMYwyVGnfuwsKm4QADpz8"]
[Tue Jul 21 07:39:25.269781 2026] [security2:error] [pid 255769:tid 255903] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MXbxMYwyVGnfuwsKm4QADpz8"]
[Tue Jul 21 07:39:25.279917 2026] [security2:error] [pid 255769:tid 255957] [client 20.197.195.24:13082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/a.php"] [unique_id "al9MXbxMYwyVGnfuwsKm4gAAA90"]
[Tue Jul 21 07:39:25.288134 2026] [security2:error] [pid 255769:tid 256019] [client 20.226.60.151:27342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp.php"] [unique_id "al9MXbxMYwyVGnfuwsKm4wAABBk"]
[Tue Jul 21 07:39:25.562446 2026] [security2:error] [pid 254995:tid 255192] [client 103.174.34.15:64255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MXf7v0rlcEGmVraFKOgAAA2E"]
[Tue Jul 21 07:39:25.562580 2026] [security2:error] [pid 254995:tid 255192] [client 103.174.34.15:64255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MXf7v0rlcEGmVraFKOgAAA2E"]
[Tue Jul 21 07:39:25.574447 2026] [security2:error] [pid 255769:tid 255985] [client 4.204.201.85:49862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/pucci.php"] [unique_id "al9MXbxMYwyVGnfuwsKm5QAAA_k"]
[Tue Jul 21 07:39:25.597223 2026] [security2:error] [pid 254995:tid 255270] [client 20.226.60.151:27343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/class.php"] [unique_id "al9MXf7v0rlcEGmVraFKOwAAA5Q"]
[Tue Jul 21 07:39:25.623159 2026] [security2:error] [pid 254995:tid 255162] [client 20.206.105.145:38111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-links.php"] [unique_id "al9MXf7v0rlcEGmVraFKQAAAA0M"]
[Tue Jul 21 07:39:25.706066 2026] [security2:error] [pid 254995:tid 255206] [client 117.132.188.205:32979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.188.132.117.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/eventos.php"] [unique_id "al9MXf7v0rlcEGmVraFKQQAAA28"]
[Tue Jul 21 07:39:25.820491 2026] [security2:error] [pid 255769:tid 256009] [client 20.197.192.193:6879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/acew67.php"] [unique_id "al9MXbxMYwyVGnfuwsKm5wAABA8"]
[Tue Jul 21 07:39:25.866132 2026] [autoindex:error] [pid 255769:tid 255904] [client 4.204.201.85:4424] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:25.898487 2026] [security2:error] [pid 254995:tid 255182] [client 20.197.195.24:13141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/edit.php"] [unique_id "al9MXf7v0rlcEGmVraFKQwAAA1c"]
[Tue Jul 21 07:39:26.118668 2026] [security2:error] [pid 255769:tid 255947] [client 20.220.225.223:34261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MXrxMYwyVGnfuwsKm7AAAA9M"]
[Tue Jul 21 07:39:26.151339 2026] [autoindex:error] [pid 255769:tid 255953] [client 4.204.201.85:4424] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:26.169454 2026] [security2:error] [pid 254995:tid 255212] [client 20.151.10.161:46029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MXv7v0rlcEGmVraFKSgAAA3Q"]
[Tue Jul 21 07:39:26.210923 2026] [security2:error] [pid 255769:tid 255842] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MXrxMYwyVGnfuwsKm8AADzEg"]
[Tue Jul 21 07:39:26.211104 2026] [security2:error] [pid 255769:tid 255940] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MXrxMYwyVGnfuwsKm8AADzEg"]
[Tue Jul 21 07:39:26.214946 2026] [security2:error] [pid 255769:tid 255970] [client 20.197.195.24:13072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/hosty.php"] [unique_id "al9MXrxMYwyVGnfuwsKm8QAAA-o"]
[Tue Jul 21 07:39:26.264736 2026] [security2:error] [pid 254995:tid 255191] [client 20.226.60.151:56314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/ho.php"] [unique_id "al9MXv7v0rlcEGmVraFKTQAAA2A"]
[Tue Jul 21 07:39:26.272309 2026] [security2:error] [pid 254995:tid 255158] [client 20.220.225.223:31188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/cron.php"] [unique_id "al9MXv7v0rlcEGmVraFKTgAAAz8"]
[Tue Jul 21 07:39:26.289384 2026] [security2:error] [pid 255769:tid 255944] [client 4.204.201.85:4424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-temp.php"] [unique_id "al9MXrxMYwyVGnfuwsKm8wAAA9A"]
[Tue Jul 21 07:39:26.334761 2026] [security2:error] [pid 254995:tid 255179] [client 20.226.60.151:27566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/echkm.php"] [unique_id "al9MXv7v0rlcEGmVraFKTwAAA1Q"]
[Tue Jul 21 07:39:26.421263 2026] [security2:error] [pid 255769:tid 255823] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MXrxMYwyVGnfuwsKm9QAEFDU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:26.421263 2026] [security2:error] [pid 254995:tid 255037] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MXv7v0rlcEGmVraFKUAADiSk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:26.545649 2026] [security2:error] [pid 255769:tid 255790] [remote 90.148.142.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.142.148.90.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MXrxMYwyVGnfuwsKm9wADoxQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:26.576362 2026] [security2:error] [pid 255769:tid 255981] [client 4.204.201.85:49839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9MXrxMYwyVGnfuwsKm-AAAA_U"]
[Tue Jul 21 07:39:26.643764 2026] [security2:error] [pid 254995:tid 255150] [client 20.197.192.193:6892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/bscclapb.php"] [unique_id "al9MXv7v0rlcEGmVraFKVwAAAzc"]
[Tue Jul 21 07:39:26.667904 2026] [security2:error] [pid 254995:tid 255047] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MXv7v0rlcEGmVraFKWgADSjM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:26.676703 2026] [security2:error] [pid 255769:tid 255773] [remote 188.49.170.205:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.170.49.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MXrxMYwyVGnfuwsKm-gADsAM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:26.804405 2026] [security2:error] [pid 254995:tid 255126] [client 193.36.225.11:44439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MXv7v0rlcEGmVraFKVQAAAx8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:26.863202 2026] [security2:error] [pid 255769:tid 255959] [client 20.197.195.24:13182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/k.php"] [unique_id "al9MXrxMYwyVGnfuwsKm-wAAA98"]
[Tue Jul 21 07:39:26.864792 2026] [security2:error] [pid 255769:tid 256010] [client 4.204.201.85:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/puc.php"] [unique_id "al9MXrxMYwyVGnfuwsKm_AAABBA"]
[Tue Jul 21 07:39:26.884489 2026] [security2:error] [pid 255769:tid 255902] [client 117.132.188.205:32980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.188.132.117.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/produtos-mercado.php"] [unique_id "al9MXrxMYwyVGnfuwsKm_QAAA6Y"]
[Tue Jul 21 07:39:26.918040 2026] [security2:error] [pid 255769:tid 255878] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MXrxMYwyVGnfuwsKm_gAD1mw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:26.961712 2026] [security2:error] [pid 255769:tid 255978] [client 20.206.105.145:38482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9MXrxMYwyVGnfuwsKnAgAAA_I"]
[Tue Jul 21 07:39:26.971309 2026] [security2:error] [pid 255769:tid 255771] [remote 188.49.170.205:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.170.49.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MXrxMYwyVGnfuwsKnAwAD_wE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:26.976673 2026] [security2:error] [pid 255769:tid 255924] [client 20.220.225.223:31708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/2x.php"] [unique_id "al9MXrxMYwyVGnfuwsKnBAAAA7w"]
[Tue Jul 21 07:39:27.045767 2026] [security2:error] [pid 255769:tid 255999] [client 20.197.195.24:13120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/aaa.php"] [unique_id "al9MX7xMYwyVGnfuwsKnCAAABAU"]
[Tue Jul 21 07:39:27.098194 2026] [security2:error] [pid 255769:tid 255967] [client 59.96.220.140:64912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MX7xMYwyVGnfuwsKnCQAAA-c"]
[Tue Jul 21 07:39:27.098306 2026] [security2:error] [pid 255769:tid 255967] [client 59.96.220.140:64912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MX7xMYwyVGnfuwsKnCQAAA-c"]
[Tue Jul 21 07:39:27.133241 2026] [security2:error] [pid 254995:tid 255107] [remote 90.148.142.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.142.148.90.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MX_7v0rlcEGmVraFKYQADR28"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:27.161883 2026] [security2:error] [pid 255769:tid 255869] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MX7xMYwyVGnfuwsKnCgAD5WM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:27.164030 2026] [security2:error] [pid 255769:tid 255903] [client 4.204.201.85:4512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/dx.php"] [unique_id "al9MX7xMYwyVGnfuwsKnCwAAA6c"]
[Tue Jul 21 07:39:27.180172 2026] [security2:error] [pid 255769:tid 255957] [client 20.226.60.151:27577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/lib.php"] [unique_id "al9MX7xMYwyVGnfuwsKnDAAAA90"]
[Tue Jul 21 07:39:27.188993 2026] [security2:error] [pid 255769:tid 255844] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MX7xMYwyVGnfuwsKnDQAEGUo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:27.203723 2026] [security2:error] [pid 255769:tid 255943] [client 20.220.225.223:34197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/dp.php"] [unique_id "al9MX7xMYwyVGnfuwsKnDwAAA88"]
[Tue Jul 21 07:39:27.211675 2026] [security2:error] [pid 255769:tid 255909] [client 20.197.195.24:13074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/file5.php"] [unique_id "al9MX7xMYwyVGnfuwsKnEAAAA60"]
[Tue Jul 21 07:39:27.223591 2026] [core:error] [pid 255769:tid 255882] [remote 52.167.144.232:64833] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:39:27.223606 2026] [core:error] [pid 255769:tid 255882] [remote 52.167.144.232:64833] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:39:27.261673 2026] [security2:error] [pid 254995:tid 255145] [client 20.220.225.223:31173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/xxx.php"] [unique_id "al9MX_7v0rlcEGmVraFKZwAAAzI"]
[Tue Jul 21 07:39:27.366727 2026] [rewrite:warn] [pid 255769:tid 255862] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:39:27.404422 2026] [security2:error] [pid 255769:tid 255787] [remote 90.148.142.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.142.148.90.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MX7xMYwyVGnfuwsKnFgADrBE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:27.405247 2026] [security2:error] [pid 254995:tid 255034] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MX_7v0rlcEGmVraFKagADISY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:27.426756 2026] [security2:error] [pid 255769:tid 255988] [client 122.179.91.63:21603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MX7xMYwyVGnfuwsKnEwAAA_w"]
[Tue Jul 21 07:39:27.426863 2026] [security2:error] [pid 255769:tid 255988] [client 122.179.91.63:21603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MX7xMYwyVGnfuwsKnEwAAA_w"]
[Tue Jul 21 07:39:27.453316 2026] [autoindex:error] [pid 255769:tid 255987] [client 4.204.201.85:21810] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:27.483002 2026] [security2:error] [pid 255769:tid 255996] [client 20.197.195.24:13134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/222.php"] [unique_id "al9MX7xMYwyVGnfuwsKnGwAABAI"]
[Tue Jul 21 07:39:27.542504 2026] [security2:error] [pid 255769:tid 255954] [client 117.217.38.194:57472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MX7xMYwyVGnfuwsKnHgAAA9o"]
[Tue Jul 21 07:39:27.542697 2026] [security2:error] [pid 255769:tid 255954] [client 117.217.38.194:57472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MX7xMYwyVGnfuwsKnHgAAA9o"]
[Tue Jul 21 07:39:27.666218 2026] [security2:error] [pid 255769:tid 255918] [client 20.226.60.151:27625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/login.php"] [unique_id "al9MX7xMYwyVGnfuwsKnIgAAA7Y"]
[Tue Jul 21 07:39:27.728980 2026] [security2:error] [pid 255769:tid 256017] [client 4.204.201.85:21810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/bthil.php"] [unique_id "al9MX7xMYwyVGnfuwsKnJwAABBc"]
[Tue Jul 21 07:39:27.830248 2026] [rewrite:warn] [pid 255769:tid 255875] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:39:27.898952 2026] [security2:error] [pid 255769:tid 256010] [client 20.226.60.151:9353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/a2.php"] [unique_id "al9MX7xMYwyVGnfuwsKnLAAABBA"]
[Tue Jul 21 07:39:28.037474 2026] [security2:error] [pid 255769:tid 255921] [client 117.132.188.205:32981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.188.132.117.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/atuacao.php"] [unique_id "al9MYLxMYwyVGnfuwsKnVAAAA7k"]
[Tue Jul 21 07:39:28.044285 2026] [security2:error] [pid 255769:tid 255958] [client 4.204.201.85:4422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/7.php"] [unique_id "al9MYLxMYwyVGnfuwsKnVQAAA94"]
[Tue Jul 21 07:39:28.095236 2026] [security2:error] [pid 254995:tid 255165] [client 139.167.225.182:54296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MYP7v0rlcEGmVraFKdwAAA0Y"]
[Tue Jul 21 07:39:28.095383 2026] [security2:error] [pid 254995:tid 255165] [client 139.167.225.182:54296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MYP7v0rlcEGmVraFKdwAAA0Y"]
[Tue Jul 21 07:39:28.146133 2026] [security2:error] [pid 255769:tid 255916] [client 20.226.60.151:27637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/d61.php"] [unique_id "al9MYLxMYwyVGnfuwsKnXAAAA7Q"]
[Tue Jul 21 07:39:28.276655 2026] [security2:error] [pid 255769:tid 255984] [client 20.220.225.223:34283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/old.php"] [unique_id "al9MYLxMYwyVGnfuwsKnagAAA_g"]
[Tue Jul 21 07:39:28.305779 2026] [security2:error] [pid 255769:tid 256025] [client 20.197.195.24:13158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/test.php"] [unique_id "al9MYLxMYwyVGnfuwsKnawAABB8"]
[Tue Jul 21 07:39:28.368297 2026] [security2:error] [pid 255769:tid 255903] [client 20.220.225.223:22473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/kq1.php"] [unique_id "al9MYLxMYwyVGnfuwsKnbAAAA6c"]
[Tue Jul 21 07:39:28.395092 2026] [security2:error] [pid 255769:tid 255957] [client 20.226.60.151:27348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/info.php"] [unique_id "al9MYLxMYwyVGnfuwsKnbQAAA90"]
[Tue Jul 21 07:39:28.407330 2026] [security2:error] [pid 255769:tid 256019] [client 4.204.201.85:49882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/8.php"] [unique_id "al9MYLxMYwyVGnfuwsKnbgAABBk"]
[Tue Jul 21 07:39:28.695587 2026] [security2:error] [pid 255769:tid 255953] [client 4.204.201.85:49888] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "x45consultoria.com.br"] [uri "/1.php"] [unique_id "al9MYLxMYwyVGnfuwsKneQAAA9k"]
[Tue Jul 21 07:39:28.695709 2026] [security2:error] [pid 255769:tid 255953] [client 4.204.201.85:49888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/1.php"] [unique_id "al9MYLxMYwyVGnfuwsKneQAAA9k"]
[Tue Jul 21 07:39:28.746692 2026] [security2:error] [pid 255769:tid 255784] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MYLxMYwyVGnfuwsKnfQAD9g4"]
[Tue Jul 21 07:39:28.746909 2026] [security2:error] [pid 255769:tid 255982] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MYLxMYwyVGnfuwsKnfQAD9g4"]
[Tue Jul 21 07:39:28.953099 2026] [security2:error] [pid 255769:tid 255932] [client 20.206.105.145:38505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/aaa.php"] [unique_id "al9MYLxMYwyVGnfuwsKnfgAAA8Q"]
[Tue Jul 21 07:39:28.957867 2026] [security2:error] [pid 254995:tid 255260] [client 20.197.192.193:6992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/else1.php"] [unique_id "al9MYP7v0rlcEGmVraFKgwAAA4o"]
[Tue Jul 21 07:39:28.979966 2026] [security2:error] [pid 254995:tid 255148] [client 4.204.201.85:4473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/100.php"] [unique_id "al9MYP7v0rlcEGmVraFKhAAAAzU"]
[Tue Jul 21 07:39:29.074484 2026] [security2:error] [pid 255769:tid 255913] [client 20.197.195.24:13169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/aaa.php"] [unique_id "al9MYbxMYwyVGnfuwsKngAAAA7E"]
[Tue Jul 21 07:39:29.193232 2026] [security2:error] [pid 255769:tid 255906] [client 117.132.188.205:32982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.188.132.117.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/index.php"] [unique_id "al9MYbxMYwyVGnfuwsKnggAAA6o"]
[Tue Jul 21 07:39:29.204462 2026] [security2:error] [pid 255769:tid 255936] [client 20.220.225.223:31179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/hunter.php"] [unique_id "al9MYbxMYwyVGnfuwsKngwAAA8g"]
[Tue Jul 21 07:39:29.261747 2026] [security2:error] [pid 255769:tid 255985] [client 106.215.181.8:32834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MYbxMYwyVGnfuwsKnhQAAA_k"]
[Tue Jul 21 07:39:29.261904 2026] [security2:error] [pid 255769:tid 255985] [client 106.215.181.8:32834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MYbxMYwyVGnfuwsKnhQAAA_k"]
[Tue Jul 21 07:39:29.299380 2026] [security2:error] [pid 254995:tid 255211] [client 4.204.201.85:49913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/about.php"] [unique_id "al9MYf7v0rlcEGmVraFKjAAAA3M"]
[Tue Jul 21 07:39:29.357984 2026] [security2:error] [pid 255769:tid 255799] [remote 103.75.187.26:41006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.187.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9MYbxMYwyVGnfuwsKnhgAD-x0"]
[Tue Jul 21 07:39:29.396986 2026] [security2:error] [pid 255769:tid 255899] [client 173.24.185.52:62009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MYbxMYwyVGnfuwsKnhwAAA6M"]
[Tue Jul 21 07:39:29.397110 2026] [security2:error] [pid 255769:tid 255899] [client 173.24.185.52:62009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MYbxMYwyVGnfuwsKnhwAAA6M"]
[Tue Jul 21 07:39:29.461304 2026] [security2:error] [pid 254995:tid 255254] [client 20.197.192.193:6898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/tkikikoko.php"] [unique_id "al9MYf7v0rlcEGmVraFKjgAAA4Q"]
[Tue Jul 21 07:39:29.654170 2026] [security2:error] [pid 254995:tid 255163] [client 4.204.201.85:4490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/admin.php"] [unique_id "al9MYf7v0rlcEGmVraFKlAAAA0Q"]
[Tue Jul 21 07:39:29.723769 2026] [security2:error] [pid 254995:tid 255264] [client 20.197.195.24:13056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/11.php"] [unique_id "al9MYf7v0rlcEGmVraFKlQAAA44"]
[Tue Jul 21 07:39:29.886154 2026] [security2:error] [pid 255769:tid 255942] [client 20.226.60.151:9348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/11.php"] [unique_id "al9MYbxMYwyVGnfuwsKnigAAA84"]
[Tue Jul 21 07:39:29.976389 2026] [security2:error] [pid 255769:tid 255990] [client 4.204.201.85:21736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/edit.php"] [unique_id "al9MYbxMYwyVGnfuwsKnjAAAA_4"]
[Tue Jul 21 07:39:30.015323 2026] [security2:error] [pid 254995:tid 255126] [client 194.164.163.80:37364] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sphawks.com.br"] [uri "/index.html"] [unique_id "al9MYv7v0rlcEGmVraFKmQAAAx8"]
[Tue Jul 21 07:39:30.020716 2026] [proxy:error] [pid 255769:tid 255801] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:39:30.020759 2026] [proxy_http:error] [pid 255769:tid 255801] [remote 205.210.31.253:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:39:30.021377 2026] [proxy:error] [pid 255769:tid 255801] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:39:30.021410 2026] [proxy_http:error] [pid 255769:tid 255801] [remote 205.210.31.253:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:39:30.198447 2026] [security2:error] [pid 255769:tid 255924] [client 20.226.60.151:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/xy.php"] [unique_id "al9MYrxMYwyVGnfuwsKnkQAAA7w"]
[Tue Jul 21 07:39:30.268899 2026] [security2:error] [pid 255769:tid 255907] [client 4.204.201.85:4480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MYrxMYwyVGnfuwsKnkwAAA6s"]
[Tue Jul 21 07:39:30.281168 2026] [security2:error] [pid 255769:tid 256019] [client 20.151.10.161:46070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/adminfuns.php"] [unique_id "al9MYrxMYwyVGnfuwsKnlAAABBk"]
[Tue Jul 21 07:39:30.569194 2026] [autoindex:error] [pid 255769:tid 255909] [client 43.135.145.117:45290] AH01276: Cannot serve directory /home1/leon6484/lumevisual.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.lumevisual.online
[Tue Jul 21 07:39:30.586693 2026] [security2:error] [pid 255769:tid 256009] [client 4.204.201.85:49852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/ss.php"] [unique_id "al9MYrxMYwyVGnfuwsKnnAAABA8"]
[Tue Jul 21 07:39:30.626585 2026] [security2:error] [pid 255769:tid 256000] [client 20.197.195.24:13100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/mac.php"] [unique_id "al9MYrxMYwyVGnfuwsKnoQAABAY"]
[Tue Jul 21 07:39:30.775318 2026] [security2:error] [pid 255769:tid 255940] [client 20.226.60.151:27527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/v2.php"] [unique_id "al9MYrxMYwyVGnfuwsKnogAAA8w"]
[Tue Jul 21 07:39:30.883516 2026] [security2:error] [pid 254995:tid 255252] [client 4.204.201.85:4468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/inputs.php"] [unique_id "al9MYv7v0rlcEGmVraFKpQAAA4M"]
[Tue Jul 21 07:39:31.022267 2026] [security2:error] [pid 255769:tid 256012] [client 122.186.204.214:63331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MY7xMYwyVGnfuwsKnpwAABBI"]
[Tue Jul 21 07:39:31.022415 2026] [security2:error] [pid 255769:tid 256012] [client 122.186.204.214:63331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MY7xMYwyVGnfuwsKnpwAABBI"]
[Tue Jul 21 07:39:31.146469 2026] [security2:error] [pid 255769:tid 255979] [client 136.144.33.96:59639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MY7xMYwyVGnfuwsKnqAAAA_M"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:31.166267 2026] [security2:error] [pid 254995:tid 255164] [client 4.204.201.85:21813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/av.php"] [unique_id "al9MY_7v0rlcEGmVraFKqQAAA0U"]
[Tue Jul 21 07:39:31.262977 2026] [security2:error] [pid 255769:tid 256028] [client 117.251.86.144:37106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MY7xMYwyVGnfuwsKnqgAABCI"]
[Tue Jul 21 07:39:31.263130 2026] [security2:error] [pid 255769:tid 256028] [client 117.251.86.144:37106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MY7xMYwyVGnfuwsKnqgAABCI"]
[Tue Jul 21 07:39:31.318859 2026] [security2:error] [pid 255769:tid 255981] [client 20.226.60.151:27521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/panel.php"] [unique_id "al9MY7xMYwyVGnfuwsKnqwAAA_U"]
[Tue Jul 21 07:39:31.451807 2026] [security2:error] [pid 255769:tid 255896] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MY7xMYwyVGnfuwsKnrgAEF34"]
[Tue Jul 21 07:39:31.451946 2026] [security2:error] [pid 255769:tid 256017] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MY7xMYwyVGnfuwsKnrgAEF34"]
[Tue Jul 21 07:39:31.483962 2026] [security2:error] [pid 254995:tid 255183] [client 193.36.225.143:47571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MY_7v0rlcEGmVraFKrQAAA1g"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:39:31.492692 2026] [security2:error] [pid 255769:tid 255902] [client 20.226.60.151:27559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/dex.php"] [unique_id "al9MY7xMYwyVGnfuwsKnrwAAA6Y"]
[Tue Jul 21 07:39:31.537614 2026] [security2:error] [pid 255769:tid 255822] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MY7xMYwyVGnfuwsKnsAAECTQ"]
[Tue Jul 21 07:39:31.537717 2026] [security2:error] [pid 255769:tid 256003] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MY7xMYwyVGnfuwsKnsAAECTQ"]
[Tue Jul 21 07:39:31.551733 2026] [security2:error] [pid 255769:tid 255942] [client 4.204.201.85:21743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/classwithtostring.php"] [unique_id "al9MY7xMYwyVGnfuwsKnsgAAA84"]
[Tue Jul 21 07:39:31.564940 2026] [security2:error] [pid 255769:tid 255963] [client 20.226.60.151:27560] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "alperembalagens.com.br"] [uri "/1.php"] [unique_id "al9MY7xMYwyVGnfuwsKnswAAA-M"]
[Tue Jul 21 07:39:31.565073 2026] [security2:error] [pid 255769:tid 255963] [client 20.226.60.151:27560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/1.php"] [unique_id "al9MY7xMYwyVGnfuwsKnswAAA-M"]
[Tue Jul 21 07:39:31.600672 2026] [security2:error] [pid 255769:tid 255808] [remote 45.150.79.142:44920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spazziojardins.com"] [uri "/wp-login.php"] [unique_id "al9MY7xMYwyVGnfuwsKntAADsSY"]
[Tue Jul 21 07:39:31.618903 2026] [rewrite:warn] [pid 255769:tid 255840] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:39:31.628769 2026] [security2:error] [pid 254995:tid 255176] [client 20.226.60.151:9365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ms.php"] [unique_id "al9MY_7v0rlcEGmVraFKrwAAA1E"]
[Tue Jul 21 07:39:31.715319 2026] [security2:error] [pid 254995:tid 255141] [client 20.197.195.24:13118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/chosen.php"] [unique_id "al9MY_7v0rlcEGmVraFKswAAAy4"]
[Tue Jul 21 07:39:31.828191 2026] [security2:error] [pid 255769:tid 255903] [client 20.226.60.151:27586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/memberfuns.php"] [unique_id "al9MY7xMYwyVGnfuwsKnuQAAA6c"]
[Tue Jul 21 07:39:31.836064 2026] [security2:error] [pid 255769:tid 255907] [client 4.204.201.85:49854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9MY7xMYwyVGnfuwsKnugAAA6s"]
[Tue Jul 21 07:39:32.017190 2026] [security2:error] [pid 255769:tid 255901] [client 20.226.60.151:27370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/0.php"] [unique_id "al9MZLxMYwyVGnfuwsKnvwAAA6U"]
[Tue Jul 21 07:39:32.058656 2026] [security2:error] [pid 255769:tid 255974] [client 20.226.60.151:9357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/BDKR28.php"] [unique_id "al9MZLxMYwyVGnfuwsKnwAAAA-4"]
[Tue Jul 21 07:39:32.089451 2026] [security2:error] [pid 254995:tid 255125] [client 20.226.60.151:27330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/green1.php"] [unique_id "al9MZP7v0rlcEGmVraFKtwAAAx4"]
[Tue Jul 21 07:39:32.113809 2026] [security2:error] [pid 255769:tid 256022] [client 4.204.201.85:49889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-blog.php"] [unique_id "al9MZLxMYwyVGnfuwsKnwQAABBw"]
[Tue Jul 21 07:39:32.138132 2026] [security2:error] [pid 255769:tid 255950] [client 20.197.195.24:13178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/cream1.php"] [unique_id "al9MZLxMYwyVGnfuwsKnwwAAA9Y"]
[Tue Jul 21 07:39:32.155954 2026] [security2:error] [pid 255769:tid 256024] [client 20.226.60.151:27609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/nc4.php"] [unique_id "al9MZLxMYwyVGnfuwsKnxAAABB4"]
[Tue Jul 21 07:39:32.194385 2026] [security2:error] [pid 255769:tid 255841] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MZLxMYwyVGnfuwsKnxwAD10c"]
[Tue Jul 21 07:39:32.194490 2026] [security2:error] [pid 255769:tid 255951] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MZLxMYwyVGnfuwsKnxwAD10c"]
[Tue Jul 21 07:39:32.199597 2026] [security2:error] [pid 255769:tid 255935] [client 20.220.225.223:32290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/zzz.php"] [unique_id "al9MZLxMYwyVGnfuwsKnyAAAA8c"]
[Tue Jul 21 07:39:32.270721 2026] [security2:error] [pid 255769:tid 255975] [client 20.226.60.151:27349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/a1.php"] [unique_id "al9MZLxMYwyVGnfuwsKnygAAA-8"]
[Tue Jul 21 07:39:32.436283 2026] [autoindex:error] [pid 255769:tid 255915] [client 4.204.201.85:4522] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:32.532285 2026] [autoindex:error] [pid 255769:tid 255825] [remote 74.7.227.191:59500] AH01276: Cannot serve directory /home2/inlaud99/erp.asserradaliberdade.ong.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:32.561165 2026] [security2:error] [pid 255769:tid 255990] [client 152.59.154.239:62814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MZLxMYwyVGnfuwsKn0wAAA_4"]
[Tue Jul 21 07:39:32.561284 2026] [security2:error] [pid 255769:tid 255990] [client 152.59.154.239:62814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MZLxMYwyVGnfuwsKn0wAAA_4"]
[Tue Jul 21 07:39:32.597133 2026] [autoindex:error] [pid 255769:tid 255889] [remote 74.7.227.63:60800] AH01276: Cannot serve directory /home3/lianem44/ubaloc.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:32.608764 2026] [security2:error] [pid 255769:tid 255978] [client 20.226.60.151:27570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/eee.php"] [unique_id "al9MZLxMYwyVGnfuwsKn1wAAA_I"]
[Tue Jul 21 07:39:32.619871 2026] [security2:error] [pid 255769:tid 256017] [client 74.7.241.180:51080] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ubaloc.online"] [uri "/cgi-sys/404.html"] [unique_id "al9MZLxMYwyVGnfuwsKn2AAEFz8"]
[Tue Jul 21 07:39:32.663483 2026] [security2:error] [pid 255769:tid 255913] [client 20.151.10.161:45894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/goods.php"] [unique_id "al9MZLxMYwyVGnfuwsKn2QAAA7E"]
[Tue Jul 21 07:39:32.689397 2026] [security2:error] [pid 255769:tid 255947] [client 20.226.60.151:9377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-aothait.php"] [unique_id "al9MZLxMYwyVGnfuwsKn2wAAA9M"]
[Tue Jul 21 07:39:32.711783 2026] [security2:error] [pid 255769:tid 255939] [client 4.204.201.85:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MZLxMYwyVGnfuwsKn3AAAA8s"]
[Tue Jul 21 07:39:32.744084 2026] [security2:error] [pid 255769:tid 255942] [client 74.7.175.132:58882] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "erp.asserradaliberdade.ong.br"] [uri "/cgi-sys/404.html"] [unique_id "al9MZLxMYwyVGnfuwsKn3QADzkg"]
[Tue Jul 21 07:39:32.902723 2026] [security2:error] [pid 255769:tid 256019] [client 20.226.60.151:27551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/config.json.php"] [unique_id "al9MZLxMYwyVGnfuwsKn5AAABBk"]
[Tue Jul 21 07:39:33.011427 2026] [security2:error] [pid 255769:tid 255905] [client 194.99.104.35:57062] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKn5QAAA6k"]
[Tue Jul 21 07:39:33.011540 2026] [security2:error] [pid 255769:tid 255905] [client 194.99.104.35:57062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKn5QAAA6k"]
[Tue Jul 21 07:39:33.012198 2026] [security2:error] [pid 255769:tid 255938] [client 20.226.60.151:27608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9MZbxMYwyVGnfuwsKn5gAAA8o"]
[Tue Jul 21 07:39:33.019644 2026] [security2:error] [pid 255769:tid 255998] [client 4.204.201.85:21783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/adminfuns.php"] [unique_id "al9MZbxMYwyVGnfuwsKn5wAABAQ"]
[Tue Jul 21 07:39:33.160070 2026] [security2:error] [pid 255769:tid 255988] [client 20.226.60.151:9401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/k2.php"] [unique_id "al9MZbxMYwyVGnfuwsKn6QAAA_w"]
[Tue Jul 21 07:39:33.190873 2026] [security2:error] [pid 255769:tid 255972] [client 154.192.233.199:59865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKn6gAAA-w"]
[Tue Jul 21 07:39:33.190990 2026] [security2:error] [pid 255769:tid 255972] [client 154.192.233.199:59865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKn6gAAA-w"]
[Tue Jul 21 07:39:33.193928 2026] [security2:error] [pid 255769:tid 255953] [client 20.226.60.151:56223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/loader.php"] [unique_id "al9MZbxMYwyVGnfuwsKn6wAAA9k"]
[Tue Jul 21 07:39:33.223335 2026] [security2:error] [pid 255769:tid 256008] [client 20.226.60.151:27352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9MZbxMYwyVGnfuwsKn7gAABA4"]
[Tue Jul 21 07:39:33.325525 2026] [authz_core:error] [pid 255769:tid 255925] [client 20.197.195.24:13073] AH01630: client denied by server configuration: /home2/ren85318/public_html/wp-content/uploads/index.php
[Tue Jul 21 07:39:33.334171 2026] [security2:error] [pid 255769:tid 255951] [client 4.204.201.85:4538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/goods.php"] [unique_id "al9MZbxMYwyVGnfuwsKn9AAAA9c"]
[Tue Jul 21 07:39:33.371100 2026] [autoindex:error] [pid 255769:tid 255944] [client 20.197.195.24:13073] AH01276: Cannot serve directory /home2/ren85318/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:33.388850 2026] [security2:error] [pid 255769:tid 255979] [client 20.197.195.24:13073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/dr.php"] [unique_id "al9MZbxMYwyVGnfuwsKn9gAAA_M"]
[Tue Jul 21 07:39:33.618963 2026] [security2:error] [pid 255769:tid 256010] [client 20.220.225.223:31728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/wicked.php"] [unique_id "al9MZbxMYwyVGnfuwsKn-wAABBA"]
[Tue Jul 21 07:39:33.620193 2026] [security2:error] [pid 255769:tid 255967] [client 175.45.70.82:52224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKn_AAAA-c"]
[Tue Jul 21 07:39:33.620344 2026] [security2:error] [pid 255769:tid 255967] [client 175.45.70.82:52224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKn_AAAA-c"]
[Tue Jul 21 07:39:33.641187 2026] [security2:error] [pid 255769:tid 255790] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKn_QAD-hQ"]
[Tue Jul 21 07:39:33.641329 2026] [security2:error] [pid 255769:tid 255986] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKn_QAD-hQ"]
[Tue Jul 21 07:39:33.644059 2026] [security2:error] [pid 255769:tid 255956] [client 4.204.201.85:4492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/ms-edit.php"] [unique_id "al9MZbxMYwyVGnfuwsKn_wAAA9w"]
[Tue Jul 21 07:39:33.644509 2026] [security2:error] [pid 255769:tid 255929] [client 107.189.2.5:60386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/.env"] [unique_id "al9MZbxMYwyVGnfuwsKn_gAAA8E"]
[Tue Jul 21 07:39:33.688098 2026] [security2:error] [pid 254995:tid 255154] [client 194.99.104.35:46156] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9MZf7v0rlcEGmVraFKygAAAzs"]
[Tue Jul 21 07:39:33.688176 2026] [security2:error] [pid 254995:tid 255154] [client 194.99.104.35:46156] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9MZf7v0rlcEGmVraFKygAAAzs"]
[Tue Jul 21 07:39:33.688193 2026] [security2:error] [pid 254995:tid 255154] [client 194.99.104.35:46156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9MZf7v0rlcEGmVraFKygAAAzs"]
[Tue Jul 21 07:39:33.692629 2026] [security2:error] [pid 255769:tid 255990] [client 20.220.225.223:38706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/we.php"] [unique_id "al9MZbxMYwyVGnfuwsKoAQAAA_4"]
[Tue Jul 21 07:39:33.746966 2026] [security2:error] [pid 254995:tid 255211] [client 20.226.60.151:27539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9MZf7v0rlcEGmVraFKzgAAA3M"]
[Tue Jul 21 07:39:33.760955 2026] [security2:error] [pid 255769:tid 255893] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKoBgAEB3s"]
[Tue Jul 21 07:39:33.761104 2026] [security2:error] [pid 255769:tid 256001] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKoBgAEB3s"]
[Tue Jul 21 07:39:33.934766 2026] [security2:error] [pid 255769:tid 255950] [client 122.162.144.145:6502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKoDgAAA9Y"]
[Tue Jul 21 07:39:33.934887 2026] [security2:error] [pid 255769:tid 255950] [client 122.162.144.145:6502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKoDgAAA9Y"]
[Tue Jul 21 07:39:33.969434 2026] [security2:error] [pid 255769:tid 255920] [client 4.204.201.85:4535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/222.php"] [unique_id "al9MZbxMYwyVGnfuwsKoDwAAA7g"]
[Tue Jul 21 07:39:33.978351 2026] [security2:error] [pid 255769:tid 256006] [client 103.106.20.201:58702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKoEAAABAw"]
[Tue Jul 21 07:39:33.978479 2026] [security2:error] [pid 255769:tid 256006] [client 103.106.20.201:58702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKoEAAABAw"]
[Tue Jul 21 07:39:34.253060 2026] [security2:error] [pid 254995:tid 255169] [client 4.204.201.85:49829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9MZv7v0rlcEGmVraFK1AAAA0o"]
[Tue Jul 21 07:39:34.395787 2026] [security2:error] [pid 255769:tid 255961] [client 20.197.195.24:13170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/x.php"] [unique_id "al9MZrxMYwyVGnfuwsKoPgAAA-E"]
[Tue Jul 21 07:39:34.565019 2026] [autoindex:error] [pid 255769:tid 255902] [client 4.204.201.85:49891] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:34.613573 2026] [security2:error] [pid 255769:tid 255921] [client 20.151.10.161:45993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ms-edit.php"] [unique_id "al9MZrxMYwyVGnfuwsKoTgAAA7k"]
[Tue Jul 21 07:39:34.618232 2026] [security2:error] [pid 255769:tid 255947] [client 184.75.223.211:46528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9MZrxMYwyVGnfuwsKoTwAAA9M"]
[Tue Jul 21 07:39:34.618301 2026] [security2:error] [pid 255769:tid 255947] [client 184.75.223.211:46528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9MZrxMYwyVGnfuwsKoTwAAA9M"]
[Tue Jul 21 07:39:34.683418 2026] [security2:error] [pid 254995:tid 255158] [client 193.36.225.102:63189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MZf7v0rlcEGmVraFKyQAAAz8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:39:34.839833 2026] [security2:error] [pid 255769:tid 255959] [client 4.204.201.85:49891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9MZrxMYwyVGnfuwsKoWAAAA98"]
[Tue Jul 21 07:39:34.917483 2026] [security2:error] [pid 254995:tid 255127] [client 20.220.225.223:31899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/edit.php"] [unique_id "al9MZv7v0rlcEGmVraFK3wAAAyA"]
[Tue Jul 21 07:39:35.119990 2026] [security2:error] [pid 255769:tid 255925] [client 107.189.2.5:60466] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/.env.old"] [unique_id "al9MZ7xMYwyVGnfuwsKoYwAAA70"]
[Tue Jul 21 07:39:35.121495 2026] [security2:error] [pid 255769:tid 255919] [client 107.189.2.5:60538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/backend/.env"] [unique_id "al9MZ7xMYwyVGnfuwsKoZgAAA7c"]
[Tue Jul 21 07:39:35.121674 2026] [security2:error] [pid 255769:tid 255945] [client 107.189.2.5:60454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/.env.swp"] [unique_id "al9MZ7xMYwyVGnfuwsKoZQAAA9E"]
[Tue Jul 21 07:39:35.121748 2026] [security2:error] [pid 254995:tid 255221] [client 107.189.2.5:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/.env.backup"] [unique_id "al9MZ_7v0rlcEGmVraFK5QAAA30"]
[Tue Jul 21 07:39:35.122312 2026] [security2:error] [pid 255769:tid 256012] [client 107.189.2.5:60442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/.env.bak"] [unique_id "al9MZ7xMYwyVGnfuwsKoZwAABBI"]
[Tue Jul 21 07:39:35.122353 2026] [security2:error] [pid 255769:tid 255979] [client 107.189.2.5:60500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/.env~"] [unique_id "al9MZ7xMYwyVGnfuwsKoagAAA_M"]
[Tue Jul 21 07:39:35.130695 2026] [autoindex:error] [pid 255769:tid 255936] [client 4.204.201.85:4421] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:35.237838 2026] [security2:error] [pid 254995:tid 255272] [client 103.86.117.203:60381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MZ_7v0rlcEGmVraFK7AAAA5Y"]
[Tue Jul 21 07:39:35.237981 2026] [security2:error] [pid 254995:tid 255272] [client 103.86.117.203:60381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MZ_7v0rlcEGmVraFK7AAAA5Y"]
[Tue Jul 21 07:39:35.345323 2026] [security2:error] [pid 255769:tid 255974] [client 20.220.225.223:38697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/phpinfo.php1"] [unique_id "al9MZ7xMYwyVGnfuwsKocQAAA-4"]
[Tue Jul 21 07:39:35.421218 2026] [autoindex:error] [pid 255769:tid 255940] [client 4.204.201.85:4421] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:35.505788 2026] [security2:error] [pid 254995:tid 255225] [client 20.197.195.24:13124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/155.php"] [unique_id "al9MZ_7v0rlcEGmVraFK8QAAA4E"]
[Tue Jul 21 07:39:35.565535 2026] [security2:error] [pid 255769:tid 255915] [client 4.204.201.85:4421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp.php"] [unique_id "al9MZ7xMYwyVGnfuwsKoegAAA7M"]
[Tue Jul 21 07:39:35.579526 2026] [security2:error] [pid 255769:tid 255983] [client 107.189.2.5:60386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/api/.env"] [unique_id "al9MZ7xMYwyVGnfuwsKofAAAA_c"]
[Tue Jul 21 07:39:35.579629 2026] [security2:error] [pid 254995:tid 255279] [client 107.189.2.5:60546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/app/.env"] [unique_id "al9MZ_7v0rlcEGmVraFK9AAAA50"]
[Tue Jul 21 07:39:35.675897 2026] [security2:error] [pid 255769:tid 255967] [client 107.189.2.5:60476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/src/.env"] [unique_id "al9MZ7xMYwyVGnfuwsKofQAAA-c"]
[Tue Jul 21 07:39:35.676100 2026] [security2:error] [pid 255769:tid 255935] [client 20.226.60.151:27628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9MZ7xMYwyVGnfuwsKofgAAA8c"]
[Tue Jul 21 07:39:35.677183 2026] [security2:error] [pid 255769:tid 256010] [client 107.189.2.5:60500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/config/.env"] [unique_id "al9MZ7xMYwyVGnfuwsKofwAABBA"]
[Tue Jul 21 07:39:35.677724 2026] [security2:error] [pid 255769:tid 255902] [client 107.189.2.5:60486] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/server/.env"] [unique_id "al9MZ7xMYwyVGnfuwsKogQAAA6Y"]
[Tue Jul 21 07:39:35.678545 2026] [security2:error] [pid 254995:tid 255190] [client 107.189.2.5:60394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/web/.env"] [unique_id "al9MZ_7v0rlcEGmVraFK-QAAA18"]
[Tue Jul 21 07:39:35.840118 2026] [security2:error] [pid 254995:tid 255198] [client 4.204.201.85:4532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/abcd.php"] [unique_id "al9MZ_7v0rlcEGmVraFLAAAAA2c"]
[Tue Jul 21 07:39:35.849022 2026] [security2:error] [pid 255769:tid 255955] [client 20.151.10.161:45999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/222.php"] [unique_id "al9MZ7xMYwyVGnfuwsKoiwAAA9s"]
[Tue Jul 21 07:39:35.990031 2026] [security2:error] [pid 255769:tid 255913] [client 136.144.33.97:55947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MZ7xMYwyVGnfuwsKoigAAA7E"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:36.121099 2026] [security2:error] [pid 254995:tid 255197] [client 4.204.201.85:57276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/a1.php"] [unique_id "al9MaP7v0rlcEGmVraFLBgAAA2Y"]
[Tue Jul 21 07:39:36.397091 2026] [security2:error] [pid 255769:tid 255919] [client 4.204.201.85:4416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9MaLxMYwyVGnfuwsKooQAAA7c"]
[Tue Jul 21 07:39:36.400657 2026] [security2:error] [pid 255769:tid 255980] [client 47.74.5.98:57948] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "avermetais.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9MaLxMYwyVGnfuwsKomAAAA_Q"]
[Tue Jul 21 07:39:36.469443 2026] [security2:error] [pid 254995:tid 255171] [client 103.174.34.15:64777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MaP7v0rlcEGmVraFLCQAAA0w"]
[Tue Jul 21 07:39:36.469568 2026] [security2:error] [pid 254995:tid 255171] [client 103.174.34.15:64777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MaP7v0rlcEGmVraFLCQAAA0w"]
[Tue Jul 21 07:39:36.652741 2026] [security2:error] [pid 255769:tid 255972] [client 20.151.10.161:45939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9MaLxMYwyVGnfuwsKorwAAA-w"]
[Tue Jul 21 07:39:36.685848 2026] [security2:error] [pid 255769:tid 255940] [client 4.204.201.85:57271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9MaLxMYwyVGnfuwsKosQAAA8w"]
[Tue Jul 21 07:39:36.848332 2026] [security2:error] [pid 255769:tid 255790] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MaLxMYwyVGnfuwsKouQAEIRQ"]
[Tue Jul 21 07:39:36.848447 2026] [security2:error] [pid 255769:tid 256027] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MaLxMYwyVGnfuwsKouQAEIRQ"]
[Tue Jul 21 07:39:36.877587 2026] [security2:error] [pid 255769:tid 255912] [client 20.226.60.151:27351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/for.php"] [unique_id "al9MaLxMYwyVGnfuwsKovQAAA7A"]
[Tue Jul 21 07:39:36.962422 2026] [security2:error] [pid 255769:tid 256017] [client 4.204.201.85:4458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/gettest.php"] [unique_id "al9MaLxMYwyVGnfuwsKowQAABBc"]
[Tue Jul 21 07:39:37.177682 2026] [security2:error] [pid 255769:tid 255984] [client 194.99.104.35:46172] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MabxMYwyVGnfuwsKoygAAA_g"]
[Tue Jul 21 07:39:37.177744 2026] [security2:error] [pid 255769:tid 255984] [client 194.99.104.35:46172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MabxMYwyVGnfuwsKoygAAA_g"]
[Tue Jul 21 07:39:37.212577 2026] [security2:error] [pid 254995:tid 255142] [client 184.75.223.211:49638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Maf7v0rlcEGmVraFLEQAAAy8"]
[Tue Jul 21 07:39:37.212648 2026] [security2:error] [pid 254995:tid 255142] [client 184.75.223.211:49638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Maf7v0rlcEGmVraFLEQAAAy8"]
[Tue Jul 21 07:39:37.262761 2026] [security2:error] [pid 255769:tid 255999] [client 47.74.5.98:57965] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "avermetais.com.br"] [uri "/"] [unique_id "al9MabxMYwyVGnfuwsKozAAABAU"]
[Tue Jul 21 07:39:37.270369 2026] [security2:error] [pid 255769:tid 256021] [client 59.96.220.140:42] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MabxMYwyVGnfuwsKozQAABBs"]
[Tue Jul 21 07:39:37.271380 2026] [security2:error] [pid 255769:tid 256021] [client 59.96.220.140:42] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MabxMYwyVGnfuwsKozQAABBs"]
[Tue Jul 21 07:39:37.446151 2026] [security2:error] [pid 255769:tid 255959] [client 20.226.60.151:27332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/raw.php"] [unique_id "al9MabxMYwyVGnfuwsKo0QAAA98"]
[Tue Jul 21 07:39:37.474611 2026] [security2:error] [pid 255769:tid 255977] [client 20.151.10.161:55243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MabxMYwyVGnfuwsKo0gAAA_E"]
[Tue Jul 21 07:39:37.771728 2026] [security2:error] [pid 254995:tid 255159] [client 20.151.10.161:45836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9Maf7v0rlcEGmVraFLGgAAA0A"]
[Tue Jul 21 07:39:37.848957 2026] [security2:error] [pid 255769:tid 255976] [client 139.167.225.182:55094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MabxMYwyVGnfuwsKo1gAAA_A"]
[Tue Jul 21 07:39:37.849057 2026] [security2:error] [pid 255769:tid 255976] [client 139.167.225.182:55094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MabxMYwyVGnfuwsKo1gAAA_A"]
[Tue Jul 21 07:39:37.857852 2026] [security2:error] [pid 255769:tid 255921] [client 122.179.91.63:7298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MabxMYwyVGnfuwsKo1wAAA7k"]
[Tue Jul 21 07:39:37.857934 2026] [security2:error] [pid 255769:tid 255921] [client 122.179.91.63:7298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MabxMYwyVGnfuwsKo1wAAA7k"]
[Tue Jul 21 07:39:37.905407 2026] [security2:error] [pid 255769:tid 255972] [client 20.226.60.151:56266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/spadex.php"] [unique_id "al9MabxMYwyVGnfuwsKo2QAAA-w"]
[Tue Jul 21 07:39:37.978313 2026] [security2:error] [pid 255769:tid 255934] [client 4.204.201.85:4438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/simple.php"] [unique_id "al9MabxMYwyVGnfuwsKo2wAAA8Y"]
[Tue Jul 21 07:39:37.995683 2026] [security2:error] [pid 254995:tid 255149] [client 117.217.38.194:57944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Maf7v0rlcEGmVraFLHgAAAzY"]
[Tue Jul 21 07:39:37.995822 2026] [security2:error] [pid 254995:tid 255149] [client 117.217.38.194:57944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Maf7v0rlcEGmVraFLHgAAAzY"]
[Tue Jul 21 07:39:38.134897 2026] [security2:error] [pid 255769:tid 255908] [client 47.74.5.98:57972] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "avermetais.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9MarxMYwyVGnfuwsKo4AAAA6w"]
[Tue Jul 21 07:39:38.253417 2026] [security2:error] [pid 255769:tid 255929] [client 20.220.225.223:19299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MarxMYwyVGnfuwsKo5gAAA8E"]
[Tue Jul 21 07:39:38.254329 2026] [security2:error] [pid 255769:tid 256003] [client 4.204.201.85:49823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/xxx.php"] [unique_id "al9MarxMYwyVGnfuwsKo5wAABAk"]
[Tue Jul 21 07:39:38.333440 2026] [security2:error] [pid 255769:tid 256020] [client 193.36.225.96:30083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MarxMYwyVGnfuwsKo4gAABBo"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:39:38.529231 2026] [security2:error] [pid 255769:tid 255994] [client 4.204.201.85:21737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/hypo.php"] [unique_id "al9MarxMYwyVGnfuwsKo7AAABAE"]
[Tue Jul 21 07:39:38.742598 2026] [security2:error] [pid 255769:tid 255992] [client 20.197.195.24:48841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/ops.php"] [unique_id "al9MarxMYwyVGnfuwsKo7wAAA_8"]
[Tue Jul 21 07:39:38.860348 2026] [autoindex:error] [pid 255769:tid 255971] [client 4.204.201.85:21822] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:38.963429 2026] [security2:error] [pid 255769:tid 256019] [client 20.151.10.161:45946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp.php"] [unique_id "al9MarxMYwyVGnfuwsKo8wAABBk"]
[Tue Jul 21 07:39:38.976219 2026] [security2:error] [pid 255769:tid 255947] [client 47.74.5.98:57985] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "avermetais.com.br"] [uri "/"] [unique_id "al9MarxMYwyVGnfuwsKo9AAAA9M"]
[Tue Jul 21 07:39:39.134922 2026] [security2:error] [pid 255769:tid 255939] [client 4.204.201.85:21822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/chosen.php"] [unique_id "al9Ma7xMYwyVGnfuwsKo9QAAA8s"]
[Tue Jul 21 07:39:39.422362 2026] [security2:error] [pid 255769:tid 255795] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Ma7xMYwyVGnfuwsKo_QADqxk"]
[Tue Jul 21 07:39:39.422942 2026] [security2:error] [pid 255769:tid 255907] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Ma7xMYwyVGnfuwsKo_QADqxk"]
[Tue Jul 21 07:39:39.428441 2026] [autoindex:error] [pid 255769:tid 255899] [client 4.204.201.85:21751] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:39.705862 2026] [security2:error] [pid 255769:tid 255982] [client 4.204.201.85:21751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/als.php"] [unique_id "al9Ma7xMYwyVGnfuwsKo_wAAA_Y"]
[Tue Jul 21 07:39:39.783391 2026] [security2:error] [pid 255769:tid 255985] [client 20.151.10.161:46011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/abcd.php"] [unique_id "al9Ma7xMYwyVGnfuwsKpAQAAA_k"]
[Tue Jul 21 07:39:39.824668 2026] [security2:error] [pid 254995:tid 255272] [client 47.74.5.98:57999] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "avermetais.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9Ma_7v0rlcEGmVraFLNQAAA5Y"]
[Tue Jul 21 07:39:39.841165 2026] [security2:error] [pid 255769:tid 255908] [client 20.220.225.223:34254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/ms-new.php"] [unique_id "al9Ma7xMYwyVGnfuwsKpAgAAA6w"]
[Tue Jul 21 07:39:39.932446 2026] [security2:error] [pid 254995:tid 255264] [client 106.215.181.8:28768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ma_7v0rlcEGmVraFLOQAAA44"]
[Tue Jul 21 07:39:39.932546 2026] [security2:error] [pid 254995:tid 255264] [client 106.215.181.8:28768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ma_7v0rlcEGmVraFLOQAAA44"]
[Tue Jul 21 07:39:39.944228 2026] [security2:error] [pid 255769:tid 255940] [client 173.24.185.52:62537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Ma7xMYwyVGnfuwsKpAwAAA8w"]
[Tue Jul 21 07:39:39.944357 2026] [security2:error] [pid 255769:tid 255940] [client 173.24.185.52:62537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Ma7xMYwyVGnfuwsKpAwAAA8w"]
[Tue Jul 21 07:39:39.995427 2026] [security2:error] [pid 255769:tid 255967] [client 4.204.201.85:4470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/pol.php"] [unique_id "al9Ma7xMYwyVGnfuwsKpBAAAA-c"]
[Tue Jul 21 07:39:40.290442 2026] [security2:error] [pid 255769:tid 256016] [client 4.204.201.85:21700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/file5.php"] [unique_id "al9MbLxMYwyVGnfuwsKpBwAABBY"]
[Tue Jul 21 07:39:40.356465 2026] [security2:error] [pid 254995:tid 255198] [client 20.151.10.161:55254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MbP7v0rlcEGmVraFLQwAAA2c"]
[Tue Jul 21 07:39:40.577656 2026] [security2:error] [pid 255769:tid 255968] [client 4.204.201.85:49811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/file.php"] [unique_id "al9MbLxMYwyVGnfuwsKpDAAAA-g"]
[Tue Jul 21 07:39:40.653868 2026] [security2:error] [pid 254995:tid 255262] [client 47.74.5.98:58011] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "avermetais.com.br"] [uri "/"] [unique_id "al9MbP7v0rlcEGmVraFLSQAAA4w"]
[Tue Jul 21 07:39:40.661039 2026] [security2:error] [pid 255769:tid 255805] [remote 203.161.62.87:46588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.62.161.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9MbLxMYwyVGnfuwsKpCgAD9SM"]
[Tue Jul 21 07:39:40.889227 2026] [security2:error] [pid 255769:tid 255938] [client 4.204.201.85:49875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/cfile.php"] [unique_id "al9MbLxMYwyVGnfuwsKpEQAAA8o"]
[Tue Jul 21 07:39:40.956867 2026] [security2:error] [pid 254995:tid 255191] [client 184.75.223.211:50754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9MbP7v0rlcEGmVraFLTwAAA2A"]
[Tue Jul 21 07:39:40.956955 2026] [security2:error] [pid 254995:tid 255191] [client 184.75.223.211:50754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9MbP7v0rlcEGmVraFLTwAAA2A"]
[Tue Jul 21 07:39:41.013153 2026] [security2:error] [pid 255769:tid 255997] [client 136.144.33.215:22495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MbbxMYwyVGnfuwsKpEwAABAM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:41.178372 2026] [security2:error] [pid 255769:tid 255925] [client 4.204.201.85:4539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/admin.php"] [unique_id "al9MbbxMYwyVGnfuwsKpFAAAA70"]
[Tue Jul 21 07:39:41.462664 2026] [security2:error] [pid 255769:tid 255979] [client 20.197.195.24:48850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/file31.php"] [unique_id "al9MbbxMYwyVGnfuwsKpFgAAA_M"]
[Tue Jul 21 07:39:41.480627 2026] [security2:error] [pid 254995:tid 255174] [client 47.74.5.98:58025] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "avermetais.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9Mbf7v0rlcEGmVraFLWwAAA08"]
[Tue Jul 21 07:39:41.547290 2026] [security2:error] [pid 255769:tid 256010] [client 4.204.201.85:49879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/aa2.php"] [unique_id "al9MbbxMYwyVGnfuwsKpGAAABBA"]
[Tue Jul 21 07:39:41.753518 2026] [security2:error] [pid 255769:tid 256017] [client 20.151.10.161:45926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/a1.php"] [unique_id "al9MbbxMYwyVGnfuwsKpHgAABBc"]
[Tue Jul 21 07:39:41.770493 2026] [security2:error] [pid 255769:tid 255945] [client 122.186.204.214:63862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MbbxMYwyVGnfuwsKpHwAAA9E"]
[Tue Jul 21 07:39:41.770607 2026] [security2:error] [pid 255769:tid 255945] [client 122.186.204.214:63862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MbbxMYwyVGnfuwsKpHwAAA9E"]
[Tue Jul 21 07:39:41.818883 2026] [security2:error] [pid 254995:tid 255274] [client 20.220.225.223:31726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/kua.php"] [unique_id "al9Mbf7v0rlcEGmVraFLZAAAA5g"]
[Tue Jul 21 07:39:41.828664 2026] [security2:error] [pid 255769:tid 256000] [client 4.204.201.85:49846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/ccou.php"] [unique_id "al9MbbxMYwyVGnfuwsKpIAAABAY"]
[Tue Jul 21 07:39:41.912681 2026] [security2:error] [pid 255769:tid 256006] [client 117.251.86.144:35510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MbbxMYwyVGnfuwsKpIwAABAw"]
[Tue Jul 21 07:39:41.912867 2026] [security2:error] [pid 255769:tid 256006] [client 117.251.86.144:35510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MbbxMYwyVGnfuwsKpIwAABAw"]
[Tue Jul 21 07:39:41.929551 2026] [security2:error] [pid 255769:tid 255883] [remote 45.79.123.44:56186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rustikusboxingschool.com"] [uri "/wp-login.php"] [unique_id "al9MbbxMYwyVGnfuwsKpJAAD93E"]
[Tue Jul 21 07:39:41.953387 2026] [security2:error] [pid 255769:tid 255854] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MbbxMYwyVGnfuwsKpJQAD-1Q"]
[Tue Jul 21 07:39:41.953507 2026] [security2:error] [pid 255769:tid 255987] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MbbxMYwyVGnfuwsKpJQAD-1Q"]
[Tue Jul 21 07:39:42.082629 2026] [security2:error] [pid 254995:tid 255027] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mbv7v0rlcEGmVraFLZwADdR8"]
[Tue Jul 21 07:39:42.082741 2026] [security2:error] [pid 254995:tid 255213] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mbv7v0rlcEGmVraFLZwADdR8"]
[Tue Jul 21 07:39:42.115923 2026] [security2:error] [pid 255769:tid 255984] [client 4.204.201.85:4472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/dr.php"] [unique_id "al9MbrxMYwyVGnfuwsKpKgAAA_g"]
[Tue Jul 21 07:39:42.214796 2026] [security2:error] [pid 254995:tid 255254] [client 37.140.223.201:46393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Mbf7v0rlcEGmVraFLVAAAA4Q"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:39:42.294750 2026] [security2:error] [pid 255769:tid 256011] [client 47.74.5.98:58037] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "avermetais.com.br"] [uri "/"] [unique_id "al9MbrxMYwyVGnfuwsKpLgAABBE"]
[Tue Jul 21 07:39:42.372081 2026] [security2:error] [pid 254995:tid 255130] [client 20.197.195.24:13144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/file6.php"] [unique_id "al9Mbv7v0rlcEGmVraFLawAAAyM"]
[Tue Jul 21 07:39:42.456178 2026] [security2:error] [pid 254995:tid 255264] [client 4.204.201.85:4528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/xamp.php"] [unique_id "al9Mbv7v0rlcEGmVraFLbAAAA44"]
[Tue Jul 21 07:39:42.493490 2026] [security2:error] [pid 255769:tid 255836] [remote 41.76.214.143:36216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atilafagundes.com.br"] [uri "/wp-login.php"] [unique_id "al9MbrxMYwyVGnfuwsKpMgAD1UI"]
[Tue Jul 21 07:39:42.524140 2026] [security2:error] [pid 254995:tid 255220] [client 20.220.225.223:19676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Mbv7v0rlcEGmVraFLbQAAA3w"]
[Tue Jul 21 07:39:42.718970 2026] [autoindex:error] [pid 255769:tid 255988] [client 20.197.195.24:13137] AH01276: Cannot serve directory /home2/ren85318/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:42.755143 2026] [security2:error] [pid 255769:tid 255920] [client 20.197.195.24:13137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/adminfuns.php"] [unique_id "al9MbrxMYwyVGnfuwsKpNQAAA7g"]
[Tue Jul 21 07:39:42.759764 2026] [security2:error] [pid 255769:tid 255925] [client 4.204.201.85:4443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/bless.php"] [unique_id "al9MbrxMYwyVGnfuwsKpNgAAA70"]
[Tue Jul 21 07:39:42.919152 2026] [security2:error] [pid 255769:tid 255899] [client 20.151.10.161:55250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/x.php"] [unique_id "al9MbrxMYwyVGnfuwsKpNwAAA6M"]
[Tue Jul 21 07:39:42.922935 2026] [security2:error] [pid 254995:tid 255184] [client 128.127.105.184:46706] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Mbv7v0rlcEGmVraFLdgAAA1k"]
[Tue Jul 21 07:39:42.923024 2026] [security2:error] [pid 254995:tid 255184] [client 128.127.105.184:46706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Mbv7v0rlcEGmVraFLdgAAA1k"]
[Tue Jul 21 07:39:43.027633 2026] [security2:error] [pid 255769:tid 255818] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpOAADzzA"]
[Tue Jul 21 07:39:43.027784 2026] [security2:error] [pid 255769:tid 255943] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpOAADzzA"]
[Tue Jul 21 07:39:43.039701 2026] [security2:error] [pid 255769:tid 256022] [client 4.204.201.85:21821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/file25.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpOQAABBw"]
[Tue Jul 21 07:39:43.098865 2026] [security2:error] [pid 255769:tid 255974] [client 20.197.195.24:13079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/goods.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpOgAAA-4"]
[Tue Jul 21 07:39:43.181424 2026] [security2:error] [pid 255769:tid 255906] [client 194.99.104.35:56072] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpOwAAA6o"]
[Tue Jul 21 07:39:43.181500 2026] [security2:error] [pid 255769:tid 255906] [client 194.99.104.35:56072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpOwAAA6o"]
[Tue Jul 21 07:39:43.328956 2026] [security2:error] [pid 255769:tid 255985] [client 4.204.201.85:49868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/file6.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpPgAAA_k"]
[Tue Jul 21 07:39:43.358110 2026] [security2:error] [pid 255769:tid 255935] [client 20.197.195.24:13150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/100.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpPwAAA8c"]
[Tue Jul 21 07:39:43.473485 2026] [security2:error] [pid 255769:tid 256001] [client 62.102.148.187:60750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpQwAABAc"]
[Tue Jul 21 07:39:43.473579 2026] [security2:error] [pid 255769:tid 256001] [client 62.102.148.187:60750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpQwAABAc"]
[Tue Jul 21 07:39:43.602409 2026] [security2:error] [pid 255769:tid 255956] [client 4.204.201.85:49859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/a2.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpSwAAA9w"]
[Tue Jul 21 07:39:43.783518 2026] [security2:error] [pid 255769:tid 256019] [client 20.197.195.24:13065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/about.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpTQAABBk"]
[Tue Jul 21 07:39:43.803708 2026] [security2:error] [pid 255769:tid 255930] [client 20.226.60.151:56227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/2x.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpTgAAA8I"]
[Tue Jul 21 07:39:43.885951 2026] [security2:error] [pid 255769:tid 255959] [client 4.204.201.85:21702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/file15.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpUwAAA98"]
[Tue Jul 21 07:39:44.081703 2026] [security2:error] [pid 254995:tid 255200] [client 20.151.10.161:45984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9McP7v0rlcEGmVraFLhgAAA2k"]
[Tue Jul 21 07:39:44.143840 2026] [security2:error] [pid 254995:tid 255273] [client 20.151.10.161:53583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/j260624_13.php"] [unique_id "al9McP7v0rlcEGmVraFLiAAAA5c"]
[Tue Jul 21 07:39:44.164449 2026] [security2:error] [pid 254995:tid 255260] [client 4.204.201.85:49828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/f35.php"] [unique_id "al9McP7v0rlcEGmVraFLiQAAA4o"]
[Tue Jul 21 07:39:44.270033 2026] [security2:error] [pid 255769:tid 255821] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9McLxMYwyVGnfuwsKpYwADzzM"]
[Tue Jul 21 07:39:44.270190 2026] [security2:error] [pid 255769:tid 255943] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9McLxMYwyVGnfuwsKpYwADzzM"]
[Tue Jul 21 07:39:44.401635 2026] [security2:error] [pid 255769:tid 255816] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9McLxMYwyVGnfuwsKpZAAEHC4"]
[Tue Jul 21 07:39:44.401873 2026] [security2:error] [pid 255769:tid 256022] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9McLxMYwyVGnfuwsKpZAAEHC4"]
[Tue Jul 21 07:39:44.423225 2026] [security2:error] [pid 254995:tid 255262] [client 175.45.70.82:52738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9McP7v0rlcEGmVraFLjAAAA4w"]
[Tue Jul 21 07:39:44.423336 2026] [security2:error] [pid 254995:tid 255262] [client 175.45.70.82:52738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9McP7v0rlcEGmVraFLjAAAA4w"]
[Tue Jul 21 07:39:44.457305 2026] [security2:error] [pid 255769:tid 256004] [client 4.204.201.85:49905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-load.php"] [unique_id "al9McLxMYwyVGnfuwsKpZwAABAo"]
[Tue Jul 21 07:39:44.461552 2026] [security2:error] [pid 254995:tid 255156] [client 154.192.233.199:58820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9McP7v0rlcEGmVraFLjgAAAz0"]
[Tue Jul 21 07:39:44.461638 2026] [security2:error] [pid 254995:tid 255156] [client 154.192.233.199:58820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9McP7v0rlcEGmVraFLjgAAAz0"]
[Tue Jul 21 07:39:44.557287 2026] [security2:error] [pid 255769:tid 255969] [client 20.226.60.151:56192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/ctex1.php"] [unique_id "al9McLxMYwyVGnfuwsKpaQAAA-k"]
[Tue Jul 21 07:39:44.586081 2026] [security2:error] [pid 255769:tid 255935] [client 20.220.225.223:38235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/ez.php"] [unique_id "al9McLxMYwyVGnfuwsKpagAAA8c"]
[Tue Jul 21 07:39:44.596601 2026] [security2:error] [pid 255769:tid 256016] [client 20.197.195.24:13064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/about.php"] [unique_id "al9McLxMYwyVGnfuwsKpawAABBY"]
[Tue Jul 21 07:39:44.671708 2026] [security2:error] [pid 255769:tid 255917] [client 103.106.20.201:59287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9McLxMYwyVGnfuwsKpbAAAA7U"]
[Tue Jul 21 07:39:44.671834 2026] [security2:error] [pid 255769:tid 255917] [client 103.106.20.201:59287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9McLxMYwyVGnfuwsKpbAAAA7U"]
[Tue Jul 21 07:39:44.766331 2026] [security2:error] [pid 255769:tid 255997] [client 122.162.144.145:26000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9McLxMYwyVGnfuwsKpcAAABAM"]
[Tue Jul 21 07:39:44.766423 2026] [security2:error] [pid 255769:tid 255997] [client 122.162.144.145:26000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9McLxMYwyVGnfuwsKpcAAABAM"]
[Tue Jul 21 07:39:44.769351 2026] [security2:error] [pid 255769:tid 255948] [client 4.204.201.85:21787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/xwpg.php"] [unique_id "al9McLxMYwyVGnfuwsKpcQAAA9Q"]
[Tue Jul 21 07:39:44.853364 2026] [security2:error] [pid 255769:tid 255945] [client 193.36.225.58:41875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9McLxMYwyVGnfuwsKpdAAAA9E"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:44.977747 2026] [security2:error] [pid 255769:tid 255938] [client 152.59.154.239:63407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9McLxMYwyVGnfuwsKpdgAAA8o"]
[Tue Jul 21 07:39:44.977855 2026] [security2:error] [pid 255769:tid 255938] [client 152.59.154.239:63407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9McLxMYwyVGnfuwsKpdgAAA8o"]
[Tue Jul 21 07:39:45.079716 2026] [autoindex:error] [pid 255769:tid 255984] [client 4.204.201.85:49855] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:45.159932 2026] [security2:error] [pid 254995:tid 255163] [client 20.151.10.161:53609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/d62.php"] [unique_id "al9Mcf7v0rlcEGmVraFLlQAAA0Q"]
[Tue Jul 21 07:39:45.174994 2026] [security2:error] [pid 254995:tid 255149] [client 184.75.223.211:50756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Mcf7v0rlcEGmVraFLlgAAAzY"]
[Tue Jul 21 07:39:45.175084 2026] [security2:error] [pid 254995:tid 255149] [client 184.75.223.211:50756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Mcf7v0rlcEGmVraFLlgAAAzY"]
[Tue Jul 21 07:39:45.187065 2026] [security2:error] [pid 254995:tid 255161] [client 20.226.60.151:56219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/edorxrr.php"] [unique_id "al9Mcf7v0rlcEGmVraFLlwAAA0I"]
[Tue Jul 21 07:39:45.419960 2026] [autoindex:error] [pid 255769:tid 255999] [client 4.204.201.85:49855] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:45.561150 2026] [security2:error] [pid 255769:tid 255905] [client 4.204.201.85:49855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/xstelth.php"] [unique_id "al9McbxMYwyVGnfuwsKpegAAA6k"]
[Tue Jul 21 07:39:45.580914 2026] [security2:error] [pid 255769:tid 255965] [client 128.127.105.184:46712] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9McbxMYwyVGnfuwsKpewAAA-U"]
[Tue Jul 21 07:39:45.581023 2026] [security2:error] [pid 255769:tid 255965] [client 128.127.105.184:46712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9McbxMYwyVGnfuwsKpewAAA-U"]
[Tue Jul 21 07:39:45.708542 2026] [security2:error] [pid 254995:tid 255144] [client 103.86.117.203:60902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mcf7v0rlcEGmVraFLpAAAAzE"]
[Tue Jul 21 07:39:45.708675 2026] [security2:error] [pid 254995:tid 255144] [client 103.86.117.203:60902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mcf7v0rlcEGmVraFLpAAAAzE"]
[Tue Jul 21 07:39:45.712610 2026] [security2:error] [pid 255769:tid 255958] [client 20.197.192.193:56442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9McbxMYwyVGnfuwsKpfwAAA94"]
[Tue Jul 21 07:39:45.724556 2026] [security2:error] [pid 255769:tid 255791] [remote 47.128.25.144:19084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcoll.com.br"] [uri "/web/page.php"] [unique_id "al9McbxMYwyVGnfuwsKpgQAD9BU"]
[Tue Jul 21 07:39:45.730733 2026] [security2:error] [pid 255769:tid 255966] [client 20.197.192.193:58465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9McbxMYwyVGnfuwsKpggAAA-Y"]
[Tue Jul 21 07:39:45.749387 2026] [security2:error] [pid 255769:tid 256009] [client 20.197.192.193:58463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/dp.php"] [unique_id "al9McbxMYwyVGnfuwsKphAAABA8"]
[Tue Jul 21 07:39:45.757149 2026] [security2:error] [pid 254995:tid 255213] [client 20.197.195.24:48862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/admin.php"] [unique_id "al9Mcf7v0rlcEGmVraFLpwAAA3U"]
[Tue Jul 21 07:39:45.761526 2026] [security2:error] [pid 255769:tid 255907] [client 20.197.192.193:58468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/old.php"] [unique_id "al9McbxMYwyVGnfuwsKphgAAA6s"]
[Tue Jul 21 07:39:45.773144 2026] [security2:error] [pid 255769:tid 255921] [client 20.197.192.193:58438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/ms-new.php"] [unique_id "al9McbxMYwyVGnfuwsKphwAAA7k"]
[Tue Jul 21 07:39:45.785086 2026] [security2:error] [pid 255769:tid 255964] [client 20.197.192.193:58204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/track.php"] [unique_id "al9McbxMYwyVGnfuwsKpiAAAA-Q"]
[Tue Jul 21 07:39:45.795413 2026] [security2:error] [pid 255769:tid 255982] [client 20.197.192.193:56444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/2352356666.php"] [unique_id "al9McbxMYwyVGnfuwsKpiQAAA_Y"]
[Tue Jul 21 07:39:45.806722 2026] [security2:error] [pid 255769:tid 256004] [client 20.197.192.193:56419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/pn.php"] [unique_id "al9McbxMYwyVGnfuwsKpigAABAo"]
[Tue Jul 21 07:39:45.829390 2026] [security2:error] [pid 255769:tid 256008] [client 20.197.192.193:58193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-wpbak.php"] [unique_id "al9McbxMYwyVGnfuwsKpiwAABA4"]
[Tue Jul 21 07:39:45.844786 2026] [security2:error] [pid 255769:tid 255954] [client 20.197.192.193:58477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/dr.php"] [unique_id "al9McbxMYwyVGnfuwsKpjQAAA9o"]
[Tue Jul 21 07:39:45.850061 2026] [security2:error] [pid 255769:tid 255908] [client 4.204.201.85:4525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9McbxMYwyVGnfuwsKpjgAAA6w"]
[Tue Jul 21 07:39:45.863527 2026] [security2:error] [pid 255769:tid 255985] [client 20.197.192.193:58457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/2x.php"] [unique_id "al9McbxMYwyVGnfuwsKpkAAAA_k"]
[Tue Jul 21 07:39:45.881263 2026] [security2:error] [pid 255769:tid 256010] [client 20.197.192.193:58458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/kq1.php"] [unique_id "al9McbxMYwyVGnfuwsKpkgAABBA"]
[Tue Jul 21 07:39:45.902195 2026] [security2:error] [pid 255769:tid 256016] [client 20.197.192.193:56443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/zzz.php"] [unique_id "al9McbxMYwyVGnfuwsKplAAABBY"]
[Tue Jul 21 07:39:45.917881 2026] [security2:error] [pid 255769:tid 255917] [client 20.197.192.193:58450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wicked.php"] [unique_id "al9McbxMYwyVGnfuwsKplQAAA7U"]
[Tue Jul 21 07:39:45.928402 2026] [security2:error] [pid 254995:tid 255254] [client 20.197.192.193:58470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/edit.php"] [unique_id "al9Mcf7v0rlcEGmVraFLqgAAA4Q"]
[Tue Jul 21 07:39:45.943851 2026] [core:alert] [pid 254995:tid 255225] [client 57.141.18.46:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:39:45.944873 2026] [security2:error] [pid 254995:tid 255128] [client 20.197.192.193:58494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/kua.php"] [unique_id "al9Mcf7v0rlcEGmVraFLrgAAAyE"]
[Tue Jul 21 07:39:45.960078 2026] [security2:error] [pid 255769:tid 256027] [client 20.197.192.193:56431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/ez.php"] [unique_id "al9McbxMYwyVGnfuwsKplwAABCE"]
[Tue Jul 21 07:39:45.977549 2026] [security2:error] [pid 255769:tid 255953] [client 20.197.192.193:58433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/fz.php"] [unique_id "al9McbxMYwyVGnfuwsKpmAAAA9k"]
[Tue Jul 21 07:39:45.989795 2026] [security2:error] [pid 254995:tid 255195] [client 20.197.192.193:56441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/la.php"] [unique_id "al9Mcf7v0rlcEGmVraFLsQAAA2Q"]
[Tue Jul 21 07:39:46.007519 2026] [security2:error] [pid 255769:tid 255915] [client 20.197.192.193:56424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/nhvoanpl.php"] [unique_id "al9McrxMYwyVGnfuwsKpmwAAA7M"]
[Tue Jul 21 07:39:46.021902 2026] [security2:error] [pid 254995:tid 255190] [client 20.197.192.193:58474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/inso.php"] [unique_id "al9Mcv7v0rlcEGmVraFLswAAA18"]
[Tue Jul 21 07:39:46.042608 2026] [security2:error] [pid 255769:tid 255929] [client 20.197.192.193:49558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wpx.php"] [unique_id "al9McrxMYwyVGnfuwsKpnAAAA8E"]
[Tue Jul 21 07:39:46.061983 2026] [security2:error] [pid 254995:tid 255165] [client 20.197.192.193:56447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/berlin.php"] [unique_id "al9Mcv7v0rlcEGmVraFLtQAAA0Y"]
[Tue Jul 21 07:39:46.083836 2026] [security2:error] [pid 254995:tid 255201] [client 20.197.192.193:58215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/billur.php"] [unique_id "al9Mcv7v0rlcEGmVraFLtwAAA2o"]
[Tue Jul 21 07:39:46.099757 2026] [security2:error] [pid 254995:tid 255155] [client 20.197.192.193:56386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/mimpi.php"] [unique_id "al9Mcv7v0rlcEGmVraFLuAAAAzw"]
[Tue Jul 21 07:39:46.101646 2026] [security2:error] [pid 254995:tid 255215] [client 20.151.10.161:46064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9Mcv7v0rlcEGmVraFLuQAAA3c"]
[Tue Jul 21 07:39:46.116647 2026] [security2:error] [pid 254995:tid 255132] [client 20.197.192.193:56414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/dp.php"] [unique_id "al9Mcv7v0rlcEGmVraFLugAAAyU"]
[Tue Jul 21 07:39:46.131381 2026] [security2:error] [pid 254995:tid 255209] [client 20.197.192.193:56425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/bootstrap.php"] [unique_id "al9Mcv7v0rlcEGmVraFLuwAAA3E"]
[Tue Jul 21 07:39:46.132612 2026] [security2:error] [pid 255769:tid 255987] [client 4.204.201.85:4515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/aaa.php"] [unique_id "al9McrxMYwyVGnfuwsKpngAAA_s"]
[Tue Jul 21 07:39:46.147185 2026] [security2:error] [pid 255769:tid 255938] [client 20.197.192.193:58476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-editor.php"] [unique_id "al9McrxMYwyVGnfuwsKpnwAAA8o"]
[Tue Jul 21 07:39:46.161047 2026] [security2:error] [pid 255769:tid 255971] [client 20.197.192.193:58486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/cro.php"] [unique_id "al9McrxMYwyVGnfuwsKpoAAAA-s"]
[Tue Jul 21 07:39:46.171832 2026] [security2:error] [pid 255769:tid 255924] [client 20.197.192.193:58491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/cron-tab.php"] [unique_id "al9McrxMYwyVGnfuwsKpoQAAA7w"]
[Tue Jul 21 07:39:46.182186 2026] [security2:error] [pid 255769:tid 255984] [client 20.197.192.193:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/koiy.php"] [unique_id "al9McrxMYwyVGnfuwsKpogAAA_g"]
[Tue Jul 21 07:39:46.194868 2026] [security2:error] [pid 255769:tid 255999] [client 20.197.192.193:58202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/hp2.php"] [unique_id "al9McrxMYwyVGnfuwsKpowAABAU"]
[Tue Jul 21 07:39:46.205954 2026] [security2:error] [pid 255769:tid 256021] [client 20.197.192.193:49595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/hp3.php"] [unique_id "al9McrxMYwyVGnfuwsKppAAABBs"]
[Tue Jul 21 07:39:46.215949 2026] [security2:error] [pid 255769:tid 255959] [client 20.197.192.193:56440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/aa1.php"] [unique_id "al9McrxMYwyVGnfuwsKppQAAA98"]
[Tue Jul 21 07:39:46.225470 2026] [security2:error] [pid 255769:tid 255965] [client 20.197.192.193:58455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/acew67.php"] [unique_id "al9McrxMYwyVGnfuwsKppgAAA-U"]
[Tue Jul 21 07:39:46.236576 2026] [security2:error] [pid 255769:tid 255968] [client 20.197.192.193:56434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/bscclapb.php"] [unique_id "al9McrxMYwyVGnfuwsKppwAAA-g"]
[Tue Jul 21 07:39:46.248436 2026] [security2:error] [pid 255769:tid 255932] [client 20.197.192.193:58179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/else1.php"] [unique_id "al9McrxMYwyVGnfuwsKpqAAAA8Q"]
[Tue Jul 21 07:39:46.260723 2026] [security2:error] [pid 255769:tid 255909] [client 20.197.192.193:56417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/tkikikoko.php"] [unique_id "al9McrxMYwyVGnfuwsKpqgAAA60"]
[Tue Jul 21 07:39:46.273231 2026] [security2:error] [pid 255769:tid 255978] [client 20.197.192.193:58203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-Blogs.php"] [unique_id "al9McrxMYwyVGnfuwsKpqwAAA_I"]
[Tue Jul 21 07:39:46.286038 2026] [security2:error] [pid 255769:tid 255966] [client 20.197.192.193:49554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-css.php"] [unique_id "al9McrxMYwyVGnfuwsKprQAAA-Y"]
[Tue Jul 21 07:39:46.302894 2026] [security2:error] [pid 254995:tid 255160] [client 20.197.192.193:58435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-explorer.php"] [unique_id "al9Mcv7v0rlcEGmVraFLvwAAA0E"]
[Tue Jul 21 07:39:46.315899 2026] [security2:error] [pid 254995:tid 255260] [client 20.197.192.193:56387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/akismet.php"] [unique_id "al9Mcv7v0rlcEGmVraFLwAAAA4o"]
[Tue Jul 21 07:39:46.329835 2026] [security2:error] [pid 255769:tid 255921] [client 20.197.192.193:58216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/ace2.php"] [unique_id "al9McrxMYwyVGnfuwsKpsAAAA7k"]
[Tue Jul 21 07:39:46.341440 2026] [security2:error] [pid 255769:tid 256024] [client 20.197.192.193:58185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/ms.php"] [unique_id "al9McrxMYwyVGnfuwsKpsQAABB4"]
[Tue Jul 21 07:39:46.413808 2026] [security2:error] [pid 254995:tid 255148] [client 4.204.201.85:49892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/gecko.php"] [unique_id "al9Mcv7v0rlcEGmVraFLwQAAAzU"]
[Tue Jul 21 07:39:46.502576 2026] [security2:error] [pid 254995:tid 255181] [client 20.226.60.151:56282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/miru1.php"] [unique_id "al9Mcv7v0rlcEGmVraFLxAAAA1Y"]
[Tue Jul 21 07:39:46.527840 2026] [security2:error] [pid 255769:tid 256008] [client 62.102.148.187:60760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9McrxMYwyVGnfuwsKptwAABA4"]
[Tue Jul 21 07:39:46.527935 2026] [security2:error] [pid 255769:tid 256008] [client 62.102.148.187:60760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9McrxMYwyVGnfuwsKptwAABA4"]
[Tue Jul 21 07:39:46.706761 2026] [security2:error] [pid 254995:tid 255150] [client 4.204.201.85:49849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/sh3ll.php"] [unique_id "al9Mcv7v0rlcEGmVraFLxwAAAzc"]
[Tue Jul 21 07:39:46.953279 2026] [security2:error] [pid 255769:tid 256011] [client 20.151.10.161:55246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ups.php"] [unique_id "al9McrxMYwyVGnfuwsKpvwAABBE"]
[Tue Jul 21 07:39:46.990821 2026] [security2:error] [pid 255769:tid 256001] [client 4.204.201.85:21732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/pbck.php"] [unique_id "al9McrxMYwyVGnfuwsKpwAAABAc"]
[Tue Jul 21 07:39:47.055793 2026] [security2:error] [pid 255769:tid 255814] [remote 162.19.86.63:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produto-express.com"] [uri "/wp-login.php"] [unique_id "al9Mc7xMYwyVGnfuwsKpwQADtSw"]
[Tue Jul 21 07:39:47.272630 2026] [security2:error] [pid 255769:tid 255987] [client 4.204.201.85:49865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/xiugai.php"] [unique_id "al9Mc7xMYwyVGnfuwsKpxgAAA_s"]
[Tue Jul 21 07:39:47.280862 2026] [security2:error] [pid 254995:tid 255273] [client 59.96.220.140:49478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Mc_7v0rlcEGmVraFL0gAAA5c"]
[Tue Jul 21 07:39:47.281561 2026] [security2:error] [pid 254995:tid 255273] [client 59.96.220.140:49478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Mc_7v0rlcEGmVraFL0gAAA5c"]
[Tue Jul 21 07:39:47.587787 2026] [security2:error] [pid 254995:tid 255111] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mc_7v0rlcEGmVraFL2AADS3M"]
[Tue Jul 21 07:39:47.587922 2026] [security2:error] [pid 254995:tid 255170] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mc_7v0rlcEGmVraFL2AADS3M"]
[Tue Jul 21 07:39:47.602062 2026] [security2:error] [pid 255769:tid 256009] [client 4.204.201.85:21785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/e.php"] [unique_id "al9Mc7xMYwyVGnfuwsKp0wAABA8"]
[Tue Jul 21 07:39:47.624396 2026] [security2:error] [pid 255769:tid 255907] [client 20.197.195.24:48873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/admin.php"] [unique_id "al9Mc7xMYwyVGnfuwsKp1AAAA6s"]
[Tue Jul 21 07:39:47.762978 2026] [security2:error] [pid 255769:tid 255948] [client 103.174.34.15:65260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mc7xMYwyVGnfuwsKp2gAAA9Q"]
[Tue Jul 21 07:39:47.763088 2026] [security2:error] [pid 255769:tid 255948] [client 103.174.34.15:65260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mc7xMYwyVGnfuwsKp2gAAA9Q"]
[Tue Jul 21 07:39:47.818564 2026] [security2:error] [pid 255769:tid 255931] [client 20.151.10.161:53612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/k.php"] [unique_id "al9Mc7xMYwyVGnfuwsKp3AAAA8M"]
[Tue Jul 21 07:39:47.901445 2026] [security2:error] [pid 254995:tid 255127] [client 4.204.201.85:21795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/for.php"] [unique_id "al9Mc_7v0rlcEGmVraFL3wAAAyA"]
[Tue Jul 21 07:39:48.036895 2026] [security2:error] [pid 255769:tid 255914] [client 20.151.10.161:45966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/gettest.php"] [unique_id "al9MdLxMYwyVGnfuwsKp4QAAA7I"]
[Tue Jul 21 07:39:48.166584 2026] [security2:error] [pid 255769:tid 256016] [client 20.151.10.161:55238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/k2.php"] [unique_id "al9MdLxMYwyVGnfuwsKp5gAABBY"]
[Tue Jul 21 07:39:48.181774 2026] [security2:error] [pid 255769:tid 255902] [client 4.204.201.85:4447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/ssh3ll.php"] [unique_id "al9MdLxMYwyVGnfuwsKp5wAAA6Y"]
[Tue Jul 21 07:39:48.404710 2026] [security2:error] [pid 255769:tid 255915] [client 20.220.225.223:19317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/dp.php"] [unique_id "al9MdLxMYwyVGnfuwsKp6gAAA7M"]
[Tue Jul 21 07:39:48.419096 2026] [security2:error] [pid 255769:tid 255911] [client 20.220.225.223:34301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/track.php"] [unique_id "al9MdLxMYwyVGnfuwsKp6wAAA68"]
[Tue Jul 21 07:39:48.455726 2026] [security2:error] [pid 254995:tid 255269] [client 122.179.91.63:13666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MdP7v0rlcEGmVraFL6QAAA5M"]
[Tue Jul 21 07:39:48.455990 2026] [security2:error] [pid 254995:tid 255269] [client 122.179.91.63:13666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MdP7v0rlcEGmVraFL6QAAA5M"]
[Tue Jul 21 07:39:48.459314 2026] [security2:error] [pid 255769:tid 255972] [client 139.167.225.182:55878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MdLxMYwyVGnfuwsKp7AAAA-w"]
[Tue Jul 21 07:39:48.459389 2026] [security2:error] [pid 255769:tid 255972] [client 139.167.225.182:55878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MdLxMYwyVGnfuwsKp7AAAA-w"]
[Tue Jul 21 07:39:48.473371 2026] [security2:error] [pid 255769:tid 255997] [client 4.204.201.85:49807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/adminner.php"] [unique_id "al9MdLxMYwyVGnfuwsKp7QAABAM"]
[Tue Jul 21 07:39:48.526632 2026] [security2:error] [pid 255769:tid 255954] [client 117.217.38.194:58421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MdLxMYwyVGnfuwsKp7wAAA9o"]
[Tue Jul 21 07:39:48.526990 2026] [security2:error] [pid 255769:tid 255954] [client 117.217.38.194:58421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MdLxMYwyVGnfuwsKp7wAAA9o"]
[Tue Jul 21 07:39:48.571671 2026] [security2:error] [pid 255769:tid 255983] [client 20.226.60.151:56270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/sump1.php"] [unique_id "al9MdLxMYwyVGnfuwsKp8wAAA_c"]
[Tue Jul 21 07:39:48.697886 2026] [security2:error] [pid 254995:tid 255141] [client 20.151.10.161:53618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/k3.php"] [unique_id "al9MdP7v0rlcEGmVraFL7wAAAy4"]
[Tue Jul 21 07:39:48.759348 2026] [security2:error] [pid 254995:tid 255162] [client 4.204.201.85:49795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/82.php"] [unique_id "al9MdP7v0rlcEGmVraFL8AAAA0M"]
[Tue Jul 21 07:39:49.044682 2026] [security2:error] [pid 255769:tid 255978] [client 4.204.201.85:21792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/kir.php"] [unique_id "al9MdbxMYwyVGnfuwsKp-wAAA_I"]
[Tue Jul 21 07:39:49.062093 2026] [security2:error] [pid 254995:tid 255206] [client 20.197.195.24:13062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/themes.php"] [unique_id "al9Mdf7v0rlcEGmVraFL9QAAA28"]
[Tue Jul 21 07:39:49.318780 2026] [security2:error] [pid 254995:tid 255160] [client 4.204.201.85:49870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/up4.php"] [unique_id "al9Mdf7v0rlcEGmVraFL-gAAA0E"]
[Tue Jul 21 07:39:49.499911 2026] [security2:error] [pid 255769:tid 255943] [client 20.197.192.193:6864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/wp-css.php"] [unique_id "al9MdbxMYwyVGnfuwsKqBQAAA88"]
[Tue Jul 21 07:39:49.545836 2026] [security2:error] [pid 254995:tid 255154] [client 20.151.10.161:55251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/k4.php"] [unique_id "al9Mdf7v0rlcEGmVraFMBAAAAzs"]
[Tue Jul 21 07:39:49.629700 2026] [security2:error] [pid 255769:tid 255969] [client 4.204.201.85:49917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/xhar.php"] [unique_id "al9MdbxMYwyVGnfuwsKqBwAAA-k"]
[Tue Jul 21 07:39:49.631257 2026] [security2:error] [pid 255769:tid 255964] [client 136.144.33.106:52841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MdbxMYwyVGnfuwsKqBAAAA-Q"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:49.932643 2026] [security2:error] [pid 255769:tid 255908] [client 4.204.201.85:49867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/file1221.php"] [unique_id "al9MdbxMYwyVGnfuwsKqCwAAA6w"]
[Tue Jul 21 07:39:50.057208 2026] [security2:error] [pid 255769:tid 255967] [client 20.151.10.161:53587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/k5.php"] [unique_id "al9MdrxMYwyVGnfuwsKqDAAAA-c"]
[Tue Jul 21 07:39:50.177614 2026] [security2:error] [pid 255769:tid 255784] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MdrxMYwyVGnfuwsKqEgAD_g4"]
[Tue Jul 21 07:39:50.177773 2026] [security2:error] [pid 255769:tid 255990] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MdrxMYwyVGnfuwsKqEgAD_g4"]
[Tue Jul 21 07:39:50.214880 2026] [security2:error] [pid 255769:tid 255987] [client 4.204.201.85:4434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/inx.php"] [unique_id "al9MdrxMYwyVGnfuwsKqEwAAA_s"]
[Tue Jul 21 07:39:50.352408 2026] [autoindex:error] [pid 255769:tid 255956] [client 20.197.195.24:13076] AH01276: Cannot serve directory /home2/ren85318/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:50.460415 2026] [security2:error] [pid 255769:tid 255999] [client 20.226.60.151:56203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/file5.php"] [unique_id "al9MdrxMYwyVGnfuwsKqGQAABAU"]
[Tue Jul 21 07:39:50.468658 2026] [security2:error] [pid 255769:tid 255963] [client 20.151.10.161:46065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/simple.php"] [unique_id "al9MdrxMYwyVGnfuwsKqGgAAA-M"]
[Tue Jul 21 07:39:50.492025 2026] [security2:error] [pid 254995:tid 255277] [client 4.204.201.85:49877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/qqqa.php"] [unique_id "al9Mdv7v0rlcEGmVraFMEwAAA5s"]
[Tue Jul 21 07:39:50.548808 2026] [security2:error] [pid 255769:tid 255938] [client 173.24.185.52:63015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MdrxMYwyVGnfuwsKqGwAAA8o"]
[Tue Jul 21 07:39:50.548921 2026] [security2:error] [pid 255769:tid 255938] [client 173.24.185.52:63015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MdrxMYwyVGnfuwsKqGwAAA8o"]
[Tue Jul 21 07:39:50.614769 2026] [security2:error] [pid 255769:tid 255902] [client 106.215.181.8:17151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MdrxMYwyVGnfuwsKqHQAAA6Y"]
[Tue Jul 21 07:39:50.614896 2026] [security2:error] [pid 255769:tid 255902] [client 106.215.181.8:17151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MdrxMYwyVGnfuwsKqHQAAA6Y"]
[Tue Jul 21 07:39:50.644939 2026] [security2:error] [pid 254995:tid 255217] [client 20.151.10.161:55242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/w.php"] [unique_id "al9Mdv7v0rlcEGmVraFMGQAAA3k"]
[Tue Jul 21 07:39:50.791689 2026] [security2:error] [pid 254995:tid 255213] [client 4.204.201.85:4428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/ffffile.php"] [unique_id "al9Mdv7v0rlcEGmVraFMHAAAA3U"]
[Tue Jul 21 07:39:50.929944 2026] [security2:error] [pid 255769:tid 255931] [client 20.197.195.24:13076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/.well-known/about.php"] [unique_id "al9MdrxMYwyVGnfuwsKqJgAAA8M"]
[Tue Jul 21 07:39:51.068713 2026] [security2:error] [pid 254995:tid 255275] [client 4.204.201.85:21770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-firewall.php"] [unique_id "al9Md_7v0rlcEGmVraFMIQAAA5k"]
[Tue Jul 21 07:39:51.342273 2026] [security2:error] [pid 255769:tid 255919] [client 4.204.201.85:21699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/reviall.php"] [unique_id "al9Md7xMYwyVGnfuwsKqLgAAA7c"]
[Tue Jul 21 07:39:51.504908 2026] [security2:error] [pid 254995:tid 255165] [client 20.151.10.161:55286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/fpwch.php"] [unique_id "al9Md_7v0rlcEGmVraFMKQAAA0Y"]
[Tue Jul 21 07:39:51.542570 2026] [security2:error] [pid 254995:tid 255137] [client 20.226.60.151:51212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/0xD.php"] [unique_id "al9Md_7v0rlcEGmVraFMKwAAAyo"]
[Tue Jul 21 07:39:51.685637 2026] [security2:error] [pid 255769:tid 255971] [client 20.220.225.223:19300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/old.php"] [unique_id "al9Md7xMYwyVGnfuwsKqNwAAA-s"]
[Tue Jul 21 07:39:51.745399 2026] [security2:error] [pid 255769:tid 255981] [client 20.197.192.193:6656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/wp-explorer.php"] [unique_id "al9Md7xMYwyVGnfuwsKqOQAAA_U"]
[Tue Jul 21 07:39:51.869875 2026] [security2:error] [pid 255769:tid 256022] [client 20.197.195.24:13080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9Md7xMYwyVGnfuwsKqOwAABBw"]
[Tue Jul 21 07:39:52.140762 2026] [security2:error] [pid 254995:tid 255209] [client 20.151.10.161:55240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/w2025.php"] [unique_id "al9MeP7v0rlcEGmVraFMMwAAA3E"]
[Tue Jul 21 07:39:52.329446 2026] [security2:error] [pid 255769:tid 255918] [client 20.151.10.161:45956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xxx.php"] [unique_id "al9MeLxMYwyVGnfuwsKqQQAAA7Y"]
[Tue Jul 21 07:39:52.471163 2026] [security2:error] [pid 255769:tid 255822] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MeLxMYwyVGnfuwsKqQwAD9jQ"]
[Tue Jul 21 07:39:52.471302 2026] [security2:error] [pid 255769:tid 255982] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MeLxMYwyVGnfuwsKqQwAD9jQ"]
[Tue Jul 21 07:39:52.477042 2026] [security2:error] [pid 255769:tid 256021] [client 122.186.204.214:64393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MeLxMYwyVGnfuwsKqRAAABBs"]
[Tue Jul 21 07:39:52.477149 2026] [security2:error] [pid 255769:tid 256021] [client 122.186.204.214:64393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MeLxMYwyVGnfuwsKqRAAABBs"]
[Tue Jul 21 07:39:52.481316 2026] [security2:error] [pid 255769:tid 256018] [client 117.251.86.144:41582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MeLxMYwyVGnfuwsKqRQAABBg"]
[Tue Jul 21 07:39:52.481424 2026] [security2:error] [pid 255769:tid 256018] [client 117.251.86.144:41582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MeLxMYwyVGnfuwsKqRQAABBg"]
[Tue Jul 21 07:39:52.505976 2026] [security2:error] [pid 254995:tid 255187] [client 20.151.10.161:53605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/scxy.php"] [unique_id "al9MeP7v0rlcEGmVraFMPwAAA1w"]
[Tue Jul 21 07:39:52.706668 2026] [security2:error] [pid 254995:tid 255156] [client 20.197.192.193:6985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/akismet.php"] [unique_id "al9MeP7v0rlcEGmVraFMRAAAAz0"]
[Tue Jul 21 07:39:52.724458 2026] [security2:error] [pid 254995:tid 255150] [client 184.75.223.211:49684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MeP7v0rlcEGmVraFMRQAAAzc"]
[Tue Jul 21 07:39:52.724570 2026] [security2:error] [pid 254995:tid 255150] [client 184.75.223.211:49684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MeP7v0rlcEGmVraFMRQAAAzc"]
[Tue Jul 21 07:39:52.791028 2026] [security2:error] [pid 254995:tid 255103] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MeP7v0rlcEGmVraFMSQADNWs"]
[Tue Jul 21 07:39:52.791157 2026] [security2:error] [pid 254995:tid 255148] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MeP7v0rlcEGmVraFMSQADNWs"]
[Tue Jul 21 07:39:53.163126 2026] [access_compat:error] [pid 254995:tid 255273] [client 162.241.63.68:39804] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:39:53.199624 2026] [security2:error] [pid 254995:tid 255278] [client 20.220.225.223:19290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/ms-new.php"] [unique_id "al9Mef7v0rlcEGmVraFMVAAAA5w"]
[Tue Jul 21 07:39:53.281441 2026] [security2:error] [pid 255769:tid 255919] [client 20.197.195.24:13106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/wefile.php"] [unique_id "al9MebxMYwyVGnfuwsKqTQAAA7c"]
[Tue Jul 21 07:39:53.299256 2026] [security2:error] [pid 254995:tid 255170] [client 20.151.10.161:12084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/FWAZ.php"] [unique_id "al9Mef7v0rlcEGmVraFMVgAAA0s"]
[Tue Jul 21 07:39:53.461678 2026] [security2:error] [pid 254995:tid 255204] [client 20.226.60.151:23160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Mef7v0rlcEGmVraFMWAAAA20"]
[Tue Jul 21 07:39:53.578596 2026] [security2:error] [pid 254995:tid 255174] [client 20.151.10.161:45916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/hypo.php"] [unique_id "al9Mef7v0rlcEGmVraFMYAAAA08"]
[Tue Jul 21 07:39:53.589865 2026] [security2:error] [pid 255769:tid 255908] [client 37.140.223.122:44515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Md7xMYwyVGnfuwsKqNQAAA6w"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:39:53.922270 2026] [security2:error] [pid 254995:tid 255038] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mef7v0rlcEGmVraFMZQADIyo"]
[Tue Jul 21 07:39:53.922414 2026] [security2:error] [pid 254995:tid 255130] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mef7v0rlcEGmVraFMZQADIyo"]
[Tue Jul 21 07:39:54.006078 2026] [security2:error] [pid 255769:tid 255948] [client 20.197.192.193:6896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/ace2.php"] [unique_id "al9MerxMYwyVGnfuwsKqWgAAA9Q"]
[Tue Jul 21 07:39:54.014266 2026] [security2:error] [pid 255769:tid 256022] [client 20.197.195.24:13103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9MerxMYwyVGnfuwsKqWwAABBw"]
[Tue Jul 21 07:39:54.037571 2026] [security2:error] [pid 254995:tid 255220] [client 20.151.10.161:53616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/qterm.php"] [unique_id "al9Mev7v0rlcEGmVraFMawAAA3w"]
[Tue Jul 21 07:39:54.109423 2026] [security2:error] [pid 255769:tid 256014] [client 20.220.225.223:34264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/2352356666.php"] [unique_id "al9MerxMYwyVGnfuwsKqXwAABBQ"]
[Tue Jul 21 07:39:54.120537 2026] [security2:error] [pid 254995:tid 255172] [client 20.226.60.151:56236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/fnstall.php"] [unique_id "al9Mev7v0rlcEGmVraFMbwAAA00"]
[Tue Jul 21 07:39:54.275144 2026] [security2:error] [pid 255769:tid 255949] [client 20.151.10.161:46063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/chosen.php"] [unique_id "al9MerxMYwyVGnfuwsKqYwAAA9U"]
[Tue Jul 21 07:39:54.347976 2026] [security2:error] [pid 255769:tid 255842] [remote 45.150.79.142:34728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-login.php"] [unique_id "al9MerxMYwyVGnfuwsKqZQAD5Ug"]
[Tue Jul 21 07:39:54.387980 2026] [security2:error] [pid 255769:tid 255912] [client 196.251.121.187:55287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "fisioevida.com"] [uri "/"] [unique_id "al9MerxMYwyVGnfuwsKqaAAAA7A"]
[Tue Jul 21 07:39:54.566871 2026] [security2:error] [pid 255769:tid 255967] [client 154.192.233.199:58585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MerxMYwyVGnfuwsKqbwAAA-c"]
[Tue Jul 21 07:39:54.567000 2026] [security2:error] [pid 255769:tid 255967] [client 154.192.233.199:58585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MerxMYwyVGnfuwsKqbwAAA-c"]
[Tue Jul 21 07:39:54.635968 2026] [security2:error] [pid 255769:tid 255925] [client 20.151.10.161:55255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/blurbs.php"] [unique_id "al9MerxMYwyVGnfuwsKqcAAAA70"]
[Tue Jul 21 07:39:54.698290 2026] [autoindex:error] [pid 255769:tid 255776] [remote 74.7.227.191:42906] AH01276: Cannot serve directory /home1/imperd48/sabino-tracker.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:54.762664 2026] [security2:error] [pid 255769:tid 255828] [remote 41.76.214.143:58544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pousadanaturalis.com.br"] [uri "/wp-login.php"] [unique_id "al9MerxMYwyVGnfuwsKqdAAEEDo"]
[Tue Jul 21 07:39:54.774560 2026] [security2:error] [pid 254995:tid 255194] [client 74.7.228.9:40690] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "sabino-tracker.com.imperdivelbestpromotionofthedaytodayonly.com"] [uri "/cgi-sys/404.html"] [unique_id "al9Mev7v0rlcEGmVraFMgQADYyE"]
[Tue Jul 21 07:39:54.818295 2026] [security2:error] [pid 254995:tid 255062] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Mev7v0rlcEGmVraFMgwADSkI"]
[Tue Jul 21 07:39:54.818441 2026] [security2:error] [pid 254995:tid 255169] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Mev7v0rlcEGmVraFMgwADSkI"]
[Tue Jul 21 07:39:54.914391 2026] [autoindex:error] [pid 254995:tid 255155] [client 20.197.195.24:13130] AH01276: Cannot serve directory /home2/ren85318/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:54.924070 2026] [security2:error] [pid 255769:tid 256009] [client 20.226.60.151:23150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MerxMYwyVGnfuwsKqewAABA8"]
[Tue Jul 21 07:39:54.955201 2026] [security2:error] [pid 255769:tid 256011] [client 20.151.10.161:45928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/als.php"] [unique_id "al9MerxMYwyVGnfuwsKqfAAABBE"]
[Tue Jul 21 07:39:55.167151 2026] [security2:error] [pid 255769:tid 255893] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Me7xMYwyVGnfuwsKqgwAD-Xs"]
[Tue Jul 21 07:39:55.167290 2026] [security2:error] [pid 255769:tid 255985] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Me7xMYwyVGnfuwsKqgwAD-Xs"]
[Tue Jul 21 07:39:55.170934 2026] [autoindex:error] [pid 254995:tid 255181] [client 20.197.195.24:13130] AH01276: Cannot serve directory /home2/ren85318/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:55.175835 2026] [security2:error] [pid 255769:tid 256027] [client 74.7.230.43:52430] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.app.pedido-online.net"] [uri "/index.php"] [unique_id "al9Me7xMYwyVGnfuwsKqgAAEIVY"]
[Tue Jul 21 07:39:55.182096 2026] [security2:error] [pid 255769:tid 255931] [client 175.45.70.82:53259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Me7xMYwyVGnfuwsKqhAAAA8M"]
[Tue Jul 21 07:39:55.182200 2026] [security2:error] [pid 255769:tid 255931] [client 175.45.70.82:53259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Me7xMYwyVGnfuwsKqhAAAA8M"]
[Tue Jul 21 07:39:55.189229 2026] [security2:error] [pid 254995:tid 255179] [client 20.197.195.24:13130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Me_7v0rlcEGmVraFMiQAAA1Q"]
[Tue Jul 21 07:39:55.247122 2026] [security2:error] [pid 254995:tid 255173] [client 20.151.10.161:55245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/v543.php"] [unique_id "al9Me_7v0rlcEGmVraFMigAAA04"]
[Tue Jul 21 07:39:55.389221 2026] [security2:error] [pid 255769:tid 255914] [client 103.106.20.201:59901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Me7xMYwyVGnfuwsKqigAAA7I"]
[Tue Jul 21 07:39:55.389309 2026] [security2:error] [pid 255769:tid 255914] [client 103.106.20.201:59901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Me7xMYwyVGnfuwsKqigAAA7I"]
[Tue Jul 21 07:39:55.427922 2026] [security2:error] [pid 254995:tid 255166] [client 20.197.192.193:6996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/ms.php"] [unique_id "al9Me_7v0rlcEGmVraFMjgAAA0c"]
[Tue Jul 21 07:39:55.484465 2026] [security2:error] [pid 255769:tid 255977] [client 4.204.201.85:3527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Me7xMYwyVGnfuwsKqjAAAA_E"]
[Tue Jul 21 07:39:55.548275 2026] [security2:error] [pid 254995:tid 255168] [client 122.162.144.145:14064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Me_7v0rlcEGmVraFMjwAAA0k"]
[Tue Jul 21 07:39:55.548402 2026] [security2:error] [pid 254995:tid 255168] [client 122.162.144.145:14064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Me_7v0rlcEGmVraFMjwAAA0k"]
[Tue Jul 21 07:39:55.741963 2026] [security2:error] [pid 254995:tid 255262] [client 152.59.154.239:63958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Me_7v0rlcEGmVraFMkgAAA4w"]
[Tue Jul 21 07:39:55.746545 2026] [security2:error] [pid 254995:tid 255262] [client 152.59.154.239:63958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Me_7v0rlcEGmVraFMkgAAA4w"]
[Tue Jul 21 07:39:55.814049 2026] [security2:error] [pid 255769:tid 255949] [client 74.7.230.0:51746] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "app.institutocrismonteiro.com.br"] [uri "/index.php"] [unique_id "al9Me7xMYwyVGnfuwsKqkgAD1Uo"]
[Tue Jul 21 07:39:55.850769 2026] [security2:error] [pid 255769:tid 255910] [client 136.144.33.98:36303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Me7xMYwyVGnfuwsKqmQAAA64"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:56.136398 2026] [security2:error] [pid 255769:tid 256017] [client 20.226.60.151:56195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/acp.php"] [unique_id "al9MfLxMYwyVGnfuwsKqvAAABBc"]
[Tue Jul 21 07:39:56.136994 2026] [autoindex:error] [pid 254995:tid 255140] [client 100.50.152.193:5603] AH01276: Cannot serve directory /home2/tropi058/loja.tropicaliaeyewear.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:56.205562 2026] [security2:error] [pid 255769:tid 255903] [client 103.86.117.203:61431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MfLxMYwyVGnfuwsKqxAAAA6c"]
[Tue Jul 21 07:39:56.205704 2026] [security2:error] [pid 255769:tid 255903] [client 103.86.117.203:61431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MfLxMYwyVGnfuwsKqxAAAA6c"]
[Tue Jul 21 07:39:56.380484 2026] [security2:error] [pid 255769:tid 255971] [client 20.151.10.161:53588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/w3lls.php"] [unique_id "al9MfLxMYwyVGnfuwsKqyQAAA-s"]
[Tue Jul 21 07:39:56.412061 2026] [security2:error] [pid 255769:tid 255936] [client 20.151.10.161:45889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/pol.php"] [unique_id "al9MfLxMYwyVGnfuwsKqygAAA8g"]
[Tue Jul 21 07:39:56.478134 2026] [security2:error] [pid 255769:tid 255990] [client 124.222.194.8:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "marmorariasolare.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9Me7xMYwyVGnfuwsKqggAAA_4"]
[Tue Jul 21 07:39:56.543291 2026] [security2:error] [pid 255769:tid 255990] [client 124.222.194.8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "marmorariasolare.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9Me7xMYwyVGnfuwsKqggAAA_4"]
[Tue Jul 21 07:39:56.812993 2026] [security2:error] [pid 255769:tid 255999] [client 20.197.195.24:13098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/8.php"] [unique_id "al9MfLxMYwyVGnfuwsKqzwAABAU"]
[Tue Jul 21 07:39:56.816377 2026] [security2:error] [pid 254995:tid 255127] [client 20.151.10.161:53625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-ws68.php"] [unique_id "al9MfP7v0rlcEGmVraFMowAAAyA"]
[Tue Jul 21 07:39:56.904341 2026] [security2:error] [pid 255769:tid 255938] [client 20.226.60.151:23115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/media.php"] [unique_id "al9MfLxMYwyVGnfuwsKq0QAAA8o"]
[Tue Jul 21 07:39:57.013524 2026] [security2:error] [pid 255769:tid 255902] [client 4.204.201.85:3532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MfbxMYwyVGnfuwsKq1QAAA6Y"]
[Tue Jul 21 07:39:57.038399 2026] [security2:error] [pid 255769:tid 255960] [client 20.226.60.151:56279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/mosty.php"] [unique_id "al9MfbxMYwyVGnfuwsKq1gAAA-A"]
[Tue Jul 21 07:39:57.128776 2026] [security2:error] [pid 255769:tid 255939] [client 37.140.223.118:20769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MfLxMYwyVGnfuwsKq0gAAA8s"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:39:57.132475 2026] [security2:error] [pid 255769:tid 256012] [client 20.151.10.161:12077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xyn.php"] [unique_id "al9MfbxMYwyVGnfuwsKq2AAABBI"]
[Tue Jul 21 07:39:57.430757 2026] [security2:error] [pid 255769:tid 255978] [client 59.96.220.140:49983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MfbxMYwyVGnfuwsKq3wAAA_I"]
[Tue Jul 21 07:39:57.432316 2026] [security2:error] [pid 255769:tid 255978] [client 59.96.220.140:49983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MfbxMYwyVGnfuwsKq3wAAA_I"]
[Tue Jul 21 07:39:57.509490 2026] [security2:error] [pid 255769:tid 255974] [client 20.151.10.161:53586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/green3.php"] [unique_id "al9MfbxMYwyVGnfuwsKq4QAAA-4"]
[Tue Jul 21 07:39:57.956720 2026] [security2:error] [pid 255769:tid 255949] [client 103.174.34.15:49353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MfbxMYwyVGnfuwsKq6gAAA9U"]
[Tue Jul 21 07:39:57.956840 2026] [security2:error] [pid 255769:tid 255949] [client 103.174.34.15:49353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MfbxMYwyVGnfuwsKq6gAAA9U"]
[Tue Jul 21 07:39:57.976021 2026] [security2:error] [pid 255769:tid 256020] [client 20.151.10.161:53595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ccs.php"] [unique_id "al9MfbxMYwyVGnfuwsKq6wAABBo"]
[Tue Jul 21 07:39:58.210362 2026] [security2:error] [pid 255769:tid 255992] [client 20.220.225.223:19693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/track.php"] [unique_id "al9MfrxMYwyVGnfuwsKq8AAAA_8"]
[Tue Jul 21 07:39:58.264738 2026] [security2:error] [pid 255769:tid 255816] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MfrxMYwyVGnfuwsKq8QADry4"]
[Tue Jul 21 07:39:58.264925 2026] [security2:error] [pid 255769:tid 255911] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MfrxMYwyVGnfuwsKq8QADry4"]
[Tue Jul 21 07:39:58.280567 2026] [security2:error] [pid 255769:tid 255903] [client 20.151.10.161:45937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file5.php"] [unique_id "al9MfrxMYwyVGnfuwsKq8wAAA6c"]
[Tue Jul 21 07:39:58.285896 2026] [security2:error] [pid 255769:tid 256015] [client 122.164.127.47:62161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MfrxMYwyVGnfuwsKq9AAABBU"]
[Tue Jul 21 07:39:58.286012 2026] [security2:error] [pid 255769:tid 256015] [client 122.164.127.47:62161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MfrxMYwyVGnfuwsKq9AAABBU"]
[Tue Jul 21 07:39:58.523675 2026] [security2:error] [pid 254995:tid 255182] [client 4.204.201.85:7451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/media.php"] [unique_id "al9Mfv7v0rlcEGmVraFMvAAAA1c"]
[Tue Jul 21 07:39:58.702638 2026] [security2:error] [pid 254995:tid 255209] [client 20.226.60.151:22927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/images.php"] [unique_id "al9Mfv7v0rlcEGmVraFMvgAAA3E"]
[Tue Jul 21 07:39:58.977380 2026] [security2:error] [pid 255769:tid 256006] [client 117.217.38.194:58896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MfrxMYwyVGnfuwsKq-QAABAw"]
[Tue Jul 21 07:39:58.977634 2026] [security2:error] [pid 255769:tid 256006] [client 117.217.38.194:58896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MfrxMYwyVGnfuwsKq-QAABAw"]
[Tue Jul 21 07:39:59.109055 2026] [security2:error] [pid 255769:tid 255936] [client 122.179.91.63:18461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Mf7xMYwyVGnfuwsKq_AAAA8g"]
[Tue Jul 21 07:39:59.109190 2026] [security2:error] [pid 255769:tid 255936] [client 122.179.91.63:18461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Mf7xMYwyVGnfuwsKq_AAAA8g"]
[Tue Jul 21 07:39:59.130713 2026] [security2:error] [pid 254995:tid 255181] [client 20.220.225.223:34296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/pn.php"] [unique_id "al9Mf_7v0rlcEGmVraFMxgAAA1Y"]
[Tue Jul 21 07:39:59.287546 2026] [security2:error] [pid 255769:tid 255963] [client 20.226.60.151:23107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/gecko.php"] [unique_id "al9Mf7xMYwyVGnfuwsKq_gAAA-M"]
[Tue Jul 21 07:39:59.377656 2026] [security2:error] [pid 254995:tid 255187] [client 74.7.228.47:47172] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pedido-online.net"] [uri "/index.php"] [unique_id "al9Mfv7v0rlcEGmVraFMvwADXDE"]
[Tue Jul 21 07:39:59.385502 2026] [security2:error] [pid 255769:tid 255781] [remote 66.249.74.164:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "nerdshoppe.com.br"] [uri "/robots.txt"] [unique_id "al9Mf7xMYwyVGnfuwsKrBAAEFAs"]
[Tue Jul 21 07:39:59.527446 2026] [security2:error] [pid 254995:tid 255212] [client 20.226.60.151:22931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/82.php"] [unique_id "al9Mf_7v0rlcEGmVraFMzAAAA3Q"]
[Tue Jul 21 07:39:59.580419 2026] [security2:error] [pid 254995:tid 255129] [client 20.226.60.151:56285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/6.php"] [unique_id "al9Mf_7v0rlcEGmVraFMzQAAAyI"]
[Tue Jul 21 07:39:59.704442 2026] [security2:error] [pid 255769:tid 255941] [client 20.226.60.151:23136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/admin.php"] [unique_id "al9Mf7xMYwyVGnfuwsKrDAAAA80"]
[Tue Jul 21 07:39:59.758075 2026] [security2:error] [pid 255769:tid 255954] [client 136.144.33.109:55045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Mf7xMYwyVGnfuwsKrDQAAA9o"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:59.781546 2026] [security2:error] [pid 254995:tid 255170] [client 20.197.195.24:13133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/wp-content/admin.php"] [unique_id "al9Mf_7v0rlcEGmVraFMzwAAA0s"]
[Tue Jul 21 07:39:59.846409 2026] [security2:error] [pid 255769:tid 255791] [remote 66.249.74.165:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "nerdshoppe.com.br"] [uri "/"] [unique_id "al9Mf7xMYwyVGnfuwsKrDgADrRU"]
[Tue Jul 21 07:39:59.974092 2026] [security2:error] [pid 255769:tid 255972] [client 20.226.60.151:23126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/adminner.php"] [unique_id "al9Mf7xMYwyVGnfuwsKrFQAAA-w"]
[Tue Jul 21 07:39:59.985586 2026] [security2:error] [pid 254995:tid 255200] [client 139.167.225.182:56540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mf_7v0rlcEGmVraFM0wAAA2k"]
[Tue Jul 21 07:39:59.987402 2026] [security2:error] [pid 254995:tid 255200] [client 139.167.225.182:56540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mf_7v0rlcEGmVraFM0wAAA2k"]
[Tue Jul 21 07:40:00.149351 2026] [security2:error] [pid 255769:tid 255992] [client 4.204.201.85:3548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/images.php"] [unique_id "al9MgLxMYwyVGnfuwsKrFgAAA_8"]
[Tue Jul 21 07:40:00.627715 2026] [security2:error] [pid 254995:tid 255126] [client 37.140.223.49:37861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MgP7v0rlcEGmVraFM3wAAAx8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:40:00.930849 2026] [security2:error] [pid 255769:tid 255959] [client 20.151.10.161:53630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ccc.php"] [unique_id "al9MgLxMYwyVGnfuwsKrHgAAA98"]
[Tue Jul 21 07:40:00.961187 2026] [security2:error] [pid 254995:tid 255012] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MgP7v0rlcEGmVraFM5QADQhA"]
[Tue Jul 21 07:40:00.961378 2026] [security2:error] [pid 254995:tid 255161] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MgP7v0rlcEGmVraFM5QADQhA"]
[Tue Jul 21 07:40:01.163977 2026] [security2:error] [pid 255769:tid 255938] [client 173.24.185.52:63490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MgbxMYwyVGnfuwsKrIgAAA8o"]
[Tue Jul 21 07:40:01.164107 2026] [security2:error] [pid 255769:tid 255938] [client 173.24.185.52:63490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MgbxMYwyVGnfuwsKrIgAAA8o"]
[Tue Jul 21 07:40:01.243655 2026] [security2:error] [pid 254995:tid 255075] [remote 210.211.125.205:45456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.125.211.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moneyclass.com.br"] [uri "/wp-login.php"] [unique_id "al9Mgf7v0rlcEGmVraFM7QADjk8"]
[Tue Jul 21 07:40:01.276071 2026] [security2:error] [pid 255769:tid 255980] [client 184.75.223.211:35376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9MgbxMYwyVGnfuwsKrJQAAA_Q"]
[Tue Jul 21 07:40:01.276161 2026] [security2:error] [pid 255769:tid 255980] [client 184.75.223.211:35376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9MgbxMYwyVGnfuwsKrJQAAA_Q"]
[Tue Jul 21 07:40:01.312115 2026] [security2:error] [pid 255769:tid 256006] [client 106.215.181.8:28771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MgbxMYwyVGnfuwsKrJgAABAw"]
[Tue Jul 21 07:40:01.312229 2026] [security2:error] [pid 255769:tid 256006] [client 106.215.181.8:28771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MgbxMYwyVGnfuwsKrJgAABAw"]
[Tue Jul 21 07:40:01.512404 2026] [security2:error] [pid 254995:tid 255199] [client 4.204.201.85:7484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/gecko.php"] [unique_id "al9Mgf7v0rlcEGmVraFM8QAAA2g"]
[Tue Jul 21 07:40:01.646053 2026] [security2:error] [pid 255769:tid 255916] [client 20.151.10.161:53591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/get.php"] [unique_id "al9MgbxMYwyVGnfuwsKrLwAAA7Q"]
[Tue Jul 21 07:40:01.735131 2026] [security2:error] [pid 254995:tid 255132] [client 20.220.225.223:19661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/2352356666.php"] [unique_id "al9Mgf7v0rlcEGmVraFM9QAAAyU"]
[Tue Jul 21 07:40:01.800302 2026] [security2:error] [pid 255769:tid 256001] [client 20.226.60.151:22912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/admin.php"] [unique_id "al9MgbxMYwyVGnfuwsKrMwAABAc"]
[Tue Jul 21 07:40:02.257066 2026] [security2:error] [pid 254995:tid 255175] [client 4.204.201.85:7424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/82.php"] [unique_id "al9Mgv7v0rlcEGmVraFM_wAAA1A"]
[Tue Jul 21 07:40:02.300609 2026] [autoindex:error] [pid 254995:tid 255151] [client 100.50.152.193:22733] AH01276: Cannot serve directory /home2/acupu265/liranesuliano.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:02.341594 2026] [security2:error] [pid 254995:tid 255173] [client 20.151.10.161:55270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/images.php"] [unique_id "al9Mgv7v0rlcEGmVraFNAQAAA04"]
[Tue Jul 21 07:40:02.367488 2026] [security2:error] [pid 255769:tid 255839] [remote 97.74.93.24:44952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "essenceclinicadesaude.com.br"] [uri "/wp-login.php"] [unique_id "al9MgrxMYwyVGnfuwsKrNwAD7EU"]
[Tue Jul 21 07:40:02.543793 2026] [security2:error] [pid 255769:tid 255946] [client 20.226.60.151:23141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/k.php"] [unique_id "al9MgrxMYwyVGnfuwsKrPwAAA9I"]
[Tue Jul 21 07:40:02.797963 2026] [security2:error] [pid 255769:tid 255939] [client 20.151.10.161:53624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/alls.php"] [unique_id "al9MgrxMYwyVGnfuwsKrRgAAA8s"]
[Tue Jul 21 07:40:03.069934 2026] [security2:error] [pid 255769:tid 256003] [client 20.151.10.161:45949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrSAAABAk"]
[Tue Jul 21 07:40:03.137319 2026] [security2:error] [pid 255769:tid 255903] [client 122.186.204.214:64924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrSgAAA6c"]
[Tue Jul 21 07:40:03.137459 2026] [security2:error] [pid 255769:tid 255903] [client 122.186.204.214:64924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrSgAAA6c"]
[Tue Jul 21 07:40:03.141619 2026] [security2:error] [pid 254995:tid 255152] [client 117.251.86.144:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Mg_7v0rlcEGmVraFNDAAAAzk"]
[Tue Jul 21 07:40:03.141728 2026] [security2:error] [pid 254995:tid 255152] [client 117.251.86.144:60312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Mg_7v0rlcEGmVraFNDAAAAzk"]
[Tue Jul 21 07:40:03.257749 2026] [security2:error] [pid 255769:tid 255978] [client 4.204.201.85:46028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/admin.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrTgAAA_I"]
[Tue Jul 21 07:40:03.297361 2026] [security2:error] [pid 255769:tid 255998] [client 20.226.60.151:23112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/blurbs.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrTwAABAQ"]
[Tue Jul 21 07:40:03.332217 2026] [security2:error] [pid 254995:tid 255211] [client 20.151.10.161:53606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/yyu.php"] [unique_id "al9Mg_7v0rlcEGmVraFNEwAAA3M"]
[Tue Jul 21 07:40:03.492221 2026] [security2:error] [pid 255769:tid 255872] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrVAADvGY"]
[Tue Jul 21 07:40:03.492359 2026] [security2:error] [pid 255769:tid 255924] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrVAADvGY"]
[Tue Jul 21 07:40:03.494621 2026] [security2:error] [pid 254995:tid 255179] [client 172.245.102.46:42427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Mg_7v0rlcEGmVraFNEQAAA1Q"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:03.545870 2026] [security2:error] [pid 255769:tid 255923] [client 193.36.225.151:48713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrUAAAA7s"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:40:03.561846 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.561883 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.562446 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Globo-2.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.575052 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.575080 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.575287 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/IstoE.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.588540 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.588548 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.588766 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Terra.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.601061 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.601080 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.601296 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Caras.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.613230 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.613240 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.613462 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Contigo.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.624633 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.624645 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.624860 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Bons-Fluidos.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.637316 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.637330 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.637609 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Boa-Forma.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.649169 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.649192 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.649385 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Globo-2.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.649433 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.649441 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.649712 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Lance.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.661369 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.661380 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.661637 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/IstoE.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.665467 2026] [security2:error] [pid 255769:tid 255954] [client 20.226.60.151:23119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/bajah.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrVgAAA9o"]
[Tue Jul 21 07:40:03.673425 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.673442 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.673629 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Terra.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.685315 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.685331 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.685552 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Caras.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.697537 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.697559 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.697941 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Contigo.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.711712 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.711741 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.712606 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Bons-Fluidos.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.725277 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.725297 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.726028 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Boa-Forma.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.736834 2026] [security2:error] [pid 255769:tid 255916] [client 20.220.225.223:34198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrWwAAA7Q"]
[Tue Jul 21 07:40:03.738923 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.738940 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.739312 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning: getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Lance.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.845595 2026] [security2:error] [pid 255769:tid 255935] [client 4.204.201.85:7444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/adminner.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrXQAAA8c"]
[Tue Jul 21 07:40:03.855370 2026] [security2:error] [pid 255769:tid 255929] [client 20.151.10.161:53590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/by.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrXgAAA8E"]
[Tue Jul 21 07:40:03.932495 2026] [security2:error] [pid 255769:tid 255964] [client 20.226.60.151:56292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrXwAAA-Q"]
[Tue Jul 21 07:40:04.221961 2026] [security2:error] [pid 255769:tid 255985] [client 184.75.223.211:35386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MhLxMYwyVGnfuwsKrZQAAA_k"]
[Tue Jul 21 07:40:04.222063 2026] [security2:error] [pid 255769:tid 255985] [client 184.75.223.211:35386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MhLxMYwyVGnfuwsKrZQAAA_k"]
[Tue Jul 21 07:40:04.265215 2026] [security2:error] [pid 254995:tid 255144] [client 20.226.60.151:22920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/a.php"] [unique_id "al9MhP7v0rlcEGmVraFNIQAAAzE"]
[Tue Jul 21 07:40:04.269550 2026] [security2:error] [pid 255769:tid 255972] [client 20.151.10.161:53617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/FAQ.php"] [unique_id "al9MhLxMYwyVGnfuwsKrZwAAA-w"]
[Tue Jul 21 07:40:04.287518 2026] [security2:error] [pid 254995:tid 255224] [client 4.204.201.85:7425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/admin.php"] [unique_id "al9MhP7v0rlcEGmVraFNIgAAA4A"]
[Tue Jul 21 07:40:04.584614 2026] [security2:error] [pid 254995:tid 255161] [client 20.226.60.151:23142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/edit.php"] [unique_id "al9MhP7v0rlcEGmVraFNJAAAA0I"]
[Tue Jul 21 07:40:04.611343 2026] [security2:error] [pid 254995:tid 255269] [client 4.204.201.85:3545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/k.php"] [unique_id "al9MhP7v0rlcEGmVraFNJQAAA5M"]
[Tue Jul 21 07:40:04.670010 2026] [security2:error] [pid 255769:tid 255885] [remote 41.186.86.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9MhLxMYwyVGnfuwsKrbwAD0nM"]
[Tue Jul 21 07:40:04.670184 2026] [security2:error] [pid 255769:tid 255946] [client 41.186.86.12:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9MhLxMYwyVGnfuwsKrbwAD0nM"]
[Tue Jul 21 07:40:04.767149 2026] [security2:error] [pid 255769:tid 255858] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MhLxMYwyVGnfuwsKrcQAD41g"]
[Tue Jul 21 07:40:04.767332 2026] [security2:error] [pid 255769:tid 255963] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MhLxMYwyVGnfuwsKrcQAD41g"]
[Tue Jul 21 07:40:04.829970 2026] [security2:error] [pid 254995:tid 255176] [client 20.226.60.151:23134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/hosty.php"] [unique_id "al9MhP7v0rlcEGmVraFNLAAAA1E"]
[Tue Jul 21 07:40:04.952608 2026] [security2:error] [pid 255769:tid 255912] [client 4.204.201.85:7429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/blurbs.php"] [unique_id "al9MhLxMYwyVGnfuwsKrcwAAA7A"]
[Tue Jul 21 07:40:04.954944 2026] [security2:error] [pid 255769:tid 255939] [client 173.252.95.58:40688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9MhLxMYwyVGnfuwsKrdAAAA8s"]
[Tue Jul 21 07:40:05.023613 2026] [security2:error] [pid 255769:tid 255973] [client 20.151.10.161:55232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/coffexium.php"] [unique_id "al9MhbxMYwyVGnfuwsKrdQAAA-0"]
[Tue Jul 21 07:40:05.072723 2026] [security2:error] [pid 255769:tid 255903] [client 20.226.60.151:23138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/k.php"] [unique_id "al9MhbxMYwyVGnfuwsKrdgAAA6c"]
[Tue Jul 21 07:40:05.329233 2026] [security2:error] [pid 254995:tid 255072] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Mhf7v0rlcEGmVraFNMQADZ0w"]
[Tue Jul 21 07:40:05.329378 2026] [security2:error] [pid 254995:tid 255198] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Mhf7v0rlcEGmVraFNMQADZ0w"]
[Tue Jul 21 07:40:05.415272 2026] [security2:error] [pid 255769:tid 255927] [client 4.204.201.85:46031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/bajah.php"] [unique_id "al9MhbxMYwyVGnfuwsKrfwAAA78"]
[Tue Jul 21 07:40:05.526789 2026] [security2:error] [pid 254995:tid 255121] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mhf7v0rlcEGmVraFNNAADYH0"]
[Tue Jul 21 07:40:05.526911 2026] [security2:error] [pid 254995:tid 255191] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mhf7v0rlcEGmVraFNNAADYH0"]
[Tue Jul 21 07:40:05.550926 2026] [security2:error] [pid 254995:tid 255133] [client 20.151.10.161:55253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/red.php"] [unique_id "al9Mhf7v0rlcEGmVraFNNwAAAyY"]
[Tue Jul 21 07:40:05.620500 2026] [security2:error] [pid 255769:tid 255990] [client 20.197.195.24:48871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/f6.php"] [unique_id "al9MhbxMYwyVGnfuwsKrxAAAA_4"]
[Tue Jul 21 07:40:05.643181 2026] [security2:error] [pid 255769:tid 255891] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MhbxMYwyVGnfuwsKryAADtnk"]
[Tue Jul 21 07:40:05.643309 2026] [security2:error] [pid 255769:tid 255918] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MhbxMYwyVGnfuwsKryAADtnk"]
[Tue Jul 21 07:40:05.694927 2026] [security2:error] [pid 255769:tid 255913] [client 20.226.60.151:23122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/aaa.php"] [unique_id "al9MhbxMYwyVGnfuwsKrygAAA7E"]
[Tue Jul 21 07:40:05.780026 2026] [security2:error] [pid 255769:tid 255922] [client 4.204.201.85:3539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/a.php"] [unique_id "al9MhbxMYwyVGnfuwsKrzAAAA7o"]
[Tue Jul 21 07:40:05.901494 2026] [security2:error] [pid 255769:tid 255921] [client 175.45.70.82:53774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MhbxMYwyVGnfuwsKr0AAAA7k"]
[Tue Jul 21 07:40:05.901587 2026] [security2:error] [pid 255769:tid 255921] [client 175.45.70.82:53774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MhbxMYwyVGnfuwsKr0AAAA7k"]
[Tue Jul 21 07:40:06.168486 2026] [security2:error] [pid 255769:tid 255949] [client 4.204.201.85:7450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/edit.php"] [unique_id "al9MhrxMYwyVGnfuwsKsEAAAA9U"]
[Tue Jul 21 07:40:06.184122 2026] [security2:error] [pid 255769:tid 255989] [client 103.106.20.201:60505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MhrxMYwyVGnfuwsKsEQAAA_0"]
[Tue Jul 21 07:40:06.184295 2026] [security2:error] [pid 255769:tid 255989] [client 103.106.20.201:60505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MhrxMYwyVGnfuwsKsEQAAA_0"]
[Tue Jul 21 07:40:06.257105 2026] [security2:error] [pid 255769:tid 256027] [client 154.192.233.199:60032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MhrxMYwyVGnfuwsKsEwAABCE"]
[Tue Jul 21 07:40:06.257232 2026] [security2:error] [pid 255769:tid 256027] [client 154.192.233.199:60032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MhrxMYwyVGnfuwsKsEwAABCE"]
[Tue Jul 21 07:40:06.299762 2026] [security2:error] [pid 255769:tid 255988] [client 20.151.10.161:55236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9MhrxMYwyVGnfuwsKsFQAAA_w"]
[Tue Jul 21 07:40:06.300254 2026] [security2:error] [pid 254995:tid 255259] [client 122.162.144.145:31630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Mhv7v0rlcEGmVraFNRwAAA4k"]
[Tue Jul 21 07:40:06.300363 2026] [security2:error] [pid 254995:tid 255259] [client 122.162.144.145:31630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Mhv7v0rlcEGmVraFNRwAAA4k"]
[Tue Jul 21 07:40:06.311319 2026] [security2:error] [pid 255769:tid 255983] [client 20.226.60.151:23167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/file5.php"] [unique_id "al9MhrxMYwyVGnfuwsKsFgAAA_c"]
[Tue Jul 21 07:40:06.680068 2026] [security2:error] [pid 254995:tid 255216] [client 103.86.117.203:61956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mhv7v0rlcEGmVraFNTQAAA3g"]
[Tue Jul 21 07:40:06.680210 2026] [security2:error] [pid 254995:tid 255216] [client 103.86.117.203:61956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mhv7v0rlcEGmVraFNTQAAA3g"]
[Tue Jul 21 07:40:06.779047 2026] [security2:error] [pid 255769:tid 255912] [client 184.75.223.211:35394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MhrxMYwyVGnfuwsKsHQAAA7A"]
[Tue Jul 21 07:40:06.779166 2026] [security2:error] [pid 255769:tid 255912] [client 184.75.223.211:35394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MhrxMYwyVGnfuwsKsHQAAA7A"]
[Tue Jul 21 07:40:07.041351 2026] [security2:error] [pid 255769:tid 255967] [client 20.151.10.161:55247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/footer.php"] [unique_id "al9Mh7xMYwyVGnfuwsKsJgAAA-c"]
[Tue Jul 21 07:40:07.108108 2026] [security2:error] [pid 255769:tid 255927] [client 152.59.154.239:64422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mh7xMYwyVGnfuwsKsJwAAA78"]
[Tue Jul 21 07:40:07.108208 2026] [security2:error] [pid 255769:tid 255927] [client 152.59.154.239:64422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mh7xMYwyVGnfuwsKsJwAAA78"]
[Tue Jul 21 07:40:07.109589 2026] [security2:error] [pid 254995:tid 255254] [client 4.204.201.85:3542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/hosty.php"] [unique_id "al9Mh_7v0rlcEGmVraFNVQAAA4Q"]
[Tue Jul 21 07:40:07.164725 2026] [security2:error] [pid 255769:tid 255986] [client 20.226.60.151:56316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/qqqa.php"] [unique_id "al9Mh7xMYwyVGnfuwsKsKAAAA_o"]
[Tue Jul 21 07:40:07.671732 2026] [security2:error] [pid 254995:tid 255161] [client 20.151.10.161:55234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-content/index.php"] [unique_id "al9Mh_7v0rlcEGmVraFNXAAAA0I"]
[Tue Jul 21 07:40:07.712984 2026] [security2:error] [pid 255769:tid 255998] [client 4.204.201.85:3524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/k.php"] [unique_id "al9Mh7xMYwyVGnfuwsKsMQAABAQ"]
[Tue Jul 21 07:40:07.910539 2026] [security2:error] [pid 255769:tid 255977] [client 122.164.127.47:63153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Mh7xMYwyVGnfuwsKsNQAAA_E"]
[Tue Jul 21 07:40:07.910677 2026] [security2:error] [pid 255769:tid 255977] [client 122.164.127.47:63153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Mh7xMYwyVGnfuwsKsNQAAA_E"]
[Tue Jul 21 07:40:07.943327 2026] [security2:error] [pid 255769:tid 255929] [client 20.226.60.151:22930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/222.php"] [unique_id "al9Mh7xMYwyVGnfuwsKsNgAAA8E"]
[Tue Jul 21 07:40:08.042062 2026] [security2:error] [pid 255769:tid 256009] [client 20.151.10.161:45950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file.php"] [unique_id "al9MiLxMYwyVGnfuwsKsOgAABA8"]
[Tue Jul 21 07:40:08.063822 2026] [security2:error] [pid 255769:tid 256005] [client 20.220.225.223:34210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/dr.php"] [unique_id "al9MiLxMYwyVGnfuwsKsOwAABAs"]
[Tue Jul 21 07:40:08.072217 2026] [security2:error] [pid 254995:tid 255197] [client 193.36.225.73:23425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MiP7v0rlcEGmVraFNYwAAA2Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:08.135747 2026] [security2:error] [pid 254995:tid 255229] [client 20.151.10.161:55239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/zoro.php"] [unique_id "al9MiP7v0rlcEGmVraFNZAAAA4I"]
[Tue Jul 21 07:40:08.198931 2026] [security2:error] [pid 255769:tid 255923] [client 59.96.220.140:50537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MiLxMYwyVGnfuwsKsPwAAA7s"]
[Tue Jul 21 07:40:08.199608 2026] [security2:error] [pid 255769:tid 255923] [client 59.96.220.140:50537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MiLxMYwyVGnfuwsKsPwAAA7s"]
[Tue Jul 21 07:40:08.577361 2026] [security2:error] [pid 255769:tid 255914] [client 4.204.201.85:3540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/aaa.php"] [unique_id "al9MiLxMYwyVGnfuwsKsRQAAA7I"]
[Tue Jul 21 07:40:08.616837 2026] [security2:error] [pid 254995:tid 255199] [client 62.102.148.187:44202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MiP7v0rlcEGmVraFNbQAAA2g"]
[Tue Jul 21 07:40:08.616931 2026] [security2:error] [pid 254995:tid 255199] [client 62.102.148.187:44202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MiP7v0rlcEGmVraFNbQAAA2g"]
[Tue Jul 21 07:40:08.642355 2026] [security2:error] [pid 254995:tid 255185] [client 20.151.10.161:53611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/admin.php"] [unique_id "al9MiP7v0rlcEGmVraFNbgAAA1o"]
[Tue Jul 21 07:40:08.689062 2026] [security2:error] [pid 254995:tid 255198] [client 20.151.10.161:45958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/cfile.php"] [unique_id "al9MiP7v0rlcEGmVraFNcAAAA2c"]
[Tue Jul 21 07:40:08.856085 2026] [security2:error] [pid 254995:tid 255203] [client 103.174.34.15:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MiP7v0rlcEGmVraFNdAAAA2w"]
[Tue Jul 21 07:40:08.856231 2026] [security2:error] [pid 254995:tid 255203] [client 103.174.34.15:49848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MiP7v0rlcEGmVraFNdAAAA2w"]
[Tue Jul 21 07:40:08.961253 2026] [security2:error] [pid 254995:tid 255087] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MiP7v0rlcEGmVraFNeAADfFs"]
[Tue Jul 21 07:40:08.961435 2026] [security2:error] [pid 254995:tid 255220] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MiP7v0rlcEGmVraFNeAADfFs"]
[Tue Jul 21 07:40:09.235570 2026] [security2:error] [pid 255769:tid 256003] [client 20.151.10.161:53597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/greap.php"] [unique_id "al9MibxMYwyVGnfuwsKsUAAABAk"]
[Tue Jul 21 07:40:09.461397 2026] [security2:error] [pid 255769:tid 255918] [client 117.217.38.194:59369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MibxMYwyVGnfuwsKsUwAAA7Y"]
[Tue Jul 21 07:40:09.461516 2026] [security2:error] [pid 255769:tid 255918] [client 117.217.38.194:59369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MibxMYwyVGnfuwsKsUwAAA7Y"]
[Tue Jul 21 07:40:09.544342 2026] [security2:error] [pid 255769:tid 255798] [remote 217.181.92.1:54319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.92.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9MibxMYwyVGnfuwsKsVwAD1xw"]
[Tue Jul 21 07:40:09.660139 2026] [security2:error] [pid 255769:tid 256028] [client 141.11.107.74:61584] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "autodiscover.rinettoar.com.br"] [uri "/"] [unique_id "al9MibxMYwyVGnfuwsKsWgAABCI"]
[Tue Jul 21 07:40:09.668671 2026] [security2:error] [pid 254995:tid 255173] [client 141.11.107.74:61587] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcontacts.rinettoar.com.br"] [uri "/___proxy_subdomain_cpcontacts/"] [unique_id "al9Mif7v0rlcEGmVraFNfgAAA04"]
[Tue Jul 21 07:40:09.674898 2026] [security2:error] [pid 255769:tid 256010] [client 141.11.107.74:61590] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.rinettoar.com.br"] [uri "/___proxy_subdomain_webdisk/"] [unique_id "al9MibxMYwyVGnfuwsKsWwAABBA"]
[Tue Jul 21 07:40:09.676768 2026] [security2:error] [pid 255769:tid 255978] [client 141.11.107.74:61592] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.rinettoar.com.br"] [uri "/___proxy_subdomain_webmail/"] [unique_id "al9MibxMYwyVGnfuwsKsXAAAA_I"]
[Tue Jul 21 07:40:09.677555 2026] [security2:error] [pid 255769:tid 255907] [client 141.11.107.74:61589] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.rinettoar.com.br"] [uri "/"] [unique_id "al9MibxMYwyVGnfuwsKsXQAAA6s"]
[Tue Jul 21 07:40:09.678437 2026] [security2:error] [pid 255769:tid 255900] [client 141.11.107.74:61593] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "rinettoar.com.br"] [uri "/"] [unique_id "al9MibxMYwyVGnfuwsKsXgAAA6Q"]
[Tue Jul 21 07:40:09.686706 2026] [security2:error] [pid 254995:tid 255166] [client 141.11.107.74:61595] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.rinettoar.com.br"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "al9Mif7v0rlcEGmVraFNfwAAA0c"]
[Tue Jul 21 07:40:09.690833 2026] [security2:error] [pid 254995:tid 255187] [client 141.11.107.74:61597] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.rinettoar.com.br"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "al9Mif7v0rlcEGmVraFNgAAAA1w"]
[Tue Jul 21 07:40:09.723042 2026] [security2:error] [pid 255769:tid 255934] [client 20.151.10.161:12078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/177.php"] [unique_id "al9MibxMYwyVGnfuwsKsXwAAA8Y"]
[Tue Jul 21 07:40:09.742538 2026] [security2:error] [pid 255769:tid 255939] [client 122.179.91.63:21028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MibxMYwyVGnfuwsKsYAAAA8s"]
[Tue Jul 21 07:40:09.742639 2026] [security2:error] [pid 255769:tid 255939] [client 122.179.91.63:21028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MibxMYwyVGnfuwsKsYAAAA8s"]
[Tue Jul 21 07:40:09.821948 2026] [security2:error] [pid 255769:tid 255937] [client 4.204.201.85:7472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/file5.php"] [unique_id "al9MibxMYwyVGnfuwsKsYgAAA8k"]
[Tue Jul 21 07:40:09.838282 2026] [security2:error] [pid 255769:tid 256018] [client 20.151.10.161:45972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/class-wp.php"] [unique_id "al9MibxMYwyVGnfuwsKsYwAABBg"]
[Tue Jul 21 07:40:10.462147 2026] [security2:error] [pid 255769:tid 256021] [client 139.167.225.182:57205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MirxMYwyVGnfuwsKscAAABBs"]
[Tue Jul 21 07:40:10.462243 2026] [security2:error] [pid 255769:tid 256021] [client 139.167.225.182:57205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MirxMYwyVGnfuwsKscAAABBs"]
[Tue Jul 21 07:40:10.492304 2026] [security2:error] [pid 254995:tid 255196] [client 20.226.60.151:56248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/aunmc.php"] [unique_id "al9Miv7v0rlcEGmVraFNjAAAA2U"]
[Tue Jul 21 07:40:10.501181 2026] [security2:error] [pid 254995:tid 255140] [client 20.151.10.161:55249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/199.php"] [unique_id "al9Miv7v0rlcEGmVraFNjQAAAy0"]
[Tue Jul 21 07:40:10.590545 2026] [security2:error] [pid 254995:tid 255262] [client 4.204.201.85:7464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/222.php"] [unique_id "al9Miv7v0rlcEGmVraFNkAAAA4w"]
[Tue Jul 21 07:40:10.601580 2026] [autoindex:error] [pid 254995:tid 255274] [client 34.76.247.13:58355] AH01276: Cannot serve directory /home2/werley42/impactoensino.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:10.640961 2026] [security2:error] [pid 254995:tid 255271] [client 20.151.10.161:45996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/admin.php"] [unique_id "al9Miv7v0rlcEGmVraFNkgAAA5U"]
[Tue Jul 21 07:40:11.092277 2026] [security2:error] [pid 254995:tid 255254] [client 4.204.201.85:7441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/test.php"] [unique_id "al9Mi_7v0rlcEGmVraFNlgAAA4Q"]
[Tue Jul 21 07:40:11.156440 2026] [security2:error] [pid 254995:tid 255174] [client 20.220.225.223:34212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/2x.php"] [unique_id "al9Mi_7v0rlcEGmVraFNmQAAA08"]
[Tue Jul 21 07:40:11.366157 2026] [security2:error] [pid 254995:tid 255146] [client 94.23.188.192:15744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.prismaseg.com"] [uri "/robots.txt"] [unique_id "al9Mi_7v0rlcEGmVraFNnQAAAzM"]
[Tue Jul 21 07:40:11.366305 2026] [security2:error] [pid 254995:tid 255146] [client 94.23.188.192:15744] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.prismaseg.com"] [uri "/robots.txt"] [unique_id "al9Mi_7v0rlcEGmVraFNnQAAAzM"]
[Tue Jul 21 07:40:11.469499 2026] [security2:error] [pid 254995:tid 255189] [client 20.220.225.223:22493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/la.php"] [unique_id "al9Mi_7v0rlcEGmVraFNnwAAA14"]
[Tue Jul 21 07:40:11.545009 2026] [security2:error] [pid 254995:tid 255184] [client 4.204.201.85:7443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/aaa.php"] [unique_id "al9Mi_7v0rlcEGmVraFNogAAA1k"]
[Tue Jul 21 07:40:11.576970 2026] [security2:error] [pid 255769:tid 255945] [client 20.151.10.161:45933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/aa2.php"] [unique_id "al9Mi7xMYwyVGnfuwsKseQAAA9E"]
[Tue Jul 21 07:40:11.692684 2026] [security2:error] [pid 254995:tid 255269] [client 173.24.185.52:63962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Mi_7v0rlcEGmVraFNqgAAA5M"]
[Tue Jul 21 07:40:11.692839 2026] [security2:error] [pid 254995:tid 255269] [client 173.24.185.52:63962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Mi_7v0rlcEGmVraFNqgAAA5M"]
[Tue Jul 21 07:40:11.694334 2026] [security2:error] [pid 254995:tid 255199] [client 20.151.10.161:55291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file52.php"] [unique_id "al9Mi_7v0rlcEGmVraFNqwAAA2g"]
[Tue Jul 21 07:40:11.734252 2026] [security2:error] [pid 254995:tid 255185] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9Mi_7v0rlcEGmVraFNrAAAA1o"]
[Tue Jul 21 07:40:11.777462 2026] [security2:error] [pid 254995:tid 255015] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mi_7v0rlcEGmVraFNrQADdxM"]
[Tue Jul 21 07:40:11.777665 2026] [security2:error] [pid 254995:tid 255215] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mi_7v0rlcEGmVraFNrQADdxM"]
[Tue Jul 21 07:40:11.831571 2026] [security2:error] [pid 254995:tid 255162] [client 62.102.148.187:44206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9Mi_7v0rlcEGmVraFNrgAAA0M"]
[Tue Jul 21 07:40:11.831657 2026] [security2:error] [pid 254995:tid 255162] [client 62.102.148.187:44206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9Mi_7v0rlcEGmVraFNrgAAA0M"]
[Tue Jul 21 07:40:11.932360 2026] [security2:error] [pid 254995:tid 255177] [client 20.226.60.151:51234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/uoocf.php"] [unique_id "al9Mi_7v0rlcEGmVraFNrwAAA1I"]
[Tue Jul 21 07:40:11.933340 2026] [security2:error] [pid 255769:tid 255849] [remote 66.249.79.137:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sejabarbara.com.br"] [uri "/wp-content/uploads/2018/11/xan-griffin-419098-unsplash-1200x675.jpg"] [unique_id "al9Mi7xMYwyVGnfuwsKsewADrk8"]
[Tue Jul 21 07:40:11.958052 2026] [security2:error] [pid 254995:tid 255203] [client 128.127.105.184:38870] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Mi_7v0rlcEGmVraFNsAAAA2w"]
[Tue Jul 21 07:40:11.958136 2026] [security2:error] [pid 254995:tid 255203] [client 128.127.105.184:38870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Mi_7v0rlcEGmVraFNsAAAA2w"]
[Tue Jul 21 07:40:12.040447 2026] [security2:error] [pid 255769:tid 256013] [client 106.215.181.8:27734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MjLxMYwyVGnfuwsKsfwAABBM"]
[Tue Jul 21 07:40:12.040587 2026] [security2:error] [pid 255769:tid 256013] [client 106.215.181.8:27734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MjLxMYwyVGnfuwsKsfwAABBM"]
[Tue Jul 21 07:40:12.045688 2026] [security2:error] [pid 255769:tid 255901] [client 143.244.57.121:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MjLxMYwyVGnfuwsKsgAAAA6U"]
[Tue Jul 21 07:40:12.077685 2026] [security2:error] [pid 255769:tid 255896] [remote 66.249.79.137:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sejabarbara.com.br"] [uri "/robots.txt"] [unique_id "al9MjLxMYwyVGnfuwsKsgQADtn4"]
[Tue Jul 21 07:40:12.318922 2026] [security2:error] [pid 255769:tid 255924] [client 62.102.148.187:44214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9MjLxMYwyVGnfuwsKshAAAA7w"]
[Tue Jul 21 07:40:12.319058 2026] [security2:error] [pid 255769:tid 255924] [client 62.102.148.187:44214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9MjLxMYwyVGnfuwsKshAAAA7w"]
[Tue Jul 21 07:40:12.351530 2026] [security2:error] [pid 254995:tid 255175] [client 20.151.10.161:45901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ccou.php"] [unique_id "al9MjP7v0rlcEGmVraFNuAAAA1A"]
[Tue Jul 21 07:40:12.451966 2026] [security2:error] [pid 255769:tid 255908] [client 4.204.201.85:7459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/11.php"] [unique_id "al9MjLxMYwyVGnfuwsKsigAAA6w"]
[Tue Jul 21 07:40:12.494546 2026] [security2:error] [pid 255769:tid 255919] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9MjLxMYwyVGnfuwsKsjAAAA7c"]
[Tue Jul 21 07:40:12.610435 2026] [security2:error] [pid 255769:tid 255935] [client 4.204.201.85:61071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MjLxMYwyVGnfuwsKskQAAA8c"]
[Tue Jul 21 07:40:12.777513 2026] [security2:error] [pid 255769:tid 255964] [client 51.222.168.222:34930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.prismaseg.com"] [uri "/"] [unique_id "al9MjLxMYwyVGnfuwsKskwAAA-Q"]
[Tue Jul 21 07:40:12.777618 2026] [security2:error] [pid 255769:tid 255964] [client 51.222.168.222:34930] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.prismaseg.com"] [uri "/"] [unique_id "al9MjLxMYwyVGnfuwsKskwAAA-Q"]
[Tue Jul 21 07:40:12.804386 2026] [security2:error] [pid 254995:tid 255157] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9MjP7v0rlcEGmVraFNvgAAAz4"]
[Tue Jul 21 07:40:12.886146 2026] [security2:error] [pid 254995:tid 255263] [client 4.204.201.85:59962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MjP7v0rlcEGmVraFNwAAAA40"]
[Tue Jul 21 07:40:13.050605 2026] [security2:error] [pid 255769:tid 255952] [client 4.204.201.85:7428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/mac.php"] [unique_id "al9MjbxMYwyVGnfuwsKslQAAA9g"]
[Tue Jul 21 07:40:13.088602 2026] [security2:error] [pid 254995:tid 255273] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9Mjf7v0rlcEGmVraFNxAAAA5c"]
[Tue Jul 21 07:40:13.163328 2026] [security2:error] [pid 254995:tid 255211] [client 4.204.201.85:57441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/x.php"] [unique_id "al9Mjf7v0rlcEGmVraFNyAAAA3M"]
[Tue Jul 21 07:40:13.178054 2026] [security2:error] [pid 255769:tid 255833] [remote 65.111.28.178:49289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9MjbxMYwyVGnfuwsKsmgAD_T8"]
[Tue Jul 21 07:40:13.191332 2026] [security2:error] [pid 255769:tid 255994] [client 20.151.10.161:53603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/122.php"] [unique_id "al9MjbxMYwyVGnfuwsKsmwAABAE"]
[Tue Jul 21 07:40:13.202853 2026] [security2:error] [pid 255769:tid 255990] [client 20.151.10.161:45994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/dr.php"] [unique_id "al9MjbxMYwyVGnfuwsKsnAAAA_4"]
[Tue Jul 21 07:40:13.256955 2026] [security2:error] [pid 254995:tid 255158] [client 193.36.225.151:37565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Mjf7v0rlcEGmVraFNygAAAz8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:40:13.372844 2026] [security2:error] [pid 255769:tid 256015] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9MjbxMYwyVGnfuwsKsnwAABBU"]
[Tue Jul 21 07:40:13.376965 2026] [security2:error] [pid 254995:tid 255262] [client 136.144.33.98:35653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Mjf7v0rlcEGmVraFNywAAA4w"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:13.444150 2026] [security2:error] [pid 255769:tid 255931] [client 4.204.201.85:59941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/mgrr.php"] [unique_id "al9MjbxMYwyVGnfuwsKsoQAAA8M"]
[Tue Jul 21 07:40:13.494584 2026] [security2:error] [pid 254995:tid 255012] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mjf7v0rlcEGmVraFNzgADfxA"]
[Tue Jul 21 07:40:13.494736 2026] [security2:error] [pid 254995:tid 255223] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mjf7v0rlcEGmVraFNzgADfxA"]
[Tue Jul 21 07:40:13.583424 2026] [security2:error] [pid 254995:tid 255258] [client 20.226.60.151:56245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/iywwi.php"] [unique_id "al9Mjf7v0rlcEGmVraFNzwAAA4g"]
[Tue Jul 21 07:40:13.658992 2026] [security2:error] [pid 254995:tid 255210] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9Mjf7v0rlcEGmVraFN0QAAA3I"]
[Tue Jul 21 07:40:13.713113 2026] [security2:error] [pid 255769:tid 255987] [client 122.186.204.214:65451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MjbxMYwyVGnfuwsKspAAAA_s"]
[Tue Jul 21 07:40:13.713230 2026] [security2:error] [pid 255769:tid 255987] [client 122.186.204.214:65451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MjbxMYwyVGnfuwsKspAAAA_s"]
[Tue Jul 21 07:40:13.721665 2026] [security2:error] [pid 254995:tid 255130] [client 4.204.201.85:57432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/stdin.php"] [unique_id "al9Mjf7v0rlcEGmVraFN1wAAAyM"]
[Tue Jul 21 07:40:13.855544 2026] [security2:error] [pid 255769:tid 255957] [client 117.251.86.144:41424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MjbxMYwyVGnfuwsKspgAAA90"]
[Tue Jul 21 07:40:13.855675 2026] [security2:error] [pid 255769:tid 255957] [client 117.251.86.144:41424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MjbxMYwyVGnfuwsKspgAAA90"]
[Tue Jul 21 07:40:13.890988 2026] [security2:error] [pid 255769:tid 255965] [client 167.235.143.113:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9MjbxMYwyVGnfuwsKspwAD5QE"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:40:13.943081 2026] [security2:error] [pid 254995:tid 255161] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9Mjf7v0rlcEGmVraFN2wAAA0I"]
[Tue Jul 21 07:40:14.003310 2026] [security2:error] [pid 255769:tid 256012] [client 4.204.201.85:59917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/BDKR28.php"] [unique_id "al9MjrxMYwyVGnfuwsKsqQAABBI"]
[Tue Jul 21 07:40:14.019481 2026] [security2:error] [pid 255769:tid 255945] [client 4.204.201.85:7481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/chosen.php"] [unique_id "al9MjrxMYwyVGnfuwsKsqgAAA9E"]
[Tue Jul 21 07:40:14.204638 2026] [security2:error] [pid 255769:tid 255844] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MjrxMYwyVGnfuwsKssAAD-ko"]
[Tue Jul 21 07:40:14.204806 2026] [security2:error] [pid 255769:tid 255986] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MjrxMYwyVGnfuwsKssAAD-ko"]
[Tue Jul 21 07:40:14.233801 2026] [security2:error] [pid 255769:tid 255968] [client 13.59.248.181:36252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "gradiente.com"] [uri "/robots.txt"] [unique_id "al9MjrxMYwyVGnfuwsKssQAAA-g"]
[Tue Jul 21 07:40:14.236849 2026] [security2:error] [pid 255769:tid 255940] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9MjrxMYwyVGnfuwsKssgAAA8w"]
[Tue Jul 21 07:40:14.265508 2026] [security2:error] [pid 255769:tid 255943] [client 13.59.248.181:36246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "gradiente.com"] [uri "/"] [unique_id "al9MjrxMYwyVGnfuwsKsswAAA88"]
[Tue Jul 21 07:40:14.273484 2026] [security2:error] [pid 255769:tid 255981] [client 13.59.248.181:36260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "gradiente.com"] [uri "/robots.txt"] [unique_id "al9MjrxMYwyVGnfuwsKstAAAA_U"]
[Tue Jul 21 07:40:14.282349 2026] [security2:error] [pid 255769:tid 255961] [client 4.204.201.85:57445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/001.php"] [unique_id "al9MjrxMYwyVGnfuwsKstQAAA-E"]
[Tue Jul 21 07:40:14.445856 2026] [security2:error] [pid 255769:tid 255925] [client 167.235.143.113:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9MjrxMYwyVGnfuwsKstwADvUE"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:40:14.463956 2026] [security2:error] [pid 254995:tid 255137] [client 4.204.201.85:3522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/cream1.php"] [unique_id "al9Mjv7v0rlcEGmVraFN4gAAAyo"]
[Tue Jul 21 07:40:14.486026 2026] [security2:error] [pid 254995:tid 255044] [remote 173.252.95.10:56570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9Mjv7v0rlcEGmVraFN4wADkzA"]
[Tue Jul 21 07:40:14.511015 2026] [security2:error] [pid 254995:tid 255199] [client 20.226.60.151:62242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Mjv7v0rlcEGmVraFN5AAAA2g"]
[Tue Jul 21 07:40:14.526209 2026] [security2:error] [pid 255769:tid 255939] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9MjrxMYwyVGnfuwsKsuAAAA8s"]
[Tue Jul 21 07:40:14.558722 2026] [security2:error] [pid 255769:tid 256026] [client 4.204.201.85:61067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/dZ3wP5.php"] [unique_id "al9MjrxMYwyVGnfuwsKsuQAABCA"]
[Tue Jul 21 07:40:14.661680 2026] [security2:error] [pid 255769:tid 255921] [client 20.226.60.151:22928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/test.php"] [unique_id "al9MjrxMYwyVGnfuwsKsugAAA7k"]
[Tue Jul 21 07:40:14.697774 2026] [security2:error] [pid 255769:tid 255916] [client 13.59.248.181:36266] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "gradiente.com"] [uri "/ads.txt"] [unique_id "al9MjrxMYwyVGnfuwsKsvgAAA7Q"]
[Tue Jul 21 07:40:14.780327 2026] [security2:error] [pid 255769:tid 255904] [client 13.59.248.181:36284] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.gradiente.com"] [uri "/"] [unique_id "al9MjrxMYwyVGnfuwsKsvwAAA6g"]
[Tue Jul 21 07:40:14.811617 2026] [security2:error] [pid 254995:tid 255178] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Mjv7v0rlcEGmVraFN6wAAA1M"]
[Tue Jul 21 07:40:14.838015 2026] [security2:error] [pid 255769:tid 255988] [client 4.204.201.85:59914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/yup.php"] [unique_id "al9MjrxMYwyVGnfuwsKswgAAA_w"]
[Tue Jul 21 07:40:14.955196 2026] [security2:error] [pid 255769:tid 255947] [client 20.151.10.161:45906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xamp.php"] [unique_id "al9MjrxMYwyVGnfuwsKsxgAAA9M"]
[Tue Jul 21 07:40:15.044040 2026] [security2:error] [pid 255769:tid 255932] [client 20.151.10.161:53622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/green1.php"] [unique_id "al9Mj7xMYwyVGnfuwsKsygAAA8Q"]
[Tue Jul 21 07:40:15.095650 2026] [security2:error] [pid 255769:tid 255965] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Mj7xMYwyVGnfuwsKszgAAA-U"]
[Tue Jul 21 07:40:15.124028 2026] [security2:error] [pid 255769:tid 255941] [client 4.204.201.85:57464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/X.php"] [unique_id "al9Mj7xMYwyVGnfuwsKs0AAAA80"]
[Tue Jul 21 07:40:15.165746 2026] [security2:error] [pid 255769:tid 255825] [remote 51.158.61.221:38834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Mj7xMYwyVGnfuwsKs0QAD1Dc"]
[Tue Jul 21 07:40:15.192440 2026] [proxy:error] [pid 255769:tid 255982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:15.192499 2026] [proxy_http:error] [pid 255769:tid 255982] [client 2a03:b0c0:3:d0::d1a:1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:15.193187 2026] [proxy:error] [pid 255769:tid 255982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:15.193227 2026] [proxy_http:error] [pid 255769:tid 255982] [client 2a03:b0c0:3:d0::d1a:1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:15.303868 2026] [proxy:error] [pid 255769:tid 255974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:15.303936 2026] [proxy_http:error] [pid 255769:tid 255974] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:15.304398 2026] [proxy:error] [pid 255769:tid 255974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:15.304427 2026] [proxy_http:error] [pid 255769:tid 255974] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:15.311450 2026] [security2:error] [pid 255769:tid 255922] [client 20.220.225.223:19272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/pn.php"] [unique_id "al9Mj7xMYwyVGnfuwsKs3wAAA7o"]
[Tue Jul 21 07:40:15.389698 2026] [security2:error] [pid 255769:tid 255924] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Mj7xMYwyVGnfuwsKs5AAAA7w"]
[Tue Jul 21 07:40:15.400942 2026] [security2:error] [pid 255769:tid 255970] [client 4.204.201.85:57416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/1polka.php"] [unique_id "al9Mj7xMYwyVGnfuwsKs5wAAA-o"]
[Tue Jul 21 07:40:15.403757 2026] [proxy:error] [pid 255769:tid 256010] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:15.403839 2026] [proxy_http:error] [pid 255769:tid 256010] [client 2604:a880:cad:d0::d9d:e001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:15.404398 2026] [proxy:error] [pid 255769:tid 256010] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:15.404427 2026] [proxy_http:error] [pid 255769:tid 256010] [client 2604:a880:cad:d0::d9d:e001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:15.413171 2026] [security2:error] [pid 255769:tid 255946] [client 69.171.230.42:64710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Mj7xMYwyVGnfuwsKs3QAAA9I"]
[Tue Jul 21 07:40:15.484882 2026] [security2:error] [pid 255769:tid 255811] [remote 47.128.50.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hauptmann.com.br"] [uri "/"] [unique_id "al9Mj7xMYwyVGnfuwsKs7wAD4Ck"]
[Tue Jul 21 07:40:15.545277 2026] [security2:error] [pid 255769:tid 255945] [client 69.171.230.3:61662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Mj7xMYwyVGnfuwsKs4wAAA9E"]
[Tue Jul 21 07:40:15.567169 2026] [security2:error] [pid 254995:tid 255138] [client 20.226.60.151:56267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/gqgsa.php"] [unique_id "al9Mj_7v0rlcEGmVraFN-gAAAys"]
[Tue Jul 21 07:40:15.675470 2026] [security2:error] [pid 255769:tid 256011] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9Mj7xMYwyVGnfuwsKs8wAABBE"]
[Tue Jul 21 07:40:15.678432 2026] [security2:error] [pid 255769:tid 255915] [client 4.204.201.85:57460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/gec.php"] [unique_id "al9Mj7xMYwyVGnfuwsKs9AAAA7M"]
[Tue Jul 21 07:40:15.860548 2026] [proxy:error] [pid 255769:tid 255942] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:15.860633 2026] [proxy_http:error] [pid 255769:tid 255942] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:15.861370 2026] [proxy:error] [pid 255769:tid 255942] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:15.861421 2026] [proxy_http:error] [pid 255769:tid 255942] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:15.869304 2026] [security2:error] [pid 254995:tid 255000] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Mj_7v0rlcEGmVraFOBAADPgQ"]
[Tue Jul 21 07:40:15.869471 2026] [security2:error] [pid 254995:tid 255157] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Mj_7v0rlcEGmVraFOBAADPgQ"]
[Tue Jul 21 07:40:15.878841 2026] [security2:error] [pid 254995:tid 255150] [client 154.192.233.199:60220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mj_7v0rlcEGmVraFOBQAAAzc"]
[Tue Jul 21 07:40:15.878930 2026] [security2:error] [pid 254995:tid 255150] [client 154.192.233.199:60220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mj_7v0rlcEGmVraFOBQAAAzc"]
[Tue Jul 21 07:40:15.942608 2026] [security2:error] [pid 254995:tid 255220] [client 122.164.127.47:63702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Mj_7v0rlcEGmVraFOBgAAA3w"]
[Tue Jul 21 07:40:15.944558 2026] [security2:error] [pid 254995:tid 255220] [client 122.164.127.47:63702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Mj_7v0rlcEGmVraFOBgAAA3w"]
[Tue Jul 21 07:40:15.954664 2026] [security2:error] [pid 255769:tid 255962] [client 4.204.201.85:59920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/sky.php"] [unique_id "al9Mj7xMYwyVGnfuwsKtAQAAA-I"]
[Tue Jul 21 07:40:15.959608 2026] [security2:error] [pid 255769:tid 255955] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9Mj7xMYwyVGnfuwsKtAgAAA9s"]
[Tue Jul 21 07:40:16.000830 2026] [proxy:error] [pid 255769:tid 255975] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.000885 2026] [proxy_http:error] [pid 255769:tid 255975] [client 2a03:b0c0:3:d0::fef:2001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:16.001469 2026] [proxy:error] [pid 255769:tid 255975] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.001490 2026] [proxy_http:error] [pid 255769:tid 255975] [client 2a03:b0c0:3:d0::fef:2001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:16.015707 2026] [security2:error] [pid 255769:tid 256015] [client 173.252.95.12:40604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9MkLxMYwyVGnfuwsKtBAAABBU"]
[Tue Jul 21 07:40:16.050739 2026] [security2:error] [pid 255769:tid 255932] [client 20.226.60.151:62280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MkLxMYwyVGnfuwsKtBQAAA8Q"]
[Tue Jul 21 07:40:16.201130 2026] [security2:error] [pid 255769:tid 255774] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtBwAEHQQ"]
[Tue Jul 21 07:40:16.201311 2026] [security2:error] [pid 255769:tid 256023] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtBwAEHQQ"]
[Tue Jul 21 07:40:16.236494 2026] [security2:error] [pid 255769:tid 255996] [client 4.204.201.85:46030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/dr.php"] [unique_id "al9MkLxMYwyVGnfuwsKtCQAABAI"]
[Tue Jul 21 07:40:16.244907 2026] [security2:error] [pid 254995:tid 255204] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9MkP7v0rlcEGmVraFOCwAAA20"]
[Tue Jul 21 07:40:16.247311 2026] [security2:error] [pid 255769:tid 256014] [client 4.204.201.85:57412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/fffm.php"] [unique_id "al9MkLxMYwyVGnfuwsKtCgAABBQ"]
[Tue Jul 21 07:40:16.313496 2026] [security2:error] [pid 255769:tid 255911] [client 20.151.10.161:12080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/biufile.php"] [unique_id "al9MkLxMYwyVGnfuwsKtDgAAA68"]
[Tue Jul 21 07:40:16.320112 2026] [security2:error] [pid 254995:tid 255213] [client 20.226.60.151:23111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/aaa.php"] [unique_id "al9MkP7v0rlcEGmVraFOEAAAA3U"]
[Tue Jul 21 07:40:16.398494 2026] [security2:error] [pid 255769:tid 255961] [client 20.220.225.223:19276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9MkLxMYwyVGnfuwsKtEgAAA-E"]
[Tue Jul 21 07:40:16.410259 2026] [proxy:error] [pid 254995:tid 255256] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.410324 2026] [proxy_http:error] [pid 254995:tid 255256] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:16.410948 2026] [proxy:error] [pid 254995:tid 255256] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.410986 2026] [proxy_http:error] [pid 254995:tid 255256] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:16.428787 2026] [proxy:error] [pid 254995:tid 255147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.428855 2026] [proxy_http:error] [pid 254995:tid 255147] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:16.429312 2026] [proxy:error] [pid 254995:tid 255147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.429339 2026] [proxy_http:error] [pid 254995:tid 255147] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:16.494165 2026] [proxy:error] [pid 255769:tid 255900] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.494232 2026] [proxy_http:error] [pid 255769:tid 255900] [client 2604:a880:4:1d0::36c:6000:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:16.494670 2026] [proxy:error] [pid 255769:tid 255900] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.494706 2026] [proxy_http:error] [pid 255769:tid 255900] [client 2604:a880:4:1d0::36c:6000:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:16.531701 2026] [security2:error] [pid 254995:tid 255127] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9MkP7v0rlcEGmVraFOFgAAAyA"]
[Tue Jul 21 07:40:16.556334 2026] [security2:error] [pid 255769:tid 256026] [client 4.204.201.85:61077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/sixxis.php"] [unique_id "al9MkLxMYwyVGnfuwsKtGgAABCA"]
[Tue Jul 21 07:40:16.588505 2026] [security2:error] [pid 254995:tid 255128] [client 20.226.60.151:56273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/elbzl.php"] [unique_id "al9MkP7v0rlcEGmVraFOFwAAAyE"]
[Tue Jul 21 07:40:16.589138 2026] [security2:error] [pid 255769:tid 256021] [client 175.45.70.82:54285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtGwAABBs"]
[Tue Jul 21 07:40:16.589255 2026] [security2:error] [pid 255769:tid 256021] [client 175.45.70.82:54285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtGwAABBs"]
[Tue Jul 21 07:40:16.723713 2026] [security2:error] [pid 255769:tid 255795] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtHQAEBBk"]
[Tue Jul 21 07:40:16.723888 2026] [security2:error] [pid 255769:tid 255998] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtHQAEBBk"]
[Tue Jul 21 07:40:16.755519 2026] [proxy:error] [pid 254995:tid 255161] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.755574 2026] [proxy_http:error] [pid 254995:tid 255161] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:16.756151 2026] [proxy:error] [pid 254995:tid 255161] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.756176 2026] [proxy_http:error] [pid 254995:tid 255161] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:16.822362 2026] [security2:error] [pid 254995:tid 255205] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9MkP7v0rlcEGmVraFOKgAAA24"]
[Tue Jul 21 07:40:16.836063 2026] [security2:error] [pid 255769:tid 256011] [client 4.204.201.85:57429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/yj09.php"] [unique_id "al9MkLxMYwyVGnfuwsKtIQAABBE"]
[Tue Jul 21 07:40:16.883563 2026] [security2:error] [pid 255769:tid 256001] [client 20.151.10.161:45882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/bless.php"] [unique_id "al9MkLxMYwyVGnfuwsKtIwAABAc"]
[Tue Jul 21 07:40:16.911498 2026] [security2:error] [pid 255769:tid 255948] [client 202.143.127.214:61529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtHgAAA9Q"]
[Tue Jul 21 07:40:16.911637 2026] [security2:error] [pid 255769:tid 255948] [client 202.143.127.214:61529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtHgAAA9Q"]
[Tue Jul 21 07:40:16.936100 2026] [security2:error] [pid 255769:tid 255983] [client 20.197.195.24:13163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/inputs.php"] [unique_id "al9MkLxMYwyVGnfuwsKtJgAAA_c"]
[Tue Jul 21 07:40:16.945067 2026] [security2:error] [pid 255769:tid 256012] [client 122.162.144.145:5766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtJwAABBI"]
[Tue Jul 21 07:40:16.945142 2026] [security2:error] [pid 255769:tid 256012] [client 122.162.144.145:5766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtJwAABBI"]
[Tue Jul 21 07:40:16.980876 2026] [security2:error] [pid 255769:tid 255918] [client 103.106.20.201:61096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtKAAAA7Y"]
[Tue Jul 21 07:40:16.980964 2026] [security2:error] [pid 255769:tid 255918] [client 103.106.20.201:61096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtKAAAA7Y"]
[Tue Jul 21 07:40:16.990192 2026] [security2:error] [pid 255769:tid 255988] [client 4.204.201.85:46042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/x.php"] [unique_id "al9MkLxMYwyVGnfuwsKtKQAAA_w"]
[Tue Jul 21 07:40:16.996483 2026] [proxy:error] [pid 255769:tid 255972] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.996531 2026] [proxy_http:error] [pid 255769:tid 255972] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:16.996966 2026] [proxy:error] [pid 255769:tid 255972] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.996988 2026] [proxy_http:error] [pid 255769:tid 255972] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:17.142545 2026] [security2:error] [pid 255769:tid 255947] [client 4.204.201.85:57467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/f900.php"] [unique_id "al9MkbxMYwyVGnfuwsKtMAAAA9M"]
[Tue Jul 21 07:40:17.156799 2026] [security2:error] [pid 255769:tid 255978] [client 103.86.117.203:62487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MkbxMYwyVGnfuwsKtMgAAA_I"]
[Tue Jul 21 07:40:17.156941 2026] [security2:error] [pid 255769:tid 255978] [client 103.86.117.203:62487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MkbxMYwyVGnfuwsKtMgAAA_I"]
[Tue Jul 21 07:40:17.301595 2026] [proxy:error] [pid 254995:tid 255225] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:17.301659 2026] [proxy_http:error] [pid 254995:tid 255225] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:17.302206 2026] [proxy:error] [pid 254995:tid 255225] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:17.302241 2026] [proxy_http:error] [pid 254995:tid 255225] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:17.382420 2026] [proxy:error] [pid 255769:tid 255911] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:17.382496 2026] [proxy_http:error] [pid 255769:tid 255911] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:17.383184 2026] [proxy:error] [pid 255769:tid 255911] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:17.383214 2026] [proxy_http:error] [pid 255769:tid 255911] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:17.412200 2026] [security2:error] [pid 255769:tid 255961] [client 20.226.60.151:62289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/xyn.php"] [unique_id "al9MkbxMYwyVGnfuwsKtQgAAA-E"]
[Tue Jul 21 07:40:17.418684 2026] [security2:error] [pid 255769:tid 255981] [client 4.204.201.85:61063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/ups.php"] [unique_id "al9MkbxMYwyVGnfuwsKtQwAAA_U"]
[Tue Jul 21 07:40:17.481862 2026] [proxy:error] [pid 254995:tid 255162] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:17.481913 2026] [proxy_http:error] [pid 254995:tid 255162] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:17.482571 2026] [proxy:error] [pid 254995:tid 255162] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:17.482595 2026] [proxy_http:error] [pid 254995:tid 255162] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:17.535724 2026] [security2:error] [pid 255769:tid 256026] [client 4.204.201.85:3533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/155.php"] [unique_id "al9MkbxMYwyVGnfuwsKtRgAABCA"]
[Tue Jul 21 07:40:17.650257 2026] [security2:error] [pid 255769:tid 255968] [client 49.13.130.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9MkbxMYwyVGnfuwsKtSAAD6FQ"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:40:17.652890 2026] [security2:error] [pid 254995:tid 255222] [client 20.151.10.161:46023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file46.php"] [unique_id "al9Mkf7v0rlcEGmVraFOPAAAA34"]
[Tue Jul 21 07:40:17.693435 2026] [security2:error] [pid 254995:tid 255177] [client 27.34.72.65:29601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.72.34.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "heyidiomas.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mkf7v0rlcEGmVraFOPQAAA1I"]
[Tue Jul 21 07:40:17.693553 2026] [security2:error] [pid 254995:tid 255177] [client 27.34.72.65:29601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "heyidiomas.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mkf7v0rlcEGmVraFOPQAAA1I"]
[Tue Jul 21 07:40:17.693833 2026] [security2:error] [pid 255769:tid 255903] [client 4.204.201.85:57469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/k.php"] [unique_id "al9MkbxMYwyVGnfuwsKtSgAAA6c"]
[Tue Jul 21 07:40:17.726296 2026] [security2:error] [pid 255769:tid 255935] [client 20.226.60.151:56243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/adjig.php"] [unique_id "al9MkbxMYwyVGnfuwsKtUwAAA8c"]
[Tue Jul 21 07:40:17.907531 2026] [proxy:error] [pid 255769:tid 255999] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:17.907606 2026] [proxy_http:error] [pid 255769:tid 255999] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:17.908362 2026] [proxy:error] [pid 255769:tid 255999] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:17.908404 2026] [proxy_http:error] [pid 255769:tid 255999] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:17.911163 2026] [security2:error] [pid 255769:tid 255989] [client 62.102.148.187:46980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MkbxMYwyVGnfuwsKtXQAAA_0"]
[Tue Jul 21 07:40:17.911269 2026] [security2:error] [pid 255769:tid 255989] [client 62.102.148.187:46980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MkbxMYwyVGnfuwsKtXQAAA_0"]
[Tue Jul 21 07:40:17.976285 2026] [security2:error] [pid 254995:tid 255158] [client 4.204.201.85:61072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/k2.php"] [unique_id "al9Mkf7v0rlcEGmVraFOUQAAAz8"]
[Tue Jul 21 07:40:17.984824 2026] [security2:error] [pid 254995:tid 255261] [client 182.8.255.181:21225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Mkf7v0rlcEGmVraFOSgAAA4s"]
[Tue Jul 21 07:40:17.984973 2026] [security2:error] [pid 254995:tid 255261] [client 182.8.255.181:21225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Mkf7v0rlcEGmVraFOSgAAA4s"]
[Tue Jul 21 07:40:18.193169 2026] [security2:error] [pid 255769:tid 255978] [client 49.13.130.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9MkrxMYwyVGnfuwsKtZAAD8kI"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:40:18.245923 2026] [access_compat:error] [pid 254995:tid 255118] [remote 206.189.95.232:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:40:18.255486 2026] [security2:error] [pid 254995:tid 255183] [client 4.204.201.85:59948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/w.php"] [unique_id "al9Mkv7v0rlcEGmVraFOWAAAA1g"]
[Tue Jul 21 07:40:18.284028 2026] [security2:error] [pid 254995:tid 255206] [client 20.151.10.161:45856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/eee.php"] [unique_id "al9Mkv7v0rlcEGmVraFOWgAAA28"]
[Tue Jul 21 07:40:18.336729 2026] [security2:error] [pid 254995:tid 255260] [client 152.59.154.239:64910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mkv7v0rlcEGmVraFOXAAAA4o"]
[Tue Jul 21 07:40:18.336824 2026] [security2:error] [pid 254995:tid 255260] [client 152.59.154.239:64910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mkv7v0rlcEGmVraFOXAAAA4o"]
[Tue Jul 21 07:40:18.381124 2026] [security2:error] [pid 254995:tid 255264] [client 167.99.210.137:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcalendars.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/server-status"] [unique_id "al9Mkv7v0rlcEGmVraFOXgAAA44"]
[Tue Jul 21 07:40:18.382516 2026] [access_compat:error] [pid 255769:tid 255967] [client 165.227.39.235:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:40:18.398584 2026] [security2:error] [pid 255769:tid 255986] [client 167.99.181.249:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webmail.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/server-status"] [unique_id "al9MkrxMYwyVGnfuwsKtagAAA_o"]
[Tue Jul 21 07:40:18.404098 2026] [security2:error] [pid 255769:tid 255946] [client 165.227.39.235:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webmail.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/server-status"] [unique_id "al9MkrxMYwyVGnfuwsKtawAAA9I"]
[Tue Jul 21 07:40:18.430347 2026] [proxy:error] [pid 255769:tid 255951] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:18.430404 2026] [proxy_http:error] [pid 255769:tid 255951] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:18.430869 2026] [proxy:error] [pid 255769:tid 255951] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:18.430902 2026] [proxy_http:error] [pid 255769:tid 255951] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:18.533938 2026] [security2:error] [pid 255769:tid 256028] [client 4.204.201.85:57431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/fpwch.php"] [unique_id "al9MkrxMYwyVGnfuwsKtcQAABCI"]
[Tue Jul 21 07:40:18.604301 2026] [access_compat:error] [pid 255769:tid 255936] [client 157.245.113.227:0] AH01797: client denied by server configuration: proxy:http://127.0.0.1/cgi-sys/autodiscover.cgi
[Tue Jul 21 07:40:18.609783 2026] [security2:error] [pid 255769:tid 255938] [client 20.226.60.151:23156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/11.php"] [unique_id "al9MkrxMYwyVGnfuwsKtdwAAA8o"]
[Tue Jul 21 07:40:18.634194 2026] [security2:error] [pid 255769:tid 255943] [client 20.151.10.161:53578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wpconf.php"] [unique_id "al9MkrxMYwyVGnfuwsKteQAAA88"]
[Tue Jul 21 07:40:18.704605 2026] [access_compat:error] [pid 255769:tid 255970] [client 64.225.75.246:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:40:18.706096 2026] [security2:error] [pid 255769:tid 255915] [client 4.204.201.85:3549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/ops.php"] [unique_id "al9MkrxMYwyVGnfuwsKtewAAA7M"]
[Tue Jul 21 07:40:18.807051 2026] [proxy:error] [pid 254995:tid 255188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:18.807107 2026] [proxy_http:error] [pid 254995:tid 255188] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:18.807762 2026] [proxy:error] [pid 254995:tid 255188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:18.807793 2026] [proxy_http:error] [pid 254995:tid 255188] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:18.810040 2026] [security2:error] [pid 254995:tid 255270] [client 4.204.201.85:59925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/w2025.php"] [unique_id "al9Mkv7v0rlcEGmVraFOZQAAA5Q"]
[Tue Jul 21 07:40:18.827593 2026] [security2:error] [pid 254995:tid 255154] [client 20.226.60.151:59516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Mkv7v0rlcEGmVraFOZgAAAzs"]
[Tue Jul 21 07:40:18.832645 2026] [access_compat:error] [pid 255769:tid 256026] [client 167.99.181.249:0] AH01797: client denied by server configuration: proxy:http://127.0.0.1/cgi-sys/autodiscover.cgi
[Tue Jul 21 07:40:18.912806 2026] [autoindex:error] [pid 255769:tid 255964] [client 136.107.11.182:57070] AH01276: Cannot serve directory /home4/arcoll06/y.arcoll.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:18.978083 2026] [security2:error] [pid 255769:tid 255997] [client 136.144.33.99:44421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MkbxMYwyVGnfuwsKtVAAABAM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:18.999687 2026] [access_compat:error] [pid 254995:tid 255163] [client 147.182.200.94:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:40:19.000435 2026] [security2:error] [pid 254995:tid 255157] [client 139.59.143.102:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcontacts.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/server-status"] [unique_id "al9Mkv7v0rlcEGmVraFObQAAAz4"]
[Tue Jul 21 07:40:19.040973 2026] [security2:error] [pid 254995:tid 255266] [client 20.151.10.161:45920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file25.php"] [unique_id "al9Mk_7v0rlcEGmVraFObwAAA5A"]
[Tue Jul 21 07:40:19.090406 2026] [security2:error] [pid 255769:tid 255923] [client 206.81.12.187:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpanel.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/server-status"] [unique_id "al9Mk7xMYwyVGnfuwsKtggAAA7s"]
[Tue Jul 21 07:40:19.091574 2026] [security2:error] [pid 255769:tid 255904] [client 4.204.201.85:57440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/FWAZ.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtgwAAA6g"]
[Tue Jul 21 07:40:19.116736 2026] [access_compat:error] [pid 255769:tid 255810] [remote 167.172.158.128:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:40:19.142595 2026] [security2:error] [pid 254995:tid 255186] [client 172.245.102.32:34117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MkP7v0rlcEGmVraFOLwAAA1s"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:40:19.151066 2026] [security2:error] [pid 254995:tid 255211] [client 209.97.180.8:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webdisk.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/server-status"] [unique_id "al9Mk_7v0rlcEGmVraFOcgAAA3M"]
[Tue Jul 21 07:40:19.228742 2026] [access_compat:error] [pid 254995:tid 255191] [client 207.154.197.113:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:40:19.314753 2026] [security2:error] [pid 255769:tid 255900] [client 59.96.220.140:51072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtiAAAA6Q"]
[Tue Jul 21 07:40:19.315381 2026] [security2:error] [pid 255769:tid 255900] [client 59.96.220.140:51072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtiAAAA6Q"]
[Tue Jul 21 07:40:19.356896 2026] [security2:error] [pid 254995:tid 255158] [client 20.220.225.223:34253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/kq1.php"] [unique_id "al9Mk_7v0rlcEGmVraFOcwAAAz8"]
[Tue Jul 21 07:40:19.367217 2026] [security2:error] [pid 254995:tid 255196] [client 142.93.129.190:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcalendars.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/server-status"] [unique_id "al9Mk_7v0rlcEGmVraFOdAAAA2U"]
[Tue Jul 21 07:40:19.379771 2026] [security2:error] [pid 255769:tid 255989] [client 4.204.201.85:57456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/qterm.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtiQAAA_0"]
[Tue Jul 21 07:40:19.400621 2026] [security2:error] [pid 255769:tid 255990] [client 136.107.11.182:57070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.11.107.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "y.arcoll.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtigAAA_4"]
[Tue Jul 21 07:40:19.464316 2026] [security2:error] [pid 254995:tid 255213] [client 209.38.208.202:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcontacts.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/server-status"] [unique_id "al9Mk_7v0rlcEGmVraFOfAAAA3U"]
[Tue Jul 21 07:40:19.538649 2026] [security2:error] [pid 255769:tid 255980] [client 20.151.10.161:45825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file48.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtkQAAA_Q"]
[Tue Jul 21 07:40:19.667215 2026] [security2:error] [pid 255769:tid 255979] [client 4.204.201.85:57471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/blurbs.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtlAAAA_M"]
[Tue Jul 21 07:40:19.672867 2026] [security2:error] [pid 255769:tid 255899] [client 20.226.60.151:62210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/patie.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtlgAAA6M"]
[Tue Jul 21 07:40:19.694461 2026] [security2:error] [pid 255769:tid 255928] [client 103.174.34.15:50327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtlwAAA8A"]
[Tue Jul 21 07:40:19.694641 2026] [security2:error] [pid 255769:tid 255928] [client 103.174.34.15:50327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtlwAAA8A"]
[Tue Jul 21 07:40:19.738340 2026] [access_compat:error] [pid 254995:tid 255256] [client 142.93.143.8:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:40:19.757497 2026] [security2:error] [pid 255769:tid 255791] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtmgAEFRU"]
[Tue Jul 21 07:40:19.757684 2026] [security2:error] [pid 255769:tid 256015] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtmgAEFRU"]
[Tue Jul 21 07:40:19.793987 2026] [security2:error] [pid 254995:tid 255272] [client 20.151.10.161:12063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/mosty.php"] [unique_id "al9Mk_7v0rlcEGmVraFOhQAAA5Y"]
[Tue Jul 21 07:40:19.797303 2026] [security2:error] [pid 255769:tid 255867] [remote 20.153.140.50:60524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/wp-login.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtmwAEG2E"]
[Tue Jul 21 07:40:19.938200 2026] [security2:error] [pid 254995:tid 255149] [client 117.217.38.194:59839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mk_7v0rlcEGmVraFOjwAAAzY"]
[Tue Jul 21 07:40:19.938340 2026] [security2:error] [pid 254995:tid 255149] [client 117.217.38.194:59839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mk_7v0rlcEGmVraFOjwAAAzY"]
[Tue Jul 21 07:40:19.944263 2026] [security2:error] [pid 254995:tid 255171] [client 4.204.201.85:59921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/v543.php"] [unique_id "al9Mk_7v0rlcEGmVraFOkAAAA0w"]
[Tue Jul 21 07:40:19.972867 2026] [security2:error] [pid 254995:tid 255274] [client 20.151.10.161:45893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file6.php"] [unique_id "al9Mk_7v0rlcEGmVraFOkgAAA5g"]
[Tue Jul 21 07:40:20.034270 2026] [security2:error] [pid 255769:tid 255919] [client 164.92.244.132:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpanel.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/server-status"] [unique_id "al9MlLxMYwyVGnfuwsKtnwAAA7c"]
[Tue Jul 21 07:40:20.224232 2026] [security2:error] [pid 255769:tid 255968] [client 4.204.201.85:59943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/w3lls.php"] [unique_id "al9MlLxMYwyVGnfuwsKtowAAA-g"]
[Tue Jul 21 07:40:20.254598 2026] [security2:error] [pid 255769:tid 256016] [client 20.226.60.151:59487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MlLxMYwyVGnfuwsKtpQAABBY"]
[Tue Jul 21 07:40:20.318800 2026] [security2:error] [pid 254995:tid 255136] [client 20.151.10.161:45918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/a2.php"] [unique_id "al9MlP7v0rlcEGmVraFOmQAAAyk"]
[Tue Jul 21 07:40:20.320430 2026] [proxy:error] [pid 255769:tid 255934] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:20.320496 2026] [proxy_http:error] [pid 255769:tid 255934] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:20.320984 2026] [proxy:error] [pid 255769:tid 255934] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:20.321024 2026] [proxy_http:error] [pid 255769:tid 255934] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:20.340037 2026] [security2:error] [pid 255769:tid 255996] [client 20.151.10.161:55237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/dejavu.php"] [unique_id "al9MlLxMYwyVGnfuwsKtrQAABAI"]
[Tue Jul 21 07:40:20.362368 2026] [security2:error] [pid 255769:tid 256010] [client 20.104.96.117:14340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MlLxMYwyVGnfuwsKtrgAABBA"]
[Tue Jul 21 07:40:20.396262 2026] [security2:error] [pid 255769:tid 255904] [client 20.226.60.151:23114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/mac.php"] [unique_id "al9MlLxMYwyVGnfuwsKtsAAAA6g"]
[Tue Jul 21 07:40:20.422349 2026] [security2:error] [pid 255769:tid 255911] [client 122.179.91.63:23299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MlLxMYwyVGnfuwsKttQAAA68"]
[Tue Jul 21 07:40:20.422477 2026] [security2:error] [pid 255769:tid 255911] [client 122.179.91.63:23299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MlLxMYwyVGnfuwsKttQAAA68"]
[Tue Jul 21 07:40:20.501888 2026] [security2:error] [pid 255769:tid 256009] [client 4.204.201.85:59956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-ws68.php"] [unique_id "al9MlLxMYwyVGnfuwsKtuQAABA8"]
[Tue Jul 21 07:40:20.578184 2026] [security2:error] [pid 255769:tid 256018] [client 4.204.201.85:46039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/file31.php"] [unique_id "al9MlLxMYwyVGnfuwsKtvQAABBg"]
[Tue Jul 21 07:40:20.614738 2026] [security2:error] [pid 255769:tid 255980] [client 20.226.60.151:62238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/aa.php"] [unique_id "al9MlLxMYwyVGnfuwsKtvwAAA_Q"]
[Tue Jul 21 07:40:20.624694 2026] [security2:error] [pid 255769:tid 255914] [client 139.167.225.182:57857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MlLxMYwyVGnfuwsKtwAAAA7I"]
[Tue Jul 21 07:40:20.624851 2026] [security2:error] [pid 255769:tid 255914] [client 139.167.225.182:57857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MlLxMYwyVGnfuwsKtwAAAA7I"]
[Tue Jul 21 07:40:20.664164 2026] [security2:error] [pid 255769:tid 256003] [client 20.104.96.117:14608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MlLxMYwyVGnfuwsKtwwAABAk"]
[Tue Jul 21 07:40:20.694660 2026] [security2:error] [pid 255769:tid 255942] [client 20.151.10.161:45944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file15.php"] [unique_id "al9MlLxMYwyVGnfuwsKtxAAAA84"]
[Tue Jul 21 07:40:20.743785 2026] [security2:error] [pid 255769:tid 256015] [client 207.154.212.47:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webdisk.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/server-status"] [unique_id "al9MlLxMYwyVGnfuwsKtxQAABBU"]
[Tue Jul 21 07:40:20.781942 2026] [security2:error] [pid 255769:tid 256021] [client 4.204.201.85:57413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/xyn.php"] [unique_id "al9MlLxMYwyVGnfuwsKtxgAABBs"]
[Tue Jul 21 07:40:20.792278 2026] [security2:error] [pid 255769:tid 255958] [client 20.151.10.161:12055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/aaf.php"] [unique_id "al9MlLxMYwyVGnfuwsKtyQAAA94"]
[Tue Jul 21 07:40:20.894184 2026] [proxy:error] [pid 255769:tid 255933] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:20.894255 2026] [proxy_http:error] [pid 255769:tid 255933] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:20.894723 2026] [proxy:error] [pid 255769:tid 255933] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:20.894764 2026] [proxy_http:error] [pid 255769:tid 255933] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:20.970343 2026] [security2:error] [pid 254995:tid 255218] [client 20.104.96.117:14372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/media.php"] [unique_id "al9MlP7v0rlcEGmVraFOrAAAA3o"]
[Tue Jul 21 07:40:21.068255 2026] [security2:error] [pid 255769:tid 255921] [client 20.226.60.151:59459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/xyn.php"] [unique_id "al9MlbxMYwyVGnfuwsKt0QAAA7k"]
[Tue Jul 21 07:40:21.069187 2026] [security2:error] [pid 255769:tid 255925] [client 4.204.201.85:59928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/green3.php"] [unique_id "al9MlbxMYwyVGnfuwsKt0gAAA70"]
[Tue Jul 21 07:40:21.184459 2026] [security2:error] [pid 255769:tid 255913] [client 20.151.10.161:45930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/jp.php"] [unique_id "al9MlbxMYwyVGnfuwsKt1AAAA7E"]
[Tue Jul 21 07:40:21.205286 2026] [security2:error] [pid 255769:tid 255998] [client 20.151.10.161:55290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/term.php"] [unique_id "al9MlbxMYwyVGnfuwsKt1QAABAQ"]
[Tue Jul 21 07:40:21.292095 2026] [security2:error] [pid 255769:tid 255905] [client 20.104.96.117:14610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/images.php"] [unique_id "al9MlbxMYwyVGnfuwsKt3QAAA6k"]
[Tue Jul 21 07:40:21.343413 2026] [security2:error] [pid 255769:tid 255926] [client 4.204.201.85:57410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/ccc.php"] [unique_id "al9MlbxMYwyVGnfuwsKt3gAAA74"]
[Tue Jul 21 07:40:21.361166 2026] [proxy:error] [pid 254995:tid 255158] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:21.361228 2026] [proxy_http:error] [pid 254995:tid 255158] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:21.361845 2026] [proxy:error] [pid 254995:tid 255158] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:21.361872 2026] [proxy_http:error] [pid 254995:tid 255158] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:21.418494 2026] [security2:error] [pid 255769:tid 255918] [client 20.226.60.151:62224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/xwpg.php"] [unique_id "al9MlbxMYwyVGnfuwsKt4QAAA7Y"]
[Tue Jul 21 07:40:21.439383 2026] [proxy:error] [pid 254995:tid 255184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:21.439445 2026] [proxy_http:error] [pid 254995:tid 255184] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:21.440055 2026] [proxy:error] [pid 254995:tid 255184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:21.440082 2026] [proxy_http:error] [pid 254995:tid 255184] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:21.495192 2026] [security2:error] [pid 255769:tid 255932] [client 4.204.201.85:7457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/file6.php"] [unique_id "al9MlbxMYwyVGnfuwsKt6AAAA8Q"]
[Tue Jul 21 07:40:21.512820 2026] [proxy:error] [pid 255769:tid 255980] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:21.512880 2026] [proxy_http:error] [pid 255769:tid 255980] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:21.513414 2026] [proxy:error] [pid 255769:tid 255980] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:21.513446 2026] [proxy_http:error] [pid 255769:tid 255980] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:21.671617 2026] [security2:error] [pid 255769:tid 256013] [client 4.204.201.85:57430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/get.php"] [unique_id "al9MlbxMYwyVGnfuwsKt7wAABBM"]
[Tue Jul 21 07:40:21.696905 2026] [security2:error] [pid 255769:tid 256015] [client 20.104.96.117:14347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/gecko.php"] [unique_id "al9MlbxMYwyVGnfuwsKt8QAABBU"]
[Tue Jul 21 07:40:21.768232 2026] [security2:error] [pid 255769:tid 255967] [client 20.226.60.151:59464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/patie.php"] [unique_id "al9MlbxMYwyVGnfuwsKt9AAAA-c"]
[Tue Jul 21 07:40:21.797402 2026] [security2:error] [pid 254995:tid 255159] [client 20.151.10.161:46002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/f35.php"] [unique_id "al9Mlf7v0rlcEGmVraFOvQAAA0A"]
[Tue Jul 21 07:40:21.849865 2026] [security2:error] [pid 254995:tid 255255] [client 20.151.10.161:12035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ha.php"] [unique_id "al9Mlf7v0rlcEGmVraFOvwAAA4U"]
[Tue Jul 21 07:40:21.850756 2026] [security2:error] [pid 255769:tid 256028] [client 20.226.60.151:23116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/chosen.php"] [unique_id "al9MlbxMYwyVGnfuwsKt-gAABCI"]
[Tue Jul 21 07:40:21.949253 2026] [security2:error] [pid 255769:tid 255945] [client 4.204.201.85:59906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/images.php"] [unique_id "al9MlbxMYwyVGnfuwsKuAQAAA9E"]
[Tue Jul 21 07:40:21.982439 2026] [access_compat:error] [pid 255769:tid 255919] [client 128.199.182.152:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:40:21.983703 2026] [security2:error] [pid 255769:tid 255970] [client 20.104.96.117:14365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/82.php"] [unique_id "al9MlbxMYwyVGnfuwsKuBAAAA-o"]
[Tue Jul 21 07:40:22.026142 2026] [security2:error] [pid 255769:tid 255916] [client 20.226.60.151:59470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/aa.php"] [unique_id "al9MlrxMYwyVGnfuwsKuBQAAA7Q"]
[Tue Jul 21 07:40:22.028992 2026] [security2:error] [pid 255769:tid 256010] [client 20.226.60.151:56317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/byp.php"] [unique_id "al9MlrxMYwyVGnfuwsKuBgAABBA"]
[Tue Jul 21 07:40:22.116288 2026] [security2:error] [pid 255769:tid 255996] [client 20.220.225.223:34208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/zzz.php"] [unique_id "al9MlrxMYwyVGnfuwsKuCAAABAI"]
[Tue Jul 21 07:40:22.212945 2026] [proxy:error] [pid 255769:tid 255987] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.213022 2026] [proxy_http:error] [pid 255769:tid 255987] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.213557 2026] [proxy:error] [pid 255769:tid 255987] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.213580 2026] [proxy_http:error] [pid 255769:tid 255987] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.225191 2026] [security2:error] [pid 254995:tid 255149] [client 4.204.201.85:59963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/alls.php"] [unique_id "al9Mlv7v0rlcEGmVraFOxwAAAzY"]
[Tue Jul 21 07:40:22.260219 2026] [security2:error] [pid 255769:tid 255936] [client 173.24.185.52:64542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MlrxMYwyVGnfuwsKuEgAAA8g"]
[Tue Jul 21 07:40:22.260357 2026] [security2:error] [pid 255769:tid 255936] [client 173.24.185.52:64542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MlrxMYwyVGnfuwsKuEgAAA8g"]
[Tue Jul 21 07:40:22.295357 2026] [security2:error] [pid 255769:tid 255900] [client 20.104.96.117:14386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/admin.php"] [unique_id "al9MlrxMYwyVGnfuwsKuFAAAA6Q"]
[Tue Jul 21 07:40:22.347896 2026] [proxy:error] [pid 254995:tid 255192] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.347969 2026] [proxy_http:error] [pid 254995:tid 255192] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.348718 2026] [proxy:error] [pid 254995:tid 255192] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.348760 2026] [proxy_http:error] [pid 254995:tid 255192] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.385096 2026] [proxy:error] [pid 255769:tid 255965] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.385188 2026] [proxy_http:error] [pid 255769:tid 255965] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.386376 2026] [proxy:error] [pid 255769:tid 255965] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.386422 2026] [proxy_http:error] [pid 255769:tid 255965] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.440523 2026] [security2:error] [pid 255769:tid 255796] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MlrxMYwyVGnfuwsKuGQAEHBo"]
[Tue Jul 21 07:40:22.440673 2026] [security2:error] [pid 255769:tid 256022] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MlrxMYwyVGnfuwsKuGQAEHBo"]
[Tue Jul 21 07:40:22.500583 2026] [security2:error] [pid 254995:tid 255269] [client 4.204.201.85:61057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/coffexium.php"] [unique_id "al9Mlv7v0rlcEGmVraFOzAAAA5M"]
[Tue Jul 21 07:40:22.515599 2026] [security2:error] [pid 255769:tid 255978] [client 20.151.10.161:46034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-load.php"] [unique_id "al9MlrxMYwyVGnfuwsKuIAAAA_I"]
[Tue Jul 21 07:40:22.549628 2026] [core:error] [pid 255769:tid 255910] [client 205.210.31.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:40:22.549651 2026] [core:error] [pid 255769:tid 255910] [client 205.210.31.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:40:22.632008 2026] [proxy:error] [pid 254995:tid 255133] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.632063 2026] [proxy_http:error] [pid 254995:tid 255133] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.632727 2026] [proxy:error] [pid 254995:tid 255133] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.632753 2026] [proxy_http:error] [pid 254995:tid 255133] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.632973 2026] [security2:error] [pid 255769:tid 256024] [client 20.104.96.117:14346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/adminner.php"] [unique_id "al9MlrxMYwyVGnfuwsKuKQAABB4"]
[Tue Jul 21 07:40:22.753779 2026] [proxy:error] [pid 255769:tid 255940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.753859 2026] [proxy_http:error] [pid 255769:tid 255940] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.754354 2026] [proxy:error] [pid 255769:tid 255940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.754386 2026] [proxy_http:error] [pid 255769:tid 255940] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.754868 2026] [security2:error] [pid 255769:tid 255934] [client 106.215.181.8:29964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MlrxMYwyVGnfuwsKuMQAAA8Y"]
[Tue Jul 21 07:40:22.754989 2026] [security2:error] [pid 255769:tid 255934] [client 106.215.181.8:29964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MlrxMYwyVGnfuwsKuMQAAA8Y"]
[Tue Jul 21 07:40:22.766161 2026] [security2:error] [pid 255769:tid 255943] [client 20.226.60.151:59435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/xwpg.php"] [unique_id "al9MlrxMYwyVGnfuwsKuMgAAA88"]
[Tue Jul 21 07:40:22.781591 2026] [security2:error] [pid 254995:tid 255162] [client 4.204.201.85:59961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/red.php"] [unique_id "al9Mlv7v0rlcEGmVraFO1AAAA0M"]
[Tue Jul 21 07:40:22.812881 2026] [security2:error] [pid 255769:tid 255979] [client 172.245.102.46:59041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MlrxMYwyVGnfuwsKuNgAAA_M"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:22.943605 2026] [proxy:error] [pid 255769:tid 255904] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.943689 2026] [proxy_http:error] [pid 255769:tid 255904] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.944825 2026] [proxy:error] [pid 255769:tid 255904] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.944880 2026] [proxy_http:error] [pid 255769:tid 255904] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.947068 2026] [security2:error] [pid 255769:tid 255983] [client 20.226.60.151:23117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/cream1.php"] [unique_id "al9MlrxMYwyVGnfuwsKuOQAAA_c"]
[Tue Jul 21 07:40:23.071275 2026] [security2:error] [pid 254995:tid 255181] [client 20.104.96.117:14366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/admin.php"] [unique_id "al9Ml_7v0rlcEGmVraFO3AAAA1Y"]
[Tue Jul 21 07:40:23.076297 2026] [autoindex:error] [pid 254995:tid 255177] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:23.153074 2026] [security2:error] [pid 255769:tid 256026] [client 20.226.60.151:62276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/ops.php"] [unique_id "al9Ml7xMYwyVGnfuwsKuRwAABCA"]
[Tue Jul 21 07:40:23.230536 2026] [security2:error] [pid 254995:tid 255214] [client 20.151.10.161:53594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/hur.php"] [unique_id "al9Ml_7v0rlcEGmVraFO3wAAA3Y"]
[Tue Jul 21 07:40:23.347137 2026] [security2:error] [pid 255769:tid 255978] [client 20.151.10.161:45908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xwpg.php"] [unique_id "al9Ml7xMYwyVGnfuwsKuTAAAA_I"]
[Tue Jul 21 07:40:23.350117 2026] [security2:error] [pid 254995:tid 255212] [client 4.204.201.85:57453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9Ml_7v0rlcEGmVraFO4wAAA3Q"]
[Tue Jul 21 07:40:23.404303 2026] [security2:error] [pid 255769:tid 256021] [client 20.104.96.117:14368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/k.php"] [unique_id "al9Ml7xMYwyVGnfuwsKuUQAABBs"]
[Tue Jul 21 07:40:23.419594 2026] [security2:error] [pid 255769:tid 255967] [client 128.127.105.184:43618] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Ml7xMYwyVGnfuwsKuUgAAA-c"]
[Tue Jul 21 07:40:23.419671 2026] [security2:error] [pid 255769:tid 255967] [client 128.127.105.184:43618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Ml7xMYwyVGnfuwsKuUgAAA-c"]
[Tue Jul 21 07:40:23.466051 2026] [proxy:error] [pid 254995:tid 255176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:23.466116 2026] [proxy_http:error] [pid 254995:tid 255176] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:23.466661 2026] [proxy:error] [pid 254995:tid 255176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:23.466684 2026] [proxy_http:error] [pid 254995:tid 255176] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:23.588475 2026] [proxy:error] [pid 255769:tid 255946] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:23.588532 2026] [proxy_http:error] [pid 255769:tid 255946] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:23.588947 2026] [proxy:error] [pid 255769:tid 255946] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:23.588974 2026] [proxy_http:error] [pid 255769:tid 255946] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:23.649874 2026] [autoindex:error] [pid 254995:tid 255129] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:23.685133 2026] [security2:error] [pid 255769:tid 256028] [client 20.104.96.117:14359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/blurbs.php"] [unique_id "al9Ml7xMYwyVGnfuwsKuYQAABCI"]
[Tue Jul 21 07:40:23.705489 2026] [security2:error] [pid 255769:tid 255970] [client 20.220.225.223:31742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9Ml7xMYwyVGnfuwsKuYgAAA-o"]
[Tue Jul 21 07:40:23.733425 2026] [proxy:error] [pid 254995:tid 255213] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:23.733499 2026] [proxy_http:error] [pid 254995:tid 255213] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:23.734493 2026] [proxy:error] [pid 254995:tid 255213] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:23.734535 2026] [proxy_http:error] [pid 254995:tid 255213] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:23.865109 2026] [proxy:error] [pid 255769:tid 255964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:23.865169 2026] [proxy_http:error] [pid 255769:tid 255964] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:23.865612 2026] [proxy:error] [pid 255769:tid 255964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:23.865636 2026] [proxy_http:error] [pid 255769:tid 255964] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:23.884640 2026] [security2:error] [pid 255769:tid 255949] [client 20.226.60.151:56237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9Ml7xMYwyVGnfuwsKuZwAAA9U"]
[Tue Jul 21 07:40:23.936124 2026] [autoindex:error] [pid 255769:tid 256012] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:23.969835 2026] [proxy:error] [pid 255769:tid 255989] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:23.969896 2026] [proxy_http:error] [pid 255769:tid 255989] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:23.970332 2026] [proxy:error] [pid 255769:tid 255989] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:23.970358 2026] [proxy_http:error] [pid 255769:tid 255989] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:24.007772 2026] [security2:error] [pid 254995:tid 255008] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MmP7v0rlcEGmVraFO9wADMAw"]
[Tue Jul 21 07:40:24.007909 2026] [security2:error] [pid 254995:tid 255143] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MmP7v0rlcEGmVraFO9wADMAw"]
[Tue Jul 21 07:40:24.011271 2026] [security2:error] [pid 255769:tid 255924] [client 20.104.96.117:14397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/bajah.php"] [unique_id "al9MmLxMYwyVGnfuwsKucAAAA7w"]
[Tue Jul 21 07:40:24.076548 2026] [security2:error] [pid 255769:tid 255988] [client 4.204.201.85:59908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-content/index.php"] [unique_id "al9MmLxMYwyVGnfuwsKucgAAA_w"]
[Tue Jul 21 07:40:24.093278 2026] [proxy:error] [pid 255769:tid 255900] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:24.093344 2026] [proxy_http:error] [pid 255769:tid 255900] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:24.093953 2026] [proxy:error] [pid 255769:tid 255900] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:24.093980 2026] [proxy_http:error] [pid 255769:tid 255900] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:24.189250 2026] [security2:error] [pid 255769:tid 255972] [client 4.204.201.85:3551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/adminfuns.php"] [unique_id "al9MmLxMYwyVGnfuwsKudwAAA-w"]
[Tue Jul 21 07:40:24.289581 2026] [autoindex:error] [pid 255769:tid 255947] [client 20.226.60.151:23113] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:24.291727 2026] [security2:error] [pid 255769:tid 256003] [client 20.104.96.117:14602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/a.php"] [unique_id "al9MmLxMYwyVGnfuwsKufAAABAk"]
[Tue Jul 21 07:40:24.301750 2026] [security2:error] [pid 255769:tid 255975] [client 165.227.39.235:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "al9MmLxMYwyVGnfuwsKufgAAA-8"]
[Tue Jul 21 07:40:24.344708 2026] [proxy:error] [pid 255769:tid 255901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:24.344786 2026] [proxy_http:error] [pid 255769:tid 255901] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:24.345738 2026] [proxy:error] [pid 255769:tid 255901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:24.345775 2026] [proxy_http:error] [pid 255769:tid 255901] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:24.351878 2026] [security2:error] [pid 255769:tid 256015] [client 4.204.201.85:59912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/admin.php"] [unique_id "al9MmLxMYwyVGnfuwsKuhwAABBU"]
[Tue Jul 21 07:40:24.353359 2026] [autoindex:error] [pid 255769:tid 255974] [client 20.226.60.151:23113] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:24.358607 2026] [security2:error] [pid 255769:tid 256021] [client 20.226.60.151:23113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/dr.php"] [unique_id "al9MmLxMYwyVGnfuwsKuiAAABBs"]
[Tue Jul 21 07:40:24.408827 2026] [security2:error] [pid 255769:tid 255986] [client 167.99.181.249:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "al9MmLxMYwyVGnfuwsKujQAAA_o"]
[Tue Jul 21 07:40:24.412488 2026] [security2:error] [pid 254995:tid 255223] [client 122.186.204.214:49602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MmP7v0rlcEGmVraFPAAAAA38"]
[Tue Jul 21 07:40:24.412677 2026] [security2:error] [pid 254995:tid 255223] [client 122.186.204.214:49602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MmP7v0rlcEGmVraFPAAAAA38"]
[Tue Jul 21 07:40:24.444872 2026] [proxy:error] [pid 255769:tid 255951] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:24.444946 2026] [proxy_http:error] [pid 255769:tid 255951] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:24.445616 2026] [proxy:error] [pid 255769:tid 255951] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:24.445654 2026] [proxy_http:error] [pid 255769:tid 255951] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:24.479903 2026] [security2:error] [pid 255769:tid 256016] [client 117.251.86.144:41610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MmLxMYwyVGnfuwsKukAAABBY"]
[Tue Jul 21 07:40:24.480024 2026] [security2:error] [pid 255769:tid 256016] [client 117.251.86.144:41610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MmLxMYwyVGnfuwsKukAAABBY"]
[Tue Jul 21 07:40:24.558924 2026] [security2:error] [pid 255769:tid 255919] [client 4.204.201.85:7473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/goods.php"] [unique_id "al9MmLxMYwyVGnfuwsKuoAAAA7c"]
[Tue Jul 21 07:40:24.626954 2026] [security2:error] [pid 255769:tid 255998] [client 4.204.201.85:59946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/177.php"] [unique_id "al9MmLxMYwyVGnfuwsKutQAABAQ"]
[Tue Jul 21 07:40:24.641865 2026] [security2:error] [pid 255769:tid 255923] [client 20.151.10.161:45907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/waf.php"] [unique_id "al9MmLxMYwyVGnfuwsKuuwAAA7s"]
[Tue Jul 21 07:40:24.656926 2026] [security2:error] [pid 255769:tid 255938] [client 20.104.96.117:14615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/edit.php"] [unique_id "al9MmLxMYwyVGnfuwsKuvAAAA8o"]
[Tue Jul 21 07:40:24.677415 2026] [security2:error] [pid 254995:tid 255206] [client 165.227.39.235:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MmP7v0rlcEGmVraFPAwAAA28"]
[Tue Jul 21 07:40:24.697661 2026] [proxy:error] [pid 254995:tid 255263] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:24.697717 2026] [proxy_http:error] [pid 254995:tid 255263] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:24.698199 2026] [proxy:error] [pid 254995:tid 255263] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:24.698225 2026] [proxy_http:error] [pid 254995:tid 255263] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:24.744268 2026] [proxy:error] [pid 254995:tid 255141] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:24.744326 2026] [proxy_http:error] [pid 254995:tid 255141] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:24.744754 2026] [proxy:error] [pid 254995:tid 255141] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:24.744785 2026] [proxy_http:error] [pid 254995:tid 255141] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:24.858937 2026] [security2:error] [pid 255769:tid 255831] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MmLxMYwyVGnfuwsKuxQAEIj0"]
[Tue Jul 21 07:40:24.859093 2026] [security2:error] [pid 255769:tid 256028] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MmLxMYwyVGnfuwsKuxQAEIj0"]
[Tue Jul 21 07:40:24.904667 2026] [security2:error] [pid 255769:tid 255935] [client 20.226.60.151:62334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/mac.php"] [unique_id "al9MmLxMYwyVGnfuwsKuxgAAA8c"]
[Tue Jul 21 07:40:24.905393 2026] [security2:error] [pid 255769:tid 255918] [client 4.204.201.85:57457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/199.php"] [unique_id "al9MmLxMYwyVGnfuwsKuxwAAA7Y"]
[Tue Jul 21 07:40:24.978246 2026] [security2:error] [pid 255769:tid 255924] [client 20.104.96.117:14620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/hosty.php"] [unique_id "al9MmLxMYwyVGnfuwsKu0gAAA7w"]
[Tue Jul 21 07:40:25.009073 2026] [security2:error] [pid 255769:tid 255988] [client 4.204.201.85:7463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/100.php"] [unique_id "al9MmbxMYwyVGnfuwsKu1AAAA_w"]
[Tue Jul 21 07:40:25.055074 2026] [proxy:error] [pid 255769:tid 255976] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:25.055138 2026] [proxy_http:error] [pid 255769:tid 255976] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:25.055577 2026] [proxy:error] [pid 255769:tid 255976] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:25.055599 2026] [proxy_http:error] [pid 255769:tid 255976] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:25.077379 2026] [security2:error] [pid 255769:tid 256019] [client 20.226.60.151:59396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/ops.php"] [unique_id "al9MmbxMYwyVGnfuwsKu2gAABBk"]
[Tue Jul 21 07:40:25.174389 2026] [security2:error] [pid 254995:tid 255156] [client 74.7.244.15:55996] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "memoriabalaiodaoxum.com.br"] [uri "/robots.txt"] [unique_id "al9Mmf7v0rlcEGmVraFPFwADPQE"]
[Tue Jul 21 07:40:25.185864 2026] [security2:error] [pid 255769:tid 255942] [client 4.204.201.85:57444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/file52.php"] [unique_id "al9MmbxMYwyVGnfuwsKu3gAAA84"]
[Tue Jul 21 07:40:25.195013 2026] [security2:error] [pid 254995:tid 255177] [client 69.171.230.116:55282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Mmf7v0rlcEGmVraFPFQAAA1I"]
[Tue Jul 21 07:40:25.249746 2026] [proxy:error] [pid 254995:tid 255168] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:25.249838 2026] [proxy_http:error] [pid 254995:tid 255168] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:25.250510 2026] [proxy:error] [pid 254995:tid 255168] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:25.250548 2026] [proxy_http:error] [pid 254995:tid 255168] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:25.275768 2026] [proxy:error] [pid 255769:tid 256014] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:25.275854 2026] [proxy_http:error] [pid 255769:tid 256014] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:25.276515 2026] [proxy:error] [pid 255769:tid 256014] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:25.276540 2026] [proxy_http:error] [pid 255769:tid 256014] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:25.317185 2026] [security2:error] [pid 254995:tid 255211] [client 20.104.96.117:14342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/k.php"] [unique_id "al9Mmf7v0rlcEGmVraFPIQAAA3M"]
[Tue Jul 21 07:40:25.320595 2026] [security2:error] [pid 255769:tid 255836] [remote 212.80.9.235:38622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.9.80.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "trconsultcontabilidade.com"] [uri "/wp-login.php"] [unique_id "al9MmbxMYwyVGnfuwsKu5gAEB0I"]
[Tue Jul 21 07:40:25.340407 2026] [security2:error] [pid 255769:tid 255978] [client 157.245.113.227:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MmbxMYwyVGnfuwsKu5wAAA_I"]
[Tue Jul 21 07:40:25.362919 2026] [security2:error] [pid 255769:tid 255910] [client 167.99.181.249:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MmbxMYwyVGnfuwsKu6AAAA64"]
[Tue Jul 21 07:40:25.402684 2026] [security2:error] [pid 255769:tid 255946] [client 20.151.10.161:46061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xstelth.php"] [unique_id "al9MmbxMYwyVGnfuwsKu6gAAA9I"]
[Tue Jul 21 07:40:25.462163 2026] [security2:error] [pid 255769:tid 255908] [client 4.204.201.85:57436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/geck.php"] [unique_id "al9MmbxMYwyVGnfuwsKu7QAAA6w"]
[Tue Jul 21 07:40:25.530587 2026] [security2:error] [pid 254995:tid 255258] [client 128.127.105.184:43634] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Mmf7v0rlcEGmVraFPIwAAA4g"]
[Tue Jul 21 07:40:25.530686 2026] [security2:error] [pid 254995:tid 255258] [client 128.127.105.184:43634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Mmf7v0rlcEGmVraFPIwAAA4g"]
[Tue Jul 21 07:40:25.567782 2026] [security2:error] [pid 255769:tid 255927] [client 4.204.201.85:3529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/about.php"] [unique_id "al9MmbxMYwyVGnfuwsKu9QAAA78"]
[Tue Jul 21 07:40:25.638242 2026] [security2:error] [pid 254995:tid 255164] [client 20.104.96.117:14345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/aaa.php"] [unique_id "al9Mmf7v0rlcEGmVraFPJQAAA0U"]
[Tue Jul 21 07:40:25.694621 2026] [security2:error] [pid 254995:tid 255122] [remote 104.207.59.203:57855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.59.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9Mmf7v0rlcEGmVraFPJgADIn4"]
[Tue Jul 21 07:40:25.713141 2026] [proxy:error] [pid 255769:tid 256010] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:25.713206 2026] [proxy_http:error] [pid 255769:tid 256010] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:25.713804 2026] [proxy:error] [pid 255769:tid 256010] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:25.713838 2026] [proxy_http:error] [pid 255769:tid 256010] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:25.716969 2026] [security2:error] [pid 255769:tid 255799] [remote 167.172.158.128:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MmbxMYwyVGnfuwsKu_wADpx0"]
[Tue Jul 21 07:40:25.727714 2026] [security2:error] [pid 255769:tid 255938] [client 64.225.75.246:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MmbxMYwyVGnfuwsKvAQAAA8o"]
[Tue Jul 21 07:40:25.737570 2026] [security2:error] [pid 255769:tid 255997] [client 4.204.201.85:57458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/biufile.php"] [unique_id "al9MmbxMYwyVGnfuwsKvAgAABAM"]
[Tue Jul 21 07:40:25.857294 2026] [security2:error] [pid 255769:tid 255928] [client 20.151.10.161:55262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/h02ugyh.php"] [unique_id "al9MmbxMYwyVGnfuwsKvCwAAA8A"]
[Tue Jul 21 07:40:25.972670 2026] [security2:error] [pid 255769:tid 255924] [client 20.104.96.117:14621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/file5.php"] [unique_id "al9MmbxMYwyVGnfuwsKvEQAAA7w"]
[Tue Jul 21 07:40:25.991881 2026] [security2:error] [pid 255769:tid 255990] [client 209.97.180.8:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "al9MmbxMYwyVGnfuwsKvEgAAA_4"]
[Tue Jul 21 07:40:26.007314 2026] [security2:error] [pid 255769:tid 255900] [client 20.151.10.161:46008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-links.php"] [unique_id "al9MmrxMYwyVGnfuwsKvEwAAA6Q"]
[Tue Jul 21 07:40:26.013535 2026] [security2:error] [pid 255769:tid 256009] [client 4.204.201.85:61062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/mosty.php"] [unique_id "al9MmrxMYwyVGnfuwsKvFAAABA8"]
[Tue Jul 21 07:40:26.027769 2026] [security2:error] [pid 255769:tid 255977] [client 147.182.200.94:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MmrxMYwyVGnfuwsKvFQAAA_E"]
[Tue Jul 21 07:40:26.037596 2026] [security2:error] [pid 255769:tid 255999] [client 20.226.60.151:23120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/x.php"] [unique_id "al9MmrxMYwyVGnfuwsKvGQAABAU"]
[Tue Jul 21 07:40:26.051971 2026] [proxy:error] [pid 254995:tid 255209] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:26.052042 2026] [proxy_http:error] [pid 254995:tid 255209] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:26.052493 2026] [proxy:error] [pid 254995:tid 255209] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:26.052514 2026] [proxy_http:error] [pid 254995:tid 255209] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:26.065431 2026] [proxy:error] [pid 255769:tid 256019] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:26.065517 2026] [proxy_http:error] [pid 255769:tid 256019] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:26.066259 2026] [proxy:error] [pid 255769:tid 256019] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:26.066312 2026] [proxy_http:error] [pid 255769:tid 256019] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:26.119149 2026] [security2:error] [pid 255769:tid 255966] [client 167.99.210.137:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al9MmrxMYwyVGnfuwsKvHAAAA-Y"]
[Tue Jul 21 07:40:26.159027 2026] [security2:error] [pid 255769:tid 255975] [client 4.204.201.85:7438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/about.php"] [unique_id "al9MmrxMYwyVGnfuwsKvIgAAA-8"]
[Tue Jul 21 07:40:26.287773 2026] [security2:error] [pid 254995:tid 255201] [client 4.204.201.85:59958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/dejavu.php"] [unique_id "al9Mmv7v0rlcEGmVraFPNQAAA2o"]
[Tue Jul 21 07:40:26.292255 2026] [security2:error] [pid 255769:tid 255940] [client 202.143.127.214:61980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MmrxMYwyVGnfuwsKvKAAAA8w"]
[Tue Jul 21 07:40:26.292368 2026] [security2:error] [pid 255769:tid 255940] [client 202.143.127.214:61980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MmrxMYwyVGnfuwsKvKAAAA8w"]
[Tue Jul 21 07:40:26.350328 2026] [security2:error] [pid 254995:tid 255266] [client 20.104.96.117:14349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/222.php"] [unique_id "al9Mmv7v0rlcEGmVraFPNwAAA5A"]
[Tue Jul 21 07:40:26.384158 2026] [security2:error] [pid 255769:tid 255804] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MmrxMYwyVGnfuwsKvLwAEHiI"]
[Tue Jul 21 07:40:26.384320 2026] [security2:error] [pid 255769:tid 256024] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MmrxMYwyVGnfuwsKvLwAEHiI"]
[Tue Jul 21 07:40:26.546059 2026] [security2:error] [pid 255769:tid 255970] [client 207.154.197.113:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MmrxMYwyVGnfuwsKvOAAAA-o"]
[Tue Jul 21 07:40:26.559559 2026] [security2:error] [pid 255769:tid 256012] [client 154.192.233.199:58837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MmrxMYwyVGnfuwsKvOgAABBI"]
[Tue Jul 21 07:40:26.559642 2026] [security2:error] [pid 255769:tid 256012] [client 154.192.233.199:58837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MmrxMYwyVGnfuwsKvOgAABBI"]
[Tue Jul 21 07:40:26.567652 2026] [security2:error] [pid 255769:tid 255903] [client 4.204.201.85:61075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/aaf.php"] [unique_id "al9MmrxMYwyVGnfuwsKvPAAAA6c"]
[Tue Jul 21 07:40:26.652819 2026] [security2:error] [pid 255769:tid 255934] [client 20.104.96.117:14363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/test.php"] [unique_id "al9MmrxMYwyVGnfuwsKvPwAAA8Y"]
[Tue Jul 21 07:40:26.711603 2026] [security2:error] [pid 255769:tid 255809] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MmrxMYwyVGnfuwsKvQgADyic"]
[Tue Jul 21 07:40:26.711773 2026] [security2:error] [pid 255769:tid 255938] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MmrxMYwyVGnfuwsKvQgADyic"]
[Tue Jul 21 07:40:26.716202 2026] [security2:error] [pid 255769:tid 255952] [client 142.93.129.190:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al9MmrxMYwyVGnfuwsKvQwAAA9g"]
[Tue Jul 21 07:40:26.764865 2026] [security2:error] [pid 255769:tid 255841] [remote 74.7.241.42:47696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MmrxMYwyVGnfuwsKvPQAD1kc"], referer: https://app.institutocrismonteiro.com.br/2023/05/31/enfrentrando-o-desafio-de-um-marido-preguicoso/
[Tue Jul 21 07:40:26.768008 2026] [security2:error] [pid 255769:tid 255905] [client 4.204.201.85:7470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/admin.php"] [unique_id "al9MmrxMYwyVGnfuwsKvSgAAA6k"]
[Tue Jul 21 07:40:26.848858 2026] [security2:error] [pid 254995:tid 255272] [client 4.204.201.85:59964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/ha.php"] [unique_id "al9Mmv7v0rlcEGmVraFPPwAAA5Y"]
[Tue Jul 21 07:40:26.985194 2026] [security2:error] [pid 254995:tid 255188] [client 20.104.96.117:14536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/aaa.php"] [unique_id "al9Mmv7v0rlcEGmVraFPQgAAA10"]
[Tue Jul 21 07:40:27.124883 2026] [security2:error] [pid 254995:tid 255203] [client 4.204.201.85:61089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/hur.php"] [unique_id "al9Mm_7v0rlcEGmVraFPQwAAA2w"]
[Tue Jul 21 07:40:27.147250 2026] [security2:error] [pid 255769:tid 255796] [remote 57.141.18.61:25178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/wp-sitemap-taxonomies-category-1.xml"] [unique_id "al9MmrxMYwyVGnfuwsKvHgAD_Bo"]
[Tue Jul 21 07:40:27.188462 2026] [security2:error] [pid 254995:tid 255214] [client 139.59.143.102:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "al9Mm_7v0rlcEGmVraFPRQAAA3Y"]
[Tue Jul 21 07:40:27.206609 2026] [security2:error] [pid 255769:tid 255978] [client 20.226.60.151:62330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/mg.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvVAAAA_I"]
[Tue Jul 21 07:40:27.212743 2026] [security2:error] [pid 255769:tid 255910] [client 20.151.10.161:46027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvVQAAA64"]
[Tue Jul 21 07:40:27.224608 2026] [security2:error] [pid 254995:tid 255166] [client 20.226.60.151:59419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/mac.php"] [unique_id "al9Mm_7v0rlcEGmVraFPRgAAA0c"]
[Tue Jul 21 07:40:27.303505 2026] [security2:error] [pid 255769:tid 255946] [client 20.104.96.117:14622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/11.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvVgAAA9I"]
[Tue Jul 21 07:40:27.393430 2026] [security2:error] [pid 255769:tid 255979] [client 175.45.70.82:54797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvXgAAA_M"]
[Tue Jul 21 07:40:27.393593 2026] [security2:error] [pid 255769:tid 255979] [client 175.45.70.82:54797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvXgAAA_M"]
[Tue Jul 21 07:40:27.400251 2026] [security2:error] [pid 255769:tid 256012] [client 4.204.201.85:59942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/h02ugyh.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvXwAABBI"]
[Tue Jul 21 07:40:27.416065 2026] [security2:error] [pid 255769:tid 255918] [client 122.164.127.47:64243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvYAAAA7Y"]
[Tue Jul 21 07:40:27.416274 2026] [security2:error] [pid 255769:tid 255918] [client 122.164.127.47:64243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvYAAAA7Y"]
[Tue Jul 21 07:40:27.503848 2026] [security2:error] [pid 255769:tid 255974] [client 173.252.95.25:63062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9MmrxMYwyVGnfuwsKvKwAAA-4"]
[Tue Jul 21 07:40:27.541391 2026] [security2:error] [pid 254995:tid 255193] [client 182.8.255.181:17586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Mm_7v0rlcEGmVraFPUAAAA2I"]
[Tue Jul 21 07:40:27.541930 2026] [security2:error] [pid 254995:tid 255193] [client 182.8.255.181:17586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Mm_7v0rlcEGmVraFPUAAAA2I"]
[Tue Jul 21 07:40:27.566190 2026] [security2:error] [pid 254995:tid 255220] [client 4.204.201.85:7440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/admin.php"] [unique_id "al9Mm_7v0rlcEGmVraFPUgAAA3w"]
[Tue Jul 21 07:40:27.576437 2026] [security2:error] [pid 254995:tid 255092] [remote 206.189.95.232:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9Mm_7v0rlcEGmVraFPUwADNWA"]
[Tue Jul 21 07:40:27.594105 2026] [security2:error] [pid 255769:tid 255935] [client 207.154.212.47:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "al9Mm7xMYwyVGnfuwsKvZgAAA8c"]
[Tue Jul 21 07:40:27.648434 2026] [security2:error] [pid 254995:tid 255128] [client 103.86.117.203:63017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mm_7v0rlcEGmVraFPVAAAAyE"]
[Tue Jul 21 07:40:27.648600 2026] [security2:error] [pid 254995:tid 255128] [client 103.86.117.203:63017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mm_7v0rlcEGmVraFPVAAAAyE"]
[Tue Jul 21 07:40:27.678363 2026] [security2:error] [pid 255769:tid 255912] [client 4.204.201.85:61068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/155.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvaAAAA7A"]
[Tue Jul 21 07:40:27.687307 2026] [security2:error] [pid 254995:tid 255276] [client 20.104.96.117:14338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/mac.php"] [unique_id "al9Mm_7v0rlcEGmVraFPVgAAA5o"]
[Tue Jul 21 07:40:27.709853 2026] [security2:error] [pid 254995:tid 255211] [client 142.93.143.8:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9Mm_7v0rlcEGmVraFPVwAAA3M"]
[Tue Jul 21 07:40:27.712345 2026] [security2:error] [pid 255769:tid 255924] [client 206.81.12.187:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "al9Mm7xMYwyVGnfuwsKvagAAA7w"]
[Tue Jul 21 07:40:27.716675 2026] [security2:error] [pid 254995:tid 255155] [client 103.106.20.201:61678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mm_7v0rlcEGmVraFPWAAAAzw"]
[Tue Jul 21 07:40:27.716791 2026] [security2:error] [pid 254995:tid 255155] [client 103.106.20.201:61678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mm_7v0rlcEGmVraFPWAAAAzw"]
[Tue Jul 21 07:40:27.720647 2026] [security2:error] [pid 255769:tid 255896] [remote 38.242.157.30:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/wp-login.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvawADwH4"]
[Tue Jul 21 07:40:27.722184 2026] [security2:error] [pid 254995:tid 255190] [client 122.162.144.145:4482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Mm_7v0rlcEGmVraFPWgAAA18"]
[Tue Jul 21 07:40:27.722270 2026] [security2:error] [pid 254995:tid 255190] [client 122.162.144.145:4482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Mm_7v0rlcEGmVraFPWgAAA18"]
[Tue Jul 21 07:40:27.759284 2026] [security2:error] [pid 255769:tid 255906] [client 136.144.33.103:64397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvbQAAA6o"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:27.876500 2026] [security2:error] [pid 255769:tid 255966] [client 20.220.225.223:31904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/inso.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvdAAAA-Y"]
[Tue Jul 21 07:40:27.882078 2026] [security2:error] [pid 255769:tid 255842] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9Mm7xMYwyVGnfuwsKvdQAD00g"]
[Tue Jul 21 07:40:27.917625 2026] [security2:error] [pid 255769:tid 255902] [client 74.7.241.153:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "entrepaginasepratos.com.br"] [uri "/index.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvaQAAA6Y"]
[Tue Jul 21 07:40:27.918456 2026] [security2:error] [pid 255769:tid 255915] [client 74.7.241.153:56780] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "entrepaginasepratos.com.br"] [uri "/robots.txt"] [unique_id "al9Mm7xMYwyVGnfuwsKvZwADs2s"]
[Tue Jul 21 07:40:27.955066 2026] [security2:error] [pid 255769:tid 256026] [client 4.204.201.85:57437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/pp.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvewAABCA"]
[Tue Jul 21 07:40:27.974038 2026] [proxy:error] [pid 255769:tid 255967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:27.974089 2026] [proxy_http:error] [pid 255769:tid 255967] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:27.974538 2026] [proxy:error] [pid 255769:tid 255967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:27.974561 2026] [proxy_http:error] [pid 255769:tid 255967] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:28.044653 2026] [security2:error] [pid 254995:tid 255216] [client 20.151.10.161:46052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/aaa.php"] [unique_id "al9MnP7v0rlcEGmVraFPXwAAA3g"]
[Tue Jul 21 07:40:28.059602 2026] [security2:error] [pid 254995:tid 255125] [client 20.104.96.117:14369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/chosen.php"] [unique_id "al9MnP7v0rlcEGmVraFPYAAAAx4"]
[Tue Jul 21 07:40:28.144569 2026] [core:error] [pid 254995:tid 255063] [remote 52.167.144.162:43271] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:40:28.144595 2026] [core:error] [pid 254995:tid 255063] [remote 52.167.144.162:43271] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:40:28.195485 2026] [proxy:error] [pid 254995:tid 255165] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:28.195554 2026] [proxy_http:error] [pid 254995:tid 255165] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:28.196112 2026] [proxy:error] [pid 254995:tid 255165] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:28.196141 2026] [proxy_http:error] [pid 254995:tid 255165] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:28.245374 2026] [security2:error] [pid 255769:tid 255945] [client 4.204.201.85:59927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/ops.php"] [unique_id "al9MnLxMYwyVGnfuwsKvggAAA9E"]
[Tue Jul 21 07:40:28.282009 2026] [security2:error] [pid 255769:tid 255887] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9MnLxMYwyVGnfuwsKvgwAEAnU"]
[Tue Jul 21 07:40:28.373652 2026] [security2:error] [pid 254995:tid 255131] [client 20.104.96.117:14351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/cream1.php"] [unique_id "al9MnP7v0rlcEGmVraFPaQAAAyQ"]
[Tue Jul 21 07:40:28.440663 2026] [security2:error] [pid 255769:tid 256027] [client 4.204.201.85:7471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/themes.php"] [unique_id "al9MnLxMYwyVGnfuwsKvhwAABCE"]
[Tue Jul 21 07:40:28.480792 2026] [security2:error] [pid 255769:tid 255794] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MnLxMYwyVGnfuwsKviQAEFhg"]
[Tue Jul 21 07:40:28.480946 2026] [security2:error] [pid 255769:tid 256016] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MnLxMYwyVGnfuwsKviQAEFhg"]
[Tue Jul 21 07:40:28.524162 2026] [security2:error] [pid 255769:tid 255912] [client 4.204.201.85:59904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/ingfo.php"] [unique_id "al9MnLxMYwyVGnfuwsKvigAAA7A"]
[Tue Jul 21 07:40:28.621809 2026] [security2:error] [pid 255769:tid 255990] [client 209.38.208.202:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "al9MnLxMYwyVGnfuwsKvjAAAA_4"]
[Tue Jul 21 07:40:28.658552 2026] [security2:error] [pid 255769:tid 256028] [client 164.92.244.132:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "al9MnLxMYwyVGnfuwsKvjQAABCI"]
[Tue Jul 21 07:40:28.674351 2026] [security2:error] [pid 255769:tid 255771] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9MnLxMYwyVGnfuwsKvjwADqQE"]
[Tue Jul 21 07:40:28.675079 2026] [security2:error] [pid 254995:tid 255136] [client 35.185.62.194:64634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.62.185.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sweetrip.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MnP7v0rlcEGmVraFPdAAAAyk"]
[Tue Jul 21 07:40:28.707510 2026] [proxy:error] [pid 255769:tid 255960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:28.707561 2026] [proxy_http:error] [pid 255769:tid 255960] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:28.707992 2026] [proxy:error] [pid 255769:tid 255960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:28.708027 2026] [proxy_http:error] [pid 255769:tid 255960] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:28.803903 2026] [security2:error] [pid 255769:tid 255980] [client 4.204.201.85:57449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/error_log.php"] [unique_id "al9MnLxMYwyVGnfuwsKvmAAAA_Q"]
[Tue Jul 21 07:40:28.811757 2026] [proxy:error] [pid 255769:tid 256011] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:28.811852 2026] [proxy_http:error] [pid 255769:tid 256011] [client 20.104.96.117:14619] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:28.812458 2026] [proxy:error] [pid 255769:tid 256011] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:28.812483 2026] [proxy_http:error] [pid 255769:tid 256011] [client 20.104.96.117:14619] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:28.864600 2026] [security2:error] [pid 255769:tid 256004] [client 20.226.60.151:62235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-post-data.php"] [unique_id "al9MnLxMYwyVGnfuwsKvmgAABAo"]
[Tue Jul 21 07:40:28.984200 2026] [security2:error] [pid 255769:tid 255926] [client 20.226.60.151:59475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/mg.php"] [unique_id "al9MnLxMYwyVGnfuwsKvoAAAA74"]
[Tue Jul 21 07:40:29.080104 2026] [security2:error] [pid 255769:tid 255951] [client 4.204.201.85:59940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/test10.php"] [unique_id "al9MnbxMYwyVGnfuwsKvoQAAA9c"]
[Tue Jul 21 07:40:29.088157 2026] [security2:error] [pid 255769:tid 255987] [client 35.185.62.194:51846] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sweetrip.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9MnbxMYwyVGnfuwsKvogAAA_s"]
[Tue Jul 21 07:40:29.160109 2026] [proxy:error] [pid 255769:tid 255940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:29.160182 2026] [proxy_http:error] [pid 255769:tid 255940] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:29.160631 2026] [proxy:error] [pid 255769:tid 255940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:29.160652 2026] [proxy_http:error] [pid 255769:tid 255940] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:29.184714 2026] [security2:error] [pid 255769:tid 255773] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9MnbxMYwyVGnfuwsKvqAAEGwM"]
[Tue Jul 21 07:40:29.186369 2026] [proxy:error] [pid 255769:tid 256017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:29.186426 2026] [proxy_http:error] [pid 255769:tid 256017] [client 20.104.96.117:14592] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:29.186939 2026] [proxy:error] [pid 255769:tid 256017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:29.186967 2026] [proxy_http:error] [pid 255769:tid 256017] [client 20.104.96.117:14592] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:29.364314 2026] [security2:error] [pid 254995:tid 255169] [client 4.204.201.85:57446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/koala.php"] [unique_id "al9Mnf7v0rlcEGmVraFPfQAAA0o"]
[Tue Jul 21 07:40:29.384829 2026] [security2:error] [pid 255769:tid 255943] [client 20.226.60.151:23152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/155.php"] [unique_id "al9MnbxMYwyVGnfuwsKvrwAAA88"]
[Tue Jul 21 07:40:29.385076 2026] [security2:error] [pid 255769:tid 255903] [client 35.185.62.194:63539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sweetrip.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9MnbxMYwyVGnfuwsKvsAAAA6c"]
[Tue Jul 21 07:40:29.388406 2026] [security2:error] [pid 255769:tid 255949] [client 20.220.225.223:19666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/dr.php"] [unique_id "al9MnbxMYwyVGnfuwsKvsQAAA9U"]
[Tue Jul 21 07:40:29.423590 2026] [security2:error] [pid 255769:tid 255934] [client 128.199.182.152:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MnbxMYwyVGnfuwsKvtgAAA8Y"]
[Tue Jul 21 07:40:29.502540 2026] [security2:error] [pid 255769:tid 255938] [client 152.59.154.239:65398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MnbxMYwyVGnfuwsKvugAAA8o"]
[Tue Jul 21 07:40:29.507204 2026] [security2:error] [pid 255769:tid 255938] [client 152.59.154.239:65398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MnbxMYwyVGnfuwsKvugAAA8o"]
[Tue Jul 21 07:40:29.579551 2026] [security2:error] [pid 254995:tid 255177] [client 20.104.96.117:14374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/dr.php"] [unique_id "al9Mnf7v0rlcEGmVraFPhAAAA1I"]
[Tue Jul 21 07:40:29.594568 2026] [security2:error] [pid 255769:tid 255851] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9MnbxMYwyVGnfuwsKvuwAD4FE"]
[Tue Jul 21 07:40:29.610782 2026] [security2:error] [pid 254995:tid 255156] [client 20.226.60.151:56318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/classwithtostring.php"] [unique_id "al9Mnf7v0rlcEGmVraFPhgAAAz0"]
[Tue Jul 21 07:40:29.639655 2026] [security2:error] [pid 254995:tid 255193] [client 4.204.201.85:57463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/mac.php"] [unique_id "al9Mnf7v0rlcEGmVraFPhwAAA2I"]
[Tue Jul 21 07:40:29.673736 2026] [security2:error] [pid 254995:tid 255150] [client 35.185.62.194:58708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sweetrip.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9Mnf7v0rlcEGmVraFPiAAAAzc"]
[Tue Jul 21 07:40:29.680718 2026] [security2:error] [pid 255769:tid 255975] [client 59.96.220.140:51597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MnbxMYwyVGnfuwsKvwAAAA-8"]
[Tue Jul 21 07:40:29.681316 2026] [security2:error] [pid 255769:tid 255975] [client 59.96.220.140:51597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MnbxMYwyVGnfuwsKvwAAAA-8"]
[Tue Jul 21 07:40:29.872182 2026] [security2:error] [pid 255769:tid 255956] [client 20.226.60.151:59434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-post-data.php"] [unique_id "al9MnbxMYwyVGnfuwsKvxwAAA9w"]
[Tue Jul 21 07:40:29.875645 2026] [security2:error] [pid 255769:tid 255908] [client 20.104.96.117:14382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/x.php"] [unique_id "al9MnbxMYwyVGnfuwsKvyAAAA6w"]
[Tue Jul 21 07:40:29.924712 2026] [security2:error] [pid 255769:tid 255958] [client 4.204.201.85:57465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wefile.php"] [unique_id "al9MnbxMYwyVGnfuwsKvygAAA94"]
[Tue Jul 21 07:40:30.090664 2026] [security2:error] [pid 254995:tid 255138] [client 35.185.62.194:63334] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sweetrip.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9Mnv7v0rlcEGmVraFPlAAAAys"]
[Tue Jul 21 07:40:30.101328 2026] [security2:error] [pid 255769:tid 255986] [client 194.99.104.35:34976] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MnrxMYwyVGnfuwsKv0QAAA_o"]
[Tue Jul 21 07:40:30.101425 2026] [security2:error] [pid 255769:tid 255986] [client 194.99.104.35:34976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MnrxMYwyVGnfuwsKv0QAAA_o"]
[Tue Jul 21 07:40:30.103172 2026] [security2:error] [pid 255769:tid 255927] [client 62.102.148.187:49200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9MnrxMYwyVGnfuwsKv0wAAA78"]
[Tue Jul 21 07:40:30.103279 2026] [security2:error] [pid 255769:tid 255927] [client 62.102.148.187:49200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9MnrxMYwyVGnfuwsKv0wAAA78"]
[Tue Jul 21 07:40:30.178014 2026] [security2:error] [pid 255769:tid 255853] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9MnrxMYwyVGnfuwsKv1wAEElM"]
[Tue Jul 21 07:40:30.213268 2026] [proxy:error] [pid 255769:tid 255919] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:30.213361 2026] [proxy_http:error] [pid 255769:tid 255919] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:30.213860 2026] [proxy:error] [pid 255769:tid 255919] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:30.213901 2026] [proxy_http:error] [pid 255769:tid 255919] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:30.221800 2026] [autoindex:error] [pid 254995:tid 255205] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:30.285637 2026] [security2:error] [pid 255769:tid 255953] [client 20.220.225.223:32294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/wpx.php"] [unique_id "al9MnrxMYwyVGnfuwsKv2wAAA9k"]
[Tue Jul 21 07:40:30.319322 2026] [security2:error] [pid 254995:tid 255196] [client 20.104.96.117:14380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/155.php"] [unique_id "al9Mnv7v0rlcEGmVraFPlwAAA2U"]
[Tue Jul 21 07:40:30.322275 2026] [security2:error] [pid 254995:tid 255148] [client 103.174.34.15:50808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mnv7v0rlcEGmVraFPmAAAAzU"]
[Tue Jul 21 07:40:30.322374 2026] [security2:error] [pid 254995:tid 255148] [client 103.174.34.15:50808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mnv7v0rlcEGmVraFPmAAAAzU"]
[Tue Jul 21 07:40:30.343071 2026] [security2:error] [pid 255769:tid 255875] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9MnrxMYwyVGnfuwsKv3QADq2k"]
[Tue Jul 21 07:40:30.416037 2026] [security2:error] [pid 255769:tid 255944] [client 117.217.38.194:60321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MnrxMYwyVGnfuwsKv4AAAA9A"]
[Tue Jul 21 07:40:30.416160 2026] [security2:error] [pid 255769:tid 255944] [client 117.217.38.194:60321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MnrxMYwyVGnfuwsKv4AAAA9A"]
[Tue Jul 21 07:40:30.455967 2026] [security2:error] [pid 254995:tid 255161] [client 35.185.62.194:56510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sweetrip.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9Mnv7v0rlcEGmVraFPngAAA0I"]
[Tue Jul 21 07:40:30.471725 2026] [security2:error] [pid 254995:tid 255033] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mnv7v0rlcEGmVraFPoAADeiU"]
[Tue Jul 21 07:40:30.471852 2026] [security2:error] [pid 254995:tid 255218] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mnv7v0rlcEGmVraFPoAADeiU"]
[Tue Jul 21 07:40:30.543778 2026] [autoindex:error] [pid 255769:tid 255938] [client 4.204.201.85:61061] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:30.567275 2026] [proxy:error] [pid 255769:tid 256028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:30.567345 2026] [proxy_http:error] [pid 255769:tid 256028] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:30.567970 2026] [proxy:error] [pid 255769:tid 256028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:30.567991 2026] [proxy_http:error] [pid 255769:tid 256028] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:30.617768 2026] [security2:error] [pid 255769:tid 256022] [client 20.104.96.117:14396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/ops.php"] [unique_id "al9MnrxMYwyVGnfuwsKv6AAABBw"]
[Tue Jul 21 07:40:30.662487 2026] [security2:error] [pid 255769:tid 255982] [client 20.226.60.151:59453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/pucci.php"] [unique_id "al9MnrxMYwyVGnfuwsKv6QAAA_Y"]
[Tue Jul 21 07:40:30.681839 2026] [security2:error] [pid 255769:tid 255947] [client 4.204.201.85:61061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/makeasmtp.php"] [unique_id "al9MnrxMYwyVGnfuwsKv6wAAA9M"]
[Tue Jul 21 07:40:30.705619 2026] [proxy:error] [pid 254995:tid 255174] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:30.705694 2026] [proxy_http:error] [pid 254995:tid 255174] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:30.706256 2026] [proxy:error] [pid 254995:tid 255174] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:30.706284 2026] [proxy_http:error] [pid 254995:tid 255174] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:30.797607 2026] [security2:error] [pid 255769:tid 255940] [client 139.167.225.182:58509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MnrxMYwyVGnfuwsKv7QAAA8w"]
[Tue Jul 21 07:40:30.797712 2026] [security2:error] [pid 255769:tid 255940] [client 139.167.225.182:58509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MnrxMYwyVGnfuwsKv7QAAA8w"]
[Tue Jul 21 07:40:30.814648 2026] [security2:error] [pid 254995:tid 255126] [client 35.185.62.194:65285] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sweetrip.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9Mnv7v0rlcEGmVraFPqwAAAx8"]
[Tue Jul 21 07:40:30.879831 2026] [security2:error] [pid 255769:tid 255805] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9MnrxMYwyVGnfuwsKv8AAD_CM"]
[Tue Jul 21 07:40:30.946235 2026] [security2:error] [pid 254995:tid 255144] [client 20.104.96.117:14618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/file31.php"] [unique_id "al9Mnv7v0rlcEGmVraFPrQAAAzE"]
[Tue Jul 21 07:40:30.958062 2026] [security2:error] [pid 254995:tid 255266] [client 4.204.201.85:61078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/2P.php"] [unique_id "al9Mnv7v0rlcEGmVraFPrgAAA5A"]
[Tue Jul 21 07:40:31.009979 2026] [security2:error] [pid 255769:tid 255943] [client 122.179.91.63:23721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Mn7xMYwyVGnfuwsKv8QAAA88"]
[Tue Jul 21 07:40:31.010106 2026] [security2:error] [pid 255769:tid 255943] [client 122.179.91.63:23721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Mn7xMYwyVGnfuwsKv8QAAA88"]
[Tue Jul 21 07:40:31.064762 2026] [security2:error] [pid 255769:tid 255890] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Mn7xMYwyVGnfuwsKv9gAEIHg"]
[Tue Jul 21 07:40:31.088524 2026] [proxy:error] [pid 254995:tid 255160] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.088572 2026] [proxy_http:error] [pid 254995:tid 255160] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:31.089081 2026] [proxy:error] [pid 254995:tid 255160] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.089107 2026] [proxy_http:error] [pid 254995:tid 255160] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:31.195655 2026] [security2:error] [pid 255769:tid 255986] [client 35.185.62.194:59638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sweetrip.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Mn7xMYwyVGnfuwsKv_QAAA_o"]
[Tue Jul 21 07:40:31.234380 2026] [security2:error] [pid 255769:tid 255900] [client 4.204.201.85:59953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/.well-known/about.php"] [unique_id "al9Mn7xMYwyVGnfuwsKv_gAAA6Q"]
[Tue Jul 21 07:40:31.261314 2026] [proxy:error] [pid 254995:tid 255225] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.261376 2026] [proxy_http:error] [pid 254995:tid 255225] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:31.262046 2026] [proxy:error] [pid 254995:tid 255225] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.262075 2026] [proxy_http:error] [pid 254995:tid 255225] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:31.265114 2026] [security2:error] [pid 254995:tid 255166] [client 20.104.96.117:14388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/file6.php"] [unique_id "al9Mn_7v0rlcEGmVraFPvwAAA0c"]
[Tue Jul 21 07:40:31.282092 2026] [security2:error] [pid 254995:tid 255260] [client 20.151.10.161:55241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/seiso.php"] [unique_id "al9Mn_7v0rlcEGmVraFPwAAAA4o"]
[Tue Jul 21 07:40:31.323969 2026] [security2:error] [pid 254995:tid 255194] [client 20.226.60.151:62307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/pucci.php"] [unique_id "al9Mn_7v0rlcEGmVraFPwQAAA2M"]
[Tue Jul 21 07:40:31.374799 2026] [security2:error] [pid 255769:tid 255847] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Mn7xMYwyVGnfuwsKwAAADxU0"]
[Tue Jul 21 07:40:31.484292 2026] [security2:error] [pid 255769:tid 255907] [client 35.185.62.194:62827] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sweetrip.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Mn7xMYwyVGnfuwsKwBQAAA6s"]
[Tue Jul 21 07:40:31.512653 2026] [security2:error] [pid 254995:tid 255150] [client 4.204.201.85:60374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9Mn_7v0rlcEGmVraFPxAAAAzc"]
[Tue Jul 21 07:40:31.549809 2026] [proxy:error] [pid 255769:tid 256027] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.549906 2026] [proxy_http:error] [pid 255769:tid 256027] [client 20.104.96.117:14367] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:31.550467 2026] [proxy:error] [pid 255769:tid 256027] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.550506 2026] [proxy_http:error] [pid 255769:tid 256027] [client 20.104.96.117:14367] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:31.559126 2026] [security2:error] [pid 255769:tid 255934] [client 20.226.60.151:62331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/black.php"] [unique_id "al9Mn7xMYwyVGnfuwsKwDQAAA8Y"]
[Tue Jul 21 07:40:31.582216 2026] [security2:error] [pid 255769:tid 255916] [client 193.36.225.64:39519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Mn7xMYwyVGnfuwsKwAgAAA7Q"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:31.630215 2026] [proxy:error] [pid 254995:tid 255190] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.630276 2026] [proxy_http:error] [pid 254995:tid 255190] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:31.630739 2026] [proxy:error] [pid 254995:tid 255190] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.630768 2026] [proxy_http:error] [pid 254995:tid 255190] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:31.699919 2026] [proxy:error] [pid 255769:tid 255999] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.699978 2026] [proxy_http:error] [pid 255769:tid 255999] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:31.700435 2026] [proxy:error] [pid 255769:tid 255999] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.700732 2026] [security2:error] [pid 255769:tid 255774] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9Mn7xMYwyVGnfuwsKwGAAEHAQ"]
[Tue Jul 21 07:40:31.701089 2026] [proxy_http:error] [pid 255769:tid 255999] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:31.713899 2026] [security2:error] [pid 255769:tid 255850] [remote 77.90.2.3:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.2.90.77.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9Mn7xMYwyVGnfuwsKwGQADrVA"]
[Tue Jul 21 07:40:31.789780 2026] [security2:error] [pid 255769:tid 255911] [client 4.204.201.85:57454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/system_log.php"] [unique_id "al9Mn7xMYwyVGnfuwsKwHQAAA68"]
[Tue Jul 21 07:40:31.848726 2026] [security2:error] [pid 254995:tid 255222] [client 20.220.225.223:19668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/2x.php"] [unique_id "al9Mn_7v0rlcEGmVraFP1wAAA34"]
[Tue Jul 21 07:40:31.859309 2026] [security2:error] [pid 254995:tid 255271] [client 35.185.62.194:64653] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sweetrip.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Mn_7v0rlcEGmVraFP2gAAA5U"]
[Tue Jul 21 07:40:31.899487 2026] [security2:error] [pid 255769:tid 256013] [client 20.104.96.117:14648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/adminfuns.php"] [unique_id "al9Mn7xMYwyVGnfuwsKwIAAABBM"]
[Tue Jul 21 07:40:31.939143 2026] [security2:error] [pid 255769:tid 255891] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9Mn7xMYwyVGnfuwsKwIwAEGXk"]
[Tue Jul 21 07:40:31.988546 2026] [proxy:error] [pid 255769:tid 255977] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.988608 2026] [proxy_http:error] [pid 255769:tid 255977] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:31.989217 2026] [proxy:error] [pid 255769:tid 255977] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.989244 2026] [proxy_http:error] [pid 255769:tid 255977] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.056119 2026] [proxy:error] [pid 255769:tid 256017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.056186 2026] [proxy_http:error] [pid 255769:tid 256017] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.056752 2026] [proxy:error] [pid 255769:tid 256017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.056775 2026] [proxy_http:error] [pid 255769:tid 256017] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.065793 2026] [security2:error] [pid 254995:tid 255209] [client 20.151.10.161:55233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/155.php"] [unique_id "al9MoP7v0rlcEGmVraFP4gAAA3E"]
[Tue Jul 21 07:40:32.125150 2026] [autoindex:error] [pid 254995:tid 255140] [client 4.204.201.85:57424] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:32.153074 2026] [proxy:error] [pid 255769:tid 255996] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.153146 2026] [proxy_http:error] [pid 255769:tid 255996] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.154007 2026] [proxy:error] [pid 255769:tid 255996] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.154038 2026] [proxy_http:error] [pid 255769:tid 255996] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.259505 2026] [security2:error] [pid 255769:tid 255933] [client 20.104.96.117:14373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/goods.php"] [unique_id "al9MoLxMYwyVGnfuwsKwNQAAA8U"]
[Tue Jul 21 07:40:32.320389 2026] [security2:error] [pid 255769:tid 255953] [client 4.204.201.85:7486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/.well-known/about.php"] [unique_id "al9MoLxMYwyVGnfuwsKwNwAAA9k"]
[Tue Jul 21 07:40:32.329537 2026] [security2:error] [pid 255769:tid 255974] [client 35.185.62.194:65406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sweetrip.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9MoLxMYwyVGnfuwsKwOAAAA-4"]
[Tue Jul 21 07:40:32.342346 2026] [proxy:error] [pid 255769:tid 255964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.342415 2026] [proxy_http:error] [pid 255769:tid 255964] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.343015 2026] [proxy:error] [pid 255769:tid 255964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.343042 2026] [proxy_http:error] [pid 255769:tid 255964] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.407631 2026] [proxy:error] [pid 255769:tid 255907] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.407701 2026] [proxy_http:error] [pid 255769:tid 255907] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.408337 2026] [proxy:error] [pid 255769:tid 255907] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.408376 2026] [proxy_http:error] [pid 255769:tid 255907] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.459834 2026] [autoindex:error] [pid 254995:tid 255174] [client 4.204.201.85:57424] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:32.586969 2026] [security2:error] [pid 254995:tid 255144] [client 20.104.96.117:14390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/100.php"] [unique_id "al9MoP7v0rlcEGmVraFP7QAAAzE"]
[Tue Jul 21 07:40:32.598208 2026] [security2:error] [pid 254995:tid 255266] [client 4.204.201.85:57424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/crgio.php"] [unique_id "al9MoP7v0rlcEGmVraFP7gAAA5A"]
[Tue Jul 21 07:40:32.609633 2026] [proxy:error] [pid 255769:tid 255913] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.609704 2026] [proxy_http:error] [pid 255769:tid 255913] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.610357 2026] [proxy:error] [pid 255769:tid 255913] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.610394 2026] [proxy_http:error] [pid 255769:tid 255913] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.630658 2026] [security2:error] [pid 255769:tid 255916] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9MoLxMYwyVGnfuwsKwQwAAA7Q"]
[Tue Jul 21 07:40:32.644520 2026] [security2:error] [pid 254995:tid 255192] [client 184.75.223.211:40134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9MoP7v0rlcEGmVraFP9AAAA2E"]
[Tue Jul 21 07:40:32.644649 2026] [security2:error] [pid 254995:tid 255192] [client 184.75.223.211:40134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9MoP7v0rlcEGmVraFP9AAAA2E"]
[Tue Jul 21 07:40:32.657743 2026] [security2:error] [pid 255769:tid 255990] [client 20.226.60.151:56253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/root.php"] [unique_id "al9MoLxMYwyVGnfuwsKwRAAAA_4"]
[Tue Jul 21 07:40:32.667014 2026] [security2:error] [pid 255769:tid 256010] [client 20.151.10.161:55263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ppp.php"] [unique_id "al9MoLxMYwyVGnfuwsKwRQAABBA"]
[Tue Jul 21 07:40:32.706728 2026] [proxy:error] [pid 254995:tid 255160] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.706793 2026] [proxy_http:error] [pid 254995:tid 255160] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.707417 2026] [proxy:error] [pid 254995:tid 255160] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.707444 2026] [proxy_http:error] [pid 254995:tid 255160] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.710469 2026] [proxy:error] [pid 255769:tid 255906] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.710532 2026] [proxy_http:error] [pid 255769:tid 255906] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.711138 2026] [proxy:error] [pid 255769:tid 255906] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.711166 2026] [proxy_http:error] [pid 255769:tid 255906] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.769539 2026] [proxy:error] [pid 255769:tid 255920] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.769604 2026] [proxy_http:error] [pid 255769:tid 255920] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.770183 2026] [proxy:error] [pid 255769:tid 255920] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.770209 2026] [proxy_http:error] [pid 255769:tid 255920] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.816028 2026] [security2:error] [pid 255769:tid 255936] [client 20.226.60.151:23159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/ops.php"] [unique_id "al9MoLxMYwyVGnfuwsKwSgAAA8g"]
[Tue Jul 21 07:40:32.874257 2026] [security2:error] [pid 255769:tid 255966] [client 4.204.201.85:56542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/pucci.php"] [unique_id "al9MoLxMYwyVGnfuwsKwTAAAA-Y"]
[Tue Jul 21 07:40:32.875635 2026] [security2:error] [pid 254995:tid 255131] [client 173.24.185.52:65240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MoP7v0rlcEGmVraFP-gAAAyQ"]
[Tue Jul 21 07:40:32.875800 2026] [security2:error] [pid 254995:tid 255131] [client 173.24.185.52:65240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MoP7v0rlcEGmVraFP-gAAAyQ"]
[Tue Jul 21 07:40:32.918259 2026] [security2:error] [pid 255769:tid 256003] [client 20.220.225.223:19273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/kq1.php"] [unique_id "al9MoLxMYwyVGnfuwsKwTgAABAk"]
[Tue Jul 21 07:40:32.945942 2026] [security2:error] [pid 255769:tid 255940] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9MoLxMYwyVGnfuwsKwUAAAA8w"]
[Tue Jul 21 07:40:32.981935 2026] [security2:error] [pid 255769:tid 255927] [client 20.104.96.117:14533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/about.php"] [unique_id "al9MoLxMYwyVGnfuwsKwUQAAA78"]
[Tue Jul 21 07:40:33.038856 2026] [security2:error] [pid 254995:tid 255113] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mof7v0rlcEGmVraFP_gADJnU"]
[Tue Jul 21 07:40:33.039048 2026] [security2:error] [pid 254995:tid 255133] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mof7v0rlcEGmVraFP_gADJnU"]
[Tue Jul 21 07:40:33.091125 2026] [proxy:error] [pid 255769:tid 255970] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.091191 2026] [proxy_http:error] [pid 255769:tid 255970] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.091840 2026] [proxy:error] [pid 255769:tid 255970] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.091865 2026] [proxy_http:error] [pid 255769:tid 255970] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.147471 2026] [proxy:error] [pid 255769:tid 256017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.147548 2026] [proxy_http:error] [pid 255769:tid 256017] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.148206 2026] [proxy:error] [pid 255769:tid 256017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.148238 2026] [proxy_http:error] [pid 255769:tid 256017] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.167449 2026] [autoindex:error] [pid 255769:tid 256021] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:33.204516 2026] [security2:error] [pid 255769:tid 255955] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9MobxMYwyVGnfuwsKwXwAAA9s"]
[Tue Jul 21 07:40:33.279903 2026] [security2:error] [pid 255769:tid 256015] [client 20.104.96.117:14638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/about.php"] [unique_id "al9MobxMYwyVGnfuwsKwYQAABBU"]
[Tue Jul 21 07:40:33.358598 2026] [security2:error] [pid 255769:tid 256027] [client 20.226.60.151:62218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/zlece.php"] [unique_id "al9MobxMYwyVGnfuwsKwYwAABCE"]
[Tue Jul 21 07:40:33.389185 2026] [proxy:error] [pid 254995:tid 255186] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.389264 2026] [proxy_http:error] [pid 254995:tid 255186] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.389898 2026] [proxy:error] [pid 254995:tid 255186] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.389938 2026] [proxy_http:error] [pid 254995:tid 255186] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.410363 2026] [security2:error] [pid 255769:tid 255932] [client 167.99.181.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.181.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MobxMYwyVGnfuwsKwZAAAA8Q"]
[Tue Jul 21 07:40:33.455287 2026] [autoindex:error] [pid 255769:tid 255912] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:33.464446 2026] [security2:error] [pid 255769:tid 255934] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9MobxMYwyVGnfuwsKwaAAAA8Y"]
[Tue Jul 21 07:40:33.476284 2026] [security2:error] [pid 255769:tid 256018] [client 20.151.10.161:53620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/201.php"] [unique_id "al9MobxMYwyVGnfuwsKwaQAABBg"]
[Tue Jul 21 07:40:33.500253 2026] [security2:error] [pid 254995:tid 255179] [client 4.204.201.85:7461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9Mof7v0rlcEGmVraFQDAAAA1Q"]
[Tue Jul 21 07:40:33.508829 2026] [proxy:error] [pid 254995:tid 255158] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.508924 2026] [proxy_http:error] [pid 254995:tid 255158] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.510013 2026] [proxy:error] [pid 254995:tid 255158] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.510061 2026] [proxy_http:error] [pid 254995:tid 255158] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.513213 2026] [security2:error] [pid 255769:tid 256016] [client 106.215.181.8:4635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MobxMYwyVGnfuwsKwawAABBY"]
[Tue Jul 21 07:40:33.517897 2026] [security2:error] [pid 255769:tid 256016] [client 106.215.181.8:4635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MobxMYwyVGnfuwsKwawAABBY"]
[Tue Jul 21 07:40:33.523240 2026] [proxy:error] [pid 255769:tid 255913] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.523298 2026] [proxy_http:error] [pid 255769:tid 255913] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.524101 2026] [proxy:error] [pid 255769:tid 255913] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.524138 2026] [proxy_http:error] [pid 255769:tid 255913] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.594539 2026] [security2:error] [pid 255769:tid 255998] [client 4.204.201.85:59951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-temp.php"] [unique_id "al9MobxMYwyVGnfuwsKwcQAABAQ"]
[Tue Jul 21 07:40:33.607873 2026] [security2:error] [pid 255769:tid 256028] [client 20.104.96.117:14375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/admin.php"] [unique_id "al9MobxMYwyVGnfuwsKwcwAABCI"]
[Tue Jul 21 07:40:33.626050 2026] [security2:error] [pid 255769:tid 256022] [client 165.227.39.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.39.227.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MobxMYwyVGnfuwsKwdAAABBw"]
[Tue Jul 21 07:40:33.685738 2026] [security2:error] [pid 254995:tid 255125] [client 128.127.105.184:52566] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Mof7v0rlcEGmVraFQEwAAAx4"]
[Tue Jul 21 07:40:33.685905 2026] [security2:error] [pid 254995:tid 255125] [client 128.127.105.184:52566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Mof7v0rlcEGmVraFQEwAAAx4"]
[Tue Jul 21 07:40:33.704675 2026] [security2:error] [pid 254995:tid 255275] [client 20.226.60.151:59504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/black.php"] [unique_id "al9Mof7v0rlcEGmVraFQFQAAA5k"]
[Tue Jul 21 07:40:33.745364 2026] [proxy:error] [pid 254995:tid 255209] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.745431 2026] [proxy_http:error] [pid 254995:tid 255209] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.746506 2026] [proxy:error] [pid 254995:tid 255209] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.746539 2026] [proxy_http:error] [pid 254995:tid 255209] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.757519 2026] [security2:error] [pid 254995:tid 255255] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9Mof7v0rlcEGmVraFQGgAAA4U"]
[Tue Jul 21 07:40:33.806691 2026] [security2:error] [pid 254995:tid 255140] [client 184.75.223.211:39590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Mof7v0rlcEGmVraFQHQAAAy0"]
[Tue Jul 21 07:40:33.806846 2026] [security2:error] [pid 254995:tid 255140] [client 184.75.223.211:39590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Mof7v0rlcEGmVraFQHQAAAy0"]
[Tue Jul 21 07:40:33.871915 2026] [security2:error] [pid 254995:tid 255180] [client 4.204.201.85:57427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-admin/js/index.php"] [unique_id "al9Mof7v0rlcEGmVraFQIwAAA1U"]
[Tue Jul 21 07:40:33.881895 2026] [proxy:error] [pid 254995:tid 255174] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.881964 2026] [proxy_http:error] [pid 254995:tid 255174] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.882646 2026] [proxy:error] [pid 254995:tid 255174] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.882692 2026] [proxy_http:error] [pid 254995:tid 255174] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.923237 2026] [security2:error] [pid 254995:tid 255149] [client 20.104.96.117:14634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/admin.php"] [unique_id "al9Mof7v0rlcEGmVraFQJwAAAzY"]
[Tue Jul 21 07:40:34.039168 2026] [security2:error] [pid 254995:tid 255146] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9Mov7v0rlcEGmVraFQKwAAAzM"]
[Tue Jul 21 07:40:34.077967 2026] [proxy:error] [pid 254995:tid 255277] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.078035 2026] [proxy_http:error] [pid 254995:tid 255277] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.078476 2026] [proxy:error] [pid 254995:tid 255277] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.078502 2026] [proxy_http:error] [pid 254995:tid 255277] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.108847 2026] [proxy:error] [pid 254995:tid 255272] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.108911 2026] [proxy_http:error] [pid 254995:tid 255272] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.109540 2026] [proxy:error] [pid 254995:tid 255272] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.109585 2026] [proxy_http:error] [pid 254995:tid 255272] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.149296 2026] [security2:error] [pid 254995:tid 255154] [client 4.204.201.85:59957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/puc.php"] [unique_id "al9Mov7v0rlcEGmVraFQNAAAAzs"]
[Tue Jul 21 07:40:34.159886 2026] [security2:error] [pid 254995:tid 255267] [client 62.102.148.187:49224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Mov7v0rlcEGmVraFQNgAAA5E"]
[Tue Jul 21 07:40:34.159964 2026] [security2:error] [pid 254995:tid 255267] [client 62.102.148.187:49224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Mov7v0rlcEGmVraFQNgAAA5E"]
[Tue Jul 21 07:40:34.286695 2026] [security2:error] [pid 254995:tid 255199] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9Mov7v0rlcEGmVraFQPwAAA2g"]
[Tue Jul 21 07:40:34.296746 2026] [security2:error] [pid 254995:tid 255252] [client 216.244.66.237:44408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.dharmanet.com.br"] [uri "/khyentse/ocidente.htm"] [unique_id "al9Mov7v0rlcEGmVraFQQAAAA4M"]
[Tue Jul 21 07:40:34.296829 2026] [security2:error] [pid 254995:tid 255252] [client 216.244.66.237:44408] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.dharmanet.com.br"] [uri "/khyentse/ocidente.htm"] [unique_id "al9Mov7v0rlcEGmVraFQQAAAA4M"]
[Tue Jul 21 07:40:34.397372 2026] [proxy:error] [pid 254995:tid 255156] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.397437 2026] [proxy_http:error] [pid 254995:tid 255156] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.398004 2026] [proxy:error] [pid 254995:tid 255156] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.398027 2026] [proxy_http:error] [pid 254995:tid 255156] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.420512 2026] [security2:error] [pid 254995:tid 255186] [client 20.104.96.117:14339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/themes.php"] [unique_id "al9Mov7v0rlcEGmVraFQQwAAA1s"]
[Tue Jul 21 07:40:34.433129 2026] [security2:error] [pid 254995:tid 255221] [client 4.204.201.85:57435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/dx.php"] [unique_id "al9Mov7v0rlcEGmVraFQRAAAA30"]
[Tue Jul 21 07:40:34.487789 2026] [proxy:error] [pid 254995:tid 255184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.487862 2026] [proxy_http:error] [pid 254995:tid 255184] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.488468 2026] [proxy:error] [pid 254995:tid 255184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.488493 2026] [proxy_http:error] [pid 254995:tid 255184] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.502651 2026] [proxy:error] [pid 254995:tid 255257] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.502714 2026] [proxy_http:error] [pid 254995:tid 255257] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.503188 2026] [proxy:error] [pid 254995:tid 255257] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.503218 2026] [proxy_http:error] [pid 254995:tid 255257] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.520935 2026] [security2:error] [pid 254995:tid 255048] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mov7v0rlcEGmVraFQSAADazQ"]
[Tue Jul 21 07:40:34.521088 2026] [security2:error] [pid 254995:tid 255202] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mov7v0rlcEGmVraFQSAADazQ"]
[Tue Jul 21 07:40:34.566987 2026] [security2:error] [pid 254995:tid 255259] [client 20.226.60.151:62266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/vssrs.php"] [unique_id "al9Mov7v0rlcEGmVraFQTQAAA4k"]
[Tue Jul 21 07:40:34.594729 2026] [security2:error] [pid 254995:tid 255216] [client 20.226.60.151:22345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/file31.php"] [unique_id "al9Mov7v0rlcEGmVraFQTwAAA3g"]
[Tue Jul 21 07:40:34.719664 2026] [security2:error] [pid 254995:tid 255164] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Mov7v0rlcEGmVraFQWgAAA0U"]
[Tue Jul 21 07:40:34.737302 2026] [proxy:error] [pid 254995:tid 255126] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.737402 2026] [proxy_http:error] [pid 254995:tid 255126] [client 20.104.96.117:14395] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.738025 2026] [proxy:error] [pid 254995:tid 255126] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.738061 2026] [proxy_http:error] [pid 254995:tid 255126] [client 20.104.96.117:14395] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.748558 2026] [autoindex:error] [pid 254995:tid 255144] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:34.771500 2026] [proxy:error] [pid 254995:tid 255165] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.771567 2026] [proxy_http:error] [pid 254995:tid 255165] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.772232 2026] [proxy:error] [pid 254995:tid 255165] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.772272 2026] [proxy_http:error] [pid 254995:tid 255165] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.854569 2026] [security2:error] [pid 254995:tid 255277] [client 20.151.10.161:12037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ops.php"] [unique_id "al9Mov7v0rlcEGmVraFQZAAAA5s"]
[Tue Jul 21 07:40:34.882940 2026] [security2:error] [pid 254995:tid 255162] [client 4.204.201.85:7478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/wefile.php"] [unique_id "al9Mov7v0rlcEGmVraFQZQAAA0M"]
[Tue Jul 21 07:40:35.022573 2026] [security2:error] [pid 254995:tid 255181] [client 4.204.201.85:59907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/bthil.php"] [unique_id "al9Mo_7v0rlcEGmVraFQawAAA1Y"]
[Tue Jul 21 07:40:35.040137 2026] [proxy:error] [pid 254995:tid 255176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:35.040215 2026] [proxy_http:error] [pid 254995:tid 255176] [client 20.104.96.117:14557] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:35.040723 2026] [proxy:error] [pid 254995:tid 255176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:35.040749 2026] [proxy_http:error] [pid 254995:tid 255176] [client 20.104.96.117:14557] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:35.042919 2026] [security2:error] [pid 254995:tid 255183] [client 165.227.39.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.39.227.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mo_7v0rlcEGmVraFQbQAAA1g"]
[Tue Jul 21 07:40:35.050829 2026] [security2:error] [pid 254995:tid 255163] [client 167.99.181.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.181.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mo_7v0rlcEGmVraFQbwAAA0Q"]
[Tue Jul 21 07:40:35.075309 2026] [security2:error] [pid 254995:tid 255193] [client 117.251.86.144:60786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Mo_7v0rlcEGmVraFQcAAAA2I"]
[Tue Jul 21 07:40:35.075390 2026] [security2:error] [pid 254995:tid 255193] [client 117.251.86.144:60786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Mo_7v0rlcEGmVraFQcAAAA2I"]
[Tue Jul 21 07:40:35.097011 2026] [security2:error] [pid 254995:tid 255194] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Mo_7v0rlcEGmVraFQcgAAA2M"]
[Tue Jul 21 07:40:35.135942 2026] [proxy:error] [pid 254995:tid 255252] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:35.135992 2026] [proxy_http:error] [pid 254995:tid 255252] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:35.136434 2026] [proxy:error] [pid 254995:tid 255252] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:35.136458 2026] [proxy_http:error] [pid 254995:tid 255252] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:35.299339 2026] [security2:error] [pid 254995:tid 255275] [client 4.204.201.85:59949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/7.php"] [unique_id "al9Mo_7v0rlcEGmVraFQhgAAA5k"]
[Tue Jul 21 07:40:35.319331 2026] [security2:error] [pid 254995:tid 255125] [client 20.104.96.117:14544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/.well-known/about.php"] [unique_id "al9Mo_7v0rlcEGmVraFQhwAAAx4"]
[Tue Jul 21 07:40:35.394393 2026] [security2:error] [pid 254995:tid 255078] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mo_7v0rlcEGmVraFQjgADKFI"]
[Tue Jul 21 07:40:35.394555 2026] [security2:error] [pid 254995:tid 255135] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mo_7v0rlcEGmVraFQjgADKFI"]
[Tue Jul 21 07:40:35.406637 2026] [security2:error] [pid 254995:tid 255127] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Mo_7v0rlcEGmVraFQjwAAAyA"]
[Tue Jul 21 07:40:35.468770 2026] [proxy:error] [pid 254995:tid 255126] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:35.468866 2026] [proxy_http:error] [pid 254995:tid 255126] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:35.469935 2026] [proxy:error] [pid 254995:tid 255126] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:35.469990 2026] [proxy_http:error] [pid 254995:tid 255126] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:35.500428 2026] [security2:error] [pid 254995:tid 255161] [client 157.245.113.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.113.245.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mo_7v0rlcEGmVraFQiQAAA0I"]
[Tue Jul 21 07:40:35.511934 2026] [proxy:error] [pid 254995:tid 255144] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:35.512011 2026] [proxy_http:error] [pid 254995:tid 255144] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:35.512606 2026] [proxy:error] [pid 254995:tid 255144] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:35.512636 2026] [proxy_http:error] [pid 254995:tid 255144] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:35.552550 2026] [security2:error] [pid 254995:tid 255146] [client 20.226.60.151:56295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/sym403.php"] [unique_id "al9Mo_7v0rlcEGmVraFQlgAAAzM"]
[Tue Jul 21 07:40:35.574053 2026] [security2:error] [pid 254995:tid 255157] [client 4.204.201.85:60357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/8.php"] [unique_id "al9Mo_7v0rlcEGmVraFQlwAAAz4"]
[Tue Jul 21 07:40:35.607688 2026] [security2:error] [pid 254995:tid 255277] [client 20.104.96.117:14614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9Mo_7v0rlcEGmVraFQmQAAA5s"]
[Tue Jul 21 07:40:35.677260 2026] [security2:error] [pid 254995:tid 255141] [client 147.182.200.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.200.182.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mo_7v0rlcEGmVraFQoQAAAy4"]
[Tue Jul 21 07:40:35.847461 2026] [security2:error] [pid 254995:tid 255177] [client 128.127.105.184:52574] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Mo_7v0rlcEGmVraFQrQAAA1I"]
[Tue Jul 21 07:40:35.847563 2026] [security2:error] [pid 254995:tid 255177] [client 128.127.105.184:52574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Mo_7v0rlcEGmVraFQrQAAA1I"]
[Tue Jul 21 07:40:35.849257 2026] [security2:error] [pid 254995:tid 255150] [client 4.204.201.85:57422] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.wellnesstrade.shop"] [uri "/1.php"] [unique_id "al9Mo_7v0rlcEGmVraFQrgAAAzc"]
[Tue Jul 21 07:40:35.849353 2026] [security2:error] [pid 254995:tid 255150] [client 4.204.201.85:57422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/1.php"] [unique_id "al9Mo_7v0rlcEGmVraFQrgAAAzc"]
[Tue Jul 21 07:40:35.934411 2026] [security2:error] [pid 254995:tid 255072] [remote 167.172.158.128:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.158.172.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mo_7v0rlcEGmVraFQsQADTEw"]
[Tue Jul 21 07:40:35.939318 2026] [security2:error] [pid 254995:tid 255190] [client 20.104.96.117:14546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/wefile.php"] [unique_id "al9Mo_7v0rlcEGmVraFQswAAA18"]
[Tue Jul 21 07:40:36.000148 2026] [security2:error] [pid 254995:tid 255202] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9Mo_7v0rlcEGmVraFQtwAAA2s"]
[Tue Jul 21 07:40:36.078369 2026] [proxy:error] [pid 254995:tid 255205] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:36.078434 2026] [proxy_http:error] [pid 254995:tid 255205] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:36.078954 2026] [proxy:error] [pid 254995:tid 255205] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:36.078989 2026] [proxy_http:error] [pid 254995:tid 255205] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:36.125388 2026] [security2:error] [pid 254995:tid 255216] [client 4.204.201.85:59954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/100.php"] [unique_id "al9MpP7v0rlcEGmVraFQuwAAA3g"]
[Tue Jul 21 07:40:36.164744 2026] [security2:error] [pid 254995:tid 255196] [client 20.151.10.161:12094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ingfo.php"] [unique_id "al9MpP7v0rlcEGmVraFQvQAAA2U"]
[Tue Jul 21 07:40:36.273650 2026] [security2:error] [pid 254995:tid 255137] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9MpP7v0rlcEGmVraFQyQAAAyo"]
[Tue Jul 21 07:40:36.321718 2026] [security2:error] [pid 254995:tid 255182] [client 136.144.33.112:48099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MpP7v0rlcEGmVraFQzwAAA1c"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:36.365961 2026] [security2:error] [pid 254995:tid 255271] [client 20.226.60.151:59482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/zlece.php"] [unique_id "al9MpP7v0rlcEGmVraFQ0wAAA5U"]
[Tue Jul 21 07:40:36.369372 2026] [security2:error] [pid 254995:tid 255229] [client 209.97.180.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.97.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MpP7v0rlcEGmVraFQwwAAA4I"]
[Tue Jul 21 07:40:36.390426 2026] [security2:error] [pid 254995:tid 255200] [client 4.204.201.85:3538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9MpP7v0rlcEGmVraFQ1AAAA2k"]
[Tue Jul 21 07:40:36.405983 2026] [security2:error] [pid 254995:tid 255154] [client 4.204.201.85:59960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/about.php"] [unique_id "al9MpP7v0rlcEGmVraFQ1QAAAzs"]
[Tue Jul 21 07:40:36.427734 2026] [security2:error] [pid 254995:tid 255266] [client 167.99.210.137:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.210.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MpP7v0rlcEGmVraFQ1gAAA5A"]
[Tue Jul 21 07:40:36.501180 2026] [proxy:error] [pid 254995:tid 255175] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:36.501244 2026] [proxy_http:error] [pid 254995:tid 255175] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:36.501768 2026] [proxy:error] [pid 254995:tid 255175] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:36.501803 2026] [proxy_http:error] [pid 254995:tid 255175] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:36.504365 2026] [proxy:error] [pid 254995:tid 255258] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:36.504428 2026] [proxy_http:error] [pid 254995:tid 255258] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:36.505061 2026] [proxy:error] [pid 254995:tid 255258] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:36.505088 2026] [proxy_http:error] [pid 254995:tid 255258] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:36.515832 2026] [security2:error] [pid 254995:tid 255176] [client 20.104.96.117:14653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9MpP7v0rlcEGmVraFQ2wAAA1E"]
[Tue Jul 21 07:40:36.638826 2026] [security2:error] [pid 254995:tid 255162] [client 64.225.75.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.75.225.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mo_7v0rlcEGmVraFQmwAAA0M"]
[Tue Jul 21 07:40:36.682720 2026] [security2:error] [pid 254995:tid 255276] [client 4.204.201.85:60389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/admin.php"] [unique_id "al9MpP7v0rlcEGmVraFQ4AAAA5o"]
[Tue Jul 21 07:40:36.695473 2026] [security2:error] [pid 254995:tid 255143] [client 122.186.204.214:50150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MpP7v0rlcEGmVraFQ4QAAAzA"]
[Tue Jul 21 07:40:36.695592 2026] [security2:error] [pid 254995:tid 255143] [client 122.186.204.214:50150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MpP7v0rlcEGmVraFQ4QAAAzA"]
[Tue Jul 21 07:40:36.734682 2026] [security2:error] [pid 254995:tid 255188] [client 20.226.60.151:62312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wicked.php"] [unique_id "al9MpP7v0rlcEGmVraFQ5gAAA10"]
[Tue Jul 21 07:40:36.843311 2026] [proxy:error] [pid 254995:tid 255259] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:36.843392 2026] [proxy_http:error] [pid 254995:tid 255259] [client 20.104.96.117:14593] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:36.843905 2026] [proxy:error] [pid 254995:tid 255259] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:36.843938 2026] [proxy_http:error] [pid 254995:tid 255259] [client 20.104.96.117:14593] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:36.857969 2026] [security2:error] [pid 254995:tid 255148] [client 142.93.129.190:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.129.93.142.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MpP7v0rlcEGmVraFQ7QAAAzU"]
[Tue Jul 21 07:40:36.859540 2026] [security2:error] [pid 254995:tid 255275] [client 20.151.10.161:55294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/error_log.php"] [unique_id "al9MpP7v0rlcEGmVraFQ7gAAA5k"]
[Tue Jul 21 07:40:36.913719 2026] [security2:error] [pid 254995:tid 255026] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MpP7v0rlcEGmVraFQ8QADVB4"]
[Tue Jul 21 07:40:36.913846 2026] [security2:error] [pid 254995:tid 255179] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MpP7v0rlcEGmVraFQ8QADVB4"]
[Tue Jul 21 07:40:36.958774 2026] [security2:error] [pid 254995:tid 255145] [client 4.204.201.85:61076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/edit.php"] [unique_id "al9MpP7v0rlcEGmVraFQ8wAAAzI"]
[Tue Jul 21 07:40:36.979294 2026] [security2:error] [pid 254995:tid 255218] [client 122.164.127.47:64812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MpP7v0rlcEGmVraFQ9AAAA3o"]
[Tue Jul 21 07:40:36.979386 2026] [security2:error] [pid 254995:tid 255218] [client 122.164.127.47:64812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MpP7v0rlcEGmVraFQ9AAAA3o"]
[Tue Jul 21 07:40:37.040758 2026] [security2:error] [pid 254995:tid 255141] [client 202.143.127.214:62606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mpf7v0rlcEGmVraFQ9gAAAy4"]
[Tue Jul 21 07:40:37.041475 2026] [security2:error] [pid 254995:tid 255141] [client 202.143.127.214:62606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mpf7v0rlcEGmVraFQ9gAAAy4"]
[Tue Jul 21 07:40:37.179142 2026] [proxy:error] [pid 254995:tid 255277] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:37.179201 2026] [proxy_http:error] [pid 254995:tid 255277] [client 20.104.96.117:14358] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:37.179847 2026] [proxy:error] [pid 254995:tid 255277] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:37.179875 2026] [proxy_http:error] [pid 254995:tid 255277] [client 20.104.96.117:14358] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:37.184660 2026] [security2:error] [pid 254995:tid 255274] [client 46.105.39.50:16715] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "leoamaraldev.com.br"] [uri "/robots.txt"] [unique_id "al9Mpf7v0rlcEGmVraFQ_QAAA5g"]
[Tue Jul 21 07:40:37.184742 2026] [security2:error] [pid 254995:tid 255274] [client 46.105.39.50:16715] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "leoamaraldev.com.br"] [uri "/robots.txt"] [unique_id "al9Mpf7v0rlcEGmVraFQ_QAAA5g"]
[Tue Jul 21 07:40:37.239148 2026] [security2:error] [pid 254995:tid 255199] [client 4.204.201.85:57466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-content/admin.php"] [unique_id "al9Mpf7v0rlcEGmVraFRAQAAA2g"]
[Tue Jul 21 07:40:37.284708 2026] [autoindex:error] [pid 254995:tid 255097] [remote 185.12.149.40:0] AH01276: Cannot serve directory /home1/bastar15/lacorsini.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://lacorsini.com.br/
[Tue Jul 21 07:40:37.310077 2026] [security2:error] [pid 254995:tid 255138] [client 154.192.233.199:60004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mpf7v0rlcEGmVraFRCgAAAys"]
[Tue Jul 21 07:40:37.310264 2026] [security2:error] [pid 254995:tid 255138] [client 154.192.233.199:60004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mpf7v0rlcEGmVraFRCgAAAys"]
[Tue Jul 21 07:40:37.393849 2026] [security2:error] [pid 254995:tid 255118] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mpf7v0rlcEGmVraFREAADcHo"]
[Tue Jul 21 07:40:37.394073 2026] [security2:error] [pid 254995:tid 255208] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mpf7v0rlcEGmVraFREAADcHo"]
[Tue Jul 21 07:40:37.444805 2026] [proxy:error] [pid 254995:tid 255191] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:37.444878 2026] [proxy_http:error] [pid 254995:tid 255191] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:37.445484 2026] [proxy:error] [pid 254995:tid 255191] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:37.445517 2026] [proxy_http:error] [pid 254995:tid 255191] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:37.461077 2026] [security2:error] [pid 254995:tid 255256] [client 20.104.96.117:14531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Mpf7v0rlcEGmVraFREwAAA4Y"]
[Tue Jul 21 07:40:37.477656 2026] [security2:error] [pid 254995:tid 255143] [client 207.154.197.113:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.197.154.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mpf7v0rlcEGmVraFRFQAAAzA"]
[Tue Jul 21 07:40:37.485757 2026] [proxy:error] [pid 254995:tid 255279] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:37.485935 2026] [proxy_http:error] [pid 254995:tid 255279] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:37.486381 2026] [proxy:error] [pid 254995:tid 255279] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:37.486403 2026] [proxy_http:error] [pid 254995:tid 255279] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:37.517797 2026] [security2:error] [pid 254995:tid 255190] [client 4.204.201.85:57417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/ss.php"] [unique_id "al9Mpf7v0rlcEGmVraFRGAAAA18"]
[Tue Jul 21 07:40:37.649305 2026] [security2:error] [pid 254995:tid 255133] [client 20.226.60.151:59494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/vssrs.php"] [unique_id "al9Mpf7v0rlcEGmVraFRHAAAAyY"]
[Tue Jul 21 07:40:37.763310 2026] [security2:error] [pid 254995:tid 255172] [client 20.151.10.161:12051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xenon1337.php"] [unique_id "al9Mpf7v0rlcEGmVraFRIgAAA00"]
[Tue Jul 21 07:40:37.792850 2026] [security2:error] [pid 254995:tid 255252] [client 4.204.201.85:61060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/inputs.php"] [unique_id "al9Mpf7v0rlcEGmVraFRJQAAA4M"]
[Tue Jul 21 07:40:37.836573 2026] [security2:error] [pid 254995:tid 255262] [client 20.104.96.117:14594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/8.php"] [unique_id "al9Mpf7v0rlcEGmVraFRKgAAA4w"]
[Tue Jul 21 07:40:37.855994 2026] [security2:error] [pid 254995:tid 255174] [client 139.59.143.102:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.143.59.139.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mpf7v0rlcEGmVraFRLAAAA08"]
[Tue Jul 21 07:40:37.859546 2026] [proxy:error] [pid 254995:tid 255263] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:37.859598 2026] [proxy_http:error] [pid 254995:tid 255263] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:37.860070 2026] [proxy:error] [pid 254995:tid 255263] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:37.860095 2026] [proxy_http:error] [pid 254995:tid 255263] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:37.894724 2026] [security2:error] [pid 254995:tid 255259] [client 207.154.212.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.212.154.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mpf7v0rlcEGmVraFRHwAAA4k"]
[Tue Jul 21 07:40:38.011671 2026] [security2:error] [pid 254995:tid 255266] [client 182.8.255.181:21223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFRNAAAA5A"]
[Tue Jul 21 07:40:38.011844 2026] [security2:error] [pid 254995:tid 255266] [client 182.8.255.181:21223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFRNAAAA5A"]
[Tue Jul 21 07:40:38.053766 2026] [security2:error] [pid 254995:tid 255199] [client 20.226.60.151:62246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/24.php"] [unique_id "al9Mpv7v0rlcEGmVraFRNgAAA2g"]
[Tue Jul 21 07:40:38.068856 2026] [security2:error] [pid 254995:tid 255181] [client 4.204.201.85:57450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/av.php"] [unique_id "al9Mpv7v0rlcEGmVraFROAAAA1Y"]
[Tue Jul 21 07:40:38.132879 2026] [security2:error] [pid 254995:tid 255187] [client 103.86.117.203:63550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFROgAAA1w"]
[Tue Jul 21 07:40:38.133018 2026] [security2:error] [pid 254995:tid 255187] [client 103.86.117.203:63550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFROgAAA1w"]
[Tue Jul 21 07:40:38.156065 2026] [security2:error] [pid 254995:tid 255212] [client 175.45.70.82:55317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFROwAAA3Q"]
[Tue Jul 21 07:40:38.156176 2026] [security2:error] [pid 254995:tid 255212] [client 175.45.70.82:55317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFROwAAA3Q"]
[Tue Jul 21 07:40:38.194864 2026] [security2:error] [pid 254995:tid 255146] [client 20.104.96.117:14616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Mpv7v0rlcEGmVraFRPQAAAzM"]
[Tue Jul 21 07:40:38.197028 2026] [security2:error] [pid 254995:tid 255169] [client 194.99.104.35:35018] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFRPgAAA0o"]
[Tue Jul 21 07:40:38.197086 2026] [security2:error] [pid 254995:tid 255169] [client 194.99.104.35:35018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFRPgAAA0o"]
[Tue Jul 21 07:40:38.346132 2026] [security2:error] [pid 254995:tid 255190] [client 4.204.201.85:60412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/classwithtostring.php"] [unique_id "al9Mpv7v0rlcEGmVraFRSwAAA18"]
[Tue Jul 21 07:40:38.375891 2026] [security2:error] [pid 254995:tid 255267] [client 103.106.20.201:62260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFRTQAAA5E"]
[Tue Jul 21 07:40:38.375983 2026] [security2:error] [pid 254995:tid 255267] [client 103.106.20.201:62260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFRTQAAA5E"]
[Tue Jul 21 07:40:38.431957 2026] [security2:error] [pid 254995:tid 255196] [client 142.93.143.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.143.93.142.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mpv7v0rlcEGmVraFRUgAAA2U"]
[Tue Jul 21 07:40:38.433512 2026] [proxy:error] [pid 254995:tid 255205] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:38.433581 2026] [proxy_http:error] [pid 254995:tid 255205] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:38.434158 2026] [proxy:error] [pid 254995:tid 255205] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:38.434189 2026] [proxy_http:error] [pid 254995:tid 255205] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:38.502500 2026] [security2:error] [pid 254995:tid 255252] [client 20.226.60.151:23143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/file6.php"] [unique_id "al9Mpv7v0rlcEGmVraFRVgAAA4M"]
[Tue Jul 21 07:40:38.505485 2026] [proxy:error] [pid 254995:tid 255197] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:38.505543 2026] [proxy_http:error] [pid 254995:tid 255197] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:38.506212 2026] [proxy:error] [pid 254995:tid 255197] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:38.506245 2026] [proxy_http:error] [pid 254995:tid 255197] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:38.522267 2026] [security2:error] [pid 254995:tid 255222] [client 122.162.144.145:20232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFRWAAAA34"]
[Tue Jul 21 07:40:38.522430 2026] [security2:error] [pid 254995:tid 255222] [client 122.162.144.145:20232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFRWAAAA34"]
[Tue Jul 21 07:40:38.612119 2026] [security2:error] [pid 254995:tid 255164] [client 20.104.96.117:14590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/f6.php"] [unique_id "al9Mpv7v0rlcEGmVraFRWQAAA0U"]
[Tue Jul 21 07:40:38.627711 2026] [security2:error] [pid 254995:tid 255159] [client 4.204.201.85:57462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-content/themes/index.php"] [unique_id "al9Mpv7v0rlcEGmVraFRWwAAA0A"]
[Tue Jul 21 07:40:38.659268 2026] [security2:error] [pid 254995:tid 255214] [client 20.151.10.161:12066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/test11.php"] [unique_id "al9Mpv7v0rlcEGmVraFRXgAAA3Y"]
[Tue Jul 21 07:40:38.771574 2026] [security2:error] [pid 254995:tid 255155] [client 164.92.244.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.244.92.164.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mpv7v0rlcEGmVraFRYgAAAzw"]
[Tue Jul 21 07:40:38.860278 2026] [proxy:error] [pid 254995:tid 255154] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:38.860339 2026] [proxy_http:error] [pid 254995:tid 255154] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:38.860929 2026] [proxy:error] [pid 254995:tid 255154] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:38.860956 2026] [proxy_http:error] [pid 254995:tid 255154] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:38.868668 2026] [proxy:error] [pid 254995:tid 255273] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:38.868715 2026] [proxy_http:error] [pid 254995:tid 255273] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:38.869156 2026] [proxy:error] [pid 254995:tid 255273] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:38.869178 2026] [proxy_http:error] [pid 254995:tid 255273] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:38.870037 2026] [security2:error] [pid 254995:tid 255181] [client 194.99.104.35:59806] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFRbwAAA1Y"]
[Tue Jul 21 07:40:38.870102 2026] [security2:error] [pid 254995:tid 255181] [client 194.99.104.35:59806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFRbwAAA1Y"]
[Tue Jul 21 07:40:38.904014 2026] [security2:error] [pid 254995:tid 255187] [client 20.104.96.117:14538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/inputs.php"] [unique_id "al9Mpv7v0rlcEGmVraFRcgAAA1w"]
[Tue Jul 21 07:40:38.905529 2026] [security2:error] [pid 254995:tid 255212] [client 4.204.201.85:61073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-blog.php"] [unique_id "al9Mpv7v0rlcEGmVraFRcwAAA3Q"]
[Tue Jul 21 07:40:39.015339 2026] [security2:error] [pid 254995:tid 255271] [client 20.226.60.151:62323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/xacs.php"] [unique_id "al9Mp_7v0rlcEGmVraFReQAAA5U"]
[Tue Jul 21 07:40:39.110753 2026] [security2:error] [pid 254995:tid 255129] [client 54.39.0.186:26248] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "premiercservices.com"] [uri "/robots.txt"] [unique_id "al9Mp_7v0rlcEGmVraFRgAAAAyI"]
[Tue Jul 21 07:40:39.110865 2026] [security2:error] [pid 254995:tid 255129] [client 54.39.0.186:26248] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "premiercservices.com"] [uri "/robots.txt"] [unique_id "al9Mp_7v0rlcEGmVraFRgAAAAyI"]
[Tue Jul 21 07:40:39.174615 2026] [security2:error] [pid 254995:tid 255215] [client 206.81.12.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.12.81.206.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mpf7v0rlcEGmVraFQ-gAAA3c"]
[Tue Jul 21 07:40:39.207503 2026] [autoindex:error] [pid 254995:tid 255257] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:39.236284 2026] [security2:error] [pid 254995:tid 255131] [client 4.204.201.85:7474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Mp_7v0rlcEGmVraFRhwAAAyQ"]
[Tue Jul 21 07:40:39.261120 2026] [security2:error] [pid 254995:tid 255252] [client 20.104.96.117:14343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/inputs.php"] [unique_id "al9Mp_7v0rlcEGmVraFRiAAAA4M"]
[Tue Jul 21 07:40:39.433130 2026] [proxy:error] [pid 254995:tid 255157] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:39.433199 2026] [proxy_http:error] [pid 254995:tid 255157] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:39.434513 2026] [proxy:error] [pid 254995:tid 255157] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:39.434555 2026] [proxy_http:error] [pid 254995:tid 255157] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:39.482276 2026] [security2:error] [pid 254995:tid 255274] [client 4.204.201.85:57461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-content/admin.php"] [unique_id "al9Mp_7v0rlcEGmVraFRlQAAA5g"]
[Tue Jul 21 07:40:39.526401 2026] [security2:error] [pid 254995:tid 255045] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mp_7v0rlcEGmVraFRlgADTjE"]
[Tue Jul 21 07:40:39.526582 2026] [security2:error] [pid 254995:tid 255173] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mp_7v0rlcEGmVraFRlgADTjE"]
[Tue Jul 21 07:40:39.584034 2026] [security2:error] [pid 254995:tid 255132] [client 20.104.96.117:14628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/classwithtostring.php"] [unique_id "al9Mp_7v0rlcEGmVraFRmwAAAyU"]
[Tue Jul 21 07:40:39.761508 2026] [security2:error] [pid 254995:tid 255166] [client 4.204.201.85:57423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/adminfuns.php"] [unique_id "al9Mp_7v0rlcEGmVraFRpAAAA0c"]
[Tue Jul 21 07:40:39.855273 2026] [proxy:error] [pid 254995:tid 255225] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:39.855354 2026] [proxy_http:error] [pid 254995:tid 255225] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:39.855944 2026] [proxy:error] [pid 254995:tid 255225] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:39.855978 2026] [proxy_http:error] [pid 254995:tid 255225] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:39.859100 2026] [proxy:error] [pid 254995:tid 255143] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:39.859143 2026] [proxy_http:error] [pid 254995:tid 255143] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:39.859563 2026] [proxy:error] [pid 254995:tid 255143] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:39.859582 2026] [proxy_http:error] [pid 254995:tid 255143] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:39.863238 2026] [security2:error] [pid 254995:tid 255175] [client 209.38.208.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.208.38.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mpv7v0rlcEGmVraFRagAAA1A"]
[Tue Jul 21 07:40:39.888116 2026] [security2:error] [pid 254995:tid 255171] [client 20.104.96.117:14348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9Mp_7v0rlcEGmVraFRrgAAA0w"]
[Tue Jul 21 07:40:39.951505 2026] [security2:error] [pid 254995:tid 255257] [client 4.204.201.85:7435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/8.php"] [unique_id "al9Mp_7v0rlcEGmVraFRsQAAA4c"]
[Tue Jul 21 07:40:40.036420 2026] [security2:error] [pid 254995:tid 255176] [client 59.96.220.140:52125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MqP7v0rlcEGmVraFRuAAAA1E"]
[Tue Jul 21 07:40:40.036512 2026] [security2:error] [pid 254995:tid 255176] [client 59.96.220.140:52125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MqP7v0rlcEGmVraFRuAAAA1E"]
[Tue Jul 21 07:40:40.042515 2026] [security2:error] [pid 254995:tid 255161] [client 172.245.102.32:53481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MqP7v0rlcEGmVraFRugAAA0I"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:40:40.056658 2026] [security2:error] [pid 254995:tid 255172] [client 4.204.201.85:60379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/goods.php"] [unique_id "al9MqP7v0rlcEGmVraFRvAAAA00"]
[Tue Jul 21 07:40:40.139527 2026] [security2:error] [pid 254995:tid 255141] [client 20.226.60.151:56308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/v543.php"] [unique_id "al9MqP7v0rlcEGmVraFRwQAAAy4"]
[Tue Jul 21 07:40:40.214123 2026] [security2:error] [pid 254995:tid 255142] [client 20.226.60.151:62281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/zildan.php"] [unique_id "al9MqP7v0rlcEGmVraFRwgAAAy8"]
[Tue Jul 21 07:40:40.217499 2026] [proxy:error] [pid 254995:tid 255150] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:40.217582 2026] [proxy_http:error] [pid 254995:tid 255150] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:40.218054 2026] [proxy:error] [pid 254995:tid 255150] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:40.218091 2026] [proxy_http:error] [pid 254995:tid 255150] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:40.272629 2026] [security2:error] [pid 254995:tid 255158] [client 20.104.96.117:14605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/wp-blog.php"] [unique_id "al9MqP7v0rlcEGmVraFRxwAAAz8"]
[Tue Jul 21 07:40:40.333244 2026] [security2:error] [pid 254995:tid 255200] [client 4.204.201.85:59935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/ms-edit.php"] [unique_id "al9MqP7v0rlcEGmVraFRzAAAA2k"]
[Tue Jul 21 07:40:40.438164 2026] [proxy:error] [pid 254995:tid 255268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:40.438227 2026] [proxy_http:error] [pid 254995:tid 255268] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:40.438934 2026] [proxy:error] [pid 254995:tid 255268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:40.438969 2026] [proxy_http:error] [pid 254995:tid 255268] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:40.456014 2026] [autoindex:error] [pid 254995:tid 255208] [client 20.226.60.151:23144] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:40.467097 2026] [security2:error] [pid 254995:tid 255186] [client 20.226.60.151:23144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/adminfuns.php"] [unique_id "al9MqP7v0rlcEGmVraFR2QAAA1s"]
[Tue Jul 21 07:40:40.573517 2026] [security2:error] [pid 254995:tid 255198] [client 4.204.201.85:7447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/wp-content/admin.php"] [unique_id "al9MqP7v0rlcEGmVraFR4gAAA2c"]
[Tue Jul 21 07:40:40.592495 2026] [proxy:error] [pid 254995:tid 255275] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:40.592553 2026] [proxy_http:error] [pid 254995:tid 255275] [client 20.104.96.117:14624] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:40.593125 2026] [proxy:error] [pid 254995:tid 255275] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:40.593149 2026] [proxy_http:error] [pid 254995:tid 255275] [client 20.104.96.117:14624] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:40.605688 2026] [security2:error] [pid 254995:tid 255196] [client 4.204.201.85:61083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/222.php"] [unique_id "al9MqP7v0rlcEGmVraFR5AAAA2U"]
[Tue Jul 21 07:40:40.631133 2026] [security2:error] [pid 254995:tid 255252] [client 20.151.10.161:55257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/koala.php"] [unique_id "al9MqP7v0rlcEGmVraFR5gAAA4M"]
[Tue Jul 21 07:40:40.717803 2026] [security2:error] [pid 254995:tid 255276] [client 54.39.89.96:50416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "premiercservices.com"] [uri "/"] [unique_id "al9MqP7v0rlcEGmVraFR6QAAA5o"]
[Tue Jul 21 07:40:40.717890 2026] [security2:error] [pid 254995:tid 255276] [client 54.39.89.96:50416] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "premiercservices.com"] [uri "/"] [unique_id "al9MqP7v0rlcEGmVraFR6QAAA5o"]
[Tue Jul 21 07:40:40.760266 2026] [security2:error] [pid 254995:tid 255169] [client 152.59.154.239:49522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MqP7v0rlcEGmVraFR6wAAA0o"]
[Tue Jul 21 07:40:40.760391 2026] [security2:error] [pid 254995:tid 255169] [client 152.59.154.239:49522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MqP7v0rlcEGmVraFR6wAAA0o"]
[Tue Jul 21 07:40:40.816962 2026] [security2:error] [pid 254995:tid 255141] [client 20.226.60.151:62256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/csa.php"] [unique_id "al9MqP7v0rlcEGmVraFR7gAAAy4"]
[Tue Jul 21 07:40:40.854982 2026] [proxy:error] [pid 254995:tid 255185] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:40.855057 2026] [proxy_http:error] [pid 254995:tid 255185] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:40.855510 2026] [proxy:error] [pid 254995:tid 255185] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:40.855535 2026] [proxy_http:error] [pid 254995:tid 255185] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:40.858581 2026] [proxy:error] [pid 254995:tid 255180] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:40.858641 2026] [proxy_http:error] [pid 254995:tid 255180] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:40.859230 2026] [proxy:error] [pid 254995:tid 255180] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:40.859255 2026] [proxy_http:error] [pid 254995:tid 255180] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:40.881486 2026] [security2:error] [pid 254995:tid 255150] [client 4.204.201.85:59924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/cgi-bin/index.php"] [unique_id "al9MqP7v0rlcEGmVraFR8wAAAzc"]
[Tue Jul 21 07:40:40.920846 2026] [security2:error] [pid 254995:tid 255147] [client 20.104.96.117:14603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MqP7v0rlcEGmVraFR-QAAAzQ"]
[Tue Jul 21 07:40:40.956954 2026] [security2:error] [pid 254995:tid 255197] [client 117.217.38.194:60801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MqP7v0rlcEGmVraFR_QAAA2Y"]
[Tue Jul 21 07:40:40.957155 2026] [security2:error] [pid 254995:tid 255197] [client 117.217.38.194:60801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MqP7v0rlcEGmVraFR_QAAA2Y"]
[Tue Jul 21 07:40:41.031034 2026] [security2:error] [pid 254995:tid 255100] [remote 206.189.95.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.95.189.206.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MqP7v0rlcEGmVraFR8gADbmg"]
[Tue Jul 21 07:40:41.132573 2026] [security2:error] [pid 254995:tid 255191] [client 103.174.34.15:51287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mqf7v0rlcEGmVraFSBQAAA2A"]
[Tue Jul 21 07:40:41.134626 2026] [security2:error] [pid 254995:tid 255191] [client 103.174.34.15:51287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mqf7v0rlcEGmVraFSBQAAA2A"]
[Tue Jul 21 07:40:41.182832 2026] [autoindex:error] [pid 254995:tid 255279] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:41.218292 2026] [security2:error] [pid 254995:tid 255261] [client 184.75.223.211:53092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Mqf7v0rlcEGmVraFSDAAAA4s"]
[Tue Jul 21 07:40:41.218385 2026] [security2:error] [pid 254995:tid 255261] [client 184.75.223.211:53092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Mqf7v0rlcEGmVraFSDAAAA4s"]
[Tue Jul 21 07:40:41.219433 2026] [proxy:error] [pid 254995:tid 255182] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:41.219496 2026] [proxy_http:error] [pid 254995:tid 255182] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:41.220041 2026] [proxy:error] [pid 254995:tid 255182] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:41.220066 2026] [proxy_http:error] [pid 254995:tid 255182] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:41.230642 2026] [security2:error] [pid 254995:tid 255114] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mqf7v0rlcEGmVraFSDQADJXY"]
[Tue Jul 21 07:40:41.230755 2026] [security2:error] [pid 254995:tid 255132] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mqf7v0rlcEGmVraFSDQADJXY"]
[Tue Jul 21 07:40:41.291546 2026] [security2:error] [pid 254995:tid 255257] [client 4.204.201.85:7482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/f6.php"] [unique_id "al9Mqf7v0rlcEGmVraFSEAAAA4c"]
[Tue Jul 21 07:40:41.330829 2026] [security2:error] [pid 254995:tid 255196] [client 20.104.96.117:14612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/ms-edit.php"] [unique_id "al9Mqf7v0rlcEGmVraFSEQAAA2U"]
[Tue Jul 21 07:40:41.437320 2026] [proxy:error] [pid 254995:tid 255164] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:41.437386 2026] [proxy_http:error] [pid 254995:tid 255164] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:41.438050 2026] [proxy:error] [pid 254995:tid 255164] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:41.438088 2026] [proxy_http:error] [pid 254995:tid 255164] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:41.457220 2026] [security2:error] [pid 254995:tid 255169] [client 4.204.201.85:59950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/BDKR28WP.php"] [unique_id "al9Mqf7v0rlcEGmVraFSGwAAA0o"]
[Tue Jul 21 07:40:41.458363 2026] [security2:error] [pid 254995:tid 255163] [client 193.36.225.57:21725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MqP7v0rlcEGmVraFRyAAAA0Q"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:41.511240 2026] [security2:error] [pid 254995:tid 255222] [client 139.167.225.182:59161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mqf7v0rlcEGmVraFSJAAAA34"]
[Tue Jul 21 07:40:41.513084 2026] [security2:error] [pid 254995:tid 255222] [client 139.167.225.182:59161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mqf7v0rlcEGmVraFSJAAAA34"]
[Tue Jul 21 07:40:41.558463 2026] [security2:error] [pid 254995:tid 255214] [client 5.69.251.235:59610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.251.69.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mp_7v0rlcEGmVraFRmAAAA3Y"]
[Tue Jul 21 07:40:41.558593 2026] [security2:error] [pid 254995:tid 255214] [client 5.69.251.235:59610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mp_7v0rlcEGmVraFRmAAAA3Y"]
[Tue Jul 21 07:40:41.746877 2026] [security2:error] [pid 254995:tid 255175] [client 20.104.96.117:14370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9Mqf7v0rlcEGmVraFSMgAAA1A"]
[Tue Jul 21 07:40:41.747056 2026] [autoindex:error] [pid 254995:tid 255140] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:41.759148 2026] [security2:error] [pid 254995:tid 255146] [client 4.204.201.85:3528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/inputs.php"] [unique_id "al9Mqf7v0rlcEGmVraFSNgAAAzM"]
[Tue Jul 21 07:40:41.822983 2026] [security2:error] [pid 254995:tid 255229] [client 20.151.10.161:55271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/mac.php"] [unique_id "al9Mqf7v0rlcEGmVraFSOAAAA4I"]
[Tue Jul 21 07:40:41.857488 2026] [proxy:error] [pid 254995:tid 255166] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:41.857593 2026] [proxy_http:error] [pid 254995:tid 255166] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:41.858178 2026] [proxy:error] [pid 254995:tid 255166] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:41.858204 2026] [proxy_http:error] [pid 254995:tid 255166] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:41.873110 2026] [proxy:error] [pid 254995:tid 255258] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:41.873178 2026] [proxy_http:error] [pid 254995:tid 255258] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:41.873749 2026] [proxy:error] [pid 254995:tid 255258] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:41.873776 2026] [proxy_http:error] [pid 254995:tid 255258] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:41.930050 2026] [security2:error] [pid 254995:tid 255190] [client 122.179.91.63:3280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Mqf7v0rlcEGmVraFSPAAAA18"]
[Tue Jul 21 07:40:41.930166 2026] [security2:error] [pid 254995:tid 255190] [client 122.179.91.63:3280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Mqf7v0rlcEGmVraFSPAAAA18"]
[Tue Jul 21 07:40:42.032982 2026] [proxy:error] [pid 254995:tid 255161] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.033044 2026] [proxy_http:error] [pid 254995:tid 255161] [client 20.104.96.117:14545] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.033460 2026] [proxy:error] [pid 254995:tid 255161] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.033486 2026] [proxy_http:error] [pid 254995:tid 255161] [client 20.104.96.117:14545] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.035840 2026] [autoindex:error] [pid 254995:tid 255256] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:42.084909 2026] [security2:error] [pid 254995:tid 255163] [client 20.226.60.151:62301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/w3llscc.php"] [unique_id "al9Mqv7v0rlcEGmVraFSUgAAA0Q"]
[Tue Jul 21 07:40:42.139714 2026] [security2:error] [pid 254995:tid 255266] [client 193.36.225.150:48885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Mqf7v0rlcEGmVraFSPwAAA5A"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:40:42.174332 2026] [security2:error] [pid 254995:tid 255150] [client 4.204.201.85:61082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp.php"] [unique_id "al9Mqv7v0rlcEGmVraFSVQAAAzc"]
[Tue Jul 21 07:40:42.221760 2026] [proxy:error] [pid 254995:tid 255147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.221835 2026] [proxy_http:error] [pid 254995:tid 255147] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.222458 2026] [proxy:error] [pid 254995:tid 255147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.222488 2026] [proxy_http:error] [pid 254995:tid 255147] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.240496 2026] [security2:error] [pid 254995:tid 255174] [client 20.226.60.151:59496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wicked.php"] [unique_id "al9Mqv7v0rlcEGmVraFSWQAAA08"]
[Tue Jul 21 07:40:42.338341 2026] [security2:error] [pid 254995:tid 255145] [client 20.104.96.117:14385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9Mqv7v0rlcEGmVraFSWgAAAzI"]
[Tue Jul 21 07:40:42.426459 2026] [security2:error] [pid 254995:tid 255272] [client 4.204.201.85:3520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/inputs.php"] [unique_id "al9Mqv7v0rlcEGmVraFSXgAAA5Y"]
[Tue Jul 21 07:40:42.436485 2026] [proxy:error] [pid 254995:tid 255138] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.436545 2026] [proxy_http:error] [pid 254995:tid 255138] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.437044 2026] [proxy:error] [pid 254995:tid 255138] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.437072 2026] [proxy_http:error] [pid 254995:tid 255138] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.454476 2026] [security2:error] [pid 254995:tid 255273] [client 4.204.201.85:56529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/abcd.php"] [unique_id "al9Mqv7v0rlcEGmVraFSZAAAA5c"]
[Tue Jul 21 07:40:42.652244 2026] [proxy:error] [pid 254995:tid 255216] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.652319 2026] [proxy_http:error] [pid 254995:tid 255216] [client 20.104.96.117:14651] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.652886 2026] [proxy:error] [pid 254995:tid 255216] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.652914 2026] [proxy_http:error] [pid 254995:tid 255216] [client 20.104.96.117:14651] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.742794 2026] [security2:error] [pid 254995:tid 255131] [client 4.204.201.85:59966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/a1.php"] [unique_id "al9Mqv7v0rlcEGmVraFSdQAAAyQ"]
[Tue Jul 21 07:40:42.858063 2026] [proxy:error] [pid 254995:tid 255202] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.858133 2026] [proxy_http:error] [pid 254995:tid 255202] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.858675 2026] [proxy:error] [pid 254995:tid 255202] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.858699 2026] [proxy_http:error] [pid 254995:tid 255202] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.860151 2026] [proxy:error] [pid 254995:tid 255187] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.860234 2026] [proxy_http:error] [pid 254995:tid 255187] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.860861 2026] [proxy:error] [pid 254995:tid 255187] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.860888 2026] [proxy_http:error] [pid 254995:tid 255187] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.980058 2026] [proxy:error] [pid 254995:tid 255137] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.980150 2026] [proxy_http:error] [pid 254995:tid 255137] [client 20.104.96.117:14549] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.980828 2026] [proxy:error] [pid 254995:tid 255137] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.980861 2026] [proxy_http:error] [pid 254995:tid 255137] [client 20.104.96.117:14549] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:43.018271 2026] [security2:error] [pid 254995:tid 255180] [client 4.204.201.85:60367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9Mq_7v0rlcEGmVraFShAAAA1U"]
[Tue Jul 21 07:40:43.132690 2026] [security2:error] [pid 254995:tid 255272] [client 4.204.201.85:3526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/classwithtostring.php"] [unique_id "al9Mq_7v0rlcEGmVraFSjgAAA5Y"]
[Tue Jul 21 07:40:43.133067 2026] [security2:error] [pid 254995:tid 255154] [client 20.226.60.151:22942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/goods.php"] [unique_id "al9Mq_7v0rlcEGmVraFSjwAAAzs"]
[Tue Jul 21 07:40:43.234559 2026] [proxy:error] [pid 254995:tid 255268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:43.234613 2026] [proxy_http:error] [pid 254995:tid 255268] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:43.235186 2026] [proxy:error] [pid 254995:tid 255268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:43.235212 2026] [proxy_http:error] [pid 254995:tid 255268] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:43.271192 2026] [security2:error] [pid 254995:tid 255186] [client 20.104.96.117:14391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/abcd.php"] [unique_id "al9Mq_7v0rlcEGmVraFSmAAAA1s"]
[Tue Jul 21 07:40:43.308937 2026] [security2:error] [pid 254995:tid 255166] [client 4.204.201.85:61059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/cgi-bin/admin.php"] [unique_id "al9Mq_7v0rlcEGmVraFSmQAAA0c"]
[Tue Jul 21 07:40:43.434806 2026] [proxy:error] [pid 254995:tid 255149] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:43.434880 2026] [proxy_http:error] [pid 254995:tid 255149] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:43.435370 2026] [proxy:error] [pid 254995:tid 255149] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:43.435398 2026] [proxy_http:error] [pid 254995:tid 255149] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:43.449488 2026] [security2:error] [pid 254995:tid 255277] [client 173.24.185.52:49416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Mq_7v0rlcEGmVraFSoAAAA5s"]
[Tue Jul 21 07:40:43.454090 2026] [security2:error] [pid 254995:tid 255277] [client 173.24.185.52:49416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Mq_7v0rlcEGmVraFSoAAAA5s"]
[Tue Jul 21 07:40:43.584508 2026] [security2:error] [pid 254995:tid 255128] [client 4.204.201.85:57447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/gettest.php"] [unique_id "al9Mq_7v0rlcEGmVraFSpgAAAyE"]
[Tue Jul 21 07:40:43.594877 2026] [security2:error] [pid 254995:tid 255125] [client 128.199.182.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.182.199.128.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mqf7v0rlcEGmVraFSGAAAAx4"]
[Tue Jul 21 07:40:43.660091 2026] [security2:error] [pid 254995:tid 255164] [client 20.104.96.117:14647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/file15.php"] [unique_id "al9Mq_7v0rlcEGmVraFSqQAAA0U"]
[Tue Jul 21 07:40:43.691868 2026] [security2:error] [pid 254995:tid 255220] [client 20.226.60.151:62288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wpx.php"] [unique_id "al9Mq_7v0rlcEGmVraFSrQAAA3w"]
[Tue Jul 21 07:40:43.739807 2026] [security2:error] [pid 254995:tid 255168] [client 20.226.60.151:23155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/100.php"] [unique_id "al9Mq_7v0rlcEGmVraFSsAAAA0k"]
[Tue Jul 21 07:40:43.822893 2026] [security2:error] [pid 254995:tid 255127] [client 4.204.201.85:7451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9Mq_7v0rlcEGmVraFSswAAAyA"]
[Tue Jul 21 07:40:43.859678 2026] [proxy:error] [pid 254995:tid 255214] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:43.859738 2026] [proxy_http:error] [pid 254995:tid 255214] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:43.860199 2026] [proxy:error] [pid 254995:tid 255214] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:43.860223 2026] [proxy_http:error] [pid 254995:tid 255214] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:43.861877 2026] [proxy:error] [pid 254995:tid 255211] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:43.861928 2026] [proxy_http:error] [pid 254995:tid 255211] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:43.862358 2026] [proxy:error] [pid 254995:tid 255211] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:43.862402 2026] [proxy_http:error] [pid 254995:tid 255211] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:43.980966 2026] [security2:error] [pid 254995:tid 255154] [client 20.151.10.161:53596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9Mq_7v0rlcEGmVraFSvgAAAzs"]
[Tue Jul 21 07:40:43.983810 2026] [security2:error] [pid 254995:tid 255181] [client 20.104.96.117:14336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/jp.php"] [unique_id "al9Mq_7v0rlcEGmVraFSwAAAA1Y"]
[Tue Jul 21 07:40:44.214775 2026] [proxy:error] [pid 254995:tid 255149] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:44.214857 2026] [proxy_http:error] [pid 254995:tid 255149] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:44.215461 2026] [proxy:error] [pid 254995:tid 255149] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:44.215504 2026] [proxy_http:error] [pid 254995:tid 255149] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:44.249889 2026] [security2:error] [pid 254995:tid 255087] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MrP7v0rlcEGmVraFS1gADXls"]
[Tue Jul 21 07:40:44.250079 2026] [security2:error] [pid 254995:tid 255189] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MrP7v0rlcEGmVraFS1gADXls"]
[Tue Jul 21 07:40:44.284055 2026] [security2:error] [pid 254995:tid 255267] [client 20.104.96.117:14572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/f35.php"] [unique_id "al9MrP7v0rlcEGmVraFS2AAAA5E"]
[Tue Jul 21 07:40:44.324736 2026] [security2:error] [pid 254995:tid 255255] [client 106.215.181.8:6642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MrP7v0rlcEGmVraFS2gAAA4U"]
[Tue Jul 21 07:40:44.329974 2026] [security2:error] [pid 254995:tid 255255] [client 106.215.181.8:6642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MrP7v0rlcEGmVraFS2gAAA4U"]
[Tue Jul 21 07:40:44.449523 2026] [proxy:error] [pid 254995:tid 255168] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:44.449590 2026] [proxy_http:error] [pid 254995:tid 255168] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:44.450281 2026] [proxy:error] [pid 254995:tid 255168] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:44.450315 2026] [proxy_http:error] [pid 254995:tid 255168] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:44.489521 2026] [security2:error] [pid 254995:tid 255133] [client 20.226.60.151:23124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/about.php"] [unique_id "al9MrP7v0rlcEGmVraFS4wAAAyY"]
[Tue Jul 21 07:40:44.515268 2026] [security2:error] [pid 254995:tid 255163] [client 4.204.201.85:3582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/wp-blog.php"] [unique_id "al9MrP7v0rlcEGmVraFS5AAAA0Q"]
[Tue Jul 21 07:40:44.531415 2026] [security2:error] [pid 254995:tid 255263] [client 4.204.201.85:56515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/simple.php"] [unique_id "al9MrP7v0rlcEGmVraFS5QAAA40"]
[Tue Jul 21 07:40:44.694211 2026] [security2:error] [pid 254995:tid 255140] [client 20.104.96.117:14606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/wp-load.php"] [unique_id "al9MrP7v0rlcEGmVraFS8QAAAy0"]
[Tue Jul 21 07:40:44.756284 2026] [security2:error] [pid 254995:tid 255279] [client 20.226.60.151:62321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-css.php"] [unique_id "al9MrP7v0rlcEGmVraFS9QAAA50"]
[Tue Jul 21 07:40:44.807021 2026] [security2:error] [pid 254995:tid 255143] [client 4.204.201.85:57426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/xxx.php"] [unique_id "al9MrP7v0rlcEGmVraFS9gAAAzA"]
[Tue Jul 21 07:40:44.865096 2026] [proxy:error] [pid 254995:tid 255257] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:44.865161 2026] [proxy_http:error] [pid 254995:tid 255257] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:44.865713 2026] [proxy:error] [pid 254995:tid 255257] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:44.865737 2026] [proxy_http:error] [pid 254995:tid 255257] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:44.868075 2026] [proxy:error] [pid 254995:tid 255260] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:44.868165 2026] [proxy_http:error] [pid 254995:tid 255260] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:44.869316 2026] [proxy:error] [pid 254995:tid 255260] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:44.869381 2026] [proxy_http:error] [pid 254995:tid 255260] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:44.962616 2026] [security2:error] [pid 254995:tid 255189] [client 20.226.60.151:56234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/sixxis.php"] [unique_id "al9MrP7v0rlcEGmVraFS-wAAA14"]
[Tue Jul 21 07:40:44.988736 2026] [security2:error] [pid 254995:tid 255131] [client 20.104.96.117:14597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/xyn.php"] [unique_id "al9MrP7v0rlcEGmVraFS_QAAAyQ"]
[Tue Jul 21 07:40:45.044990 2026] [security2:error] [pid 254995:tid 255021] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mrf7v0rlcEGmVraFS_wADkRk"]
[Tue Jul 21 07:40:45.045140 2026] [security2:error] [pid 254995:tid 255267] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mrf7v0rlcEGmVraFS_wADkRk"]
[Tue Jul 21 07:40:45.082892 2026] [security2:error] [pid 254995:tid 255255] [client 4.204.201.85:61058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/hypo.php"] [unique_id "al9Mrf7v0rlcEGmVraFTAAAAA4U"]
[Tue Jul 21 07:40:45.215057 2026] [proxy:error] [pid 254995:tid 255199] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:45.215124 2026] [proxy_http:error] [pid 254995:tid 255199] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:45.215685 2026] [proxy:error] [pid 254995:tid 255199] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:45.215709 2026] [proxy_http:error] [pid 254995:tid 255199] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:45.267555 2026] [security2:error] [pid 254995:tid 255266] [client 20.226.60.151:22936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/about.php"] [unique_id "al9Mrf7v0rlcEGmVraFTDAAAA5A"]
[Tue Jul 21 07:40:45.318401 2026] [security2:error] [pid 254995:tid 255141] [client 20.226.60.151:59477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/24.php"] [unique_id "al9Mrf7v0rlcEGmVraFTDwAAAy4"]
[Tue Jul 21 07:40:45.410035 2026] [autoindex:error] [pid 254995:tid 255273] [client 4.204.201.85:59934] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:45.449065 2026] [proxy:error] [pid 254995:tid 255147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:45.449606 2026] [proxy_http:error] [pid 254995:tid 255147] [client 20.104.96.117:14613] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:45.450334 2026] [proxy:error] [pid 254995:tid 255147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:45.450377 2026] [proxy_http:error] [pid 254995:tid 255147] [client 20.104.96.117:14613] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:45.454395 2026] [security2:error] [pid 254995:tid 255140] [client 20.151.10.161:53580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wefile.php"] [unique_id "al9Mrf7v0rlcEGmVraFTEwAAAy0"]
[Tue Jul 21 07:40:45.505837 2026] [security2:error] [pid 254995:tid 255192] [client 20.226.60.151:62326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/ho.php"] [unique_id "al9Mrf7v0rlcEGmVraFTFQAAA2E"]
[Tue Jul 21 07:40:45.531149 2026] [security2:error] [pid 254995:tid 255279] [client 20.226.60.151:23158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/admin.php"] [unique_id "al9Mrf7v0rlcEGmVraFTFgAAA50"]
[Tue Jul 21 07:40:45.684904 2026] [security2:error] [pid 254995:tid 255197] [client 4.204.201.85:59934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/chosen.php"] [unique_id "al9Mrf7v0rlcEGmVraFTIAAAA2Y"]
[Tue Jul 21 07:40:45.798364 2026] [security2:error] [pid 254995:tid 255144] [client 20.226.60.151:23165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/admin.php"] [unique_id "al9Mrf7v0rlcEGmVraFTLAAAAzE"]
[Tue Jul 21 07:40:45.799486 2026] [security2:error] [pid 254995:tid 255271] [client 117.251.86.144:55190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Mrf7v0rlcEGmVraFTLQAAA5U"]
[Tue Jul 21 07:40:45.799572 2026] [security2:error] [pid 254995:tid 255271] [client 117.251.86.144:55190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Mrf7v0rlcEGmVraFTLQAAA5U"]
[Tue Jul 21 07:40:45.809333 2026] [security2:error] [pid 254995:tid 255157] [client 193.36.225.69:34387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Mrf7v0rlcEGmVraFTLwAAAz4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:45.842638 2026] [proxy:error] [pid 254995:tid 255276] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:45.842711 2026] [proxy_http:error] [pid 254995:tid 255276] [client 20.104.96.117:14377] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:45.843444 2026] [proxy:error] [pid 254995:tid 255276] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:45.843474 2026] [proxy_http:error] [pid 254995:tid 255276] [client 20.104.96.117:14377] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:45.870196 2026] [proxy:error] [pid 254995:tid 255176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:45.870268 2026] [proxy_http:error] [pid 254995:tid 255176] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:45.870931 2026] [proxy:error] [pid 254995:tid 255176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:45.870975 2026] [proxy_http:error] [pid 254995:tid 255176] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:45.933660 2026] [security2:error] [pid 254995:tid 255199] [client 4.204.201.85:7460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/wp-content/admin.php"] [unique_id "al9Mrf7v0rlcEGmVraFTNQAAA2g"]
[Tue Jul 21 07:40:45.977206 2026] [autoindex:error] [pid 254995:tid 255163] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:46.007545 2026] [security2:error] [pid 254995:tid 255224] [client 20.226.60.151:62270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/xy.php"] [unique_id "al9Mrv7v0rlcEGmVraFTPAAAA4A"]
[Tue Jul 21 07:40:46.017299 2026] [security2:error] [pid 254995:tid 255058] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mrv7v0rlcEGmVraFTPQADHj4"]
[Tue Jul 21 07:40:46.017458 2026] [security2:error] [pid 254995:tid 255125] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mrv7v0rlcEGmVraFTPQADHj4"]
[Tue Jul 21 07:40:46.024727 2026] [security2:error] [pid 254995:tid 255219] [client 20.226.60.151:56306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/ip.php"] [unique_id "al9Mrv7v0rlcEGmVraFTPgAAA3s"]
[Tue Jul 21 07:40:46.087637 2026] [security2:error] [pid 254995:tid 255127] [client 196.251.121.187:57312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "fit4me.store"] [uri "/wp-json/batch/v1"] [unique_id "al9Mrv7v0rlcEGmVraFTQAAAAyA"]
[Tue Jul 21 07:40:46.127412 2026] [security2:error] [pid 254995:tid 255272] [client 122.186.204.214:50680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mrv7v0rlcEGmVraFTQQAAA5Y"]
[Tue Jul 21 07:40:46.127575 2026] [security2:error] [pid 254995:tid 255272] [client 122.186.204.214:50680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mrv7v0rlcEGmVraFTQQAAA5Y"]
[Tue Jul 21 07:40:46.163693 2026] [security2:error] [pid 254995:tid 255150] [client 20.104.96.117:14652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/ccc.php"] [unique_id "al9Mrv7v0rlcEGmVraFTQwAAAzc"]
[Tue Jul 21 07:40:46.189282 2026] [security2:error] [pid 254995:tid 255138] [client 20.226.60.151:62244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/loader.php"] [unique_id "al9Mrv7v0rlcEGmVraFTRAAAAys"]
[Tue Jul 21 07:40:46.231380 2026] [proxy:error] [pid 254995:tid 255260] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:46.231442 2026] [proxy_http:error] [pid 254995:tid 255260] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:46.232119 2026] [proxy:error] [pid 254995:tid 255260] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:46.232148 2026] [proxy_http:error] [pid 254995:tid 255260] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:46.263390 2026] [security2:error] [pid 254995:tid 255211] [client 4.204.201.85:61086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/als.php"] [unique_id "al9Mrv7v0rlcEGmVraFTTQAAA3M"]
[Tue Jul 21 07:40:46.290897 2026] [security2:error] [pid 254995:tid 255190] [client 20.226.60.151:62221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/spadex.php"] [unique_id "al9Mrv7v0rlcEGmVraFTTwAAA18"]
[Tue Jul 21 07:40:46.452739 2026] [security2:error] [pid 254995:tid 255202] [client 20.226.60.151:23146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/themes.php"] [unique_id "al9Mrv7v0rlcEGmVraFTVwAAA2s"]
[Tue Jul 21 07:40:46.519217 2026] [security2:error] [pid 254995:tid 255159] [client 4.204.201.85:3530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/ms-edit.php"] [unique_id "al9Mrv7v0rlcEGmVraFTWQAAA0A"]
[Tue Jul 21 07:40:46.528183 2026] [security2:error] [pid 254995:tid 255274] [client 20.104.96.117:14626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/w.php"] [unique_id "al9Mrv7v0rlcEGmVraFTWgAAA5g"]
[Tue Jul 21 07:40:46.540629 2026] [security2:error] [pid 254995:tid 255215] [client 4.204.201.85:59910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/pol.php"] [unique_id "al9Mrv7v0rlcEGmVraFTWwAAA3c"]
[Tue Jul 21 07:40:46.576985 2026] [security2:error] [pid 254995:tid 255168] [client 20.220.225.223:5271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Mrv7v0rlcEGmVraFTXQAAA0k"]
[Tue Jul 21 07:40:46.599938 2026] [security2:error] [pid 254995:tid 255199] [client 20.226.60.151:62320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/2x.php"] [unique_id "al9Mrv7v0rlcEGmVraFTXgAAA2g"]
[Tue Jul 21 07:40:46.721939 2026] [security2:error] [pid 254995:tid 255042] [remote 185.27.20.235:44234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.20.27.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/wp-login.php"] [unique_id "al9Mrv7v0rlcEGmVraFTYwADMS4"]
[Tue Jul 21 07:40:46.799237 2026] [autoindex:error] [pid 254995:tid 255175] [client 20.226.60.151:22916] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:46.816144 2026] [security2:error] [pid 254995:tid 255260] [client 4.204.201.85:61092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/file5.php"] [unique_id "al9Mrv7v0rlcEGmVraFTbAAAA4o"]
[Tue Jul 21 07:40:46.933656 2026] [security2:error] [pid 254995:tid 255136] [client 20.104.96.117:14630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Mrv7v0rlcEGmVraFTbgAAAyk"]
[Tue Jul 21 07:40:46.951690 2026] [security2:error] [pid 254995:tid 255223] [client 4.204.201.85:7465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/cgi-bin/index.php"] [unique_id "al9Mrv7v0rlcEGmVraFTbwAAA38"]
[Tue Jul 21 07:40:47.014116 2026] [security2:error] [pid 254995:tid 255012] [remote 154.61.75.100:33410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp-login.php"] [unique_id "al9Mr_7v0rlcEGmVraFTcAADkxA"]
[Tue Jul 21 07:40:47.085917 2026] [core:error] [pid 254995:tid 255256] [client 137.184.93.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:40:47.085933 2026] [core:error] [pid 254995:tid 255256] [client 137.184.93.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:40:47.092955 2026] [security2:error] [pid 254995:tid 255202] [client 4.204.201.85:61095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/file.php"] [unique_id "al9Mr_7v0rlcEGmVraFTewAAA2s"]
[Tue Jul 21 07:40:47.224969 2026] [proxy:error] [pid 254995:tid 255176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:47.225051 2026] [proxy_http:error] [pid 254995:tid 255176] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:47.225553 2026] [proxy:error] [pid 254995:tid 255176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:47.225579 2026] [proxy_http:error] [pid 254995:tid 255176] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:47.238037 2026] [security2:error] [pid 254995:tid 255163] [client 20.104.96.117:14535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/FWAZ.php"] [unique_id "al9Mr_7v0rlcEGmVraFTggAAA0Q"]
[Tue Jul 21 07:40:47.338567 2026] [security2:error] [pid 254995:tid 255219] [client 20.220.225.223:5266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Mr_7v0rlcEGmVraFTqgAAA3s"]
[Tue Jul 21 07:40:47.393881 2026] [security2:error] [pid 254995:tid 255213] [client 4.204.201.85:61111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/cfile.php"] [unique_id "al9Mr_7v0rlcEGmVraFTrQAAA3U"]
[Tue Jul 21 07:40:47.427850 2026] [security2:error] [pid 254995:tid 255065] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Mr_7v0rlcEGmVraFTrgADOUU"]
[Tue Jul 21 07:40:47.428062 2026] [security2:error] [pid 254995:tid 255152] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Mr_7v0rlcEGmVraFTrgADOUU"]
[Tue Jul 21 07:40:47.456043 2026] [security2:error] [pid 254995:tid 255029] [remote 152.53.111.131:52330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Mr_7v0rlcEGmVraFTsAADPCE"]
[Tue Jul 21 07:40:47.510685 2026] [security2:error] [pid 254995:tid 255169] [client 122.164.127.47:65375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Mr_7v0rlcEGmVraFTtQAAA0o"]
[Tue Jul 21 07:40:47.510778 2026] [security2:error] [pid 254995:tid 255169] [client 122.164.127.47:65375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Mr_7v0rlcEGmVraFTtQAAA0o"]
[Tue Jul 21 07:40:47.546108 2026] [security2:error] [pid 254995:tid 255177] [client 20.104.96.117:14530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/miru1.php"] [unique_id "al9Mr_7v0rlcEGmVraFTtwAAA1I"]
[Tue Jul 21 07:40:47.562664 2026] [core:error] [pid 254995:tid 254998] [remote 5.255.231.176:52976] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:40:47.562685 2026] [core:error] [pid 254995:tid 254998] [remote 5.255.231.176:52976] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:40:47.687913 2026] [security2:error] [pid 254995:tid 255197] [client 4.204.201.85:59938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/admin.php"] [unique_id "al9Mr_7v0rlcEGmVraFTvQAAA2Y"]
[Tue Jul 21 07:40:47.794675 2026] [security2:error] [pid 254995:tid 255269] [client 20.226.60.151:59424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/xacs.php"] [unique_id "al9Mr_7v0rlcEGmVraFTwgAAA5M"]
[Tue Jul 21 07:40:47.858557 2026] [security2:error] [pid 254995:tid 255159] [client 20.104.96.117:14640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/aa.php"] [unique_id "al9Mr_7v0rlcEGmVraFTzAAAA0A"]
[Tue Jul 21 07:40:47.912243 2026] [security2:error] [pid 254995:tid 255196] [client 154.192.233.199:60322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mr_7v0rlcEGmVraFTzwAAA2U"]
[Tue Jul 21 07:40:47.912414 2026] [security2:error] [pid 254995:tid 255196] [client 154.192.233.199:60322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mr_7v0rlcEGmVraFTzwAAA2U"]
[Tue Jul 21 07:40:47.963626 2026] [security2:error] [pid 254995:tid 255173] [client 4.204.201.85:57418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/aa2.php"] [unique_id "al9Mr_7v0rlcEGmVraFT0QAAA04"]
[Tue Jul 21 07:40:47.974810 2026] [security2:error] [pid 254995:tid 255125] [client 4.204.201.85:7439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/BDKR28WP.php"] [unique_id "al9Mr_7v0rlcEGmVraFT0gAAAx4"]
[Tue Jul 21 07:40:48.060283 2026] [security2:error] [pid 254995:tid 255151] [client 20.226.60.151:62211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/ctex1.php"] [unique_id "al9MsP7v0rlcEGmVraFT1QAAAzg"]
[Tue Jul 21 07:40:48.062908 2026] [security2:error] [pid 254995:tid 255213] [client 20.226.60.151:22916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/.well-known/about.php"] [unique_id "al9MsP7v0rlcEGmVraFT1gAAA3U"]
[Tue Jul 21 07:40:48.101069 2026] [security2:error] [pid 254995:tid 255120] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT2AADiXw"]
[Tue Jul 21 07:40:48.101216 2026] [security2:error] [pid 254995:tid 255259] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT2AADiXw"]
[Tue Jul 21 07:40:48.106597 2026] [security2:error] [pid 254995:tid 255143] [client 202.143.127.214:63026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT2QAAAzA"]
[Tue Jul 21 07:40:48.106720 2026] [security2:error] [pid 254995:tid 255143] [client 202.143.127.214:63026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT2QAAAzA"]
[Tue Jul 21 07:40:48.145650 2026] [security2:error] [pid 254995:tid 255191] [client 20.104.96.117:14604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/122.php"] [unique_id "al9MsP7v0rlcEGmVraFT2gAAA2A"]
[Tue Jul 21 07:40:48.247945 2026] [security2:error] [pid 254995:tid 255177] [client 4.204.201.85:57420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/ccou.php"] [unique_id "al9MsP7v0rlcEGmVraFT3QAAA1I"]
[Tue Jul 21 07:40:48.384736 2026] [security2:error] [pid 254995:tid 255225] [client 182.8.255.181:17596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT6AAAA4E"]
[Tue Jul 21 07:40:48.384854 2026] [security2:error] [pid 254995:tid 255225] [client 182.8.255.181:17596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT6AAAA4E"]
[Tue Jul 21 07:40:48.444700 2026] [security2:error] [pid 254995:tid 255159] [client 20.104.96.117:13069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/get.php"] [unique_id "al9MsP7v0rlcEGmVraFT7QAAA0A"]
[Tue Jul 21 07:40:48.452288 2026] [security2:error] [pid 254995:tid 255171] [client 185.198.240.105:49497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "voweltravel.com.br"] [uri "/wp-login.php"] [unique_id "al9Mr_7v0rlcEGmVraFTrwAAA0w"]
[Tue Jul 21 07:40:48.532466 2026] [security2:error] [pid 254995:tid 255163] [client 4.204.201.85:59915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/dr.php"] [unique_id "al9MsP7v0rlcEGmVraFT7wAAA0Q"]
[Tue Jul 21 07:40:48.605417 2026] [security2:error] [pid 254995:tid 255275] [client 103.86.117.203:64075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT8QAAA5k"]
[Tue Jul 21 07:40:48.605553 2026] [security2:error] [pid 254995:tid 255275] [client 103.86.117.203:64075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT8QAAA5k"]
[Tue Jul 21 07:40:48.637580 2026] [security2:error] [pid 254995:tid 255176] [client 209.141.34.121:55850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "ericksheik.com.br"] [uri "/"] [unique_id "al9MsP7v0rlcEGmVraFT8gAAA1E"]
[Tue Jul 21 07:40:48.681799 2026] [security2:error] [pid 254995:tid 255219] [client 62.102.148.187:59500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT9wAAA3s"]
[Tue Jul 21 07:40:48.681944 2026] [security2:error] [pid 254995:tid 255219] [client 62.102.148.187:59500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT9wAAA3s"]
[Tue Jul 21 07:40:48.690679 2026] [security2:error] [pid 254995:tid 255148] [client 20.226.60.151:23137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9MsP7v0rlcEGmVraFT-AAAAzU"]
[Tue Jul 21 07:40:48.750011 2026] [security2:error] [pid 254995:tid 255155] [client 20.104.96.117:14595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/as.php"] [unique_id "al9MsP7v0rlcEGmVraFT-QAAAzw"]
[Tue Jul 21 07:40:48.785405 2026] [security2:error] [pid 254995:tid 255152] [client 175.45.70.82:55828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT_gAAAzk"]
[Tue Jul 21 07:40:48.785504 2026] [security2:error] [pid 254995:tid 255152] [client 175.45.70.82:55828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT_gAAAzk"]
[Tue Jul 21 07:40:48.807881 2026] [security2:error] [pid 254995:tid 255279] [client 4.204.201.85:60368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/xamp.php"] [unique_id "al9MsP7v0rlcEGmVraFUAAAAA50"]
[Tue Jul 21 07:40:48.876986 2026] [security2:error] [pid 254995:tid 255263] [client 194.99.104.35:34454] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFUAgAAA40"]
[Tue Jul 21 07:40:48.877069 2026] [security2:error] [pid 254995:tid 255263] [client 194.99.104.35:34454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFUAgAAA40"]
[Tue Jul 21 07:40:48.920069 2026] [security2:error] [pid 254995:tid 255222] [client 4.204.201.85:45955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/abcd.php"] [unique_id "al9MsP7v0rlcEGmVraFUCAAAA34"]
[Tue Jul 21 07:40:48.973733 2026] [security2:error] [pid 254995:tid 255267] [client 20.226.60.151:62222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/edorxrr.php"] [unique_id "al9MsP7v0rlcEGmVraFUCgAAA5E"]
[Tue Jul 21 07:40:49.081224 2026] [security2:error] [pid 254995:tid 255193] [client 20.104.96.117:14556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/ccou.php"] [unique_id "al9Msf7v0rlcEGmVraFUDQAAA2I"]
[Tue Jul 21 07:40:49.084161 2026] [security2:error] [pid 254995:tid 255229] [client 4.204.201.85:59933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/bless.php"] [unique_id "al9Msf7v0rlcEGmVraFUDgAAA4I"]
[Tue Jul 21 07:40:49.142781 2026] [security2:error] [pid 254995:tid 255196] [client 103.106.20.201:62849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Msf7v0rlcEGmVraFUDwAAA2U"]
[Tue Jul 21 07:40:49.142897 2026] [security2:error] [pid 254995:tid 255196] [client 103.106.20.201:62849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Msf7v0rlcEGmVraFUDwAAA2U"]
[Tue Jul 21 07:40:49.151311 2026] [security2:error] [pid 254995:tid 255269] [client 209.141.34.121:55876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "ericksheik.com.br"] [uri "/"] [unique_id "al9Msf7v0rlcEGmVraFUEAAAA5M"]
[Tue Jul 21 07:40:49.164324 2026] [security2:error] [pid 254995:tid 255216] [client 20.226.60.151:22924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wefile.php"] [unique_id "al9Msf7v0rlcEGmVraFUEQAAA3g"]
[Tue Jul 21 07:40:49.233382 2026] [security2:error] [pid 254995:tid 255215] [client 122.162.144.145:20041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Msf7v0rlcEGmVraFUFwAAA3c"]
[Tue Jul 21 07:40:49.233510 2026] [security2:error] [pid 254995:tid 255215] [client 122.162.144.145:20041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Msf7v0rlcEGmVraFUFwAAA3c"]
[Tue Jul 21 07:40:49.278114 2026] [security2:error] [pid 254995:tid 255176] [client 4.204.201.85:3583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/file15.php"] [unique_id "al9Msf7v0rlcEGmVraFUGgAAA1E"]
[Tue Jul 21 07:40:49.370119 2026] [security2:error] [pid 254995:tid 255197] [client 4.204.201.85:56540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/file25.php"] [unique_id "al9Msf7v0rlcEGmVraFUIgAAA2Y"]
[Tue Jul 21 07:40:49.391789 2026] [security2:error] [pid 254995:tid 255155] [client 20.104.96.117:14599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/w3lls.php"] [unique_id "al9Msf7v0rlcEGmVraFUIwAAAzw"]
[Tue Jul 21 07:40:49.646159 2026] [security2:error] [pid 254995:tid 255257] [client 4.204.201.85:3547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/jp.php"] [unique_id "al9Msf7v0rlcEGmVraFULwAAA4c"]
[Tue Jul 21 07:40:49.647415 2026] [security2:error] [pid 254995:tid 255169] [client 4.204.201.85:57428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/file6.php"] [unique_id "al9Msf7v0rlcEGmVraFUMAAAA0o"]
[Tue Jul 21 07:40:49.683856 2026] [security2:error] [pid 254995:tid 255193] [client 20.104.96.117:14655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/test1.php"] [unique_id "al9Msf7v0rlcEGmVraFUMQAAA2I"]
[Tue Jul 21 07:40:49.718080 2026] [security2:error] [pid 254995:tid 255271] [client 20.220.225.223:5270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/dp.php"] [unique_id "al9Msf7v0rlcEGmVraFUMgAAA5U"]
[Tue Jul 21 07:40:49.726488 2026] [security2:error] [pid 254995:tid 255196] [client 20.226.60.151:59422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/zildan.php"] [unique_id "al9Msf7v0rlcEGmVraFUMwAAA2U"]
[Tue Jul 21 07:40:49.863579 2026] [security2:error] [pid 254995:tid 255173] [client 20.226.60.151:56272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/kq1.php"] [unique_id "al9Msf7v0rlcEGmVraFUNwAAA04"]
[Tue Jul 21 07:40:49.870695 2026] [security2:error] [pid 254995:tid 255160] [client 20.226.60.151:22918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9Msf7v0rlcEGmVraFUOAAAA0E"]
[Tue Jul 21 07:40:49.924909 2026] [security2:error] [pid 254995:tid 255275] [client 4.204.201.85:59930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/a2.php"] [unique_id "al9Msf7v0rlcEGmVraFUOwAAA5k"]
[Tue Jul 21 07:40:49.986864 2026] [security2:error] [pid 254995:tid 255132] [client 20.104.96.117:14387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/database.php"] [unique_id "al9Msf7v0rlcEGmVraFUQAAAAyU"]
[Tue Jul 21 07:40:50.200158 2026] [security2:error] [pid 254995:tid 255127] [client 4.204.201.85:61069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/file15.php"] [unique_id "al9Msv7v0rlcEGmVraFUSwAAAyA"]
[Tue Jul 21 07:40:50.296664 2026] [security2:error] [pid 254995:tid 255042] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Msv7v0rlcEGmVraFUTQADUy4"]
[Tue Jul 21 07:40:50.296786 2026] [security2:error] [pid 254995:tid 255178] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Msv7v0rlcEGmVraFUTQADUy4"]
[Tue Jul 21 07:40:50.335250 2026] [security2:error] [pid 254995:tid 255151] [client 20.151.10.161:11719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Msv7v0rlcEGmVraFUUgAAAzg"]
[Tue Jul 21 07:40:50.335276 2026] [security2:error] [pid 254995:tid 255267] [client 20.104.96.117:14609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/file.php"] [unique_id "al9Msv7v0rlcEGmVraFUUwAAA5E"]
[Tue Jul 21 07:40:50.410361 2026] [security2:error] [pid 254995:tid 255083] [remote 68.178.165.65:49048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.165.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "benattiodontologia.com.br"] [uri "/wp-login.php"] [unique_id "al9Msv7v0rlcEGmVraFUWAADS1c"]
[Tue Jul 21 07:40:50.475003 2026] [security2:error] [pid 254995:tid 255125] [client 4.204.201.85:57408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/f35.php"] [unique_id "al9Msv7v0rlcEGmVraFUXQAAAx4"]
[Tue Jul 21 07:40:50.577292 2026] [security2:error] [pid 254995:tid 255275] [client 4.204.201.85:7479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/f35.php"] [unique_id "al9Msv7v0rlcEGmVraFUYAAAA5k"]
[Tue Jul 21 07:40:50.659358 2026] [security2:error] [pid 254995:tid 255205] [client 20.104.96.117:13060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/file.php"] [unique_id "al9Msv7v0rlcEGmVraFUYgAAA24"]
[Tue Jul 21 07:40:50.725883 2026] [autoindex:error] [pid 254995:tid 255148] [client 20.226.60.151:22922] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:50.771599 2026] [security2:error] [pid 254995:tid 255175] [client 4.204.201.85:56530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-load.php"] [unique_id "al9Msv7v0rlcEGmVraFUZQAAA1A"]
[Tue Jul 21 07:40:50.953950 2026] [security2:error] [pid 254995:tid 255278] [client 193.36.225.66:24621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Msv7v0rlcEGmVraFUZgAAA5w"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:50.959337 2026] [security2:error] [pid 254995:tid 255224] [client 20.104.96.117:14623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/777.php"] [unique_id "al9Msv7v0rlcEGmVraFUbwAAA4A"]
[Tue Jul 21 07:40:51.018720 2026] [autoindex:error] [pid 254995:tid 255166] [client 20.226.60.151:22922] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:51.024144 2026] [security2:error] [pid 254995:tid 255140] [client 20.226.60.151:22922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Ms_7v0rlcEGmVraFUdAAAAy0"]
[Tue Jul 21 07:40:51.037043 2026] [security2:error] [pid 254995:tid 255267] [client 4.204.201.85:3544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/wp-load.php"] [unique_id "al9Ms_7v0rlcEGmVraFUdQAAA5E"]
[Tue Jul 21 07:40:51.047637 2026] [security2:error] [pid 254995:tid 255150] [client 4.204.201.85:61104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/xwpg.php"] [unique_id "al9Ms_7v0rlcEGmVraFUdgAAAzc"]
[Tue Jul 21 07:40:51.278076 2026] [security2:error] [pid 254995:tid 255218] [client 20.226.60.151:22340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/8.php"] [unique_id "al9Ms_7v0rlcEGmVraFUfAAAA3o"]
[Tue Jul 21 07:40:51.320696 2026] [security2:error] [pid 254995:tid 255199] [client 20.104.96.117:14378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/ssixta.php"] [unique_id "al9Ms_7v0rlcEGmVraFUfQAAA2g"]
[Tue Jul 21 07:40:51.337369 2026] [autoindex:error] [pid 254995:tid 255125] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:51.415466 2026] [security2:error] [pid 254995:tid 255205] [client 4.204.201.85:46018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/xyn.php"] [unique_id "al9Ms_7v0rlcEGmVraFUhwAAA24"]
[Tue Jul 21 07:40:51.425410 2026] [security2:error] [pid 254995:tid 255182] [client 117.217.38.194:61285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ms_7v0rlcEGmVraFUiwAAA1c"]
[Tue Jul 21 07:40:51.425524 2026] [security2:error] [pid 254995:tid 255182] [client 117.217.38.194:61285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ms_7v0rlcEGmVraFUiwAAA1c"]
[Tue Jul 21 07:40:51.430565 2026] [core:error] [pid 254995:tid 255219] [client 137.184.93.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.portalerotes.com.br/
[Tue Jul 21 07:40:51.430579 2026] [core:error] [pid 254995:tid 255219] [client 137.184.93.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.portalerotes.com.br/
[Tue Jul 21 07:40:51.440742 2026] [security2:error] [pid 254995:tid 255192] [client 20.226.60.151:22950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Ms_7v0rlcEGmVraFUjQAAA2E"]
[Tue Jul 21 07:40:51.457239 2026] [security2:error] [pid 254995:tid 255043] [remote 130.51.180.8:53158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "loopfinancas.com"] [uri "/wp-login.php"] [unique_id "al9Msf7v0rlcEGmVraFUKQADQC8"]
[Tue Jul 21 07:40:51.603292 2026] [security2:error] [pid 254995:tid 255198] [client 20.226.60.151:23140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/f6.php"] [unique_id "al9Ms_7v0rlcEGmVraFUlAAAA2c"]
[Tue Jul 21 07:40:51.605772 2026] [security2:error] [pid 254995:tid 255221] [client 20.220.225.223:5289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/old.php"] [unique_id "al9Ms_7v0rlcEGmVraFUlQAAA30"]
[Tue Jul 21 07:40:51.650690 2026] [security2:error] [pid 254995:tid 255150] [client 20.104.96.117:14585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/1c.php"] [unique_id "al9Ms_7v0rlcEGmVraFUmAAAAzc"]
[Tue Jul 21 07:40:51.659990 2026] [autoindex:error] [pid 254995:tid 255190] [client 4.204.201.85:59922] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:51.796778 2026] [security2:error] [pid 254995:tid 255136] [client 4.204.201.85:59922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/xstelth.php"] [unique_id "al9Ms_7v0rlcEGmVraFUmgAAAyk"]
[Tue Jul 21 07:40:51.810140 2026] [security2:error] [pid 254995:tid 255208] [client 103.174.34.15:51765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ms_7v0rlcEGmVraFUmwAAA3A"]
[Tue Jul 21 07:40:51.810270 2026] [security2:error] [pid 254995:tid 255208] [client 103.174.34.15:51765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ms_7v0rlcEGmVraFUmwAAA3A"]
[Tue Jul 21 07:40:51.817480 2026] [security2:error] [pid 254995:tid 255255] [client 20.151.10.161:11734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/2P.php"] [unique_id "al9Ms_7v0rlcEGmVraFUnAAAA4U"]
[Tue Jul 21 07:40:51.835469 2026] [security2:error] [pid 254995:tid 255131] [client 194.99.104.35:48608] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Ms_7v0rlcEGmVraFUnQAAAyQ"]
[Tue Jul 21 07:40:51.835569 2026] [security2:error] [pid 254995:tid 255131] [client 194.99.104.35:48608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Ms_7v0rlcEGmVraFUnQAAAyQ"]
[Tue Jul 21 07:40:51.866665 2026] [security2:error] [pid 254995:tid 255170] [client 20.226.60.151:22921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/inputs.php"] [unique_id "al9Ms_7v0rlcEGmVraFUnwAAA0s"]
[Tue Jul 21 07:40:51.893010 2026] [security2:error] [pid 254995:tid 255196] [client 20.220.225.223:31732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/billur.php"] [unique_id "al9Ms_7v0rlcEGmVraFUoAAAA2U"]
[Tue Jul 21 07:40:51.934283 2026] [security2:error] [pid 254995:tid 255005] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Ms_7v0rlcEGmVraFUogADmwk"]
[Tue Jul 21 07:40:51.934439 2026] [security2:error] [pid 254995:tid 255277] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Ms_7v0rlcEGmVraFUogADmwk"]
[Tue Jul 21 07:40:51.938331 2026] [security2:error] [pid 254995:tid 255154] [client 152.59.154.239:50013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ms_7v0rlcEGmVraFUoQAAAzs"]
[Tue Jul 21 07:40:51.938575 2026] [security2:error] [pid 254995:tid 255154] [client 152.59.154.239:50013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ms_7v0rlcEGmVraFUoQAAAzs"]
[Tue Jul 21 07:40:51.975051 2026] [security2:error] [pid 254995:tid 255141] [client 20.104.96.117:14356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/test2.php"] [unique_id "al9Ms_7v0rlcEGmVraFUowAAAy4"]
[Tue Jul 21 07:40:52.020558 2026] [security2:error] [pid 254995:tid 255199] [client 20.226.60.151:56259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9MtP7v0rlcEGmVraFUpgAAA2g"]
[Tue Jul 21 07:40:52.066984 2026] [security2:error] [pid 254995:tid 255155] [client 20.226.60.151:22938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/inputs.php"] [unique_id "al9MtP7v0rlcEGmVraFUrAAAAzw"]
[Tue Jul 21 07:40:52.071844 2026] [security2:error] [pid 254995:tid 255211] [client 4.204.201.85:59959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9MtP7v0rlcEGmVraFUrQAAA3M"]
[Tue Jul 21 07:40:52.081762 2026] [security2:error] [pid 254995:tid 255161] [client 139.167.225.182:59811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MtP7v0rlcEGmVraFUrgAAA0I"]
[Tue Jul 21 07:40:52.081888 2026] [security2:error] [pid 254995:tid 255161] [client 139.167.225.182:59811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MtP7v0rlcEGmVraFUrgAAA0I"]
[Tue Jul 21 07:40:52.175165 2026] [core:alert] [pid 254995:tid 255184] [client 57.141.18.113:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:40:52.247503 2026] [security2:error] [pid 254995:tid 255279] [client 20.226.60.151:22926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/classwithtostring.php"] [unique_id "al9MtP7v0rlcEGmVraFUuAAAA50"]
[Tue Jul 21 07:40:52.261793 2026] [security2:error] [pid 254995:tid 255187] [client 122.179.91.63:13190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MtP7v0rlcEGmVraFUuQAAA1w"]
[Tue Jul 21 07:40:52.262108 2026] [security2:error] [pid 254995:tid 255187] [client 122.179.91.63:13190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MtP7v0rlcEGmVraFUuQAAA1w"]
[Tue Jul 21 07:40:52.265672 2026] [security2:error] [pid 254995:tid 255268] [client 20.104.96.117:14625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/buy.php"] [unique_id "al9MtP7v0rlcEGmVraFUugAAA5I"]
[Tue Jul 21 07:40:52.336977 2026] [security2:error] [pid 254995:tid 255216] [client 37.140.223.154:43725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Msv7v0rlcEGmVraFUSAAAA3g"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:40:52.356401 2026] [security2:error] [pid 254995:tid 255178] [client 4.204.201.85:60413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/aaa.php"] [unique_id "al9MtP7v0rlcEGmVraFUvAAAA1M"]
[Tue Jul 21 07:40:52.383911 2026] [security2:error] [pid 254995:tid 255140] [client 20.226.60.151:22954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9MtP7v0rlcEGmVraFUvQAAAy0"]
[Tue Jul 21 07:40:52.450488 2026] [security2:error] [pid 254995:tid 255267] [client 20.226.60.151:23164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wp-blog.php"] [unique_id "al9MtP7v0rlcEGmVraFUvgAAA5E"]
[Tue Jul 21 07:40:52.450962 2026] [security2:error] [pid 254995:tid 255128] [client 4.204.201.85:46038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/ccc.php"] [unique_id "al9MtP7v0rlcEGmVraFUvwAAAyE"]
[Tue Jul 21 07:40:52.580501 2026] [security2:error] [pid 254995:tid 255223] [client 20.104.96.117:14575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/ssend.php"] [unique_id "al9MtP7v0rlcEGmVraFUyAAAA38"]
[Tue Jul 21 07:40:52.603273 2026] [security2:error] [pid 254995:tid 255125] [client 20.226.60.151:56307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/h02ugyh.php"] [unique_id "al9MtP7v0rlcEGmVraFUzAAAAx4"]
[Tue Jul 21 07:40:52.640343 2026] [security2:error] [pid 254995:tid 255173] [client 4.204.201.85:57415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/gecko.php"] [unique_id "al9MtP7v0rlcEGmVraFUzgAAA04"]
[Tue Jul 21 07:40:52.663311 2026] [security2:error] [pid 254995:tid 255025] [remote 202.73.26.211:43686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.26.73.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Ms_7v0rlcEGmVraFUmQADhh0"]
[Tue Jul 21 07:40:52.715612 2026] [autoindex:error] [pid 254995:tid 255211] [client 20.226.60.151:23145] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:52.724634 2026] [security2:error] [pid 254995:tid 255152] [client 20.226.60.151:23145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MtP7v0rlcEGmVraFU1AAAAzk"]
[Tue Jul 21 07:40:52.748400 2026] [security2:error] [pid 254995:tid 255214] [client 20.220.225.223:11591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/ms-new.php"] [unique_id "al9MtP7v0rlcEGmVraFU1wAAA3Y"]
[Tue Jul 21 07:40:52.832030 2026] [security2:error] [pid 254995:tid 255144] [client 20.226.60.151:62249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/miru1.php"] [unique_id "al9MtP7v0rlcEGmVraFU2AAAAzE"]
[Tue Jul 21 07:40:52.857613 2026] [security2:error] [pid 254995:tid 255200] [client 20.104.96.117:14629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/item.php"] [unique_id "al9MtP7v0rlcEGmVraFU2QAAA2k"]
[Tue Jul 21 07:40:52.880387 2026] [security2:error] [pid 254995:tid 255197] [client 59.96.220.140:52662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MtP7v0rlcEGmVraFU2gAAA2Y"]
[Tue Jul 21 07:40:52.880511 2026] [security2:error] [pid 254995:tid 255197] [client 59.96.220.140:52662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MtP7v0rlcEGmVraFU2gAAA2Y"]
[Tue Jul 21 07:40:52.894712 2026] [security2:error] [pid 254995:tid 255260] [client 4.204.201.85:46025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/w.php"] [unique_id "al9MtP7v0rlcEGmVraFU3AAAA4o"]
[Tue Jul 21 07:40:52.906203 2026] [security2:error] [pid 254995:tid 255263] [client 184.75.223.211:37630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MtP7v0rlcEGmVraFU3QAAA40"]
[Tue Jul 21 07:40:52.906282 2026] [security2:error] [pid 254995:tid 255263] [client 184.75.223.211:37630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MtP7v0rlcEGmVraFU3QAAA40"]
[Tue Jul 21 07:40:52.915361 2026] [security2:error] [pid 254995:tid 255279] [client 4.204.201.85:61102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/sh3ll.php"] [unique_id "al9MtP7v0rlcEGmVraFU3gAAA50"]
[Tue Jul 21 07:40:53.179855 2026] [security2:error] [pid 254995:tid 255202] [client 20.104.96.117:14558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/ss.php"] [unique_id "al9Mtf7v0rlcEGmVraFU6AAAA2s"]
[Tue Jul 21 07:40:53.205092 2026] [security2:error] [pid 254995:tid 255191] [client 4.204.201.85:57414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/pbck.php"] [unique_id "al9Mtf7v0rlcEGmVraFU6wAAA2A"]
[Tue Jul 21 07:40:53.294636 2026] [security2:error] [pid 254995:tid 255164] [client 20.226.60.151:23147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/ms-edit.php"] [unique_id "al9Mtf7v0rlcEGmVraFU8AAAA0U"]
[Tue Jul 21 07:40:53.308428 2026] [access_compat:error] [pid 254995:tid 255269] [client 162.241.63.68:33316] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:40:53.328973 2026] [security2:error] [pid 254995:tid 255193] [client 20.226.60.151:56210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-temp.php"] [unique_id "al9Mtf7v0rlcEGmVraFU8wAAA2I"]
[Tue Jul 21 07:40:53.360804 2026] [security2:error] [pid 254995:tid 255225] [client 20.226.60.151:62284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/sump1.php"] [unique_id "al9Mtf7v0rlcEGmVraFU9QAAA4E"]
[Tue Jul 21 07:40:53.428167 2026] [security2:error] [pid 254995:tid 255141] [client 128.127.105.184:60548] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Mtf7v0rlcEGmVraFU9gAAAy4"]
[Tue Jul 21 07:40:53.428271 2026] [security2:error] [pid 254995:tid 255141] [client 128.127.105.184:60548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Mtf7v0rlcEGmVraFU9gAAAy4"]
[Tue Jul 21 07:40:53.445011 2026] [security2:error] [pid 254995:tid 255148] [client 4.204.201.85:3554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Mtf7v0rlcEGmVraFU9wAAAzU"]
[Tue Jul 21 07:40:53.495503 2026] [security2:error] [pid 254995:tid 255155] [client 4.204.201.85:59947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/xiugai.php"] [unique_id "al9Mtf7v0rlcEGmVraFU-AAAAzw"]
[Tue Jul 21 07:40:53.538168 2026] [security2:error] [pid 254995:tid 255158] [client 20.104.96.117:14381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/hypo.php"] [unique_id "al9Mtf7v0rlcEGmVraFU_QAAAz8"]
[Tue Jul 21 07:40:53.777484 2026] [security2:error] [pid 254995:tid 255274] [client 4.204.201.85:57451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/e.php"] [unique_id "al9Mtf7v0rlcEGmVraFVBwAAA5g"]
[Tue Jul 21 07:40:53.799668 2026] [security2:error] [pid 254995:tid 255266] [client 20.151.10.161:53589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/.well-known/about.php"] [unique_id "al9Mtf7v0rlcEGmVraFVCwAAA5A"]
[Tue Jul 21 07:40:53.827469 2026] [security2:error] [pid 254995:tid 255221] [client 20.104.96.117:14528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/users.php"] [unique_id "al9Mtf7v0rlcEGmVraFVDQAAA30"]
[Tue Jul 21 07:40:53.834796 2026] [security2:error] [pid 254995:tid 255258] [client 20.220.225.223:31704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/mimpi.php"] [unique_id "al9Mtf7v0rlcEGmVraFVDgAAA4g"]
[Tue Jul 21 07:40:53.929504 2026] [security2:error] [pid 254995:tid 255202] [client 4.204.201.85:46050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/FWAZ.php"] [unique_id "al9Mtf7v0rlcEGmVraFVEAAAA2s"]
[Tue Jul 21 07:40:53.949381 2026] [security2:error] [pid 254995:tid 255146] [client 20.226.60.151:22917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9Mtf7v0rlcEGmVraFVEQAAAzM"]
[Tue Jul 21 07:40:54.051267 2026] [security2:error] [pid 254995:tid 255218] [client 4.204.201.85:60355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/for.php"] [unique_id "al9Mtv7v0rlcEGmVraFVGgAAA3o"]
[Tue Jul 21 07:40:54.119036 2026] [security2:error] [pid 254995:tid 255169] [client 173.24.185.52:50764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Mtv7v0rlcEGmVraFVHwAAA0o"]
[Tue Jul 21 07:40:54.119186 2026] [security2:error] [pid 254995:tid 255169] [client 173.24.185.52:50764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Mtv7v0rlcEGmVraFVHwAAA0o"]
[Tue Jul 21 07:40:54.132739 2026] [autoindex:error] [pid 254995:tid 255225] [client 198.235.24.158:59892] AH01276: Cannot serve directory /home1/guiiaz25/eduardolustosa.guiiaz.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:54.173407 2026] [security2:error] [pid 254995:tid 255215] [client 20.104.96.117:13095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/177.php"] [unique_id "al9Mtv7v0rlcEGmVraFVIQAAA3c"]
[Tue Jul 21 07:40:54.257310 2026] [security2:error] [pid 254995:tid 255158] [client 20.226.60.151:56278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9Mtv7v0rlcEGmVraFVJwAAAz8"]
[Tue Jul 21 07:40:54.328491 2026] [security2:error] [pid 254995:tid 255152] [client 4.204.201.85:61101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/ssh3ll.php"] [unique_id "al9Mtv7v0rlcEGmVraFVKQAAAzk"]
[Tue Jul 21 07:40:54.349916 2026] [security2:error] [pid 254995:tid 255211] [client 4.204.201.85:46053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/miru1.php"] [unique_id "al9Mtv7v0rlcEGmVraFVKwAAA3M"]
[Tue Jul 21 07:40:54.381144 2026] [security2:error] [pid 254995:tid 255145] [client 20.226.60.151:62278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/file5.php"] [unique_id "al9Mtv7v0rlcEGmVraFVLAAAAzI"]
[Tue Jul 21 07:40:54.441034 2026] [security2:error] [pid 254995:tid 255200] [client 62.102.148.187:59502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9Mtv7v0rlcEGmVraFVLQAAA2k"]
[Tue Jul 21 07:40:54.441156 2026] [security2:error] [pid 254995:tid 255200] [client 62.102.148.187:59502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9Mtv7v0rlcEGmVraFVLQAAA2k"]
[Tue Jul 21 07:40:54.450693 2026] [security2:error] [pid 254995:tid 255136] [client 20.104.96.117:14631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/config.php"] [unique_id "al9Mtv7v0rlcEGmVraFVLwAAAyk"]
[Tue Jul 21 07:40:54.509450 2026] [security2:error] [pid 254995:tid 255132] [client 20.226.60.151:59461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/csa.php"] [unique_id "al9Mtv7v0rlcEGmVraFVMQAAAyU"]
[Tue Jul 21 07:40:54.604777 2026] [security2:error] [pid 254995:tid 255224] [client 4.204.201.85:57438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/adminner.php"] [unique_id "al9Mtv7v0rlcEGmVraFVNQAAA4A"]
[Tue Jul 21 07:40:54.606374 2026] [security2:error] [pid 254995:tid 255278] [client 173.239.214.235:30275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.214.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mbarcondicionados.com.br"] [uri "/wp-login.php"] [unique_id "al9Mtf7v0rlcEGmVraFVAgAAA5w"]
[Tue Jul 21 07:40:54.731872 2026] [security2:error] [pid 254995:tid 255153] [client 136.144.33.53:22547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Mtv7v0rlcEGmVraFVOQAAAzo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:54.747168 2026] [security2:error] [pid 254995:tid 255229] [client 20.104.96.117:14561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/gettest.php"] [unique_id "al9Mtv7v0rlcEGmVraFVOgAAA4I"]
[Tue Jul 21 07:40:54.796911 2026] [security2:error] [pid 254995:tid 255131] [client 4.204.201.85:3543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/aa.php"] [unique_id "al9Mtv7v0rlcEGmVraFVPAAAAyQ"]
[Tue Jul 21 07:40:54.880878 2026] [security2:error] [pid 254995:tid 255267] [client 4.204.201.85:61094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/82.php"] [unique_id "al9Mtv7v0rlcEGmVraFVPgAAA5E"]
[Tue Jul 21 07:40:54.982274 2026] [security2:error] [pid 254995:tid 255162] [client 106.215.181.8:11890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mtv7v0rlcEGmVraFVPwAAA0M"]
[Tue Jul 21 07:40:54.982389 2026] [security2:error] [pid 254995:tid 255162] [client 106.215.181.8:11890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mtv7v0rlcEGmVraFVPwAAA0M"]
[Tue Jul 21 07:40:55.026957 2026] [security2:error] [pid 254995:tid 255021] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mt_7v0rlcEGmVraFVQAADiBk"]
[Tue Jul 21 07:40:55.027158 2026] [security2:error] [pid 254995:tid 255258] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mt_7v0rlcEGmVraFVQAADiBk"]
[Tue Jul 21 07:40:55.038205 2026] [autoindex:error] [pid 254995:tid 255215] [client 20.226.60.151:22913] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:55.098141 2026] [security2:error] [pid 254995:tid 255155] [client 20.226.60.151:22913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9Mt_7v0rlcEGmVraFVRAAAAzw"]
[Tue Jul 21 07:40:55.098772 2026] [security2:error] [pid 254995:tid 255148] [client 20.104.96.117:14383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/min.php"] [unique_id "al9Mt_7v0rlcEGmVraFVRQAAAzU"]
[Tue Jul 21 07:40:55.156641 2026] [security2:error] [pid 254995:tid 255261] [client 4.204.201.85:60394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/kir.php"] [unique_id "al9Mt_7v0rlcEGmVraFVSQAAA4s"]
[Tue Jul 21 07:40:55.168779 2026] [security2:error] [pid 254995:tid 255214] [client 4.204.201.85:7426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/122.php"] [unique_id "al9Mt_7v0rlcEGmVraFVTAAAA3Y"]
[Tue Jul 21 07:40:55.405102 2026] [security2:error] [pid 254995:tid 255257] [client 20.104.96.117:14636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/dvjul.php"] [unique_id "al9Mt_7v0rlcEGmVraFVVgAAA4c"]
[Tue Jul 21 07:40:55.429645 2026] [security2:error] [pid 254995:tid 255263] [client 4.204.201.85:56563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/up4.php"] [unique_id "al9Mt_7v0rlcEGmVraFVWAAAA40"]
[Tue Jul 21 07:40:55.550339 2026] [security2:error] [pid 254995:tid 255057] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mt_7v0rlcEGmVraFVWwADXj0"]
[Tue Jul 21 07:40:55.550497 2026] [security2:error] [pid 254995:tid 255189] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mt_7v0rlcEGmVraFVWwADXj0"]
[Tue Jul 21 07:40:55.555911 2026] [security2:error] [pid 254995:tid 255143] [client 20.151.10.161:12036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9Mt_7v0rlcEGmVraFVXAAAAzA"]
[Tue Jul 21 07:40:55.575439 2026] [security2:error] [pid 254995:tid 255273] [client 4.204.201.85:3571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/get.php"] [unique_id "al9Mt_7v0rlcEGmVraFVXQAAA5c"]
[Tue Jul 21 07:40:55.654525 2026] [autoindex:error] [pid 254995:tid 255179] [client 20.226.60.151:23106] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:55.701349 2026] [security2:error] [pid 254995:tid 255140] [client 20.104.96.117:13088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/biufile.php"] [unique_id "al9Mt_7v0rlcEGmVraFVYgAAAy0"]
[Tue Jul 21 07:40:55.706636 2026] [security2:error] [pid 254995:tid 255276] [client 4.204.201.85:59952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/xhar.php"] [unique_id "al9Mt_7v0rlcEGmVraFVZQAAA5o"]
[Tue Jul 21 07:40:55.719240 2026] [autoindex:error] [pid 254995:tid 255221] [client 20.226.60.151:23106] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:55.723791 2026] [security2:error] [pid 254995:tid 255168] [client 20.226.60.151:33480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/0xD.php"] [unique_id "al9Mt_7v0rlcEGmVraFVaQAAA0k"]
[Tue Jul 21 07:40:55.910209 2026] [security2:error] [pid 254995:tid 255192] [client 20.226.60.151:23106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/abcd.php"] [unique_id "al9Mt_7v0rlcEGmVraFVcgAAA2E"]
[Tue Jul 21 07:40:55.978218 2026] [security2:error] [pid 254995:tid 255211] [client 20.104.96.117:14550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/av.php"] [unique_id "al9Mt_7v0rlcEGmVraFVdAAAA3M"]
[Tue Jul 21 07:40:55.980228 2026] [security2:error] [pid 254995:tid 255144] [client 4.204.201.85:56455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/file1221.php"] [unique_id "al9Mt_7v0rlcEGmVraFVdQAAAzE"]
[Tue Jul 21 07:40:56.101338 2026] [security2:error] [pid 254995:tid 255159] [client 20.151.10.161:55261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/bob.php"] [unique_id "al9MuP7v0rlcEGmVraFVegAAA0A"]
[Tue Jul 21 07:40:56.239978 2026] [security2:error] [pid 254995:tid 255268] [client 4.204.201.85:45977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/as.php"] [unique_id "al9MuP7v0rlcEGmVraFVfQAAA5I"]
[Tue Jul 21 07:40:56.256151 2026] [security2:error] [pid 254995:tid 255149] [client 4.204.201.85:56473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/inx.php"] [unique_id "al9MuP7v0rlcEGmVraFVgAAAAzY"]
[Tue Jul 21 07:40:56.269219 2026] [security2:error] [pid 254995:tid 255279] [client 20.104.96.117:14353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/coffexium.php"] [unique_id "al9MuP7v0rlcEGmVraFVggAAA50"]
[Tue Jul 21 07:40:56.312355 2026] [security2:error] [pid 254995:tid 255275] [client 20.226.60.151:62234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/fnstall.php"] [unique_id "al9MuP7v0rlcEGmVraFVgwAAA5k"]
[Tue Jul 21 07:40:56.533604 2026] [security2:error] [pid 254995:tid 255169] [client 4.204.201.85:57468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/qqqa.php"] [unique_id "al9MuP7v0rlcEGmVraFVkgAAA0o"]
[Tue Jul 21 07:40:56.556841 2026] [security2:error] [pid 254995:tid 255077] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MuP7v0rlcEGmVraFVlAADnFE"]
[Tue Jul 21 07:40:56.557018 2026] [security2:error] [pid 254995:tid 255278] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MuP7v0rlcEGmVraFVlAADnFE"]
[Tue Jul 21 07:40:56.567800 2026] [security2:error] [pid 254995:tid 255141] [client 117.251.86.144:38242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MuP7v0rlcEGmVraFVlgAAAy4"]
[Tue Jul 21 07:40:56.567928 2026] [security2:error] [pid 254995:tid 255141] [client 117.251.86.144:38242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MuP7v0rlcEGmVraFVlgAAAy4"]
[Tue Jul 21 07:40:56.592856 2026] [security2:error] [pid 254995:tid 255199] [client 20.104.96.117:14352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/core.php"] [unique_id "al9MuP7v0rlcEGmVraFVmAAAA2g"]
[Tue Jul 21 07:40:56.608291 2026] [security2:error] [pid 254995:tid 255208] [client 20.226.60.151:59480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/w3llscc.php"] [unique_id "al9MuP7v0rlcEGmVraFVmQAAA3A"]
[Tue Jul 21 07:40:56.653844 2026] [security2:error] [pid 254995:tid 255220] [client 20.220.225.223:5278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/track.php"] [unique_id "al9MuP7v0rlcEGmVraFVmgAAA3w"]
[Tue Jul 21 07:40:56.684473 2026] [security2:error] [pid 254995:tid 255269] [client 4.204.201.85:46045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/ccou.php"] [unique_id "al9MuP7v0rlcEGmVraFVmwAAA5M"]
[Tue Jul 21 07:40:56.808740 2026] [security2:error] [pid 254995:tid 255214] [client 4.204.201.85:56458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/ffffile.php"] [unique_id "al9MuP7v0rlcEGmVraFVoQAAA3Y"]
[Tue Jul 21 07:40:56.876947 2026] [security2:error] [pid 254995:tid 255175] [client 122.186.204.214:51212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MuP7v0rlcEGmVraFVpgAAA1A"]
[Tue Jul 21 07:40:56.877069 2026] [security2:error] [pid 254995:tid 255175] [client 122.186.204.214:51212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MuP7v0rlcEGmVraFVpgAAA1A"]
[Tue Jul 21 07:40:56.908168 2026] [security2:error] [pid 254995:tid 255256] [client 20.104.96.117:14587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/als.php"] [unique_id "al9MuP7v0rlcEGmVraFVpwAAA4Y"]
[Tue Jul 21 07:40:56.950567 2026] [security2:error] [pid 254995:tid 255223] [client 62.102.148.187:59510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9MuP7v0rlcEGmVraFVqwAAA38"]
[Tue Jul 21 07:40:56.950731 2026] [security2:error] [pid 254995:tid 255223] [client 62.102.148.187:59510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9MuP7v0rlcEGmVraFVqwAAA38"]
[Tue Jul 21 07:40:56.976893 2026] [security2:error] [pid 254995:tid 255145] [client 20.226.60.151:22943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/file15.php"] [unique_id "al9MuP7v0rlcEGmVraFVrAAAAzI"]
[Tue Jul 21 07:40:57.085092 2026] [security2:error] [pid 254995:tid 255268] [client 4.204.201.85:56535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-firewall.php"] [unique_id "al9Muf7v0rlcEGmVraFVrgAAA5I"]
[Tue Jul 21 07:40:57.175951 2026] [security2:error] [pid 254995:tid 255136] [client 20.226.60.151:62333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/acp.php"] [unique_id "al9Muf7v0rlcEGmVraFVtAAAAyk"]
[Tue Jul 21 07:40:57.185470 2026] [security2:error] [pid 254995:tid 255275] [client 20.104.96.117:13072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/simple.php"] [unique_id "al9Muf7v0rlcEGmVraFVtQAAA5k"]
[Tue Jul 21 07:40:57.256756 2026] [security2:error] [pid 254995:tid 255178] [client 20.220.225.223:11193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/2352356666.php"] [unique_id "al9Muf7v0rlcEGmVraFVtwAAA1M"]
[Tue Jul 21 07:40:57.360361 2026] [security2:error] [pid 254995:tid 255177] [client 4.204.201.85:59939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/reviall.php"] [unique_id "al9Muf7v0rlcEGmVraFVvgAAA1I"]
[Tue Jul 21 07:40:57.461986 2026] [security2:error] [pid 254995:tid 255184] [client 20.151.10.161:55268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/crgio.php"] [unique_id "al9Muf7v0rlcEGmVraFVwgAAA1k"]
[Tue Jul 21 07:40:57.508354 2026] [security2:error] [pid 254995:tid 255155] [client 20.226.60.151:62328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/mosty.php"] [unique_id "al9Muf7v0rlcEGmVraFVwwAAAzw"]
[Tue Jul 21 07:40:57.521448 2026] [security2:error] [pid 254995:tid 255161] [client 20.104.96.117:14596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/init.php"] [unique_id "al9Muf7v0rlcEGmVraFVxAAAA0I"]
[Tue Jul 21 07:40:57.551175 2026] [security2:error] [pid 254995:tid 255170] [client 20.226.60.151:23105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/jp.php"] [unique_id "al9Muf7v0rlcEGmVraFVxQAAA0s"]
[Tue Jul 21 07:40:57.801636 2026] [security2:error] [pid 254995:tid 255267] [client 37.140.223.152:43671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MuP7v0rlcEGmVraFVjAAAA5E"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:40:57.807828 2026] [security2:error] [pid 254995:tid 255197] [client 20.104.96.117:14573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/fpwch.php"] [unique_id "al9Muf7v0rlcEGmVraFVyQAAA2Y"]
[Tue Jul 21 07:40:57.889250 2026] [security2:error] [pid 254995:tid 255192] [client 4.204.201.85:7446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/w3lls.php"] [unique_id "al9Muf7v0rlcEGmVraFVzgAAA2E"]
[Tue Jul 21 07:40:58.005840 2026] [security2:error] [pid 254995:tid 255219] [client 20.151.10.161:12060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/pucci.php"] [unique_id "al9Muv7v0rlcEGmVraFV0wAAA3s"]
[Tue Jul 21 07:40:58.089769 2026] [security2:error] [pid 254995:tid 255216] [client 20.104.96.117:14632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/domvf.php"] [unique_id "al9Muv7v0rlcEGmVraFV1QAAA3g"]
[Tue Jul 21 07:40:58.162288 2026] [security2:error] [pid 254995:tid 255150] [client 20.226.60.151:23121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/f35.php"] [unique_id "al9Muv7v0rlcEGmVraFV1gAAAzc"]
[Tue Jul 21 07:40:58.168987 2026] [security2:error] [pid 254995:tid 255218] [client 122.164.127.47:49562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Muv7v0rlcEGmVraFV1wAAA3o"]
[Tue Jul 21 07:40:58.169113 2026] [security2:error] [pid 254995:tid 255218] [client 122.164.127.47:49562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Muv7v0rlcEGmVraFV1wAAA3o"]
[Tue Jul 21 07:40:58.192254 2026] [security2:error] [pid 254995:tid 255154] [client 20.220.225.223:19302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/wicked.php"] [unique_id "al9Muv7v0rlcEGmVraFV2gAAAzs"]
[Tue Jul 21 07:40:58.308898 2026] [security2:error] [pid 254995:tid 255255] [client 20.226.60.151:62283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/6.php"] [unique_id "al9Muv7v0rlcEGmVraFV3AAAA4U"]
[Tue Jul 21 07:40:58.389890 2026] [security2:error] [pid 254995:tid 255184] [client 20.226.60.151:22955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wp-load.php"] [unique_id "al9Muv7v0rlcEGmVraFV4QAAA1k"]
[Tue Jul 21 07:40:58.503588 2026] [security2:error] [pid 254995:tid 255144] [client 20.226.60.151:22915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/xyn.php"] [unique_id "al9Muv7v0rlcEGmVraFV5wAAAzE"]
[Tue Jul 21 07:40:58.550979 2026] [security2:error] [pid 254995:tid 255176] [client 20.104.96.117:14627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/wp.php"] [unique_id "al9Muv7v0rlcEGmVraFV6AAAA1E"]
[Tue Jul 21 07:40:58.609065 2026] [security2:error] [pid 254995:tid 255213] [client 154.192.233.199:59829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Muv7v0rlcEGmVraFV6QAAA3U"]
[Tue Jul 21 07:40:58.609195 2026] [security2:error] [pid 254995:tid 255213] [client 154.192.233.199:59829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Muv7v0rlcEGmVraFV6QAAA3U"]
[Tue Jul 21 07:40:58.619434 2026] [security2:error] [pid 254995:tid 254997] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Muv7v0rlcEGmVraFV6wADcwE"]
[Tue Jul 21 07:40:58.619576 2026] [security2:error] [pid 254995:tid 255211] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Muv7v0rlcEGmVraFV6wADcwE"]
[Tue Jul 21 07:40:58.673763 2026] [security2:error] [pid 254995:tid 255037] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Muv7v0rlcEGmVraFV7AADgSk"]
[Tue Jul 21 07:40:58.673921 2026] [security2:error] [pid 254995:tid 255225] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Muv7v0rlcEGmVraFV7AADgSk"]
[Tue Jul 21 07:40:58.716861 2026] [autoindex:error] [pid 254995:tid 255222] [client 20.226.60.151:22961] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:58.774176 2026] [security2:error] [pid 254995:tid 255192] [client 20.226.60.151:56280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9Muv7v0rlcEGmVraFV7wAAA2E"]
[Tue Jul 21 07:40:58.805967 2026] [autoindex:error] [pid 254995:tid 255193] [client 20.226.60.151:22961] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:58.811056 2026] [security2:error] [pid 254995:tid 255156] [client 20.226.60.151:22961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/ccc.php"] [unique_id "al9Muv7v0rlcEGmVraFV9AAAAz0"]
[Tue Jul 21 07:40:58.868511 2026] [security2:error] [pid 254995:tid 255263] [client 20.104.96.117:14392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/class.php"] [unique_id "al9Muv7v0rlcEGmVraFV9wAAA40"]
[Tue Jul 21 07:40:58.876594 2026] [security2:error] [pid 254995:tid 255202] [client 182.8.255.181:17691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Muv7v0rlcEGmVraFV-AAAA2s"]
[Tue Jul 21 07:40:58.876716 2026] [security2:error] [pid 254995:tid 255202] [client 182.8.255.181:17691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Muv7v0rlcEGmVraFV-AAAA2s"]
[Tue Jul 21 07:40:59.098346 2026] [security2:error] [pid 254995:tid 255278] [client 20.226.60.151:59418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wpx.php"] [unique_id "al9Mu_7v0rlcEGmVraFWBAAAA5w"]
[Tue Jul 21 07:40:59.102210 2026] [security2:error] [pid 254995:tid 255258] [client 103.86.117.203:64603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mu_7v0rlcEGmVraFWBQAAA4g"]
[Tue Jul 21 07:40:59.102360 2026] [security2:error] [pid 254995:tid 255258] [client 103.86.117.203:64603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mu_7v0rlcEGmVraFWBQAAA4g"]
[Tue Jul 21 07:40:59.214342 2026] [security2:error] [pid 254995:tid 255220] [client 20.104.96.117:14571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/echkm.php"] [unique_id "al9Mu_7v0rlcEGmVraFWBgAAA3w"]
[Tue Jul 21 07:40:59.336621 2026] [security2:error] [pid 254995:tid 255179] [client 20.226.60.151:33485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9Mu_7v0rlcEGmVraFWCgAAA1Q"]
[Tue Jul 21 07:40:59.437607 2026] [proxy:error] [pid 254995:tid 255158] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:59.437674 2026] [proxy_http:error] [pid 254995:tid 255158] [client 84.37.204.163:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:59.438298 2026] [proxy:error] [pid 254995:tid 255158] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:59.438331 2026] [proxy_http:error] [pid 254995:tid 255158] [client 84.37.204.163:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:59.504909 2026] [security2:error] [pid 254995:tid 255159] [client 20.104.96.117:14532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/lib.php"] [unique_id "al9Mu_7v0rlcEGmVraFWGAAAA0A"]
[Tue Jul 21 07:40:59.505319 2026] [security2:error] [pid 254995:tid 255195] [client 175.45.70.82:56344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mu_7v0rlcEGmVraFWGQAAA2Q"]
[Tue Jul 21 07:40:59.505473 2026] [security2:error] [pid 254995:tid 255195] [client 175.45.70.82:56344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mu_7v0rlcEGmVraFWGQAAA2Q"]
[Tue Jul 21 07:40:59.536839 2026] [security2:error] [pid 254995:tid 255279] [client 202.143.127.214:63435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mu_7v0rlcEGmVraFWGgAAA50"]
[Tue Jul 21 07:40:59.536976 2026] [security2:error] [pid 254995:tid 255279] [client 202.143.127.214:63435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mu_7v0rlcEGmVraFWGgAAA50"]
[Tue Jul 21 07:40:59.568719 2026] [security2:error] [pid 254995:tid 255145] [client 4.204.201.85:7430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/test1.php"] [unique_id "al9Mu_7v0rlcEGmVraFWHQAAAzI"]
[Tue Jul 21 07:40:59.750634 2026] [security2:error] [pid 254995:tid 255260] [client 136.144.33.215:21831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Mu_7v0rlcEGmVraFWHgAAA4o"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:59.859362 2026] [security2:error] [pid 254995:tid 255182] [client 20.104.96.117:14547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/login.php"] [unique_id "al9Mu_7v0rlcEGmVraFWHwAAA1c"]
[Tue Jul 21 07:40:59.930516 2026] [security2:error] [pid 254995:tid 255216] [client 20.226.60.151:23127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/w.php"] [unique_id "al9Mu_7v0rlcEGmVraFWIAAAA3g"]
[Tue Jul 21 07:40:59.971853 2026] [security2:error] [pid 254995:tid 255205] [client 103.106.20.201:63446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mu_7v0rlcEGmVraFWIgAAA24"]
[Tue Jul 21 07:40:59.971961 2026] [security2:error] [pid 254995:tid 255205] [client 103.106.20.201:63446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mu_7v0rlcEGmVraFWIgAAA24"]
[Tue Jul 21 07:41:00.016563 2026] [security2:error] [pid 254995:tid 255276] [client 122.162.144.145:31789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MvP7v0rlcEGmVraFWKQAAA5o"]
[Tue Jul 21 07:41:00.016646 2026] [security2:error] [pid 254995:tid 255276] [client 122.162.144.145:31789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MvP7v0rlcEGmVraFWKQAAA5o"]
[Tue Jul 21 07:41:00.157364 2026] [security2:error] [pid 254995:tid 255208] [client 20.104.96.117:14570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/a2.php"] [unique_id "al9MvP7v0rlcEGmVraFWLQAAA3A"]
[Tue Jul 21 07:41:00.451881 2026] [security2:error] [pid 254995:tid 255140] [client 20.104.96.117:14598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/d61.php"] [unique_id "al9MvP7v0rlcEGmVraFWMQAAAy0"]
[Tue Jul 21 07:41:00.669607 2026] [security2:error] [pid 254995:tid 255159] [client 20.151.10.161:53623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-temp.php"] [unique_id "al9MvP7v0rlcEGmVraFWOgAAA0A"]
[Tue Jul 21 07:41:00.758908 2026] [security2:error] [pid 254995:tid 255279] [client 20.104.96.117:14635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/info.php"] [unique_id "al9MvP7v0rlcEGmVraFWPAAAA50"]
[Tue Jul 21 07:41:00.766884 2026] [security2:error] [pid 254995:tid 255097] [remote 216.73.160.190:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marketingderua.com.br"] [uri "/wp-login.php"] [unique_id "al9MvP7v0rlcEGmVraFWPQADfmU"]
[Tue Jul 21 07:41:00.912905 2026] [security2:error] [pid 254995:tid 255260] [client 20.226.60.151:62212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/qqqa.php"] [unique_id "al9MvP7v0rlcEGmVraFWQgAAA4o"]
[Tue Jul 21 07:41:00.918138 2026] [autoindex:error] [pid 254995:tid 255189] [client 172.252.180.7:0] AH01276: Cannot serve directory /home2/inlaud99/distribuidorasja.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:41:01.096530 2026] [security2:error] [pid 254995:tid 255157] [client 20.226.60.151:59395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-css.php"] [unique_id "al9Mvf7v0rlcEGmVraFWSgAAAz4"]
[Tue Jul 21 07:41:01.097050 2026] [security2:error] [pid 254995:tid 255154] [client 20.104.96.117:14607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/11.php"] [unique_id "al9Mvf7v0rlcEGmVraFWSwAAAzs"]
[Tue Jul 21 07:41:01.251963 2026] [security2:error] [pid 254995:tid 255196] [client 59.96.220.140:53180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Mvf7v0rlcEGmVraFWTgAAA2U"]
[Tue Jul 21 07:41:01.255211 2026] [security2:error] [pid 254995:tid 255196] [client 59.96.220.140:53180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Mvf7v0rlcEGmVraFWTgAAA2U"]
[Tue Jul 21 07:41:01.288711 2026] [security2:error] [pid 254995:tid 255278] [client 51.68.107.159:30823] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "avermetais.com.br"] [uri "/robots.txt"] [unique_id "al9Mvf7v0rlcEGmVraFWUAAAA5w"]
[Tue Jul 21 07:41:01.288920 2026] [security2:error] [pid 254995:tid 255278] [client 51.68.107.159:30823] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "avermetais.com.br"] [uri "/robots.txt"] [unique_id "al9Mvf7v0rlcEGmVraFWUAAAA5w"]
[Tue Jul 21 07:41:01.397969 2026] [security2:error] [pid 254995:tid 255179] [client 20.104.96.117:14569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/v2.php"] [unique_id "al9Mvf7v0rlcEGmVraFWVgAAA1Q"]
[Tue Jul 21 07:41:01.413153 2026] [security2:error] [pid 254995:tid 255197] [client 20.220.225.223:5301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/pn.php"] [unique_id "al9Mvf7v0rlcEGmVraFWVwAAA2Y"]
[Tue Jul 21 07:41:01.427342 2026] [security2:error] [pid 254995:tid 255170] [client 4.204.201.85:7487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/database.php"] [unique_id "al9Mvf7v0rlcEGmVraFWWAAAA0s"]
[Tue Jul 21 07:41:01.435885 2026] [security2:error] [pid 254995:tid 255014] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mvf7v0rlcEGmVraFWWQADJBI"]
[Tue Jul 21 07:41:01.436077 2026] [security2:error] [pid 254995:tid 255131] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mvf7v0rlcEGmVraFWWQADJBI"]
[Tue Jul 21 07:41:01.515103 2026] [security2:error] [pid 254995:tid 255275] [client 37.140.223.191:46697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Mvf7v0rlcEGmVraFWVQAAA5k"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:01.585626 2026] [security2:error] [pid 254995:tid 255191] [client 20.226.60.151:56197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/jj.php"] [unique_id "al9Mvf7v0rlcEGmVraFWYQAAA2A"]
[Tue Jul 21 07:41:01.670243 2026] [security2:error] [pid 254995:tid 255184] [client 20.226.60.151:23123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Mvf7v0rlcEGmVraFWZAAAA1k"]
[Tue Jul 21 07:41:01.689410 2026] [security2:error] [pid 254995:tid 255185] [client 20.104.96.117:14542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/panel.php"] [unique_id "al9Mvf7v0rlcEGmVraFWZQAAA1o"]
[Tue Jul 21 07:41:01.749354 2026] [security2:error] [pid 254995:tid 255192] [client 20.197.195.24:13573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/classwithtostring.php"] [unique_id "al9Mvf7v0rlcEGmVraFWaAAAA2E"]
[Tue Jul 21 07:41:01.811921 2026] [security2:error] [pid 254995:tid 255187] [client 20.220.225.223:34256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/edit.php"] [unique_id "al9Mvf7v0rlcEGmVraFWagAAA1w"]
[Tue Jul 21 07:41:01.882966 2026] [security2:error] [pid 254995:tid 255166] [client 117.217.38.194:61766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mvf7v0rlcEGmVraFWbQAAA0c"]
[Tue Jul 21 07:41:01.883150 2026] [security2:error] [pid 254995:tid 255166] [client 117.217.38.194:61766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mvf7v0rlcEGmVraFWbQAAA0c"]
[Tue Jul 21 07:41:01.889054 2026] [security2:error] [pid 254995:tid 255216] [client 20.151.10.161:53573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9Mvf7v0rlcEGmVraFWbgAAA3g"]
[Tue Jul 21 07:41:01.990476 2026] [security2:error] [pid 254995:tid 255224] [client 20.104.96.117:14399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/dex.php"] [unique_id "al9Mvf7v0rlcEGmVraFWcQAAA4A"]
[Tue Jul 21 07:41:02.341020 2026] [security2:error] [pid 254995:tid 255225] [client 20.104.96.117:13078] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/1.php"] [unique_id "al9Mvv7v0rlcEGmVraFWgwAAA4E"]
[Tue Jul 21 07:41:02.341123 2026] [security2:error] [pid 254995:tid 255225] [client 20.104.96.117:13078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/1.php"] [unique_id "al9Mvv7v0rlcEGmVraFWgwAAA4E"]
[Tue Jul 21 07:41:02.521672 2026] [security2:error] [pid 254995:tid 255129] [client 4.204.201.85:7427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/file.php"] [unique_id "al9Mvv7v0rlcEGmVraFWhQAAAyI"]
[Tue Jul 21 07:41:02.592663 2026] [security2:error] [pid 254995:tid 255190] [client 103.174.34.15:52244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mvv7v0rlcEGmVraFWjAAAA18"]
[Tue Jul 21 07:41:02.593124 2026] [security2:error] [pid 254995:tid 255190] [client 103.174.34.15:52244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mvv7v0rlcEGmVraFWjAAAA18"]
[Tue Jul 21 07:41:02.596933 2026] [security2:error] [pid 254995:tid 255040] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mvv7v0rlcEGmVraFWjQADPyw"]
[Tue Jul 21 07:41:02.597098 2026] [security2:error] [pid 254995:tid 255158] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mvv7v0rlcEGmVraFWjQADPyw"]
[Tue Jul 21 07:41:02.656646 2026] [security2:error] [pid 254995:tid 255182] [client 139.167.225.182:60464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mvv7v0rlcEGmVraFWkgAAA1c"]
[Tue Jul 21 07:41:02.656784 2026] [security2:error] [pid 254995:tid 255182] [client 139.167.225.182:60464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mvv7v0rlcEGmVraFWkgAAA1c"]
[Tue Jul 21 07:41:02.699456 2026] [security2:error] [pid 254995:tid 255154] [client 20.104.96.117:14654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/ms.php"] [unique_id "al9Mvv7v0rlcEGmVraFWlgAAAzs"]
[Tue Jul 21 07:41:02.705018 2026] [security2:error] [pid 254995:tid 255157] [client 20.226.60.151:62322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/aunmc.php"] [unique_id "al9Mvv7v0rlcEGmVraFWmAAAAz4"]
[Tue Jul 21 07:41:02.838456 2026] [security2:error] [pid 254995:tid 255278] [client 122.179.91.63:10547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Mvv7v0rlcEGmVraFWoAAAA5w"]
[Tue Jul 21 07:41:02.838559 2026] [security2:error] [pid 254995:tid 255278] [client 122.179.91.63:10547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Mvv7v0rlcEGmVraFWoAAAA5w"]
[Tue Jul 21 07:41:02.997079 2026] [proxy:error] [pid 254995:tid 255275] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:02.997155 2026] [proxy_http:error] [pid 254995:tid 255275] [client 20.104.96.117:14529] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:02.997768 2026] [proxy:error] [pid 254995:tid 255275] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:02.997795 2026] [proxy_http:error] [pid 254995:tid 255275] [client 20.104.96.117:14529] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:03.195336 2026] [security2:error] [pid 254995:tid 255164] [client 152.59.154.239:64170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mv_7v0rlcEGmVraFWqwAAA0U"]
[Tue Jul 21 07:41:03.195452 2026] [security2:error] [pid 254995:tid 255164] [client 152.59.154.239:64170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mv_7v0rlcEGmVraFWqwAAA0U"]
[Tue Jul 21 07:41:03.267140 2026] [security2:error] [pid 254995:tid 255222] [client 20.226.60.151:62209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/uoocf.php"] [unique_id "al9Mv_7v0rlcEGmVraFWsAAAA34"]
[Tue Jul 21 07:41:03.366036 2026] [security2:error] [pid 254995:tid 255208] [client 20.104.96.117:13068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/memberfuns.php"] [unique_id "al9Mv_7v0rlcEGmVraFWtQAAA3A"]
[Tue Jul 21 07:41:03.443583 2026] [security2:error] [pid 254995:tid 255156] [client 4.204.201.85:3525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/file.php"] [unique_id "al9Mv_7v0rlcEGmVraFWtwAAAz0"]
[Tue Jul 21 07:41:03.528364 2026] [security2:error] [pid 254995:tid 255193] [client 20.220.225.223:19324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/edit.php"] [unique_id "al9Mv_7v0rlcEGmVraFWuAAAA2I"]
[Tue Jul 21 07:41:03.597245 2026] [security2:error] [pid 254995:tid 255190] [client 20.226.60.151:23157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/FWAZ.php"] [unique_id "al9Mv_7v0rlcEGmVraFWugAAA18"]
[Tue Jul 21 07:41:03.643563 2026] [security2:error] [pid 254995:tid 255256] [client 20.226.60.151:59414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/ho.php"] [unique_id "al9Mv_7v0rlcEGmVraFWvgAAA4Y"]
[Tue Jul 21 07:41:03.681381 2026] [security2:error] [pid 254995:tid 255178] [client 20.104.96.117:14645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/0.php"] [unique_id "al9Mv_7v0rlcEGmVraFWvwAAA1M"]
[Tue Jul 21 07:41:03.738005 2026] [security2:error] [pid 254995:tid 255004] [remote 193.36.225.189:41107] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/"] [unique_id "al9Mv_7v0rlcEGmVraFWwQADeAg"], referer: http://tabelionatopraiadebelas.com.br/
[Tue Jul 21 07:41:03.895911 2026] [security2:error] [pid 254995:tid 255275] [client 20.151.10.161:53629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/puc.php"] [unique_id "al9Mv_7v0rlcEGmVraFWygAAA5k"]
[Tue Jul 21 07:41:04.015843 2026] [security2:error] [pid 254995:tid 255192] [client 172.245.102.30:53203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Mv_7v0rlcEGmVraFWxgAAA2E"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:04.031921 2026] [security2:error] [pid 254995:tid 255214] [client 20.104.96.117:14376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/BDKR28.php"] [unique_id "al9MwP7v0rlcEGmVraFWzAAAA3Y"]
[Tue Jul 21 07:41:04.246859 2026] [security2:error] [pid 254995:tid 255023] [remote 193.36.225.189:41107] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/wp-includes/css/buttons.css"] [unique_id "al9MwP7v0rlcEGmVraFW0wADThs"], referer: http://tabelionatopraiadebelas.com.br/wp-includes/css/buttons.css
[Tue Jul 21 07:41:04.324614 2026] [security2:error] [pid 254995:tid 255229] [client 20.104.96.117:13083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/green1.php"] [unique_id "al9MwP7v0rlcEGmVraFW2gAAA4I"]
[Tue Jul 21 07:41:04.470681 2026] [proxy:error] [pid 254995:tid 255274] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:04.470749 2026] [proxy_http:error] [pid 254995:tid 255274] [client 23.230.121.85:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:04.471379 2026] [proxy:error] [pid 254995:tid 255274] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:04.471407 2026] [proxy_http:error] [pid 254995:tid 255274] [client 23.230.121.85:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:04.578040 2026] [security2:error] [pid 254995:tid 255187] [client 20.226.60.151:33476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/iywwi.php"] [unique_id "al9MwP7v0rlcEGmVraFW4wAAA1w"]
[Tue Jul 21 07:41:04.609093 2026] [security2:error] [pid 254995:tid 255200] [client 20.226.60.151:22970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/miru1.php"] [unique_id "al9MwP7v0rlcEGmVraFW5AAAA2k"]
[Tue Jul 21 07:41:04.626475 2026] [security2:error] [pid 254995:tid 255199] [client 20.104.96.117:13087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/nc4.php"] [unique_id "al9MwP7v0rlcEGmVraFW5gAAA2g"]
[Tue Jul 21 07:41:04.696412 2026] [security2:error] [pid 254995:tid 255175] [client 128.127.105.184:53030] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9MwP7v0rlcEGmVraFW8AAAA1A"]
[Tue Jul 21 07:41:04.696502 2026] [security2:error] [pid 254995:tid 255175] [client 128.127.105.184:53030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9MwP7v0rlcEGmVraFW8AAAA1A"]
[Tue Jul 21 07:41:04.743897 2026] [security2:error] [pid 254995:tid 255174] [client 173.24.185.52:51240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MwP7v0rlcEGmVraFXBwAAA08"]
[Tue Jul 21 07:41:04.748404 2026] [security2:error] [pid 254995:tid 255174] [client 173.24.185.52:51240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MwP7v0rlcEGmVraFXBwAAA08"]
[Tue Jul 21 07:41:04.787443 2026] [security2:error] [pid 255769:tid 255797] [remote 74.7.228.9:54626] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "arielson.com.br"] [uri "/index.php"] [unique_id "al9MobxMYwyVGnfuwsKwcgAD0hs"]
[Tue Jul 21 07:41:04.847920 2026] [security2:error] [pid 254995:tid 255189] [client 4.204.201.85:46029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/777.php"] [unique_id "al9MwP7v0rlcEGmVraFXDgAAA14"]
[Tue Jul 21 07:41:04.943071 2026] [security2:error] [pid 254995:tid 255263] [client 20.226.60.151:56215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9MwP7v0rlcEGmVraFXEAAAA40"]
[Tue Jul 21 07:41:04.954076 2026] [security2:error] [pid 254995:tid 255026] [remote 193.36.225.189:41107] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/media/system/js/core.js"] [unique_id "al9MwP7v0rlcEGmVraFXEQADlB4"], referer: http://tabelionatopraiadebelas.com.br/media/system/js/core.js
[Tue Jul 21 07:41:04.974366 2026] [security2:error] [pid 254995:tid 255184] [client 20.104.96.117:14577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/a1.php"] [unique_id "al9MwP7v0rlcEGmVraFXEgAAA1k"]
[Tue Jul 21 07:41:05.427103 2026] [security2:error] [pid 254995:tid 255269] [client 20.104.96.117:14642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/eee.php"] [unique_id "al9Mwf7v0rlcEGmVraFXHwAAA5M"]
[Tue Jul 21 07:41:05.639560 2026] [security2:error] [pid 254995:tid 255168] [client 106.215.181.8:24340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mwf7v0rlcEGmVraFXJgAAA0k"]
[Tue Jul 21 07:41:05.639701 2026] [security2:error] [pid 254995:tid 255168] [client 106.215.181.8:24340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mwf7v0rlcEGmVraFXJgAAA0k"]
[Tue Jul 21 07:41:05.694028 2026] [security2:error] [pid 254995:tid 255131] [client 20.151.10.161:12050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/themes.php"] [unique_id "al9Mwf7v0rlcEGmVraFXJwAAAyQ"]
[Tue Jul 21 07:41:05.744498 2026] [security2:error] [pid 254995:tid 255200] [client 20.104.96.117:13109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/wp-aothait.php"] [unique_id "al9Mwf7v0rlcEGmVraFXLgAAA2k"]
[Tue Jul 21 07:41:05.816852 2026] [security2:error] [pid 254995:tid 255213] [client 136.144.33.107:44507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MwP7v0rlcEGmVraFW5wAAA3U"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:05.913858 2026] [security2:error] [pid 254995:tid 255110] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mwf7v0rlcEGmVraFXNwADLXI"]
[Tue Jul 21 07:41:05.914074 2026] [security2:error] [pid 254995:tid 255140] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mwf7v0rlcEGmVraFXNwADLXI"]
[Tue Jul 21 07:41:06.047787 2026] [security2:error] [pid 254995:tid 255272] [client 20.226.60.151:62233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/gqgsa.php"] [unique_id "al9Mwv7v0rlcEGmVraFXOgAAA5Y"]
[Tue Jul 21 07:41:06.061537 2026] [security2:error] [pid 254995:tid 255033] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mwv7v0rlcEGmVraFXOwADLiU"]
[Tue Jul 21 07:41:06.061722 2026] [security2:error] [pid 254995:tid 255141] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mwv7v0rlcEGmVraFXOwADLiU"]
[Tue Jul 21 07:41:06.123556 2026] [security2:error] [pid 254995:tid 255225] [client 20.104.96.117:14560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/config.json.php"] [unique_id "al9Mwv7v0rlcEGmVraFXPAAAA4E"]
[Tue Jul 21 07:41:06.696060 2026] [security2:error] [pid 254995:tid 255168] [client 20.104.96.117:14578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9Mwv7v0rlcEGmVraFXSwAAA0k"]
[Tue Jul 21 07:41:06.722726 2026] [security2:error] [pid 254995:tid 255265] [client 20.226.60.151:62305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/elbzl.php"] [unique_id "al9Mwv7v0rlcEGmVraFXTAAAA48"]
[Tue Jul 21 07:41:06.962328 2026] [security2:error] [pid 254995:tid 255278] [client 20.151.10.161:53614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/dx.php"] [unique_id "al9Mwv7v0rlcEGmVraFXVgAAA5w"]
[Tue Jul 21 07:41:07.074008 2026] [security2:error] [pid 254995:tid 255202] [client 20.226.60.151:62227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/adjig.php"] [unique_id "al9Mw_7v0rlcEGmVraFXWAAAA2s"]
[Tue Jul 21 07:41:07.190505 2026] [security2:error] [pid 254995:tid 255164] [client 20.104.96.117:13117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/k2.php"] [unique_id "al9Mw_7v0rlcEGmVraFXXQAAA0U"]
[Tue Jul 21 07:41:07.262095 2026] [security2:error] [pid 254995:tid 255269] [client 117.251.86.144:38446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Mw_7v0rlcEGmVraFXXgAAA5M"]
[Tue Jul 21 07:41:07.262217 2026] [security2:error] [pid 254995:tid 255269] [client 117.251.86.144:38446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Mw_7v0rlcEGmVraFXXgAAA5M"]
[Tue Jul 21 07:41:07.300920 2026] [security2:error] [pid 254995:tid 255034] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mw_7v0rlcEGmVraFXXwADTyY"]
[Tue Jul 21 07:41:07.301061 2026] [security2:error] [pid 254995:tid 255174] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mw_7v0rlcEGmVraFXXwADTyY"]
[Tue Jul 21 07:41:07.302207 2026] [security2:error] [pid 254995:tid 255225] [client 20.226.60.151:59420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/xy.php"] [unique_id "al9Mw_7v0rlcEGmVraFXYAAAA4E"]
[Tue Jul 21 07:41:07.476522 2026] [security2:error] [pid 254995:tid 255197] [client 20.104.96.117:14641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9Mw_7v0rlcEGmVraFXaQAAA2Y"]
[Tue Jul 21 07:41:07.579445 2026] [security2:error] [pid 254995:tid 255131] [client 37.140.223.154:54661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Mw_7v0rlcEGmVraFXagAAAyQ"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:07.631680 2026] [security2:error] [pid 254995:tid 255191] [client 20.220.225.223:11160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9Mw_7v0rlcEGmVraFXawAAA2A"]
[Tue Jul 21 07:41:07.651775 2026] [security2:error] [pid 254995:tid 255175] [client 122.186.204.214:51748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mw_7v0rlcEGmVraFXbQAAA1A"]
[Tue Jul 21 07:41:07.651928 2026] [security2:error] [pid 254995:tid 255175] [client 122.186.204.214:51748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mw_7v0rlcEGmVraFXbQAAA1A"]
[Tue Jul 21 07:41:07.752407 2026] [security2:error] [pid 254995:tid 255273] [client 20.104.96.117:14563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9Mw_7v0rlcEGmVraFXcAAAA5c"]
[Tue Jul 21 07:41:07.753246 2026] [core:error] [pid 254995:tid 255042] [remote 52.167.144.232:10707] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:07.753271 2026] [core:error] [pid 254995:tid 255042] [remote 52.167.144.232:10707] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:07.807600 2026] [security2:error] [pid 254995:tid 255198] [client 20.226.60.151:59499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/loader.php"] [unique_id "al9Mw_7v0rlcEGmVraFXcgAAA2c"]
[Tue Jul 21 07:41:07.990129 2026] [security2:error] [pid 254995:tid 255149] [client 4.204.201.85:46021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/ssixta.php"] [unique_id "al9Mw_7v0rlcEGmVraFXegAAAzY"]
[Tue Jul 21 07:41:08.059008 2026] [security2:error] [pid 254995:tid 255266] [client 20.226.60.151:62247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/byp.php"] [unique_id "al9MxP7v0rlcEGmVraFXfAAAA5A"]
[Tue Jul 21 07:41:08.098258 2026] [security2:error] [pid 254995:tid 255278] [client 20.104.96.117:14580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9MxP7v0rlcEGmVraFXfQAAA5w"]
[Tue Jul 21 07:41:08.409672 2026] [security2:error] [pid 254995:tid 255269] [client 20.104.96.117:14564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/for.php"] [unique_id "al9MxP7v0rlcEGmVraFXhgAAA5M"]
[Tue Jul 21 07:41:08.651309 2026] [security2:error] [pid 254995:tid 255152] [client 122.164.127.47:50132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MxP7v0rlcEGmVraFXjAAAAzk"]
[Tue Jul 21 07:41:08.651441 2026] [security2:error] [pid 254995:tid 255152] [client 122.164.127.47:50132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MxP7v0rlcEGmVraFXjAAAAzk"]
[Tue Jul 21 07:41:08.807146 2026] [security2:error] [pid 254995:tid 255197] [client 20.226.60.151:33526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9MxP7v0rlcEGmVraFXjwAAA2Y"]
[Tue Jul 21 07:41:08.883371 2026] [security2:error] [pid 254995:tid 255254] [client 20.104.96.117:14337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/raw.php"] [unique_id "al9MxP7v0rlcEGmVraFXlAAAA4Q"]
[Tue Jul 21 07:41:08.956314 2026] [security2:error] [pid 254995:tid 255267] [client 20.226.60.151:23154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/aa.php"] [unique_id "al9MxP7v0rlcEGmVraFXmAAAA5E"]
[Tue Jul 21 07:41:09.013822 2026] [security2:error] [pid 254995:tid 255219] [client 20.220.225.223:11185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/dr.php"] [unique_id "al9Mxf7v0rlcEGmVraFXmwAAA3s"]
[Tue Jul 21 07:41:09.026782 2026] [security2:error] [pid 254995:tid 255201] [client 20.151.10.161:55266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/p.php"] [unique_id "al9Mxf7v0rlcEGmVraFXnQAAA2o"]
[Tue Jul 21 07:41:09.245635 2026] [security2:error] [pid 254995:tid 255220] [client 20.226.60.151:59410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/spadex.php"] [unique_id "al9Mxf7v0rlcEGmVraFXqwAAA3w"]
[Tue Jul 21 07:41:09.335975 2026] [security2:error] [pid 254995:tid 255132] [client 182.8.255.181:17597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Mxf7v0rlcEGmVraFXrAAAAyU"]
[Tue Jul 21 07:41:09.336129 2026] [security2:error] [pid 254995:tid 255132] [client 182.8.255.181:17597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Mxf7v0rlcEGmVraFXrAAAAyU"]
[Tue Jul 21 07:41:09.385055 2026] [security2:error] [pid 254995:tid 255141] [client 4.204.201.85:3565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/1c.php"] [unique_id "al9Mxf7v0rlcEGmVraFXrQAAAy4"]
[Tue Jul 21 07:41:09.589934 2026] [security2:error] [pid 254995:tid 255171] [client 103.86.117.203:65137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mxf7v0rlcEGmVraFXvAAAA0w"]
[Tue Jul 21 07:41:09.590082 2026] [security2:error] [pid 254995:tid 255171] [client 103.86.117.203:65137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mxf7v0rlcEGmVraFXvAAAA0w"]
[Tue Jul 21 07:41:09.716422 2026] [security2:error] [pid 254995:tid 255258] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Mxf7v0rlcEGmVraFXwAAAA4g"]
[Tue Jul 21 07:41:09.735207 2026] [security2:error] [pid 254995:tid 255131] [client 20.226.60.151:33533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/classwithtostring.php"] [unique_id "al9Mxf7v0rlcEGmVraFXwQAAAyQ"]
[Tue Jul 21 07:41:09.837309 2026] [security2:error] [pid 254995:tid 255107] [remote 113.160.142.119:39926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carrosselbuique.com.br"] [uri "/wp-login.php"] [unique_id "al9Mxf7v0rlcEGmVraFXwgADkG8"]
[Tue Jul 21 07:41:09.841742 2026] [security2:error] [pid 254995:tid 255164] [client 193.36.225.71:45735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Mxf7v0rlcEGmVraFXwwAAA0U"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:09.928306 2026] [security2:error] [pid 254995:tid 255068] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mxf7v0rlcEGmVraFXxQADYEg"]
[Tue Jul 21 07:41:09.928437 2026] [security2:error] [pid 254995:tid 255191] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mxf7v0rlcEGmVraFXxQADYEg"]
[Tue Jul 21 07:41:09.946987 2026] [security2:error] [pid 254995:tid 255146] [client 194.99.104.35:39020] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Mxf7v0rlcEGmVraFXxgAAAzM"]
[Tue Jul 21 07:41:09.947100 2026] [security2:error] [pid 254995:tid 255146] [client 194.99.104.35:39020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Mxf7v0rlcEGmVraFXxgAAAzM"]
[Tue Jul 21 07:41:09.955652 2026] [security2:error] [pid 254995:tid 255144] [client 4.204.201.85:7433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/test2.php"] [unique_id "al9Mxf7v0rlcEGmVraFXxwAAAzE"]
[Tue Jul 21 07:41:10.010249 2026] [security2:error] [pid 254995:tid 255213] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Mxv7v0rlcEGmVraFXzgAAA3U"]
[Tue Jul 21 07:41:10.242263 2026] [security2:error] [pid 254995:tid 255274] [client 37.140.223.156:54887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Mxv7v0rlcEGmVraFX0AAAA5g"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:10.290979 2026] [security2:error] [pid 254995:tid 255145] [client 154.192.233.199:59267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX3wAAAzI"]
[Tue Jul 21 07:41:10.291115 2026] [security2:error] [pid 254995:tid 255145] [client 154.192.233.199:59267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX3wAAAzI"]
[Tue Jul 21 07:41:10.323899 2026] [security2:error] [pid 254995:tid 255177] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/wp.php"] [unique_id "al9Mxv7v0rlcEGmVraFX4gAAA1I"]
[Tue Jul 21 07:41:10.327975 2026] [security2:error] [pid 254995:tid 255154] [client 175.45.70.82:56860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX4wAAAzs"]
[Tue Jul 21 07:41:10.328089 2026] [security2:error] [pid 254995:tid 255154] [client 175.45.70.82:56860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX4wAAAzs"]
[Tue Jul 21 07:41:10.369345 2026] [security2:error] [pid 254995:tid 255256] [client 4.204.201.85:7436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/buy.php"] [unique_id "al9Mxv7v0rlcEGmVraFX5AAAA4Y"]
[Tue Jul 21 07:41:10.380891 2026] [security2:error] [pid 254995:tid 255197] [client 20.226.60.151:59466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/2x.php"] [unique_id "al9Mxv7v0rlcEGmVraFX5QAAA2Y"]
[Tue Jul 21 07:41:10.603337 2026] [security2:error] [pid 254995:tid 255150] [client 20.220.225.223:5299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/2x.php"] [unique_id "al9Mxv7v0rlcEGmVraFX7AAAAzc"]
[Tue Jul 21 07:41:10.606747 2026] [security2:error] [pid 254995:tid 255191] [client 20.226.60.151:56287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/txets.php"] [unique_id "al9Mxv7v0rlcEGmVraFX7QAAA2A"]
[Tue Jul 21 07:41:10.652128 2026] [security2:error] [pid 254995:tid 255265] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/new.php"] [unique_id "al9Mxv7v0rlcEGmVraFX8wAAA48"]
[Tue Jul 21 07:41:10.693884 2026] [security2:error] [pid 254995:tid 255223] [client 4.204.201.85:46056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/ssend.php"] [unique_id "al9Mxv7v0rlcEGmVraFX9AAAA38"]
[Tue Jul 21 07:41:10.694311 2026] [security2:error] [pid 254995:tid 255278] [client 20.226.60.151:62310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/root.php"] [unique_id "al9Mxv7v0rlcEGmVraFX9QAAA5w"]
[Tue Jul 21 07:41:10.708323 2026] [security2:error] [pid 254995:tid 255157] [client 103.106.20.201:64020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX9gAAAz4"]
[Tue Jul 21 07:41:10.708417 2026] [security2:error] [pid 254995:tid 255157] [client 103.106.20.201:64020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX9gAAAz4"]
[Tue Jul 21 07:41:10.750168 2026] [security2:error] [pid 254995:tid 255211] [client 202.143.127.214:63840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX-QAAA3M"]
[Tue Jul 21 07:41:10.750285 2026] [security2:error] [pid 254995:tid 255211] [client 202.143.127.214:63840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX-QAAA3M"]
[Tue Jul 21 07:41:10.777244 2026] [security2:error] [pid 254995:tid 255189] [client 128.127.105.184:33096] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX-gAAA14"]
[Tue Jul 21 07:41:10.777392 2026] [security2:error] [pid 254995:tid 255189] [client 128.127.105.184:33096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX-gAAA14"]
[Tue Jul 21 07:41:10.813856 2026] [security2:error] [pid 254995:tid 255220] [client 122.162.144.145:29832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX-wAAA3w"]
[Tue Jul 21 07:41:10.813986 2026] [security2:error] [pid 254995:tid 255220] [client 122.162.144.145:29832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX-wAAA3w"]
[Tue Jul 21 07:41:10.865058 2026] [security2:error] [pid 254995:tid 255070] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX_AADbko"]
[Tue Jul 21 07:41:10.865213 2026] [security2:error] [pid 254995:tid 255205] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX_AADbko"]
[Tue Jul 21 07:41:10.985654 2026] [security2:error] [pid 254995:tid 255272] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/class-t.api.php"] [unique_id "al9Mxv7v0rlcEGmVraFX_wAAA5Y"]
[Tue Jul 21 07:41:11.259450 2026] [security2:error] [pid 254995:tid 255178] [client 4.204.201.85:46048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/item.php"] [unique_id "al9Mx_7v0rlcEGmVraFYEgAAA1M"]
[Tue Jul 21 07:41:11.299627 2026] [security2:error] [pid 254995:tid 255206] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/plugins.php"] [unique_id "al9Mx_7v0rlcEGmVraFYEwAAA28"]
[Tue Jul 21 07:41:11.592310 2026] [security2:error] [pid 254995:tid 255269] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/jp.php"] [unique_id "al9Mx_7v0rlcEGmVraFYHwAAA5M"]
[Tue Jul 21 07:41:11.593794 2026] [security2:error] [pid 254995:tid 255033] [remote 192.241.143.148:45992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nutrawidenews.com"] [uri "/wp-login.php"] [unique_id "al9Mx_7v0rlcEGmVraFYIAADMCU"]
[Tue Jul 21 07:41:11.709961 2026] [security2:error] [pid 254995:tid 255225] [client 20.226.60.151:22336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/122.php"] [unique_id "al9Mx_7v0rlcEGmVraFYKQAAA4E"]
[Tue Jul 21 07:41:11.832146 2026] [security2:error] [pid 254995:tid 255140] [client 4.204.201.85:3574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/ss.php"] [unique_id "al9Mx_7v0rlcEGmVraFYKgAAAy0"]
[Tue Jul 21 07:41:11.846061 2026] [security2:error] [pid 254995:tid 255176] [client 20.151.10.161:12088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/bthil.php"] [unique_id "al9Mx_7v0rlcEGmVraFYKwAAA1E"]
[Tue Jul 21 07:41:11.904342 2026] [security2:error] [pid 254995:tid 255188] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/error.php"] [unique_id "al9Mx_7v0rlcEGmVraFYLAAAA10"]
[Tue Jul 21 07:41:12.140683 2026] [security2:error] [pid 254995:tid 255256] [client 4.204.201.85:3535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/hypo.php"] [unique_id "al9MyP7v0rlcEGmVraFYNwAAA4Y"]
[Tue Jul 21 07:41:12.220584 2026] [security2:error] [pid 254995:tid 255200] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/classwithtostring.php"] [unique_id "al9MyP7v0rlcEGmVraFYPQAAA2k"]
[Tue Jul 21 07:41:12.257886 2026] [security2:error] [pid 254995:tid 255273] [client 20.226.60.151:62267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/sym403.php"] [unique_id "al9MyP7v0rlcEGmVraFYPgAAA5c"]
[Tue Jul 21 07:41:12.309635 2026] [core:error] [pid 254995:tid 255114] [remote 52.167.144.206:64029] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:12.309662 2026] [core:error] [pid 254995:tid 255114] [remote 52.167.144.206:64029] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:12.344723 2026] [security2:error] [pid 254995:tid 255019] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MyP7v0rlcEGmVraFYQQADXxc"]
[Tue Jul 21 07:41:12.344870 2026] [security2:error] [pid 254995:tid 255190] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MyP7v0rlcEGmVraFYQQADXxc"]
[Tue Jul 21 07:41:12.425463 2026] [security2:error] [pid 254995:tid 255168] [client 117.217.38.194:62257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MyP7v0rlcEGmVraFYRwAAA0k"]
[Tue Jul 21 07:41:12.425571 2026] [security2:error] [pid 254995:tid 255168] [client 117.217.38.194:62257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MyP7v0rlcEGmVraFYRwAAA0k"]
[Tue Jul 21 07:41:12.494403 2026] [security2:error] [pid 254995:tid 255199] [client 4.204.201.85:3550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/users.php"] [unique_id "al9MyP7v0rlcEGmVraFYSwAAA2g"]
[Tue Jul 21 07:41:12.494778 2026] [security2:error] [pid 254995:tid 255160] [client 128.127.105.184:47600] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9MyP7v0rlcEGmVraFYTAAAA0E"]
[Tue Jul 21 07:41:12.494853 2026] [security2:error] [pid 254995:tid 255160] [client 128.127.105.184:47600] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9MyP7v0rlcEGmVraFYTAAAA0E"]
[Tue Jul 21 07:41:12.494874 2026] [security2:error] [pid 254995:tid 255160] [client 128.127.105.184:47600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9MyP7v0rlcEGmVraFYTAAAA0E"]
[Tue Jul 21 07:41:12.535686 2026] [security2:error] [pid 254995:tid 255143] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/bless.php"] [unique_id "al9MyP7v0rlcEGmVraFYTQAAAzA"]
[Tue Jul 21 07:41:12.550299 2026] [security2:error] [pid 254995:tid 255219] [client 20.226.60.151:59486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/ctex1.php"] [unique_id "al9MyP7v0rlcEGmVraFYTgAAA3s"]
[Tue Jul 21 07:41:12.648035 2026] [security2:error] [pid 254995:tid 255161] [client 20.226.60.151:33492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/v543.php"] [unique_id "al9MyP7v0rlcEGmVraFYVwAAA0I"]
[Tue Jul 21 07:41:12.794791 2026] [security2:error] [pid 254995:tid 255200] [client 20.220.225.223:5281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/kq1.php"] [unique_id "al9MyP7v0rlcEGmVraFYXwAAA2k"]
[Tue Jul 21 07:41:12.851918 2026] [security2:error] [pid 254995:tid 255273] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/storage/index.php"] [unique_id "al9MyP7v0rlcEGmVraFYYQAAA5c"]
[Tue Jul 21 07:41:12.913201 2026] [security2:error] [pid 254995:tid 255258] [client 4.204.201.85:3559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/177.php"] [unique_id "al9MyP7v0rlcEGmVraFYYgAAA4g"]
[Tue Jul 21 07:41:12.928062 2026] [security2:error] [pid 254995:tid 255190] [client 20.151.10.161:53579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/7.php"] [unique_id "al9MyP7v0rlcEGmVraFYYwAAA18"]
[Tue Jul 21 07:41:13.008125 2026] [security2:error] [pid 254995:tid 255186] [client 20.226.60.151:59493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/edorxrr.php"] [unique_id "al9Myf7v0rlcEGmVraFYZAAAA1s"]
[Tue Jul 21 07:41:13.032179 2026] [security2:error] [pid 254995:tid 255160] [client 20.226.60.151:59403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/miru1.php"] [unique_id "al9Myf7v0rlcEGmVraFYZQAAA0E"]
[Tue Jul 21 07:41:13.103276 2026] [security2:error] [pid 254995:tid 255208] [client 20.226.60.151:59425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/sump1.php"] [unique_id "al9Myf7v0rlcEGmVraFYaQAAA3A"]
[Tue Jul 21 07:41:13.161453 2026] [security2:error] [pid 254995:tid 255225] [client 20.226.60.151:59392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/file5.php"] [unique_id "al9Myf7v0rlcEGmVraFYawAAA4E"]
[Tue Jul 21 07:41:13.175568 2026] [security2:error] [pid 254995:tid 255198] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/g.php"] [unique_id "al9Myf7v0rlcEGmVraFYbAAAA2c"]
[Tue Jul 21 07:41:13.234854 2026] [security2:error] [pid 254995:tid 255013] [remote 45.150.79.142:55682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "loopfinancas.com"] [uri "/wp-login.php"] [unique_id "al9Myf7v0rlcEGmVraFYcQADhhE"]
[Tue Jul 21 07:41:13.300103 2026] [security2:error] [pid 254995:tid 255000] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Myf7v0rlcEGmVraFYegADMAQ"]
[Tue Jul 21 07:41:13.300257 2026] [security2:error] [pid 254995:tid 255143] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Myf7v0rlcEGmVraFYegADMAQ"]
[Tue Jul 21 07:41:13.400499 2026] [security2:error] [pid 254995:tid 255278] [client 20.226.60.151:59490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/0xD.php"] [unique_id "al9Myf7v0rlcEGmVraFYfwAAA5w"]
[Tue Jul 21 07:41:13.483944 2026] [security2:error] [pid 254995:tid 255141] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/nf.php"] [unique_id "al9Myf7v0rlcEGmVraFYggAAAy4"]
[Tue Jul 21 07:41:13.486300 2026] [security2:error] [pid 254995:tid 255222] [client 59.96.220.140:53660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Myf7v0rlcEGmVraFYgwAAA34"]
[Tue Jul 21 07:41:13.486855 2026] [security2:error] [pid 254995:tid 255222] [client 59.96.220.140:53660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Myf7v0rlcEGmVraFYgwAAA34"]
[Tue Jul 21 07:41:13.529129 2026] [security2:error] [pid 254995:tid 255206] [client 4.204.201.85:46044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/config.php"] [unique_id "al9Myf7v0rlcEGmVraFYhAAAA28"]
[Tue Jul 21 07:41:13.539869 2026] [security2:error] [pid 254995:tid 255195] [client 122.179.91.63:14443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Myf7v0rlcEGmVraFYhQAAA2Q"]
[Tue Jul 21 07:41:13.539968 2026] [security2:error] [pid 254995:tid 255195] [client 122.179.91.63:14443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Myf7v0rlcEGmVraFYhQAAA2Q"]
[Tue Jul 21 07:41:13.542572 2026] [security2:error] [pid 254995:tid 255157] [client 103.174.34.15:52735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Myf7v0rlcEGmVraFYhgAAAz4"]
[Tue Jul 21 07:41:13.542694 2026] [security2:error] [pid 254995:tid 255157] [client 103.174.34.15:52735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Myf7v0rlcEGmVraFYhgAAAz4"]
[Tue Jul 21 07:41:13.544726 2026] [security2:error] [pid 254995:tid 255149] [client 139.167.225.182:61114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Myf7v0rlcEGmVraFYhwAAAzY"]
[Tue Jul 21 07:41:13.544779 2026] [security2:error] [pid 254995:tid 255149] [client 139.167.225.182:61114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Myf7v0rlcEGmVraFYhwAAAzY"]
[Tue Jul 21 07:41:13.810588 2026] [security2:error] [pid 254995:tid 255152] [client 20.226.60.151:50932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/fnstall.php"] [unique_id "al9Myf7v0rlcEGmVraFYkQAAAzk"]
[Tue Jul 21 07:41:13.839544 2026] [security2:error] [pid 254995:tid 255145] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/xda.php"] [unique_id "al9Myf7v0rlcEGmVraFYlAAAAzI"]
[Tue Jul 21 07:41:13.942021 2026] [security2:error] [pid 254995:tid 255024] [remote 57.141.18.7:54442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemape.xml"] [unique_id "al9Myf7v0rlcEGmVraFYjwADThw"]
[Tue Jul 21 07:41:14.148716 2026] [security2:error] [pid 254995:tid 255216] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/shell.php"] [unique_id "al9Myv7v0rlcEGmVraFYoQAAA3g"]
[Tue Jul 21 07:41:14.267600 2026] [security2:error] [pid 254995:tid 255146] [client 4.204.201.85:7448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/gettest.php"] [unique_id "al9Myv7v0rlcEGmVraFYpAAAAzM"]
[Tue Jul 21 07:41:14.268018 2026] [security2:error] [pid 254995:tid 255265] [client 20.226.60.151:22359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/get.php"] [unique_id "al9Myv7v0rlcEGmVraFYpQAAA48"]
[Tue Jul 21 07:41:14.450286 2026] [security2:error] [pid 254995:tid 255224] [client 20.226.60.151:59502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/acp.php"] [unique_id "al9Myv7v0rlcEGmVraFYrAAAA4A"]
[Tue Jul 21 07:41:14.453950 2026] [security2:error] [pid 254995:tid 255178] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/3.php"] [unique_id "al9Myv7v0rlcEGmVraFYrQAAA1M"]
[Tue Jul 21 07:41:14.505720 2026] [security2:error] [pid 254995:tid 255168] [client 152.59.154.239:56545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Myv7v0rlcEGmVraFYrwAAA0k"]
[Tue Jul 21 07:41:14.505881 2026] [security2:error] [pid 254995:tid 255168] [client 152.59.154.239:56545] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Myv7v0rlcEGmVraFYrwAAA0k"]
[Tue Jul 21 07:41:14.653224 2026] [security2:error] [pid 254995:tid 255192] [client 4.204.201.85:3578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/min.php"] [unique_id "al9Myv7v0rlcEGmVraFYtgAAA2E"]
[Tue Jul 21 07:41:14.775700 2026] [security2:error] [pid 254995:tid 255158] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/mds.php"] [unique_id "al9Myv7v0rlcEGmVraFYuwAAAz8"]
[Tue Jul 21 07:41:14.989245 2026] [security2:error] [pid 254995:tid 255134] [client 4.204.201.85:7462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/dvjul.php"] [unique_id "al9Myv7v0rlcEGmVraFYwQAAAyc"]
[Tue Jul 21 07:41:15.060007 2026] [security2:error] [pid 254995:tid 255200] [client 20.226.60.151:59404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/mosty.php"] [unique_id "al9My_7v0rlcEGmVraFYxAAAA2k"]
[Tue Jul 21 07:41:15.079113 2026] [security2:error] [pid 254995:tid 255153] [client 62.102.148.187:40074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9My_7v0rlcEGmVraFYxQAAAzo"]
[Tue Jul 21 07:41:15.079280 2026] [security2:error] [pid 254995:tid 255153] [client 62.102.148.187:40074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9My_7v0rlcEGmVraFYxQAAAzo"]
[Tue Jul 21 07:41:15.081685 2026] [security2:error] [pid 254995:tid 255265] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/archive.php"] [unique_id "al9My_7v0rlcEGmVraFYxwAAA48"]
[Tue Jul 21 07:41:15.152097 2026] [security2:error] [pid 254995:tid 255179] [client 20.226.60.151:62250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/sixxis.php"] [unique_id "al9My_7v0rlcEGmVraFYyAAAA1Q"]
[Tue Jul 21 07:41:15.302326 2026] [security2:error] [pid 254995:tid 255218] [client 173.24.185.52:51713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9My_7v0rlcEGmVraFYzwAAA3o"]
[Tue Jul 21 07:41:15.302414 2026] [security2:error] [pid 254995:tid 255218] [client 173.24.185.52:51713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9My_7v0rlcEGmVraFYzwAAA3o"]
[Tue Jul 21 07:41:15.329772 2026] [security2:error] [pid 254995:tid 255160] [client 4.204.201.85:45968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/biufile.php"] [unique_id "al9My_7v0rlcEGmVraFY0QAAA0E"]
[Tue Jul 21 07:41:15.383753 2026] [security2:error] [pid 254995:tid 255141] [client 20.226.60.151:22357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/as.php"] [unique_id "al9My_7v0rlcEGmVraFY0wAAAy4"]
[Tue Jul 21 07:41:15.435482 2026] [security2:error] [pid 254995:tid 255208] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/amax.php"] [unique_id "al9My_7v0rlcEGmVraFY1QAAA3A"]
[Tue Jul 21 07:41:15.653152 2026] [security2:error] [pid 254995:tid 255275] [client 20.226.60.151:59491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/6.php"] [unique_id "al9My_7v0rlcEGmVraFY3AAAA5k"]
[Tue Jul 21 07:41:15.744335 2026] [security2:error] [pid 254995:tid 255190] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/moon.php"] [unique_id "al9My_7v0rlcEGmVraFY4QAAA18"]
[Tue Jul 21 07:41:15.973245 2026] [security2:error] [pid 254995:tid 255216] [client 4.204.201.85:3521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/av.php"] [unique_id "al9My_7v0rlcEGmVraFY6gAAA3g"]
[Tue Jul 21 07:41:15.996583 2026] [security2:error] [pid 254995:tid 255214] [client 136.144.33.106:37565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Myf7v0rlcEGmVraFYkwAAA3Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:16.027426 2026] [security2:error] [pid 254995:tid 255213] [client 20.226.60.151:62223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/ip.php"] [unique_id "al9MzP7v0rlcEGmVraFY6wAAA3U"]
[Tue Jul 21 07:41:16.041207 2026] [security2:error] [pid 254995:tid 255155] [client 136.144.42.179:23431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.42.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MzP7v0rlcEGmVraFY7AAAAzw"]
[Tue Jul 21 07:41:16.051541 2026] [security2:error] [pid 254995:tid 255223] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/ws83.php"] [unique_id "al9MzP7v0rlcEGmVraFY7wAAA38"]
[Tue Jul 21 07:41:16.054236 2026] [security2:error] [pid 254995:tid 255205] [client 20.226.60.151:59474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/32e17094cfindex.php"] [unique_id "al9MzP7v0rlcEGmVraFY8AAAA24"]
[Tue Jul 21 07:41:16.056010 2026] [security2:error] [pid 254995:tid 255203] [client 20.151.10.161:12039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/8.php"] [unique_id "al9MzP7v0rlcEGmVraFY8QAAA2w"]
[Tue Jul 21 07:41:16.351878 2026] [security2:error] [pid 254995:tid 255274] [client 106.215.181.8:16565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MzP7v0rlcEGmVraFY_gAAA5g"]
[Tue Jul 21 07:41:16.351982 2026] [security2:error] [pid 254995:tid 255274] [client 106.215.181.8:16565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MzP7v0rlcEGmVraFY_gAAA5g"]
[Tue Jul 21 07:41:16.384481 2026] [security2:error] [pid 254995:tid 255146] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/CDX1.php"] [unique_id "al9MzP7v0rlcEGmVraFZAgAAAzM"]
[Tue Jul 21 07:41:16.410660 2026] [security2:error] [pid 254995:tid 255195] [client 4.204.201.85:45974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/coffexium.php"] [unique_id "al9MzP7v0rlcEGmVraFZBAAAA2Q"]
[Tue Jul 21 07:41:16.602209 2026] [security2:error] [pid 254995:tid 255022] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MzP7v0rlcEGmVraFZBwADeRo"]
[Tue Jul 21 07:41:16.602353 2026] [security2:error] [pid 254995:tid 255217] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MzP7v0rlcEGmVraFZBwADeRo"]
[Tue Jul 21 07:41:16.638615 2026] [security2:error] [pid 254995:tid 255142] [client 20.104.96.117:30424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MzP7v0rlcEGmVraFZCAAAAy8"]
[Tue Jul 21 07:41:16.712554 2026] [security2:error] [pid 254995:tid 255193] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/inputs.php"] [unique_id "al9MzP7v0rlcEGmVraFZDAAAA2I"]
[Tue Jul 21 07:41:16.822035 2026] [security2:error] [pid 254995:tid 255148] [client 20.226.60.151:59514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/qqqa.php"] [unique_id "al9MzP7v0rlcEGmVraFZEAAAAzU"]
[Tue Jul 21 07:41:16.870893 2026] [security2:error] [pid 254995:tid 255033] [remote 45.117.83.212:45148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9MzP7v0rlcEGmVraFZEgADVyU"]
[Tue Jul 21 07:41:16.925349 2026] [security2:error] [pid 254995:tid 255200] [client 4.204.201.85:46033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/core.php"] [unique_id "al9MzP7v0rlcEGmVraFZFgAAA2k"]
[Tue Jul 21 07:41:16.974653 2026] [security2:error] [pid 254995:tid 255216] [client 20.226.60.151:62324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/kq1.php"] [unique_id "al9MzP7v0rlcEGmVraFZGAAAA3g"]
[Tue Jul 21 07:41:17.041504 2026] [security2:error] [pid 254995:tid 255155] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/ms-edit.php"] [unique_id "al9Mzf7v0rlcEGmVraFZGgAAAzw"]
[Tue Jul 21 07:41:17.153690 2026] [security2:error] [pid 254995:tid 255063] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mzf7v0rlcEGmVraFZHQADakM"]
[Tue Jul 21 07:41:17.153859 2026] [security2:error] [pid 254995:tid 255201] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mzf7v0rlcEGmVraFZHQADakM"]
[Tue Jul 21 07:41:17.419432 2026] [security2:error] [pid 254995:tid 255131] [client 20.226.60.151:59427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/aunmc.php"] [unique_id "al9Mzf7v0rlcEGmVraFZIgAAAyQ"]
[Tue Jul 21 07:41:17.432457 2026] [security2:error] [pid 254995:tid 255220] [client 4.204.201.85:7480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/als.php"] [unique_id "al9Mzf7v0rlcEGmVraFZJgAAA3w"]
[Tue Jul 21 07:41:17.625939 2026] [security2:error] [pid 254995:tid 255149] [client 20.151.10.161:53601] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.jandel.com.br"] [uri "/1.php"] [unique_id "al9Mzf7v0rlcEGmVraFZKQAAAzY"]
[Tue Jul 21 07:41:17.626072 2026] [security2:error] [pid 254995:tid 255149] [client 20.151.10.161:53601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/1.php"] [unique_id "al9Mzf7v0rlcEGmVraFZKQAAAzY"]
[Tue Jul 21 07:41:17.831209 2026] [security2:error] [pid 254995:tid 255142] [client 4.204.201.85:3564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/simple.php"] [unique_id "al9Mzf7v0rlcEGmVraFZLgAAAy8"]
[Tue Jul 21 07:41:17.854283 2026] [security2:error] [pid 254995:tid 255172] [client 20.226.60.151:56242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/dex.php"] [unique_id "al9Mzf7v0rlcEGmVraFZMAAAA00"]
[Tue Jul 21 07:41:17.863695 2026] [security2:error] [pid 254995:tid 255016] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mzf7v0rlcEGmVraFZMQADmBQ"]
[Tue Jul 21 07:41:17.863856 2026] [security2:error] [pid 254995:tid 255274] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mzf7v0rlcEGmVraFZMQADmBQ"]
[Tue Jul 21 07:41:17.884432 2026] [security2:error] [pid 254995:tid 255164] [client 20.226.60.151:22939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/ccou.php"] [unique_id "al9Mzf7v0rlcEGmVraFZMwAAA0U"]
[Tue Jul 21 07:41:17.907516 2026] [security2:error] [pid 254995:tid 255192] [client 185.251.19.64:34669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MzP7v0rlcEGmVraFY7QAAA2E"]
[Tue Jul 21 07:41:17.911393 2026] [security2:error] [pid 254995:tid 255141] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/simple.php"] [unique_id "al9Mzf7v0rlcEGmVraFZNQAAAy4"]
[Tue Jul 21 07:41:18.026332 2026] [security2:error] [pid 254995:tid 255262] [client 20.226.60.151:33473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9Mzv7v0rlcEGmVraFZOQAAA4w"]
[Tue Jul 21 07:41:18.230650 2026] [security2:error] [pid 254995:tid 255201] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/404.php"] [unique_id "al9Mzv7v0rlcEGmVraFZPAAAA2o"]
[Tue Jul 21 07:41:18.325435 2026] [security2:error] [pid 254995:tid 255195] [client 122.186.204.214:52278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mzv7v0rlcEGmVraFZQgAAA2Q"]
[Tue Jul 21 07:41:18.325551 2026] [security2:error] [pid 254995:tid 255195] [client 122.186.204.214:52278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mzv7v0rlcEGmVraFZQgAAA2Q"]
[Tue Jul 21 07:41:18.343600 2026] [security2:error] [pid 254995:tid 255222] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9Mzv7v0rlcEGmVraFZQwAAA34"]
[Tue Jul 21 07:41:18.352317 2026] [security2:error] [pid 254995:tid 255265] [client 4.204.201.85:3541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/init.php"] [unique_id "al9Mzv7v0rlcEGmVraFZRAAAA48"]
[Tue Jul 21 07:41:18.476061 2026] [security2:error] [pid 254995:tid 255258] [client 20.226.60.151:50911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/uoocf.php"] [unique_id "al9Mzv7v0rlcEGmVraFZSgAAA4g"]
[Tue Jul 21 07:41:18.561473 2026] [security2:error] [pid 254995:tid 255157] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/file3.php"] [unique_id "al9Mzv7v0rlcEGmVraFZSwAAAz4"]
[Tue Jul 21 07:41:18.596586 2026] [security2:error] [pid 254995:tid 255149] [client 159.65.243.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.243.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mzv7v0rlcEGmVraFZTQAAAzY"]
[Tue Jul 21 07:41:18.770231 2026] [security2:error] [pid 254995:tid 255273] [client 173.239.211.121:50935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.211.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9Mzv7v0rlcEGmVraFZTwAAA5c"]
[Tue Jul 21 07:41:18.778518 2026] [security2:error] [pid 254995:tid 255256] [client 173.239.211.144:38777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.211.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9Mzv7v0rlcEGmVraFZUAAAA4Y"]
[Tue Jul 21 07:41:18.901819 2026] [security2:error] [pid 254995:tid 255175] [client 4.204.201.85:7477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/fpwch.php"] [unique_id "al9Mzv7v0rlcEGmVraFZVwAAA1A"]
[Tue Jul 21 07:41:18.928020 2026] [security2:error] [pid 254995:tid 255216] [client 216.73.161.169:20449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9Mzv7v0rlcEGmVraFZTgAAA3g"]
[Tue Jul 21 07:41:18.965526 2026] [security2:error] [pid 254995:tid 255132] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9Mzv7v0rlcEGmVraFZXAAAAyU"]
[Tue Jul 21 07:41:19.013828 2026] [security2:error] [pid 254995:tid 255214] [client 117.251.86.144:54942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Mz_7v0rlcEGmVraFZXQAAA3Y"]
[Tue Jul 21 07:41:19.013963 2026] [security2:error] [pid 254995:tid 255214] [client 117.251.86.144:54942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Mz_7v0rlcEGmVraFZXQAAA3Y"]
[Tue Jul 21 07:41:19.187050 2026] [security2:error] [pid 254995:tid 255268] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/wp-mail.php"] [unique_id "al9Mz_7v0rlcEGmVraFZXwAAA5I"]
[Tue Jul 21 07:41:19.203887 2026] [security2:error] [pid 254995:tid 255143] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9Mz_7v0rlcEGmVraFZYAAAAzA"]
[Tue Jul 21 07:41:19.223519 2026] [security2:error] [pid 254995:tid 255179] [client 122.164.127.47:50694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Mz_7v0rlcEGmVraFZYQAAA1Q"]
[Tue Jul 21 07:41:19.225109 2026] [security2:error] [pid 254995:tid 255179] [client 122.164.127.47:50694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Mz_7v0rlcEGmVraFZYQAAA1Q"]
[Tue Jul 21 07:41:19.264934 2026] [security2:error] [pid 254995:tid 255182] [client 20.151.10.161:12070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/100.php"] [unique_id "al9Mz_7v0rlcEGmVraFZYwAAA1c"]
[Tue Jul 21 07:41:19.437512 2026] [security2:error] [pid 254995:tid 255195] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9Mz_7v0rlcEGmVraFZawAAA2Q"]
[Tue Jul 21 07:41:19.501257 2026] [security2:error] [pid 254995:tid 255259] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/about.php"] [unique_id "al9Mz_7v0rlcEGmVraFZbgAAA4k"]
[Tue Jul 21 07:41:19.633832 2026] [security2:error] [pid 254995:tid 255186] [client 4.204.201.85:3523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/domvf.php"] [unique_id "al9Mz_7v0rlcEGmVraFZdgAAA1s"]
[Tue Jul 21 07:41:19.678241 2026] [security2:error] [pid 254995:tid 255272] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9Mz_7v0rlcEGmVraFZdwAAA5Y"]
[Tue Jul 21 07:41:19.699525 2026] [security2:error] [pid 254995:tid 255229] [client 182.8.255.181:21115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Mz_7v0rlcEGmVraFZeAAAA4I"]
[Tue Jul 21 07:41:19.699649 2026] [security2:error] [pid 254995:tid 255229] [client 182.8.255.181:21115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Mz_7v0rlcEGmVraFZeAAAA4I"]
[Tue Jul 21 07:41:19.806822 2026] [security2:error] [pid 254995:tid 255203] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/adminfuns.php"] [unique_id "al9Mz_7v0rlcEGmVraFZeQAAA2w"]
[Tue Jul 21 07:41:19.840929 2026] [security2:error] [pid 254995:tid 255125] [client 20.226.60.151:62229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/h02ugyh.php"] [unique_id "al9Mz_7v0rlcEGmVraFZegAAAx4"]
[Tue Jul 21 07:41:19.920598 2026] [security2:error] [pid 254995:tid 255217] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9Mz_7v0rlcEGmVraFZgQAAA3k"]
[Tue Jul 21 07:41:19.928806 2026] [security2:error] [pid 254995:tid 255134] [client 154.192.233.199:59570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mz_7v0rlcEGmVraFZggAAAyc"]
[Tue Jul 21 07:41:19.928902 2026] [security2:error] [pid 254995:tid 255134] [client 154.192.233.199:59570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mz_7v0rlcEGmVraFZggAAAyc"]
[Tue Jul 21 07:41:20.069395 2026] [security2:error] [pid 254995:tid 255278] [client 103.86.117.203:49282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M0P7v0rlcEGmVraFZhwAAA5w"]
[Tue Jul 21 07:41:20.069543 2026] [security2:error] [pid 254995:tid 255278] [client 103.86.117.203:49282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M0P7v0rlcEGmVraFZhwAAA5w"]
[Tue Jul 21 07:41:20.080908 2026] [security2:error] [pid 254995:tid 255181] [client 172.245.102.46:50549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9M0P7v0rlcEGmVraFZiQAAA1Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:20.104056 2026] [security2:error] [pid 254995:tid 255171] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/php8.php"] [unique_id "al9M0P7v0rlcEGmVraFZjQAAA0w"]
[Tue Jul 21 07:41:20.153658 2026] [security2:error] [pid 254995:tid 255168] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9M0P7v0rlcEGmVraFZjgAAA0k"]
[Tue Jul 21 07:41:20.393414 2026] [security2:error] [pid 254995:tid 255152] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9M0P7v0rlcEGmVraFZjwAAAzk"]
[Tue Jul 21 07:41:20.432512 2026] [security2:error] [pid 254995:tid 255254] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/info.php"] [unique_id "al9M0P7v0rlcEGmVraFZkwAAA4Q"]
[Tue Jul 21 07:41:20.630546 2026] [security2:error] [pid 254995:tid 255274] [client 193.36.225.118:62605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Mz_7v0rlcEGmVraFZbQAAA5g"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:20.640182 2026] [security2:error] [pid 254995:tid 255258] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9M0P7v0rlcEGmVraFZnQAAA4g"]
[Tue Jul 21 07:41:20.653453 2026] [security2:error] [pid 254995:tid 255272] [client 20.220.225.223:55498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/bootstrap.php"] [unique_id "al9M0P7v0rlcEGmVraFZngAAA5Y"]
[Tue Jul 21 07:41:20.655162 2026] [security2:error] [pid 254995:tid 255039] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9M0P7v0rlcEGmVraFZnwADJCs"]
[Tue Jul 21 07:41:20.655257 2026] [security2:error] [pid 254995:tid 255131] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9M0P7v0rlcEGmVraFZnwADJCs"]
[Tue Jul 21 07:41:20.734282 2026] [security2:error] [pid 254995:tid 255140] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/edit.php"] [unique_id "al9M0P7v0rlcEGmVraFZoQAAAy0"]
[Tue Jul 21 07:41:20.743071 2026] [security2:error] [pid 254995:tid 255125] [client 20.226.60.151:33509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-temp.php"] [unique_id "al9M0P7v0rlcEGmVraFZogAAAx4"]
[Tue Jul 21 07:41:20.745631 2026] [security2:error] [pid 254995:tid 255189] [client 20.226.60.151:59408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/iywwi.php"] [unique_id "al9M0P7v0rlcEGmVraFZowAAA14"]
[Tue Jul 21 07:41:20.766100 2026] [security2:error] [pid 254995:tid 255183] [client 20.226.60.151:51256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/xpwer1.php"] [unique_id "al9M0P7v0rlcEGmVraFZpAAAA1g"]
[Tue Jul 21 07:41:20.887125 2026] [security2:error] [pid 254995:tid 255149] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9M0P7v0rlcEGmVraFZqQAAAzY"]
[Tue Jul 21 07:41:20.914450 2026] [security2:error] [pid 254995:tid 255172] [client 20.226.60.151:23166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/w3lls.php"] [unique_id "al9M0P7v0rlcEGmVraFZqgAAA00"]
[Tue Jul 21 07:41:21.028737 2026] [security2:error] [pid 254995:tid 255182] [client 175.45.70.82:57581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M0f7v0rlcEGmVraFZsAAAA1c"]
[Tue Jul 21 07:41:21.028855 2026] [security2:error] [pid 254995:tid 255182] [client 175.45.70.82:57581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M0f7v0rlcEGmVraFZsAAAA1c"]
[Tue Jul 21 07:41:21.029597 2026] [security2:error] [pid 254995:tid 255214] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/166.php"] [unique_id "al9M0f7v0rlcEGmVraFZsQAAA3Y"]
[Tue Jul 21 07:41:21.135194 2026] [security2:error] [pid 254995:tid 255148] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9M0f7v0rlcEGmVraFZsgAAAzU"]
[Tue Jul 21 07:41:21.324563 2026] [security2:error] [pid 254995:tid 255179] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/8.php"] [unique_id "al9M0f7v0rlcEGmVraFZtwAAA1Q"]
[Tue Jul 21 07:41:21.375585 2026] [security2:error] [pid 254995:tid 255142] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9M0f7v0rlcEGmVraFZuAAAAy8"]
[Tue Jul 21 07:41:21.397421 2026] [security2:error] [pid 254995:tid 255133] [client 20.226.60.151:59397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/gqgsa.php"] [unique_id "al9M0f7v0rlcEGmVraFZuQAAAyY"]
[Tue Jul 21 07:41:21.403026 2026] [security2:error] [pid 254995:tid 255037] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9M0f7v0rlcEGmVraFZugADOSk"]
[Tue Jul 21 07:41:21.403128 2026] [security2:error] [pid 254995:tid 255152] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9M0f7v0rlcEGmVraFZugADOSk"]
[Tue Jul 21 07:41:21.443853 2026] [security2:error] [pid 254995:tid 255188] [client 103.106.20.201:64603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M0f7v0rlcEGmVraFZvQAAA10"]
[Tue Jul 21 07:41:21.443933 2026] [security2:error] [pid 254995:tid 255188] [client 103.106.20.201:64603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M0f7v0rlcEGmVraFZvQAAA10"]
[Tue Jul 21 07:41:21.587739 2026] [security2:error] [pid 254995:tid 255275] [client 122.162.144.145:32979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9M0f7v0rlcEGmVraFZwwAAA5k"]
[Tue Jul 21 07:41:21.587870 2026] [security2:error] [pid 254995:tid 255275] [client 122.162.144.145:32979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9M0f7v0rlcEGmVraFZwwAAA5k"]
[Tue Jul 21 07:41:21.604947 2026] [security2:error] [pid 254995:tid 255266] [client 62.102.148.187:57574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9M0f7v0rlcEGmVraFZxAAAA5A"]
[Tue Jul 21 07:41:21.605028 2026] [security2:error] [pid 254995:tid 255266] [client 62.102.148.187:57574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9M0f7v0rlcEGmVraFZxAAAA5A"]
[Tue Jul 21 07:41:21.612282 2026] [security2:error] [pid 254995:tid 255220] [client 20.226.60.151:62300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9M0f7v0rlcEGmVraFZxQAAA3w"]
[Tue Jul 21 07:41:21.615625 2026] [security2:error] [pid 254995:tid 255160] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9M0f7v0rlcEGmVraFZxgAAA0E"]
[Tue Jul 21 07:41:21.642105 2026] [security2:error] [pid 254995:tid 255218] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/ws38.php"] [unique_id "al9M0f7v0rlcEGmVraFZxwAAA3o"]
[Tue Jul 21 07:41:21.867857 2026] [security2:error] [pid 254995:tid 255225] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9M0f7v0rlcEGmVraFZzAAAA4E"]
[Tue Jul 21 07:41:22.009137 2026] [security2:error] [pid 254995:tid 255149] [client 20.151.10.161:53615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/about.php"] [unique_id "al9M0v7v0rlcEGmVraFZ0gAAAzY"]
[Tue Jul 21 07:41:22.116652 2026] [security2:error] [pid 254995:tid 255192] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9M0v7v0rlcEGmVraFZ1QAAA2E"]
[Tue Jul 21 07:41:22.256155 2026] [security2:error] [pid 254995:tid 255168] [client 20.226.60.151:22948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/test1.php"] [unique_id "al9M0v7v0rlcEGmVraFZ2QAAA0k"]
[Tue Jul 21 07:41:22.327551 2026] [security2:error] [pid 254995:tid 255174] [client 20.104.96.117:30455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9M0v7v0rlcEGmVraFZ2gAAA08"]
[Tue Jul 21 07:41:22.364363 2026] [security2:error] [pid 254995:tid 255173] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9M0v7v0rlcEGmVraFZ2wAAA04"]
[Tue Jul 21 07:41:22.412263 2026] [security2:error] [pid 254995:tid 255147] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/a7.php"] [unique_id "al9M0v7v0rlcEGmVraFZ3AAAAzQ"]
[Tue Jul 21 07:41:22.594366 2026] [security2:error] [pid 254995:tid 255179] [client 20.10.88.201:27841] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "arthromdcanada.online"] [uri "/robots.txt"] [unique_id "al9M0v7v0rlcEGmVraFZ4wAAA1Q"]
[Tue Jul 21 07:41:22.607363 2026] [security2:error] [pid 254995:tid 255208] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9M0v7v0rlcEGmVraFZ5QAAA3A"]
[Tue Jul 21 07:41:22.685246 2026] [security2:error] [pid 254995:tid 255177] [client 4.204.201.85:46072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/wp.php"] [unique_id "al9M0v7v0rlcEGmVraFZ5wAAA1I"]
[Tue Jul 21 07:41:22.695213 2026] [proxy:error] [pid 254995:tid 255223] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:22.695279 2026] [proxy_http:error] [pid 254995:tid 255223] [client 20.226.60.151:62252] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:22.695862 2026] [proxy:error] [pid 254995:tid 255223] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:22.695886 2026] [proxy_http:error] [pid 254995:tid 255223] [client 20.226.60.151:62252] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:22.699848 2026] [security2:error] [pid 254995:tid 255190] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/classsmtps.php"] [unique_id "al9M0v7v0rlcEGmVraFZ6QAAA18"]
[Tue Jul 21 07:41:22.899086 2026] [security2:error] [pid 254995:tid 255278] [client 202.143.127.214:64277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M0v7v0rlcEGmVraFZ7gAAA5w"]
[Tue Jul 21 07:41:22.899220 2026] [security2:error] [pid 254995:tid 255278] [client 202.143.127.214:64277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M0v7v0rlcEGmVraFZ7gAAA5w"]
[Tue Jul 21 07:41:22.902655 2026] [security2:error] [pid 254995:tid 255209] [client 117.217.38.194:62733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M0v7v0rlcEGmVraFZ7wAAA3E"]
[Tue Jul 21 07:41:22.903088 2026] [security2:error] [pid 254995:tid 255209] [client 117.217.38.194:62733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M0v7v0rlcEGmVraFZ7wAAA3E"]
[Tue Jul 21 07:41:23.004595 2026] [security2:error] [pid 254995:tid 255157] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/rip.php"] [unique_id "al9M0_7v0rlcEGmVraFZ9AAAAz4"]
[Tue Jul 21 07:41:23.110860 2026] [security2:error] [pid 254995:tid 255187] [client 62.102.148.187:57590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9M0_7v0rlcEGmVraFZ9gAAA1w"]
[Tue Jul 21 07:41:23.110962 2026] [security2:error] [pid 254995:tid 255187] [client 62.102.148.187:57590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9M0_7v0rlcEGmVraFZ9gAAA1w"]
[Tue Jul 21 07:41:23.327226 2026] [security2:error] [pid 254995:tid 255213] [client 74.249.245.134:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/1.php"] [unique_id "al9M0_7v0rlcEGmVraFZ_wAAA3U"]
[Tue Jul 21 07:41:23.327311 2026] [security2:error] [pid 254995:tid 255213] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/1.php"] [unique_id "al9M0_7v0rlcEGmVraFZ_wAAA3U"]
[Tue Jul 21 07:41:23.489578 2026] [security2:error] [pid 254995:tid 255262] [client 59.96.220.140:54205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9M0_7v0rlcEGmVraFaAQAAA4w"]
[Tue Jul 21 07:41:23.489711 2026] [security2:error] [pid 254995:tid 255262] [client 59.96.220.140:54205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9M0_7v0rlcEGmVraFaAQAAA4w"]
[Tue Jul 21 07:41:23.522225 2026] [security2:error] [pid 254995:tid 255087] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M0_7v0rlcEGmVraFaAgADSVs"]
[Tue Jul 21 07:41:23.522369 2026] [security2:error] [pid 254995:tid 255168] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M0_7v0rlcEGmVraFaAgADSVs"]
[Tue Jul 21 07:41:23.635996 2026] [security2:error] [pid 254995:tid 255224] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/chosen.php"] [unique_id "al9M0_7v0rlcEGmVraFaCgAAA4A"]
[Tue Jul 21 07:41:23.961952 2026] [security2:error] [pid 254995:tid 255033] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M0_7v0rlcEGmVraFaEQADKCU"]
[Tue Jul 21 07:41:23.962083 2026] [security2:error] [pid 254995:tid 255135] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M0_7v0rlcEGmVraFaEQADKCU"]
[Tue Jul 21 07:41:24.003685 2026] [security2:error] [pid 254995:tid 255212] [client 139.167.225.182:61763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M1P7v0rlcEGmVraFaEgAAA3Q"]
[Tue Jul 21 07:41:24.003782 2026] [security2:error] [pid 254995:tid 255212] [client 139.167.225.182:61763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M1P7v0rlcEGmVraFaEgAAA3Q"]
[Tue Jul 21 07:41:24.008900 2026] [security2:error] [pid 254995:tid 255178] [client 20.226.60.151:59400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/elbzl.php"] [unique_id "al9M1P7v0rlcEGmVraFaEwAAA1M"]
[Tue Jul 21 07:41:24.101436 2026] [security2:error] [pid 254995:tid 255210] [client 193.36.225.107:64731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9M0v7v0rlcEGmVraFZ8AAAA3I"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:24.263835 2026] [security2:error] [pid 254995:tid 255143] [client 20.226.60.151:23131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/database.php"] [unique_id "al9M1P7v0rlcEGmVraFaGgAAAzA"]
[Tue Jul 21 07:41:24.275879 2026] [security2:error] [pid 254995:tid 255173] [client 122.179.91.63:10997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9M1P7v0rlcEGmVraFaGwAAA04"]
[Tue Jul 21 07:41:24.276027 2026] [security2:error] [pid 254995:tid 255173] [client 122.179.91.63:10997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9M1P7v0rlcEGmVraFaGwAAA04"]
[Tue Jul 21 07:41:24.516132 2026] [security2:error] [pid 254995:tid 255181] [client 20.151.10.161:53598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/admin.php"] [unique_id "al9M1P7v0rlcEGmVraFaKAAAA1Y"]
[Tue Jul 21 07:41:24.548280 2026] [security2:error] [pid 254995:tid 255192] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/css.php"] [unique_id "al9M1P7v0rlcEGmVraFaKQAAA2E"]
[Tue Jul 21 07:41:24.648579 2026] [security2:error] [pid 254995:tid 255268] [client 184.75.223.211:56194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9M1P7v0rlcEGmVraFaLwAAA5I"]
[Tue Jul 21 07:41:24.648678 2026] [security2:error] [pid 254995:tid 255268] [client 184.75.223.211:56194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9M1P7v0rlcEGmVraFaLwAAA5I"]
[Tue Jul 21 07:41:24.661425 2026] [security2:error] [pid 254995:tid 255164] [client 20.104.96.117:30900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/xyn.php"] [unique_id "al9M1P7v0rlcEGmVraFaMQAAA0U"]
[Tue Jul 21 07:41:24.693114 2026] [security2:error] [pid 254995:tid 255224] [client 20.226.60.151:62306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9M1P7v0rlcEGmVraFaMgAAA4A"]
[Tue Jul 21 07:41:24.775341 2026] [security2:error] [pid 254995:tid 255190] [client 103.174.34.15:53219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M1P7v0rlcEGmVraFaNAAAA18"]
[Tue Jul 21 07:41:24.775483 2026] [security2:error] [pid 254995:tid 255190] [client 103.174.34.15:53219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M1P7v0rlcEGmVraFaNAAAA18"]
[Tue Jul 21 07:41:24.854291 2026] [security2:error] [pid 254995:tid 255163] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/php.php"] [unique_id "al9M1P7v0rlcEGmVraFaOQAAA0Q"]
[Tue Jul 21 07:41:25.071132 2026] [security2:error] [pid 254995:tid 255093] [remote 20.75.217.73:3382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "precisosolucao.com.br"] [uri "/wp-login.php"] [unique_id "al9M1f7v0rlcEGmVraFaQQADOWE"]
[Tue Jul 21 07:41:25.151654 2026] [security2:error] [pid 254995:tid 255143] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/aa.php"] [unique_id "al9M1f7v0rlcEGmVraFaRAAAAzA"]
[Tue Jul 21 07:41:25.161654 2026] [core:error] [pid 254995:tid 255047] [remote 35.221.29.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:25.161673 2026] [core:error] [pid 254995:tid 255047] [remote 35.221.29.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:25.196541 2026] [security2:error] [pid 254995:tid 255160] [client 193.36.225.64:20653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9M1f7v0rlcEGmVraFaSAAAA0E"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:25.203211 2026] [security2:error] [pid 254995:tid 255173] [client 20.226.60.151:62274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/jj.php"] [unique_id "al9M1f7v0rlcEGmVraFaSgAAA04"]
[Tue Jul 21 07:41:25.214125 2026] [security2:error] [pid 254995:tid 255183] [client 20.226.60.151:50954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/flox.php"] [unique_id "al9M1f7v0rlcEGmVraFaSwAAA1g"]
[Tue Jul 21 07:41:25.434870 2026] [security2:error] [pid 254995:tid 255213] [client 20.220.225.223:11190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/zzz.php"] [unique_id "al9M1f7v0rlcEGmVraFaTwAAA3U"]
[Tue Jul 21 07:41:25.483628 2026] [security2:error] [pid 254995:tid 255181] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/bolt.php"] [unique_id "al9M1f7v0rlcEGmVraFaUQAAA1Y"]
[Tue Jul 21 07:41:25.606787 2026] [security2:error] [pid 254995:tid 255158] [client 152.59.154.239:51467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M1f7v0rlcEGmVraFaVQAAAz8"]
[Tue Jul 21 07:41:25.606911 2026] [security2:error] [pid 254995:tid 255158] [client 152.59.154.239:51467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M1f7v0rlcEGmVraFaVQAAAz8"]
[Tue Jul 21 07:41:25.613929 2026] [security2:error] [pid 254995:tid 255042] [remote 148.113.128.149:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "luminabeauty.com.br"] [uri "/robots.txt"] [unique_id "al9M1f7v0rlcEGmVraFaVgADVy4"]
[Tue Jul 21 07:41:25.614093 2026] [security2:error] [pid 254995:tid 255182] [client 148.113.128.149:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "luminabeauty.com.br"] [uri "/robots.txt"] [unique_id "al9M1f7v0rlcEGmVraFaVgADVy4"]
[Tue Jul 21 07:41:25.676616 2026] [security2:error] [pid 254995:tid 255147] [client 20.104.96.117:30409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/patie.php"] [unique_id "al9M1f7v0rlcEGmVraFaWAAAAzQ"]
[Tue Jul 21 07:41:25.691410 2026] [security2:error] [pid 254995:tid 255155] [client 20.197.195.24:13586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/wp-blog.php"] [unique_id "al9M1f7v0rlcEGmVraFaWQAAAzw"]
[Tue Jul 21 07:41:25.733289 2026] [security2:error] [pid 254995:tid 255176] [client 4.204.201.85:46059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/class.php"] [unique_id "al9M1f7v0rlcEGmVraFaWwAAA1E"]
[Tue Jul 21 07:41:25.810083 2026] [security2:error] [pid 254995:tid 255224] [client 128.127.105.184:59826] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9M1f7v0rlcEGmVraFaXgAAA4A"]
[Tue Jul 21 07:41:25.810191 2026] [security2:error] [pid 254995:tid 255224] [client 128.127.105.184:59826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9M1f7v0rlcEGmVraFaXgAAA4A"]
[Tue Jul 21 07:41:25.941722 2026] [security2:error] [pid 254995:tid 255164] [client 173.24.185.52:52193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9M1f7v0rlcEGmVraFaYgAAA0U"]
[Tue Jul 21 07:41:25.941837 2026] [security2:error] [pid 254995:tid 255164] [client 173.24.185.52:52193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9M1f7v0rlcEGmVraFaYgAAA0U"]
[Tue Jul 21 07:41:25.961379 2026] [security2:error] [pid 254995:tid 255252] [client 20.226.60.151:22925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/file.php"] [unique_id "al9M1f7v0rlcEGmVraFaYwAAA4M"]
[Tue Jul 21 07:41:26.018650 2026] [security2:error] [pid 254995:tid 255179] [client 20.226.60.151:62236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9M1v7v0rlcEGmVraFaZgAAA1Q"]
[Tue Jul 21 07:41:26.367785 2026] [security2:error] [pid 254995:tid 255272] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/x.php"] [unique_id "al9M1v7v0rlcEGmVraFacwAAA5Y"]
[Tue Jul 21 07:41:26.563229 2026] [security2:error] [pid 254995:tid 255141] [client 20.226.60.151:56230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/popo.php"] [unique_id "al9M1v7v0rlcEGmVraFafQAAAy4"]
[Tue Jul 21 07:41:26.636368 2026] [security2:error] [pid 254995:tid 255192] [client 20.220.225.223:11584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/wicked.php"] [unique_id "al9M1v7v0rlcEGmVraFagQAAA2E"]
[Tue Jul 21 07:41:26.910952 2026] [security2:error] [pid 254995:tid 255132] [client 20.220.225.223:19309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/ez.php"] [unique_id "al9M1v7v0rlcEGmVraFaiwAAAyU"]
[Tue Jul 21 07:41:26.921701 2026] [security2:error] [pid 254995:tid 255151] [client 106.215.181.8:20448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M1v7v0rlcEGmVraFajAAAAzg"]
[Tue Jul 21 07:41:26.921850 2026] [security2:error] [pid 254995:tid 255151] [client 106.215.181.8:20448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M1v7v0rlcEGmVraFajAAAAzg"]
[Tue Jul 21 07:41:26.925205 2026] [core:error] [pid 254995:tid 255018] [remote 35.221.29.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:26.925222 2026] [core:error] [pid 254995:tid 255018] [remote 35.221.29.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:26.933199 2026] [security2:error] [pid 254995:tid 255224] [client 4.204.201.85:7434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/echkm.php"] [unique_id "al9M1v7v0rlcEGmVraFajQAAA4A"]
[Tue Jul 21 07:41:26.965701 2026] [security2:error] [pid 254995:tid 255126] [client 20.104.96.117:30853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/aa.php"] [unique_id "al9M1v7v0rlcEGmVraFajgAAAx8"]
[Tue Jul 21 07:41:27.108964 2026] [security2:error] [pid 254995:tid 255012] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M1_7v0rlcEGmVraFakAADNRA"]
[Tue Jul 21 07:41:27.109120 2026] [security2:error] [pid 254995:tid 255148] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M1_7v0rlcEGmVraFakAADNRA"]
[Tue Jul 21 07:41:27.138518 2026] [security2:error] [pid 254995:tid 255163] [client 20.226.60.151:59500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/adjig.php"] [unique_id "al9M1_7v0rlcEGmVraFakQAAA0Q"]
[Tue Jul 21 07:41:27.207550 2026] [security2:error] [pid 254995:tid 255088] [remote 15.235.98.228:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "luminabeauty.com.br"] [uri "/"] [unique_id "al9M1_7v0rlcEGmVraFalQADaVw"]
[Tue Jul 21 07:41:27.207736 2026] [security2:error] [pid 254995:tid 255200] [client 15.235.98.228:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "luminabeauty.com.br"] [uri "/"] [unique_id "al9M1_7v0rlcEGmVraFalQADaVw"]
[Tue Jul 21 07:41:27.281100 2026] [security2:error] [pid 254995:tid 255179] [client 194.99.104.35:39394] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9M1_7v0rlcEGmVraFalwAAA1Q"]
[Tue Jul 21 07:41:27.281185 2026] [security2:error] [pid 254995:tid 255179] [client 194.99.104.35:39394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9M1_7v0rlcEGmVraFalwAAA1Q"]
[Tue Jul 21 07:41:27.348073 2026] [security2:error] [pid 254995:tid 255276] [client 20.226.60.151:22945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/file.php"] [unique_id "al9M1_7v0rlcEGmVraFamAAAA5o"]
[Tue Jul 21 07:41:27.417464 2026] [security2:error] [pid 254995:tid 255172] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/jga.php"] [unique_id "al9M1_7v0rlcEGmVraFamgAAA00"]
[Tue Jul 21 07:41:27.455352 2026] [security2:error] [pid 254995:tid 255218] [client 20.226.60.151:62253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/txets.php"] [unique_id "al9M1_7v0rlcEGmVraFanwAAA3o"]
[Tue Jul 21 07:41:27.700856 2026] [security2:error] [pid 254995:tid 255161] [client 20.151.10.161:53569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/edit.php"] [unique_id "al9M1_7v0rlcEGmVraFaowAAA0I"]
[Tue Jul 21 07:41:27.740064 2026] [security2:error] [pid 254995:tid 255189] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/k.php"] [unique_id "al9M1_7v0rlcEGmVraFapwAAA14"]
[Tue Jul 21 07:41:27.778187 2026] [security2:error] [pid 254995:tid 255071] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9M1_7v0rlcEGmVraFaqQADK0s"]
[Tue Jul 21 07:41:27.971422 2026] [security2:error] [pid 254995:tid 255068] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M1_7v0rlcEGmVraFargADWEg"]
[Tue Jul 21 07:41:27.971576 2026] [security2:error] [pid 254995:tid 255183] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M1_7v0rlcEGmVraFargADWEg"]
[Tue Jul 21 07:41:28.051059 2026] [security2:error] [pid 254995:tid 255168] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/vx.php"] [unique_id "al9M2P7v0rlcEGmVraFasAAAA0k"]
[Tue Jul 21 07:41:28.075494 2026] [security2:error] [pid 254995:tid 255177] [client 193.36.225.121:54967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9M2P7v0rlcEGmVraFasQAAA1I"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:28.103723 2026] [security2:error] [pid 254995:tid 254999] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9M2P7v0rlcEGmVraFasgADLwM"]
[Tue Jul 21 07:41:28.349091 2026] [security2:error] [pid 254995:tid 255082] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sarareginadosreis1782388162420.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9M2P7v0rlcEGmVraFauAADNFY"]
[Tue Jul 21 07:41:28.363100 2026] [security2:error] [pid 254995:tid 255153] [client 20.104.96.117:30446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/xwpg.php"] [unique_id "al9M2P7v0rlcEGmVraFauQAAAzo"]
[Tue Jul 21 07:41:28.437426 2026] [security2:error] [pid 254995:tid 255020] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9M2P7v0rlcEGmVraFavAADfxg"]
[Tue Jul 21 07:41:28.453851 2026] [security2:error] [pid 254995:tid 255055] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M2P7v0rlcEGmVraFavQADczs"]
[Tue Jul 21 07:41:28.453981 2026] [security2:error] [pid 254995:tid 255211] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M2P7v0rlcEGmVraFavQADczs"]
[Tue Jul 21 07:41:28.482459 2026] [security2:error] [pid 254995:tid 255135] [client 20.226.60.151:51211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/yas.php"] [unique_id "al9M2P7v0rlcEGmVraFawAAAAyg"]
[Tue Jul 21 07:41:28.589234 2026] [security2:error] [pid 254995:tid 255276] [client 20.226.60.151:22923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/777.php"] [unique_id "al9M2P7v0rlcEGmVraFawgAAA5o"]
[Tue Jul 21 07:41:28.594382 2026] [security2:error] [pid 254995:tid 255131] [client 117.251.86.144:37802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9M2P7v0rlcEGmVraFawwAAAyQ"]
[Tue Jul 21 07:41:28.594506 2026] [security2:error] [pid 254995:tid 255131] [client 117.251.86.144:37802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9M2P7v0rlcEGmVraFawwAAAyQ"]
[Tue Jul 21 07:41:28.661606 2026] [security2:error] [pid 254995:tid 255059] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9M2P7v0rlcEGmVraFayQADjT8"]
[Tue Jul 21 07:41:28.748847 2026] [security2:error] [pid 254995:tid 255160] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/ws77.php"] [unique_id "al9M2P7v0rlcEGmVraFazAAAA0E"]
[Tue Jul 21 07:41:28.963306 2026] [security2:error] [pid 254995:tid 255225] [client 20.220.225.223:19657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/fz.php"] [unique_id "al9M2P7v0rlcEGmVraFa1gAAA4E"]
[Tue Jul 21 07:41:29.012996 2026] [security2:error] [pid 254995:tid 255046] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9M2f7v0rlcEGmVraFa2QADjDI"]
[Tue Jul 21 07:41:29.012987 2026] [security2:error] [pid 254995:tid 255192] [client 4.204.201.85:45958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/lib.php"] [unique_id "al9M2f7v0rlcEGmVraFa2AAAA2E"]
[Tue Jul 21 07:41:29.019653 2026] [security2:error] [pid 254995:tid 255171] [client 20.226.60.151:59401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/byp.php"] [unique_id "al9M2f7v0rlcEGmVraFa2gAAA0w"]
[Tue Jul 21 07:41:29.021144 2026] [security2:error] [pid 254995:tid 255201] [client 122.186.204.214:52812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M2f7v0rlcEGmVraFa2wAAA2o"]
[Tue Jul 21 07:41:29.040070 2026] [security2:error] [pid 254995:tid 255158] [client 194.99.104.35:54052] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9M2f7v0rlcEGmVraFa3AAAAz8"]
[Tue Jul 21 07:41:29.040164 2026] [security2:error] [pid 254995:tid 255158] [client 194.99.104.35:54052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9M2f7v0rlcEGmVraFa3AAAAz8"]
[Tue Jul 21 07:41:29.040168 2026] [security2:error] [pid 254995:tid 255201] [client 122.186.204.214:52812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M2f7v0rlcEGmVraFa2wAAA2o"]
[Tue Jul 21 07:41:29.064567 2026] [security2:error] [pid 254995:tid 255183] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/2.php"] [unique_id "al9M2f7v0rlcEGmVraFa4AAAA1g"]
[Tue Jul 21 07:41:29.217384 2026] [security2:error] [pid 254995:tid 255176] [client 20.226.60.151:62309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/dex.php"] [unique_id "al9M2f7v0rlcEGmVraFa4gAAA1E"]
[Tue Jul 21 07:41:29.226678 2026] [security2:error] [pid 254995:tid 255206] [client 20.226.60.151:22932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/ssixta.php"] [unique_id "al9M2f7v0rlcEGmVraFa5AAAA28"]
[Tue Jul 21 07:41:29.298201 2026] [security2:error] [pid 254995:tid 255151] [client 20.104.96.117:30406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/ops.php"] [unique_id "al9M2f7v0rlcEGmVraFa5QAAAzg"]
[Tue Jul 21 07:41:29.342336 2026] [security2:error] [pid 254995:tid 255095] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9M2f7v0rlcEGmVraFa6gADMmM"]
[Tue Jul 21 07:41:29.387273 2026] [security2:error] [pid 254995:tid 255127] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/asd.php"] [unique_id "al9M2f7v0rlcEGmVraFa6wAAAyA"]
[Tue Jul 21 07:41:29.569074 2026] [security2:error] [pid 254995:tid 255276] [client 20.220.225.223:5277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/edit.php"] [unique_id "al9M2f7v0rlcEGmVraFa8AAAA5o"]
[Tue Jul 21 07:41:29.622280 2026] [security2:error] [pid 254995:tid 255022] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9M2f7v0rlcEGmVraFa8gADcho"]
[Tue Jul 21 07:41:29.711101 2026] [security2:error] [pid 254995:tid 255275] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/default.php"] [unique_id "al9M2f7v0rlcEGmVraFa9AAAA5k"]
[Tue Jul 21 07:41:29.804063 2026] [security2:error] [pid 254995:tid 255219] [client 20.104.96.117:30863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/mac.php"] [unique_id "al9M2f7v0rlcEGmVraFa9QAAA3s"]
[Tue Jul 21 07:41:29.805111 2026] [security2:error] [pid 254995:tid 255014] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9M2f7v0rlcEGmVraFa9gADQRI"]
[Tue Jul 21 07:41:29.820914 2026] [security2:error] [pid 254995:tid 255268] [client 122.164.127.47:51256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9M2f7v0rlcEGmVraFa9wAAA5I"]
[Tue Jul 21 07:41:29.821068 2026] [security2:error] [pid 254995:tid 255268] [client 122.164.127.47:51256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9M2f7v0rlcEGmVraFa9wAAA5I"]
[Tue Jul 21 07:41:29.902355 2026] [security2:error] [pid 254995:tid 255258] [client 62.102.148.187:36712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9M2f7v0rlcEGmVraFa_AAAA4g"]
[Tue Jul 21 07:41:29.902450 2026] [security2:error] [pid 254995:tid 255258] [client 62.102.148.187:36712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9M2f7v0rlcEGmVraFa_AAAA4g"]
[Tue Jul 21 07:41:30.023058 2026] [security2:error] [pid 254995:tid 255146] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/gettest.php"] [unique_id "al9M2v7v0rlcEGmVraFbBQAAAzM"]
[Tue Jul 21 07:41:30.172722 2026] [security2:error] [pid 254995:tid 255255] [client 182.8.255.181:21218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9M2v7v0rlcEGmVraFbCgAAA4U"]
[Tue Jul 21 07:41:30.172860 2026] [security2:error] [pid 254995:tid 255255] [client 182.8.255.181:21218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9M2v7v0rlcEGmVraFbCgAAA4U"]
[Tue Jul 21 07:41:30.191644 2026] [security2:error] [pid 254995:tid 255049] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9M2v7v0rlcEGmVraFbCwADJTU"]
[Tue Jul 21 07:41:30.213321 2026] [security2:error] [pid 254995:tid 255260] [client 4.204.201.85:3553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/login.php"] [unique_id "al9M2v7v0rlcEGmVraFbDQAAA4o"]
[Tue Jul 21 07:41:30.284117 2026] [security2:error] [pid 254995:tid 255163] [client 20.220.225.223:22505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/wp-editor.php"] [unique_id "al9M2v7v0rlcEGmVraFbEAAAA0Q"]
[Tue Jul 21 07:41:30.530092 2026] [security2:error] [pid 254995:tid 255047] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9M2v7v0rlcEGmVraFbHgADVzM"]
[Tue Jul 21 07:41:30.553089 2026] [security2:error] [pid 254995:tid 255199] [client 103.86.117.203:49820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M2v7v0rlcEGmVraFbHwAAA2g"]
[Tue Jul 21 07:41:30.553212 2026] [security2:error] [pid 254995:tid 255199] [client 103.86.117.203:49820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M2v7v0rlcEGmVraFbHwAAA2g"]
[Tue Jul 21 07:41:30.593300 2026] [security2:error] [pid 254995:tid 255203] [client 20.151.10.161:53593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9M2v7v0rlcEGmVraFbIAAAA2w"]
[Tue Jul 21 07:41:30.660950 2026] [security2:error] [pid 254995:tid 255189] [client 20.104.96.117:30430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/mg.php"] [unique_id "al9M2v7v0rlcEGmVraFbJQAAA14"]
[Tue Jul 21 07:41:30.676620 2026] [security2:error] [pid 254995:tid 255188] [client 20.226.60.151:59513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/ortasekerli1.php"] [unique_id "al9M2v7v0rlcEGmVraFbJgAAA10"]
[Tue Jul 21 07:41:30.770965 2026] [security2:error] [pid 254995:tid 255157] [client 193.36.225.72:47893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9M2f7v0rlcEGmVraFa8QAAAz4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:30.861780 2026] [security2:error] [pid 254995:tid 255042] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9M2v7v0rlcEGmVraFbLQADjC4"]
[Tue Jul 21 07:41:30.915429 2026] [security2:error] [pid 254995:tid 255278] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sarareginadosreis1782388162420.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9M2v7v0rlcEGmVraFbMQAAA5w"]
[Tue Jul 21 07:41:30.922360 2026] [security2:error] [pid 254995:tid 255201] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/tfm.php"] [unique_id "al9M2v7v0rlcEGmVraFbMwAAA2o"]
[Tue Jul 21 07:41:31.072473 2026] [security2:error] [pid 254995:tid 255004] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9M2_7v0rlcEGmVraFbOAADQAg"]
[Tue Jul 21 07:41:31.083590 2026] [security2:error] [pid 254995:tid 255143] [client 154.192.233.199:59997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M2_7v0rlcEGmVraFbOQAAAzA"]
[Tue Jul 21 07:41:31.083712 2026] [security2:error] [pid 254995:tid 255143] [client 154.192.233.199:59997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M2_7v0rlcEGmVraFbOQAAAzA"]
[Tue Jul 21 07:41:31.102276 2026] [security2:error] [pid 254995:tid 255163] [client 20.220.225.223:11174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/kua.php"] [unique_id "al9M2_7v0rlcEGmVraFbPgAAA0Q"]
[Tue Jul 21 07:41:31.241370 2026] [security2:error] [pid 254995:tid 255212] [client 20.226.60.151:62298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/xpwer1.php"] [unique_id "al9M2_7v0rlcEGmVraFbQgAAA3Q"]
[Tue Jul 21 07:41:31.267098 2026] [security2:error] [pid 254995:tid 255179] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/ws81.php"] [unique_id "al9M2_7v0rlcEGmVraFbRQAAA1Q"]
[Tue Jul 21 07:41:31.321277 2026] [security2:error] [pid 254995:tid 255184] [client 20.226.60.151:22656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/1c.php"] [unique_id "al9M2_7v0rlcEGmVraFbRgAAA1k"]
[Tue Jul 21 07:41:31.433335 2026] [security2:error] [pid 254995:tid 255211] [client 193.36.225.153:50303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9M2_7v0rlcEGmVraFbRAAAA3M"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:31.593402 2026] [security2:error] [pid 254995:tid 255256] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/222.php"] [unique_id "al9M2_7v0rlcEGmVraFbTwAAA4Y"]
[Tue Jul 21 07:41:31.605769 2026] [security2:error] [pid 254995:tid 255170] [client 4.204.201.85:3560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/a2.php"] [unique_id "al9M2_7v0rlcEGmVraFbUgAAA0s"]
[Tue Jul 21 07:41:31.761739 2026] [security2:error] [pid 254995:tid 255220] [client 175.45.70.82:58326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M2_7v0rlcEGmVraFbVQAAA3w"]
[Tue Jul 21 07:41:31.761938 2026] [security2:error] [pid 254995:tid 255220] [client 175.45.70.82:58326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M2_7v0rlcEGmVraFbVQAAA3w"]
[Tue Jul 21 07:41:31.869361 2026] [security2:error] [pid 254995:tid 255206] [client 20.151.10.161:55248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/f6.php"] [unique_id "al9M2_7v0rlcEGmVraFbVwAAA28"]
[Tue Jul 21 07:41:31.900694 2026] [security2:error] [pid 254995:tid 255117] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9M2_7v0rlcEGmVraFbWAADdnk"]
[Tue Jul 21 07:41:31.900831 2026] [security2:error] [pid 254995:tid 255214] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9M2_7v0rlcEGmVraFbWAADdnk"]
[Tue Jul 21 07:41:31.930246 2026] [security2:error] [pid 254995:tid 255255] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/t.php"] [unique_id "al9M2_7v0rlcEGmVraFbWwAAA4U"]
[Tue Jul 21 07:41:31.942266 2026] [security2:error] [pid 254995:tid 255192] [client 20.226.60.151:33475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/flox.php"] [unique_id "al9M2_7v0rlcEGmVraFbXQAAA2E"]
[Tue Jul 21 07:41:32.048069 2026] [security2:error] [pid 254995:tid 255143] [client 20.226.60.151:22377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/test2.php"] [unique_id "al9M3P7v0rlcEGmVraFbYQAAAzA"]
[Tue Jul 21 07:41:32.217623 2026] [security2:error] [pid 254995:tid 255167] [client 103.106.20.201:65215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M3P7v0rlcEGmVraFbZwAAA0g"]
[Tue Jul 21 07:41:32.217760 2026] [security2:error] [pid 254995:tid 255167] [client 103.106.20.201:65215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M3P7v0rlcEGmVraFbZwAAA0g"]
[Tue Jul 21 07:41:32.253098 2026] [security2:error] [pid 254995:tid 255252] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/a.php"] [unique_id "al9M3P7v0rlcEGmVraFbaAAAA4M"]
[Tue Jul 21 07:41:32.354726 2026] [security2:error] [pid 254995:tid 255274] [client 122.162.144.145:15052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9M3P7v0rlcEGmVraFbagAAA5g"]
[Tue Jul 21 07:41:32.354838 2026] [security2:error] [pid 254995:tid 255274] [client 122.162.144.145:15052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9M3P7v0rlcEGmVraFbagAAA5g"]
[Tue Jul 21 07:41:32.540163 2026] [security2:error] [pid 254995:tid 255069] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sarasantosdasilva1782312779991.0711679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9M3P7v0rlcEGmVraFbcAADmUk"]
[Tue Jul 21 07:41:32.542757 2026] [security2:error] [pid 254995:tid 255273] [client 125.164.233.50:31734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/"] [unique_id "al9M3P7v0rlcEGmVraFbcQAAA5c"]
[Tue Jul 21 07:41:32.594804 2026] [security2:error] [pid 254995:tid 255189] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/a1.php"] [unique_id "al9M3P7v0rlcEGmVraFbcwAAA14"]
[Tue Jul 21 07:41:32.738831 2026] [security2:error] [pid 254995:tid 255209] [client 20.226.60.151:62290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/popo.php"] [unique_id "al9M3P7v0rlcEGmVraFbeQAAA3E"]
[Tue Jul 21 07:41:32.759480 2026] [security2:error] [pid 254995:tid 255125] [client 20.104.96.117:30451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wp-post-data.php"] [unique_id "al9M3P7v0rlcEGmVraFbegAAAx4"]
[Tue Jul 21 07:41:32.921364 2026] [security2:error] [pid 254995:tid 255202] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/w.php"] [unique_id "al9M3P7v0rlcEGmVraFbfQAAA2s"]
[Tue Jul 21 07:41:32.948049 2026] [security2:error] [pid 254995:tid 255147] [client 20.226.60.151:59407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/classwithtostring.php"] [unique_id "al9M3P7v0rlcEGmVraFbfgAAAzQ"]
[Tue Jul 21 07:41:32.967451 2026] [security2:error] [pid 254995:tid 255132] [client 4.204.201.85:45966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/d61.php"] [unique_id "al9M3P7v0rlcEGmVraFbfwAAAyU"]
[Tue Jul 21 07:41:33.120841 2026] [security2:error] [pid 254995:tid 255153] [client 20.226.60.151:33528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/yas.php"] [unique_id "al9M3f7v0rlcEGmVraFbhQAAAzo"]
[Tue Jul 21 07:41:33.125699 2026] [security2:error] [pid 254995:tid 255224] [client 20.226.60.151:56233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/file61.php"] [unique_id "al9M3f7v0rlcEGmVraFbhgAAA4A"]
[Tue Jul 21 07:41:33.236961 2026] [security2:error] [pid 254995:tid 255182] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/wp-good.php"] [unique_id "al9M3f7v0rlcEGmVraFbjwAAA1c"]
[Tue Jul 21 07:41:33.245927 2026] [security2:error] [pid 254995:tid 255141] [client 37.140.223.191:33579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9M3f7v0rlcEGmVraFbkAAAAy4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:33.356015 2026] [security2:error] [pid 254995:tid 255199] [client 20.151.10.161:53570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/inputs.php"] [unique_id "al9M3f7v0rlcEGmVraFbkgAAA2g"]
[Tue Jul 21 07:41:33.375389 2026] [security2:error] [pid 254995:tid 255171] [client 117.217.38.194:63244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M3f7v0rlcEGmVraFbkwAAA0w"]
[Tue Jul 21 07:41:33.375509 2026] [security2:error] [pid 254995:tid 255171] [client 117.217.38.194:63244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M3f7v0rlcEGmVraFbkwAAA0w"]
[Tue Jul 21 07:41:33.407356 2026] [security2:error] [pid 254995:tid 255172] [client 20.226.60.151:22941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/buy.php"] [unique_id "al9M3f7v0rlcEGmVraFblAAAA00"]
[Tue Jul 21 07:41:33.728285 2026] [security2:error] [pid 254995:tid 255125] [client 20.226.60.151:62239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/file61.php"] [unique_id "al9M3f7v0rlcEGmVraFbnwAAAx4"]
[Tue Jul 21 07:41:33.822506 2026] [security2:error] [pid 254995:tid 255201] [client 20.104.96.117:30458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/pucci.php"] [unique_id "al9M3f7v0rlcEGmVraFboQAAA2o"]
[Tue Jul 21 07:41:33.825669 2026] [security2:error] [pid 254995:tid 255192] [client 4.204.201.85:46019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/info.php"] [unique_id "al9M3f7v0rlcEGmVraFbogAAA2E"]
[Tue Jul 21 07:41:33.835026 2026] [security2:error] [pid 254995:tid 255161] [client 20.226.60.151:62303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/water.php"] [unique_id "al9M3f7v0rlcEGmVraFbowAAA0I"]
[Tue Jul 21 07:41:33.993864 2026] [security2:error] [pid 254995:tid 255213] [client 74.249.245.134:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/.info.php"] [unique_id "al9M3f7v0rlcEGmVraFbpAAAA3U"]
[Tue Jul 21 07:41:34.034949 2026] [security2:error] [pid 254995:tid 255163] [client 20.226.60.151:22937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/ssend.php"] [unique_id "al9M3v7v0rlcEGmVraFbpgAAA0Q"]
[Tue Jul 21 07:41:34.122687 2026] [security2:error] [pid 254995:tid 255153] [client 20.226.60.151:62225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/nano.php"] [unique_id "al9M3v7v0rlcEGmVraFbqgAAAzo"]
[Tue Jul 21 07:41:34.152246 2026] [security2:error] [pid 254995:tid 255260] [client 20.226.60.151:59509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/root.php"] [unique_id "al9M3v7v0rlcEGmVraFbrAAAA4o"]
[Tue Jul 21 07:41:34.297412 2026] [security2:error] [pid 254995:tid 255151] [client 59.96.220.140:54701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbswAAAzg"]
[Tue Jul 21 07:41:34.298130 2026] [security2:error] [pid 254995:tid 255151] [client 59.96.220.140:54701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbswAAAzg"]
[Tue Jul 21 07:41:34.309632 2026] [security2:error] [pid 254995:tid 255274] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/item.php"] [unique_id "al9M3v7v0rlcEGmVraFbtQAAA5g"]
[Tue Jul 21 07:41:34.379840 2026] [security2:error] [pid 254995:tid 255109] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbtgADJHE"]
[Tue Jul 21 07:41:34.380027 2026] [security2:error] [pid 254995:tid 255131] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbtgADJHE"]
[Tue Jul 21 07:41:34.438261 2026] [security2:error] [pid 254995:tid 255214] [client 20.226.60.151:62216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/moon.php"] [unique_id "al9M3v7v0rlcEGmVraFbtwAAA3Y"]
[Tue Jul 21 07:41:34.489426 2026] [security2:error] [pid 254995:tid 255180] [client 139.167.225.182:62419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbuAAAA1U"]
[Tue Jul 21 07:41:34.489540 2026] [security2:error] [pid 254995:tid 255180] [client 139.167.225.182:62419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbuAAAA1U"]
[Tue Jul 21 07:41:34.599335 2026] [security2:error] [pid 254995:tid 255128] [client 136.144.33.102:26277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9M3v7v0rlcEGmVraFbugAAAyE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:34.615353 2026] [security2:error] [pid 254995:tid 255258] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/albin.php"] [unique_id "al9M3v7v0rlcEGmVraFbvgAAA4g"]
[Tue Jul 21 07:41:34.665353 2026] [security2:error] [pid 254995:tid 255026] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbwgADmh4"]
[Tue Jul 21 07:41:34.665477 2026] [security2:error] [pid 254995:tid 255276] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbwgADmh4"]
[Tue Jul 21 07:41:34.772901 2026] [security2:error] [pid 254995:tid 255154] [client 4.204.201.85:45975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/11.php"] [unique_id "al9M3v7v0rlcEGmVraFbyAAAAzs"]
[Tue Jul 21 07:41:34.780098 2026] [security2:error] [pid 254995:tid 255041] [remote 198.244.240.123:51508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.moveisrafael.com.br"] [uri "/robots.txt"] [unique_id "al9M3v7v0rlcEGmVraFbyQADly0"]
[Tue Jul 21 07:41:34.780211 2026] [security2:error] [pid 254995:tid 255273] [client 198.244.240.123:51508] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.moveisrafael.com.br"] [uri "/robots.txt"] [unique_id "al9M3v7v0rlcEGmVraFbyQADly0"]
[Tue Jul 21 07:41:34.900098 2026] [security2:error] [pid 254995:tid 255212] [client 122.179.91.63:13817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbygAAA3Q"]
[Tue Jul 21 07:41:34.900211 2026] [security2:error] [pid 254995:tid 255212] [client 122.179.91.63:13817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbygAAA3Q"]
[Tue Jul 21 07:41:34.919256 2026] [security2:error] [pid 254995:tid 255142] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/alfa.php"] [unique_id "al9M3v7v0rlcEGmVraFbywAAAy8"]
[Tue Jul 21 07:41:34.939201 2026] [security2:error] [pid 254995:tid 255184] [client 202.143.127.214:64726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbzQAAA1k"]
[Tue Jul 21 07:41:34.939285 2026] [security2:error] [pid 254995:tid 255184] [client 202.143.127.214:64726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbzQAAA1k"]
[Tue Jul 21 07:41:35.036342 2026] [security2:error] [pid 254995:tid 255161] [client 20.226.60.151:56251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/water.php"] [unique_id "al9M3_7v0rlcEGmVraFbzwAAA0I"]
[Tue Jul 21 07:41:35.071798 2026] [security2:error] [pid 254995:tid 255163] [client 20.226.60.151:23139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/item.php"] [unique_id "al9M3_7v0rlcEGmVraFb0QAAA0Q"]
[Tue Jul 21 07:41:35.076631 2026] [security2:error] [pid 254995:tid 255218] [client 20.226.60.151:62217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-info.php"] [unique_id "al9M3_7v0rlcEGmVraFb0gAAA3o"]
[Tue Jul 21 07:41:35.128597 2026] [security2:error] [pid 254995:tid 255254] [client 20.104.96.117:30404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/black.php"] [unique_id "al9M3_7v0rlcEGmVraFb2AAAA4Q"]
[Tue Jul 21 07:41:35.219045 2026] [security2:error] [pid 254995:tid 255263] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/autoload_classmap.php"] [unique_id "al9M3_7v0rlcEGmVraFb3AAAA40"]
[Tue Jul 21 07:41:35.236909 2026] [security2:error] [pid 254995:tid 255027] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sarareginadosreis1782388162420.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9M3_7v0rlcEGmVraFb3QADSh8"]
[Tue Jul 21 07:41:35.411834 2026] [security2:error] [pid 254995:tid 255038] [remote 57.141.18.71:45650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9M3_7v0rlcEGmVraFb4wADmCo"]
[Tue Jul 21 07:41:35.478262 2026] [security2:error] [pid 254995:tid 255211] [client 4.204.201.85:3534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/v2.php"] [unique_id "al9M3_7v0rlcEGmVraFb5QAAA3M"]
[Tue Jul 21 07:41:35.547047 2026] [security2:error] [pid 254995:tid 255200] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/av.php"] [unique_id "al9M3_7v0rlcEGmVraFb5wAAA2k"]
[Tue Jul 21 07:41:35.565166 2026] [security2:error] [pid 254995:tid 255189] [client 20.226.60.151:34050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/2000.php"] [unique_id "al9M3_7v0rlcEGmVraFb6AAAA14"]
[Tue Jul 21 07:41:35.574801 2026] [security2:error] [pid 254995:tid 255276] [client 20.226.60.151:22350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/ss.php"] [unique_id "al9M3_7v0rlcEGmVraFb6QAAA5o"]
[Tue Jul 21 07:41:35.709239 2026] [security2:error] [pid 254995:tid 255154] [client 20.226.60.151:59515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/sym403.php"] [unique_id "al9M3_7v0rlcEGmVraFb8QAAAzs"]
[Tue Jul 21 07:41:35.780999 2026] [security2:error] [pid 254995:tid 255142] [client 20.151.10.161:12044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/av.php"] [unique_id "al9M3_7v0rlcEGmVraFb9gAAAy8"]
[Tue Jul 21 07:41:35.860748 2026] [security2:error] [pid 254995:tid 255257] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/gg.php"] [unique_id "al9M3_7v0rlcEGmVraFb-gAAA4c"]
[Tue Jul 21 07:41:35.921701 2026] [autoindex:error] [pid 254995:tid 255179] [client 43.135.145.117:44252] AH01276: Cannot serve directory /home2/luc15241/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:41:35.997251 2026] [security2:error] [pid 254995:tid 255196] [client 20.104.96.117:30456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/zlece.php"] [unique_id "al9M3_7v0rlcEGmVraFb_gAAA2U"]
[Tue Jul 21 07:41:36.158560 2026] [security2:error] [pid 254995:tid 255215] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/sql.php"] [unique_id "al9M4P7v0rlcEGmVraFcBAAAA3c"]
[Tue Jul 21 07:41:36.250254 2026] [security2:error] [pid 254995:tid 255266] [client 20.226.60.151:62319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/122.php"] [unique_id "al9M4P7v0rlcEGmVraFcCwAAA5A"]
[Tue Jul 21 07:41:36.306215 2026] [security2:error] [pid 254995:tid 255057] [remote 15.235.27.175:31886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.moveisrafael.com.br"] [uri "/"] [unique_id "al9M4P7v0rlcEGmVraFcDwADSD0"]
[Tue Jul 21 07:41:36.306356 2026] [security2:error] [pid 254995:tid 255167] [client 15.235.27.175:31886] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.moveisrafael.com.br"] [uri "/"] [unique_id "al9M4P7v0rlcEGmVraFcDwADSD0"]
[Tue Jul 21 07:41:36.461391 2026] [security2:error] [pid 254995:tid 255125] [client 103.174.34.15:53718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M4P7v0rlcEGmVraFcFQAAAx4"]
[Tue Jul 21 07:41:36.461724 2026] [security2:error] [pid 254995:tid 255125] [client 103.174.34.15:53718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M4P7v0rlcEGmVraFcFQAAAx4"]
[Tue Jul 21 07:41:36.470633 2026] [security2:error] [pid 254995:tid 255273] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/up.php"] [unique_id "al9M4P7v0rlcEGmVraFcFgAAA5c"]
[Tue Jul 21 07:41:36.537762 2026] [security2:error] [pid 254995:tid 255220] [client 4.204.201.85:3537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/panel.php"] [unique_id "al9M4P7v0rlcEGmVraFcGQAAA3w"]
[Tue Jul 21 07:41:36.550711 2026] [security2:error] [pid 254995:tid 255200] [client 173.24.185.52:52670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9M4P7v0rlcEGmVraFcGwAAA2k"]
[Tue Jul 21 07:41:36.550805 2026] [security2:error] [pid 254995:tid 255200] [client 173.24.185.52:52670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9M4P7v0rlcEGmVraFcGwAAA2k"]
[Tue Jul 21 07:41:36.613207 2026] [security2:error] [pid 254995:tid 255112] [remote 162.19.86.63:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produto-express.com"] [uri "/wp-login.php"] [unique_id "al9M4P7v0rlcEGmVraFcHAADbHQ"]
[Tue Jul 21 07:41:36.641768 2026] [security2:error] [pid 254995:tid 255257] [client 20.226.60.151:22675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/hypo.php"] [unique_id "al9M4P7v0rlcEGmVraFcHQAAA4c"]
[Tue Jul 21 07:41:36.670291 2026] [security2:error] [pid 254995:tid 255196] [client 20.226.60.151:34024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/mds.php"] [unique_id "al9M4P7v0rlcEGmVraFcIAAAA2U"]
[Tue Jul 21 07:41:36.740322 2026] [security2:error] [pid 254995:tid 255135] [client 20.104.96.117:30463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/vssrs.php"] [unique_id "al9M4P7v0rlcEGmVraFcKAAAAyg"]
[Tue Jul 21 07:41:36.788587 2026] [security2:error] [pid 254995:tid 255148] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/66.php"] [unique_id "al9M4P7v0rlcEGmVraFcKQAAAzU"]
[Tue Jul 21 07:41:36.832281 2026] [security2:error] [pid 254995:tid 255268] [client 152.59.154.239:51973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M4P7v0rlcEGmVraFcKgAAA5I"]
[Tue Jul 21 07:41:36.832385 2026] [security2:error] [pid 254995:tid 255268] [client 152.59.154.239:51973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M4P7v0rlcEGmVraFcKgAAA5I"]
[Tue Jul 21 07:41:36.890537 2026] [security2:error] [pid 254995:tid 255181] [client 20.226.60.151:62316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-blink.php"] [unique_id "al9M4P7v0rlcEGmVraFcLgAAA1Y"]
[Tue Jul 21 07:41:37.088290 2026] [security2:error] [pid 254995:tid 255132] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/666.php"] [unique_id "al9M4f7v0rlcEGmVraFcNQAAAyU"]
[Tue Jul 21 07:41:37.250838 2026] [security2:error] [pid 254995:tid 255146] [client 4.204.201.85:7449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/dex.php"] [unique_id "al9M4f7v0rlcEGmVraFcOwAAAzM"]
[Tue Jul 21 07:41:37.322241 2026] [security2:error] [pid 254995:tid 255162] [client 20.226.60.151:33489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/zc-208.php"] [unique_id "al9M4f7v0rlcEGmVraFcPQAAA0M"]
[Tue Jul 21 07:41:37.442987 2026] [security2:error] [pid 254995:tid 255159] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/byp.php"] [unique_id "al9M4f7v0rlcEGmVraFcRgAAA0A"]
[Tue Jul 21 07:41:37.451426 2026] [security2:error] [pid 254995:tid 255213] [client 20.226.60.151:51204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/nano.php"] [unique_id "al9M4f7v0rlcEGmVraFcRwAAA3U"]
[Tue Jul 21 07:41:37.462918 2026] [security2:error] [pid 254995:tid 255212] [client 20.226.60.151:23162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/users.php"] [unique_id "al9M4f7v0rlcEGmVraFcSAAAA3Q"]
[Tue Jul 21 07:41:37.469776 2026] [security2:error] [pid 254995:tid 255156] [client 20.104.96.117:30412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wicked.php"] [unique_id "al9M4f7v0rlcEGmVraFcSQAAAz0"]
[Tue Jul 21 07:41:37.475695 2026] [security2:error] [pid 254995:tid 255140] [client 20.226.60.151:62228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/sid4.php"] [unique_id "al9M4f7v0rlcEGmVraFcSgAAAy0"]
[Tue Jul 21 07:41:37.536248 2026] [security2:error] [pid 254995:tid 255125] [client 193.36.225.123:51893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9M4f7v0rlcEGmVraFcQQAAAx4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:37.571738 2026] [security2:error] [pid 254995:tid 255145] [client 106.215.181.8:26264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M4f7v0rlcEGmVraFcSwAAAzI"]
[Tue Jul 21 07:41:37.581310 2026] [security2:error] [pid 254995:tid 255145] [client 106.215.181.8:26264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M4f7v0rlcEGmVraFcSwAAAzI"]
[Tue Jul 21 07:41:37.651867 2026] [security2:error] [pid 254995:tid 255104] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M4f7v0rlcEGmVraFcTQADemw"]
[Tue Jul 21 07:41:37.652003 2026] [security2:error] [pid 254995:tid 255218] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M4f7v0rlcEGmVraFcTQADemw"]
[Tue Jul 21 07:41:37.716702 2026] [security2:error] [pid 254995:tid 255263] [client 4.204.201.85:46016] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "futurelogistica.com"] [uri "/1.php"] [unique_id "al9M4f7v0rlcEGmVraFcUAAAA40"]
[Tue Jul 21 07:41:37.716837 2026] [security2:error] [pid 254995:tid 255263] [client 4.204.201.85:46016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/1.php"] [unique_id "al9M4f7v0rlcEGmVraFcUAAAA40"]
[Tue Jul 21 07:41:37.746632 2026] [security2:error] [pid 254995:tid 255131] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/date.php"] [unique_id "al9M4f7v0rlcEGmVraFcUQAAAyQ"]
[Tue Jul 21 07:41:37.761393 2026] [security2:error] [pid 254995:tid 255215] [client 20.226.60.151:59460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/v543.php"] [unique_id "al9M4f7v0rlcEGmVraFcUgAAA3c"]
[Tue Jul 21 07:41:38.037737 2026] [security2:error] [pid 254995:tid 255223] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/pomo.php"] [unique_id "al9M4v7v0rlcEGmVraFcWwAAA38"]
[Tue Jul 21 07:41:38.119959 2026] [security2:error] [pid 254995:tid 255190] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sarareginadosreis1782388162420.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9M4v7v0rlcEGmVraFcXAAAA18"]
[Tue Jul 21 07:41:38.231129 2026] [security2:error] [pid 254995:tid 255146] [client 20.104.96.117:30413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/24.php"] [unique_id "al9M4v7v0rlcEGmVraFcYAAAAzM"]
[Tue Jul 21 07:41:38.232955 2026] [proxy:error] [pid 254995:tid 255278] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:38.233032 2026] [proxy_http:error] [pid 254995:tid 255278] [client 20.226.60.151:62297] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:38.233661 2026] [proxy:error] [pid 254995:tid 255278] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:38.233693 2026] [proxy_http:error] [pid 254995:tid 255278] [client 20.226.60.151:62297] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:38.276479 2026] [security2:error] [pid 254995:tid 255174] [client 4.204.201.85:3562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/ms.php"] [unique_id "al9M4v7v0rlcEGmVraFcYgAAA08"]
[Tue Jul 21 07:41:38.329670 2026] [security2:error] [pid 254995:tid 255143] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/test1.php"] [unique_id "al9M4v7v0rlcEGmVraFcZAAAAzA"]
[Tue Jul 21 07:41:38.352588 2026] [security2:error] [pid 254995:tid 255170] [client 20.226.60.151:22344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/177.php"] [unique_id "al9M4v7v0rlcEGmVraFcZwAAA0s"]
[Tue Jul 21 07:41:38.647466 2026] [security2:error] [pid 254995:tid 255145] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/fw.php"] [unique_id "al9M4v7v0rlcEGmVraFccQAAAzI"]
[Tue Jul 21 07:41:38.650076 2026] [security2:error] [pid 254995:tid 255260] [client 20.226.60.151:62332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wmore1.php"] [unique_id "al9M4v7v0rlcEGmVraFccgAAA4o"]
[Tue Jul 21 07:41:38.799010 2026] [security2:error] [pid 254995:tid 255084] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M4v7v0rlcEGmVraFcdQADVFg"]
[Tue Jul 21 07:41:38.799160 2026] [security2:error] [pid 254995:tid 255179] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M4v7v0rlcEGmVraFcdQADVFg"]
[Tue Jul 21 07:41:38.852612 2026] [security2:error] [pid 254995:tid 255221] [client 136.144.33.107:58249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9M4v7v0rlcEGmVraFceQAAA30"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:38.978735 2026] [security2:error] [pid 254995:tid 255169] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/fm.php"] [unique_id "al9M4v7v0rlcEGmVraFcfgAAA0o"]
[Tue Jul 21 07:41:39.139475 2026] [security2:error] [pid 254995:tid 255082] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M4_7v0rlcEGmVraFchgADSFY"]
[Tue Jul 21 07:41:39.139892 2026] [security2:error] [pid 254995:tid 255167] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M4_7v0rlcEGmVraFchgADSFY"]
[Tue Jul 21 07:41:39.229110 2026] [security2:error] [pid 254995:tid 255219] [client 20.226.60.151:62325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/solo1.php"] [unique_id "al9M4_7v0rlcEGmVraFcigAAA3s"]
[Tue Jul 21 07:41:39.242100 2026] [security2:error] [pid 254995:tid 255213] [client 117.251.86.144:46930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9M4_7v0rlcEGmVraFciwAAA3U"]
[Tue Jul 21 07:41:39.242206 2026] [security2:error] [pid 254995:tid 255213] [client 117.251.86.144:46930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9M4_7v0rlcEGmVraFciwAAA3U"]
[Tue Jul 21 07:41:39.291860 2026] [security2:error] [pid 254995:tid 255220] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/ini.php"] [unique_id "al9M4_7v0rlcEGmVraFcjQAAA3w"]
[Tue Jul 21 07:41:39.420590 2026] [security2:error] [pid 254995:tid 255188] [client 20.226.60.151:22947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/config.php"] [unique_id "al9M4_7v0rlcEGmVraFckwAAA10"]
[Tue Jul 21 07:41:39.473965 2026] [security2:error] [pid 254995:tid 255201] [client 20.104.96.117:30448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/xacs.php"] [unique_id "al9M4_7v0rlcEGmVraFclAAAA2o"]
[Tue Jul 21 07:41:39.543734 2026] [security2:error] [pid 254995:tid 255210] [client 4.204.201.85:3555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/memberfuns.php"] [unique_id "al9M4_7v0rlcEGmVraFcmAAAA3I"]
[Tue Jul 21 07:41:39.613510 2026] [security2:error] [pid 254995:tid 255145] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/themes.php"] [unique_id "al9M4_7v0rlcEGmVraFcmwAAAzI"]
[Tue Jul 21 07:41:39.659503 2026] [security2:error] [pid 254995:tid 255164] [client 62.102.148.187:39998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9M4_7v0rlcEGmVraFcnAAAA0U"]
[Tue Jul 21 07:41:39.659645 2026] [security2:error] [pid 254995:tid 255164] [client 62.102.148.187:39998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9M4_7v0rlcEGmVraFcnAAAA0U"]
[Tue Jul 21 07:41:39.665493 2026] [security2:error] [pid 254995:tid 255211] [client 122.186.204.214:53620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M4_7v0rlcEGmVraFcnQAAA3M"]
[Tue Jul 21 07:41:39.665603 2026] [security2:error] [pid 254995:tid 255211] [client 122.186.204.214:53620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M4_7v0rlcEGmVraFcnQAAA3M"]
[Tue Jul 21 07:41:39.942132 2026] [security2:error] [pid 254995:tid 255258] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/dropdown.php"] [unique_id "al9M4_7v0rlcEGmVraFcowAAA4g"]
[Tue Jul 21 07:41:39.954485 2026] [security2:error] [pid 254995:tid 255275] [client 20.226.60.151:59463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/sixxis.php"] [unique_id "al9M4_7v0rlcEGmVraFcpAAAA5k"]
[Tue Jul 21 07:41:40.152327 2026] [security2:error] [pid 254995:tid 255278] [client 20.104.96.117:30457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/zildan.php"] [unique_id "al9M5P7v0rlcEGmVraFcrQAAA5w"]
[Tue Jul 21 07:41:40.153376 2026] [proxy:error] [pid 254995:tid 255209] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:40.153458 2026] [proxy_http:error] [pid 254995:tid 255209] [client 20.226.60.151:62226] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:40.154073 2026] [proxy:error] [pid 254995:tid 255209] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:40.154106 2026] [proxy_http:error] [pid 254995:tid 255209] [client 20.226.60.151:62226] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:40.245677 2026] [security2:error] [pid 254995:tid 255200] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/wp-links.php"] [unique_id "al9M5P7v0rlcEGmVraFcrwAAA2k"]
[Tue Jul 21 07:41:40.420007 2026] [security2:error] [pid 254995:tid 255128] [client 194.99.104.35:59876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9M5P7v0rlcEGmVraFctQAAAyE"]
[Tue Jul 21 07:41:40.420111 2026] [security2:error] [pid 254995:tid 255128] [client 194.99.104.35:59876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9M5P7v0rlcEGmVraFctQAAAyE"]
[Tue Jul 21 07:41:40.435699 2026] [security2:error] [pid 254995:tid 255218] [client 122.164.127.47:51814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9M5P7v0rlcEGmVraFcugAAA3o"]
[Tue Jul 21 07:41:40.435808 2026] [security2:error] [pid 254995:tid 255218] [client 122.164.127.47:51814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9M5P7v0rlcEGmVraFcugAAA3o"]
[Tue Jul 21 07:41:40.580028 2026] [security2:error] [pid 254995:tid 255254] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/xmrlpc.php"] [unique_id "al9M5P7v0rlcEGmVraFcwgAAA4Q"]
[Tue Jul 21 07:41:40.670581 2026] [security2:error] [pid 254995:tid 255169] [client 182.8.255.181:21216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9M5P7v0rlcEGmVraFcyAAAA0o"]
[Tue Jul 21 07:41:40.670754 2026] [security2:error] [pid 254995:tid 255169] [client 182.8.255.181:21216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9M5P7v0rlcEGmVraFcyAAAA0o"]
[Tue Jul 21 07:41:40.726182 2026] [autoindex:error] [pid 254995:tid 255256] [client 20.197.195.24:13664] AH01276: Cannot serve directory /home2/ren85318/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:41:40.752111 2026] [security2:error] [pid 254995:tid 255177] [client 20.197.195.24:13664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/wp-content/admin.php"] [unique_id "al9M5P7v0rlcEGmVraFczAAAA1I"]
[Tue Jul 21 07:41:40.762640 2026] [security2:error] [pid 254995:tid 255132] [client 4.204.201.85:46071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/0.php"] [unique_id "al9M5P7v0rlcEGmVraFczQAAAyU"]
[Tue Jul 21 07:41:40.890192 2026] [security2:error] [pid 254995:tid 255197] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/htaccess.php"] [unique_id "al9M5P7v0rlcEGmVraFc0AAAA2Y"]
[Tue Jul 21 07:41:41.033425 2026] [security2:error] [pid 254995:tid 255223] [client 103.86.117.203:50358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M5f7v0rlcEGmVraFc1wAAA38"]
[Tue Jul 21 07:41:41.033542 2026] [security2:error] [pid 254995:tid 255223] [client 103.86.117.203:50358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M5f7v0rlcEGmVraFc1wAAA38"]
[Tue Jul 21 07:41:41.086022 2026] [security2:error] [pid 254995:tid 255128] [client 20.104.96.117:30859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/csa.php"] [unique_id "al9M5f7v0rlcEGmVraFc2wAAAyE"]
[Tue Jul 21 07:41:41.208843 2026] [security2:error] [pid 254995:tid 255218] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/readme.php"] [unique_id "al9M5f7v0rlcEGmVraFc3AAAA3o"]
[Tue Jul 21 07:41:41.248603 2026] [security2:error] [pid 254995:tid 255189] [client 154.192.233.199:60423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M5f7v0rlcEGmVraFc3QAAA14"]
[Tue Jul 21 07:41:41.248894 2026] [security2:error] [pid 254995:tid 255189] [client 154.192.233.199:60423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M5f7v0rlcEGmVraFc3QAAA14"]
[Tue Jul 21 07:41:41.398076 2026] [security2:error] [pid 254995:tid 255254] [client 20.226.60.151:56293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/moon.php"] [unique_id "al9M5f7v0rlcEGmVraFc4wAAA4Q"]
[Tue Jul 21 07:41:41.448894 2026] [security2:error] [pid 254995:tid 255135] [client 20.226.60.151:22949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/gettest.php"] [unique_id "al9M5f7v0rlcEGmVraFc5gAAAyg"]
[Tue Jul 21 07:41:41.622060 2026] [security2:error] [pid 254995:tid 255147] [client 20.226.60.151:59428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/ip.php"] [unique_id "al9M5f7v0rlcEGmVraFc9AAAAzQ"]
[Tue Jul 21 07:41:41.661102 2026] [security2:error] [pid 254995:tid 255278] [client 194.99.104.35:59882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9M5f7v0rlcEGmVraFc9QAAA5w"]
[Tue Jul 21 07:41:41.661198 2026] [security2:error] [pid 254995:tid 255278] [client 194.99.104.35:59882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9M5f7v0rlcEGmVraFc9QAAA5w"]
[Tue Jul 21 07:41:41.670693 2026] [security2:error] [pid 254995:tid 255181] [client 4.204.201.85:7431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/BDKR28.php"] [unique_id "al9M5f7v0rlcEGmVraFc9gAAA1Y"]
[Tue Jul 21 07:41:41.743982 2026] [security2:error] [pid 254995:tid 255269] [client 20.226.60.151:33479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/cong.php"] [unique_id "al9M5f7v0rlcEGmVraFc-wAAA5M"]
[Tue Jul 21 07:41:41.858738 2026] [security2:error] [pid 254995:tid 255218] [client 20.104.96.117:30435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/w3llscc.php"] [unique_id "al9M5f7v0rlcEGmVraFc_gAAA3o"]
[Tue Jul 21 07:41:42.027299 2026] [security2:error] [pid 254995:tid 255161] [client 20.151.10.161:12034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/classwithtostring.php"] [unique_id "al9M5v7v0rlcEGmVraFdBAAAA0I"]
[Tue Jul 21 07:41:42.077922 2026] [security2:error] [pid 254995:tid 255211] [client 20.220.225.223:19281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/la.php"] [unique_id "al9M5v7v0rlcEGmVraFdBgAAA3M"]
[Tue Jul 21 07:41:42.192713 2026] [security2:error] [pid 254995:tid 255258] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/403.php"] [unique_id "al9M5v7v0rlcEGmVraFdDQAAA4g"]
[Tue Jul 21 07:41:42.240283 2026] [security2:error] [pid 254995:tid 255184] [client 4.204.201.85:46040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/green1.php"] [unique_id "al9M5v7v0rlcEGmVraFdDgAAA1k"]
[Tue Jul 21 07:41:42.406603 2026] [security2:error] [pid 254995:tid 255028] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9M5v7v0rlcEGmVraFdEAADciA"]
[Tue Jul 21 07:41:42.406758 2026] [security2:error] [pid 254995:tid 255210] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9M5v7v0rlcEGmVraFdEAADciA"]
[Tue Jul 21 07:41:42.506008 2026] [security2:error] [pid 254995:tid 255194] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/max.php"] [unique_id "al9M5v7v0rlcEGmVraFdFQAAA2M"]
[Tue Jul 21 07:41:42.530081 2026] [security2:error] [pid 254995:tid 255166] [client 175.45.70.82:58841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M5v7v0rlcEGmVraFdGQAAA0c"]
[Tue Jul 21 07:41:42.530221 2026] [security2:error] [pid 254995:tid 255166] [client 175.45.70.82:58841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M5v7v0rlcEGmVraFdGQAAA0c"]
[Tue Jul 21 07:41:42.544690 2026] [security2:error] [pid 254995:tid 255103] [remote 47.128.50.197:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hauptmann.com.br"] [uri "/"] [unique_id "al9M5v7v0rlcEGmVraFdGwADTWs"]
[Tue Jul 21 07:41:42.715888 2026] [security2:error] [pid 254995:tid 255268] [client 136.144.33.215:56491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9M5v7v0rlcEGmVraFdGgAAA5I"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:42.811688 2026] [security2:error] [pid 254995:tid 255197] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/m.php"] [unique_id "al9M5v7v0rlcEGmVraFdJgAAA2Y"]
[Tue Jul 21 07:41:42.862714 2026] [security2:error] [pid 254995:tid 255144] [client 4.204.201.85:46032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/nc4.php"] [unique_id "al9M5v7v0rlcEGmVraFdJwAAAzE"]
[Tue Jul 21 07:41:43.047251 2026] [security2:error] [pid 254995:tid 255183] [client 103.106.20.201:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M5_7v0rlcEGmVraFdMAAAA1g"]
[Tue Jul 21 07:41:43.047358 2026] [security2:error] [pid 254995:tid 255183] [client 103.106.20.201:49678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M5_7v0rlcEGmVraFdMAAAA1g"]
[Tue Jul 21 07:41:43.121240 2026] [security2:error] [pid 254995:tid 255184] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/click.php"] [unique_id "al9M5_7v0rlcEGmVraFdMQAAA1k"]
[Tue Jul 21 07:41:43.161485 2026] [security2:error] [pid 254995:tid 255181] [client 122.162.144.145:15965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9M5_7v0rlcEGmVraFdMgAAA1Y"]
[Tue Jul 21 07:41:43.161616 2026] [security2:error] [pid 254995:tid 255181] [client 122.162.144.145:15965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9M5_7v0rlcEGmVraFdMgAAA1Y"]
[Tue Jul 21 07:41:43.317779 2026] [security2:error] [pid 254995:tid 255182] [client 20.226.60.151:22360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/min.php"] [unique_id "al9M5_7v0rlcEGmVraFdNwAAA1c"]
[Tue Jul 21 07:41:43.333201 2026] [security2:error] [pid 254995:tid 255271] [client 20.226.60.151:56255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-info.php"] [unique_id "al9M5_7v0rlcEGmVraFdOAAAA5U"]
[Tue Jul 21 07:41:43.438432 2026] [proxy:error] [pid 254995:tid 255194] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:43.438520 2026] [proxy_http:error] [pid 254995:tid 255194] [client 23.137.105.99:40496] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:43.439097 2026] [proxy:error] [pid 254995:tid 255194] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:43.439125 2026] [proxy_http:error] [pid 254995:tid 255194] [client 23.137.105.99:40496] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:43.445735 2026] [security2:error] [pid 254995:tid 255209] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/lv.php"] [unique_id "al9M5_7v0rlcEGmVraFdOgAAA3E"]
[Tue Jul 21 07:41:43.604172 2026] [security2:error] [pid 254995:tid 255175] [client 20.220.225.223:5251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/ez.php"] [unique_id "al9M5_7v0rlcEGmVraFdQQAAA1A"]
[Tue Jul 21 07:41:43.729538 2026] [security2:error] [pid 254995:tid 255165] [client 4.204.201.85:7485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/a1.php"] [unique_id "al9M5_7v0rlcEGmVraFdRwAAA0Y"]
[Tue Jul 21 07:41:43.768960 2026] [security2:error] [pid 254995:tid 255128] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/cong.php"] [unique_id "al9M5_7v0rlcEGmVraFdSAAAAyE"]
[Tue Jul 21 07:41:43.841700 2026] [security2:error] [pid 254995:tid 255254] [client 20.104.96.117:30850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wpx.php"] [unique_id "al9M5_7v0rlcEGmVraFdSgAAA4Q"]
[Tue Jul 21 07:41:43.860359 2026] [security2:error] [pid 254995:tid 255215] [client 117.217.38.194:63719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M5_7v0rlcEGmVraFdSwAAA3c"]
[Tue Jul 21 07:41:43.860460 2026] [security2:error] [pid 254995:tid 255215] [client 117.217.38.194:63719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M5_7v0rlcEGmVraFdSwAAA3c"]
[Tue Jul 21 07:41:43.879267 2026] [security2:error] [pid 254995:tid 255188] [client 59.96.220.140:55235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9M5_7v0rlcEGmVraFdTAAAA10"]
[Tue Jul 21 07:41:43.880000 2026] [security2:error] [pid 254995:tid 255188] [client 59.96.220.140:55235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9M5_7v0rlcEGmVraFdTAAAA10"]
[Tue Jul 21 07:41:43.919647 2026] [core:error] [pid 254995:tid 255274] [client 23.137.105.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:43.919667 2026] [core:error] [pid 254995:tid 255274] [client 23.137.105.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:44.092128 2026] [security2:error] [pid 254995:tid 255271] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/brand.php"] [unique_id "al9M6P7v0rlcEGmVraFdWQAAA5U"]
[Tue Jul 21 07:41:44.097634 2026] [security2:error] [pid 254995:tid 255179] [client 20.226.60.151:59416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/kq1.php"] [unique_id "al9M6P7v0rlcEGmVraFdWgAAA1Q"]
[Tue Jul 21 07:41:44.400546 2026] [security2:error] [pid 254995:tid 255270] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/atomlib.php"] [unique_id "al9M6P7v0rlcEGmVraFdaQAAA5Q"]
[Tue Jul 21 07:41:44.432033 2026] [core:error] [pid 254995:tid 255188] [client 23.137.105.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:44.432060 2026] [core:error] [pid 254995:tid 255188] [client 23.137.105.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:44.433317 2026] [core:error] [pid 254995:tid 255143] [client 23.137.105.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:44.433334 2026] [core:error] [pid 254995:tid 255143] [client 23.137.105.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:44.600737 2026] [security2:error] [pid 254995:tid 255213] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sarasantosdasilva1782312779991.0711679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9M6P7v0rlcEGmVraFdegAAA3U"]
[Tue Jul 21 07:41:44.721253 2026] [security2:error] [pid 254995:tid 255166] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/0x.php"] [unique_id "al9M6P7v0rlcEGmVraFdfgAAA0c"]
[Tue Jul 21 07:41:44.803402 2026] [security2:error] [pid 254995:tid 255158] [client 20.226.60.151:54329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9M6P7v0rlcEGmVraFdggAAAz8"]
[Tue Jul 21 07:41:44.840637 2026] [security2:error] [pid 254995:tid 255263] [client 37.140.223.191:24915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9M6P7v0rlcEGmVraFdgwAAA40"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:44.841630 2026] [security2:error] [pid 254995:tid 255260] [client 4.204.201.85:3566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/eee.php"] [unique_id "al9M6P7v0rlcEGmVraFdhAAAA4o"]
[Tue Jul 21 07:41:44.898608 2026] [security2:error] [pid 254995:tid 255200] [client 20.226.60.151:22951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/dvjul.php"] [unique_id "al9M6P7v0rlcEGmVraFdhwAAA2k"]
[Tue Jul 21 07:41:44.956363 2026] [security2:error] [pid 254995:tid 255071] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M6P7v0rlcEGmVraFdiAADnEs"]
[Tue Jul 21 07:41:44.956525 2026] [security2:error] [pid 254995:tid 255278] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M6P7v0rlcEGmVraFdiAADnEs"]
[Tue Jul 21 07:41:45.063410 2026] [security2:error] [pid 254995:tid 255187] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/buy.php"] [unique_id "al9M6f7v0rlcEGmVraFdjgAAA1w"]
[Tue Jul 21 07:41:45.069793 2026] [proxy:error] [pid 254995:tid 255255] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:45.069865 2026] [proxy_http:error] [pid 254995:tid 255255] [client 20.226.60.151:62313] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:45.070317 2026] [proxy:error] [pid 254995:tid 255255] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:45.070340 2026] [proxy_http:error] [pid 254995:tid 255255] [client 20.226.60.151:62313] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:45.192901 2026] [security2:error] [pid 254995:tid 255224] [client 139.167.225.182:63066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M6f7v0rlcEGmVraFdkgAAA4A"]
[Tue Jul 21 07:41:45.193054 2026] [security2:error] [pid 254995:tid 255224] [client 139.167.225.182:63066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M6f7v0rlcEGmVraFdkgAAA4A"]
[Tue Jul 21 07:41:45.210252 2026] [security2:error] [pid 254995:tid 255141] [client 20.220.225.223:34188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/ez.php"] [unique_id "al9M6f7v0rlcEGmVraFdlAAAAy4"]
[Tue Jul 21 07:41:45.265983 2026] [security2:error] [pid 254995:tid 255102] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M6f7v0rlcEGmVraFdmgADOmo"]
[Tue Jul 21 07:41:45.266178 2026] [security2:error] [pid 254995:tid 255153] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M6f7v0rlcEGmVraFdmgADOmo"]
[Tue Jul 21 07:41:45.397542 2026] [security2:error] [pid 254995:tid 255177] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/sx.php"] [unique_id "al9M6f7v0rlcEGmVraFdngAAA1I"]
[Tue Jul 21 07:41:45.472822 2026] [security2:error] [pid 254995:tid 255139] [client 122.179.91.63:1797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9M6f7v0rlcEGmVraFdnwAAAyw"]
[Tue Jul 21 07:41:45.472954 2026] [security2:error] [pid 254995:tid 255139] [client 122.179.91.63:1797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9M6f7v0rlcEGmVraFdnwAAAyw"]
[Tue Jul 21 07:41:45.737399 2026] [security2:error] [pid 254995:tid 255175] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/article.php"] [unique_id "al9M6f7v0rlcEGmVraFdqAAAA1A"]
[Tue Jul 21 07:41:45.810123 2026] [security2:error] [pid 254995:tid 255273] [client 4.204.201.85:7458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/wp-aothait.php"] [unique_id "al9M6f7v0rlcEGmVraFdrQAAA5c"]
[Tue Jul 21 07:41:45.872668 2026] [security2:error] [pid 254995:tid 255178] [client 20.226.60.151:51206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/2000.php"] [unique_id "al9M6f7v0rlcEGmVraFdrwAAA1M"]
[Tue Jul 21 07:41:45.891350 2026] [security2:error] [pid 254995:tid 255181] [client 20.226.60.151:59506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/fw/faiyy.php"] [unique_id "al9M6f7v0rlcEGmVraFdsAAAA1Y"]
[Tue Jul 21 07:41:45.999340 2026] [security2:error] [pid 254995:tid 255215] [client 20.226.60.151:23128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/biufile.php"] [unique_id "al9M6f7v0rlcEGmVraFdswAAA3c"]
[Tue Jul 21 07:41:46.037942 2026] [security2:error] [pid 254995:tid 255143] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/bootstrap.php"] [unique_id "al9M6v7v0rlcEGmVraFdtAAAAzA"]
[Tue Jul 21 07:41:46.127669 2026] [security2:error] [pid 254995:tid 255271] [client 202.143.127.214:65189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M6v7v0rlcEGmVraFdtgAAA5U"]
[Tue Jul 21 07:41:46.128430 2026] [security2:error] [pid 254995:tid 255271] [client 202.143.127.214:65189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M6v7v0rlcEGmVraFdtgAAA5U"]
[Tue Jul 21 07:41:46.363579 2026] [core:error] [pid 254995:tid 255095] [remote 40.77.167.77:18325] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:46.363604 2026] [core:error] [pid 254995:tid 255095] [remote 40.77.167.77:18325] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:46.381428 2026] [security2:error] [pid 254995:tid 255266] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/config-backup.php"] [unique_id "al9M6v7v0rlcEGmVraFdwAAAA5A"]
[Tue Jul 21 07:41:46.438010 2026] [security2:error] [pid 254995:tid 255144] [client 20.226.60.151:62230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/public/css.php"] [unique_id "al9M6v7v0rlcEGmVraFdwQAAAzE"]
[Tue Jul 21 07:41:46.547942 2026] [core:error] [pid 254995:tid 255122] [remote 40.77.167.77:18325] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:46.547962 2026] [core:error] [pid 254995:tid 255122] [remote 40.77.167.77:18325] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:46.672258 2026] [core:error] [pid 254995:tid 255027] [remote 40.77.167.77:18325] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:46.672283 2026] [core:error] [pid 254995:tid 255027] [remote 40.77.167.77:18325] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:46.685975 2026] [security2:error] [pid 254995:tid 255175] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/goods.php"] [unique_id "al9M6v7v0rlcEGmVraFdywAAA1A"]
[Tue Jul 21 07:41:46.997078 2026] [security2:error] [pid 254995:tid 255165] [client 20.226.60.151:59455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/h02ugyh.php"] [unique_id "al9M6v7v0rlcEGmVraFd2AAAA0Y"]
[Tue Jul 21 07:41:47.003575 2026] [security2:error] [pid 254995:tid 255143] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/init.php"] [unique_id "al9M6_7v0rlcEGmVraFd2wAAAzA"]
[Tue Jul 21 07:41:47.085612 2026] [security2:error] [pid 254995:tid 255271] [client 20.226.60.151:54320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9M6_7v0rlcEGmVraFd3QAAA5U"]
[Tue Jul 21 07:41:47.107316 2026] [security2:error] [pid 254995:tid 255178] [client 173.24.185.52:53150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9M6_7v0rlcEGmVraFd3gAAA1M"]
[Tue Jul 21 07:41:47.107422 2026] [security2:error] [pid 254995:tid 255178] [client 173.24.185.52:53150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9M6_7v0rlcEGmVraFd3gAAA1M"]
[Tue Jul 21 07:41:47.138387 2026] [security2:error] [pid 254995:tid 255159] [client 4.204.201.85:7483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/config.json.php"] [unique_id "al9M6_7v0rlcEGmVraFd4AAAA0A"]
[Tue Jul 21 07:41:47.218059 2026] [security2:error] [pid 254995:tid 255136] [client 20.104.96.117:30852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wp-css.php"] [unique_id "al9M6_7v0rlcEGmVraFd4wAAAyk"]
[Tue Jul 21 07:41:47.301448 2026] [security2:error] [pid 254995:tid 255166] [client 103.174.34.15:54202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M6_7v0rlcEGmVraFd7AAAA0c"]
[Tue Jul 21 07:41:47.301573 2026] [security2:error] [pid 254995:tid 255166] [client 103.174.34.15:54202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M6_7v0rlcEGmVraFd7AAAA0c"]
[Tue Jul 21 07:41:47.388146 2026] [security2:error] [pid 254995:tid 255173] [client 20.220.225.223:11197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/fz.php"] [unique_id "al9M6_7v0rlcEGmVraFd8QAAA04"]
[Tue Jul 21 07:41:47.470961 2026] [security2:error] [pid 254995:tid 255263] [client 20.151.10.161:53575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9M6_7v0rlcEGmVraFd9gAAA40"]
[Tue Jul 21 07:41:47.545046 2026] [authz_core:error] [pid 254995:tid 255273] [client 74.249.245.134:0] AH01630: client denied by server configuration: /home4/inhous92/fortenegociosimobiliarios/php.ini
[Tue Jul 21 07:41:47.686016 2026] [security2:error] [pid 254995:tid 255268] [client 194.99.104.35:43662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9M6_7v0rlcEGmVraFd-gAAA5I"]
[Tue Jul 21 07:41:47.686139 2026] [security2:error] [pid 254995:tid 255268] [client 194.99.104.35:43662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9M6_7v0rlcEGmVraFd-gAAA5I"]
[Tue Jul 21 07:41:47.719724 2026] [security2:error] [pid 254995:tid 255162] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/settings.php"] [unique_id "al9M6_7v0rlcEGmVraFd_gAAA0M"]
[Tue Jul 21 07:41:47.754761 2026] [security2:error] [pid 254995:tid 255179] [client 172.245.102.45:38799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9M6_7v0rlcEGmVraFeAAAAA1Q"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:48.078737 2026] [security2:error] [pid 254995:tid 255125] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/g.php"] [unique_id "al9M7P7v0rlcEGmVraFeCwAAAx4"]
[Tue Jul 21 07:41:48.106783 2026] [security2:error] [pid 254995:tid 255169] [client 152.59.154.239:52453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M7P7v0rlcEGmVraFeDAAAA0o"]
[Tue Jul 21 07:41:48.106905 2026] [security2:error] [pid 254995:tid 255169] [client 152.59.154.239:52453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M7P7v0rlcEGmVraFeDAAAA0o"]
[Tue Jul 21 07:41:48.170032 2026] [security2:error] [pid 254995:tid 255047] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M7P7v0rlcEGmVraFeDQADXjM"]
[Tue Jul 21 07:41:48.170202 2026] [security2:error] [pid 254995:tid 255189] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M7P7v0rlcEGmVraFeDQADXjM"]
[Tue Jul 21 07:41:48.264627 2026] [security2:error] [pid 254995:tid 255180] [client 106.215.181.8:6648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M7P7v0rlcEGmVraFeEQAAA1U"]
[Tue Jul 21 07:41:48.264743 2026] [security2:error] [pid 254995:tid 255180] [client 106.215.181.8:6648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M7P7v0rlcEGmVraFeEQAAA1U"]
[Tue Jul 21 07:41:48.412046 2026] [security2:error] [pid 254995:tid 255223] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/403.php"] [unique_id "al9M7P7v0rlcEGmVraFeEwAAA38"]
[Tue Jul 21 07:41:48.541286 2026] [security2:error] [pid 254995:tid 255175] [client 20.226.60.151:23133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/av.php"] [unique_id "al9M7P7v0rlcEGmVraFeGQAAA1A"]
[Tue Jul 21 07:41:48.677009 2026] [security2:error] [pid 254995:tid 255270] [client 20.104.96.117:30460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/ho.php"] [unique_id "al9M7P7v0rlcEGmVraFeHgAAA5Q"]
[Tue Jul 21 07:41:48.705309 2026] [security2:error] [pid 254995:tid 255162] [client 20.226.60.151:56275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/122.php"] [unique_id "al9M7P7v0rlcEGmVraFeIQAAA0M"]
[Tue Jul 21 07:41:48.735889 2026] [security2:error] [pid 254995:tid 255221] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/api.php"] [unique_id "al9M7P7v0rlcEGmVraFeIgAAA30"]
[Tue Jul 21 07:41:48.933230 2026] [security2:error] [pid 254995:tid 255279] [client 20.226.60.151:23161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/coffexium.php"] [unique_id "al9M7P7v0rlcEGmVraFeKQAAA50"]
[Tue Jul 21 07:41:48.965739 2026] [security2:error] [pid 254995:tid 255256] [client 20.226.60.151:59394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-temp.php"] [unique_id "al9M7P7v0rlcEGmVraFeLQAAA4Y"]
[Tue Jul 21 07:41:49.052271 2026] [security2:error] [pid 254995:tid 255156] [client 4.204.201.85:46057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9M7f7v0rlcEGmVraFeMAAAAz0"]
[Tue Jul 21 07:41:49.114182 2026] [security2:error] [pid 254995:tid 255146] [client 20.104.96.117:30875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/xy.php"] [unique_id "al9M7f7v0rlcEGmVraFeMgAAAzM"]
[Tue Jul 21 07:41:49.342496 2026] [security2:error] [pid 254995:tid 255265] [client 20.226.60.151:22342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/core.php"] [unique_id "al9M7f7v0rlcEGmVraFePQAAA48"]
[Tue Jul 21 07:41:49.343500 2026] [security2:error] [pid 254995:tid 255252] [client 193.36.225.102:24127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9M6_7v0rlcEGmVraFd4QAAA4M"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:49.668785 2026] [security2:error] [pid 254995:tid 255108] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M7f7v0rlcEGmVraFeRQADf3A"]
[Tue Jul 21 07:41:49.669048 2026] [security2:error] [pid 254995:tid 255223] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M7f7v0rlcEGmVraFeRQADf3A"]
[Tue Jul 21 07:41:49.741645 2026] [security2:error] [pid 254995:tid 255106] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M7f7v0rlcEGmVraFeRgADh24"]
[Tue Jul 21 07:41:49.741831 2026] [security2:error] [pid 254995:tid 255257] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M7f7v0rlcEGmVraFeRgADh24"]
[Tue Jul 21 07:41:49.921403 2026] [security2:error] [pid 254995:tid 255182] [client 117.251.86.144:47158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9M7f7v0rlcEGmVraFeTQAAA1c"]
[Tue Jul 21 07:41:49.921521 2026] [security2:error] [pid 254995:tid 255182] [client 117.251.86.144:47158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9M7f7v0rlcEGmVraFeTQAAA1c"]
[Tue Jul 21 07:41:49.942893 2026] [security2:error] [pid 254995:tid 255220] [client 20.226.60.151:23148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/als.php"] [unique_id "al9M7f7v0rlcEGmVraFeTgAAA3w"]
[Tue Jul 21 07:41:49.969922 2026] [security2:error] [pid 254995:tid 255179] [client 34.1.17.177:52186] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bastarecomecar.com.br"] [uri "/index.php"] [unique_id "al9M7P7v0rlcEGmVraFeJgAAA1Q"]
[Tue Jul 21 07:41:49.974963 2026] [security2:error] [pid 254995:tid 255166] [client 34.1.17.177:38612] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bastarecomecar.com.br"] [uri "/index.php"] [unique_id "al9M7f7v0rlcEGmVraFeQQAAA0c"]
[Tue Jul 21 07:41:50.043311 2026] [security2:error] [pid 254995:tid 255224] [client 20.226.60.151:54317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/media.php"] [unique_id "al9M7v7v0rlcEGmVraFeVgAAA4A"]
[Tue Jul 21 07:41:50.228741 2026] [security2:error] [pid 254995:tid 255169] [client 4.204.201.85:46051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/k2.php"] [unique_id "al9M7v7v0rlcEGmVraFeXAAAA0o"]
[Tue Jul 21 07:41:50.288688 2026] [security2:error] [pid 254995:tid 255139] [client 34.1.17.177:52198] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bastarecomecar.com.br"] [uri "/index.php"] [unique_id "al9M7v7v0rlcEGmVraFeWwAAAyw"]
[Tue Jul 21 07:41:50.300329 2026] [security2:error] [pid 254995:tid 255218] [client 20.226.60.151:22370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/simple.php"] [unique_id "al9M7v7v0rlcEGmVraFeXQAAA3o"]
[Tue Jul 21 07:41:50.308515 2026] [security2:error] [pid 254995:tid 255269] [client 122.186.204.214:54259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M7v7v0rlcEGmVraFeXgAAA5M"]
[Tue Jul 21 07:41:50.308639 2026] [security2:error] [pid 254995:tid 255269] [client 122.186.204.214:54259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M7v7v0rlcEGmVraFeXgAAA5M"]
[Tue Jul 21 07:41:50.346280 2026] [security2:error] [pid 254995:tid 255189] [client 20.226.60.151:62237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/output.php"] [unique_id "al9M7v7v0rlcEGmVraFeYgAAA14"]
[Tue Jul 21 07:41:50.369043 2026] [security2:error] [pid 254995:tid 255131] [client 20.226.60.151:59519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-content/cong.php"] [unique_id "al9M7v7v0rlcEGmVraFeZAAAAyQ"]
[Tue Jul 21 07:41:50.393514 2026] [security2:error] [pid 254995:tid 255252] [client 20.226.60.151:56264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/mds.php"] [unique_id "al9M7v7v0rlcEGmVraFeZgAAA4M"]
[Tue Jul 21 07:41:50.562264 2026] [security2:error] [pid 254995:tid 255273] [client 20.226.60.151:23129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/init.php"] [unique_id "al9M7v7v0rlcEGmVraFebQAAA5c"]
[Tue Jul 21 07:41:50.627035 2026] [security2:error] [pid 254995:tid 255260] [client 20.226.60.151:22380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/fpwch.php"] [unique_id "al9M7v7v0rlcEGmVraFecQAAA4o"]
[Tue Jul 21 07:41:50.646430 2026] [core:error] [pid 254995:tid 254997] [remote 52.167.144.206:52545] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:50.646455 2026] [core:error] [pid 254995:tid 254997] [remote 52.167.144.206:52545] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:50.762609 2026] [security2:error] [pid 254995:tid 255220] [client 20.226.60.151:23135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/domvf.php"] [unique_id "al9M7v7v0rlcEGmVraFedAAAA3w"]
[Tue Jul 21 07:41:50.775093 2026] [core:error] [pid 254995:tid 255024] [remote 52.167.144.206:52545] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:50.775125 2026] [core:error] [pid 254995:tid 255024] [remote 52.167.144.206:52545] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:50.854395 2026] [security2:error] [pid 254995:tid 255268] [client 34.1.17.177:38628] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bastarecomecar.com.br"] [uri "/index.php"] [unique_id "al9M7v7v0rlcEGmVraFedwAAA5I"]
[Tue Jul 21 07:41:50.902522 2026] [core:error] [pid 254995:tid 255018] [remote 52.167.144.206:52545] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:50.902548 2026] [core:error] [pid 254995:tid 255018] [remote 52.167.144.206:52545] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:50.940938 2026] [security2:error] [pid 254995:tid 255270] [client 20.220.225.223:55503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/cron-tab.php"] [unique_id "al9M7v7v0rlcEGmVraFefgAAA5Q"]
[Tue Jul 21 07:41:50.961472 2026] [security2:error] [pid 254995:tid 255125] [client 122.164.127.47:52374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9M7v7v0rlcEGmVraFegAAAAx4"]
[Tue Jul 21 07:41:50.961598 2026] [security2:error] [pid 254995:tid 255125] [client 122.164.127.47:52374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9M7v7v0rlcEGmVraFegAAAAx4"]
[Tue Jul 21 07:41:51.069074 2026] [security2:error] [pid 254995:tid 255229] [client 20.104.96.117:30861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/loader.php"] [unique_id "al9M7_7v0rlcEGmVraFehQAAA4I"]
[Tue Jul 21 07:41:51.086657 2026] [security2:error] [pid 254995:tid 255198] [client 20.220.225.223:5292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/la.php"] [unique_id "al9M7_7v0rlcEGmVraFeiAAAA2c"]
[Tue Jul 21 07:41:51.116017 2026] [security2:error] [pid 254995:tid 255173] [client 182.8.255.181:17183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9M7_7v0rlcEGmVraFeigAAA04"]
[Tue Jul 21 07:41:51.116139 2026] [security2:error] [pid 254995:tid 255173] [client 182.8.255.181:17183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9M7_7v0rlcEGmVraFeigAAA04"]
[Tue Jul 21 07:41:51.397948 2026] [security2:error] [pid 254995:tid 255181] [client 20.151.10.161:12057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-blog.php"] [unique_id "al9M7_7v0rlcEGmVraFekQAAA1Y"]
[Tue Jul 21 07:41:51.448334 2026] [security2:error] [pid 254995:tid 255275] [client 20.226.60.151:23104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wp.php"] [unique_id "al9M7_7v0rlcEGmVraFekgAAA5k"]
[Tue Jul 21 07:41:51.448597 2026] [security2:error] [pid 254995:tid 255183] [client 4.204.201.85:3572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/uiuvs58l.php"] [unique_id "al9M7_7v0rlcEGmVraFekwAAA1g"]
[Tue Jul 21 07:41:51.523241 2026] [security2:error] [pid 254995:tid 255147] [client 103.86.117.203:51156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M7_7v0rlcEGmVraFelQAAAzQ"]
[Tue Jul 21 07:41:51.523430 2026] [security2:error] [pid 254995:tid 255147] [client 103.86.117.203:51156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M7_7v0rlcEGmVraFelQAAAzQ"]
[Tue Jul 21 07:41:51.718745 2026] [security2:error] [pid 254995:tid 255202] [client 20.197.195.24:13644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/ms-edit.php"] [unique_id "al9M7_7v0rlcEGmVraFemwAAA2s"]
[Tue Jul 21 07:41:51.856246 2026] [security2:error] [pid 254995:tid 255125] [client 20.226.60.151:62302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-file-120.php"] [unique_id "al9M7_7v0rlcEGmVraFenwAAAx4"]
[Tue Jul 21 07:41:51.989844 2026] [security2:error] [pid 254995:tid 255131] [client 20.226.60.151:22914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/class.php"] [unique_id "al9M7_7v0rlcEGmVraFeqgAAAyQ"]
[Tue Jul 21 07:41:52.144385 2026] [security2:error] [pid 254995:tid 255222] [client 20.226.60.151:22337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/echkm.php"] [unique_id "al9M8P7v0rlcEGmVraFesgAAA34"]
[Tue Jul 21 07:41:52.362493 2026] [security2:error] [pid 254995:tid 255182] [client 20.220.225.223:34203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/fz.php"] [unique_id "al9M8P7v0rlcEGmVraFetgAAA1c"]
[Tue Jul 21 07:41:52.433581 2026] [security2:error] [pid 254995:tid 255146] [client 194.99.104.35:47274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9M8P7v0rlcEGmVraFeuAAAAzM"]
[Tue Jul 21 07:41:52.433693 2026] [security2:error] [pid 254995:tid 255146] [client 194.99.104.35:47274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9M8P7v0rlcEGmVraFeuAAAAzM"]
[Tue Jul 21 07:41:52.481584 2026] [security2:error] [pid 254995:tid 255212] [client 4.204.201.85:3561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/40p9ixjd.php"] [unique_id "al9M8P7v0rlcEGmVraFeuwAAA3Q"]
[Tue Jul 21 07:41:52.682167 2026] [proxy:error] [pid 254995:tid 255270] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:52.682260 2026] [proxy_http:error] [pid 254995:tid 255270] [client 20.226.60.151:59462] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:52.682869 2026] [proxy:error] [pid 254995:tid 255270] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:52.684070 2026] [proxy_http:error] [pid 254995:tid 255270] [client 20.226.60.151:59462] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:52.877683 2026] [security2:error] [pid 254995:tid 255183] [client 154.192.233.199:60229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8P7v0rlcEGmVraFexQAAA1g"]
[Tue Jul 21 07:41:52.877829 2026] [security2:error] [pid 254995:tid 255183] [client 154.192.233.199:60229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8P7v0rlcEGmVraFexQAAA1g"]
[Tue Jul 21 07:41:52.891870 2026] [security2:error] [pid 254995:tid 255122] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9M8P7v0rlcEGmVraFeyAADP34"]
[Tue Jul 21 07:41:52.892029 2026] [security2:error] [pid 254995:tid 255158] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9M8P7v0rlcEGmVraFeyAADP34"]
[Tue Jul 21 07:41:52.925370 2026] [security2:error] [pid 254995:tid 255140] [client 20.226.60.151:54384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/images.php"] [unique_id "al9M8P7v0rlcEGmVraFeyQAAAy0"]
[Tue Jul 21 07:41:53.050068 2026] [security2:error] [pid 254995:tid 255167] [client 20.220.225.223:32285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/koiy.php"] [unique_id "al9M8f7v0rlcEGmVraFe0AAAA0g"]
[Tue Jul 21 07:41:53.105070 2026] [security2:error] [pid 254995:tid 255175] [client 20.226.60.151:22919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/lib.php"] [unique_id "al9M8f7v0rlcEGmVraFe1QAAA1A"]
[Tue Jul 21 07:41:53.135112 2026] [security2:error] [pid 254995:tid 255153] [client 20.226.60.151:54300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/gecko.php"] [unique_id "al9M8f7v0rlcEGmVraFe1wAAAzo"]
[Tue Jul 21 07:41:53.251554 2026] [security2:error] [pid 254995:tid 255182] [client 20.226.60.151:54315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/82.php"] [unique_id "al9M8f7v0rlcEGmVraFe2gAAA1c"]
[Tue Jul 21 07:41:53.308307 2026] [security2:error] [pid 254995:tid 255156] [client 175.45.70.82:59163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8f7v0rlcEGmVraFe2wAAAz0"]
[Tue Jul 21 07:41:53.308442 2026] [security2:error] [pid 254995:tid 255156] [client 175.45.70.82:59163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8f7v0rlcEGmVraFe2wAAAz0"]
[Tue Jul 21 07:41:53.311604 2026] [security2:error] [pid 254995:tid 255147] [client 20.226.60.151:54372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/admin.php"] [unique_id "al9M8f7v0rlcEGmVraFe3AAAAzQ"]
[Tue Jul 21 07:41:53.352521 2026] [security2:error] [pid 254995:tid 255220] [client 20.226.60.151:33486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/special.php"] [unique_id "al9M8f7v0rlcEGmVraFe3QAAA3w"]
[Tue Jul 21 07:41:53.417030 2026] [security2:error] [pid 254995:tid 255194] [client 193.36.225.63:59749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9M8P7v0rlcEGmVraFetAAAA2M"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:53.491618 2026] [security2:error] [pid 254995:tid 255174] [client 20.226.60.151:22940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/login.php"] [unique_id "al9M8f7v0rlcEGmVraFe5AAAA08"]
[Tue Jul 21 07:41:53.505322 2026] [security2:error] [pid 254995:tid 255202] [client 20.226.60.151:54399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/adminner.php"] [unique_id "al9M8f7v0rlcEGmVraFe5QAAA2s"]
[Tue Jul 21 07:41:53.726485 2026] [access_compat:error] [pid 254995:tid 255189] [client 162.241.63.68:15446] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:41:53.792285 2026] [security2:error] [pid 254995:tid 255129] [client 103.106.20.201:50257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8f7v0rlcEGmVraFe8QAAAyI"]
[Tue Jul 21 07:41:53.792419 2026] [security2:error] [pid 254995:tid 255129] [client 103.106.20.201:50257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8f7v0rlcEGmVraFe8QAAAyI"]
[Tue Jul 21 07:41:53.805525 2026] [security2:error] [pid 254995:tid 255279] [client 20.151.10.161:55275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9M8f7v0rlcEGmVraFe8wAAA50"]
[Tue Jul 21 07:41:53.865440 2026] [security2:error] [pid 254995:tid 255142] [client 4.204.201.85:46061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/uiuvs58l.update.php"] [unique_id "al9M8f7v0rlcEGmVraFe9gAAAy8"]
[Tue Jul 21 07:41:53.886856 2026] [security2:error] [pid 254995:tid 255132] [client 122.162.144.145:10195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9M8f7v0rlcEGmVraFe9wAAAyU"]
[Tue Jul 21 07:41:53.887016 2026] [security2:error] [pid 254995:tid 255132] [client 122.162.144.145:10195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9M8f7v0rlcEGmVraFe9wAAAyU"]
[Tue Jul 21 07:41:54.205755 2026] [security2:error] [pid 254995:tid 255179] [client 20.226.60.151:56284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-blink.php"] [unique_id "al9M8v7v0rlcEGmVraFfBQAAA1Q"]
[Tue Jul 21 07:41:54.270654 2026] [security2:error] [pid 254995:tid 255224] [client 20.226.60.151:59423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-includes/css/index.php"] [unique_id "al9M8v7v0rlcEGmVraFfCwAAA4A"]
[Tue Jul 21 07:41:54.270668 2026] [security2:error] [pid 254995:tid 255136] [client 20.104.96.117:30425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/spadex.php"] [unique_id "al9M8v7v0rlcEGmVraFfDAAAAyk"]
[Tue Jul 21 07:41:54.332947 2026] [security2:error] [pid 254995:tid 255174] [client 20.226.60.151:33518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/as.php"] [unique_id "al9M8v7v0rlcEGmVraFfDQAAA08"]
[Tue Jul 21 07:41:54.341060 2026] [security2:error] [pid 254995:tid 255131] [client 117.217.38.194:64207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8v7v0rlcEGmVraFfDgAAAyQ"]
[Tue Jul 21 07:41:54.341171 2026] [security2:error] [pid 254995:tid 255131] [client 117.217.38.194:64207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8v7v0rlcEGmVraFfDgAAAyQ"]
[Tue Jul 21 07:41:54.456551 2026] [security2:error] [pid 254995:tid 255218] [client 59.96.220.140:55797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9M8v7v0rlcEGmVraFfFQAAA3o"]
[Tue Jul 21 07:41:54.456679 2026] [security2:error] [pid 254995:tid 255218] [client 59.96.220.140:55797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9M8v7v0rlcEGmVraFfFQAAA3o"]
[Tue Jul 21 07:41:54.612543 2026] [security2:error] [pid 254995:tid 255177] [client 4.204.201.85:45959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/for.php"] [unique_id "al9M8v7v0rlcEGmVraFfGgAAA1I"]
[Tue Jul 21 07:41:55.048867 2026] [security2:error] [pid 254995:tid 255147] [client 20.226.60.151:54345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/admin.php"] [unique_id "al9M8_7v0rlcEGmVraFfJwAAAzQ"]
[Tue Jul 21 07:41:55.100891 2026] [security2:error] [pid 254995:tid 255212] [client 4.204.201.85:46054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/raw.php"] [unique_id "al9M8_7v0rlcEGmVraFfKQAAA3Q"]
[Tue Jul 21 07:41:55.186627 2026] [security2:error] [pid 254995:tid 255194] [client 20.226.60.151:22378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/a2.php"] [unique_id "al9M8_7v0rlcEGmVraFfLgAAA2M"]
[Tue Jul 21 07:41:55.240333 2026] [security2:error] [pid 254995:tid 255174] [client 20.220.225.223:22485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/hp2.php"] [unique_id "al9M8_7v0rlcEGmVraFfMgAAA08"]
[Tue Jul 21 07:41:55.300046 2026] [security2:error] [pid 254995:tid 255196] [client 20.220.225.223:19278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9M8_7v0rlcEGmVraFfNgAAA2U"]
[Tue Jul 21 07:41:55.543277 2026] [security2:error] [pid 254995:tid 255198] [client 20.104.96.117:30867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/2x.php"] [unique_id "al9M8_7v0rlcEGmVraFfPAAAA2c"]
[Tue Jul 21 07:41:55.571530 2026] [security2:error] [pid 254995:tid 255152] [client 139.167.225.182:63714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8_7v0rlcEGmVraFfPQAAAzk"]
[Tue Jul 21 07:41:55.573435 2026] [security2:error] [pid 254995:tid 255152] [client 139.167.225.182:63714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8_7v0rlcEGmVraFfPQAAAzk"]
[Tue Jul 21 07:41:55.653265 2026] [security2:error] [pid 254995:tid 255195] [client 194.99.104.35:54226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9M8_7v0rlcEGmVraFfQQAAA2Q"]
[Tue Jul 21 07:41:55.653404 2026] [security2:error] [pid 254995:tid 255195] [client 194.99.104.35:54226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9M8_7v0rlcEGmVraFfQQAAA2Q"]
[Tue Jul 21 07:41:55.658240 2026] [security2:error] [pid 254995:tid 255273] [client 20.220.225.223:32273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/hp3.php"] [unique_id "al9M8_7v0rlcEGmVraFfQwAAA5c"]
[Tue Jul 21 07:41:55.818376 2026] [security2:error] [pid 254995:tid 255012] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8_7v0rlcEGmVraFfUQADmBA"]
[Tue Jul 21 07:41:55.818563 2026] [security2:error] [pid 254995:tid 255274] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8_7v0rlcEGmVraFfUQADmBA"]
[Tue Jul 21 07:41:55.823433 2026] [security2:error] [pid 254995:tid 255194] [client 20.220.225.223:11164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9M8_7v0rlcEGmVraFfUgAAA2M"]
[Tue Jul 21 07:41:55.869881 2026] [security2:error] [pid 254995:tid 255224] [client 20.226.60.151:33529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9M8_7v0rlcEGmVraFfUwAAA4A"]
[Tue Jul 21 07:41:55.976999 2026] [security2:error] [pid 254995:tid 255017] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M8_7v0rlcEGmVraFfVAADVxU"]
[Tue Jul 21 07:41:55.977124 2026] [security2:error] [pid 254995:tid 255182] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M8_7v0rlcEGmVraFfVAADVxU"]
[Tue Jul 21 07:41:56.150440 2026] [security2:error] [pid 254995:tid 255258] [client 20.226.60.151:22935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/d61.php"] [unique_id "al9M9P7v0rlcEGmVraFfWwAAA4g"]
[Tue Jul 21 07:41:56.560823 2026] [security2:error] [pid 254995:tid 255084] [remote 45.79.123.44:58958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "voweltravel.com.br"] [uri "/wp-login.php"] [unique_id "al9M9P7v0rlcEGmVraFfYwADHlg"]
[Tue Jul 21 07:41:57.010120 2026] [security2:error] [pid 254995:tid 255221] [client 20.226.60.151:54363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/k.php"] [unique_id "al9M9f7v0rlcEGmVraFfdAAAA30"]
[Tue Jul 21 07:41:57.142840 2026] [security2:error] [pid 254995:tid 255178] [client 122.179.91.63:6880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9M9f7v0rlcEGmVraFfeAAAA1M"]
[Tue Jul 21 07:41:57.142976 2026] [security2:error] [pid 254995:tid 255178] [client 122.179.91.63:6880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9M9f7v0rlcEGmVraFfeAAAA1M"]
[Tue Jul 21 07:41:57.284514 2026] [security2:error] [pid 254995:tid 255259] [client 74.7.228.9:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.lunarium.tec.br"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "al9M9f7v0rlcEGmVraFffwADiTs"]
[Tue Jul 21 07:41:57.354180 2026] [security2:error] [pid 254995:tid 255181] [client 202.143.127.214:49241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M9f7v0rlcEGmVraFfhgAAA1Y"]
[Tue Jul 21 07:41:57.354297 2026] [security2:error] [pid 254995:tid 255181] [client 202.143.127.214:49241] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M9f7v0rlcEGmVraFfhgAAA1Y"]
[Tue Jul 21 07:41:57.374835 2026] [security2:error] [pid 254995:tid 255142] [client 20.151.10.161:53626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/adminfuns.php"] [unique_id "al9M9f7v0rlcEGmVraFfiQAAAy8"]
[Tue Jul 21 07:41:57.648769 2026] [security2:error] [pid 254995:tid 255270] [client 20.226.60.151:59443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/jj.php"] [unique_id "al9M9f7v0rlcEGmVraFfjAAAA5Q"]
[Tue Jul 21 07:41:57.668568 2026] [security2:error] [pid 254995:tid 255215] [client 173.24.185.52:53627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9M9f7v0rlcEGmVraFfjQAAA3c"]
[Tue Jul 21 07:41:57.668710 2026] [security2:error] [pid 254995:tid 255215] [client 173.24.185.52:53627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9M9f7v0rlcEGmVraFfjQAAA3c"]
[Tue Jul 21 07:41:57.699842 2026] [security2:error] [pid 254995:tid 255204] [client 20.226.60.151:62219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/w1px.php"] [unique_id "al9M9f7v0rlcEGmVraFfjgAAA20"]
[Tue Jul 21 07:41:57.914878 2026] [security2:error] [pid 254995:tid 255131] [client 103.174.34.15:54689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M9f7v0rlcEGmVraFflQAAAyQ"]
[Tue Jul 21 07:41:57.915031 2026] [security2:error] [pid 254995:tid 255131] [client 103.174.34.15:54689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M9f7v0rlcEGmVraFflQAAAyQ"]
[Tue Jul 21 07:41:57.927957 2026] [security2:error] [pid 254995:tid 255169] [client 20.220.225.223:32298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/aa1.php"] [unique_id "al9M9f7v0rlcEGmVraFfmQAAA0o"]
[Tue Jul 21 07:41:58.077528 2026] [security2:error] [pid 254995:tid 255130] [client 20.226.60.151:62255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/yawa.php"] [unique_id "al9M9v7v0rlcEGmVraFfnwAAAyM"]
[Tue Jul 21 07:41:58.112420 2026] [security2:error] [pid 254995:tid 255146] [client 20.226.60.151:33498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/js.php"] [unique_id "al9M9v7v0rlcEGmVraFfoAAAAzM"]
[Tue Jul 21 07:41:58.149220 2026] [security2:error] [pid 254995:tid 255267] [client 172.245.102.46:45589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9M9v7v0rlcEGmVraFfogAAA5E"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:58.167475 2026] [security2:error] [pid 254995:tid 255125] [client 45.8.19.184:28273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lotfiimplantes.com.br"] [uri "/wp-login.php"] [unique_id "al9M9v7v0rlcEGmVraFfpAAAAx4"]
[Tue Jul 21 07:41:58.168151 2026] [security2:error] [pid 254995:tid 255202] [client 45.8.19.190:53169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lotfiimplantes.com.br"] [uri "/wp-login.php"] [unique_id "al9M9v7v0rlcEGmVraFfowAAA2s"]
[Tue Jul 21 07:41:58.263104 2026] [security2:error] [pid 254995:tid 255188] [client 20.226.60.151:51235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/zc-208.php"] [unique_id "al9M9v7v0rlcEGmVraFfrAAAA10"]
[Tue Jul 21 07:41:58.284767 2026] [security2:error] [pid 254995:tid 255222] [client 20.220.225.223:34242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9M9v7v0rlcEGmVraFfsQAAA34"]
[Tue Jul 21 07:41:58.512952 2026] [security2:error] [pid 254995:tid 255162] [client 20.226.60.151:61952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/blurbs.php"] [unique_id "al9M9v7v0rlcEGmVraFfuwAAA0M"]
[Tue Jul 21 07:41:58.620289 2026] [security2:error] [pid 254995:tid 255174] [client 20.226.60.151:62299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/core.php"] [unique_id "al9M9v7v0rlcEGmVraFfwgAAA08"]
[Tue Jul 21 07:41:58.703370 2026] [security2:error] [pid 254995:tid 255183] [client 20.226.60.151:22969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/info.php"] [unique_id "al9M9v7v0rlcEGmVraFfxwAAA1g"]
[Tue Jul 21 07:41:58.969534 2026] [security2:error] [pid 254995:tid 255189] [client 20.220.225.223:19297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/inso.php"] [unique_id "al9M9v7v0rlcEGmVraFf0gAAA14"]
[Tue Jul 21 07:41:59.066599 2026] [core:alert] [pid 254995:tid 255193] [client 57.141.18.42:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:41:59.080696 2026] [security2:error] [pid 254995:tid 255209] [client 106.215.181.8:28639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M9_7v0rlcEGmVraFf2QAAA3E"]
[Tue Jul 21 07:41:59.080782 2026] [security2:error] [pid 254995:tid 255209] [client 106.215.181.8:28639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M9_7v0rlcEGmVraFf2QAAA3E"]
[Tue Jul 21 07:41:59.154112 2026] [security2:error] [pid 254995:tid 255217] [client 152.59.154.239:52941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M9_7v0rlcEGmVraFf3QAAA3k"]
[Tue Jul 21 07:41:59.154246 2026] [security2:error] [pid 254995:tid 255217] [client 152.59.154.239:52941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M9_7v0rlcEGmVraFf3QAAA3k"]
[Tue Jul 21 07:41:59.223119 2026] [security2:error] [pid 254995:tid 255204] [client 20.104.96.117:30864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/ctex1.php"] [unique_id "al9M9_7v0rlcEGmVraFf3wAAA20"]
[Tue Jul 21 07:41:59.380717 2026] [security2:error] [pid 254995:tid 255273] [client 20.226.60.151:54339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/bajah.php"] [unique_id "al9M9_7v0rlcEGmVraFf6AAAA5c"]
[Tue Jul 21 07:42:00.120876 2026] [core:crit] [pid 254995:tid 255058] (13)Permission denied: [remote 146.70.194.220:0] AH00529: /home1/deesmo24/public_html/cgi-bin/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/deesmo24/public_html/cgi-bin/' is executable
[Tue Jul 21 07:42:00.319427 2026] [security2:error] [pid 254995:tid 255016] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M-P7v0rlcEGmVraFgBAADSBQ"]
[Tue Jul 21 07:42:00.319878 2026] [security2:error] [pid 254995:tid 255167] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M-P7v0rlcEGmVraFgBAADSBQ"]
[Tue Jul 21 07:42:00.373582 2026] [security2:error] [pid 254995:tid 255088] [remote 188.166.248.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.248.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9M-P7v0rlcEGmVraFgCAADUFw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:42:00.380609 2026] [security2:error] [pid 254995:tid 255108] [remote 188.166.248.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.248.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9M-P7v0rlcEGmVraFgCQADInA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:42:00.385579 2026] [security2:error] [pid 254995:tid 255100] [remote 188.166.248.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.248.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9M-P7v0rlcEGmVraFgCgADI2g"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:42:00.392810 2026] [security2:error] [pid 254995:tid 255257] [client 20.151.10.161:53610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/goods.php"] [unique_id "al9M-P7v0rlcEGmVraFgCwAAA4c"]
[Tue Jul 21 07:42:00.485583 2026] [security2:error] [pid 254995:tid 255006] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M-P7v0rlcEGmVraFgEgADNAo"]
[Tue Jul 21 07:42:00.485728 2026] [security2:error] [pid 254995:tid 255147] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M-P7v0rlcEGmVraFgEgADNAo"]
[Tue Jul 21 07:42:00.718097 2026] [security2:error] [pid 254995:tid 254997] [remote 188.166.248.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.248.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9M-P7v0rlcEGmVraFgGwADeQE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:42:00.721696 2026] [security2:error] [pid 254995:tid 255229] [client 117.251.86.144:42586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9M-P7v0rlcEGmVraFgHAAAA4I"]
[Tue Jul 21 07:42:00.721831 2026] [security2:error] [pid 254995:tid 255229] [client 117.251.86.144:42586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9M-P7v0rlcEGmVraFgHAAAA4I"]
[Tue Jul 21 07:42:00.745248 2026] [security2:error] [pid 254995:tid 255092] [remote 188.166.248.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.248.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9M-P7v0rlcEGmVraFgHQADUmA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:42:00.752097 2026] [security2:error] [pid 254995:tid 255084] [remote 188.166.248.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.248.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9M-P7v0rlcEGmVraFgHgADk1g"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:42:00.806982 2026] [security2:error] [pid 254995:tid 255212] [client 20.226.60.151:54285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/a.php"] [unique_id "al9M-P7v0rlcEGmVraFgIAAAA3Q"]
[Tue Jul 21 07:42:00.866648 2026] [security2:error] [pid 254995:tid 255211] [client 20.226.60.151:59436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/class-walker-footer-dev.php"] [unique_id "al9M-P7v0rlcEGmVraFgJQAAA3M"]
[Tue Jul 21 07:42:00.952582 2026] [security2:error] [pid 254995:tid 255224] [client 122.186.204.214:54788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M-P7v0rlcEGmVraFgKQAAA4A"]
[Tue Jul 21 07:42:00.952727 2026] [security2:error] [pid 254995:tid 255224] [client 122.186.204.214:54788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M-P7v0rlcEGmVraFgKQAAA4A"]
[Tue Jul 21 07:42:01.104488 2026] [security2:error] [pid 254995:tid 255071] [remote 188.166.248.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.248.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9M-f7v0rlcEGmVraFgLwADWUs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:42:01.108314 2026] [security2:error] [pid 254995:tid 255082] [remote 188.166.248.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.248.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9M-f7v0rlcEGmVraFgMAADhFY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:42:01.371796 2026] [security2:error] [pid 254995:tid 255012] [remote 188.166.248.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.248.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9M-P7v0rlcEGmVraFgBwADKRA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:42:01.456255 2026] [security2:error] [pid 254995:tid 255089] [remote 188.166.248.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.248.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9M-f7v0rlcEGmVraFgOwADZF0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:42:01.524462 2026] [security2:error] [pid 254995:tid 255205] [client 122.164.127.47:52938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9M-f7v0rlcEGmVraFgPwAAA24"]
[Tue Jul 21 07:42:01.524561 2026] [security2:error] [pid 254995:tid 255205] [client 122.164.127.47:52938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9M-f7v0rlcEGmVraFgPwAAA24"]
[Tue Jul 21 07:42:01.543627 2026] [security2:error] [pid 254995:tid 255215] [client 20.220.225.223:5295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/inso.php"] [unique_id "al9M-f7v0rlcEGmVraFgQAAAA3c"]
[Tue Jul 21 07:42:01.605037 2026] [security2:error] [pid 254995:tid 255156] [client 182.8.255.181:21085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9M-f7v0rlcEGmVraFgQgAAAz0"]
[Tue Jul 21 07:42:01.605160 2026] [security2:error] [pid 254995:tid 255156] [client 182.8.255.181:21085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9M-f7v0rlcEGmVraFgQgAAAz0"]
[Tue Jul 21 07:42:01.707182 2026] [security2:error] [pid 254995:tid 255081] [remote 188.166.248.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.248.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9M-f7v0rlcEGmVraFgRQADlFU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:42:01.730415 2026] [security2:error] [pid 254995:tid 255167] [client 20.226.60.151:62314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/19.php"] [unique_id "al9M-f7v0rlcEGmVraFgRgAAA0g"]
[Tue Jul 21 07:42:01.747277 2026] [security2:error] [pid 254995:tid 255194] [client 20.197.195.24:44699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/cgi-bin/index.php"] [unique_id "al9M-f7v0rlcEGmVraFgSAAAA2M"]
[Tue Jul 21 07:42:02.003408 2026] [security2:error] [pid 254995:tid 255273] [client 103.86.117.203:51852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M-v7v0rlcEGmVraFgegAAA5c"]
[Tue Jul 21 07:42:02.003603 2026] [security2:error] [pid 254995:tid 255273] [client 103.86.117.203:51852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M-v7v0rlcEGmVraFgegAAA5c"]
[Tue Jul 21 07:42:02.141863 2026] [security2:error] [pid 254995:tid 255193] [client 20.104.96.117:30462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/edorxrr.php"] [unique_id "al9M-v7v0rlcEGmVraFgfwAAA2I"]
[Tue Jul 21 07:42:02.187972 2026] [security2:error] [pid 254995:tid 255189] [client 194.99.104.35:56454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9M-v7v0rlcEGmVraFggQAAA14"]
[Tue Jul 21 07:42:02.188133 2026] [security2:error] [pid 254995:tid 255189] [client 194.99.104.35:56454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9M-v7v0rlcEGmVraFggQAAA14"]
[Tue Jul 21 07:42:02.205141 2026] [security2:error] [pid 254995:tid 255143] [client 20.220.225.223:31714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/acew67.php"] [unique_id "al9M-v7v0rlcEGmVraFgggAAAzA"]
[Tue Jul 21 07:42:02.430428 2026] [security2:error] [pid 254995:tid 255160] [client 154.192.233.199:60443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M-v7v0rlcEGmVraFghQAAA0E"]
[Tue Jul 21 07:42:02.430535 2026] [security2:error] [pid 254995:tid 255160] [client 154.192.233.199:60443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M-v7v0rlcEGmVraFghQAAA0E"]
[Tue Jul 21 07:42:02.454069 2026] [security2:error] [pid 254995:tid 255219] [client 20.151.10.161:12059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ms-edit.php"] [unique_id "al9M-v7v0rlcEGmVraFgiAAAA3s"]
[Tue Jul 21 07:42:02.723614 2026] [security2:error] [pid 254995:tid 255268] [client 172.245.102.42:42811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9M-v7v0rlcEGmVraFgjgAAA5I"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:02.725369 2026] [security2:error] [pid 254995:tid 255277] [client 20.226.60.151:59415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/txets.php"] [unique_id "al9M-v7v0rlcEGmVraFglQAAA5s"]
[Tue Jul 21 07:42:03.017027 2026] [security2:error] [pid 254995:tid 255197] [client 20.226.60.151:22395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/11.php"] [unique_id "al9M-_7v0rlcEGmVraFgpAAAA2Y"]
[Tue Jul 21 07:42:03.051706 2026] [security2:error] [pid 254995:tid 255214] [client 74.7.244.30:54476] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "porondeeuestive.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9M-_7v0rlcEGmVraFgqAADdhw"]
[Tue Jul 21 07:42:03.063435 2026] [security2:error] [pid 254995:tid 255222] [client 37.140.223.156:24713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9M-_7v0rlcEGmVraFgqgAAA34"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:42:03.088623 2026] [security2:error] [pid 254995:tid 255173] [client 114.119.152.161:45375] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "insp1.com.br"] [uri "/irma-benigna/"] [unique_id "al9M-_7v0rlcEGmVraFgrAAAA04"], referer: https://www.insp1.com.br/robotica-1?lightbox=dataItem-jxz3k2ys
[Tue Jul 21 07:42:03.208994 2026] [security2:error] [pid 254995:tid 255204] [client 65.21.232.200:14243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.232.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-comments-post.php"] [unique_id "al9M-f7v0rlcEGmVraFgMQAAA20"], referer: https://valloratoodo.com/hello-world/#comment-7855
[Tue Jul 21 07:42:03.209159 2026] [security2:error] [pid 254995:tid 255204] [client 65.21.232.200:14243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "valloratoodo.com"] [uri "/wp-comments-post.php"] [unique_id "al9M-f7v0rlcEGmVraFgMQAAA20"], referer: https://valloratoodo.com/hello-world/#comment-7855
[Tue Jul 21 07:42:03.224591 2026] [security2:error] [pid 254995:tid 255185] [client 20.151.10.161:55274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/222.php"] [unique_id "al9M-_7v0rlcEGmVraFgsQAAA1o"]
[Tue Jul 21 07:42:03.420793 2026] [security2:error] [pid 254995:tid 255257] [client 20.220.225.223:22482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/bscclapb.php"] [unique_id "al9M-_7v0rlcEGmVraFgtwAAA4c"]
[Tue Jul 21 07:42:03.434122 2026] [security2:error] [pid 254995:tid 255018] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9M-_7v0rlcEGmVraFgugADYRY"]
[Tue Jul 21 07:42:03.434249 2026] [security2:error] [pid 254995:tid 255192] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9M-_7v0rlcEGmVraFgugADYRY"]
[Tue Jul 21 07:42:03.435505 2026] [core:alert] [pid 254995:tid 255130] [client 35.196.36.160:0] /home1/ofic8899/quietum-plus.tryhealth.shop/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:42:03.447712 2026] [security2:error] [pid 254995:tid 255196] [client 20.226.60.151:54370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/edit.php"] [unique_id "al9M-_7v0rlcEGmVraFgvAAAA2U"]
[Tue Jul 21 07:42:03.459909 2026] [security2:error] [pid 254995:tid 255268] [client 20.226.60.151:62240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/inc.php"] [unique_id "al9M-_7v0rlcEGmVraFgvQAAA5I"]
[Tue Jul 21 07:42:03.860225 2026] [core:alert] [pid 254995:tid 255222] [client 35.196.36.160:0] /home1/ofic8899/quietum-plus.tryhealth.shop/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:42:04.196017 2026] [security2:error] [pid 254995:tid 255260] [client 190.92.174.183:58542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_P7v0rlcEGmVraFg2wAAA4o"]
[Tue Jul 21 07:42:04.196117 2026] [security2:error] [pid 254995:tid 255260] [client 190.92.174.183:58542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_P7v0rlcEGmVraFg2wAAA4o"]
[Tue Jul 21 07:42:04.287184 2026] [core:alert] [pid 254995:tid 255266] [client 35.196.36.160:0] /home1/ofic8899/quietum-plus.tryhealth.shop/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:42:04.569487 2026] [security2:error] [pid 254995:tid 255229] [client 103.106.20.201:50836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_P7v0rlcEGmVraFg6QAAA4I"]
[Tue Jul 21 07:42:04.569613 2026] [security2:error] [pid 254995:tid 255229] [client 103.106.20.201:50836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_P7v0rlcEGmVraFg6QAAA4I"]
[Tue Jul 21 07:42:04.691825 2026] [security2:error] [pid 254995:tid 255134] [client 35.196.36.160:58380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.36.196.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "quietum-plus.tryhealth.shop"] [uri "/xmlrpc.php"] [unique_id "al9M_P7v0rlcEGmVraFg7gAAAyc"]
[Tue Jul 21 07:42:04.715783 2026] [security2:error] [pid 254995:tid 255193] [client 20.226.60.151:54390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/hosty.php"] [unique_id "al9M_P7v0rlcEGmVraFg8AAAA2I"]
[Tue Jul 21 07:42:04.719097 2026] [security2:error] [pid 254995:tid 255217] [client 122.162.144.145:21954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9M_P7v0rlcEGmVraFg8QAAA3k"]
[Tue Jul 21 07:42:04.719220 2026] [security2:error] [pid 254995:tid 255217] [client 122.162.144.145:21954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9M_P7v0rlcEGmVraFg8QAAA3k"]
[Tue Jul 21 07:42:04.822675 2026] [security2:error] [pid 254995:tid 255224] [client 117.217.38.194:64690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_P7v0rlcEGmVraFg9gAAA4A"]
[Tue Jul 21 07:42:04.822827 2026] [security2:error] [pid 254995:tid 255224] [client 117.217.38.194:64690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_P7v0rlcEGmVraFg9gAAA4A"]
[Tue Jul 21 07:42:04.847558 2026] [security2:error] [pid 254995:tid 255212] [client 184.75.223.211:34920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9M_P7v0rlcEGmVraFg9wAAA3Q"]
[Tue Jul 21 07:42:04.847679 2026] [security2:error] [pid 254995:tid 255212] [client 184.75.223.211:34920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9M_P7v0rlcEGmVraFg9wAAA3Q"]
[Tue Jul 21 07:42:04.952014 2026] [security2:error] [pid 254995:tid 255162] [client 35.196.36.160:64347] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quietum-plus.tryhealth.shop"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9M_P7v0rlcEGmVraFg-QAAA0M"]
[Tue Jul 21 07:42:05.048749 2026] [security2:error] [pid 254995:tid 255252] [client 20.151.10.161:55277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9M_f7v0rlcEGmVraFg-wAAA4M"]
[Tue Jul 21 07:42:05.164619 2026] [security2:error] [pid 254995:tid 255222] [client 190.92.174.183:58544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_f7v0rlcEGmVraFhAwAAA34"]
[Tue Jul 21 07:42:05.164770 2026] [security2:error] [pid 254995:tid 255222] [client 190.92.174.183:58544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_f7v0rlcEGmVraFhAwAAA34"]
[Tue Jul 21 07:42:05.205133 2026] [security2:error] [pid 254995:tid 255257] [client 35.196.36.160:54319] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quietum-plus.tryhealth.shop"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9M_f7v0rlcEGmVraFhBQAAA4c"]
[Tue Jul 21 07:42:05.370193 2026] [security2:error] [pid 254995:tid 255270] [client 20.220.225.223:11162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/wpx.php"] [unique_id "al9M_f7v0rlcEGmVraFhCAAAA5Q"]
[Tue Jul 21 07:42:05.381808 2026] [security2:error] [pid 254995:tid 255254] [client 20.226.60.151:62296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9M_f7v0rlcEGmVraFhCQAAA4Q"]
[Tue Jul 21 07:42:05.428052 2026] [security2:error] [pid 254995:tid 255142] [client 20.226.60.151:56239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/sid4.php"] [unique_id "al9M_f7v0rlcEGmVraFhCgAAAy8"]
[Tue Jul 21 07:42:05.484898 2026] [security2:error] [pid 254995:tid 255181] [client 20.226.60.151:59495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/dex.php"] [unique_id "al9M_f7v0rlcEGmVraFhDAAAA1Y"]
[Tue Jul 21 07:42:05.514366 2026] [security2:error] [pid 254995:tid 255166] [client 35.196.36.160:49223] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quietum-plus.tryhealth.shop"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9M_f7v0rlcEGmVraFhDQAAA0c"]
[Tue Jul 21 07:42:05.785013 2026] [security2:error] [pid 254995:tid 255202] [client 35.196.36.160:61752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quietum-plus.tryhealth.shop"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9M_f7v0rlcEGmVraFhGQAAA2s"]
[Tue Jul 21 07:42:06.043660 2026] [security2:error] [pid 254995:tid 255142] [client 35.196.36.160:64192] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quietum-plus.tryhealth.shop"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9M_v7v0rlcEGmVraFhIwAAAy8"]
[Tue Jul 21 07:42:06.064910 2026] [security2:error] [pid 254995:tid 255184] [client 20.226.60.151:54397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/k.php"] [unique_id "al9M_v7v0rlcEGmVraFhJAAAA1k"]
[Tue Jul 21 07:42:06.103559 2026] [security2:error] [pid 254995:tid 255229] [client 20.226.60.151:22659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/v2.php"] [unique_id "al9M_v7v0rlcEGmVraFhJQAAA4I"]
[Tue Jul 21 07:42:06.320846 2026] [security2:error] [pid 254995:tid 255147] [client 139.167.225.182:64358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_v7v0rlcEGmVraFhNgAAAzQ"]
[Tue Jul 21 07:42:06.320942 2026] [security2:error] [pid 254995:tid 255147] [client 139.167.225.182:64358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_v7v0rlcEGmVraFhNgAAAzQ"]
[Tue Jul 21 07:42:06.411976 2026] [security2:error] [pid 254995:tid 255138] [client 35.196.36.160:51087] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quietum-plus.tryhealth.shop"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9M_v7v0rlcEGmVraFhOwAAAys"]
[Tue Jul 21 07:42:06.446108 2026] [security2:error] [pid 254995:tid 255188] [client 136.144.33.111:43109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9M_v7v0rlcEGmVraFhPAAAA10"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:06.615440 2026] [security2:error] [pid 254995:tid 255075] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_v7v0rlcEGmVraFhPgADa08"]
[Tue Jul 21 07:42:06.615625 2026] [security2:error] [pid 254995:tid 255202] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_v7v0rlcEGmVraFhPgADa08"]
[Tue Jul 21 07:42:06.654648 2026] [security2:error] [pid 254995:tid 255033] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M_v7v0rlcEGmVraFhPwADYSU"]
[Tue Jul 21 07:42:06.654780 2026] [security2:error] [pid 254995:tid 255192] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M_v7v0rlcEGmVraFhPwADYSU"]
[Tue Jul 21 07:42:06.655306 2026] [security2:error] [pid 254995:tid 255209] [client 20.226.60.151:62262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9M_v7v0rlcEGmVraFhQAAAA3E"]
[Tue Jul 21 07:42:06.662879 2026] [security2:error] [pid 254995:tid 255125] [client 59.96.220.140:56296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9M_v7v0rlcEGmVraFhQgAAAx4"]
[Tue Jul 21 07:42:06.662960 2026] [security2:error] [pid 254995:tid 255125] [client 59.96.220.140:56296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9M_v7v0rlcEGmVraFhQgAAAx4"]
[Tue Jul 21 07:42:06.698455 2026] [security2:error] [pid 254995:tid 255181] [client 35.196.36.160:55733] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quietum-plus.tryhealth.shop"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9M_v7v0rlcEGmVraFhRwAAA1Y"]
[Tue Jul 21 07:42:06.808575 2026] [security2:error] [pid 254995:tid 255126] [client 190.92.174.183:58558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "al9M_v7v0rlcEGmVraFhUgAAAx8"]
[Tue Jul 21 07:42:06.808668 2026] [security2:error] [pid 254995:tid 255126] [client 190.92.174.183:58558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "al9M_v7v0rlcEGmVraFhUgAAAx8"]
[Tue Jul 21 07:42:07.006722 2026] [security2:error] [pid 254995:tid 255154] [client 35.196.36.160:49307] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quietum-plus.tryhealth.shop"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9M__7v0rlcEGmVraFhWwAAAzs"]
[Tue Jul 21 07:42:07.264866 2026] [security2:error] [pid 254995:tid 255279] [client 35.196.36.160:63065] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quietum-plus.tryhealth.shop"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9M__7v0rlcEGmVraFhaAAAA50"]
[Tue Jul 21 07:42:07.353936 2026] [security2:error] [pid 254995:tid 255127] [client 20.151.10.161:53584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9M__7v0rlcEGmVraFhawAAAyA"]
[Tue Jul 21 07:42:07.460053 2026] [security2:error] [pid 254995:tid 255166] [client 20.226.60.151:54385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/aaa.php"] [unique_id "al9M__7v0rlcEGmVraFhbgAAA0c"]
[Tue Jul 21 07:42:07.508677 2026] [security2:error] [pid 254995:tid 255169] [client 20.104.96.117:30417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/miru1.php"] [unique_id "al9M__7v0rlcEGmVraFhcAAAA0o"]
[Tue Jul 21 07:42:07.511787 2026] [security2:error] [pid 254995:tid 255152] [client 35.196.36.160:53347] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quietum-plus.tryhealth.shop"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9M__7v0rlcEGmVraFhcQAAAzk"]
[Tue Jul 21 07:42:07.765165 2026] [security2:error] [pid 254995:tid 255220] [client 20.226.60.151:22960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/panel.php"] [unique_id "al9M__7v0rlcEGmVraFhgAAAA3w"]
[Tue Jul 21 07:42:07.802946 2026] [security2:error] [pid 254995:tid 255194] [client 35.196.36.160:63296] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quietum-plus.tryhealth.shop"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9M__7v0rlcEGmVraFhgwAAA2M"]
[Tue Jul 21 07:42:07.966724 2026] [security2:error] [pid 254995:tid 255199] [client 190.92.174.183:58566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "al9M__7v0rlcEGmVraFhiAAAA2g"]
[Tue Jul 21 07:42:07.966833 2026] [security2:error] [pid 254995:tid 255199] [client 190.92.174.183:58566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "al9M__7v0rlcEGmVraFhiAAAA2g"]
[Tue Jul 21 07:42:07.982088 2026] [security2:error] [pid 254995:tid 255156] [client 122.179.91.63:27808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9M__7v0rlcEGmVraFhiQAAAz0"]
[Tue Jul 21 07:42:07.982299 2026] [security2:error] [pid 254995:tid 255156] [client 122.179.91.63:27808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9M__7v0rlcEGmVraFhiQAAAz0"]
[Tue Jul 21 07:42:08.272559 2026] [security2:error] [pid 254995:tid 255192] [client 173.24.185.52:54100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NAP7v0rlcEGmVraFhvAAAA2E"]
[Tue Jul 21 07:42:08.272675 2026] [security2:error] [pid 254995:tid 255192] [client 173.24.185.52:54100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NAP7v0rlcEGmVraFhvAAAA2E"]
[Tue Jul 21 07:42:08.401877 2026] [security2:error] [pid 254995:tid 255220] [client 20.226.60.151:62279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/ss.php"] [unique_id "al9NAP7v0rlcEGmVraFh0AAAA3w"]
[Tue Jul 21 07:42:08.478318 2026] [security2:error] [pid 254995:tid 255229] [client 37.140.223.118:60221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9M__7v0rlcEGmVraFhbwAAA4I"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:42:08.597426 2026] [security2:error] [pid 254995:tid 255140] [client 202.143.127.214:49679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NAP7v0rlcEGmVraFh1gAAAy0"]
[Tue Jul 21 07:42:08.597570 2026] [security2:error] [pid 254995:tid 255140] [client 202.143.127.214:49679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NAP7v0rlcEGmVraFh1gAAAy0"]
[Tue Jul 21 07:42:08.665837 2026] [autoindex:error] [pid 254995:tid 255129] [client 20.197.195.24:44709] AH01276: Cannot serve directory /home2/ren85318/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:08.675443 2026] [security2:error] [pid 254995:tid 255274] [client 20.197.195.24:44709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/BDKR28WP.php"] [unique_id "al9NAP7v0rlcEGmVraFh2AAAA5g"]
[Tue Jul 21 07:42:08.807141 2026] [security2:error] [pid 254995:tid 255200] [client 103.174.34.15:55174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NAP7v0rlcEGmVraFh4gAAA2k"]
[Tue Jul 21 07:42:08.807253 2026] [security2:error] [pid 254995:tid 255200] [client 103.174.34.15:55174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NAP7v0rlcEGmVraFh4gAAA2k"]
[Tue Jul 21 07:42:09.076994 2026] [security2:error] [pid 254995:tid 255153] [client 190.92.174.183:58576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "al9NAf7v0rlcEGmVraFh6gAAAzo"]
[Tue Jul 21 07:42:09.077110 2026] [security2:error] [pid 254995:tid 255153] [client 190.92.174.183:58576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "al9NAf7v0rlcEGmVraFh6gAAAzo"]
[Tue Jul 21 07:42:09.115491 2026] [security2:error] [pid 254995:tid 255183] [client 20.226.60.151:59508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/xpwer1.php"] [unique_id "al9NAf7v0rlcEGmVraFh7QAAA1g"]
[Tue Jul 21 07:42:09.126968 2026] [autoindex:error] [pid 254995:tid 255277] [client 20.226.60.151:0] AH01276: Cannot serve directory /home3/vivia357/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:09.137319 2026] [security2:error] [pid 254995:tid 255143] [client 20.226.60.151:56299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wmore1.php"] [unique_id "al9NAf7v0rlcEGmVraFh8AAAAzA"]
[Tue Jul 21 07:42:09.412745 2026] [security2:error] [pid 254995:tid 255146] [client 20.226.60.151:22352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/dex.php"] [unique_id "al9NAf7v0rlcEGmVraFh_gAAAzM"]
[Tue Jul 21 07:42:09.659868 2026] [security2:error] [pid 254995:tid 255129] [client 20.226.60.151:54318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/file5.php"] [unique_id "al9NAf7v0rlcEGmVraFiAQAAAyI"]
[Tue Jul 21 07:42:09.751252 2026] [autoindex:error] [pid 254995:tid 255202] [client 172.252.54.73:0] AH01276: Cannot serve directory /home2/inlaud99/distribuidorasja.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:09.796422 2026] [security2:error] [pid 254995:tid 255192] [client 106.215.181.8:5840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NAf7v0rlcEGmVraFiDwAAA2E"]
[Tue Jul 21 07:42:09.796530 2026] [security2:error] [pid 254995:tid 255192] [client 106.215.181.8:5840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NAf7v0rlcEGmVraFiDwAAA2E"]
[Tue Jul 21 07:42:10.021425 2026] [security2:error] [pid 254995:tid 255199] [client 190.92.174.183:58586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/site/xmlrpc.php"] [unique_id "al9NAv7v0rlcEGmVraFiGgAAA2g"]
[Tue Jul 21 07:42:10.021525 2026] [security2:error] [pid 254995:tid 255199] [client 190.92.174.183:58586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/site/xmlrpc.php"] [unique_id "al9NAv7v0rlcEGmVraFiGgAAA2g"]
[Tue Jul 21 07:42:10.289567 2026] [security2:error] [pid 254995:tid 255179] [client 20.151.10.161:11721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp.php"] [unique_id "al9NAv7v0rlcEGmVraFiHQAAA1Q"]
[Tue Jul 21 07:42:10.298572 2026] [security2:error] [pid 254995:tid 255252] [client 152.59.154.239:53422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NAv7v0rlcEGmVraFiHgAAA4M"]
[Tue Jul 21 07:42:10.298691 2026] [security2:error] [pid 254995:tid 255252] [client 152.59.154.239:53422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NAv7v0rlcEGmVraFiHgAAA4M"]
[Tue Jul 21 07:42:10.384857 2026] [security2:error] [pid 254995:tid 255042] [remote 5.252.52.249:52402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aprendizadosemlimites.store"] [uri "/wp-login.php"] [unique_id "al9NAv7v0rlcEGmVraFiKAADPC4"]
[Tue Jul 21 07:42:10.566827 2026] [autoindex:error] [pid 254995:tid 255139] [client 20.197.195.24:44711] AH01276: Cannot serve directory /home2/ren85318/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:10.584685 2026] [authz_core:error] [pid 254995:tid 255156] [client 20.197.195.24:44711] AH01630: client denied by server configuration: /home2/ren85318/public_html/wp-content/uploads/index.php
[Tue Jul 21 07:42:10.593475 2026] [security2:error] [pid 254995:tid 255222] [client 20.197.195.24:44711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/abcd.php"] [unique_id "al9NAv7v0rlcEGmVraFiOwAAA34"]
[Tue Jul 21 07:42:10.825091 2026] [security2:error] [pid 254995:tid 255162] [client 20.226.60.151:62254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/min.php"] [unique_id "al9NAv7v0rlcEGmVraFiQgAAA0M"]
[Tue Jul 21 07:42:10.862659 2026] [security2:error] [pid 254995:tid 255211] [client 20.226.60.151:56212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/solo1.php"] [unique_id "al9NAv7v0rlcEGmVraFiRAAAA3M"]
[Tue Jul 21 07:42:10.883248 2026] [security2:error] [pid 254995:tid 255164] [client 74.7.228.51:53206] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "guiapleno.com"] [uri "/robots.txt"] [unique_id "al9NAv7v0rlcEGmVraFiRQADRXQ"]
[Tue Jul 21 07:42:10.918764 2026] [security2:error] [pid 254995:tid 255277] [client 128.127.105.184:47210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9NAf7v0rlcEGmVraFiFgAAA5s"]
[Tue Jul 21 07:42:10.918872 2026] [security2:error] [pid 254995:tid 255277] [client 128.127.105.184:47210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9NAf7v0rlcEGmVraFiFgAAA5s"]
[Tue Jul 21 07:42:10.937543 2026] [security2:error] [pid 254995:tid 255117] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NAv7v0rlcEGmVraFiTAADZHk"]
[Tue Jul 21 07:42:10.937693 2026] [security2:error] [pid 254995:tid 255195] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NAv7v0rlcEGmVraFiTAADZHk"]
[Tue Jul 21 07:42:10.984741 2026] [security2:error] [pid 254995:tid 255202] [client 62.102.148.187:35308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9NAv7v0rlcEGmVraFiUAAAA2s"]
[Tue Jul 21 07:42:10.984839 2026] [security2:error] [pid 254995:tid 255202] [client 62.102.148.187:35308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9NAv7v0rlcEGmVraFiUAAAA2s"]
[Tue Jul 21 07:42:11.048539 2026] [security2:error] [pid 254995:tid 255104] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NA_7v0rlcEGmVraFiUwADaGw"]
[Tue Jul 21 07:42:11.048719 2026] [security2:error] [pid 254995:tid 255199] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NA_7v0rlcEGmVraFiUwADaGw"]
[Tue Jul 21 07:42:11.054609 2026] [security2:error] [pid 254995:tid 255171] [client 74.7.228.51:53206] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "guiapleno.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al9NA_7v0rlcEGmVraFiUgADTF0"], referer: https://guiapleno.com/robots.txt
[Tue Jul 21 07:42:11.108394 2026] [security2:error] [pid 254995:tid 255149] [client 45.146.55.214:22203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.55.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lumerah.com.br"] [uri "/wp-login.php"] [unique_id "al9NA_7v0rlcEGmVraFiVgAAAzY"]
[Tue Jul 21 07:42:11.114010 2026] [security2:error] [pid 254995:tid 255143] [client 190.92.174.183:58590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/web/xmlrpc.php"] [unique_id "al9NA_7v0rlcEGmVraFiVwAAAzA"]
[Tue Jul 21 07:42:11.114122 2026] [security2:error] [pid 254995:tid 255143] [client 190.92.174.183:58590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/web/xmlrpc.php"] [unique_id "al9NA_7v0rlcEGmVraFiVwAAAzA"]
[Tue Jul 21 07:42:11.160946 2026] [security2:error] [pid 254995:tid 255260] [client 20.226.60.151:22391] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cavilhaslufra.com.br"] [uri "/1.php"] [unique_id "al9NA_7v0rlcEGmVraFiWQAAA4o"]
[Tue Jul 21 07:42:11.161055 2026] [security2:error] [pid 254995:tid 255260] [client 20.226.60.151:22391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/1.php"] [unique_id "al9NA_7v0rlcEGmVraFiWQAAA4o"]
[Tue Jul 21 07:42:11.307080 2026] [security2:error] [pid 254995:tid 255131] [client 20.104.96.117:30461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/sump1.php"] [unique_id "al9NA_7v0rlcEGmVraFiXAAAAyQ"]
[Tue Jul 21 07:42:11.330839 2026] [security2:error] [pid 254995:tid 255200] [client 136.144.33.111:40471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NA_7v0rlcEGmVraFiXQAAA2k"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:11.384267 2026] [security2:error] [pid 254995:tid 255142] [client 20.226.60.151:54380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/222.php"] [unique_id "al9NA_7v0rlcEGmVraFiYAAAAy8"]
[Tue Jul 21 07:42:11.475231 2026] [security2:error] [pid 254995:tid 255275] [client 117.251.86.144:49054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NA_7v0rlcEGmVraFiawAAA5k"]
[Tue Jul 21 07:42:11.475324 2026] [security2:error] [pid 254995:tid 255275] [client 117.251.86.144:49054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NA_7v0rlcEGmVraFiawAAA5k"]
[Tue Jul 21 07:42:11.620539 2026] [security2:error] [pid 254995:tid 255229] [client 20.151.10.161:12095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/abcd.php"] [unique_id "al9NA_7v0rlcEGmVraFicAAAA4I"]
[Tue Jul 21 07:42:11.621822 2026] [security2:error] [pid 254995:tid 255184] [client 122.186.204.214:55320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NA_7v0rlcEGmVraFicQAAA1k"]
[Tue Jul 21 07:42:11.621939 2026] [security2:error] [pid 254995:tid 255184] [client 122.186.204.214:55320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NA_7v0rlcEGmVraFicQAAA1k"]
[Tue Jul 21 07:42:12.011617 2026] [security2:error] [pid 254995:tid 255214] [client 182.8.255.181:21220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NBP7v0rlcEGmVraFigAAAA3Y"]
[Tue Jul 21 07:42:12.011718 2026] [security2:error] [pid 254995:tid 255214] [client 182.8.255.181:21220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NBP7v0rlcEGmVraFigAAAA3Y"]
[Tue Jul 21 07:42:12.061955 2026] [security2:error] [pid 254995:tid 255252] [client 190.92.174.183:58594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/main/xmlrpc.php"] [unique_id "al9NBP7v0rlcEGmVraFigwAAA4M"]
[Tue Jul 21 07:42:12.062061 2026] [security2:error] [pid 254995:tid 255252] [client 190.92.174.183:58594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/main/xmlrpc.php"] [unique_id "al9NBP7v0rlcEGmVraFigwAAA4M"]
[Tue Jul 21 07:42:12.098178 2026] [security2:error] [pid 254995:tid 255258] [client 122.164.127.47:53497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NBP7v0rlcEGmVraFihgAAA4g"]
[Tue Jul 21 07:42:12.098293 2026] [security2:error] [pid 254995:tid 255258] [client 122.164.127.47:53497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NBP7v0rlcEGmVraFihgAAA4g"]
[Tue Jul 21 07:42:12.159900 2026] [security2:error] [pid 254995:tid 255162] [client 20.226.60.151:50917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/flox.php"] [unique_id "al9NBP7v0rlcEGmVraFihwAAA0M"]
[Tue Jul 21 07:42:12.197972 2026] [security2:error] [pid 254995:tid 255218] [client 74.7.175.148:45646] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.resultados.liranesuliano.com.br"] [uri "/index.php"] [unique_id "al9NA_7v0rlcEGmVraFicwADenw"]
[Tue Jul 21 07:42:12.253227 2026] [security2:error] [pid 254995:tid 255129] [client 20.197.195.24:44720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/file15.php"] [unique_id "al9NBP7v0rlcEGmVraFiiwAAAyI"]
[Tue Jul 21 07:42:12.494201 2026] [security2:error] [pid 254995:tid 255199] [client 103.86.117.203:52388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NBP7v0rlcEGmVraFilgAAA2g"]
[Tue Jul 21 07:42:12.494375 2026] [security2:error] [pid 254995:tid 255199] [client 103.86.117.203:52388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NBP7v0rlcEGmVraFilgAAA2g"]
[Tue Jul 21 07:42:12.582382 2026] [security2:error] [pid 254995:tid 255200] [client 20.226.60.151:62220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9NBP7v0rlcEGmVraFinQAAA2k"]
[Tue Jul 21 07:42:12.699382 2026] [security2:error] [pid 254995:tid 255138] [client 20.220.225.223:34249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9NBP7v0rlcEGmVraFioAAAAys"]
[Tue Jul 21 07:42:12.704422 2026] [security2:error] [pid 254995:tid 255222] [client 20.220.225.223:11169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/berlin.php"] [unique_id "al9NBP7v0rlcEGmVraFioQAAA34"]
[Tue Jul 21 07:42:12.845829 2026] [security2:error] [pid 254995:tid 255162] [client 20.104.96.117:30459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/file5.php"] [unique_id "al9NBP7v0rlcEGmVraFipQAAA0M"]
[Tue Jul 21 07:42:12.859021 2026] [security2:error] [pid 254995:tid 255272] [client 74.7.175.148:45662] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "resultados.liranesuliano.com.br"] [uri "/index.php"] [unique_id "al9NBP7v0rlcEGmVraFiogADlgU"], referer: https://www.resultados.liranesuliano.com.br/robots.txt
[Tue Jul 21 07:42:12.910999 2026] [security2:error] [pid 254995:tid 255277] [client 20.226.60.151:54287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/test.php"] [unique_id "al9NBP7v0rlcEGmVraFiqwAAA5s"]
[Tue Jul 21 07:42:13.031819 2026] [autoindex:error] [pid 254995:tid 255205] [client 20.226.60.151:0] AH01276: Cannot serve directory /home3/vivia357/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:13.035655 2026] [security2:error] [pid 254995:tid 255163] [client 74.7.244.14:58852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "resultados.liranesuliano.com.br"] [uri "/index.php"] [unique_id "al9NBP7v0rlcEGmVraFirQADRG8"]
[Tue Jul 21 07:42:13.054159 2026] [security2:error] [pid 254995:tid 255212] [client 20.226.60.151:51217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/cong.php"] [unique_id "al9NBf7v0rlcEGmVraFisQAAA3Q"]
[Tue Jul 21 07:42:13.155532 2026] [security2:error] [pid 254995:tid 255131] [client 190.92.174.183:42548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/cms/xmlrpc.php"] [unique_id "al9NBf7v0rlcEGmVraFitQAAAyQ"]
[Tue Jul 21 07:42:13.155625 2026] [security2:error] [pid 254995:tid 255131] [client 190.92.174.183:42548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/cms/xmlrpc.php"] [unique_id "al9NBf7v0rlcEGmVraFitQAAAyQ"]
[Tue Jul 21 07:42:13.198852 2026] [security2:error] [pid 254995:tid 255169] [client 74.7.230.0:40388] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.visagismo2.0.oficialwebsite.com.br"] [uri "/index.php"] [unique_id "al9NBP7v0rlcEGmVraFiowADSiw"]
[Tue Jul 21 07:42:13.199027 2026] [security2:error] [pid 254995:tid 255149] [client 154.192.233.199:59611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NBf7v0rlcEGmVraFiuAAAAzY"]
[Tue Jul 21 07:42:13.199121 2026] [security2:error] [pid 254995:tid 255149] [client 154.192.233.199:59611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NBf7v0rlcEGmVraFiuAAAAzY"]
[Tue Jul 21 07:42:13.212252 2026] [security2:error] [pid 254995:tid 255199] [client 20.220.225.223:19675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/wpx.php"] [unique_id "al9NBf7v0rlcEGmVraFiuQAAA2g"]
[Tue Jul 21 07:42:13.317243 2026] [security2:error] [pid 254995:tid 255257] [client 20.226.60.151:22946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/ms.php"] [unique_id "al9NBf7v0rlcEGmVraFiwgAAA4c"]
[Tue Jul 21 07:42:13.423720 2026] [security2:error] [pid 254995:tid 255171] [client 20.151.10.161:12076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/a1.php"] [unique_id "al9NBf7v0rlcEGmVraFixwAAA0w"]
[Tue Jul 21 07:42:13.660032 2026] [security2:error] [pid 254995:tid 255156] [client 74.7.230.32:46332] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "visagismo2.0.oficialwebsite.com.br"] [uri "/index.php"] [unique_id "al9NBf7v0rlcEGmVraFiuwADPSM"]
[Tue Jul 21 07:42:13.927956 2026] [security2:error] [pid 254995:tid 255110] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NBf7v0rlcEGmVraFi2QADgnI"]
[Tue Jul 21 07:42:13.928111 2026] [security2:error] [pid 254995:tid 255229] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NBf7v0rlcEGmVraFi2QADgnI"]
[Tue Jul 21 07:42:14.153659 2026] [security2:error] [pid 254995:tid 255197] [client 20.197.195.24:44766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/jp.php"] [unique_id "al9NBv7v0rlcEGmVraFi4QAAA2Y"]
[Tue Jul 21 07:42:14.199994 2026] [security2:error] [pid 254995:tid 255174] [client 20.220.225.223:22499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/else1.php"] [unique_id "al9NBv7v0rlcEGmVraFi4gAAA08"]
[Tue Jul 21 07:42:14.255256 2026] [security2:error] [pid 254995:tid 255157] [client 190.92.174.183:42574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/wpsite/xmlrpc.php"] [unique_id "al9NBv7v0rlcEGmVraFi5AAAAz4"]
[Tue Jul 21 07:42:14.255392 2026] [security2:error] [pid 254995:tid 255157] [client 190.92.174.183:42574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/wpsite/xmlrpc.php"] [unique_id "al9NBv7v0rlcEGmVraFi5AAAAz4"]
[Tue Jul 21 07:42:14.292526 2026] [security2:error] [pid 254995:tid 255127] [client 74.7.230.0:40402] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "visagismo2.0.oficialwebsite.com.br"] [uri "/index.php"] [unique_id "al9NBf7v0rlcEGmVraFi2gADIEE"], referer: https://www.visagismo2.0.oficialwebsite.com.br/robots.txt
[Tue Jul 21 07:42:14.521289 2026] [security2:error] [pid 254995:tid 255130] [client 20.104.96.117:30426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/0xD.php"] [unique_id "al9NBv7v0rlcEGmVraFi7QAAAyM"]
[Tue Jul 21 07:42:14.760603 2026] [security2:error] [pid 254995:tid 255218] [client 20.151.10.161:53613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9NBv7v0rlcEGmVraFi9gAAA3o"]
[Tue Jul 21 07:42:14.793781 2026] [security2:error] [pid 254995:tid 255203] [client 20.226.60.151:33523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9NBv7v0rlcEGmVraFi9wAAA2w"]
[Tue Jul 21 07:42:15.020317 2026] [security2:error] [pid 254995:tid 255133] [client 128.127.105.184:47212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjBAAAAyY"]
[Tue Jul 21 07:42:15.020415 2026] [security2:error] [pid 254995:tid 255133] [client 128.127.105.184:47212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjBAAAAyY"]
[Tue Jul 21 07:42:15.279425 2026] [security2:error] [pid 254995:tid 255143] [client 117.217.38.194:65167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjDwAAAzA"]
[Tue Jul 21 07:42:15.279550 2026] [security2:error] [pid 254995:tid 255143] [client 117.217.38.194:65167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjDwAAAzA"]
[Tue Jul 21 07:42:15.282672 2026] [security2:error] [pid 254995:tid 255162] [client 103.106.20.201:51413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjEAAAA0M"]
[Tue Jul 21 07:42:15.282776 2026] [security2:error] [pid 254995:tid 255162] [client 103.106.20.201:51413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjEAAAA0M"]
[Tue Jul 21 07:42:15.349492 2026] [security2:error] [pid 254995:tid 255229] [client 190.92.174.183:42576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/old/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjEwAAA4I"]
[Tue Jul 21 07:42:15.349588 2026] [security2:error] [pid 254995:tid 255229] [client 190.92.174.183:42576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/old/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjEwAAA4I"]
[Tue Jul 21 07:42:15.455275 2026] [security2:error] [pid 254995:tid 255257] [client 194.99.104.35:40758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjFAAAA4c"]
[Tue Jul 21 07:42:15.455372 2026] [security2:error] [pid 254995:tid 255257] [client 194.99.104.35:40758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjFAAAA4c"]
[Tue Jul 21 07:42:15.627074 2026] [security2:error] [pid 254995:tid 255166] [client 59.96.220.140:56791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjHgAAA0c"]
[Tue Jul 21 07:42:15.627199 2026] [security2:error] [pid 254995:tid 255166] [client 59.96.220.140:56791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjHgAAA0c"]
[Tue Jul 21 07:42:15.645652 2026] [security2:error] [pid 254995:tid 255275] [client 122.162.144.145:18499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjHwAAA5k"]
[Tue Jul 21 07:42:15.645830 2026] [security2:error] [pid 254995:tid 255275] [client 122.162.144.145:18499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjHwAAA5k"]
[Tue Jul 21 07:42:15.683805 2026] [security2:error] [pid 254995:tid 255266] [client 136.144.33.103:28621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NB_7v0rlcEGmVraFjFwAAA5A"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:15.696933 2026] [http2:info] [pid 296703:tid 296703] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 07:42:15.771911 2026] [security2:error] [pid 254995:tid 255164] [client 20.220.225.223:31720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/tkikikoko.php"] [unique_id "al9NB_7v0rlcEGmVraFjJQAAA0U"]
[Tue Jul 21 07:42:15.773489 2026] [security2:error] [pid 254995:tid 255213] [client 20.151.10.161:12056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9NB_7v0rlcEGmVraFjJgAAA3U"]
[Tue Jul 21 07:42:15.953882 2026] [security2:error] [pid 254995:tid 255179] [client 20.197.195.24:44789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/f35.php"] [unique_id "al9NB_7v0rlcEGmVraFjKgAAA1Q"]
[Tue Jul 21 07:42:16.286653 2026] [security2:error] [pid 254995:tid 255088] [remote 74.7.242.41:34054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "visagismo2.0.oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NCP7v0rlcEGmVraFjLQADPlw"], referer: https://visagismo2.0.oficialwebsite.com.br/
[Tue Jul 21 07:42:16.297347 2026] [security2:error] [pid 254995:tid 255197] [client 190.92.174.183:42578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/new/xmlrpc.php"] [unique_id "al9NCP7v0rlcEGmVraFjNQAAA2Y"]
[Tue Jul 21 07:42:16.297453 2026] [security2:error] [pid 254995:tid 255197] [client 190.92.174.183:42578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/new/xmlrpc.php"] [unique_id "al9NCP7v0rlcEGmVraFjNQAAA2Y"]
[Tue Jul 21 07:42:16.334130 2026] [security2:error] [pid 296703:tid 296837] [client 198.204.224.34:52612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wp-includes/adc37af5/edit.php"] [unique_id "al9NCCn25uliftkV1n75yQAAAAQ"], referer: https://aumentodevendas.factorial.studio/wp-includes/adc37af5/edit.php
[Tue Jul 21 07:42:16.339050 2026] [security2:error] [pid 296703:tid 296840] [client 20.226.60.151:54396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/aaa.php"] [unique_id "al9NCCn25uliftkV1n75ygAAAAc"]
[Tue Jul 21 07:42:16.448959 2026] [security2:error] [pid 296703:tid 296842] [client 194.99.104.35:56946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9NCCn25uliftkV1n75zAAAAAk"]
[Tue Jul 21 07:42:16.449089 2026] [security2:error] [pid 296703:tid 296842] [client 194.99.104.35:56946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9NCCn25uliftkV1n75zAAAAAk"]
[Tue Jul 21 07:42:16.459848 2026] [security2:error] [pid 254995:tid 255277] [client 20.226.60.151:59454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/popo.php"] [unique_id "al9NCP7v0rlcEGmVraFjOQAAA5s"]
[Tue Jul 21 07:42:16.561626 2026] [autoindex:error] [pid 296703:tid 296848] [client 20.226.60.151:0] AH01276: Cannot serve directory /home3/vivia357/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:16.594276 2026] [security2:error] [pid 296703:tid 296852] [client 20.226.60.151:51216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/public/css.php"] [unique_id "al9NCCn25uliftkV1n750AAAABM"]
[Tue Jul 21 07:42:16.598478 2026] [security2:error] [pid 296703:tid 296853] [client 20.151.10.161:11758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/gettest.php"] [unique_id "al9NCCn25uliftkV1n750QAAABQ"]
[Tue Jul 21 07:42:16.723697 2026] [security2:error] [pid 254995:tid 255152] [client 20.104.96.117:30862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/fnstall.php"] [unique_id "al9NCP7v0rlcEGmVraFjRQAAAzk"]
[Tue Jul 21 07:42:17.016698 2026] [security2:error] [pid 296703:tid 296866] [client 20.197.195.24:44767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/wp-load.php"] [unique_id "al9NCSn25uliftkV1n754AAAACE"]
[Tue Jul 21 07:42:17.099612 2026] [security2:error] [pid 296703:tid 296870] [client 20.220.225.223:34294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9NCSn25uliftkV1n754QAAACU"]
[Tue Jul 21 07:42:17.123297 2026] [security2:error] [pid 254995:tid 255074] [remote 217.182.128.41:48986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "financasparaempreendedoras.com"] [uri "/wp-login.php"] [unique_id "al9NCf7v0rlcEGmVraFjTAADJU4"]
[Tue Jul 21 07:42:17.293623 2026] [security2:error] [pid 296703:tid 296715] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NCSn25uliftkV1n755QAAIAs"]
[Tue Jul 21 07:42:17.293824 2026] [security2:error] [pid 296703:tid 296865] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NCSn25uliftkV1n755QAAIAs"]
[Tue Jul 21 07:42:17.308049 2026] [security2:error] [pid 296703:tid 296880] [client 20.151.10.161:55295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/simple.php"] [unique_id "al9NCSn25uliftkV1n755wAAAC8"]
[Tue Jul 21 07:42:17.383895 2026] [security2:error] [pid 254995:tid 255120] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NCf7v0rlcEGmVraFjVgADO3w"]
[Tue Jul 21 07:42:17.384086 2026] [security2:error] [pid 254995:tid 255154] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NCf7v0rlcEGmVraFjVgADO3w"]
[Tue Jul 21 07:42:17.396195 2026] [security2:error] [pid 296703:tid 296883] [client 20.220.225.223:11152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/billur.php"] [unique_id "al9NCSn25uliftkV1n757AAAADI"]
[Tue Jul 21 07:42:17.448574 2026] [security2:error] [pid 254995:tid 255153] [client 20.226.60.151:33481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9NCf7v0rlcEGmVraFjWAAAAzo"]
[Tue Jul 21 07:42:17.509006 2026] [security2:error] [pid 296703:tid 296845] [client 139.167.225.182:65008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NCSn25uliftkV1n757gAAAAw"]
[Tue Jul 21 07:42:17.509118 2026] [security2:error] [pid 296703:tid 296845] [client 139.167.225.182:65008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NCSn25uliftkV1n757gAAAAw"]
[Tue Jul 21 07:42:17.894230 2026] [security2:error] [pid 296703:tid 296899] [client 20.197.195.24:44721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/xyn.php"] [unique_id "al9NCSn25uliftkV1n759AAAAEI"]
[Tue Jul 21 07:42:18.014232 2026] [security2:error] [pid 254995:tid 255209] [client 20.151.10.161:53582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xxx.php"] [unique_id "al9NCv7v0rlcEGmVraFjZQAAA3E"]
[Tue Jul 21 07:42:18.372288 2026] [security2:error] [pid 254995:tid 255064] [remote 42.200.84.61:56968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cezadvogados.com"] [uri "/wp-login.php"] [unique_id "al9NCv7v0rlcEGmVraFjbwADc0Q"]
[Tue Jul 21 07:42:18.373918 2026] [security2:error] [pid 296703:tid 296916] [client 20.104.96.117:30419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/acp.php"] [unique_id "al9NCin25uliftkV1n75-wAAAFM"]
[Tue Jul 21 07:42:18.382107 2026] [security2:error] [pid 296703:tid 296917] [client 20.220.225.223:34241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/inso.php"] [unique_id "al9NCin25uliftkV1n75_AAAAFQ"]
[Tue Jul 21 07:42:18.524868 2026] [security2:error] [pid 296703:tid 296921] [client 20.226.60.151:56240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/output.php"] [unique_id "al9NCin25uliftkV1n75_QAAAFg"]
[Tue Jul 21 07:42:18.542290 2026] [autoindex:error] [pid 296703:tid 296922] [client 20.197.195.24:44787] AH01276: Cannot serve directory /home2/ren85318/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:18.749372 2026] [security2:error] [pid 254995:tid 255163] [client 190.92.174.183:42592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/wp-login.php"] [unique_id "al9NCf7v0rlcEGmVraFjYAAAA0Q"]
[Tue Jul 21 07:42:18.801167 2026] [security2:error] [pid 254995:tid 255149] [client 173.24.185.52:54574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NCv7v0rlcEGmVraFjeAAAAzY"]
[Tue Jul 21 07:42:18.801298 2026] [security2:error] [pid 254995:tid 255149] [client 173.24.185.52:54574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NCv7v0rlcEGmVraFjeAAAAzY"]
[Tue Jul 21 07:42:18.921050 2026] [security2:error] [pid 296703:tid 296913] [client 122.179.91.63:26448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NCin25uliftkV1n76BAAAAFA"]
[Tue Jul 21 07:42:18.921414 2026] [security2:error] [pid 296703:tid 296913] [client 122.179.91.63:26448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NCin25uliftkV1n76BAAAAFA"]
[Tue Jul 21 07:42:18.930727 2026] [autoindex:error] [pid 296703:tid 296928] [client 20.197.195.24:44787] AH01276: Cannot serve directory /home2/ren85318/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:18.939007 2026] [security2:error] [pid 296703:tid 296931] [client 20.197.195.24:44787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/ccc.php"] [unique_id "al9NCin25uliftkV1n76BQAAAGI"]
[Tue Jul 21 07:42:18.995137 2026] [security2:error] [pid 296703:tid 296877] [client 62.102.148.187:35320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9NCin25uliftkV1n76BgAAACw"]
[Tue Jul 21 07:42:18.995242 2026] [security2:error] [pid 296703:tid 296877] [client 62.102.148.187:35320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9NCin25uliftkV1n76BgAAACw"]
[Tue Jul 21 07:42:19.101321 2026] [security2:error] [pid 296703:tid 296933] [client 74.249.245.134:54371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9NCyn25uliftkV1n76BwAAAGQ"]
[Tue Jul 21 07:42:19.229648 2026] [security2:error] [pid 296703:tid 296937] [client 20.226.60.151:59505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/yas.php"] [unique_id "al9NCyn25uliftkV1n76CgAAAGg"]
[Tue Jul 21 07:42:19.252393 2026] [security2:error] [pid 296703:tid 296939] [client 20.151.10.161:12048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/hypo.php"] [unique_id "al9NCyn25uliftkV1n76CwAAAGo"]
[Tue Jul 21 07:42:19.447362 2026] [security2:error] [pid 296703:tid 296912] [client 136.144.33.97:40605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NCyn25uliftkV1n76DQAAAE8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:19.521905 2026] [security2:error] [pid 296703:tid 296929] [client 103.174.34.15:55663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NCyn25uliftkV1n76DgAAAGA"]
[Tue Jul 21 07:42:19.522052 2026] [security2:error] [pid 296703:tid 296929] [client 103.174.34.15:55663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NCyn25uliftkV1n76DgAAAGA"]
[Tue Jul 21 07:42:19.540423 2026] [security2:error] [pid 254995:tid 255009] [remote 97.74.93.24:55682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abrsolar.org.br"] [uri "/wp-login.php"] [unique_id "al9NC_7v0rlcEGmVraFjhgADPw0"]
[Tue Jul 21 07:42:19.655005 2026] [security2:error] [pid 296703:tid 296947] [client 20.197.195.24:44713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/w.php"] [unique_id "al9NCyn25uliftkV1n76DwAAAHI"]
[Tue Jul 21 07:42:19.662860 2026] [security2:error] [pid 254995:tid 255190] [client 20.226.60.151:54275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/11.php"] [unique_id "al9NC_7v0rlcEGmVraFjhwAAA18"]
[Tue Jul 21 07:42:19.699510 2026] [security2:error] [pid 254995:tid 255184] [client 202.143.127.214:50105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NC_7v0rlcEGmVraFjiQAAA1k"]
[Tue Jul 21 07:42:19.699637 2026] [security2:error] [pid 254995:tid 255184] [client 202.143.127.214:50105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NC_7v0rlcEGmVraFjiQAAA1k"]
[Tue Jul 21 07:42:19.788164 2026] [security2:error] [pid 254995:tid 255203] [client 20.104.96.117:30427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/mosty.php"] [unique_id "al9NC_7v0rlcEGmVraFjiwAAA2w"]
[Tue Jul 21 07:42:19.805575 2026] [security2:error] [pid 296703:tid 296955] [client 20.220.225.223:19280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/berlin.php"] [unique_id "al9NCyn25uliftkV1n76EgAAAHo"]
[Tue Jul 21 07:42:19.849877 2026] [security2:error] [pid 296703:tid 296958] [client 20.226.60.151:62287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9NCyn25uliftkV1n76FAAAAH0"]
[Tue Jul 21 07:42:19.966000 2026] [security2:error] [pid 254995:tid 255127] [client 193.36.225.105:64035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NC_7v0rlcEGmVraFjkwAAAyA"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:42:20.152357 2026] [security2:error] [pid 254995:tid 255152] [client 20.220.225.223:5269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/mimpi.php"] [unique_id "al9NDP7v0rlcEGmVraFjlgAAAzk"]
[Tue Jul 21 07:42:20.265584 2026] [security2:error] [pid 296703:tid 296847] [client 20.151.10.161:12038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/chosen.php"] [unique_id "al9NDCn25uliftkV1n76HAAAAA4"]
[Tue Jul 21 07:42:20.358210 2026] [security2:error] [pid 254995:tid 255132] [client 20.197.195.24:44727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9NDP7v0rlcEGmVraFjnAAAAyU"]
[Tue Jul 21 07:42:20.429041 2026] [security2:error] [pid 254995:tid 255191] [client 106.215.181.8:26953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NDP7v0rlcEGmVraFjogAAA2A"]
[Tue Jul 21 07:42:20.429168 2026] [security2:error] [pid 254995:tid 255191] [client 106.215.181.8:26953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NDP7v0rlcEGmVraFjogAAA2A"]
[Tue Jul 21 07:42:20.871165 2026] [security2:error] [pid 254995:tid 255120] [remote 144.217.254.10:37800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.254.217.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abrsolar.org.br"] [uri "/wp-login.php"] [unique_id "al9NDP7v0rlcEGmVraFj3AADQHw"]
[Tue Jul 21 07:42:20.887297 2026] [security2:error] [pid 254995:tid 255164] [client 20.197.195.24:44691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/FWAZ.php"] [unique_id "al9NDP7v0rlcEGmVraFj3QAAA0U"]
[Tue Jul 21 07:42:20.910434 2026] [security2:error] [pid 254995:tid 255151] [client 20.104.96.117:30408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/6.php"] [unique_id "al9NDP7v0rlcEGmVraFj3wAAAzg"]
[Tue Jul 21 07:42:21.056862 2026] [security2:error] [pid 254995:tid 255269] [client 20.226.60.151:51247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-file-120.php"] [unique_id "al9NDf7v0rlcEGmVraFj4gAAA5M"]
[Tue Jul 21 07:42:21.177905 2026] [security2:error] [pid 296703:tid 296841] [client 20.197.195.24:44675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/miru1.php"] [unique_id "al9NDSn25uliftkV1n76KwAAAAg"]
[Tue Jul 21 07:42:21.198683 2026] [security2:error] [pid 296703:tid 296880] [client 20.226.60.151:59448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/file61.php"] [unique_id "al9NDSn25uliftkV1n76LAAAAC8"]
[Tue Jul 21 07:42:21.209620 2026] [security2:error] [pid 254995:tid 255200] [client 20.151.10.161:55284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/als.php"] [unique_id "al9NDf7v0rlcEGmVraFj5AAAA2k"]
[Tue Jul 21 07:42:21.213908 2026] [security2:error] [pid 254995:tid 255127] [client 184.75.223.211:37090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9NDf7v0rlcEGmVraFj5QAAAyA"]
[Tue Jul 21 07:42:21.214006 2026] [security2:error] [pid 254995:tid 255127] [client 184.75.223.211:37090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9NDf7v0rlcEGmVraFj5QAAAyA"]
[Tue Jul 21 07:42:21.305093 2026] [security2:error] [pid 296703:tid 296884] [client 20.220.225.223:22491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9NDSn25uliftkV1n76LgAAADM"]
[Tue Jul 21 07:42:21.463768 2026] [security2:error] [pid 254995:tid 255252] [client 20.197.195.24:44743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/aa.php"] [unique_id "al9NDf7v0rlcEGmVraFj9QAAA4M"]
[Tue Jul 21 07:42:21.541902 2026] [security2:error] [pid 296703:tid 296736] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NDSn25uliftkV1n76MAAAMiA"]
[Tue Jul 21 07:42:21.542044 2026] [security2:error] [pid 296703:tid 296883] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NDSn25uliftkV1n76MAAAMiA"]
[Tue Jul 21 07:42:21.591597 2026] [security2:error] [pid 254995:tid 255010] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NDf7v0rlcEGmVraFj-gADMw4"]
[Tue Jul 21 07:42:21.591830 2026] [security2:error] [pid 254995:tid 255146] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NDf7v0rlcEGmVraFj-gADMw4"]
[Tue Jul 21 07:42:21.618087 2026] [security2:error] [pid 296703:tid 296882] [client 20.197.195.24:44757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/122.php"] [unique_id "al9NDSn25uliftkV1n76MgAAADE"]
[Tue Jul 21 07:42:21.645654 2026] [security2:error] [pid 296703:tid 296897] [client 20.151.10.161:11718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/pol.php"] [unique_id "al9NDSn25uliftkV1n76MwAAAEA"]
[Tue Jul 21 07:42:21.713769 2026] [security2:error] [pid 296703:tid 296902] [client 20.220.225.223:27980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/dp.php"] [unique_id "al9NDSn25uliftkV1n76NAAAAEU"]
[Tue Jul 21 07:42:21.816598 2026] [security2:error] [pid 254995:tid 255166] [client 152.59.154.239:30414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NDf7v0rlcEGmVraFkAAAAA0c"]
[Tue Jul 21 07:42:21.816684 2026] [security2:error] [pid 254995:tid 255166] [client 152.59.154.239:30414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NDf7v0rlcEGmVraFkAAAAA0c"]
[Tue Jul 21 07:42:21.838035 2026] [security2:error] [pid 254995:tid 255190] [client 20.197.195.24:44768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/get.php"] [unique_id "al9NDf7v0rlcEGmVraFkAgAAA18"]
[Tue Jul 21 07:42:21.942062 2026] [security2:error] [pid 254995:tid 255128] [client 20.197.195.24:44742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/as.php"] [unique_id "al9NDf7v0rlcEGmVraFkBgAAAyE"]
[Tue Jul 21 07:42:21.949729 2026] [security2:error] [pid 296703:tid 296872] [client 47.128.99.162:10984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "precisosolucao.com.br"] [uri "/robots.txt"] [unique_id "al9NDSn25uliftkV1n76NgAAACc"]
[Tue Jul 21 07:42:21.958428 2026] [security2:error] [pid 254995:tid 255129] [client 20.226.60.151:50838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/water.php"] [unique_id "al9NDf7v0rlcEGmVraFkCgAAAyI"]
[Tue Jul 21 07:42:22.129124 2026] [security2:error] [pid 296703:tid 296914] [client 20.151.10.161:55289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file5.php"] [unique_id "al9NDin25uliftkV1n76OQAAAFE"]
[Tue Jul 21 07:42:22.151704 2026] [security2:error] [pid 254995:tid 255163] [client 117.251.86.144:58072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NDv7v0rlcEGmVraFkDgAAA0Q"]
[Tue Jul 21 07:42:22.151838 2026] [security2:error] [pid 254995:tid 255163] [client 117.251.86.144:58072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NDv7v0rlcEGmVraFkDgAAA0Q"]
[Tue Jul 21 07:42:22.159533 2026] [security2:error] [pid 254995:tid 255209] [client 20.197.195.24:44722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/ccou.php"] [unique_id "al9NDv7v0rlcEGmVraFkDwAAA3E"]
[Tue Jul 21 07:42:22.254102 2026] [security2:error] [pid 296703:tid 296907] [client 45.3.46.170:33377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.46.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NDin25uliftkV1n76OAAAAEo"]
[Tue Jul 21 07:42:22.254286 2026] [security2:error] [pid 296703:tid 296907] [client 45.3.46.170:33377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3d-surgery.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NDin25uliftkV1n76OAAAAEo"]
[Tue Jul 21 07:42:22.265562 2026] [security2:error] [pid 254995:tid 255131] [client 20.197.195.24:44755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/w3lls.php"] [unique_id "al9NDv7v0rlcEGmVraFkEwAAAyQ"]
[Tue Jul 21 07:42:22.295941 2026] [security2:error] [pid 296703:tid 296919] [client 20.226.60.151:33987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/albin.php"] [unique_id "al9NDin25uliftkV1n76OgAAAFY"]
[Tue Jul 21 07:42:22.311968 2026] [security2:error] [pid 296703:tid 296899] [client 122.186.204.214:55855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NDin25uliftkV1n76OwAAAEI"]
[Tue Jul 21 07:42:22.312129 2026] [security2:error] [pid 296703:tid 296899] [client 122.186.204.214:55855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NDin25uliftkV1n76OwAAAEI"]
[Tue Jul 21 07:42:22.357596 2026] [security2:error] [pid 254995:tid 255169] [client 20.197.195.24:44778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/test1.php"] [unique_id "al9NDv7v0rlcEGmVraFkFQAAA0o"]
[Tue Jul 21 07:42:22.454937 2026] [security2:error] [pid 254995:tid 255155] [client 20.226.60.151:54335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/mac.php"] [unique_id "al9NDv7v0rlcEGmVraFkGAAAAzw"]
[Tue Jul 21 07:42:22.507452 2026] [security2:error] [pid 254995:tid 255142] [client 182.8.255.181:21227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NDv7v0rlcEGmVraFkHgAAAy8"]
[Tue Jul 21 07:42:22.507563 2026] [security2:error] [pid 254995:tid 255142] [client 182.8.255.181:21227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NDv7v0rlcEGmVraFkHgAAAy8"]
[Tue Jul 21 07:42:22.518386 2026] [security2:error] [pid 254995:tid 255216] [client 20.197.195.24:13642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/database.php"] [unique_id "al9NDv7v0rlcEGmVraFkHwAAA3g"]
[Tue Jul 21 07:42:22.581515 2026] [autoindex:error] [pid 296703:tid 296931] [client 20.226.60.151:22933] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:22.594316 2026] [security2:error] [pid 254995:tid 255268] [client 74.249.245.134:5536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9NDv7v0rlcEGmVraFkJAAAA5I"]
[Tue Jul 21 07:42:22.615796 2026] [security2:error] [pid 296703:tid 296933] [client 20.226.60.151:22933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/memberfuns.php"] [unique_id "al9NDin25uliftkV1n76QwAAAGQ"]
[Tue Jul 21 07:42:22.630170 2026] [security2:error] [pid 254995:tid 255164] [client 122.164.127.47:54061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NDv7v0rlcEGmVraFkJgAAA0U"]
[Tue Jul 21 07:42:22.630296 2026] [security2:error] [pid 254995:tid 255164] [client 122.164.127.47:54061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NDv7v0rlcEGmVraFkJgAAA0U"]
[Tue Jul 21 07:42:22.812752 2026] [security2:error] [pid 254995:tid 255063] [remote 5.252.52.249:60588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9NDv7v0rlcEGmVraFkKgADIEM"]
[Tue Jul 21 07:42:22.854544 2026] [security2:error] [pid 296703:tid 296938] [client 20.151.10.161:55252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9NDin25uliftkV1n76RQAAAGk"]
[Tue Jul 21 07:42:22.970762 2026] [security2:error] [pid 296703:tid 296944] [client 20.220.225.223:5268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/bootstrap.php"] [unique_id "al9NDin25uliftkV1n76RwAAAG8"]
[Tue Jul 21 07:42:22.983037 2026] [security2:error] [pid 254995:tid 255125] [client 103.86.117.203:52927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NDv7v0rlcEGmVraFkLgAAAx4"]
[Tue Jul 21 07:42:22.983141 2026] [security2:error] [pid 254995:tid 255125] [client 103.86.117.203:52927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NDv7v0rlcEGmVraFkLgAAAx4"]
[Tue Jul 21 07:42:23.138666 2026] [security2:error] [pid 254995:tid 255168] [client 20.226.60.151:59430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/nano.php"] [unique_id "al9ND_7v0rlcEGmVraFkNAAAA0k"]
[Tue Jul 21 07:42:23.145492 2026] [security2:error] [pid 254995:tid 255220] [client 193.36.225.153:23249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9ND_7v0rlcEGmVraFkNQAAA3w"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:42:23.365351 2026] [security2:error] [pid 254995:tid 255151] [client 104.207.63.247:35791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.63.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9ND_7v0rlcEGmVraFkNgAAAzg"]
[Tue Jul 21 07:42:23.385486 2026] [security2:error] [pid 254995:tid 255128] [client 45.3.54.172:24623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9ND_7v0rlcEGmVraFkNwAAAyE"]
[Tue Jul 21 07:42:23.423364 2026] [security2:error] [pid 296703:tid 296838] [client 20.197.192.193:23527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9NDyn25uliftkV1n76UAAAAAU"]
[Tue Jul 21 07:42:23.424351 2026] [security2:error] [pid 296703:tid 296952] [client 45.3.48.133:25087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.48.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NDyn25uliftkV1n76TgAAAHc"]
[Tue Jul 21 07:42:23.490858 2026] [security2:error] [pid 254995:tid 255197] [client 195.63.31.255:12237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.31.63.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9ND_7v0rlcEGmVraFkOgAAA2Y"]
[Tue Jul 21 07:42:23.493756 2026] [security2:error] [pid 296703:tid 296929] [client 104.207.54.10:29895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.54.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NDyn25uliftkV1n76SQAAAGA"]
[Tue Jul 21 07:42:23.502293 2026] [security2:error] [pid 296703:tid 296848] [client 20.197.195.24:44773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/file.php"] [unique_id "al9NDyn25uliftkV1n76UgAAAA8"]
[Tue Jul 21 07:42:23.556163 2026] [security2:error] [pid 296703:tid 296930] [client 20.226.60.151:51243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/special.php"] [unique_id "al9NDyn25uliftkV1n76VgAAAGE"]
[Tue Jul 21 07:42:23.590287 2026] [security2:error] [pid 296703:tid 296951] [client 104.207.42.121:27069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.42.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NDyn25uliftkV1n76TwAAAHY"]
[Tue Jul 21 07:42:23.640171 2026] [security2:error] [pid 296703:tid 296833] [client 65.111.8.38:25619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.8.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NDyn25uliftkV1n76WQAAAAA"]
[Tue Jul 21 07:42:23.669092 2026] [security2:error] [pid 254995:tid 255149] [client 20.151.10.161:12047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file.php"] [unique_id "al9ND_7v0rlcEGmVraFkSQAAAzY"]
[Tue Jul 21 07:42:23.679482 2026] [security2:error] [pid 296703:tid 296843] [client 20.197.192.193:23520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9NDyn25uliftkV1n76XAAAAAo"]
[Tue Jul 21 07:42:23.700008 2026] [security2:error] [pid 296703:tid 296862] [client 20.104.96.117:30443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9NDyn25uliftkV1n76XQAAAB0"]
[Tue Jul 21 07:42:23.714449 2026] [security2:error] [pid 254995:tid 255274] [client 74.7.175.175:46816] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.a06.arcoll.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9ND_7v0rlcEGmVraFkSgADmAg"]
[Tue Jul 21 07:42:23.744049 2026] [security2:error] [pid 296703:tid 296864] [client 20.197.192.193:23491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/dp.php"] [unique_id "al9NDyn25uliftkV1n76XwAAAB8"]
[Tue Jul 21 07:42:23.765289 2026] [security2:error] [pid 254995:tid 255153] [client 20.197.192.193:24450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/old.php"] [unique_id "al9ND_7v0rlcEGmVraFkTAAAAzo"]
[Tue Jul 21 07:42:23.766588 2026] [security2:error] [pid 296703:tid 296955] [client 182.8.226.25:25671] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "darsenavogamarine.com"] [uri "/wp-json/batch/v1"] [unique_id "al9NDyn25uliftkV1n76WwAAAHo"]
[Tue Jul 21 07:42:23.789674 2026] [security2:error] [pid 296703:tid 296871] [client 20.197.192.193:23534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/ms-new.php"] [unique_id "al9NDyn25uliftkV1n76YAAAACY"]
[Tue Jul 21 07:42:23.859562 2026] [security2:error] [pid 254995:tid 255266] [client 20.197.192.193:23536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/track.php"] [unique_id "al9ND_7v0rlcEGmVraFkTQAAA5A"]
[Tue Jul 21 07:42:23.924609 2026] [security2:error] [pid 296703:tid 296860] [client 20.197.192.193:24449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/2352356666.php"] [unique_id "al9NDyn25uliftkV1n76YQAAABs"]
[Tue Jul 21 07:42:23.938722 2026] [security2:error] [pid 296703:tid 296849] [client 20.220.225.223:34277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/dp.php"] [unique_id "al9NDyn25uliftkV1n76YgAAABA"]
[Tue Jul 21 07:42:24.000323 2026] [security2:error] [pid 296703:tid 296958] [client 154.192.233.199:58927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NECn25uliftkV1n76ZgAAAH0"]
[Tue Jul 21 07:42:24.000464 2026] [security2:error] [pid 296703:tid 296958] [client 154.192.233.199:58927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NECn25uliftkV1n76ZgAAAH0"]
[Tue Jul 21 07:42:24.001644 2026] [security2:error] [pid 296703:tid 296880] [client 20.197.192.193:23489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/pn.php"] [unique_id "al9NECn25uliftkV1n76ZwAAAC8"]
[Tue Jul 21 07:42:24.031920 2026] [security2:error] [pid 296703:tid 296884] [client 20.226.60.151:54272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/chosen.php"] [unique_id "al9NECn25uliftkV1n76aAAAADM"]
[Tue Jul 21 07:42:24.132430 2026] [security2:error] [pid 254995:tid 255158] [client 184.75.223.211:37104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9NEP7v0rlcEGmVraFkVgAAAz8"]
[Tue Jul 21 07:42:24.132590 2026] [security2:error] [pid 254995:tid 255158] [client 184.75.223.211:37104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9NEP7v0rlcEGmVraFkVgAAAz8"]
[Tue Jul 21 07:42:24.146597 2026] [security2:error] [pid 296703:tid 296868] [client 151.123.176.212:15037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.176.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NDyn25uliftkV1n76ZAAAACM"]
[Tue Jul 21 07:42:24.161279 2026] [security2:error] [pid 296703:tid 296869] [client 65.111.30.122:29173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.30.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NDyn25uliftkV1n76ZQAAACQ"]
[Tue Jul 21 07:42:24.243914 2026] [security2:error] [pid 254995:tid 255133] [client 193.36.225.60:31601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NEP7v0rlcEGmVraFkWAAAAyY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:24.282182 2026] [security2:error] [pid 296703:tid 296856] [client 20.197.192.193:24466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/wp-wpbak.php"] [unique_id "al9NECn25uliftkV1n76awAAABc"]
[Tue Jul 21 07:42:24.365682 2026] [security2:error] [pid 296703:tid 296878] [client 104.207.57.141:53959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.57.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NECn25uliftkV1n76agAAAC0"]
[Tue Jul 21 07:42:24.433409 2026] [security2:error] [pid 254995:tid 255022] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NEP7v0rlcEGmVraFkXQADeRo"]
[Tue Jul 21 07:42:24.433550 2026] [security2:error] [pid 254995:tid 255217] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NEP7v0rlcEGmVraFkXQADeRo"]
[Tue Jul 21 07:42:24.465253 2026] [security2:error] [pid 296703:tid 296882] [client 74.249.245.134:5540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/wp.php"] [unique_id "al9NECn25uliftkV1n76cAAAADE"]
[Tue Jul 21 07:42:24.484838 2026] [security2:error] [pid 296703:tid 296886] [client 104.207.39.249:44233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.39.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NECn25uliftkV1n76bAAAADU"]
[Tue Jul 21 07:42:24.510718 2026] [security2:error] [pid 296703:tid 296900] [client 20.197.192.193:23522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/dr.php"] [unique_id "al9NECn25uliftkV1n76cQAAAEM"]
[Tue Jul 21 07:42:24.516970 2026] [security2:error] [pid 296703:tid 296901] [client 20.151.10.161:53607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/cfile.php"] [unique_id "al9NECn25uliftkV1n76cgAAAEQ"]
[Tue Jul 21 07:42:24.539412 2026] [security2:error] [pid 296703:tid 296909] [client 20.197.192.193:23518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/2x.php"] [unique_id "al9NECn25uliftkV1n76cwAAAEw"]
[Tue Jul 21 07:42:24.554762 2026] [security2:error] [pid 254995:tid 255202] [client 20.197.192.193:23538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/kq1.php"] [unique_id "al9NEP7v0rlcEGmVraFkYAAAA2s"]
[Tue Jul 21 07:42:24.574962 2026] [security2:error] [pid 296703:tid 296947] [client 65.111.11.9:57839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.11.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NDyn25uliftkV1n76TAAAAHI"]
[Tue Jul 21 07:42:24.586210 2026] [security2:error] [pid 296703:tid 296950] [client 65.111.13.109:52345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.13.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NDyn25uliftkV1n76TQAAAHU"]
[Tue Jul 21 07:42:24.586468 2026] [security2:error] [pid 296703:tid 296890] [client 45.3.52.120:52627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.52.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NECn25uliftkV1n76bQAAADk"]
[Tue Jul 21 07:42:24.616658 2026] [security2:error] [pid 296703:tid 296911] [client 20.197.195.24:44776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/file.php"] [unique_id "al9NECn25uliftkV1n76dAAAAE4"]
[Tue Jul 21 07:42:24.620030 2026] [security2:error] [pid 296703:tid 296914] [client 20.197.192.193:23502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/zzz.php"] [unique_id "al9NECn25uliftkV1n76dQAAAFE"]
[Tue Jul 21 07:42:24.701605 2026] [security2:error] [pid 254995:tid 255255] [client 45.3.36.121:30439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.36.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9ND_7v0rlcEGmVraFkQQAAA4U"]
[Tue Jul 21 07:42:24.702603 2026] [security2:error] [pid 296703:tid 296920] [client 20.197.192.193:24452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/wicked.php"] [unique_id "al9NECn25uliftkV1n76egAAAFc"]
[Tue Jul 21 07:42:24.777715 2026] [security2:error] [pid 254995:tid 255183] [client 20.197.192.193:23540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/edit.php"] [unique_id "al9NEP7v0rlcEGmVraFkZwAAA1g"]
[Tue Jul 21 07:42:24.809288 2026] [security2:error] [pid 254995:tid 255218] [client 65.111.7.220:40873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.7.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9ND_7v0rlcEGmVraFkRwAAA3o"]
[Tue Jul 21 07:42:24.866831 2026] [security2:error] [pid 296703:tid 296928] [client 20.197.192.193:23513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/kua.php"] [unique_id "al9NECn25uliftkV1n76fAAAAF8"]
[Tue Jul 21 07:42:24.936565 2026] [security2:error] [pid 254995:tid 255169] [client 20.226.60.151:50914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/moon.php"] [unique_id "al9NEP7v0rlcEGmVraFkawAAA0o"]
[Tue Jul 21 07:42:24.986990 2026] [security2:error] [pid 254995:tid 255157] [client 20.197.192.193:23530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/ez.php"] [unique_id "al9NEP7v0rlcEGmVraFkbwAAAz4"]
[Tue Jul 21 07:42:25.004017 2026] [security2:error] [pid 296703:tid 296927] [client 20.226.60.151:62268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/cilus.php"] [unique_id "al9NESn25uliftkV1n76fQAAAF4"]
[Tue Jul 21 07:42:25.121723 2026] [security2:error] [pid 296703:tid 296921] [client 182.8.226.25:23659] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "darsenavogamarine.com"] [uri "/wp-json/batch/v1"] [unique_id "al9NESn25uliftkV1n76fgAAAFg"]
[Tue Jul 21 07:42:25.181668 2026] [security2:error] [pid 254995:tid 255260] [client 20.197.192.193:24453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/fz.php"] [unique_id "al9NEf7v0rlcEGmVraFkdAAAA4o"]
[Tue Jul 21 07:42:25.278006 2026] [security2:error] [pid 296703:tid 296945] [client 20.197.192.193:23510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/la.php"] [unique_id "al9NESn25uliftkV1n76hQAAAHA"]
[Tue Jul 21 07:42:25.287092 2026] [security2:error] [pid 296703:tid 296960] [client 20.226.60.151:54377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/cream1.php"] [unique_id "al9NESn25uliftkV1n76hwAAAH8"]
[Tue Jul 21 07:42:25.305344 2026] [security2:error] [pid 296703:tid 296932] [client 104.207.49.97:9701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.49.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NESn25uliftkV1n76gAAAAGM"]
[Tue Jul 21 07:42:25.376446 2026] [security2:error] [pid 296703:tid 296836] [client 20.151.10.161:55276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/class-wp.php"] [unique_id "al9NESn25uliftkV1n76iwAAAAM"]
[Tue Jul 21 07:42:25.401342 2026] [security2:error] [pid 296703:tid 296842] [client 20.197.192.193:23503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/nhvoanpl.php"] [unique_id "al9NESn25uliftkV1n76jAAAAAk"]
[Tue Jul 21 07:42:25.484616 2026] [security2:error] [pid 296703:tid 296935] [client 45.3.51.209:14995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.51.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NESn25uliftkV1n76igAAAGY"]
[Tue Jul 21 07:42:25.519671 2026] [security2:error] [pid 296703:tid 296852] [client 20.197.192.193:23532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/inso.php"] [unique_id "al9NESn25uliftkV1n76jgAAABM"]
[Tue Jul 21 07:42:25.557615 2026] [security2:error] [pid 254995:tid 255252] [client 104.207.52.81:59483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NEf7v0rlcEGmVraFkdgAAA4M"]
[Tue Jul 21 07:42:25.573602 2026] [security2:error] [pid 254995:tid 255270] [client 151.123.177.142:50635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.177.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NEf7v0rlcEGmVraFkdwAAA5Q"]
[Tue Jul 21 07:42:25.603248 2026] [security2:error] [pid 254995:tid 255268] [client 20.197.192.193:23493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/wpx.php"] [unique_id "al9NEf7v0rlcEGmVraFkfQAAA5I"]
[Tue Jul 21 07:42:25.668663 2026] [security2:error] [pid 254995:tid 255273] [client 20.197.192.193:24507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/berlin.php"] [unique_id "al9NEf7v0rlcEGmVraFkgAAAA5c"]
[Tue Jul 21 07:42:25.679288 2026] [security2:error] [pid 254995:tid 255190] [client 20.197.195.24:44760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/777.php"] [unique_id "al9NEf7v0rlcEGmVraFkgQAAA18"]
[Tue Jul 21 07:42:25.706042 2026] [security2:error] [pid 254995:tid 255164] [client 104.207.35.18:35481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.35.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NEf7v0rlcEGmVraFkewAAA0U"]
[Tue Jul 21 07:42:25.720501 2026] [security2:error] [pid 254995:tid 255135] [client 20.197.192.193:24453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/billur.php"] [unique_id "al9NEf7v0rlcEGmVraFkhAAAAyg"]
[Tue Jul 21 07:42:25.763516 2026] [security2:error] [pid 254995:tid 255153] [client 45.3.40.34:47797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.40.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NEf7v0rlcEGmVraFkfAAAAzo"]
[Tue Jul 21 07:42:25.771529 2026] [security2:error] [pid 254995:tid 255217] [client 20.197.192.193:23488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/mimpi.php"] [unique_id "al9NEf7v0rlcEGmVraFkhwAAA3k"]
[Tue Jul 21 07:42:25.789171 2026] [security2:error] [pid 296703:tid 296849] [client 20.197.192.193:24479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/dp.php"] [unique_id "al9NESn25uliftkV1n76lAAAABA"]
[Tue Jul 21 07:42:25.806349 2026] [security2:error] [pid 296703:tid 296948] [client 65.111.5.248:27789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.5.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NDyn25uliftkV1n76WgAAAHM"]
[Tue Jul 21 07:42:25.817649 2026] [security2:error] [pid 296703:tid 296940] [client 117.217.38.194:49256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NESn25uliftkV1n76lQAAAGs"]
[Tue Jul 21 07:42:25.817756 2026] [security2:error] [pid 296703:tid 296940] [client 117.217.38.194:49256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NESn25uliftkV1n76lQAAAGs"]
[Tue Jul 21 07:42:25.841400 2026] [security2:error] [pid 296703:tid 296958] [client 20.197.192.193:23509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/bootstrap.php"] [unique_id "al9NESn25uliftkV1n76lgAAAH0"]
[Tue Jul 21 07:42:25.894421 2026] [security2:error] [pid 296703:tid 296854] [client 20.197.192.193:23550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/wp-editor.php"] [unique_id "al9NESn25uliftkV1n76lwAAABU"]
[Tue Jul 21 07:42:25.937288 2026] [security2:error] [pid 296703:tid 296888] [client 20.197.192.193:24467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/cro.php"] [unique_id "al9NESn25uliftkV1n76mAAAADc"]
[Tue Jul 21 07:42:25.960029 2026] [security2:error] [pid 254995:tid 255209] [client 20.197.192.193:24481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/cron-tab.php"] [unique_id "al9NEf7v0rlcEGmVraFkiwAAA3E"]
[Tue Jul 21 07:42:25.962733 2026] [security2:error] [pid 296703:tid 296838] [client 103.106.20.201:51992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NESn25uliftkV1n76mQAAAAU"]
[Tue Jul 21 07:42:25.962936 2026] [security2:error] [pid 296703:tid 296838] [client 103.106.20.201:51992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NESn25uliftkV1n76mQAAAAU"]
[Tue Jul 21 07:42:26.029174 2026] [security2:error] [pid 254995:tid 255145] [client 20.197.192.193:24465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/koiy.php"] [unique_id "al9NEv7v0rlcEGmVraFkjgAAAzI"]
[Tue Jul 21 07:42:26.078170 2026] [security2:error] [pid 296703:tid 296869] [client 20.151.10.161:55287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/admin.php"] [unique_id "al9NEin25uliftkV1n76mwAAACQ"]
[Tue Jul 21 07:42:26.086378 2026] [security2:error] [pid 254995:tid 255218] [client 20.197.192.193:23545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/hp2.php"] [unique_id "al9NEv7v0rlcEGmVraFkkQAAA3o"]
[Tue Jul 21 07:42:26.110146 2026] [security2:error] [pid 254995:tid 255189] [client 20.197.192.193:23546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/hp3.php"] [unique_id "al9NEv7v0rlcEGmVraFklAAAA14"]
[Tue Jul 21 07:42:26.155322 2026] [security2:error] [pid 254995:tid 255180] [client 20.197.192.193:23533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/aa1.php"] [unique_id "al9NEv7v0rlcEGmVraFklwAAA1U"]
[Tue Jul 21 07:42:26.190007 2026] [security2:error] [pid 296703:tid 296856] [client 20.197.192.193:23496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/acew67.php"] [unique_id "al9NEin25uliftkV1n76nAAAABc"]
[Tue Jul 21 07:42:26.201307 2026] [security2:error] [pid 296703:tid 296837] [client 20.226.60.151:51215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/as.php"] [unique_id "al9NEin25uliftkV1n76ngAAAAQ"]
[Tue Jul 21 07:42:26.224902 2026] [security2:error] [pid 296703:tid 296878] [client 20.197.192.193:23515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/bscclapb.php"] [unique_id "al9NEin25uliftkV1n76oAAAAC0"]
[Tue Jul 21 07:42:26.311672 2026] [security2:error] [pid 296703:tid 296901] [client 20.197.192.193:24462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/else1.php"] [unique_id "al9NEin25uliftkV1n76pAAAAEQ"]
[Tue Jul 21 07:42:26.403732 2026] [security2:error] [pid 296703:tid 296959] [client 20.197.192.193:24042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/tkikikoko.php"] [unique_id "al9NEin25uliftkV1n76pQAAAH4"]
[Tue Jul 21 07:42:26.479457 2026] [security2:error] [pid 296703:tid 296909] [client 20.197.192.193:23549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/wp-Blogs.php"] [unique_id "al9NEin25uliftkV1n76pwAAAEw"]
[Tue Jul 21 07:42:26.494369 2026] [security2:error] [pid 254995:tid 255222] [client 217.181.91.227:65451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.91.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NEv7v0rlcEGmVraFkowAAA34"]
[Tue Jul 21 07:42:26.519647 2026] [security2:error] [pid 296703:tid 296860] [client 122.162.144.145:15093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NEin25uliftkV1n76qQAAABs"]
[Tue Jul 21 07:42:26.519785 2026] [security2:error] [pid 296703:tid 296860] [client 122.162.144.145:15093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NEin25uliftkV1n76qQAAABs"]
[Tue Jul 21 07:42:26.546637 2026] [security2:error] [pid 296703:tid 296947] [client 20.220.225.223:34276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/wpx.php"] [unique_id "al9NEin25uliftkV1n76qgAAAHI"]
[Tue Jul 21 07:42:26.549259 2026] [security2:error] [pid 296703:tid 296872] [client 20.197.192.193:24497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/wp-css.php"] [unique_id "al9NEin25uliftkV1n76qwAAACc"]
[Tue Jul 21 07:42:26.665176 2026] [security2:error] [pid 254995:tid 255147] [client 20.197.192.193:23516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/wp-explorer.php"] [unique_id "al9NEv7v0rlcEGmVraFktwAAAzQ"]
[Tue Jul 21 07:42:26.683363 2026] [security2:error] [pid 296703:tid 296917] [client 20.151.10.161:12041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/aa2.php"] [unique_id "al9NEin25uliftkV1n76rQAAAFQ"]
[Tue Jul 21 07:42:26.729893 2026] [security2:error] [pid 254995:tid 255252] [client 184.75.223.211:37118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9NEv7v0rlcEGmVraFkuwAAA4M"]
[Tue Jul 21 07:42:26.729991 2026] [security2:error] [pid 254995:tid 255252] [client 184.75.223.211:37118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9NEv7v0rlcEGmVraFkuwAAA4M"]
[Tue Jul 21 07:42:26.849536 2026] [security2:error] [pid 296703:tid 296943] [client 20.197.192.193:23507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/akismet.php"] [unique_id "al9NEin25uliftkV1n76swAAAG4"]
[Tue Jul 21 07:42:26.909193 2026] [security2:error] [pid 254995:tid 255149] [client 45.3.37.145:57521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.37.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NEv7v0rlcEGmVraFkvAAAAzY"]
[Tue Jul 21 07:42:26.961876 2026] [autoindex:error] [pid 296703:tid 296912] [client 20.226.60.151:54277] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:26.988024 2026] [autoindex:error] [pid 296703:tid 296952] [client 20.226.60.151:54277] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:26.994007 2026] [security2:error] [pid 296703:tid 296932] [client 20.226.60.151:54277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/dr.php"] [unique_id "al9NEin25uliftkV1n76twAAAGM"]
[Tue Jul 21 07:42:27.029802 2026] [security2:error] [pid 296703:tid 296836] [client 20.197.192.193:23539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/ace2.php"] [unique_id "al9NEyn25uliftkV1n76uAAAAAM"]
[Tue Jul 21 07:42:27.078869 2026] [security2:error] [pid 296703:tid 296842] [client 20.220.225.223:34192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/old.php"] [unique_id "al9NEyn25uliftkV1n76uwAAAAk"]
[Tue Jul 21 07:42:27.128672 2026] [security2:error] [pid 296703:tid 296951] [client 20.197.192.193:24482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/ms.php"] [unique_id "al9NEyn25uliftkV1n76vQAAAHY"]
[Tue Jul 21 07:42:27.142523 2026] [security2:error] [pid 296703:tid 296899] [client 20.226.60.151:59492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-info.php"] [unique_id "al9NEyn25uliftkV1n76vgAAAEI"]
[Tue Jul 21 07:42:27.226717 2026] [security2:error] [pid 296703:tid 296866] [client 74.249.245.134:5549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/new.php"] [unique_id "al9NEyn25uliftkV1n76wAAAACE"]
[Tue Jul 21 07:42:27.242475 2026] [security2:error] [pid 254995:tid 255121] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9NE_7v0rlcEGmVraFkwwADQH0"]
[Tue Jul 21 07:42:27.263278 2026] [security2:error] [pid 254995:tid 255125] [client 20.226.60.151:62304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/gptsh.php"] [unique_id "al9NE_7v0rlcEGmVraFkxQAAAx4"]
[Tue Jul 21 07:42:27.292889 2026] [security2:error] [pid 254995:tid 255217] [client 20.151.10.161:53574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ccou.php"] [unique_id "al9NE_7v0rlcEGmVraFkyAAAA3k"]
[Tue Jul 21 07:42:27.421202 2026] [security2:error] [pid 254995:tid 255205] [client 193.56.28.44:61287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.28.56.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NEf7v0rlcEGmVraFkeAAAA24"]
[Tue Jul 21 07:42:27.497249 2026] [security2:error] [pid 254995:tid 255178] [client 104.207.55.155:20929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.55.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NEv7v0rlcEGmVraFkswAAA1M"]
[Tue Jul 21 07:42:27.568233 2026] [security2:error] [pid 296703:tid 296750] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9NEyn25uliftkV1n76yQAAfS4"]
[Tue Jul 21 07:42:27.648038 2026] [security2:error] [pid 296703:tid 296897] [client 104.207.59.45:22221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.59.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NEin25uliftkV1n76pgAAAEA"]
[Tue Jul 21 07:42:27.690925 2026] [security2:error] [pid 254995:tid 255030] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9NE_7v0rlcEGmVraFk0QADMCI"]
[Tue Jul 21 07:42:27.788934 2026] [security2:error] [pid 296703:tid 296960] [client 139.167.225.182:49287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NEyn25uliftkV1n76ywAAAH8"]
[Tue Jul 21 07:42:27.789114 2026] [security2:error] [pid 296703:tid 296960] [client 139.167.225.182:49287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NEyn25uliftkV1n76ywAAAH8"]
[Tue Jul 21 07:42:27.828193 2026] [security2:error] [pid 296703:tid 296751] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9NEyn25uliftkV1n76zAAANy8"]
[Tue Jul 21 07:42:27.941247 2026] [security2:error] [pid 296703:tid 296838] [client 20.151.10.161:11715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/dr.php"] [unique_id "al9NEyn25uliftkV1n76zQAAAAU"]
[Tue Jul 21 07:42:27.970325 2026] [security2:error] [pid 254995:tid 255049] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9NE_7v0rlcEGmVraFk2QADTzU"]
[Tue Jul 21 07:42:28.068137 2026] [security2:error] [pid 296703:tid 296856] [client 20.220.225.223:34296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/ms-new.php"] [unique_id "al9NFCn25uliftkV1n76zgAAABc"]
[Tue Jul 21 07:42:28.106405 2026] [security2:error] [pid 254995:tid 255090] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NFP7v0rlcEGmVraFk2wADPl4"]
[Tue Jul 21 07:42:28.106530 2026] [security2:error] [pid 254995:tid 255157] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NFP7v0rlcEGmVraFk2wADPl4"]
[Tue Jul 21 07:42:28.107774 2026] [security2:error] [pid 296703:tid 296752] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9NFCn25uliftkV1n760AAAATA"]
[Tue Jul 21 07:42:28.115947 2026] [security2:error] [pid 254995:tid 255162] [client 20.226.60.151:50880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/2000.php"] [unique_id "al9NFP7v0rlcEGmVraFk3AAAA0M"]
[Tue Jul 21 07:42:28.181192 2026] [security2:error] [pid 254995:tid 255179] [client 59.96.220.140:57297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NFP7v0rlcEGmVraFk3gAAA1Q"]
[Tue Jul 21 07:42:28.186904 2026] [security2:error] [pid 254995:tid 255179] [client 59.96.220.140:57297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NFP7v0rlcEGmVraFk3gAAA1Q"]
[Tue Jul 21 07:42:28.222638 2026] [security2:error] [pid 296703:tid 296901] [client 20.104.96.117:62940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9NFCn25uliftkV1n760wAAAEQ"]
[Tue Jul 21 07:42:28.226003 2026] [security2:error] [pid 296703:tid 296857] [client 20.220.225.223:11150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/wp-editor.php"] [unique_id "al9NFCn25uliftkV1n761AAAABg"]
[Tue Jul 21 07:42:28.232103 2026] [security2:error] [pid 254995:tid 255114] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9NFP7v0rlcEGmVraFk4AADL3Y"]
[Tue Jul 21 07:42:28.237622 2026] [security2:error] [pid 296703:tid 296754] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NFCn25uliftkV1n761QAAJDI"]
[Tue Jul 21 07:42:28.237764 2026] [security2:error] [pid 296703:tid 296869] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NFCn25uliftkV1n761QAAJDI"]
[Tue Jul 21 07:42:28.292108 2026] [security2:error] [pid 254995:tid 255140] [client 122.179.91.63:30657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NFP7v0rlcEGmVraFk5AAAAy0"]
[Tue Jul 21 07:42:28.292471 2026] [security2:error] [pid 254995:tid 255140] [client 122.179.91.63:30657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NFP7v0rlcEGmVraFk5AAAAy0"]
[Tue Jul 21 07:42:28.366094 2026] [security2:error] [pid 296703:tid 296755] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9NFCn25uliftkV1n762AAATjM"]
[Tue Jul 21 07:42:28.404692 2026] [security2:error] [pid 296703:tid 296868] [client 104.207.33.57:40343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.33.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NEin25uliftkV1n76ogAAACM"]
[Tue Jul 21 07:42:28.451067 2026] [security2:error] [pid 296703:tid 296910] [client 20.104.96.117:30403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/qqqa.php"] [unique_id "al9NFCn25uliftkV1n763AAAAE0"]
[Tue Jul 21 07:42:28.459335 2026] [security2:error] [pid 254995:tid 255146] [client 20.151.10.161:11728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xamp.php"] [unique_id "al9NFP7v0rlcEGmVraFk5gAAAzM"]
[Tue Jul 21 07:42:28.477323 2026] [security2:error] [pid 296703:tid 296896] [client 20.197.195.24:44769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/ssixta.php"] [unique_id "al9NFCn25uliftkV1n763QAAAD8"]
[Tue Jul 21 07:42:28.486936 2026] [security2:error] [pid 254995:tid 255076] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9NFP7v0rlcEGmVraFk5wADQlA"]
[Tue Jul 21 07:42:28.793973 2026] [security2:error] [pid 296703:tid 296895] [client 20.104.96.117:64010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9NFCn25uliftkV1n764gAAAD4"]
[Tue Jul 21 07:42:28.809445 2026] [security2:error] [pid 296703:tid 296928] [client 20.226.60.151:61970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/x.php"] [unique_id "al9NFCn25uliftkV1n764wAAAF8"]
[Tue Jul 21 07:42:28.926613 2026] [security2:error] [pid 296703:tid 296759] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9NFCn25uliftkV1n765QAAZTc"]
[Tue Jul 21 07:42:28.998854 2026] [security2:error] [pid 254995:tid 255127] [client 45.3.37.80:62865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.37.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NE_7v0rlcEGmVraFk1wAAAyA"]
[Tue Jul 21 07:42:29.021520 2026] [security2:error] [pid 254995:tid 255159] [client 20.226.60.151:33497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/rithin.php"] [unique_id "al9NFf7v0rlcEGmVraFk8QAAA0A"]
[Tue Jul 21 07:42:29.052077 2026] [security2:error] [pid 254995:tid 255117] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9NFf7v0rlcEGmVraFk8wADOnk"]
[Tue Jul 21 07:42:29.186744 2026] [security2:error] [pid 296703:tid 296761] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9NFSn25uliftkV1n765wAAaDk"]
[Tue Jul 21 07:42:29.375085 2026] [security2:error] [pid 254995:tid 255194] [client 173.24.185.52:55050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NFf7v0rlcEGmVraFk_QAAA2M"]
[Tue Jul 21 07:42:29.375207 2026] [security2:error] [pid 254995:tid 255194] [client 173.24.185.52:55050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NFf7v0rlcEGmVraFk_QAAA2M"]
[Tue Jul 21 07:42:29.433200 2026] [security2:error] [pid 254995:tid 255158] [client 193.36.225.121:56893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NFf7v0rlcEGmVraFk_gAAAz8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:42:29.448533 2026] [security2:error] [pid 254995:tid 255131] [client 74.249.245.134:54340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/class-t.api.php"] [unique_id "al9NFf7v0rlcEGmVraFk_wAAAyQ"]
[Tue Jul 21 07:42:29.453556 2026] [security2:error] [pid 254995:tid 255268] [client 136.144.33.97:30397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NFP7v0rlcEGmVraFk4gAAA5I"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:29.558836 2026] [security2:error] [pid 296703:tid 296894] [client 20.104.96.117:64031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/media.php"] [unique_id "al9NFSn25uliftkV1n767AAAAD0"]
[Tue Jul 21 07:42:29.757285 2026] [security2:error] [pid 296703:tid 296852] [client 20.220.225.223:34300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/berlin.php"] [unique_id "al9NFSn25uliftkV1n767wAAABM"]
[Tue Jul 21 07:42:29.782408 2026] [security2:error] [pid 254995:tid 255002] [remote 195.26.244.42:39116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "escoladaseguranca.com.br"] [uri "/wp-login.php"] [unique_id "al9NFf7v0rlcEGmVraFlBQADXwY"]
[Tue Jul 21 07:42:29.918910 2026] [security2:error] [pid 254995:tid 255174] [client 20.104.96.117:62929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/images.php"] [unique_id "al9NFf7v0rlcEGmVraFlCgAAA08"]
[Tue Jul 21 07:42:29.966145 2026] [security2:error] [pid 296703:tid 296764] [remote 13.41.15.21:48212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.15.41.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9NFSn25uliftkV1n769QAAEjw"]
[Tue Jul 21 07:42:30.057430 2026] [security2:error] [pid 296703:tid 296841] [client 20.226.60.151:56312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9NFin25uliftkV1n76-QAAAAg"]
[Tue Jul 21 07:42:30.154537 2026] [security2:error] [pid 296703:tid 296940] [client 20.151.10.161:12058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/bless.php"] [unique_id "al9NFin25uliftkV1n76_AAAAGs"]
[Tue Jul 21 07:42:30.211415 2026] [security2:error] [pid 296703:tid 296848] [client 103.174.34.15:56135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NFin25uliftkV1n76_gAAAA8"]
[Tue Jul 21 07:42:30.211533 2026] [security2:error] [pid 296703:tid 296848] [client 103.174.34.15:56135] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NFin25uliftkV1n76_gAAAA8"]
[Tue Jul 21 07:42:30.286882 2026] [security2:error] [pid 296703:tid 296887] [client 20.104.96.117:62944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/gecko.php"] [unique_id "al9NFin25uliftkV1n77AAAAADY"]
[Tue Jul 21 07:42:30.298824 2026] [security2:error] [pid 296703:tid 296888] [client 20.226.60.151:62318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/fffm.php"] [unique_id "al9NFin25uliftkV1n77AQAAADc"]
[Tue Jul 21 07:42:30.609571 2026] [security2:error] [pid 254995:tid 255146] [client 20.104.96.117:64035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/82.php"] [unique_id "al9NFv7v0rlcEGmVraFlFwAAAzM"]
[Tue Jul 21 07:42:30.671070 2026] [security2:error] [pid 254995:tid 255266] [client 20.220.225.223:5249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/cro.php"] [unique_id "al9NFv7v0rlcEGmVraFlGQAAA5A"]
[Tue Jul 21 07:42:30.673475 2026] [security2:error] [pid 296703:tid 296902] [client 20.197.195.24:44692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/1c.php"] [unique_id "al9NFin25uliftkV1n77CAAAAEU"]
[Tue Jul 21 07:42:30.748445 2026] [security2:error] [pid 296703:tid 296875] [client 20.226.60.151:50919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/122.php"] [unique_id "al9NFin25uliftkV1n77CwAAACo"]
[Tue Jul 21 07:42:30.790294 2026] [security2:error] [pid 296703:tid 296769] [remote 38.242.157.30:34070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "liranesuliano.acupunturaebemestar.com.br"] [uri "/wp-login.php"] [unique_id "al9NFin25uliftkV1n77DQAAQUE"]
[Tue Jul 21 07:42:30.804248 2026] [security2:error] [pid 254995:tid 255162] [client 202.143.127.214:50536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NFv7v0rlcEGmVraFlGwAAA0M"]
[Tue Jul 21 07:42:30.804372 2026] [security2:error] [pid 254995:tid 255162] [client 202.143.127.214:50536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NFv7v0rlcEGmVraFlGwAAA0M"]
[Tue Jul 21 07:42:30.916201 2026] [security2:error] [pid 296703:tid 296860] [client 20.104.96.117:64014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/admin.php"] [unique_id "al9NFin25uliftkV1n77DwAAABs"]
[Tue Jul 21 07:42:31.196625 2026] [security2:error] [pid 296703:tid 296878] [client 106.215.181.8:3222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NFyn25uliftkV1n77EAAAAC0"]
[Tue Jul 21 07:42:31.196773 2026] [security2:error] [pid 296703:tid 296878] [client 106.215.181.8:3222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NFyn25uliftkV1n77EAAAAC0"]
[Tue Jul 21 07:42:31.210023 2026] [security2:error] [pid 254995:tid 255217] [client 74.249.245.134:5544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/plugins.php"] [unique_id "al9NF_7v0rlcEGmVraFlJQAAA3k"]
[Tue Jul 21 07:42:31.254589 2026] [security2:error] [pid 296703:tid 296896] [client 20.104.96.117:62923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/adminner.php"] [unique_id "al9NFyn25uliftkV1n77EwAAAD8"]
[Tue Jul 21 07:42:31.264338 2026] [security2:error] [pid 254995:tid 255153] [client 20.226.60.151:33506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/dfre.php"] [unique_id "al9NF_7v0rlcEGmVraFlJwAAAzo"]
[Tue Jul 21 07:42:31.592315 2026] [security2:error] [pid 296703:tid 296913] [client 20.104.96.117:62948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/admin.php"] [unique_id "al9NFyn25uliftkV1n77GQAAAFA"]
[Tue Jul 21 07:42:31.603556 2026] [security2:error] [pid 254995:tid 255158] [client 20.226.60.151:54355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/155.php"] [unique_id "al9NF_7v0rlcEGmVraFlMQAAAz8"]
[Tue Jul 21 07:42:31.738975 2026] [security2:error] [pid 296703:tid 296931] [client 62.102.148.187:35008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9NFyn25uliftkV1n77GwAAAGI"]
[Tue Jul 21 07:42:31.739069 2026] [security2:error] [pid 296703:tid 296931] [client 62.102.148.187:35008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9NFyn25uliftkV1n77GwAAAGI"]
[Tue Jul 21 07:42:31.740298 2026] [security2:error] [pid 296703:tid 296927] [client 20.197.195.24:44751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/test2.php"] [unique_id "al9NFyn25uliftkV1n77HAAAAF4"]
[Tue Jul 21 07:42:31.741501 2026] [security2:error] [pid 296703:tid 296844] [client 74.249.245.134:54339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/jp.php"] [unique_id "al9NFyn25uliftkV1n77HQAAAAs"]
[Tue Jul 21 07:42:31.899953 2026] [security2:error] [pid 254995:tid 255189] [client 20.226.60.151:50908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/mds.php"] [unique_id "al9NF_7v0rlcEGmVraFlNwAAA14"]
[Tue Jul 21 07:42:31.917061 2026] [security2:error] [pid 296703:tid 296845] [client 20.104.96.117:62922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/k.php"] [unique_id "al9NFyn25uliftkV1n77HwAAAAw"]
[Tue Jul 21 07:42:32.063277 2026] [autoindex:error] [pid 254995:tid 255196] [client 205.210.31.250:62288] AH01276: Cannot serve directory /home1/bastar15/mirth.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:32.117137 2026] [security2:error] [pid 296703:tid 296772] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NGCn25uliftkV1n77IgAAZEQ"]
[Tue Jul 21 07:42:32.117314 2026] [security2:error] [pid 296703:tid 296933] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NGCn25uliftkV1n77IgAAZEQ"]
[Tue Jul 21 07:42:32.229644 2026] [security2:error] [pid 296703:tid 296932] [client 20.104.96.117:62939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/blurbs.php"] [unique_id "al9NGCn25uliftkV1n77IwAAAGM"]
[Tue Jul 21 07:42:32.277575 2026] [security2:error] [pid 296703:tid 296773] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NGCn25uliftkV1n77JQAAcEU"]
[Tue Jul 21 07:42:32.277692 2026] [security2:error] [pid 296703:tid 296945] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NGCn25uliftkV1n77JQAAcEU"]
[Tue Jul 21 07:42:32.393825 2026] [security2:error] [pid 296703:tid 296852] [client 20.151.10.161:12040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file46.php"] [unique_id "al9NGCn25uliftkV1n77KAAAABM"]
[Tue Jul 21 07:42:32.489712 2026] [security2:error] [pid 254995:tid 255216] [client 20.220.225.223:19326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/billur.php"] [unique_id "al9NGP7v0rlcEGmVraFlQAAAA3g"]
[Tue Jul 21 07:42:32.527419 2026] [security2:error] [pid 254995:tid 255266] [client 20.104.96.117:64021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/bajah.php"] [unique_id "al9NGP7v0rlcEGmVraFlRwAAA5A"]
[Tue Jul 21 07:42:32.651462 2026] [security2:error] [pid 254995:tid 255156] [client 20.220.225.223:34477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/billur.php"] [unique_id "al9NGP7v0rlcEGmVraFlSAAAAz0"]
[Tue Jul 21 07:42:32.831289 2026] [security2:error] [pid 296703:tid 296876] [client 20.226.60.151:54272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ops.php"] [unique_id "al9NGCn25uliftkV1n77KwAAACs"]
[Tue Jul 21 07:42:32.865962 2026] [security2:error] [pid 296703:tid 296957] [client 182.8.255.181:21082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NGCn25uliftkV1n77LAAAAHw"]
[Tue Jul 21 07:42:32.866131 2026] [security2:error] [pid 296703:tid 296957] [client 182.8.255.181:21082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NGCn25uliftkV1n77LAAAAHw"]
[Tue Jul 21 07:42:32.881161 2026] [security2:error] [pid 254995:tid 255157] [client 117.251.86.144:41398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NGP7v0rlcEGmVraFlSQAAAz4"]
[Tue Jul 21 07:42:32.881285 2026] [security2:error] [pid 254995:tid 255157] [client 117.251.86.144:41398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NGP7v0rlcEGmVraFlSQAAAz4"]
[Tue Jul 21 07:42:32.892911 2026] [security2:error] [pid 254995:tid 255191] [client 20.104.96.117:62945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/a.php"] [unique_id "al9NGP7v0rlcEGmVraFlSgAAA2A"]
[Tue Jul 21 07:42:32.946384 2026] [security2:error] [pid 254995:tid 255139] [client 74.249.245.134:54358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/error.php"] [unique_id "al9NGP7v0rlcEGmVraFlTQAAAyw"]
[Tue Jul 21 07:42:32.976708 2026] [security2:error] [pid 254995:tid 255133] [client 20.226.60.151:62294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-happy.php"] [unique_id "al9NGP7v0rlcEGmVraFlTwAAAyY"]
[Tue Jul 21 07:42:33.031582 2026] [security2:error] [pid 296703:tid 296842] [client 122.186.204.214:56394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NGSn25uliftkV1n77MAAAAAk"]
[Tue Jul 21 07:42:33.031699 2026] [security2:error] [pid 296703:tid 296842] [client 122.186.204.214:56394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NGSn25uliftkV1n77MAAAAAk"]
[Tue Jul 21 07:42:33.057457 2026] [security2:error] [pid 254995:tid 255141] [client 136.144.33.241:20301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NGf7v0rlcEGmVraFlUgAAAy4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:33.190623 2026] [security2:error] [pid 296703:tid 296897] [client 20.104.96.117:64042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/edit.php"] [unique_id "al9NGSn25uliftkV1n77MgAAAEA"]
[Tue Jul 21 07:42:33.195131 2026] [security2:error] [pid 296703:tid 296881] [client 122.164.127.47:54630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NGSn25uliftkV1n77NAAAADA"]
[Tue Jul 21 07:42:33.200117 2026] [security2:error] [pid 296703:tid 296881] [client 122.164.127.47:54630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NGSn25uliftkV1n77NAAAADA"]
[Tue Jul 21 07:42:33.338438 2026] [security2:error] [pid 296703:tid 296834] [client 20.197.195.24:44679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/buy.php"] [unique_id "al9NGSn25uliftkV1n77NwAAAAE"]
[Tue Jul 21 07:42:33.462878 2026] [security2:error] [pid 296703:tid 296867] [client 103.86.117.203:53464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NGSn25uliftkV1n77PgAAACI"]
[Tue Jul 21 07:42:33.463040 2026] [security2:error] [pid 296703:tid 296867] [client 103.86.117.203:53464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NGSn25uliftkV1n77PgAAACI"]
[Tue Jul 21 07:42:33.489409 2026] [security2:error] [pid 254995:tid 255170] [client 20.104.96.117:64024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/hosty.php"] [unique_id "al9NGf7v0rlcEGmVraFlVgAAA0s"]
[Tue Jul 21 07:42:33.757700 2026] [security2:error] [pid 254995:tid 255128] [client 20.220.225.223:34288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/mimpi.php"] [unique_id "al9NGf7v0rlcEGmVraFlYQAAAyE"]
[Tue Jul 21 07:42:33.788114 2026] [security2:error] [pid 254995:tid 255143] [client 74.249.245.134:5512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/classwithtostring.php"] [unique_id "al9NGf7v0rlcEGmVraFlYgAAAzA"]
[Tue Jul 21 07:42:33.808452 2026] [security2:error] [pid 254995:tid 255189] [client 20.226.60.151:56269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/w1px.php"] [unique_id "al9NGf7v0rlcEGmVraFlYwAAA14"]
[Tue Jul 21 07:42:34.033992 2026] [security2:error] [pid 254995:tid 255196] [client 20.104.96.117:62953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/k.php"] [unique_id "al9NGv7v0rlcEGmVraFlaAAAA2U"]
[Tue Jul 21 07:42:34.204463 2026] [security2:error] [pid 296703:tid 296781] [remote 54.39.210.143:47202] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.odontoclinicms.com.br"] [uri "/robots.txt"] [unique_id "al9NGin25uliftkV1n77SAAAUk0"]
[Tue Jul 21 07:42:34.204679 2026] [security2:error] [pid 296703:tid 296915] [client 54.39.210.143:47202] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.odontoclinicms.com.br"] [uri "/robots.txt"] [unique_id "al9NGin25uliftkV1n77SAAAUk0"]
[Tue Jul 21 07:42:34.251367 2026] [security2:error] [pid 296703:tid 296913] [client 20.226.60.151:59405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-blink.php"] [unique_id "al9NGin25uliftkV1n77SgAAAFA"]
[Tue Jul 21 07:42:34.401217 2026] [security2:error] [pid 296703:tid 296914] [client 20.104.96.117:62916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/aaa.php"] [unique_id "al9NGin25uliftkV1n77TQAAAFE"]
[Tue Jul 21 07:42:34.427624 2026] [security2:error] [pid 296703:tid 296836] [client 37.140.223.157:44717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NGCn25uliftkV1n77JAAAAAM"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:42:34.562222 2026] [security2:error] [pid 296703:tid 296942] [client 20.226.60.151:54359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/file31.php"] [unique_id "al9NGin25uliftkV1n77TwAAAG0"]
[Tue Jul 21 07:42:34.595190 2026] [security2:error] [pid 254995:tid 255157] [client 20.226.60.151:33483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/fpr4.php"] [unique_id "al9NGv7v0rlcEGmVraFleQAAAz4"]
[Tue Jul 21 07:42:34.597268 2026] [security2:error] [pid 296703:tid 296909] [client 154.192.233.199:59657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NGin25uliftkV1n77UAAAAEw"]
[Tue Jul 21 07:42:34.597422 2026] [security2:error] [pid 296703:tid 296909] [client 154.192.233.199:59657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NGin25uliftkV1n77UAAAAEw"]
[Tue Jul 21 07:42:34.795699 2026] [security2:error] [pid 254995:tid 255258] [client 20.104.96.117:62921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/file5.php"] [unique_id "al9NGv7v0rlcEGmVraFlfQAAA4g"]
[Tue Jul 21 07:42:34.838483 2026] [security2:error] [pid 254995:tid 255141] [client 62.102.148.187:35022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9NGv7v0rlcEGmVraFlfwAAAy4"]
[Tue Jul 21 07:42:34.838595 2026] [security2:error] [pid 254995:tid 255141] [client 62.102.148.187:35022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9NGv7v0rlcEGmVraFlfwAAAy4"]
[Tue Jul 21 07:42:34.980643 2026] [security2:error] [pid 254995:tid 255028] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NGv7v0rlcEGmVraFlgAADNyA"]
[Tue Jul 21 07:42:34.980835 2026] [security2:error] [pid 254995:tid 255150] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NGv7v0rlcEGmVraFlgAADNyA"]
[Tue Jul 21 07:42:35.031230 2026] [security2:error] [pid 296703:tid 296883] [client 20.197.195.24:44678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/ssend.php"] [unique_id "al9NGyn25uliftkV1n77WAAAADI"]
[Tue Jul 21 07:42:35.184114 2026] [security2:error] [pid 296703:tid 296865] [client 20.104.96.117:64002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/222.php"] [unique_id "al9NGyn25uliftkV1n77XAAAACA"]
[Tue Jul 21 07:42:35.238683 2026] [security2:error] [pid 296703:tid 296842] [client 20.104.96.117:30871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/aunmc.php"] [unique_id "al9NGyn25uliftkV1n77XgAAAAk"]
[Tue Jul 21 07:42:35.278850 2026] [security2:error] [pid 296703:tid 296951] [client 114.119.133.30:43211] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hometohomelondon.com"] [uri "/en/servico/corporate-services"] [unique_id "al9NGyn25uliftkV1n77XwAAAHY"], referer: https://hometohomelondon.com/en/services
[Tue Jul 21 07:42:35.465090 2026] [security2:error] [pid 296703:tid 296837] [client 20.104.96.117:5071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/test.php"] [unique_id "al9NGyn25uliftkV1n77ZQAAAAQ"]
[Tue Jul 21 07:42:35.737365 2026] [security2:error] [pid 296703:tid 296790] [remote 167.114.139.77:18858] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.odontoclinicms.com.br"] [uri "/"] [unique_id "al9NGyn25uliftkV1n77awAARlY"]
[Tue Jul 21 07:42:35.737545 2026] [security2:error] [pid 296703:tid 296903] [client 167.114.139.77:18858] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.odontoclinicms.com.br"] [uri "/"] [unique_id "al9NGyn25uliftkV1n77awAARlY"]
[Tue Jul 21 07:42:35.763381 2026] [security2:error] [pid 296703:tid 296905] [client 74.249.245.134:5538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/bless.php"] [unique_id "al9NGyn25uliftkV1n77bAAAAEg"]
[Tue Jul 21 07:42:35.767171 2026] [security2:error] [pid 296703:tid 296898] [client 20.104.96.117:62916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/aaa.php"] [unique_id "al9NGyn25uliftkV1n77bQAAAEE"]
[Tue Jul 21 07:42:35.870866 2026] [security2:error] [pid 296703:tid 296879] [client 20.151.10.161:55264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/eee.php"] [unique_id "al9NGyn25uliftkV1n77bgAAAC4"]
[Tue Jul 21 07:42:35.923675 2026] [security2:error] [pid 296703:tid 296855] [client 20.226.60.151:33484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/file88.php"] [unique_id "al9NGyn25uliftkV1n77bwAAABY"]
[Tue Jul 21 07:42:36.099395 2026] [security2:error] [pid 296703:tid 296955] [client 20.104.96.117:64001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/11.php"] [unique_id "al9NHCn25uliftkV1n77cgAAAHo"]
[Tue Jul 21 07:42:36.111360 2026] [security2:error] [pid 254995:tid 255087] [remote 116.179.33.17:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.33.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9NHP7v0rlcEGmVraFlkgADWFs"], referer: https://androapkmod.com/luna-re-dimensional-watcher-apk-mod/
[Tue Jul 21 07:42:36.293868 2026] [security2:error] [pid 296703:tid 296867] [client 117.217.38.194:49744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NHCn25uliftkV1n77dAAAACI"]
[Tue Jul 21 07:42:36.293962 2026] [security2:error] [pid 296703:tid 296867] [client 117.217.38.194:49744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NHCn25uliftkV1n77dAAAACI"]
[Tue Jul 21 07:42:36.414338 2026] [security2:error] [pid 296703:tid 296952] [client 20.104.96.117:5068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/mac.php"] [unique_id "al9NHCn25uliftkV1n77fwAAAHc"]
[Tue Jul 21 07:42:36.477539 2026] [security2:error] [pid 296703:tid 296909] [client 20.226.60.151:54393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/file6.php"] [unique_id "al9NHCn25uliftkV1n77hQAAAEw"]
[Tue Jul 21 07:42:36.513503 2026] [security2:error] [pid 296703:tid 296956] [client 20.220.225.223:34285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/dp.php"] [unique_id "al9NHCn25uliftkV1n77hgAAAHs"]
[Tue Jul 21 07:42:36.595907 2026] [security2:error] [pid 254995:tid 255158] [client 152.59.154.239:54453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NHP7v0rlcEGmVraFlkwAAAz8"]
[Tue Jul 21 07:42:36.610493 2026] [security2:error] [pid 254995:tid 255158] [client 152.59.154.239:54453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NHP7v0rlcEGmVraFlkwAAAz8"]
[Tue Jul 21 07:42:36.732397 2026] [security2:error] [pid 296703:tid 296856] [client 103.106.20.201:52577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NHCn25uliftkV1n77lgAAABc"]
[Tue Jul 21 07:42:36.732499 2026] [security2:error] [pid 296703:tid 296861] [client 20.104.96.117:62946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/chosen.php"] [unique_id "al9NHCn25uliftkV1n77lQAAABw"]
[Tue Jul 21 07:42:36.732526 2026] [security2:error] [pid 296703:tid 296856] [client 103.106.20.201:52577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NHCn25uliftkV1n77lgAAABc"]
[Tue Jul 21 07:42:36.732973 2026] [security2:error] [pid 296703:tid 296960] [client 20.197.195.24:13639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/item.php"] [unique_id "al9NHCn25uliftkV1n77lwAAAH8"]
[Tue Jul 21 07:42:36.748663 2026] [security2:error] [pid 296703:tid 296846] [client 20.226.60.151:22346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/0.php"] [unique_id "al9NHCn25uliftkV1n77mQAAAA0"]
[Tue Jul 21 07:42:36.765732 2026] [security2:error] [pid 296703:tid 296897] [client 136.144.33.29:65447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NHCn25uliftkV1n77mgAAAEA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:36.981187 2026] [security2:error] [pid 296703:tid 296888] [client 74.249.245.134:5562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/storage/index.php"] [unique_id "al9NHCn25uliftkV1n77nAAAADc"]
[Tue Jul 21 07:42:37.072962 2026] [autoindex:error] [pid 296703:tid 296875] [client 20.226.60.151:54282] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:37.088063 2026] [security2:error] [pid 296703:tid 296907] [client 20.104.96.117:62914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/cream1.php"] [unique_id "al9NHSn25uliftkV1n77oAAAAEo"]
[Tue Jul 21 07:42:37.299866 2026] [security2:error] [pid 296703:tid 296858] [client 122.162.144.145:3405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NHSn25uliftkV1n77rQAAABk"]
[Tue Jul 21 07:42:37.300006 2026] [security2:error] [pid 296703:tid 296858] [client 122.162.144.145:3405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NHSn25uliftkV1n77rQAAABk"]
[Tue Jul 21 07:42:37.443031 2026] [security2:error] [pid 296703:tid 296923] [client 20.226.60.151:54282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/adminfuns.php"] [unique_id "al9NHSn25uliftkV1n77tAAAAFo"]
[Tue Jul 21 07:42:37.461045 2026] [security2:error] [pid 296703:tid 296836] [client 20.226.60.151:33490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/ccc.php"] [unique_id "al9NHSn25uliftkV1n77tQAAAAM"]
[Tue Jul 21 07:42:37.621421 2026] [security2:error] [pid 296703:tid 296852] [client 20.220.225.223:34187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/bootstrap.php"] [unique_id "al9NHSn25uliftkV1n77vwAAABM"]
[Tue Jul 21 07:42:37.673173 2026] [security2:error] [pid 296703:tid 296833] [client 20.220.225.223:34276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/track.php"] [unique_id "al9NHSn25uliftkV1n77wwAAAAA"]
[Tue Jul 21 07:42:37.953318 2026] [security2:error] [pid 296703:tid 296870] [client 128.127.105.184:51054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9NHSn25uliftkV1n77zwAAACU"]
[Tue Jul 21 07:42:37.953420 2026] [security2:error] [pid 296703:tid 296870] [client 128.127.105.184:51054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9NHSn25uliftkV1n77zwAAACU"]
[Tue Jul 21 07:42:38.011352 2026] [security2:error] [pid 296703:tid 296926] [client 20.226.60.151:54391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/goods.php"] [unique_id "al9NHin25uliftkV1n770QAAAF0"]
[Tue Jul 21 07:42:38.056904 2026] [security2:error] [pid 296703:tid 296857] [client 20.226.60.151:59442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/zc-208.php"] [unique_id "al9NHin25uliftkV1n770wAAABg"]
[Tue Jul 21 07:42:38.093439 2026] [security2:error] [pid 296703:tid 296886] [client 20.104.96.117:64039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/dr.php"] [unique_id "al9NHin25uliftkV1n771AAAADU"]
[Tue Jul 21 07:42:38.111787 2026] [security2:error] [pid 296703:tid 296913] [client 139.167.225.182:49945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NHin25uliftkV1n771QAAAFA"]
[Tue Jul 21 07:42:38.111923 2026] [security2:error] [pid 296703:tid 296913] [client 139.167.225.182:49945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NHin25uliftkV1n771QAAAFA"]
[Tue Jul 21 07:42:38.311523 2026] [security2:error] [pid 296703:tid 296936] [client 59.96.220.140:57808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NHin25uliftkV1n774AAAAGc"]
[Tue Jul 21 07:42:38.311640 2026] [security2:error] [pid 296703:tid 296936] [client 59.96.220.140:57808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NHin25uliftkV1n774AAAAGc"]
[Tue Jul 21 07:42:38.321144 2026] [security2:error] [pid 296703:tid 296887] [client 20.151.10.161:11746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file25.php"] [unique_id "al9NHin25uliftkV1n774QAAADY"]
[Tue Jul 21 07:42:38.432722 2026] [security2:error] [pid 296703:tid 296858] [client 20.104.96.117:64051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/x.php"] [unique_id "al9NHin25uliftkV1n774wAAABk"]
[Tue Jul 21 07:42:38.552765 2026] [security2:error] [pid 296703:tid 296860] [client 172.202.118.31:55476] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "162.241.63.69"] [uri "/index.cgi"] [unique_id "al9NHin25uliftkV1n776wAAABs"]
[Tue Jul 21 07:42:38.613957 2026] [security2:error] [pid 296703:tid 296894] [client 20.226.60.151:56313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/yawa.php"] [unique_id "al9NHin25uliftkV1n777QAAAD0"]
[Tue Jul 21 07:42:38.619465 2026] [security2:error] [pid 296703:tid 296912] [client 37.140.223.152:38659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NHin25uliftkV1n775gAAAE8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:42:38.728660 2026] [security2:error] [pid 296703:tid 296851] [client 20.104.96.117:64057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/155.php"] [unique_id "al9NHin25uliftkV1n778QAAABI"]
[Tue Jul 21 07:42:38.930141 2026] [security2:error] [pid 296703:tid 296907] [client 122.179.91.63:18992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NHin25uliftkV1n77_gAAAEo"]
[Tue Jul 21 07:42:38.930279 2026] [security2:error] [pid 296703:tid 296907] [client 122.179.91.63:18992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NHin25uliftkV1n77_gAAAEo"]
[Tue Jul 21 07:42:39.017400 2026] [security2:error] [pid 296703:tid 296717] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NHyn25uliftkV1n78AAAAEw0"]
[Tue Jul 21 07:42:39.017582 2026] [security2:error] [pid 296703:tid 296852] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NHyn25uliftkV1n78AAAAEw0"]
[Tue Jul 21 07:42:39.072788 2026] [security2:error] [pid 296703:tid 296960] [client 20.104.96.117:64023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/ops.php"] [unique_id "al9NHyn25uliftkV1n78AgAAAH8"]
[Tue Jul 21 07:42:39.120391 2026] [security2:error] [pid 296703:tid 296722] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NHyn25uliftkV1n78AwAACRI"]
[Tue Jul 21 07:42:39.120589 2026] [security2:error] [pid 296703:tid 296842] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NHyn25uliftkV1n78AwAACRI"]
[Tue Jul 21 07:42:39.218747 2026] [security2:error] [pid 296703:tid 296926] [client 74.249.245.134:5528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/g.php"] [unique_id "al9NHyn25uliftkV1n78BwAAAF0"]
[Tue Jul 21 07:42:39.427481 2026] [security2:error] [pid 296703:tid 296879] [client 20.226.60.151:54383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/100.php"] [unique_id "al9NHyn25uliftkV1n78EQAAAC4"]
[Tue Jul 21 07:42:39.547600 2026] [security2:error] [pid 296703:tid 296937] [client 20.104.96.117:64058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/file31.php"] [unique_id "al9NHyn25uliftkV1n78FwAAAGg"]
[Tue Jul 21 07:42:39.678505 2026] [autoindex:error] [pid 296703:tid 296730] [remote 74.7.227.20:38772] AH01276: Cannot serve directory /home2/bavosc49/gratech.bavos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:39.741514 2026] [security2:error] [pid 296703:tid 296858] [client 74.7.228.22:41110] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "gratech.bavos.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9NHyn25uliftkV1n78GwAAGSM"]
[Tue Jul 21 07:42:39.812989 2026] [security2:error] [pid 296703:tid 296930] [client 20.197.195.24:44737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/ss.php"] [unique_id "al9NHyn25uliftkV1n78IgAAAGE"]
[Tue Jul 21 07:42:39.821055 2026] [security2:error] [pid 296703:tid 296851] [client 20.220.225.223:19672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/mimpi.php"] [unique_id "al9NHyn25uliftkV1n78JQAAABI"]
[Tue Jul 21 07:42:39.884506 2026] [security2:error] [pid 296703:tid 296878] [client 20.104.96.117:64055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/file6.php"] [unique_id "al9NHyn25uliftkV1n78KQAAAC0"]
[Tue Jul 21 07:42:39.885062 2026] [security2:error] [pid 296703:tid 296876] [client 20.226.60.151:62248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/777.php"] [unique_id "al9NHyn25uliftkV1n78KgAAACs"]
[Tue Jul 21 07:42:39.954194 2026] [security2:error] [pid 296703:tid 296938] [client 173.24.185.52:55525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NHyn25uliftkV1n78KwAAAGk"]
[Tue Jul 21 07:42:39.954314 2026] [security2:error] [pid 296703:tid 296938] [client 173.24.185.52:55525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NHyn25uliftkV1n78KwAAAGk"]
[Tue Jul 21 07:42:40.346391 2026] [security2:error] [pid 296703:tid 296844] [client 103.166.103.129:8421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NICn25uliftkV1n78MgAAAAs"]
[Tue Jul 21 07:42:40.353005 2026] [security2:error] [pid 296703:tid 296844] [client 103.166.103.129:8421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NICn25uliftkV1n78MgAAAAs"]
[Tue Jul 21 07:42:40.569594 2026] [security2:error] [pid 296703:tid 296906] [client 20.151.10.161:55279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file48.php"] [unique_id "al9NICn25uliftkV1n78PAAAAEk"]
[Tue Jul 21 07:42:40.596045 2026] [security2:error] [pid 296703:tid 296913] [client 20.104.96.117:64013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/adminfuns.php"] [unique_id "al9NICn25uliftkV1n78PgAAAFA"]
[Tue Jul 21 07:42:40.677439 2026] [security2:error] [pid 296703:tid 296951] [client 172.245.102.34:35355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NICn25uliftkV1n78QQAAAHY"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:42:40.785214 2026] [security2:error] [pid 296703:tid 296905] [client 20.226.60.151:59472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/sid4.php"] [unique_id "al9NICn25uliftkV1n78RQAAAEg"]
[Tue Jul 21 07:42:40.820248 2026] [security2:error] [pid 296703:tid 296887] [client 20.226.60.151:54330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/about.php"] [unique_id "al9NICn25uliftkV1n78SgAAADY"]
[Tue Jul 21 07:42:40.858925 2026] [security2:error] [pid 296703:tid 296942] [client 20.104.96.117:30849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/uoocf.php"] [unique_id "al9NICn25uliftkV1n78TwAAAG0"]
[Tue Jul 21 07:42:40.991377 2026] [security2:error] [pid 296703:tid 296920] [client 103.174.34.15:56614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NICn25uliftkV1n78WgAAAFc"]
[Tue Jul 21 07:42:40.991554 2026] [security2:error] [pid 296703:tid 296920] [client 103.174.34.15:56614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NICn25uliftkV1n78WgAAAFc"]
[Tue Jul 21 07:42:40.994147 2026] [security2:error] [pid 296703:tid 296929] [client 74.249.245.134:5522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/nf.php"] [unique_id "al9NICn25uliftkV1n78WwAAAGA"]
[Tue Jul 21 07:42:41.117645 2026] [security2:error] [pid 296703:tid 296871] [client 20.220.225.223:34230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/wp-editor.php"] [unique_id "al9NISn25uliftkV1n78YwAAACY"]
[Tue Jul 21 07:42:41.181913 2026] [security2:error] [pid 296703:tid 296928] [client 20.104.96.117:64053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/goods.php"] [unique_id "al9NISn25uliftkV1n78ZAAAAF8"]
[Tue Jul 21 07:42:41.405739 2026] [security2:error] [pid 296703:tid 296834] [client 20.226.60.151:54305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/about.php"] [unique_id "al9NISn25uliftkV1n78bAAAAAE"]
[Tue Jul 21 07:42:41.425551 2026] [security2:error] [pid 296703:tid 296943] [client 37.140.223.68:55275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NISn25uliftkV1n78bwAAAG4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:41.446675 2026] [security2:error] [pid 296703:tid 296857] [client 20.197.195.24:44726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/hypo.php"] [unique_id "al9NISn25uliftkV1n78cAAAABg"]
[Tue Jul 21 07:42:41.471514 2026] [security2:error] [pid 296703:tid 296945] [client 2.57.168.7:58193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.168.57.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cursosonlinesiteoficial.com"] [uri "/wp-login.php"] [unique_id "al9NISn25uliftkV1n78cQAAAHA"]
[Tue Jul 21 07:42:41.513729 2026] [security2:error] [pid 296703:tid 296884] [client 20.104.96.117:62942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/100.php"] [unique_id "al9NISn25uliftkV1n78cwAAADM"]
[Tue Jul 21 07:42:41.726671 2026] [security2:error] [pid 296703:tid 296858] [client 74.7.175.173:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "solucaomodular.com.br"] [uri "/index.php"] [unique_id "al9NICn25uliftkV1n78UgAAABk"]
[Tue Jul 21 07:42:41.727575 2026] [security2:error] [pid 296703:tid 296879] [client 74.7.175.173:44524] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "solucaomodular.com.br"] [uri "/robots.txt"] [unique_id "al9NICn25uliftkV1n78TQAALjU"]
[Tue Jul 21 07:42:41.765475 2026] [security2:error] [pid 296703:tid 296891] [client 20.220.225.223:32259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/wp-explorer.php"] [unique_id "al9NISn25uliftkV1n78eAAAADo"]
[Tue Jul 21 07:42:41.791261 2026] [proxy:error] [pid 296703:tid 296927] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:42:41.791310 2026] [proxy_http:error] [pid 296703:tid 296927] [client 20.226.60.151:59429] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:42:41.792208 2026] [proxy:error] [pid 296703:tid 296927] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:42:41.792245 2026] [proxy_http:error] [pid 296703:tid 296927] [client 20.226.60.151:59429] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:42:41.825377 2026] [security2:error] [pid 296703:tid 296893] [client 20.104.96.117:64018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/about.php"] [unique_id "al9NISn25uliftkV1n78fAAAADw"]
[Tue Jul 21 07:42:41.870073 2026] [security2:error] [pid 296703:tid 296767] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NISn25uliftkV1n78dQAAfz8"]
[Tue Jul 21 07:42:41.870335 2026] [security2:error] [pid 296703:tid 296960] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NISn25uliftkV1n78dQAAfz8"]
[Tue Jul 21 07:42:41.876643 2026] [security2:error] [pid 296703:tid 296847] [client 106.215.181.8:19843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NISn25uliftkV1n78fQAAAA4"]
[Tue Jul 21 07:42:41.876731 2026] [security2:error] [pid 296703:tid 296847] [client 106.215.181.8:19843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NISn25uliftkV1n78fQAAAA4"]
[Tue Jul 21 07:42:42.020000 2026] [security2:error] [pid 296703:tid 296939] [client 20.151.10.161:53599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file6.php"] [unique_id "al9NIin25uliftkV1n78iAAAAGo"]
[Tue Jul 21 07:42:42.308765 2026] [security2:error] [pid 296703:tid 296895] [client 20.104.96.117:5099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/about.php"] [unique_id "al9NIin25uliftkV1n78jgAAAD4"]
[Tue Jul 21 07:42:42.399382 2026] [security2:error] [pid 296703:tid 296917] [client 202.143.127.214:50981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NIin25uliftkV1n78kAAAAFQ"]
[Tue Jul 21 07:42:42.399538 2026] [security2:error] [pid 296703:tid 296917] [client 202.143.127.214:50981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NIin25uliftkV1n78kAAAAFQ"]
[Tue Jul 21 07:42:42.610531 2026] [security2:error] [pid 296703:tid 296856] [client 20.104.96.117:62932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/admin.php"] [unique_id "al9NIin25uliftkV1n78mgAAABc"]
[Tue Jul 21 07:42:42.745195 2026] [security2:error] [pid 296703:tid 296956] [client 20.197.195.24:13648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/users.php"] [unique_id "al9NIin25uliftkV1n78mwAAAHs"]
[Tue Jul 21 07:42:42.770426 2026] [security2:error] [pid 296703:tid 296785] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NIin25uliftkV1n78nQAAS1E"]
[Tue Jul 21 07:42:42.770581 2026] [security2:error] [pid 296703:tid 296908] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NIin25uliftkV1n78nQAAS1E"]
[Tue Jul 21 07:42:42.776616 2026] [security2:error] [pid 296703:tid 296884] [client 74.249.245.134:54376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/xda.php"] [unique_id "al9NIin25uliftkV1n78ngAAADM"]
[Tue Jul 21 07:42:42.867681 2026] [security2:error] [pid 296703:tid 296789] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NIin25uliftkV1n78owAAB1U"]
[Tue Jul 21 07:42:42.867831 2026] [security2:error] [pid 296703:tid 296840] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NIin25uliftkV1n78owAAB1U"]
[Tue Jul 21 07:42:42.918638 2026] [security2:error] [pid 296703:tid 296841] [client 20.104.96.117:62968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/admin.php"] [unique_id "al9NIin25uliftkV1n78pQAAAAg"]
[Tue Jul 21 07:42:43.089847 2026] [security2:error] [pid 296703:tid 296894] [client 20.197.195.24:44759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/177.php"] [unique_id "al9NIyn25uliftkV1n78sQAAAD0"]
[Tue Jul 21 07:42:43.193025 2026] [security2:error] [pid 296703:tid 296919] [client 20.104.96.117:30429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/iywwi.php"] [unique_id "al9NIyn25uliftkV1n78tAAAAFY"]
[Tue Jul 21 07:42:43.207941 2026] [security2:error] [pid 296703:tid 296863] [client 20.104.96.117:64045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/themes.php"] [unique_id "al9NIyn25uliftkV1n78tQAAAB4"]
[Tue Jul 21 07:42:43.243523 2026] [security2:error] [pid 296703:tid 296902] [client 20.226.60.151:56196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/js.php"] [unique_id "al9NIyn25uliftkV1n78tgAAAEU"]
[Tue Jul 21 07:42:43.245986 2026] [security2:error] [pid 296703:tid 296939] [client 20.197.195.24:44712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/config.php"] [unique_id "al9NIyn25uliftkV1n78twAAAGo"]
[Tue Jul 21 07:42:43.310834 2026] [security2:error] [pid 296703:tid 296903] [client 182.8.255.181:17557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NIyn25uliftkV1n78uAAAAEY"]
[Tue Jul 21 07:42:43.310935 2026] [security2:error] [pid 296703:tid 296903] [client 182.8.255.181:17557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NIyn25uliftkV1n78uAAAAEY"]
[Tue Jul 21 07:42:43.545307 2026] [security2:error] [pid 296703:tid 296834] [client 20.226.60.151:59413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wmore1.php"] [unique_id "al9NIyn25uliftkV1n78vwAAAAE"]
[Tue Jul 21 07:42:43.662088 2026] [core:error] [pid 296703:tid 296857] [client 143.198.156.18:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:42:43.662108 2026] [core:error] [pid 296703:tid 296857] [client 143.198.156.18:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:42:43.663438 2026] [security2:error] [pid 296703:tid 296855] [client 117.251.86.144:46712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NIyn25uliftkV1n78yQAAABY"]
[Tue Jul 21 07:42:43.663573 2026] [security2:error] [pid 296703:tid 296855] [client 117.251.86.144:46712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NIyn25uliftkV1n78yQAAABY"]
[Tue Jul 21 07:42:43.708282 2026] [security2:error] [pid 296703:tid 296877] [client 20.197.195.24:44758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/gettest.php"] [unique_id "al9NIyn25uliftkV1n78zAAAACw"]
[Tue Jul 21 07:42:43.725833 2026] [security2:error] [pid 296703:tid 296960] [client 122.186.204.214:56925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NIyn25uliftkV1n78zQAAAH8"]
[Tue Jul 21 07:42:43.725941 2026] [security2:error] [pid 296703:tid 296960] [client 122.186.204.214:56925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NIyn25uliftkV1n78zQAAAH8"]
[Tue Jul 21 07:42:43.940091 2026] [security2:error] [pid 296703:tid 296876] [client 103.86.117.203:54011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NIyn25uliftkV1n781AAAACs"]
[Tue Jul 21 07:42:43.940181 2026] [security2:error] [pid 296703:tid 296876] [client 103.86.117.203:54011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NIyn25uliftkV1n781AAAACs"]
[Tue Jul 21 07:42:44.006075 2026] [security2:error] [pid 296703:tid 296940] [client 20.220.225.223:32296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/akismet.php"] [unique_id "al9NJCn25uliftkV1n781gAAAGs"]
[Tue Jul 21 07:42:44.023556 2026] [security2:error] [pid 296703:tid 296806] [remote 192.241.143.148:38058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "links.principiamatematica.com"] [uri "/wp-login.php"] [unique_id "al9NJCn25uliftkV1n782wAAEGY"]
[Tue Jul 21 07:42:44.035062 2026] [security2:error] [pid 296703:tid 296922] [client 122.164.127.47:55207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NJCn25uliftkV1n783QAAAFk"]
[Tue Jul 21 07:42:44.035166 2026] [security2:error] [pid 296703:tid 296922] [client 122.164.127.47:55207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NJCn25uliftkV1n783QAAAFk"]
[Tue Jul 21 07:42:44.135755 2026] [security2:error] [pid 296703:tid 296915] [client 20.220.225.223:34266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/cro.php"] [unique_id "al9NJCn25uliftkV1n785gAAAFI"]
[Tue Jul 21 07:42:44.215315 2026] [security2:error] [pid 296703:tid 296846] [client 20.197.195.24:13782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9NJCn25uliftkV1n786gAAAA0"]
[Tue Jul 21 07:42:44.268321 2026] [security2:error] [pid 296703:tid 296842] [client 20.104.96.117:64052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/.well-known/about.php"] [unique_id "al9NJCn25uliftkV1n787wAAAAk"]
[Tue Jul 21 07:42:44.399090 2026] [security2:error] [pid 296703:tid 296837] [client 20.226.60.151:62000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/admin.php"] [unique_id "al9NJCn25uliftkV1n789QAAAAQ"]
[Tue Jul 21 07:42:44.464728 2026] [security2:error] [pid 296703:tid 296812] [remote 119.155.20.197:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.20.155.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NJCn25uliftkV1n788gAAXGw"]
[Tue Jul 21 07:42:44.464995 2026] [security2:error] [pid 296703:tid 296925] [client 119.155.20.197:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hauptmann.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NJCn25uliftkV1n788gAAXGw"]
[Tue Jul 21 07:42:44.631262 2026] [security2:error] [pid 296703:tid 296940] [client 20.104.96.117:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9NJCn25uliftkV1n79AQAAAGs"]
[Tue Jul 21 07:42:44.667286 2026] [security2:error] [pid 296703:tid 296920] [client 20.226.60.151:56214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/core.php"] [unique_id "al9NJCn25uliftkV1n79BQAAAFc"]
[Tue Jul 21 07:42:45.029770 2026] [security2:error] [pid 296703:tid 296846] [client 74.249.245.134:54380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/shell.php"] [unique_id "al9NJSn25uliftkV1n79DAAAAA0"]
[Tue Jul 21 07:42:45.038103 2026] [security2:error] [pid 296703:tid 296854] [client 20.197.195.24:13683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/min.php"] [unique_id "al9NJSn25uliftkV1n79DgAAABU"]
[Tue Jul 21 07:42:45.057470 2026] [security2:error] [pid 296703:tid 296844] [client 20.104.96.117:62974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wefile.php"] [unique_id "al9NJSn25uliftkV1n79DwAAAAs"]
[Tue Jul 21 07:42:45.187714 2026] [security2:error] [pid 296703:tid 296870] [client 20.226.60.151:50897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/solo1.php"] [unique_id "al9NJSn25uliftkV1n79GAAAACU"]
[Tue Jul 21 07:42:45.286059 2026] [security2:error] [pid 296703:tid 296942] [client 20.226.60.151:62245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/for.php"] [unique_id "al9NJSn25uliftkV1n79HAAAAG0"]
[Tue Jul 21 07:42:45.313059 2026] [security2:error] [pid 296703:tid 296849] [client 154.192.233.199:59142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NJSn25uliftkV1n79HgAAABA"]
[Tue Jul 21 07:42:45.313518 2026] [security2:error] [pid 296703:tid 296849] [client 154.192.233.199:59142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NJSn25uliftkV1n79HgAAABA"]
[Tue Jul 21 07:42:45.405703 2026] [security2:error] [pid 296703:tid 296948] [client 20.104.96.117:62950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9NJSn25uliftkV1n79HwAAAHM"]
[Tue Jul 21 07:42:45.537429 2026] [security2:error] [pid 296703:tid 296830] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NJSn25uliftkV1n79IQAAM34"]
[Tue Jul 21 07:42:45.537608 2026] [security2:error] [pid 296703:tid 296884] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NJSn25uliftkV1n79IQAAM34"]
[Tue Jul 21 07:42:45.613173 2026] [security2:error] [pid 296703:tid 296879] [client 20.226.60.151:56241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/19.php"] [unique_id "al9NJSn25uliftkV1n79JAAAAC4"]
[Tue Jul 21 07:42:45.774696 2026] [security2:error] [pid 296703:tid 296909] [client 20.104.96.117:30856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/gqgsa.php"] [unique_id "al9NJSn25uliftkV1n79KgAAAEw"]
[Tue Jul 21 07:42:46.051402 2026] [security2:error] [pid 296703:tid 296834] [client 20.151.10.161:53581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/a2.php"] [unique_id "al9NJin25uliftkV1n79MQAAAAE"]
[Tue Jul 21 07:42:46.355937 2026] [proxy:error] [pid 296703:tid 296849] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:42:46.356027 2026] [proxy_http:error] [pid 296703:tid 296849] [client 20.226.60.151:50939] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:42:46.356486 2026] [proxy:error] [pid 296703:tid 296849] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:42:46.356508 2026] [proxy_http:error] [pid 296703:tid 296849] [client 20.226.60.151:50939] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:42:46.417297 2026] [security2:error] [pid 296703:tid 296926] [client 20.226.60.151:61979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/admin.php"] [unique_id "al9NJin25uliftkV1n79QwAAAF0"]
[Tue Jul 21 07:42:46.479519 2026] [security2:error] [pid 296703:tid 296898] [client 136.144.33.102:20187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NJin25uliftkV1n79RAAAAEE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:46.489008 2026] [security2:error] [pid 296703:tid 296871] [client 20.197.195.24:44719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/dvjul.php"] [unique_id "al9NJin25uliftkV1n79RQAAACY"]
[Tue Jul 21 07:42:46.499674 2026] [security2:error] [pid 296703:tid 296724] [remote 41.76.214.143:46598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/wp-login.php"] [unique_id "al9NJin25uliftkV1n79RgAAWhQ"]
[Tue Jul 21 07:42:46.500039 2026] [security2:error] [pid 296703:tid 296905] [client 20.104.96.117:64050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wp-admin/css/colour.php"] [unique_id "al9NJin25uliftkV1n79RwAAAEg"]
[Tue Jul 21 07:42:46.741259 2026] [security2:error] [pid 296703:tid 296960] [client 20.197.195.24:13714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9NJin25uliftkV1n79UQAAAH8"]
[Tue Jul 21 07:42:46.787939 2026] [security2:error] [pid 296703:tid 296899] [client 117.217.38.194:50435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NJin25uliftkV1n79VQAAAEI"]
[Tue Jul 21 07:42:46.788060 2026] [security2:error] [pid 296703:tid 296899] [client 117.217.38.194:50435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NJin25uliftkV1n79VQAAAEI"]
[Tue Jul 21 07:42:46.842130 2026] [security2:error] [pid 296703:tid 296957] [client 20.104.96.117:64058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/8.php"] [unique_id "al9NJin25uliftkV1n79VgAAAHw"]
[Tue Jul 21 07:42:47.039675 2026] [security2:error] [pid 296703:tid 296873] [client 62.102.148.187:36238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9NJyn25uliftkV1n79WQAAACg"]
[Tue Jul 21 07:42:47.039762 2026] [security2:error] [pid 296703:tid 296873] [client 62.102.148.187:36238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9NJyn25uliftkV1n79WQAAACg"]
[Tue Jul 21 07:42:47.162088 2026] [security2:error] [pid 296703:tid 296841] [client 20.104.96.117:62955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wp-content/admin.php"] [unique_id "al9NJyn25uliftkV1n79XQAAAAg"]
[Tue Jul 21 07:42:47.306851 2026] [security2:error] [pid 296703:tid 296891] [client 20.226.60.151:50820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/cong.php"] [unique_id "al9NJyn25uliftkV1n79aQAAADo"]
[Tue Jul 21 07:42:47.440408 2026] [security2:error] [pid 296703:tid 296870] [client 20.104.96.117:62937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/f6.php"] [unique_id "al9NJyn25uliftkV1n79awAAACU"]
[Tue Jul 21 07:42:47.549055 2026] [security2:error] [pid 296703:tid 296922] [client 59.96.220.140:58324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NJyn25uliftkV1n79bQAAAFk"]
[Tue Jul 21 07:42:47.549170 2026] [security2:error] [pid 296703:tid 296922] [client 59.96.220.140:58324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NJyn25uliftkV1n79bQAAAFk"]
[Tue Jul 21 07:42:47.551653 2026] [security2:error] [pid 296703:tid 296911] [client 103.106.20.201:53164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NJyn25uliftkV1n79bAAAAE4"]
[Tue Jul 21 07:42:47.551784 2026] [security2:error] [pid 296703:tid 296911] [client 103.106.20.201:53164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NJyn25uliftkV1n79bAAAAE4"]
[Tue Jul 21 07:42:47.572365 2026] [security2:error] [pid 296703:tid 296948] [client 20.197.195.24:44725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/biufile.php"] [unique_id "al9NJyn25uliftkV1n79bgAAAHM"]
[Tue Jul 21 07:42:47.586376 2026] [security2:error] [pid 296703:tid 296923] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9NJyn25uliftkV1n79bwAAAFo"]
[Tue Jul 21 07:42:47.591287 2026] [security2:error] [pid 296703:tid 296905] [client 74.249.245.134:54343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/3.php"] [unique_id "al9NJyn25uliftkV1n79cAAAAEg"]
[Tue Jul 21 07:42:47.722559 2026] [security2:error] [pid 296703:tid 296893] [client 20.151.10.161:11774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file15.php"] [unique_id "al9NJyn25uliftkV1n79eAAAADw"]
[Tue Jul 21 07:42:47.728760 2026] [security2:error] [pid 296703:tid 296848] [client 20.104.96.117:62963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/inputs.php"] [unique_id "al9NJyn25uliftkV1n79eQAAAA8"]
[Tue Jul 21 07:42:47.826959 2026] [security2:error] [pid 296703:tid 296867] [client 20.220.225.223:34245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/2352356666.php"] [unique_id "al9NJyn25uliftkV1n79gQAAACI"]
[Tue Jul 21 07:42:47.858140 2026] [security2:error] [pid 296703:tid 296909] [client 20.226.60.151:56228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/inc.php"] [unique_id "al9NJyn25uliftkV1n79ggAAAEw"]
[Tue Jul 21 07:42:47.861095 2026] [security2:error] [pid 296703:tid 296957] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9NJyn25uliftkV1n79gwAAAHw"]
[Tue Jul 21 07:42:47.897473 2026] [security2:error] [pid 296703:tid 296874] [client 152.59.154.239:54970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NJyn25uliftkV1n79hAAAACk"]
[Tue Jul 21 07:42:47.897592 2026] [security2:error] [pid 296703:tid 296874] [client 152.59.154.239:54970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NJyn25uliftkV1n79hAAAACk"]
[Tue Jul 21 07:42:47.983938 2026] [core:error] [pid 296703:tid 296842] [client 143.198.156.18:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.newpostapp.com/
[Tue Jul 21 07:42:47.983967 2026] [core:error] [pid 296703:tid 296842] [client 143.198.156.18:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.newpostapp.com/
[Tue Jul 21 07:42:48.038589 2026] [security2:error] [pid 296703:tid 296895] [client 20.104.96.117:62975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/inputs.php"] [unique_id "al9NKCn25uliftkV1n79jAAAAD4"]
[Tue Jul 21 07:42:48.108179 2026] [security2:error] [pid 296703:tid 296849] [client 122.162.144.145:4564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NKCn25uliftkV1n79jgAAABA"]
[Tue Jul 21 07:42:48.108298 2026] [security2:error] [pid 296703:tid 296849] [client 122.162.144.145:4564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NKCn25uliftkV1n79jgAAABA"]
[Tue Jul 21 07:42:48.225473 2026] [security2:error] [pid 296703:tid 296836] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/media.php"] [unique_id "al9NKCn25uliftkV1n79kAAAAAM"]
[Tue Jul 21 07:42:48.347918 2026] [security2:error] [pid 296703:tid 296929] [client 20.104.96.117:64047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/classwithtostring.php"] [unique_id "al9NKCn25uliftkV1n79lQAAAGA"]
[Tue Jul 21 07:42:48.378072 2026] [autoindex:error] [pid 296703:tid 296917] [client 44.220.233.148:20350] AH01276: Cannot serve directory /home2/acupu265/public_html/lp.liranesuliano.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:48.426163 2026] [autoindex:error] [pid 296703:tid 296901] [client 34.78.230.243:0] AH01276: Cannot serve directory /home1/hostag18/seiac.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:48.512471 2026] [proxy:error] [pid 296703:tid 296860] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:42:48.512543 2026] [proxy_http:error] [pid 296703:tid 296860] [client 20.226.60.151:59468] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:42:48.513152 2026] [proxy:error] [pid 296703:tid 296860] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:42:48.513182 2026] [proxy_http:error] [pid 296703:tid 296860] [client 20.226.60.151:59468] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:42:48.532818 2026] [security2:error] [pid 296703:tid 296920] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/images.php"] [unique_id "al9NKCn25uliftkV1n79ogAAAFc"]
[Tue Jul 21 07:42:48.646534 2026] [security2:error] [pid 296703:tid 296884] [client 20.197.195.24:13757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/media.php"] [unique_id "al9NKCn25uliftkV1n79pAAAADM"]
[Tue Jul 21 07:42:48.770796 2026] [security2:error] [pid 296703:tid 296912] [client 20.104.96.117:5060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wp-content/themes/index.php"] [unique_id "al9NKCn25uliftkV1n79qgAAAE8"]
[Tue Jul 21 07:42:48.815426 2026] [security2:error] [pid 296703:tid 296873] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/gecko.php"] [unique_id "al9NKCn25uliftkV1n79rAAAACg"]
[Tue Jul 21 07:42:48.979741 2026] [security2:error] [pid 296703:tid 296834] [client 20.226.60.151:34001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/ssla.php"] [unique_id "al9NKCn25uliftkV1n79sQAAAAE"]
[Tue Jul 21 07:42:49.039974 2026] [security2:error] [pid 296703:tid 296938] [client 20.197.195.24:44723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/av.php"] [unique_id "al9NKSn25uliftkV1n79sgAAAGk"]
[Tue Jul 21 07:42:49.060123 2026] [security2:error] [pid 296703:tid 296889] [client 62.102.148.187:33118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9NKSn25uliftkV1n79swAAADg"]
[Tue Jul 21 07:42:49.060223 2026] [security2:error] [pid 296703:tid 296889] [client 62.102.148.187:33118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9NKSn25uliftkV1n79swAAADg"]
[Tue Jul 21 07:42:49.067087 2026] [core:error] [pid 296703:tid 296763] [remote 205.210.31.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:42:49.067103 2026] [core:error] [pid 296703:tid 296763] [remote 205.210.31.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:42:49.106675 2026] [security2:error] [pid 296703:tid 296906] [client 139.167.225.182:50590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NKSn25uliftkV1n79tgAAAEk"]
[Tue Jul 21 07:42:49.106782 2026] [security2:error] [pid 296703:tid 296906] [client 139.167.225.182:50590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NKSn25uliftkV1n79tgAAAEk"]
[Tue Jul 21 07:42:49.183390 2026] [security2:error] [pid 296703:tid 296869] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/82.php"] [unique_id "al9NKSn25uliftkV1n79uQAAACQ"]
[Tue Jul 21 07:42:49.187762 2026] [security2:error] [pid 296703:tid 296770] [remote 207.180.241.245:35468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/xmlrpc.php"] [unique_id "al9NKSn25uliftkV1n79ugAAGUI"]
[Tue Jul 21 07:42:49.187951 2026] [security2:error] [pid 296703:tid 296858] [client 207.180.241.245:35468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rlvmultiofertas.com"] [uri "/xmlrpc.php"] [unique_id "al9NKSn25uliftkV1n79ugAAGUI"]
[Tue Jul 21 07:42:49.319723 2026] [security2:error] [pid 296703:tid 296934] [client 20.151.10.161:55283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/jp.php"] [unique_id "al9NKSn25uliftkV1n79wQAAAGU"]
[Tue Jul 21 07:42:49.410873 2026] [security2:error] [pid 296703:tid 296948] [client 20.226.60.151:50882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/public/css.php"] [unique_id "al9NKSn25uliftkV1n79xgAAAHM"]
[Tue Jul 21 07:42:49.480467 2026] [security2:error] [pid 296703:tid 296936] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/admin.php"] [unique_id "al9NKSn25uliftkV1n79yAAAAGc"]
[Tue Jul 21 07:42:49.495108 2026] [security2:error] [pid 296703:tid 296848] [client 20.104.96.117:30445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/elbzl.php"] [unique_id "al9NKSn25uliftkV1n79ywAAAA8"]
[Tue Jul 21 07:42:49.603612 2026] [security2:error] [pid 296703:tid 296920] [client 20.104.96.117:64026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wp-blog.php"] [unique_id "al9NKSn25uliftkV1n79zQAAAFc"]
[Tue Jul 21 07:42:49.640458 2026] [security2:error] [pid 296703:tid 296884] [client 20.226.60.151:54301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/themes.php"] [unique_id "al9NKSn25uliftkV1n79zgAAADM"]
[Tue Jul 21 07:42:49.759123 2026] [security2:error] [pid 296703:tid 296912] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/adminner.php"] [unique_id "al9NKSn25uliftkV1n790gAAAE8"]
[Tue Jul 21 07:42:49.759419 2026] [security2:error] [pid 296703:tid 296953] [client 20.197.195.24:13775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/images.php"] [unique_id "al9NKSn25uliftkV1n790wAAAHg"]
[Tue Jul 21 07:42:49.817390 2026] [security2:error] [pid 296703:tid 296914] [client 20.226.60.151:50940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/output.php"] [unique_id "al9NKSn25uliftkV1n791wAAAFE"]
[Tue Jul 21 07:42:49.882012 2026] [security2:error] [pid 296703:tid 296928] [client 20.197.195.24:13575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/coffexium.php"] [unique_id "al9NKSn25uliftkV1n792wAAAF8"]
[Tue Jul 21 07:42:49.920872 2026] [security2:error] [pid 296703:tid 296785] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NKSn25uliftkV1n793gAAPVE"]
[Tue Jul 21 07:42:49.921031 2026] [security2:error] [pid 296703:tid 296894] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NKSn25uliftkV1n793gAAPVE"]
[Tue Jul 21 07:42:50.036231 2026] [security2:error] [pid 296703:tid 296849] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/admin.php"] [unique_id "al9NKin25uliftkV1n794wAAABA"]
[Tue Jul 21 07:42:50.207568 2026] [security2:error] [pid 296703:tid 296855] [client 74.249.245.134:54382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/mds.php"] [unique_id "al9NKin25uliftkV1n796gAAABY"]
[Tue Jul 21 07:42:50.317136 2026] [security2:error] [pid 296703:tid 296922] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/k.php"] [unique_id "al9NKin25uliftkV1n797gAAAFk"]
[Tue Jul 21 07:42:50.323631 2026] [security2:error] [pid 296703:tid 296847] [client 103.166.103.129:8857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NKin25uliftkV1n798AAAAA4"]
[Tue Jul 21 07:42:50.324039 2026] [security2:error] [pid 296703:tid 296847] [client 103.166.103.129:8857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NKin25uliftkV1n798AAAAA4"]
[Tue Jul 21 07:42:50.359113 2026] [security2:error] [pid 296703:tid 296883] [client 62.102.148.187:33128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9NKin25uliftkV1n798QAAADI"]
[Tue Jul 21 07:42:50.359198 2026] [security2:error] [pid 296703:tid 296883] [client 62.102.148.187:33128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9NKin25uliftkV1n798QAAADI"]
[Tue Jul 21 07:42:50.517674 2026] [security2:error] [pid 296703:tid 296929] [client 173.24.185.52:55995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NKin25uliftkV1n79-wAAAGA"]
[Tue Jul 21 07:42:50.517775 2026] [security2:error] [pid 296703:tid 296929] [client 173.24.185.52:55995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NKin25uliftkV1n79-wAAAGA"]
[Tue Jul 21 07:42:50.521901 2026] [security2:error] [pid 296703:tid 296887] [client 20.197.195.24:44686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/core.php"] [unique_id "al9NKin25uliftkV1n79_AAAADY"]
[Tue Jul 21 07:42:50.583698 2026] [security2:error] [pid 296703:tid 296806] [remote 43.157.224.197:54546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.224.157.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roseoliveirarose.com.br"] [uri "/wp-login.php"] [unique_id "al9NKin25uliftkV1n79_gAAGWY"]
[Tue Jul 21 07:42:50.617560 2026] [security2:error] [pid 296703:tid 296892] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/blurbs.php"] [unique_id "al9NKin25uliftkV1n79_wAAADs"]
[Tue Jul 21 07:42:50.699155 2026] [security2:error] [pid 296703:tid 296906] [client 122.179.91.63:26407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NKin25uliftkV1n7-AQAAAEk"]
[Tue Jul 21 07:42:50.699371 2026] [security2:error] [pid 296703:tid 296906] [client 122.179.91.63:26407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NKin25uliftkV1n7-AQAAAEk"]
[Tue Jul 21 07:42:50.871882 2026] [security2:error] [pid 296703:tid 296947] [client 20.226.60.151:22667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/BDKR28.php"] [unique_id "al9NKin25uliftkV1n7-CAAAAHI"]
[Tue Jul 21 07:42:50.892126 2026] [security2:error] [pid 296703:tid 296841] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/bajah.php"] [unique_id "al9NKin25uliftkV1n7-CQAAAAg"]
[Tue Jul 21 07:42:51.102638 2026] [autoindex:error] [pid 296703:tid 296934] [client 198.235.24.151:61966] AH01276: Cannot serve directory /home2/bavosc49/finance.bavos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:51.107418 2026] [security2:error] [pid 296703:tid 296891] [client 20.226.60.151:50904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-file-120.php"] [unique_id "al9NKyn25uliftkV1n7-EgAAADo"]
[Tue Jul 21 07:42:51.129373 2026] [security2:error] [pid 296703:tid 296942] [client 20.104.96.117:64030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wp-content/admin.php"] [unique_id "al9NKyn25uliftkV1n7-EwAAAG0"]
[Tue Jul 21 07:42:51.200533 2026] [security2:error] [pid 296703:tid 296854] [client 136.144.33.107:33893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NKyn25uliftkV1n7-GAAAABU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:51.231635 2026] [security2:error] [pid 296703:tid 296870] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/a.php"] [unique_id "al9NKyn25uliftkV1n7-GQAAACU"]
[Tue Jul 21 07:42:51.266491 2026] [security2:error] [pid 296703:tid 296943] [client 20.104.96.117:30433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/adjig.php"] [unique_id "al9NKyn25uliftkV1n7-GgAAAG4"]
[Tue Jul 21 07:42:51.515053 2026] [security2:error] [pid 296703:tid 296876] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/edit.php"] [unique_id "al9NKyn25uliftkV1n7-KwAAACs"]
[Tue Jul 21 07:42:51.581501 2026] [security2:error] [pid 296703:tid 296872] [client 20.197.195.24:13759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/gecko.php"] [unique_id "al9NKyn25uliftkV1n7-LQAAACc"]
[Tue Jul 21 07:42:51.592024 2026] [security2:error] [pid 296703:tid 296905] [client 20.104.96.117:62965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/ms-edit.php"] [unique_id "al9NKyn25uliftkV1n7-LwAAAEg"]
[Tue Jul 21 07:42:51.615941 2026] [security2:error] [pid 296703:tid 296932] [client 20.197.195.24:13668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/als.php"] [unique_id "al9NKyn25uliftkV1n7-MAAAAGM"]
[Tue Jul 21 07:42:51.769186 2026] [security2:error] [pid 296703:tid 296933] [client 20.226.60.151:50941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/special.php"] [unique_id "al9NKyn25uliftkV1n7-NAAAAGQ"]
[Tue Jul 21 07:42:51.801777 2026] [security2:error] [pid 296703:tid 296834] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/hosty.php"] [unique_id "al9NKyn25uliftkV1n7-NQAAAAE"]
[Tue Jul 21 07:42:51.895299 2026] [security2:error] [pid 296703:tid 296871] [client 103.174.34.15:57105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NKyn25uliftkV1n7-OAAAACY"]
[Tue Jul 21 07:42:51.895433 2026] [security2:error] [pid 296703:tid 296871] [client 103.174.34.15:57105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NKyn25uliftkV1n7-OAAAACY"]
[Tue Jul 21 07:42:52.030728 2026] [security2:error] [pid 296703:tid 296712] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NLCn25uliftkV1n7-QQAAAwg"]
[Tue Jul 21 07:42:52.030908 2026] [security2:error] [pid 296703:tid 296836] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NLCn25uliftkV1n7-QQAAAwg"]
[Tue Jul 21 07:42:52.054347 2026] [autoindex:error] [pid 296703:tid 296869] [client 20.226.60.151:54356] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:52.083627 2026] [security2:error] [pid 296703:tid 296956] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/k.php"] [unique_id "al9NLCn25uliftkV1n7-RAAAAHs"]
[Tue Jul 21 07:42:52.114666 2026] [security2:error] [pid 296703:tid 296707] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NLCn25uliftkV1n7-RQAAaQM"]
[Tue Jul 21 07:42:52.114787 2026] [security2:error] [pid 296703:tid 296938] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NLCn25uliftkV1n7-RQAAaQM"]
[Tue Jul 21 07:42:52.176280 2026] [security2:error] [pid 296703:tid 296917] [client 20.226.60.151:50913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/as.php"] [unique_id "al9NLCn25uliftkV1n7-RgAAAFQ"]
[Tue Jul 21 07:42:52.236645 2026] [autoindex:error] [pid 296703:tid 296840] [client 205.210.31.142:59266] AH01276: Cannot serve directory /home4/fabi0417/admin.powerflats.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:52.376102 2026] [security2:error] [pid 296703:tid 296912] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/aaa.php"] [unique_id "al9NLCn25uliftkV1n7-SwAAAE8"]
[Tue Jul 21 07:42:52.400559 2026] [security2:error] [pid 296703:tid 296863] [client 20.226.60.151:56277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9NLCn25uliftkV1n7-TAAAAB4"]
[Tue Jul 21 07:42:52.618465 2026] [security2:error] [pid 296703:tid 296845] [client 20.104.96.117:64046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/cgi-bin/index.php"] [unique_id "al9NLCn25uliftkV1n7-XQAAAAw"]
[Tue Jul 21 07:42:52.640833 2026] [security2:error] [pid 296703:tid 296884] [client 20.197.195.24:49863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/82.php"] [unique_id "al9NLCn25uliftkV1n7-XwAAADM"]
[Tue Jul 21 07:42:52.651286 2026] [security2:error] [pid 296703:tid 296908] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/file5.php"] [unique_id "al9NLCn25uliftkV1n7-YAAAAEs"]
[Tue Jul 21 07:42:52.712915 2026] [security2:error] [pid 296703:tid 296837] [client 20.151.10.161:55269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/f35.php"] [unique_id "al9NLCn25uliftkV1n7-YQAAAAQ"]
[Tue Jul 21 07:42:52.713910 2026] [security2:error] [pid 296703:tid 296877] [client 20.197.195.24:44762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/simple.php"] [unique_id "al9NLCn25uliftkV1n7-YgAAACw"]
[Tue Jul 21 07:42:52.771826 2026] [security2:error] [pid 296703:tid 296945] [client 106.215.181.8:32620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NLCn25uliftkV1n7-ZQAAAHA"]
[Tue Jul 21 07:42:52.771952 2026] [security2:error] [pid 296703:tid 296945] [client 106.215.181.8:32620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NLCn25uliftkV1n7-ZQAAAHA"]
[Tue Jul 21 07:42:52.783308 2026] [security2:error] [pid 296703:tid 296947] [client 74.249.245.134:5529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/archive.php"] [unique_id "al9NLCn25uliftkV1n7-ZgAAAHI"]
[Tue Jul 21 07:42:52.826801 2026] [security2:error] [pid 296703:tid 296836] [client 20.220.225.223:11170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/koiy.php"] [unique_id "al9NLCn25uliftkV1n7-ZwAAAAM"]
[Tue Jul 21 07:42:52.867046 2026] [security2:error] [pid 296703:tid 296911] [client 20.226.60.151:59471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/cgi-bin/index.php"] [unique_id "al9NLCn25uliftkV1n7-aAAAAE4"]
[Tue Jul 21 07:42:52.966776 2026] [security2:error] [pid 296703:tid 296898] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/222.php"] [unique_id "al9NLCn25uliftkV1n7-awAAAEE"]
[Tue Jul 21 07:42:53.039871 2026] [security2:error] [pid 296703:tid 296917] [client 20.220.225.223:19320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/dp.php"] [unique_id "al9NLSn25uliftkV1n7-cQAAAFQ"]
[Tue Jul 21 07:42:53.280882 2026] [security2:error] [pid 296703:tid 296923] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/test.php"] [unique_id "al9NLSn25uliftkV1n7-eAAAAFo"]
[Tue Jul 21 07:42:53.390690 2026] [security2:error] [pid 296703:tid 296960] [client 20.220.225.223:34202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/cron-tab.php"] [unique_id "al9NLSn25uliftkV1n7-ewAAAH8"]
[Tue Jul 21 07:42:53.408089 2026] [security2:error] [pid 296703:tid 296842] [client 20.226.60.151:50922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/w1px.php"] [unique_id "al9NLSn25uliftkV1n7-fgAAAAk"]
[Tue Jul 21 07:42:53.433452 2026] [security2:error] [pid 296703:tid 296733] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NLSn25uliftkV1n7-gQAAIx0"]
[Tue Jul 21 07:42:53.433647 2026] [security2:error] [pid 296703:tid 296868] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NLSn25uliftkV1n7-gQAAIx0"]
[Tue Jul 21 07:42:53.437362 2026] [security2:error] [pid 296703:tid 296933] [client 20.104.96.117:30854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/byp.php"] [unique_id "al9NLSn25uliftkV1n7-ggAAAGQ"]
[Tue Jul 21 07:42:53.445066 2026] [security2:error] [pid 296703:tid 296834] [client 20.104.96.117:64054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/BDKR28WP.php"] [unique_id "al9NLSn25uliftkV1n7-gwAAAAE"]
[Tue Jul 21 07:42:53.448868 2026] [security2:error] [pid 296703:tid 296881] [client 194.99.104.35:47300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9NLSn25uliftkV1n7-hAAAADA"]
[Tue Jul 21 07:42:53.448955 2026] [security2:error] [pid 296703:tid 296881] [client 194.99.104.35:47300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9NLSn25uliftkV1n7-hAAAADA"]
[Tue Jul 21 07:42:53.491021 2026] [security2:error] [pid 296703:tid 296899] [client 20.197.195.24:44702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/init.php"] [unique_id "al9NLSn25uliftkV1n7-hwAAAEI"]
[Tue Jul 21 07:42:53.563702 2026] [security2:error] [pid 296703:tid 296877] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/aaa.php"] [unique_id "al9NLSn25uliftkV1n7-jQAAACw"]
[Tue Jul 21 07:42:53.722078 2026] [security2:error] [pid 296703:tid 296925] [client 182.8.255.181:17591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NLSn25uliftkV1n7-lAAAAFw"]
[Tue Jul 21 07:42:53.722201 2026] [security2:error] [pid 296703:tid 296925] [client 182.8.255.181:17591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NLSn25uliftkV1n7-lAAAAFw"]
[Tue Jul 21 07:42:53.848084 2026] [security2:error] [pid 296703:tid 296838] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/11.php"] [unique_id "al9NLSn25uliftkV1n7-mQAAAAU"]
[Tue Jul 21 07:42:53.900549 2026] [security2:error] [pid 296703:tid 296737] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NLSn25uliftkV1n7-ngAATyE"]
[Tue Jul 21 07:42:53.900707 2026] [security2:error] [pid 296703:tid 296912] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NLSn25uliftkV1n7-ngAATyE"]
[Tue Jul 21 07:42:53.922779 2026] [security2:error] [pid 296703:tid 296863] [client 20.220.225.223:5258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/hp2.php"] [unique_id "al9NLSn25uliftkV1n7-oQAAAB4"]
[Tue Jul 21 07:42:53.947763 2026] [security2:error] [pid 296703:tid 296939] [client 202.143.127.214:51420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NLSn25uliftkV1n7-owAAAGo"]
[Tue Jul 21 07:42:53.947887 2026] [security2:error] [pid 296703:tid 296939] [client 202.143.127.214:51420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NLSn25uliftkV1n7-owAAAGo"]
[Tue Jul 21 07:42:54.130808 2026] [security2:error] [pid 296703:tid 296868] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/mac.php"] [unique_id "al9NLin25uliftkV1n7-qgAAACM"]
[Tue Jul 21 07:42:54.165914 2026] [access_compat:error] [pid 296703:tid 296881] [client 162.241.63.68:58052] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:42:54.238829 2026] [security2:error] [pid 296703:tid 296877] [client 20.197.195.24:13804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/admin.php"] [unique_id "al9NLin25uliftkV1n7-sgAAACw"]
[Tue Jul 21 07:42:54.244265 2026] [security2:error] [pid 296703:tid 296891] [client 20.226.60.151:56221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9NLin25uliftkV1n7-swAAADo"]
[Tue Jul 21 07:42:54.361322 2026] [security2:error] [pid 296703:tid 296837] [client 20.226.60.151:59444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/yawa.php"] [unique_id "al9NLin25uliftkV1n7-tAAAAAQ"]
[Tue Jul 21 07:42:54.381494 2026] [security2:error] [pid 296703:tid 296922] [client 20.197.195.24:44697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/fpwch.php"] [unique_id "al9NLin25uliftkV1n7-tQAAAFk"]
[Tue Jul 21 07:42:54.413852 2026] [security2:error] [pid 296703:tid 296911] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/chosen.php"] [unique_id "al9NLin25uliftkV1n7-tgAAAE4"]
[Tue Jul 21 07:42:54.416521 2026] [security2:error] [pid 296703:tid 296846] [client 122.186.204.214:57460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NLin25uliftkV1n7-twAAAA0"]
[Tue Jul 21 07:42:54.416617 2026] [security2:error] [pid 296703:tid 296846] [client 122.186.204.214:57460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NLin25uliftkV1n7-twAAAA0"]
[Tue Jul 21 07:42:54.432800 2026] [security2:error] [pid 296703:tid 296870] [client 103.86.117.203:54553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NLin25uliftkV1n7-uQAAACU"]
[Tue Jul 21 07:42:54.432908 2026] [security2:error] [pid 296703:tid 296870] [client 103.86.117.203:54553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NLin25uliftkV1n7-uQAAACU"]
[Tue Jul 21 07:42:54.437045 2026] [security2:error] [pid 296703:tid 296893] [client 20.104.96.117:64015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/abcd.php"] [unique_id "al9NLin25uliftkV1n7-ugAAADw"]
[Tue Jul 21 07:42:54.438976 2026] [security2:error] [pid 296703:tid 296901] [client 20.220.225.223:5257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/hp3.php"] [unique_id "al9NLin25uliftkV1n7-uwAAAEQ"]
[Tue Jul 21 07:42:54.514490 2026] [security2:error] [pid 296703:tid 296855] [client 20.197.195.24:44777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/domvf.php"] [unique_id "al9NLin25uliftkV1n7-wQAAABY"]
[Tue Jul 21 07:42:54.664304 2026] [security2:error] [pid 296703:tid 296839] [client 20.197.195.24:13638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/wp.php"] [unique_id "al9NLin25uliftkV1n7-zAAAAAY"]
[Tue Jul 21 07:42:54.673966 2026] [security2:error] [pid 296703:tid 296873] [client 122.164.127.47:55780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NLin25uliftkV1n7-zgAAACg"]
[Tue Jul 21 07:42:54.674132 2026] [security2:error] [pid 296703:tid 296873] [client 122.164.127.47:55780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NLin25uliftkV1n7-zgAAACg"]
[Tue Jul 21 07:42:54.720656 2026] [security2:error] [pid 296703:tid 296918] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/cream1.php"] [unique_id "al9NLin25uliftkV1n7-0gAAAFU"]
[Tue Jul 21 07:42:54.774057 2026] [security2:error] [pid 296703:tid 296844] [client 20.104.96.117:5113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/file15.php"] [unique_id "al9NLin25uliftkV1n7-1QAAAAs"]
[Tue Jul 21 07:42:54.892246 2026] [security2:error] [pid 296703:tid 296837] [client 20.197.195.24:44738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/class.php"] [unique_id "al9NLin25uliftkV1n7-2QAAAAQ"]
[Tue Jul 21 07:42:54.912222 2026] [security2:error] [pid 296703:tid 296911] [client 20.220.225.223:5260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/aa1.php"] [unique_id "al9NLin25uliftkV1n7-3AAAAE4"]
[Tue Jul 21 07:42:54.915054 2026] [security2:error] [pid 296703:tid 296762] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NLin25uliftkV1n7-2wAAMDo"]
[Tue Jul 21 07:42:54.915231 2026] [security2:error] [pid 296703:tid 296881] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NLin25uliftkV1n7-2wAAMDo"]
[Tue Jul 21 07:42:55.014268 2026] [autoindex:error] [pid 296703:tid 296952] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:55.026313 2026] [security2:error] [pid 296703:tid 296901] [client 20.151.10.161:12093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-load.php"] [unique_id "al9NLyn25uliftkV1n7-4AAAAEQ"]
[Tue Jul 21 07:42:55.062923 2026] [security2:error] [pid 296703:tid 296889] [client 37.140.223.118:49387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NLyn25uliftkV1n7-4wAAADg"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:42:55.092514 2026] [security2:error] [pid 296703:tid 296835] [client 20.104.96.117:62949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/jp.php"] [unique_id "al9NLyn25uliftkV1n7-5gAAAAI"]
[Tue Jul 21 07:42:55.119092 2026] [security2:error] [pid 296703:tid 296887] [client 20.226.60.151:59497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/js.php"] [unique_id "al9NLyn25uliftkV1n7-6AAAADY"]
[Tue Jul 21 07:42:55.160567 2026] [security2:error] [pid 296703:tid 296953] [client 20.226.60.151:54356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/.well-known/about.php"] [unique_id "al9NLyn25uliftkV1n7-6QAAAHg"]
[Tue Jul 21 07:42:55.183374 2026] [autoindex:error] [pid 296703:tid 296951] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:55.225402 2026] [security2:error] [pid 296703:tid 296899] [client 20.197.195.24:44730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/echkm.php"] [unique_id "al9NLyn25uliftkV1n7-8AAAAEI"]
[Tue Jul 21 07:42:55.349649 2026] [security2:error] [pid 296703:tid 296885] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/dr.php"] [unique_id "al9NLyn25uliftkV1n7-8gAAADQ"]
[Tue Jul 21 07:42:55.369274 2026] [security2:error] [pid 296703:tid 296935] [client 20.197.195.24:13689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/lib.php"] [unique_id "al9NLyn25uliftkV1n7-8wAAAGY"]
[Tue Jul 21 07:42:55.428773 2026] [security2:error] [pid 296703:tid 296945] [client 20.197.195.24:13577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/login.php"] [unique_id "al9NLyn25uliftkV1n7-9QAAAHA"]
[Tue Jul 21 07:42:55.437739 2026] [proxy:error] [pid 296703:tid 296774] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:42:55.437785 2026] [proxy_http:error] [pid 296703:tid 296774] [remote 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:42:55.438392 2026] [proxy:error] [pid 296703:tid 296774] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:42:55.438424 2026] [proxy_http:error] [pid 296703:tid 296774] [remote 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:42:55.443822 2026] [security2:error] [pid 296703:tid 296867] [client 20.104.96.117:5058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/f35.php"] [unique_id "al9NLyn25uliftkV1n7--AAAACI"]
[Tue Jul 21 07:42:55.491176 2026] [security2:error] [pid 296703:tid 296848] [client 20.197.195.24:44744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/a2.php"] [unique_id "al9NLyn25uliftkV1n7--QAAAA8"]
[Tue Jul 21 07:42:55.558472 2026] [security2:error] [pid 296703:tid 296888] [client 143.244.57.90:44282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "links.principiamatematica.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9NLyn25uliftkV1n7-_AAAADc"]
[Tue Jul 21 07:42:55.569855 2026] [security2:error] [pid 296703:tid 296908] [client 20.197.195.24:44731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/d61.php"] [unique_id "al9NLyn25uliftkV1n7-_gAAAEs"]
[Tue Jul 21 07:42:55.647552 2026] [security2:error] [pid 296703:tid 296929] [client 20.197.195.24:44765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/info.php"] [unique_id "al9NLyn25uliftkV1n7_BAAAAGA"]
[Tue Jul 21 07:42:55.752418 2026] [security2:error] [pid 296703:tid 296830] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9NLyn25uliftkV1n7_LwAAQn4"]
[Tue Jul 21 07:42:55.768369 2026] [security2:error] [pid 296703:tid 296845] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/x.php"] [unique_id "al9NLyn25uliftkV1n7_MgAAAAw"]
[Tue Jul 21 07:42:55.776036 2026] [security2:error] [pid 296703:tid 296935] [client 20.104.96.117:62919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wp-load.php"] [unique_id "al9NLyn25uliftkV1n7_NAAAAGY"]
[Tue Jul 21 07:42:55.888259 2026] [security2:error] [pid 296703:tid 296861] [client 20.220.225.223:5256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/acew67.php"] [unique_id "al9NLyn25uliftkV1n7_PAAAABw"]
[Tue Jul 21 07:42:56.007424 2026] [security2:error] [pid 296703:tid 296847] [client 20.226.60.151:59409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/core.php"] [unique_id "al9NMCn25uliftkV1n7_PwAAAA4"]
[Tue Jul 21 07:42:56.043493 2026] [security2:error] [pid 296703:tid 296705] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NMCn25uliftkV1n7_QgAATgE"]
[Tue Jul 21 07:42:56.043664 2026] [security2:error] [pid 296703:tid 296911] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NMCn25uliftkV1n7_QgAATgE"]
[Tue Jul 21 07:42:56.054073 2026] [security2:error] [pid 296703:tid 296870] [client 20.197.195.24:44764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/11.php"] [unique_id "al9NMCn25uliftkV1n7_RQAAACU"]
[Tue Jul 21 07:42:56.064630 2026] [security2:error] [pid 296703:tid 296949] [client 154.192.233.199:60039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NMCn25uliftkV1n7_RwAAAHQ"]
[Tue Jul 21 07:42:56.064735 2026] [security2:error] [pid 296703:tid 296949] [client 154.192.233.199:60039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NMCn25uliftkV1n7_RwAAAHQ"]
[Tue Jul 21 07:42:56.136262 2026] [security2:error] [pid 296703:tid 296917] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/155.php"] [unique_id "al9NMCn25uliftkV1n7_SwAAAFQ"]
[Tue Jul 21 07:42:56.138363 2026] [security2:error] [pid 296703:tid 296938] [client 20.226.60.151:54343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9NMCn25uliftkV1n7_TAAAAGk"]
[Tue Jul 21 07:42:56.205091 2026] [security2:error] [pid 296703:tid 296943] [client 20.104.96.117:64005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/xyn.php"] [unique_id "al9NMCn25uliftkV1n7_TQAAAG4"]
[Tue Jul 21 07:42:56.209417 2026] [security2:error] [pid 296703:tid 296936] [client 136.144.33.100:28699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NMCn25uliftkV1n7_QwAAAGc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:56.215860 2026] [security2:error] [pid 296703:tid 296912] [client 117.247.80.59:30314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NLyn25uliftkV1n7-7wAAAE8"]
[Tue Jul 21 07:42:56.215968 2026] [security2:error] [pid 296703:tid 296912] [client 117.247.80.59:30314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NLyn25uliftkV1n7-7wAAAE8"]
[Tue Jul 21 07:42:56.290933 2026] [security2:error] [pid 296703:tid 296855] [client 194.99.104.35:47312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9NMCn25uliftkV1n7_UgAAABY"]
[Tue Jul 21 07:42:56.291008 2026] [security2:error] [pid 296703:tid 296855] [client 194.99.104.35:47312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9NMCn25uliftkV1n7_UgAAABY"]
[Tue Jul 21 07:42:56.317051 2026] [security2:error] [pid 296703:tid 296871] [client 20.197.195.24:44782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/v2.php"] [unique_id "al9NMCn25uliftkV1n7_UwAAACY"]
[Tue Jul 21 07:42:56.338163 2026] [security2:error] [pid 296703:tid 296920] [client 20.104.96.117:30432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9NMCn25uliftkV1n7_VAAAAFc"]
[Tue Jul 21 07:42:56.387878 2026] [security2:error] [pid 296703:tid 296837] [client 143.244.57.90:44298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "links.principiamatematica.com"] [uri "/xmlrpc.php"] [unique_id "al9NMCn25uliftkV1n7_VQAAAAQ"]
[Tue Jul 21 07:42:56.420907 2026] [security2:error] [pid 296703:tid 296923] [client 20.197.195.24:13661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/panel.php"] [unique_id "al9NMCn25uliftkV1n7_VwAAAFo"]
[Tue Jul 21 07:42:56.438818 2026] [security2:error] [pid 296703:tid 296910] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/ops.php"] [unique_id "al9NMCn25uliftkV1n7_WAAAAE0"]
[Tue Jul 21 07:42:56.672068 2026] [security2:error] [pid 296703:tid 296728] [remote 159.223.41.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NMCn25uliftkV1n7_YAAAXxg"]
[Tue Jul 21 07:42:56.738299 2026] [security2:error] [pid 296703:tid 296903] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/file31.php"] [unique_id "al9NMCn25uliftkV1n7_ZgAAAEY"]
[Tue Jul 21 07:42:56.742068 2026] [security2:error] [pid 296703:tid 296867] [client 20.197.195.24:13666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/dex.php"] [unique_id "al9NMCn25uliftkV1n7_aQAAACI"]
[Tue Jul 21 07:42:56.755870 2026] [security2:error] [pid 296703:tid 296934] [client 20.197.195.24:13747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/adminner.php"] [unique_id "al9NMCn25uliftkV1n7_bAAAAGU"]
[Tue Jul 21 07:42:56.939237 2026] [security2:error] [pid 296703:tid 296838] [client 20.226.60.151:33512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/zc-131.php"] [unique_id "al9NMCn25uliftkV1n7_dQAAAAU"]
[Tue Jul 21 07:42:56.979823 2026] [proxy:error] [pid 296703:tid 296746] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:42:56.979886 2026] [proxy_http:error] [pid 296703:tid 296746] [remote 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:42:56.980328 2026] [proxy:error] [pid 296703:tid 296746] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:42:56.980354 2026] [proxy_http:error] [pid 296703:tid 296746] [remote 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:42:57.020934 2026] [security2:error] [pid 296703:tid 296886] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/file6.php"] [unique_id "al9NMSn25uliftkV1n7_egAAADU"]
[Tue Jul 21 07:42:57.110223 2026] [security2:error] [pid 296703:tid 296837] [client 20.197.195.24:44694] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "nrfilmes.com"] [uri "/1.php"] [unique_id "al9NMSn25uliftkV1n7_hAAAAAQ"]
[Tue Jul 21 07:42:57.110361 2026] [security2:error] [pid 296703:tid 296837] [client 20.197.195.24:44694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/1.php"] [unique_id "al9NMSn25uliftkV1n7_hAAAAAQ"]
[Tue Jul 21 07:42:57.260409 2026] [security2:error] [pid 296703:tid 296845] [client 117.217.38.194:51057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NMSn25uliftkV1n7_mgAAAAw"]
[Tue Jul 21 07:42:57.260517 2026] [security2:error] [pid 296703:tid 296845] [client 117.217.38.194:51057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NMSn25uliftkV1n7_mgAAAAw"]
[Tue Jul 21 07:42:57.292572 2026] [security2:error] [pid 296703:tid 296793] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9NMSn25uliftkV1n7_rAAAUVk"]
[Tue Jul 21 07:42:57.313086 2026] [security2:error] [pid 296703:tid 296902] [client 74.249.245.134:5539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/amax.php"] [unique_id "al9NMSn25uliftkV1n7_sAAAAEU"]
[Tue Jul 21 07:42:57.313950 2026] [autoindex:error] [pid 296703:tid 296834] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:57.434611 2026] [security2:error] [pid 296703:tid 296925] [client 20.220.225.223:5304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/bscclapb.php"] [unique_id "al9NMSn25uliftkV1n7_uQAAAFw"]
[Tue Jul 21 07:42:57.465918 2026] [security2:error] [pid 296703:tid 296848] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/adminfuns.php"] [unique_id "al9NMSn25uliftkV1n7_ugAAAA8"]
[Tue Jul 21 07:42:57.468347 2026] [security2:error] [pid 296703:tid 296839] [client 20.197.195.24:44795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/ms.php"] [unique_id "al9NMSn25uliftkV1n7_uwAAAAY"]
[Tue Jul 21 07:42:57.507875 2026] [security2:error] [pid 296703:tid 296861] [client 20.226.60.151:59483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/19.php"] [unique_id "al9NMSn25uliftkV1n7_vQAAABw"]
[Tue Jul 21 07:42:57.562293 2026] [security2:error] [pid 296703:tid 296938] [client 20.104.96.117:4180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/ccc.php"] [unique_id "al9NMSn25uliftkV1n7_wwAAAGk"]
[Tue Jul 21 07:42:57.602182 2026] [security2:error] [pid 296703:tid 296791] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9NMSn25uliftkV1n7_xQAAblc"]
[Tue Jul 21 07:42:57.748122 2026] [security2:error] [pid 296703:tid 296874] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/goods.php"] [unique_id "al9NMSn25uliftkV1n7_ywAAACk"]
[Tue Jul 21 07:42:57.855709 2026] [autoindex:error] [pid 296703:tid 296960] [client 20.197.195.24:44685] AH01276: Cannot serve directory /home2/ren85318/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:57.880238 2026] [security2:error] [pid 296703:tid 296889] [client 20.197.195.24:44685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/memberfuns.php"] [unique_id "al9NMSn25uliftkV1n7_1AAAADg"]
[Tue Jul 21 07:42:57.913490 2026] [security2:error] [pid 296703:tid 296816] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9NMSn25uliftkV1n7_1wAAZHA"]
[Tue Jul 21 07:42:58.021732 2026] [security2:error] [pid 296703:tid 296867] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/100.php"] [unique_id "al9NMin25uliftkV1n7_2wAAACI"]
[Tue Jul 21 07:42:58.071018 2026] [security2:error] [pid 296703:tid 296862] [client 20.226.60.151:50910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/inc.php"] [unique_id "al9NMin25uliftkV1n7_3QAAAB0"]
[Tue Jul 21 07:42:58.112765 2026] [security2:error] [pid 296703:tid 296729] [remote 182.77.62.24:39230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moratoadvogado.com"] [uri "/wp-login.php"] [unique_id "al9NMin25uliftkV1n7_4wAALRk"]
[Tue Jul 21 07:42:58.136429 2026] [security2:error] [pid 296703:tid 296952] [client 20.197.195.24:44748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/0.php"] [unique_id "al9NMin25uliftkV1n7_5gAAAHc"]
[Tue Jul 21 07:42:58.180710 2026] [security2:error] [pid 296703:tid 296939] [client 59.96.220.140:59016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NMin25uliftkV1n7_7QAAAGo"]
[Tue Jul 21 07:42:58.180824 2026] [security2:error] [pid 296703:tid 296939] [client 59.96.220.140:59016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NMin25uliftkV1n7_7QAAAGo"]
[Tue Jul 21 07:42:58.197984 2026] [security2:error] [pid 296703:tid 296847] [client 136.144.33.25:26499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NMin25uliftkV1n7_3AAAAA4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:42:58.220745 2026] [security2:error] [pid 296703:tid 296792] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9NMin25uliftkV1n7_7gAABVg"]
[Tue Jul 21 07:42:58.251535 2026] [security2:error] [pid 296703:tid 296896] [client 20.104.96.117:64063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/w.php"] [unique_id "al9NMin25uliftkV1n7_8QAAAD8"]
[Tue Jul 21 07:42:58.301516 2026] [security2:error] [pid 296703:tid 296912] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/about.php"] [unique_id "al9NMin25uliftkV1n7_8wAAAE8"]
[Tue Jul 21 07:42:58.309175 2026] [security2:error] [pid 296703:tid 296835] [client 103.106.20.201:53746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NMin25uliftkV1n7_9AAAAAI"]
[Tue Jul 21 07:42:58.309286 2026] [security2:error] [pid 296703:tid 296835] [client 103.106.20.201:53746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NMin25uliftkV1n7_9AAAAAI"]
[Tue Jul 21 07:42:58.309862 2026] [security2:error] [pid 296703:tid 296886] [client 20.197.195.24:44677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/BDKR28.php"] [unique_id "al9NMin25uliftkV1n7_9QAAADU"]
[Tue Jul 21 07:42:58.535306 2026] [security2:error] [pid 296703:tid 296748] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9NMin25uliftkV1n4AFwAAcCw"]
[Tue Jul 21 07:42:58.599575 2026] [security2:error] [pid 296703:tid 296862] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/about.php"] [unique_id "al9NMin25uliftkV1n4AHwAAAB0"]
[Tue Jul 21 07:42:58.643194 2026] [security2:error] [pid 296703:tid 296911] [client 20.197.195.24:44746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/green1.php"] [unique_id "al9NMin25uliftkV1n4AJwAAAE4"]
[Tue Jul 21 07:42:58.700892 2026] [security2:error] [pid 296703:tid 296847] [client 20.226.60.151:59467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-ppoxua4.php"] [unique_id "al9NMin25uliftkV1n4ALAAAAA4"]
[Tue Jul 21 07:42:58.773104 2026] [security2:error] [pid 296703:tid 296912] [client 20.226.60.151:54337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wefile.php"] [unique_id "al9NMin25uliftkV1n4ANgAAAE8"]
[Tue Jul 21 07:42:58.797044 2026] [security2:error] [pid 296703:tid 296868] [client 122.162.144.145:1645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NMin25uliftkV1n4ANwAAACM"]
[Tue Jul 21 07:42:58.797143 2026] [security2:error] [pid 296703:tid 296868] [client 122.162.144.145:1645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NMin25uliftkV1n4ANwAAACM"]
[Tue Jul 21 07:42:58.824179 2026] [security2:error] [pid 296703:tid 296860] [client 20.104.96.117:64044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9NMin25uliftkV1n4AOQAAABs"]
[Tue Jul 21 07:42:58.842538 2026] [security2:error] [pid 296703:tid 296757] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9NMin25uliftkV1n4AOgAAPjU"]
[Tue Jul 21 07:42:58.874673 2026] [security2:error] [pid 296703:tid 296932] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/admin.php"] [unique_id "al9NMin25uliftkV1n4AOwAAAGM"]
[Tue Jul 21 07:42:58.974001 2026] [security2:error] [pid 296703:tid 296940] [client 20.197.195.24:13812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/admin.php"] [unique_id "al9NMin25uliftkV1n4AQAAAAGs"]
[Tue Jul 21 07:42:59.148364 2026] [security2:error] [pid 296703:tid 296835] [client 154.92.130.87:44333] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=http://:"] [hostname "www.startonesite.com.br"] [uri "/"] [unique_id "al9NMyn25uliftkV1n4ASQAAAAI"]
[Tue Jul 21 07:42:59.154577 2026] [security2:error] [pid 296703:tid 296809] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9NMyn25uliftkV1n4ASgAAJ2k"]
[Tue Jul 21 07:42:59.166332 2026] [security2:error] [pid 296703:tid 296903] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/admin.php"] [unique_id "al9NMyn25uliftkV1n4ATAAAAEY"]
[Tue Jul 21 07:42:59.209305 2026] [security2:error] [pid 296703:tid 296866] [client 20.104.96.117:64029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/FWAZ.php"] [unique_id "al9NMyn25uliftkV1n4ATQAAACE"]
[Tue Jul 21 07:42:59.305412 2026] [security2:error] [pid 296703:tid 296843] [client 152.59.154.239:5394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NMyn25uliftkV1n4AVAAAAAo"]
[Tue Jul 21 07:42:59.309851 2026] [security2:error] [pid 296703:tid 296843] [client 152.59.154.239:5394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NMyn25uliftkV1n4AVAAAAAo"]
[Tue Jul 21 07:42:59.350954 2026] [security2:error] [pid 296703:tid 296914] [client 20.197.195.24:13589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/nc4.php"] [unique_id "al9NMyn25uliftkV1n4AVgAAAFE"]
[Tue Jul 21 07:42:59.409472 2026] [security2:error] [pid 296703:tid 296861] [client 20.226.60.151:59450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-u3nxbvx.php"] [unique_id "al9NMyn25uliftkV1n4AWAAAABw"]
[Tue Jul 21 07:42:59.448592 2026] [security2:error] [pid 296703:tid 296950] [client 139.167.225.182:51236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NMyn25uliftkV1n4AWQAAAHU"]
[Tue Jul 21 07:42:59.450163 2026] [security2:error] [pid 296703:tid 296950] [client 139.167.225.182:51236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NMyn25uliftkV1n4AWQAAAHU"]
[Tue Jul 21 07:42:59.475564 2026] [security2:error] [pid 296703:tid 296789] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9NMyn25uliftkV1n4AXQAARFU"]
[Tue Jul 21 07:42:59.542024 2026] [security2:error] [pid 296703:tid 296923] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/themes.php"] [unique_id "al9NMyn25uliftkV1n4AYAAAAFo"]
[Tue Jul 21 07:42:59.639294 2026] [security2:error] [pid 296703:tid 296851] [client 20.104.96.117:5089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/miru1.php"] [unique_id "al9NMyn25uliftkV1n4AYwAAABI"]
[Tue Jul 21 07:42:59.777370 2026] [security2:error] [pid 296703:tid 296947] [client 20.226.60.151:56301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/ss.php"] [unique_id "al9NMyn25uliftkV1n4AawAAAHI"]
[Tue Jul 21 07:42:59.787488 2026] [security2:error] [pid 296703:tid 296731] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9NMyn25uliftkV1n4AbAAAShs"]
[Tue Jul 21 07:42:59.815497 2026] [security2:error] [pid 296703:tid 296866] [client 20.197.195.24:13660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/a1.php"] [unique_id "al9NMyn25uliftkV1n4AbQAAACE"]
[Tue Jul 21 07:42:59.852667 2026] [autoindex:error] [pid 296703:tid 296945] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:59.883161 2026] [security2:error] [pid 296703:tid 296834] [client 20.226.60.151:22964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/green1.php"] [unique_id "al9NMyn25uliftkV1n4AcAAAAAE"]
[Tue Jul 21 07:43:00.025146 2026] [autoindex:error] [pid 296703:tid 296801] [remote 74.7.227.60:58968] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/conhecaonordeste.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:00.045615 2026] [security2:error] [pid 296703:tid 296869] [client 74.7.228.57:47238] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "conhecaonordeste.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9NNCn25uliftkV1n4AeAAAJGA"]
[Tue Jul 21 07:43:00.046221 2026] [security2:error] [pid 296703:tid 296838] [client 20.104.96.117:5098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/aa.php"] [unique_id "al9NNCn25uliftkV1n4AeQAAAAU"]
[Tue Jul 21 07:43:00.093677 2026] [security2:error] [pid 296703:tid 296791] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9NNCn25uliftkV1n4AfAAAUVc"]
[Tue Jul 21 07:43:00.112220 2026] [security2:error] [pid 296703:tid 296876] [client 20.151.10.161:11656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xwpg.php"] [unique_id "al9NNCn25uliftkV1n4AfQAAACs"]
[Tue Jul 21 07:43:00.127591 2026] [security2:error] [pid 296703:tid 296902] [client 20.197.195.24:44681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/eee.php"] [unique_id "al9NNCn25uliftkV1n4AfgAAAEU"]
[Tue Jul 21 07:43:00.166696 2026] [security2:error] [pid 296703:tid 296861] [client 20.226.60.151:50821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/ss.php"] [unique_id "al9NNCn25uliftkV1n4AgAAAABw"]
[Tue Jul 21 07:43:00.296843 2026] [security2:error] [pid 296703:tid 296860] [client 20.226.60.151:51230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/min.php"] [unique_id "al9NNCn25uliftkV1n4AiAAAABs"]
[Tue Jul 21 07:43:00.366221 2026] [security2:error] [pid 296703:tid 296887] [client 20.104.96.117:5117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/122.php"] [unique_id "al9NNCn25uliftkV1n4AigAAADY"]
[Tue Jul 21 07:43:00.375668 2026] [security2:error] [pid 296703:tid 296960] [client 20.197.195.24:44745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/wp-aothait.php"] [unique_id "al9NNCn25uliftkV1n4AiwAAAH8"]
[Tue Jul 21 07:43:00.406098 2026] [security2:error] [pid 296703:tid 296797] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9NNCn25uliftkV1n4AjAAAEl0"]
[Tue Jul 21 07:43:00.431136 2026] [security2:error] [pid 296703:tid 296928] [client 20.226.60.151:54326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9NNCn25uliftkV1n4AjQAAAF8"]
[Tue Jul 21 07:43:00.468380 2026] [security2:error] [pid 296703:tid 296855] [client 20.226.60.151:56246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9NNCn25uliftkV1n4AjwAAABY"]
[Tue Jul 21 07:43:00.524888 2026] [security2:error] [pid 296703:tid 296885] [client 20.226.60.151:59431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/min.php"] [unique_id "al9NNCn25uliftkV1n4AlgAAADQ"]
[Tue Jul 21 07:43:00.538930 2026] [security2:error] [pid 296703:tid 296849] [client 20.226.60.151:56311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9NNCn25uliftkV1n4AlwAAABA"]
[Tue Jul 21 07:43:00.565335 2026] [security2:error] [pid 296703:tid 296945] [client 20.197.195.24:13607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/config.json.php"] [unique_id "al9NNCn25uliftkV1n4AmAAAAHA"]
[Tue Jul 21 07:43:00.566602 2026] [security2:error] [pid 296703:tid 296751] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NNCn25uliftkV1n4AmQAAbi8"]
[Tue Jul 21 07:43:00.566740 2026] [security2:error] [pid 296703:tid 296943] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NNCn25uliftkV1n4AmQAAbi8"]
[Tue Jul 21 07:43:00.590373 2026] [security2:error] [pid 296703:tid 296952] [client 20.220.225.223:11159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/else1.php"] [unique_id "al9NNCn25uliftkV1n4AmgAAAHc"]
[Tue Jul 21 07:43:00.626593 2026] [security2:error] [pid 296703:tid 296922] [client 20.197.195.24:44707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9NNCn25uliftkV1n4AmwAAAFk"]
[Tue Jul 21 07:43:00.644599 2026] [security2:error] [pid 296703:tid 296958] [client 143.244.57.90:44328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "links.principiamatematica.com"] [uri "/xmlrpc.php"] [unique_id "al9NNCn25uliftkV1n4AnAAAAH0"]
[Tue Jul 21 07:43:00.644698 2026] [security2:error] [pid 296703:tid 296958] [client 143.244.57.90:44328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "links.principiamatematica.com"] [uri "/xmlrpc.php"] [unique_id "al9NNCn25uliftkV1n4AnAAAAH0"]
[Tue Jul 21 07:43:00.656114 2026] [security2:error] [pid 296703:tid 296920] [client 20.226.60.151:51258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9NNCn25uliftkV1n4AnQAAAFc"]
[Tue Jul 21 07:43:00.686833 2026] [security2:error] [pid 296703:tid 296884] [client 20.104.96.117:5082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/get.php"] [unique_id "al9NNCn25uliftkV1n4AoAAAADM"]
[Tue Jul 21 07:43:00.713920 2026] [security2:error] [pid 296703:tid 296712] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9NNCn25uliftkV1n4AowAALgg"]
[Tue Jul 21 07:43:00.790637 2026] [security2:error] [pid 296703:tid 296954] [client 20.197.195.24:44754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/k2.php"] [unique_id "al9NNCn25uliftkV1n4ApwAAAHk"]
[Tue Jul 21 07:43:00.888466 2026] [security2:error] [pid 296703:tid 296894] [client 193.36.225.60:61979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NNCn25uliftkV1n4ArgAAAD0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:00.910059 2026] [security2:error] [pid 296703:tid 296858] [client 74.249.245.134:5525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/moon.php"] [unique_id "al9NNCn25uliftkV1n4ArwAAABk"]
[Tue Jul 21 07:43:01.026228 2026] [security2:error] [pid 296703:tid 296822] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9NNSn25uliftkV1n4AswAAC3Y"]
[Tue Jul 21 07:43:01.034928 2026] [security2:error] [pid 296703:tid 296837] [client 103.166.103.129:58692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NNSn25uliftkV1n4AtAAAAAQ"]
[Tue Jul 21 07:43:01.035033 2026] [security2:error] [pid 296703:tid 296837] [client 103.166.103.129:58692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NNSn25uliftkV1n4AtAAAAAQ"]
[Tue Jul 21 07:43:01.122202 2026] [security2:error] [pid 296703:tid 296935] [client 173.24.185.52:56465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NNSn25uliftkV1n4AuAAAAGY"]
[Tue Jul 21 07:43:01.122316 2026] [security2:error] [pid 296703:tid 296935] [client 173.24.185.52:56465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NNSn25uliftkV1n4AuAAAAGY"]
[Tue Jul 21 07:43:01.144039 2026] [security2:error] [pid 296703:tid 296903] [client 20.104.96.117:5059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/as.php"] [unique_id "al9NNSn25uliftkV1n4AuQAAAEY"]
[Tue Jul 21 07:43:01.170743 2026] [security2:error] [pid 296703:tid 296885] [client 20.220.225.223:19294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/bootstrap.php"] [unique_id "al9NNSn25uliftkV1n4AugAAADQ"]
[Tue Jul 21 07:43:01.218056 2026] [security2:error] [pid 296703:tid 296947] [client 122.179.91.63:2593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NNSn25uliftkV1n4AvgAAAHI"]
[Tue Jul 21 07:43:01.218218 2026] [security2:error] [pid 296703:tid 296947] [client 122.179.91.63:2593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NNSn25uliftkV1n4AvgAAAHI"]
[Tue Jul 21 07:43:01.318996 2026] [security2:error] [pid 296703:tid 296864] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/.well-known/about.php"] [unique_id "al9NNSn25uliftkV1n4AxAAAAB8"]
[Tue Jul 21 07:43:01.334263 2026] [security2:error] [pid 296703:tid 296721] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9NNSn25uliftkV1n4AxwAAARE"]
[Tue Jul 21 07:43:01.530019 2026] [security2:error] [pid 296703:tid 296906] [client 20.104.96.117:5079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/ccou.php"] [unique_id "al9NNSn25uliftkV1n4AzgAAAEk"]
[Tue Jul 21 07:43:01.542063 2026] [autoindex:error] [pid 296703:tid 296876] [client 20.226.60.151:54348] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:01.553095 2026] [security2:error] [pid 296703:tid 296938] [client 20.226.60.151:50943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9NNSn25uliftkV1n4A0AAAAGk"]
[Tue Jul 21 07:43:01.617114 2026] [security2:error] [pid 296703:tid 296923] [client 20.197.195.24:44689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/uiuvs58l.php"] [unique_id "al9NNSn25uliftkV1n4A1QAAAFo"]
[Tue Jul 21 07:43:01.620203 2026] [autoindex:error] [pid 296703:tid 296861] [client 20.226.60.151:54348] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:01.625654 2026] [security2:error] [pid 296703:tid 296839] [client 20.226.60.151:54348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9NNSn25uliftkV1n4A1wAAAAY"]
[Tue Jul 21 07:43:01.646351 2026] [security2:error] [pid 296703:tid 296738] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9NNSn25uliftkV1n4A2gAAMCI"]
[Tue Jul 21 07:43:01.818747 2026] [security2:error] [pid 296703:tid 296947] [client 20.104.96.117:30627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/classwithtostring.php"] [unique_id "al9NNSn25uliftkV1n4A4AAAAHI"]
[Tue Jul 21 07:43:01.818948 2026] [security2:error] [pid 296703:tid 296888] [client 37.140.223.190:26681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NNSn25uliftkV1n4A2wAAADc"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:01.819319 2026] [security2:error] [pid 296703:tid 296907] [client 74.249.245.134:54362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/ws83.php"] [unique_id "al9NNSn25uliftkV1n4A4QAAAEo"]
[Tue Jul 21 07:43:01.825466 2026] [security2:error] [pid 296703:tid 296951] [client 194.99.104.35:46230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9NNSn25uliftkV1n4A4gAAAHY"]
[Tue Jul 21 07:43:01.825527 2026] [security2:error] [pid 296703:tid 296951] [client 194.99.104.35:46230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9NNSn25uliftkV1n4A4gAAAHY"]
[Tue Jul 21 07:43:01.835064 2026] [security2:error] [pid 296703:tid 296710] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NNSn25uliftkV1n4A4wAAJwY"]
[Tue Jul 21 07:43:01.835227 2026] [security2:error] [pid 296703:tid 296872] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NNSn25uliftkV1n4A4wAAJwY"]
[Tue Jul 21 07:43:01.857760 2026] [security2:error] [pid 296703:tid 296908] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9NNSn25uliftkV1n4A5gAAAEs"]
[Tue Jul 21 07:43:01.912464 2026] [security2:error] [pid 296703:tid 296945] [client 20.197.195.24:13147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/40p9ixjd.php"] [unique_id "al9NNSn25uliftkV1n4A6AAAAHA"]
[Tue Jul 21 07:43:01.953075 2026] [security2:error] [pid 296703:tid 296717] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9NNSn25uliftkV1n4A6gAABw0"]
[Tue Jul 21 07:43:01.983220 2026] [security2:error] [pid 296703:tid 296866] [client 20.104.96.117:64011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/w3lls.php"] [unique_id "al9NNSn25uliftkV1n4A6wAAACE"]
[Tue Jul 21 07:43:02.063293 2026] [security2:error] [pid 296703:tid 296848] [client 20.226.60.151:51260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9NNin25uliftkV1n4A7QAAAA8"]
[Tue Jul 21 07:43:02.140655 2026] [security2:error] [pid 296703:tid 296876] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wefile.php"] [unique_id "al9NNin25uliftkV1n4A8QAAACs"]
[Tue Jul 21 07:43:02.277742 2026] [security2:error] [pid 296703:tid 296869] [client 20.197.195.24:13616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/uiuvs58l.update.php"] [unique_id "al9NNin25uliftkV1n4A9AAAACQ"]
[Tue Jul 21 07:43:02.302356 2026] [security2:error] [pid 296703:tid 296910] [client 20.104.96.117:5096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/test1.php"] [unique_id "al9NNin25uliftkV1n4A9QAAAE0"]
[Tue Jul 21 07:43:02.419058 2026] [security2:error] [pid 296703:tid 296837] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9NNin25uliftkV1n4A-gAAAAQ"]
[Tue Jul 21 07:43:02.580751 2026] [security2:error] [pid 296703:tid 296947] [client 20.197.195.24:13580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/for.php"] [unique_id "al9NNin25uliftkV1n4A_gAAAHI"]
[Tue Jul 21 07:43:02.581809 2026] [security2:error] [pid 296703:tid 296888] [client 20.226.60.151:54292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/8.php"] [unique_id "al9NNin25uliftkV1n4A_wAAADc"]
[Tue Jul 21 07:43:02.685013 2026] [security2:error] [pid 296703:tid 296954] [client 20.104.96.117:62943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/database.php"] [unique_id "al9NNin25uliftkV1n4BAwAAAHk"]
[Tue Jul 21 07:43:02.706365 2026] [autoindex:error] [pid 296703:tid 296834] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:02.727128 2026] [security2:error] [pid 296703:tid 296917] [client 20.197.195.24:44797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/raw.php"] [unique_id "al9NNin25uliftkV1n4BBQAAAFQ"]
[Tue Jul 21 07:43:02.819169 2026] [security2:error] [pid 296703:tid 296716] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NNin25uliftkV1n4BDQAAMgw"]
[Tue Jul 21 07:43:02.819341 2026] [security2:error] [pid 296703:tid 296883] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NNin25uliftkV1n4BDQAAMgw"]
[Tue Jul 21 07:43:02.862806 2026] [security2:error] [pid 296703:tid 296867] [client 20.226.60.151:51253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/albin.php"] [unique_id "al9NNin25uliftkV1n4BDwAAACI"]
[Tue Jul 21 07:43:02.899739 2026] [security2:error] [pid 296703:tid 296762] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NNin25uliftkV1n4BFAAABTo"]
[Tue Jul 21 07:43:02.899933 2026] [security2:error] [pid 296703:tid 296838] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NNin25uliftkV1n4BFAAABTo"]
[Tue Jul 21 07:43:02.902711 2026] [autoindex:error] [pid 296703:tid 296870] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:02.952901 2026] [security2:error] [pid 296703:tid 296952] [client 20.220.225.223:19303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/wp-editor.php"] [unique_id "al9NNin25uliftkV1n4BFQAAAHc"]
[Tue Jul 21 07:43:02.978904 2026] [security2:error] [pid 296703:tid 296876] [client 20.104.96.117:62912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/file.php"] [unique_id "al9NNin25uliftkV1n4BFwAAACs"]
[Tue Jul 21 07:43:03.047607 2026] [security2:error] [pid 296703:tid 296896] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9NNyn25uliftkV1n4BGQAAAD8"]
[Tue Jul 21 07:43:03.124180 2026] [security2:error] [pid 296703:tid 296869] [client 20.220.225.223:5285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/tkikikoko.php"] [unique_id "al9NNyn25uliftkV1n4BGwAAACQ"]
[Tue Jul 21 07:43:03.162318 2026] [security2:error] [pid 296703:tid 296910] [client 20.197.195.24:13787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/k.php"] [unique_id "al9NNyn25uliftkV1n4BHgAAAE0"]
[Tue Jul 21 07:43:03.243471 2026] [security2:error] [pid 296703:tid 296918] [client 20.226.60.151:54325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9NNyn25uliftkV1n4BIAAAAFU"]
[Tue Jul 21 07:43:03.278210 2026] [security2:error] [pid 296703:tid 296936] [client 20.104.96.117:5088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/file.php"] [unique_id "al9NNyn25uliftkV1n4BIgAAAGc"]
[Tue Jul 21 07:43:03.402199 2026] [security2:error] [pid 296703:tid 296919] [client 106.215.181.8:9549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NNyn25uliftkV1n4BJAAAAFY"]
[Tue Jul 21 07:43:03.402305 2026] [security2:error] [pid 296703:tid 296919] [client 106.215.181.8:9549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NNyn25uliftkV1n4BJAAAAFY"]
[Tue Jul 21 07:43:03.573879 2026] [security2:error] [pid 296703:tid 296880] [client 20.104.96.117:62952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/777.php"] [unique_id "al9NNyn25uliftkV1n4BLQAAAC8"]
[Tue Jul 21 07:43:03.636909 2026] [security2:error] [pid 296703:tid 296841] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/8.php"] [unique_id "al9NNyn25uliftkV1n4BLgAAAAg"]
[Tue Jul 21 07:43:03.826573 2026] [security2:error] [pid 296703:tid 296952] [client 74.249.245.134:5518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/CDX1.php"] [unique_id "al9NNyn25uliftkV1n4BNgAAAHc"]
[Tue Jul 21 07:43:03.859846 2026] [security2:error] [pid 296703:tid 296924] [client 20.226.60.151:54331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/f6.php"] [unique_id "al9NNyn25uliftkV1n4BNwAAAFs"]
[Tue Jul 21 07:43:03.911525 2026] [security2:error] [pid 296703:tid 296863] [client 20.104.96.117:5102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/ssixta.php"] [unique_id "al9NNyn25uliftkV1n4BOAAAAB4"]
[Tue Jul 21 07:43:03.915348 2026] [security2:error] [pid 296703:tid 296896] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9NNyn25uliftkV1n4BOQAAAD8"]
[Tue Jul 21 07:43:04.024748 2026] [security2:error] [pid 296703:tid 296765] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BQAAAKT0"]
[Tue Jul 21 07:43:04.024920 2026] [security2:error] [pid 296703:tid 296874] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BQAAAKT0"]
[Tue Jul 21 07:43:04.186166 2026] [security2:error] [pid 296703:tid 296953] [client 182.8.255.181:17482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BRgAAAHg"]
[Tue Jul 21 07:43:04.186267 2026] [security2:error] [pid 296703:tid 296953] [client 182.8.255.181:17482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BRgAAAHg"]
[Tue Jul 21 07:43:04.189408 2026] [security2:error] [pid 296703:tid 296846] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/f6.php"] [unique_id "al9NOCn25uliftkV1n4BRwAAAA0"]
[Tue Jul 21 07:43:04.216230 2026] [security2:error] [pid 296703:tid 296918] [client 20.104.96.117:5072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/1c.php"] [unique_id "al9NOCn25uliftkV1n4BSQAAAFU"]
[Tue Jul 21 07:43:04.234304 2026] [security2:error] [pid 296703:tid 296938] [client 20.226.60.151:51237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/cilus.php"] [unique_id "al9NOCn25uliftkV1n4BTAAAAGk"]
[Tue Jul 21 07:43:04.324844 2026] [security2:error] [pid 296703:tid 296778] [remote 199.189.225.40:45059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/wp-login.php"] [unique_id "al9NOCn25uliftkV1n4BTgAAYEo"]
[Tue Jul 21 07:43:04.370552 2026] [security2:error] [pid 296703:tid 296950] [client 20.220.225.223:34206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/wp-wpbak.php"] [unique_id "al9NOCn25uliftkV1n4BUAAAAHU"]
[Tue Jul 21 07:43:04.429046 2026] [security2:error] [pid 296703:tid 296845] [client 103.174.34.15:57586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BUgAAAAw"]
[Tue Jul 21 07:43:04.429166 2026] [security2:error] [pid 296703:tid 296845] [client 103.174.34.15:57586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BUgAAAAw"]
[Tue Jul 21 07:43:04.503991 2026] [security2:error] [pid 296703:tid 296862] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/inputs.php"] [unique_id "al9NOCn25uliftkV1n4BVAAAAB0"]
[Tue Jul 21 07:43:04.517425 2026] [security2:error] [pid 296703:tid 296917] [client 20.104.96.117:64022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/test2.php"] [unique_id "al9NOCn25uliftkV1n4BVQAAAFQ"]
[Tue Jul 21 07:43:04.544459 2026] [security2:error] [pid 296703:tid 296871] [client 62.102.148.187:51348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BVgAAACY"]
[Tue Jul 21 07:43:04.544533 2026] [security2:error] [pid 296703:tid 296871] [client 62.102.148.187:51348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BVgAAACY"]
[Tue Jul 21 07:43:04.709699 2026] [security2:error] [pid 296703:tid 296763] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BYQAAFjs"]
[Tue Jul 21 07:43:04.709839 2026] [security2:error] [pid 296703:tid 296855] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BYQAAFjs"]
[Tue Jul 21 07:43:04.821544 2026] [security2:error] [pid 296703:tid 296861] [client 20.104.96.117:62973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/buy.php"] [unique_id "al9NOCn25uliftkV1n4BagAAABw"]
[Tue Jul 21 07:43:04.893832 2026] [security2:error] [pid 296703:tid 296935] [client 193.36.225.61:56869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NOCn25uliftkV1n4BYgAAAGY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:04.902650 2026] [security2:error] [pid 296703:tid 296864] [client 20.226.60.151:63578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/autoload_classmap.php"] [unique_id "al9NOCn25uliftkV1n4BcgAAAB8"]
[Tue Jul 21 07:43:04.909130 2026] [security2:error] [pid 296703:tid 296881] [client 103.86.117.203:55093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BcwAAADA"]
[Tue Jul 21 07:43:04.909242 2026] [security2:error] [pid 296703:tid 296881] [client 103.86.117.203:55093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BcwAAADA"]
[Tue Jul 21 07:43:04.938051 2026] [security2:error] [pid 296703:tid 296837] [client 20.226.60.151:50974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/gptsh.php"] [unique_id "al9NOCn25uliftkV1n4BdwAAAAQ"]
[Tue Jul 21 07:43:05.061112 2026] [security2:error] [pid 296703:tid 296950] [client 20.226.60.151:61994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/inputs.php"] [unique_id "al9NOSn25uliftkV1n4BfQAAAHU"]
[Tue Jul 21 07:43:05.116593 2026] [security2:error] [pid 296703:tid 296859] [client 20.104.96.117:5067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/ssend.php"] [unique_id "al9NOSn25uliftkV1n4BfgAAABo"]
[Tue Jul 21 07:43:05.124407 2026] [security2:error] [pid 296703:tid 296847] [client 122.186.204.214:57996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NOSn25uliftkV1n4BfwAAAA4"]
[Tue Jul 21 07:43:05.124574 2026] [security2:error] [pid 296703:tid 296847] [client 122.186.204.214:57996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NOSn25uliftkV1n4BfwAAAA4"]
[Tue Jul 21 07:43:05.188967 2026] [security2:error] [pid 296703:tid 296960] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/inputs.php"] [unique_id "al9NOSn25uliftkV1n4BgQAAAH8"]
[Tue Jul 21 07:43:05.195184 2026] [security2:error] [pid 296703:tid 296873] [client 117.247.80.59:20206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOSn25uliftkV1n4BggAAACg"]
[Tue Jul 21 07:43:05.195289 2026] [security2:error] [pid 296703:tid 296873] [client 117.247.80.59:20206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOSn25uliftkV1n4BggAAACg"]
[Tue Jul 21 07:43:05.195667 2026] [security2:error] [pid 296703:tid 296884] [client 202.143.127.214:51852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOSn25uliftkV1n4BgwAAADM"]
[Tue Jul 21 07:43:05.196581 2026] [security2:error] [pid 296703:tid 296884] [client 202.143.127.214:51852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOSn25uliftkV1n4BgwAAADM"]
[Tue Jul 21 07:43:05.257767 2026] [security2:error] [pid 296703:tid 296954] [client 20.226.60.151:50970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/rithin.php"] [unique_id "al9NOSn25uliftkV1n4BiAAAAHk"]
[Tue Jul 21 07:43:05.311791 2026] [security2:error] [pid 296703:tid 296867] [client 122.164.127.47:56356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NOSn25uliftkV1n4BiQAAACI"]
[Tue Jul 21 07:43:05.313098 2026] [security2:error] [pid 296703:tid 296867] [client 122.164.127.47:56356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NOSn25uliftkV1n4BiQAAACI"]
[Tue Jul 21 07:43:05.421620 2026] [security2:error] [pid 296703:tid 296933] [client 20.104.96.117:64048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/item.php"] [unique_id "al9NOSn25uliftkV1n4BjAAAAGQ"]
[Tue Jul 21 07:43:05.471292 2026] [security2:error] [pid 296703:tid 296860] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/classwithtostring.php"] [unique_id "al9NOSn25uliftkV1n4BjQAAABs"]
[Tue Jul 21 07:43:05.688573 2026] [security2:error] [pid 296703:tid 296820] [remote 202.51.202.242:56044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "legadoengenhariaam.com.br"] [uri "/wp-login.php"] [unique_id "al9NOSn25uliftkV1n4BlAAAY3Q"]
[Tue Jul 21 07:43:05.689080 2026] [security2:error] [pid 296703:tid 296903] [client 15.235.27.119:16214] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "aronimoveis.com.br"] [uri "/robots.txt"] [unique_id "al9NOSn25uliftkV1n4BlQAAAEY"]
[Tue Jul 21 07:43:05.689162 2026] [security2:error] [pid 296703:tid 296903] [client 15.235.27.119:16214] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aronimoveis.com.br"] [uri "/robots.txt"] [unique_id "al9NOSn25uliftkV1n4BlQAAAEY"]
[Tue Jul 21 07:43:05.759949 2026] [core:alert] [pid 296703:tid 296872] [client 57.141.18.65:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:43:05.785482 2026] [security2:error] [pid 296703:tid 296845] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9NOSn25uliftkV1n4BngAAAAw"]
[Tue Jul 21 07:43:05.789734 2026] [security2:error] [pid 296703:tid 296859] [client 20.104.96.117:62926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/ss.php"] [unique_id "al9NOSn25uliftkV1n4BnwAAABo"]
[Tue Jul 21 07:43:06.016756 2026] [security2:error] [pid 296703:tid 296943] [client 20.197.195.24:49859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/blurbs.php"] [unique_id "al9NOin25uliftkV1n4BqAAAAG4"]
[Tue Jul 21 07:43:06.067863 2026] [security2:error] [pid 296703:tid 296841] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wp-blog.php"] [unique_id "al9NOin25uliftkV1n4BqgAAAAg"]
[Tue Jul 21 07:43:06.179850 2026] [security2:error] [pid 296703:tid 296906] [client 20.226.60.151:56274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/fffm.php"] [unique_id "al9NOin25uliftkV1n4BrwAAAEk"]
[Tue Jul 21 07:43:06.336616 2026] [security2:error] [pid 296703:tid 296870] [client 130.195.241.7:39949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.241.195.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bellascleaningsolutionsllc.com"] [uri "/xmlrpc.php"] [unique_id "al9NOin25uliftkV1n4BtAAAACU"]
[Tue Jul 21 07:43:06.336735 2026] [security2:error] [pid 296703:tid 296870] [client 130.195.241.7:39949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bellascleaningsolutionsllc.com"] [uri "/xmlrpc.php"] [unique_id "al9NOin25uliftkV1n4BtAAAACU"]
[Tue Jul 21 07:43:06.343251 2026] [security2:error] [pid 296703:tid 296861] [client 20.104.96.117:64009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/hypo.php"] [unique_id "al9NOin25uliftkV1n4BtQAAABw"]
[Tue Jul 21 07:43:06.401850 2026] [security2:error] [pid 296703:tid 296921] [client 20.220.225.223:19264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/cro.php"] [unique_id "al9NOin25uliftkV1n4BtgAAAFg"]
[Tue Jul 21 07:43:06.445315 2026] [autoindex:error] [pid 296703:tid 296938] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:06.512564 2026] [security2:error] [pid 296703:tid 296821] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NOin25uliftkV1n4BugAAW3U"]
[Tue Jul 21 07:43:06.512686 2026] [security2:error] [pid 296703:tid 296924] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NOin25uliftkV1n4BugAAW3U"]
[Tue Jul 21 07:43:06.602902 2026] [security2:error] [pid 296703:tid 296911] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9NOin25uliftkV1n4BvwAAAE4"]
[Tue Jul 21 07:43:06.619101 2026] [security2:error] [pid 296703:tid 296907] [client 74.249.245.134:5515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/inputs.php"] [unique_id "al9NOin25uliftkV1n4BwAAAAEo"]
[Tue Jul 21 07:43:06.677043 2026] [security2:error] [pid 296703:tid 296853] [client 20.104.96.117:64020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/users.php"] [unique_id "al9NOin25uliftkV1n4BwgAAABQ"]
[Tue Jul 21 07:43:06.729304 2026] [security2:error] [pid 296703:tid 296879] [client 154.192.233.199:58639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOin25uliftkV1n4BwwAAAC4"]
[Tue Jul 21 07:43:06.729424 2026] [security2:error] [pid 296703:tid 296879] [client 154.192.233.199:58639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOin25uliftkV1n4BwwAAAC4"]
[Tue Jul 21 07:43:06.883857 2026] [security2:error] [pid 296703:tid 296862] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/ms-edit.php"] [unique_id "al9NOin25uliftkV1n4ByQAAAB0"]
[Tue Jul 21 07:43:06.941783 2026] [security2:error] [pid 296703:tid 296885] [client 20.226.60.151:54284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/inputs.php"] [unique_id "al9NOin25uliftkV1n4BywAAADQ"]
[Tue Jul 21 07:43:06.988837 2026] [security2:error] [pid 296703:tid 296884] [client 20.104.96.117:64000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/177.php"] [unique_id "al9NOin25uliftkV1n4BzAAAADM"]
[Tue Jul 21 07:43:06.998521 2026] [security2:error] [pid 296703:tid 296834] [client 184.75.223.211:43286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9NOin25uliftkV1n4BzQAAAAE"]
[Tue Jul 21 07:43:06.998634 2026] [security2:error] [pid 296703:tid 296834] [client 184.75.223.211:43286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9NOin25uliftkV1n4BzQAAAAE"]
[Tue Jul 21 07:43:07.015028 2026] [security2:error] [pid 296703:tid 296918] [client 37.140.223.134:27823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NOCn25uliftkV1n4BbgAAAFU"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:07.123509 2026] [security2:error] [pid 296703:tid 296920] [client 54.39.210.168:37260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "aronimoveis.com.br"] [uri "/"] [unique_id "al9NOyn25uliftkV1n4B0wAAAFc"]
[Tue Jul 21 07:43:07.123633 2026] [security2:error] [pid 296703:tid 296920] [client 54.39.210.168:37260] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aronimoveis.com.br"] [uri "/"] [unique_id "al9NOyn25uliftkV1n4B0wAAAFc"]
[Tue Jul 21 07:43:07.159158 2026] [security2:error] [pid 296703:tid 296896] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9NOyn25uliftkV1n4B1AAAAD8"]
[Tue Jul 21 07:43:07.327037 2026] [security2:error] [pid 296703:tid 296870] [client 20.197.195.24:13717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/bajah.php"] [unique_id "al9NOyn25uliftkV1n4B2QAAACU"]
[Tue Jul 21 07:43:07.451429 2026] [security2:error] [pid 296703:tid 296928] [client 20.104.96.117:5118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/config.php"] [unique_id "al9NOyn25uliftkV1n4B4AAAAF8"]
[Tue Jul 21 07:43:07.480543 2026] [autoindex:error] [pid 296703:tid 296924] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:07.540931 2026] [security2:error] [pid 296703:tid 296932] [client 20.220.225.223:19971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/cron-tab.php"] [unique_id "al9NOyn25uliftkV1n4B4gAAAGM"]
[Tue Jul 21 07:43:07.557657 2026] [security2:error] [pid 296703:tid 296891] [client 194.99.104.35:46236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9NOyn25uliftkV1n4B4wAAADo"]
[Tue Jul 21 07:43:07.557732 2026] [security2:error] [pid 296703:tid 296891] [client 194.99.104.35:46236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9NOyn25uliftkV1n4B4wAAADo"]
[Tue Jul 21 07:43:07.625827 2026] [security2:error] [pid 296703:tid 296851] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9NOyn25uliftkV1n4B5gAAABI"]
[Tue Jul 21 07:43:07.791198 2026] [security2:error] [pid 296703:tid 296882] [client 117.217.38.194:51594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOyn25uliftkV1n4B7AAAADE"]
[Tue Jul 21 07:43:07.791305 2026] [security2:error] [pid 296703:tid 296882] [client 117.217.38.194:51594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOyn25uliftkV1n4B7AAAADE"]
[Tue Jul 21 07:43:07.827831 2026] [security2:error] [pid 296703:tid 296922] [client 20.104.96.117:5056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/gettest.php"] [unique_id "al9NOyn25uliftkV1n4B7QAAAFk"]
[Tue Jul 21 07:43:07.913389 2026] [security2:error] [pid 296703:tid 296878] [client 20.226.60.151:59433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-link-zorm.php"] [unique_id "al9NOyn25uliftkV1n4B8gAAAC0"]
[Tue Jul 21 07:43:07.934459 2026] [autoindex:error] [pid 296703:tid 296849] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:08.117754 2026] [autoindex:error] [pid 296703:tid 296896] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:08.205663 2026] [security2:error] [pid 296703:tid 296860] [client 20.226.60.151:22339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/nc4.php"] [unique_id "al9NPCn25uliftkV1n4CAAAAABs"]
[Tue Jul 21 07:43:08.262782 2026] [security2:error] [pid 296703:tid 296871] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/abcd.php"] [unique_id "al9NPCn25uliftkV1n4CAQAAACY"]
[Tue Jul 21 07:43:08.452723 2026] [security2:error] [pid 296703:tid 296887] [client 20.226.60.151:60158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/classwithtostring.php"] [unique_id "al9NPCn25uliftkV1n4CBwAAADY"]
[Tue Jul 21 07:43:08.470104 2026] [security2:error] [pid 296703:tid 296880] [client 74.249.245.134:54337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/ms-edit.php"] [unique_id "al9NPCn25uliftkV1n4CCAAAAC8"]
[Tue Jul 21 07:43:08.488942 2026] [security2:error] [pid 296703:tid 296907] [client 20.226.60.151:56225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/dfre.php"] [unique_id "al9NPCn25uliftkV1n4CCQAAAEo"]
[Tue Jul 21 07:43:08.522242 2026] [security2:error] [pid 296703:tid 296919] [client 20.104.96.117:5073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/min.php"] [unique_id "al9NPCn25uliftkV1n4CDQAAAFY"]
[Tue Jul 21 07:43:08.548602 2026] [security2:error] [pid 296703:tid 296872] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/file15.php"] [unique_id "al9NPCn25uliftkV1n4CDwAAACc"]
[Tue Jul 21 07:43:08.648258 2026] [security2:error] [pid 296703:tid 296917] [client 20.197.195.24:13732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/a.php"] [unique_id "al9NPCn25uliftkV1n4CEQAAAFQ"]
[Tue Jul 21 07:43:08.815411 2026] [security2:error] [pid 296703:tid 296884] [client 59.96.220.140:59689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NPCn25uliftkV1n4CFgAAADM"]
[Tue Jul 21 07:43:08.815554 2026] [security2:error] [pid 296703:tid 296884] [client 59.96.220.140:59689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NPCn25uliftkV1n4CFgAAADM"]
[Tue Jul 21 07:43:08.830068 2026] [security2:error] [pid 296703:tid 296840] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/jp.php"] [unique_id "al9NPCn25uliftkV1n4CFwAAAAc"]
[Tue Jul 21 07:43:09.033804 2026] [security2:error] [pid 296703:tid 296924] [client 103.106.20.201:54354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NPSn25uliftkV1n4CHgAAAFs"]
[Tue Jul 21 07:43:09.033937 2026] [security2:error] [pid 296703:tid 296924] [client 103.106.20.201:54354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NPSn25uliftkV1n4CHgAAAFs"]
[Tue Jul 21 07:43:09.121569 2026] [security2:error] [pid 296703:tid 296886] [client 20.104.96.117:62936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/dvjul.php"] [unique_id "al9NPSn25uliftkV1n4CIwAAADU"]
[Tue Jul 21 07:43:09.145651 2026] [security2:error] [pid 296703:tid 296870] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/f35.php"] [unique_id "al9NPSn25uliftkV1n4CJAAAACU"]
[Tue Jul 21 07:43:09.210672 2026] [security2:error] [pid 296703:tid 296861] [client 20.226.60.151:51219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-happy.php"] [unique_id "al9NPSn25uliftkV1n4CJgAAABw"]
[Tue Jul 21 07:43:09.434616 2026] [security2:error] [pid 296703:tid 296880] [client 20.104.96.117:62971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/biufile.php"] [unique_id "al9NPSn25uliftkV1n4CMQAAAC8"]
[Tue Jul 21 07:43:09.452547 2026] [security2:error] [pid 296703:tid 296879] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wp-load.php"] [unique_id "al9NPSn25uliftkV1n4CMwAAAC4"]
[Tue Jul 21 07:43:09.522016 2026] [security2:error] [pid 296703:tid 296911] [client 74.249.245.134:17459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/simple.php"] [unique_id "al9NPSn25uliftkV1n4CNwAAAE4"]
[Tue Jul 21 07:43:09.560092 2026] [security2:error] [pid 296703:tid 296883] [client 122.162.144.145:20134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NPSn25uliftkV1n4COQAAADI"]
[Tue Jul 21 07:43:09.560202 2026] [security2:error] [pid 296703:tid 296883] [client 122.162.144.145:20134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NPSn25uliftkV1n4COQAAADI"]
[Tue Jul 21 07:43:09.657178 2026] [security2:error] [pid 296703:tid 296933] [client 20.226.60.151:61953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9NPSn25uliftkV1n4COgAAAGQ"]
[Tue Jul 21 07:43:09.753379 2026] [security2:error] [pid 296703:tid 296923] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/xyn.php"] [unique_id "al9NPSn25uliftkV1n4CPwAAAFo"]
[Tue Jul 21 07:43:09.832859 2026] [security2:error] [pid 296703:tid 296958] [client 20.104.96.117:4186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/av.php"] [unique_id "al9NPSn25uliftkV1n4CRQAAAH0"]
[Tue Jul 21 07:43:09.848018 2026] [security2:error] [pid 296703:tid 296873] [client 193.36.225.65:32873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NPSn25uliftkV1n4CSAAAACg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:09.957141 2026] [security2:error] [pid 296703:tid 296876] [client 20.197.195.24:13697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/edit.php"] [unique_id "al9NPSn25uliftkV1n4CTQAAACs"]
[Tue Jul 21 07:43:09.985446 2026] [security2:error] [pid 296703:tid 296868] [client 152.59.154.239:55938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NPSn25uliftkV1n4CUAAAACM"]
[Tue Jul 21 07:43:09.985528 2026] [security2:error] [pid 296703:tid 296868] [client 152.59.154.239:55938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NPSn25uliftkV1n4CUAAAACM"]
[Tue Jul 21 07:43:10.040197 2026] [autoindex:error] [pid 296703:tid 296928] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:10.077250 2026] [security2:error] [pid 296703:tid 296855] [client 20.104.96.117:30860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/root.php"] [unique_id "al9NPin25uliftkV1n4CVAAAABY"]
[Tue Jul 21 07:43:10.109458 2026] [security2:error] [pid 296703:tid 296850] [client 139.167.225.182:51886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NPin25uliftkV1n4CVgAAABE"]
[Tue Jul 21 07:43:10.109641 2026] [security2:error] [pid 296703:tid 296850] [client 139.167.225.182:51886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NPin25uliftkV1n4CVgAAABE"]
[Tue Jul 21 07:43:10.160685 2026] [security2:error] [pid 296703:tid 296919] [client 20.104.96.117:62915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/coffexium.php"] [unique_id "al9NPin25uliftkV1n4CWAAAAFY"]
[Tue Jul 21 07:43:10.232097 2026] [autoindex:error] [pid 296703:tid 296835] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:10.370863 2026] [security2:error] [pid 296703:tid 296877] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/ccc.php"] [unique_id "al9NPin25uliftkV1n4CYwAAACw"]
[Tue Jul 21 07:43:10.464503 2026] [security2:error] [pid 296703:tid 296904] [client 20.104.96.117:5097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/core.php"] [unique_id "al9NPin25uliftkV1n4CZgAAAEc"]
[Tue Jul 21 07:43:10.681732 2026] [security2:error] [pid 296703:tid 296924] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/w.php"] [unique_id "al9NPin25uliftkV1n4CagAAAFs"]
[Tue Jul 21 07:43:10.704009 2026] [security2:error] [pid 296703:tid 296838] [client 20.226.60.151:59421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-link-szoppm.php"] [unique_id "al9NPin25uliftkV1n4CawAAAAU"]
[Tue Jul 21 07:43:10.751202 2026] [security2:error] [pid 296703:tid 296840] [client 20.104.96.117:5080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/als.php"] [unique_id "al9NPin25uliftkV1n4CbAAAAAc"]
[Tue Jul 21 07:43:10.856848 2026] [security2:error] [pid 296703:tid 296952] [client 74.249.245.134:5505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/404.php"] [unique_id "al9NPin25uliftkV1n4CcgAAAHc"]
[Tue Jul 21 07:43:10.898059 2026] [security2:error] [pid 296703:tid 296896] [client 54.238.249.23:60176] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=http://user@:80"] [hostname "academycont.com"] [uri "/wp-json/batch/v1"] [unique_id "al9NPin25uliftkV1n4CdAAAAD8"]
[Tue Jul 21 07:43:10.996227 2026] [security2:error] [pid 296703:tid 296841] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9NPin25uliftkV1n4CeAAAAAg"]
[Tue Jul 21 07:43:11.039004 2026] [security2:error] [pid 296703:tid 296850] [client 20.197.195.24:13803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/hosty.php"] [unique_id "al9NPyn25uliftkV1n4CfAAAABE"]
[Tue Jul 21 07:43:11.074920 2026] [security2:error] [pid 296703:tid 296906] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9NPyn25uliftkV1n4CfQAAAEk"]
[Tue Jul 21 07:43:11.096663 2026] [security2:error] [pid 296703:tid 296929] [client 20.104.96.117:62918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/simple.php"] [unique_id "al9NPyn25uliftkV1n4CfgAAAGA"]
[Tue Jul 21 07:43:11.279626 2026] [security2:error] [pid 296703:tid 296879] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/FWAZ.php"] [unique_id "al9NPyn25uliftkV1n4CfwAAAC4"]
[Tue Jul 21 07:43:11.305794 2026] [security2:error] [pid 296703:tid 296888] [client 20.226.60.151:54347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-blog.php"] [unique_id "al9NPyn25uliftkV1n4CggAAADc"]
[Tue Jul 21 07:43:11.317136 2026] [security2:error] [pid 296703:tid 296931] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9NPyn25uliftkV1n4ChAAAAGI"]
[Tue Jul 21 07:43:11.494281 2026] [security2:error] [pid 296703:tid 296930] [client 20.104.96.117:64004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/init.php"] [unique_id "al9NPyn25uliftkV1n4CigAAAGE"]
[Tue Jul 21 07:43:11.561319 2026] [security2:error] [pid 296703:tid 296868] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/miru1.php"] [unique_id "al9NPyn25uliftkV1n4ClAAAACM"]
[Tue Jul 21 07:43:11.604838 2026] [security2:error] [pid 296703:tid 296839] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9NPyn25uliftkV1n4ClgAAAAY"]
[Tue Jul 21 07:43:11.644684 2026] [security2:error] [pid 296703:tid 296796] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NPyn25uliftkV1n4CmAAAUlw"]
[Tue Jul 21 07:43:11.644798 2026] [security2:error] [pid 296703:tid 296915] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NPyn25uliftkV1n4CmAAAUlw"]
[Tue Jul 21 07:43:11.677327 2026] [security2:error] [pid 296703:tid 296952] [client 20.151.10.161:55292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/waf.php"] [unique_id "al9NPyn25uliftkV1n4CmQAAAHc"]
[Tue Jul 21 07:43:11.723628 2026] [security2:error] [pid 296703:tid 296902] [client 20.197.195.24:13706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/k.php"] [unique_id "al9NPyn25uliftkV1n4CmwAAAEU"]
[Tue Jul 21 07:43:11.755581 2026] [security2:error] [pid 296703:tid 296940] [client 173.24.185.52:56940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NPyn25uliftkV1n4CnwAAAGs"]
[Tue Jul 21 07:43:11.755742 2026] [security2:error] [pid 296703:tid 296940] [client 173.24.185.52:56940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NPyn25uliftkV1n4CnwAAAGs"]
[Tue Jul 21 07:43:11.773253 2026] [security2:error] [pid 296703:tid 296950] [client 20.226.60.151:56238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/fpr4.php"] [unique_id "al9NPyn25uliftkV1n4CoAAAAHU"]
[Tue Jul 21 07:43:11.804372 2026] [security2:error] [pid 296703:tid 296887] [client 20.104.96.117:5104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/fpwch.php"] [unique_id "al9NPyn25uliftkV1n4CoQAAADY"]
[Tue Jul 21 07:43:11.827079 2026] [security2:error] [pid 296703:tid 296835] [client 103.166.103.129:59278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NPyn25uliftkV1n4CpAAAAAI"]
[Tue Jul 21 07:43:11.827277 2026] [security2:error] [pid 296703:tid 296835] [client 103.166.103.129:59278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NPyn25uliftkV1n4CpAAAAAI"]
[Tue Jul 21 07:43:11.838158 2026] [security2:error] [pid 296703:tid 296861] [client 54.238.249.23:33758] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=http://user@:80"] [hostname "academycont.com"] [uri "/"] [unique_id "al9NPyn25uliftkV1n4CpwAAABw"]
[Tue Jul 21 07:43:11.843477 2026] [security2:error] [pid 296703:tid 296883] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/aa.php"] [unique_id "al9NPyn25uliftkV1n4CqgAAADI"]
[Tue Jul 21 07:43:11.893757 2026] [security2:error] [pid 296703:tid 296882] [client 20.220.225.223:19266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/koiy.php"] [unique_id "al9NPyn25uliftkV1n4CrAAAADE"]
[Tue Jul 21 07:43:11.968486 2026] [security2:error] [pid 296703:tid 296888] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9NPyn25uliftkV1n4CrQAAADc"]
[Tue Jul 21 07:43:11.975855 2026] [security2:error] [pid 296703:tid 296939] [client 122.179.91.63:29355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NPyn25uliftkV1n4CrgAAAGo"]
[Tue Jul 21 07:43:11.975946 2026] [security2:error] [pid 296703:tid 296939] [client 122.179.91.63:29355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NPyn25uliftkV1n4CrgAAAGo"]
[Tue Jul 21 07:43:12.125285 2026] [security2:error] [pid 296703:tid 296913] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/122.php"] [unique_id "al9NQCn25uliftkV1n4CtAAAAFA"]
[Tue Jul 21 07:43:12.141450 2026] [security2:error] [pid 296703:tid 296930] [client 20.104.96.117:4229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/domvf.php"] [unique_id "al9NQCn25uliftkV1n4CtQAAAGE"]
[Tue Jul 21 07:43:12.219715 2026] [security2:error] [pid 296703:tid 296908] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9NQCn25uliftkV1n4CugAAAEs"]
[Tue Jul 21 07:43:12.227180 2026] [security2:error] [pid 296703:tid 296848] [client 74.249.245.134:5567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/file3.php"] [unique_id "al9NQCn25uliftkV1n4CuwAAAA8"]
[Tue Jul 21 07:43:12.351594 2026] [security2:error] [pid 296703:tid 296817] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NQCn25uliftkV1n4CvgAAJXE"]
[Tue Jul 21 07:43:12.351736 2026] [security2:error] [pid 296703:tid 296870] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NQCn25uliftkV1n4CvgAAJXE"]
[Tue Jul 21 07:43:12.431137 2026] [security2:error] [pid 296703:tid 296807] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9NQCn25uliftkV1n4CwgAAX2c"]
[Tue Jul 21 07:43:12.442804 2026] [security2:error] [pid 296703:tid 296853] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/get.php"] [unique_id "al9NQCn25uliftkV1n4CwwAAABQ"]
[Tue Jul 21 07:43:12.503679 2026] [security2:error] [pid 296703:tid 296781] [remote 45.3.45.241:34879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9NQCn25uliftkV1n4CvQAAOk0"]
[Tue Jul 21 07:43:12.520885 2026] [security2:error] [pid 296703:tid 296950] [client 20.104.96.117:62917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wp.php"] [unique_id "al9NQCn25uliftkV1n4CxAAAAHU"]
[Tue Jul 21 07:43:12.581013 2026] [security2:error] [pid 296703:tid 296731] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9NQCn25uliftkV1n4CxgAANhs"]
[Tue Jul 21 07:43:12.641466 2026] [security2:error] [pid 296703:tid 296947] [client 20.197.195.24:13752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/aaa.php"] [unique_id "al9NQCn25uliftkV1n4CywAAAHI"]
[Tue Jul 21 07:43:12.648220 2026] [security2:error] [pid 296703:tid 296938] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9NQCn25uliftkV1n4CzAAAAGk"]
[Tue Jul 21 07:43:12.785742 2026] [security2:error] [pid 296703:tid 296811] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9NQCn25uliftkV1n4C0AAALWs"]
[Tue Jul 21 07:43:12.822400 2026] [security2:error] [pid 296703:tid 296931] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/as.php"] [unique_id "al9NQCn25uliftkV1n4C0QAAAGI"]
[Tue Jul 21 07:43:12.840320 2026] [security2:error] [pid 296703:tid 296845] [client 20.104.96.117:5084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/class.php"] [unique_id "al9NQCn25uliftkV1n4C0gAAAAw"]
[Tue Jul 21 07:43:12.905737 2026] [security2:error] [pid 296703:tid 296847] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9NQCn25uliftkV1n4C1wAAAA4"]
[Tue Jul 21 07:43:12.925278 2026] [security2:error] [pid 296703:tid 296822] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9NQCn25uliftkV1n4C2AAAWnY"]
[Tue Jul 21 07:43:13.104515 2026] [security2:error] [pid 296703:tid 296920] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/ccou.php"] [unique_id "al9NQSn25uliftkV1n4C3gAAAFc"]
[Tue Jul 21 07:43:13.137925 2026] [security2:error] [pid 296703:tid 296839] [client 20.104.96.117:4173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/echkm.php"] [unique_id "al9NQSn25uliftkV1n4C4AAAAAY"]
[Tue Jul 21 07:43:13.154058 2026] [security2:error] [pid 296703:tid 296706] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9NQSn25uliftkV1n4C4QAAKwI"]
[Tue Jul 21 07:43:13.155973 2026] [security2:error] [pid 296703:tid 296915] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9NQSn25uliftkV1n4C4gAAAFI"]
[Tue Jul 21 07:43:13.219611 2026] [security2:error] [pid 296703:tid 296960] [client 20.226.60.151:56258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/file88.php"] [unique_id "al9NQSn25uliftkV1n4C4wAAAH8"]
[Tue Jul 21 07:43:13.242272 2026] [security2:error] [pid 296703:tid 296863] [client 103.174.34.15:58072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NQSn25uliftkV1n4C5AAAAB4"]
[Tue Jul 21 07:43:13.242698 2026] [security2:error] [pid 296703:tid 296863] [client 103.174.34.15:58072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NQSn25uliftkV1n4C5AAAAB4"]
[Tue Jul 21 07:43:13.333961 2026] [security2:error] [pid 296703:tid 296850] [client 62.102.148.187:34684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9NQSn25uliftkV1n4C5gAAABE"]
[Tue Jul 21 07:43:13.334120 2026] [security2:error] [pid 296703:tid 296850] [client 62.102.148.187:34684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9NQSn25uliftkV1n4C5gAAABE"]
[Tue Jul 21 07:43:13.348776 2026] [security2:error] [pid 296703:tid 296853] [client 20.197.195.24:13818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/file5.php"] [unique_id "al9NQSn25uliftkV1n4C5wAAABQ"]
[Tue Jul 21 07:43:13.365520 2026] [security2:error] [pid 296703:tid 296767] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9NQSn25uliftkV1n4C6AAAFj8"]
[Tue Jul 21 07:43:13.388064 2026] [security2:error] [pid 296703:tid 296935] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/w3lls.php"] [unique_id "al9NQSn25uliftkV1n4C6gAAAGY"]
[Tue Jul 21 07:43:13.461833 2026] [security2:error] [pid 296703:tid 296862] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9NQSn25uliftkV1n4C7gAAAB0"]
[Tue Jul 21 07:43:13.462847 2026] [security2:error] [pid 296703:tid 296718] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NQSn25uliftkV1n4C7wAAHA4"]
[Tue Jul 21 07:43:13.462969 2026] [security2:error] [pid 296703:tid 296861] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NQSn25uliftkV1n4C7wAAHA4"]
[Tue Jul 21 07:43:13.567893 2026] [security2:error] [pid 296703:tid 296881] [client 20.104.96.117:64062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/lib.php"] [unique_id "al9NQSn25uliftkV1n4C8gAAADA"]
[Tue Jul 21 07:43:13.612765 2026] [security2:error] [pid 296703:tid 296829] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9NQSn25uliftkV1n4C9AAASn0"]
[Tue Jul 21 07:43:13.690930 2026] [security2:error] [pid 296703:tid 296922] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/test1.php"] [unique_id "al9NQSn25uliftkV1n4C-AAAAFk"]
[Tue Jul 21 07:43:13.714101 2026] [security2:error] [pid 296703:tid 296884] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9NQSn25uliftkV1n4C-gAAADM"]
[Tue Jul 21 07:43:13.760971 2026] [security2:error] [pid 296703:tid 296904] [client 20.197.195.24:13723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/222.php"] [unique_id "al9NQSn25uliftkV1n4C-wAAAEc"]
[Tue Jul 21 07:43:13.879537 2026] [security2:error] [pid 296703:tid 296738] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9NQSn25uliftkV1n4C_AAAGiI"]
[Tue Jul 21 07:43:13.919627 2026] [security2:error] [pid 296703:tid 296918] [client 20.104.96.117:4196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/login.php"] [unique_id "al9NQSn25uliftkV1n4C_QAAAFU"]
[Tue Jul 21 07:43:13.942115 2026] [security2:error] [pid 296703:tid 296897] [client 106.215.181.8:3523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NQSn25uliftkV1n4DAgAAAEA"]
[Tue Jul 21 07:43:13.942244 2026] [security2:error] [pid 296703:tid 296897] [client 106.215.181.8:3523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NQSn25uliftkV1n4DAgAAAEA"]
[Tue Jul 21 07:43:13.949718 2026] [security2:error] [pid 296703:tid 296953] [client 31.14.72.5:49156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9NQSn25uliftkV1n4DAwAAAHg"]
[Tue Jul 21 07:43:13.956728 2026] [security2:error] [pid 296703:tid 296886] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9NQSn25uliftkV1n4DBAAAADU"]
[Tue Jul 21 07:43:13.966544 2026] [security2:error] [pid 296703:tid 296888] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/database.php"] [unique_id "al9NQSn25uliftkV1n4DBQAAADc"]
[Tue Jul 21 07:43:14.011248 2026] [security2:error] [pid 296703:tid 296719] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9NQin25uliftkV1n4DBgAARA8"]
[Tue Jul 21 07:43:14.093578 2026] [security2:error] [pid 296703:tid 296742] [remote 47.128.54.230:48604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.serbetoadv.com"] [uri "/siemens-iq300-sn63ex15be-k.html"] [unique_id "al9NQin25uliftkV1n4DCwAAJiY"]
[Tue Jul 21 07:43:14.123319 2026] [security2:error] [pid 296703:tid 296960] [client 20.197.195.24:13771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/test.php"] [unique_id "al9NQin25uliftkV1n4DDAAAAH8"]
[Tue Jul 21 07:43:14.144867 2026] [security2:error] [pid 296703:tid 296776] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9NQin25uliftkV1n4DDQAACEg"]
[Tue Jul 21 07:43:14.176357 2026] [security2:error] [pid 296703:tid 296930] [client 20.151.10.161:12072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xstelth.php"] [unique_id "al9NQin25uliftkV1n4DEAAAAGE"]
[Tue Jul 21 07:43:14.234717 2026] [security2:error] [pid 296703:tid 296928] [client 20.104.96.117:62957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/a2.php"] [unique_id "al9NQin25uliftkV1n4DEgAAAF8"]
[Tue Jul 21 07:43:14.251809 2026] [security2:error] [pid 296703:tid 296927] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/file.php"] [unique_id "al9NQin25uliftkV1n4DEwAAAF4"]
[Tue Jul 21 07:43:14.268606 2026] [security2:error] [pid 296703:tid 296853] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9NQin25uliftkV1n4DFAAAABQ"]
[Tue Jul 21 07:43:14.454760 2026] [security2:error] [pid 296703:tid 296722] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NQin25uliftkV1n4DHAAAERI"]
[Tue Jul 21 07:43:14.454937 2026] [security2:error] [pid 296703:tid 296850] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NQin25uliftkV1n4DHAAAERI"]
[Tue Jul 21 07:43:14.482886 2026] [security2:error] [pid 296703:tid 296736] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9NQin25uliftkV1n4DHQAAASA"]
[Tue Jul 21 07:43:14.535286 2026] [security2:error] [pid 296703:tid 296931] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/file.php"] [unique_id "al9NQin25uliftkV1n4DIAAAAGI"]
[Tue Jul 21 07:43:14.663910 2026] [security2:error] [pid 296703:tid 296730] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9NQin25uliftkV1n4DKAAADho"]
[Tue Jul 21 07:43:14.674519 2026] [security2:error] [pid 296703:tid 296913] [client 182.8.255.181:17341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NQin25uliftkV1n4DKQAAAFA"]
[Tue Jul 21 07:43:14.674717 2026] [security2:error] [pid 296703:tid 296913] [client 182.8.255.181:17341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NQin25uliftkV1n4DKQAAAFA"]
[Tue Jul 21 07:43:14.683434 2026] [security2:error] [pid 296703:tid 296752] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NQin25uliftkV1n4DKwAAbjA"]
[Tue Jul 21 07:43:14.683565 2026] [security2:error] [pid 296703:tid 296943] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NQin25uliftkV1n4DKwAAbjA"]
[Tue Jul 21 07:43:14.708729 2026] [security2:error] [pid 296703:tid 296838] [client 20.104.96.117:5103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/d61.php"] [unique_id "al9NQin25uliftkV1n4DLgAAAAU"]
[Tue Jul 21 07:43:14.719325 2026] [autoindex:error] [pid 296703:tid 296953] [client 20.226.60.151:61971] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:14.741504 2026] [security2:error] [pid 296703:tid 296888] [client 20.226.60.151:61971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9NQin25uliftkV1n4DMgAAADc"]
[Tue Jul 21 07:43:14.842916 2026] [security2:error] [pid 296703:tid 296902] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/777.php"] [unique_id "al9NQin25uliftkV1n4DNQAAAEU"]
[Tue Jul 21 07:43:14.866695 2026] [security2:error] [pid 296703:tid 296870] [client 20.226.60.151:51239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/ccc.php"] [unique_id "al9NQin25uliftkV1n4DNgAAACU"]
[Tue Jul 21 07:43:14.974756 2026] [security2:error] [pid 296703:tid 296889] [client 31.14.72.5:49906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9NQin25uliftkV1n4DPAAAADg"]
[Tue Jul 21 07:43:15.063886 2026] [security2:error] [pid 296703:tid 296861] [client 20.104.96.117:4189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/info.php"] [unique_id "al9NQyn25uliftkV1n4DQQAAABw"]
[Tue Jul 21 07:43:15.085735 2026] [security2:error] [pid 296703:tid 296880] [client 136.144.33.54:49667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NQin25uliftkV1n4DNwAAAC8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:15.132668 2026] [security2:error] [pid 296703:tid 296876] [client 20.197.195.24:13731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/aaa.php"] [unique_id "al9NQyn25uliftkV1n4DQgAAACs"]
[Tue Jul 21 07:43:15.167507 2026] [security2:error] [pid 296703:tid 296890] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/ssixta.php"] [unique_id "al9NQyn25uliftkV1n4DQwAAADk"]
[Tue Jul 21 07:43:15.280630 2026] [security2:error] [pid 296703:tid 296937] [client 20.151.10.161:12046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-links.php"] [unique_id "al9NQyn25uliftkV1n4DTAAAAGg"]
[Tue Jul 21 07:43:15.305555 2026] [security2:error] [pid 296703:tid 296847] [client 74.249.245.134:5543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/wp-mail.php"] [unique_id "al9NQyn25uliftkV1n4DTgAAAA4"]
[Tue Jul 21 07:43:15.347309 2026] [security2:error] [pid 296703:tid 296859] [client 20.226.60.151:63577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/albin.php"] [unique_id "al9NQyn25uliftkV1n4DTwAAABo"]
[Tue Jul 21 07:43:15.395730 2026] [security2:error] [pid 296703:tid 296848] [client 103.86.117.203:55637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DUAAAAA8"]
[Tue Jul 21 07:43:15.395896 2026] [security2:error] [pid 296703:tid 296848] [client 103.86.117.203:55637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DUAAAAA8"]
[Tue Jul 21 07:43:15.430084 2026] [security2:error] [pid 296703:tid 296838] [client 20.104.96.117:5091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/11.php"] [unique_id "al9NQyn25uliftkV1n4DUQAAAAU"]
[Tue Jul 21 07:43:15.442469 2026] [security2:error] [pid 296703:tid 296885] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/1c.php"] [unique_id "al9NQyn25uliftkV1n4DUgAAADQ"]
[Tue Jul 21 07:43:15.637229 2026] [security2:error] [pid 296703:tid 296853] [client 31.14.72.5:50431] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9NQyn25uliftkV1n4DWgAAABQ"]
[Tue Jul 21 07:43:15.660855 2026] [security2:error] [pid 296703:tid 296841] [client 117.251.86.144:60910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DXAAAAAg"]
[Tue Jul 21 07:43:15.660961 2026] [security2:error] [pid 296703:tid 296841] [client 117.251.86.144:60910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DXAAAAAg"]
[Tue Jul 21 07:43:15.732497 2026] [security2:error] [pid 296703:tid 296862] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/test2.php"] [unique_id "al9NQyn25uliftkV1n4DYgAAAB0"]
[Tue Jul 21 07:43:15.791990 2026] [security2:error] [pid 296703:tid 296947] [client 122.186.204.214:58532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DZAAAAHI"]
[Tue Jul 21 07:43:15.811867 2026] [security2:error] [pid 296703:tid 296947] [client 122.186.204.214:58532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DZAAAAHI"]
[Tue Jul 21 07:43:15.830332 2026] [security2:error] [pid 296703:tid 296856] [client 20.104.96.117:62959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/v2.php"] [unique_id "al9NQyn25uliftkV1n4DZQAAABc"]
[Tue Jul 21 07:43:15.850323 2026] [security2:error] [pid 296703:tid 296935] [client 122.164.127.47:56924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DZgAAAGY"]
[Tue Jul 21 07:43:15.850438 2026] [security2:error] [pid 296703:tid 296935] [client 122.164.127.47:56924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DZgAAAGY"]
[Tue Jul 21 07:43:15.908557 2026] [security2:error] [pid 296703:tid 296775] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DZwAAOEc"]
[Tue Jul 21 07:43:15.908698 2026] [security2:error] [pid 296703:tid 296889] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DZwAAOEc"]
[Tue Jul 21 07:43:15.932707 2026] [security2:error] [pid 296703:tid 296884] [client 117.247.80.59:31032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DaQAAADM"]
[Tue Jul 21 07:43:15.932832 2026] [security2:error] [pid 296703:tid 296884] [client 117.247.80.59:31032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DaQAAADM"]
[Tue Jul 21 07:43:15.993185 2026] [security2:error] [pid 296703:tid 296929] [client 20.226.60.151:54327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ms-edit.php"] [unique_id "al9NQyn25uliftkV1n4DagAAAGA"]
[Tue Jul 21 07:43:16.089087 2026] [security2:error] [pid 296703:tid 296937] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/buy.php"] [unique_id "al9NRCn25uliftkV1n4DbwAAAGg"]
[Tue Jul 21 07:43:16.098859 2026] [security2:error] [pid 296703:tid 296955] [client 20.226.60.151:50918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/cilus.php"] [unique_id "al9NRCn25uliftkV1n4DcAAAAHo"]
[Tue Jul 21 07:43:16.133289 2026] [security2:error] [pid 296703:tid 296945] [client 20.104.96.117:4236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/panel.php"] [unique_id "al9NRCn25uliftkV1n4DcQAAAHA"]
[Tue Jul 21 07:43:16.336337 2026] [security2:error] [pid 296703:tid 296930] [client 31.14.72.5:50732] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9NRCn25uliftkV1n4DeQAAAGE"]
[Tue Jul 21 07:43:16.371535 2026] [security2:error] [pid 296703:tid 296933] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/ssend.php"] [unique_id "al9NRCn25uliftkV1n4DegAAAGQ"]
[Tue Jul 21 07:43:16.394993 2026] [security2:error] [pid 296703:tid 296850] [client 202.143.127.214:52286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NRCn25uliftkV1n4DewAAABE"]
[Tue Jul 21 07:43:16.395220 2026] [security2:error] [pid 296703:tid 296850] [client 202.143.127.214:52286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NRCn25uliftkV1n4DewAAABE"]
[Tue Jul 21 07:43:16.404961 2026] [security2:error] [pid 296703:tid 296917] [client 20.151.10.161:53621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9NRCn25uliftkV1n4DfAAAAFQ"]
[Tue Jul 21 07:43:16.436720 2026] [security2:error] [pid 296703:tid 296887] [client 20.104.96.117:5094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/dex.php"] [unique_id "al9NRCn25uliftkV1n4DfgAAADY"]
[Tue Jul 21 07:43:16.647367 2026] [security2:error] [pid 296703:tid 296876] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/item.php"] [unique_id "al9NRCn25uliftkV1n4DhAAAACs"]
[Tue Jul 21 07:43:16.717721 2026] [security2:error] [pid 296703:tid 296856] [client 20.226.60.151:59426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/gptsh.php"] [unique_id "al9NRCn25uliftkV1n4DhQAAABc"]
[Tue Jul 21 07:43:16.725566 2026] [security2:error] [pid 296703:tid 296935] [client 20.104.96.117:5081] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "fit4me.online"] [uri "/1.php"] [unique_id "al9NRCn25uliftkV1n4DhwAAAGY"]
[Tue Jul 21 07:43:16.725689 2026] [security2:error] [pid 296703:tid 296935] [client 20.104.96.117:5081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/1.php"] [unique_id "al9NRCn25uliftkV1n4DhwAAAGY"]
[Tue Jul 21 07:43:16.939687 2026] [security2:error] [pid 296703:tid 296926] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/ss.php"] [unique_id "al9NRCn25uliftkV1n4DjQAAAF0"]
[Tue Jul 21 07:43:17.002060 2026] [security2:error] [pid 296703:tid 296845] [client 31.14.72.5:51059] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9NRSn25uliftkV1n4DjgAAAAw"]
[Tue Jul 21 07:43:17.036364 2026] [security2:error] [pid 296703:tid 296847] [client 20.226.60.151:54312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9NRSn25uliftkV1n4DjwAAAA4"]
[Tue Jul 21 07:43:17.051580 2026] [security2:error] [pid 296703:tid 296938] [client 20.197.195.24:13733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/11.php"] [unique_id "al9NRSn25uliftkV1n4DkAAAAGk"]
[Tue Jul 21 07:43:17.062032 2026] [security2:error] [pid 296703:tid 296793] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NRSn25uliftkV1n4DkQAAGlk"]
[Tue Jul 21 07:43:17.062207 2026] [security2:error] [pid 296703:tid 296859] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NRSn25uliftkV1n4DkQAAGlk"]
[Tue Jul 21 07:43:17.107472 2026] [security2:error] [pid 296703:tid 296953] [client 20.104.96.117:30400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/sym403.php"] [unique_id "al9NRSn25uliftkV1n4DlQAAAHg"]
[Tue Jul 21 07:43:17.121461 2026] [security2:error] [pid 296703:tid 296950] [client 20.104.96.117:5061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/ms.php"] [unique_id "al9NRSn25uliftkV1n4DmQAAAHU"]
[Tue Jul 21 07:43:17.218643 2026] [security2:error] [pid 296703:tid 296869] [client 74.249.245.134:54344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/about.php"] [unique_id "al9NRSn25uliftkV1n4DnAAAACQ"]
[Tue Jul 21 07:43:17.257662 2026] [security2:error] [pid 296703:tid 296885] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/hypo.php"] [unique_id "al9NRSn25uliftkV1n4DngAAADQ"]
[Tue Jul 21 07:43:17.323275 2026] [security2:error] [pid 296703:tid 296917] [client 20.226.60.151:51236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/777.php"] [unique_id "al9NRSn25uliftkV1n4DoAAAAFQ"]
[Tue Jul 21 07:43:17.356995 2026] [security2:error] [pid 296703:tid 296928] [client 20.197.195.24:13822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/mac.php"] [unique_id "al9NRSn25uliftkV1n4DoQAAAF8"]
[Tue Jul 21 07:43:17.401509 2026] [security2:error] [pid 296703:tid 296911] [client 20.197.195.24:13820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/chosen.php"] [unique_id "al9NRSn25uliftkV1n4DpQAAAE4"]
[Tue Jul 21 07:43:17.543862 2026] [security2:error] [pid 296703:tid 296931] [client 154.192.233.199:59921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NRSn25uliftkV1n4DpwAAAGI"]
[Tue Jul 21 07:43:17.544030 2026] [security2:error] [pid 296703:tid 296931] [client 154.192.233.199:59921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NRSn25uliftkV1n4DpwAAAGI"]
[Tue Jul 21 07:43:17.575732 2026] [security2:error] [pid 296703:tid 296924] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/users.php"] [unique_id "al9NRSn25uliftkV1n4DqQAAAFs"]
[Tue Jul 21 07:43:17.600731 2026] [security2:error] [pid 296703:tid 296939] [client 20.151.10.161:12056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/aaa.php"] [unique_id "al9NRSn25uliftkV1n4DqwAAAGo"]
[Tue Jul 21 07:43:17.623501 2026] [security2:error] [pid 296703:tid 296884] [client 20.197.195.24:13711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/cream1.php"] [unique_id "al9NRSn25uliftkV1n4DrgAAADM"]
[Tue Jul 21 07:43:17.692467 2026] [security2:error] [pid 296703:tid 296878] [client 31.14.72.5:51350] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9NRSn25uliftkV1n4DswAAAC0"]
[Tue Jul 21 07:43:17.747641 2026] [security2:error] [pid 296703:tid 296955] [client 20.104.96.117:4190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/memberfuns.php"] [unique_id "al9NRSn25uliftkV1n4DtQAAAHo"]
[Tue Jul 21 07:43:18.001781 2026] [security2:error] [pid 296703:tid 296838] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/177.php"] [unique_id "al9NRin25uliftkV1n4DvAAAAAU"]
[Tue Jul 21 07:43:18.018638 2026] [autoindex:error] [pid 296703:tid 296953] [client 20.226.60.151:61963] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:18.029123 2026] [security2:error] [pid 296703:tid 296900] [client 20.226.60.151:61963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9NRin25uliftkV1n4DvwAAAEM"]
[Tue Jul 21 07:43:18.065257 2026] [security2:error] [pid 296703:tid 296904] [client 20.104.96.117:4237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/0.php"] [unique_id "al9NRin25uliftkV1n4DwAAAAEc"]
[Tue Jul 21 07:43:18.252902 2026] [security2:error] [pid 296703:tid 296881] [client 117.217.38.194:52096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NRin25uliftkV1n4DxgAAADA"]
[Tue Jul 21 07:43:18.253092 2026] [security2:error] [pid 296703:tid 296881] [client 117.217.38.194:52096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NRin25uliftkV1n4DxgAAADA"]
[Tue Jul 21 07:43:18.284050 2026] [security2:error] [pid 296703:tid 296863] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/config.php"] [unique_id "al9NRin25uliftkV1n4DxwAAAB4"]
[Tue Jul 21 07:43:18.365902 2026] [security2:error] [pid 296703:tid 296951] [client 31.14.72.5:51636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9NRin25uliftkV1n4DzQAAAHY"]
[Tue Jul 21 07:43:18.368724 2026] [security2:error] [pid 296703:tid 296919] [client 20.104.96.117:5090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/BDKR28.php"] [unique_id "al9NRin25uliftkV1n4DzgAAAFY"]
[Tue Jul 21 07:43:18.379512 2026] [security2:error] [pid 296703:tid 296872] [client 128.140.106.114:18234] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9NRin25uliftkV1n4DzwAAACc"], referer: https://artetoner.com.br
[Tue Jul 21 07:43:18.457280 2026] [autoindex:error] [pid 296703:tid 296939] [client 20.197.195.24:0] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:18.489023 2026] [autoindex:error] [pid 296703:tid 296889] [client 20.197.195.24:0] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:18.498327 2026] [security2:error] [pid 296703:tid 296862] [client 20.197.195.24:49904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/dr.php"] [unique_id "al9NRin25uliftkV1n4D1wAAAB0"]
[Tue Jul 21 07:43:18.594963 2026] [security2:error] [pid 296703:tid 296926] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/gettest.php"] [unique_id "al9NRin25uliftkV1n4D2gAAAF0"]
[Tue Jul 21 07:43:18.642624 2026] [security2:error] [pid 296703:tid 296909] [client 74.249.245.134:17417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/adminfuns.php"] [unique_id "al9NRin25uliftkV1n4D3gAAAEw"]
[Tue Jul 21 07:43:18.707003 2026] [security2:error] [pid 296703:tid 296890] [client 20.104.96.117:64012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/green1.php"] [unique_id "al9NRin25uliftkV1n4D3wAAADk"]
[Tue Jul 21 07:43:18.747272 2026] [security2:error] [pid 296703:tid 296934] [client 136.144.33.97:45073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NRin25uliftkV1n4D5AAAAGU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:18.876179 2026] [security2:error] [pid 296703:tid 296871] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/min.php"] [unique_id "al9NRin25uliftkV1n4D7AAAACY"]
[Tue Jul 21 07:43:19.001368 2026] [security2:error] [pid 296703:tid 296891] [client 20.104.96.117:62913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/nc4.php"] [unique_id "al9NRyn25uliftkV1n4D8AAAADo"]
[Tue Jul 21 07:43:19.033860 2026] [security2:error] [pid 296703:tid 296853] [client 31.14.72.5:51899] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9NRyn25uliftkV1n4D8gAAABQ"]
[Tue Jul 21 07:43:19.042051 2026] [autoindex:error] [pid 296703:tid 296952] [client 20.226.60.151:54307] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:19.062320 2026] [autoindex:error] [pid 296703:tid 296897] [client 20.226.60.151:54307] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:19.067353 2026] [security2:error] [pid 296703:tid 296894] [client 20.226.60.151:54307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/abcd.php"] [unique_id "al9NRyn25uliftkV1n4D9QAAAD0"]
[Tue Jul 21 07:43:19.110835 2026] [security2:error] [pid 296703:tid 296951] [client 20.226.60.151:56213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/for.php"] [unique_id "al9NRyn25uliftkV1n4D-AAAAHY"]
[Tue Jul 21 07:43:19.126516 2026] [security2:error] [pid 296703:tid 296919] [client 62.102.148.187:37294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9NRyn25uliftkV1n4D-QAAAFY"]
[Tue Jul 21 07:43:19.126630 2026] [security2:error] [pid 296703:tid 296919] [client 62.102.148.187:37294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9NRyn25uliftkV1n4D-QAAAFY"]
[Tue Jul 21 07:43:19.177404 2026] [security2:error] [pid 296703:tid 296837] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/dvjul.php"] [unique_id "al9NRyn25uliftkV1n4D-wAAAAQ"]
[Tue Jul 21 07:43:19.288549 2026] [security2:error] [pid 296703:tid 296878] [client 20.104.96.117:62933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/a1.php"] [unique_id "al9NRyn25uliftkV1n4EAAAAAC0"]
[Tue Jul 21 07:43:19.315956 2026] [security2:error] [pid 296703:tid 296926] [client 20.197.195.24:13734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/x.php"] [unique_id "al9NRyn25uliftkV1n4EAQAAAF0"]
[Tue Jul 21 07:43:19.459131 2026] [security2:error] [pid 296703:tid 296876] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/biufile.php"] [unique_id "al9NRyn25uliftkV1n4EBwAAACs"]
[Tue Jul 21 07:43:19.645896 2026] [security2:error] [pid 296703:tid 296915] [client 20.104.96.117:5085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/eee.php"] [unique_id "al9NRyn25uliftkV1n4ECQAAAFI"]
[Tue Jul 21 07:43:19.702214 2026] [core:error] [pid 296703:tid 296771] [remote 2600:1f16:743:ac02:233c:ec46:b0a2:6f83:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://webdisk.dralulmabhering.com.br/
[Tue Jul 21 07:43:19.702232 2026] [core:error] [pid 296703:tid 296771] [remote 2600:1f16:743:ac02:233c:ec46:b0a2:6f83:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://webdisk.dralulmabhering.com.br/
[Tue Jul 21 07:43:19.708694 2026] [security2:error] [pid 296703:tid 296902] [client 31.14.72.5:52246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9NRyn25uliftkV1n4EDAAAAEU"]
[Tue Jul 21 07:43:19.749917 2026] [security2:error] [pid 296703:tid 296848] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/av.php"] [unique_id "al9NRyn25uliftkV1n4EEAAAAA8"]
[Tue Jul 21 07:43:19.853836 2026] [security2:error] [pid 296703:tid 296924] [client 103.106.20.201:54942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NRyn25uliftkV1n4EEQAAAFs"]
[Tue Jul 21 07:43:19.854558 2026] [security2:error] [pid 296703:tid 296924] [client 103.106.20.201:54942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NRyn25uliftkV1n4EEQAAAFs"]
[Tue Jul 21 07:43:19.984393 2026] [security2:error] [pid 296703:tid 296874] [client 20.104.96.117:62947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wp-aothait.php"] [unique_id "al9NRyn25uliftkV1n4EFgAAACk"]
[Tue Jul 21 07:43:20.049356 2026] [security2:error] [pid 296703:tid 296861] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/coffexium.php"] [unique_id "al9NSCn25uliftkV1n4EGAAAABw"]
[Tue Jul 21 07:43:20.135193 2026] [security2:error] [pid 296703:tid 296884] [client 47.128.22.36:14740] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fisioevida.com"] [uri "/robots.txt"] [unique_id "al9NSCn25uliftkV1n4EGgAAADM"]
[Tue Jul 21 07:43:20.149620 2026] [security2:error] [pid 296703:tid 296944] [client 74.249.245.134:5519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/php8.php"] [unique_id "al9NSCn25uliftkV1n4EHAAAAG8"]
[Tue Jul 21 07:43:20.154041 2026] [security2:error] [pid 296703:tid 296837] [client 20.197.195.24:49856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/155.php"] [unique_id "al9NSCn25uliftkV1n4EHQAAAAQ"]
[Tue Jul 21 07:43:20.274119 2026] [security2:error] [pid 296703:tid 296907] [client 20.104.96.117:62928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/config.json.php"] [unique_id "al9NSCn25uliftkV1n4EIAAAAEo"]
[Tue Jul 21 07:43:20.311824 2026] [security2:error] [pid 296703:tid 296862] [client 20.226.60.151:54289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/file15.php"] [unique_id "al9NSCn25uliftkV1n4EIwAAAB0"]
[Tue Jul 21 07:43:20.331942 2026] [security2:error] [pid 296703:tid 296834] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/core.php"] [unique_id "al9NSCn25uliftkV1n4EJAAAAAE"]
[Tue Jul 21 07:43:20.334706 2026] [security2:error] [pid 296703:tid 296844] [client 122.162.144.145:11400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NSCn25uliftkV1n4EJQAAAAs"]
[Tue Jul 21 07:43:20.334797 2026] [security2:error] [pid 296703:tid 296844] [client 122.162.144.145:11400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NSCn25uliftkV1n4EJQAAAAs"]
[Tue Jul 21 07:43:20.387722 2026] [security2:error] [pid 296703:tid 296958] [client 31.14.72.5:52579] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9NSCn25uliftkV1n4EJwAAAH0"]
[Tue Jul 21 07:43:20.478662 2026] [security2:error] [pid 296703:tid 296953] [client 20.226.60.151:54278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/jp.php"] [unique_id "al9NSCn25uliftkV1n4ELAAAAHg"]
[Tue Jul 21 07:43:20.501318 2026] [security2:error] [pid 296703:tid 296869] [client 59.96.220.140:60208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NSCn25uliftkV1n4ELQAAACQ"]
[Tue Jul 21 07:43:20.501416 2026] [security2:error] [pid 296703:tid 296869] [client 59.96.220.140:60208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NSCn25uliftkV1n4ELQAAACQ"]
[Tue Jul 21 07:43:20.602393 2026] [security2:error] [pid 296703:tid 296879] [client 20.104.96.117:64056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9NSCn25uliftkV1n4ELgAAAC4"]
[Tue Jul 21 07:43:20.616994 2026] [security2:error] [pid 296703:tid 296950] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/als.php"] [unique_id "al9NSCn25uliftkV1n4ELwAAAHU"]
[Tue Jul 21 07:43:20.640661 2026] [security2:error] [pid 296703:tid 296920] [client 20.226.60.151:60136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/f35.php"] [unique_id "al9NSCn25uliftkV1n4EMAAAAFc"]
[Tue Jul 21 07:43:20.899362 2026] [security2:error] [pid 296703:tid 296881] [client 20.104.96.117:4212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/k2.php"] [unique_id "al9NSCn25uliftkV1n4ENgAAADA"]
[Tue Jul 21 07:43:20.919997 2026] [security2:error] [pid 296703:tid 296894] [client 152.59.154.239:56420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NSCn25uliftkV1n4ENwAAAD0"]
[Tue Jul 21 07:43:20.922032 2026] [security2:error] [pid 296703:tid 296894] [client 152.59.154.239:56420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NSCn25uliftkV1n4ENwAAAD0"]
[Tue Jul 21 07:43:21.073269 2026] [security2:error] [pid 296703:tid 296908] [client 31.14.72.5:53081] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9NSSn25uliftkV1n4EPQAAAEs"]
[Tue Jul 21 07:43:21.191817 2026] [security2:error] [pid 296703:tid 296909] [client 139.167.225.182:52541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NSSn25uliftkV1n4EQAAAAEw"]
[Tue Jul 21 07:43:21.191972 2026] [security2:error] [pid 296703:tid 296909] [client 139.167.225.182:52541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NSSn25uliftkV1n4EQAAAAEw"]
[Tue Jul 21 07:43:21.232322 2026] [security2:error] [pid 296703:tid 296931] [client 20.104.96.117:64059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/uiuvs58l.php"] [unique_id "al9NSSn25uliftkV1n4EQQAAAGI"]
[Tue Jul 21 07:43:21.250247 2026] [security2:error] [pid 296703:tid 296861] [client 20.226.60.151:54314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-load.php"] [unique_id "al9NSSn25uliftkV1n4EQgAAABw"]
[Tue Jul 21 07:43:21.271827 2026] [security2:error] [pid 296703:tid 296884] [client 20.226.60.151:56209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/ssla.php"] [unique_id "al9NSSn25uliftkV1n4ERAAAADM"]
[Tue Jul 21 07:43:21.342960 2026] [security2:error] [pid 296703:tid 296837] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/simple.php"] [unique_id "al9NSSn25uliftkV1n4ERQAAAAQ"]
[Tue Jul 21 07:43:21.387309 2026] [security2:error] [pid 296703:tid 296957] [client 74.249.245.134:5530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/info.php"] [unique_id "al9NSSn25uliftkV1n4ESQAAAHw"]
[Tue Jul 21 07:43:21.420784 2026] [security2:error] [pid 296703:tid 296935] [client 20.220.225.223:5261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/wp-css.php"] [unique_id "al9NSSn25uliftkV1n4ESgAAAGY"]
[Tue Jul 21 07:43:21.542051 2026] [security2:error] [pid 296703:tid 296844] [client 20.226.60.151:61965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/xyn.php"] [unique_id "al9NSSn25uliftkV1n4ETgAAAAs"]
[Tue Jul 21 07:43:21.551952 2026] [security2:error] [pid 296703:tid 296955] [client 20.104.96.117:4169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/40p9ixjd.php"] [unique_id "al9NSSn25uliftkV1n4EUAAAAHo"]
[Tue Jul 21 07:43:21.627172 2026] [security2:error] [pid 296703:tid 296937] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/init.php"] [unique_id "al9NSSn25uliftkV1n4EUgAAAGg"]
[Tue Jul 21 07:43:21.720841 2026] [autoindex:error] [pid 296703:tid 296838] [client 20.226.60.151:54332] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:21.744477 2026] [security2:error] [pid 296703:tid 296924] [client 122.179.91.63:19931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NSSn25uliftkV1n4EVgAAAFs"]
[Tue Jul 21 07:43:21.747347 2026] [security2:error] [pid 296703:tid 296924] [client 122.179.91.63:19931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NSSn25uliftkV1n4EVgAAAFs"]
[Tue Jul 21 07:43:21.748337 2026] [security2:error] [pid 296703:tid 296879] [client 31.14.72.5:53469] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9NSSn25uliftkV1n4EVwAAAC4"]
[Tue Jul 21 07:43:21.815262 2026] [security2:error] [pid 296703:tid 296960] [client 20.220.225.223:34194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/2x.php"] [unique_id "al9NSSn25uliftkV1n4EWwAAAH8"]
[Tue Jul 21 07:43:21.902060 2026] [security2:error] [pid 296703:tid 296891] [client 20.104.96.117:64017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/uiuvs58l.update.php"] [unique_id "al9NSSn25uliftkV1n4EYgAAADo"]
[Tue Jul 21 07:43:21.929969 2026] [security2:error] [pid 296703:tid 296928] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/fpwch.php"] [unique_id "al9NSSn25uliftkV1n4EYwAAAF8"]
[Tue Jul 21 07:43:21.946527 2026] [security2:error] [pid 296703:tid 296932] [client 20.197.195.24:13785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/ops.php"] [unique_id "al9NSSn25uliftkV1n4EZAAAAGM"]
[Tue Jul 21 07:43:22.167971 2026] [autoindex:error] [pid 296703:tid 296944] [client 20.226.60.151:54332] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:22.188247 2026] [security2:error] [pid 296703:tid 296957] [client 20.226.60.151:54332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ccc.php"] [unique_id "al9NSin25uliftkV1n4EbQAAAHw"]
[Tue Jul 21 07:43:22.188747 2026] [security2:error] [pid 296703:tid 296865] [client 20.220.225.223:19714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/hp2.php"] [unique_id "al9NSin25uliftkV1n4EbgAAACA"]
[Tue Jul 21 07:43:22.216560 2026] [security2:error] [pid 296703:tid 296951] [client 20.104.96.117:5057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/for.php"] [unique_id "al9NSin25uliftkV1n4EbwAAAHY"]
[Tue Jul 21 07:43:22.288676 2026] [security2:error] [pid 296703:tid 296853] [client 173.24.185.52:57412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NSin25uliftkV1n4EcQAAABQ"]
[Tue Jul 21 07:43:22.288763 2026] [security2:error] [pid 296703:tid 296853] [client 173.24.185.52:57412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NSin25uliftkV1n4EcQAAABQ"]
[Tue Jul 21 07:43:22.346637 2026] [security2:error] [pid 296703:tid 296716] [remote 5.39.1.236:39046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "brasilmotoeletrica.com"] [uri "/robots.txt"] [unique_id "al9NSin25uliftkV1n4EcwAAOAw"]
[Tue Jul 21 07:43:22.346782 2026] [security2:error] [pid 296703:tid 296889] [client 5.39.1.236:39046] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "brasilmotoeletrica.com"] [uri "/robots.txt"] [unique_id "al9NSin25uliftkV1n4EcwAAOAw"]
[Tue Jul 21 07:43:22.363030 2026] [security2:error] [pid 296703:tid 296743] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NSin25uliftkV1n4EdAAALSc"]
[Tue Jul 21 07:43:22.363142 2026] [security2:error] [pid 296703:tid 296878] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NSin25uliftkV1n4EdAAALSc"]
[Tue Jul 21 07:43:22.404045 2026] [security2:error] [pid 296703:tid 296834] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/domvf.php"] [unique_id "al9NSin25uliftkV1n4EeAAAAAE"]
[Tue Jul 21 07:43:22.436046 2026] [security2:error] [pid 296703:tid 296890] [client 31.14.72.5:53897] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9NSin25uliftkV1n4EegAAADk"]
[Tue Jul 21 07:43:22.534940 2026] [security2:error] [pid 296703:tid 296923] [client 74.249.245.134:54351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/edit.php"] [unique_id "al9NSin25uliftkV1n4EfgAAAFo"]
[Tue Jul 21 07:43:22.540949 2026] [security2:error] [pid 296703:tid 296937] [client 20.104.96.117:5063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/raw.php"] [unique_id "al9NSin25uliftkV1n4EfwAAAGg"]
[Tue Jul 21 07:43:22.604969 2026] [security2:error] [pid 296703:tid 296950] [client 20.226.60.151:56224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/zc-131.php"] [unique_id "al9NSin25uliftkV1n4EgwAAAHU"]
[Tue Jul 21 07:43:22.659625 2026] [security2:error] [pid 296703:tid 296940] [client 103.166.103.129:10761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NSin25uliftkV1n4EhAAAAGs"]
[Tue Jul 21 07:43:22.659714 2026] [security2:error] [pid 296703:tid 296940] [client 103.166.103.129:10761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NSin25uliftkV1n4EhAAAAGs"]
[Tue Jul 21 07:43:22.711792 2026] [security2:error] [pid 296703:tid 296848] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wp.php"] [unique_id "al9NSin25uliftkV1n4EhQAAAA8"]
[Tue Jul 21 07:43:22.866142 2026] [security2:error] [pid 296703:tid 296917] [client 20.220.225.223:11188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/wp-explorer.php"] [unique_id "al9NSin25uliftkV1n4EigAAAFQ"]
[Tue Jul 21 07:43:22.873879 2026] [security2:error] [pid 296703:tid 296775] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NSin25uliftkV1n4EjAAAc0c"]
[Tue Jul 21 07:43:22.873992 2026] [security2:error] [pid 296703:tid 296948] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NSin25uliftkV1n4EjAAAc0c"]
[Tue Jul 21 07:43:22.996599 2026] [security2:error] [pid 296703:tid 296863] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/class.php"] [unique_id "al9NSin25uliftkV1n4EjQAAAB4"]
[Tue Jul 21 07:43:23.039678 2026] [security2:error] [pid 296703:tid 296892] [client 20.220.225.223:19664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/hp3.php"] [unique_id "al9NSyn25uliftkV1n4EjgAAADs"]
[Tue Jul 21 07:43:23.107128 2026] [security2:error] [pid 296703:tid 296872] [client 31.14.72.5:54257] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9NSyn25uliftkV1n4EkAAAACc"]
[Tue Jul 21 07:43:23.191599 2026] [security2:error] [pid 296703:tid 296907] [client 47.128.49.54:50460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.andrelageorthobolics.com.br"] [uri "/robots.txt"] [unique_id "al9NSyn25uliftkV1n4ElgAAAEo"]
[Tue Jul 21 07:43:23.223893 2026] [security2:error] [pid 296703:tid 296865] [client 20.226.60.151:60128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/w.php"] [unique_id "al9NSyn25uliftkV1n4ElwAAACA"]
[Tue Jul 21 07:43:23.375245 2026] [security2:error] [pid 296703:tid 296878] [client 20.226.60.151:59441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/rithin.php"] [unique_id "al9NSyn25uliftkV1n4EnAAAAC0"]
[Tue Jul 21 07:43:23.499248 2026] [security2:error] [pid 296703:tid 296927] [client 37.140.223.191:54249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NSyn25uliftkV1n4EmAAAAF4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:23.530127 2026] [security2:error] [pid 296703:tid 296876] [client 37.140.223.68:59105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NSyn25uliftkV1n4EoAAAACs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:23.561132 2026] [security2:error] [pid 296703:tid 296880] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/echkm.php"] [unique_id "al9NSyn25uliftkV1n4EogAAAC8"]
[Tue Jul 21 07:43:23.578483 2026] [security2:error] [pid 296703:tid 296859] [client 20.197.195.24:49864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/file31.php"] [unique_id "al9NSyn25uliftkV1n4EowAAABo"]
[Tue Jul 21 07:43:23.654037 2026] [security2:error] [pid 296703:tid 296879] [client 74.249.245.134:54384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/166.php"] [unique_id "al9NSyn25uliftkV1n4EqAAAAC4"]
[Tue Jul 21 07:43:23.654650 2026] [security2:error] [pid 296703:tid 296938] [client 20.220.225.223:19653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/aa1.php"] [unique_id "al9NSyn25uliftkV1n4EqQAAAGk"]
[Tue Jul 21 07:43:23.711361 2026] [security2:error] [pid 296703:tid 296940] [client 20.226.60.151:22351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/a1.php"] [unique_id "al9NSyn25uliftkV1n4EqgAAAGs"]
[Tue Jul 21 07:43:23.798794 2026] [security2:error] [pid 296703:tid 296945] [client 20.226.60.151:61990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9NSyn25uliftkV1n4EqwAAAHA"]
[Tue Jul 21 07:43:23.997312 2026] [security2:error] [pid 296703:tid 296909] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/lib.php"] [unique_id "al9NSyn25uliftkV1n4EswAAAEw"]
[Tue Jul 21 07:43:24.037537 2026] [security2:error] [pid 296703:tid 296929] [client 103.174.34.15:58554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTCn25uliftkV1n4EtQAAAGA"]
[Tue Jul 21 07:43:24.037995 2026] [security2:error] [pid 296703:tid 296929] [client 103.174.34.15:58554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTCn25uliftkV1n4EtQAAAGA"]
[Tue Jul 21 07:43:24.059923 2026] [security2:error] [pid 296703:tid 296784] [remote 142.44.233.164:46878] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "brasilmotoeletrica.com"] [uri "/"] [unique_id "al9NTCn25uliftkV1n4EtgAADlA"]
[Tue Jul 21 07:43:24.060121 2026] [security2:error] [pid 296703:tid 296847] [client 142.44.233.164:46878] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "brasilmotoeletrica.com"] [uri "/"] [unique_id "al9NTCn25uliftkV1n4EtgAADlA"]
[Tue Jul 21 07:43:24.272034 2026] [security2:error] [pid 296703:tid 296793] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NTCn25uliftkV1n4EvAAAOFk"]
[Tue Jul 21 07:43:24.272187 2026] [security2:error] [pid 296703:tid 296889] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NTCn25uliftkV1n4EvAAAOFk"]
[Tue Jul 21 07:43:24.274277 2026] [security2:error] [pid 296703:tid 296878] [client 20.220.225.223:19267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/acew67.php"] [unique_id "al9NTCn25uliftkV1n4EvQAAAC0"]
[Tue Jul 21 07:43:24.285123 2026] [security2:error] [pid 296703:tid 296943] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/login.php"] [unique_id "al9NTCn25uliftkV1n4EvgAAAG4"]
[Tue Jul 21 07:43:24.604757 2026] [security2:error] [pid 296703:tid 296894] [client 106.215.181.8:19875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTCn25uliftkV1n4ExQAAAD0"]
[Tue Jul 21 07:43:24.604908 2026] [security2:error] [pid 296703:tid 296894] [client 106.215.181.8:19875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTCn25uliftkV1n4ExQAAAD0"]
[Tue Jul 21 07:43:24.622399 2026] [security2:error] [pid 296703:tid 296934] [client 20.226.60.151:54336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/FWAZ.php"] [unique_id "al9NTCn25uliftkV1n4ExwAAAGU"]
[Tue Jul 21 07:43:24.625213 2026] [security2:error] [pid 296703:tid 296922] [client 74.249.245.134:5556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/8.php"] [unique_id "al9NTCn25uliftkV1n4EyAAAAFk"]
[Tue Jul 21 07:43:24.784809 2026] [security2:error] [pid 296703:tid 296940] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/a2.php"] [unique_id "al9NTCn25uliftkV1n4EzwAAAGs"]
[Tue Jul 21 07:43:24.826986 2026] [security2:error] [pid 296703:tid 296900] [client 184.75.223.211:58596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9NTCn25uliftkV1n4E0AAAAEM"]
[Tue Jul 21 07:43:24.827106 2026] [security2:error] [pid 296703:tid 296900] [client 184.75.223.211:58596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9NTCn25uliftkV1n4E0AAAAEM"]
[Tue Jul 21 07:43:25.015563 2026] [security2:error] [pid 296703:tid 296834] [client 182.8.255.181:10169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NTSn25uliftkV1n4E1QAAAAE"]
[Tue Jul 21 07:43:25.015694 2026] [security2:error] [pid 296703:tid 296834] [client 182.8.255.181:10169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NTSn25uliftkV1n4E1QAAAAE"]
[Tue Jul 21 07:43:25.062147 2026] [security2:error] [pid 296703:tid 296872] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/d61.php"] [unique_id "al9NTSn25uliftkV1n4E1wAAACc"]
[Tue Jul 21 07:43:25.110129 2026] [security2:error] [pid 296703:tid 296810] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NTSn25uliftkV1n4E2wAAFWo"]
[Tue Jul 21 07:43:25.110278 2026] [security2:error] [pid 296703:tid 296854] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NTSn25uliftkV1n4E2wAAFWo"]
[Tue Jul 21 07:43:25.128571 2026] [security2:error] [pid 296703:tid 296929] [client 5.161.69.178:39250] ModSecurity: Access denied with code 406 (phase 1). Match of "rx (^/administrator/)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "63"] [id "331216"] [rev "2"] [msg "Atomicorp.com WAF Rules: Wordpress DOS Attack Dropped"] [severity "CRITICAL"] [hostname "cotidianorural.com.br"] [uri "/wp-load.php"] [unique_id "al9NTSn25uliftkV1n4E3AAAAGA"]
[Tue Jul 21 07:43:25.210593 2026] [security2:error] [pid 296703:tid 296931] [client 20.226.60.151:54290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/miru1.php"] [unique_id "al9NTSn25uliftkV1n4E4wAAAGI"]
[Tue Jul 21 07:43:25.292379 2026] [security2:error] [pid 296703:tid 296712] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTSn25uliftkV1n4E5AAAVAg"]
[Tue Jul 21 07:43:25.292619 2026] [security2:error] [pid 296703:tid 296917] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTSn25uliftkV1n4E5AAAVAg"]
[Tue Jul 21 07:43:25.339692 2026] [security2:error] [pid 296703:tid 296889] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/info.php"] [unique_id "al9NTSn25uliftkV1n4E5gAAADg"]
[Tue Jul 21 07:43:25.352277 2026] [security2:error] [pid 296703:tid 296935] [client 74.249.245.134:54352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/ws38.php"] [unique_id "al9NTSn25uliftkV1n4E6AAAAGY"]
[Tue Jul 21 07:43:25.452306 2026] [security2:error] [pid 296703:tid 296861] [client 37.140.223.152:31403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NTSn25uliftkV1n4E7AAAABw"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:25.530366 2026] [security2:error] [pid 296703:tid 296807] [remote 182.77.62.24:43960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zooparquevet.com.br"] [uri "/wp-login.php"] [unique_id "al9NTSn25uliftkV1n4E8gAALmc"]
[Tue Jul 21 07:43:25.563247 2026] [security2:error] [pid 296703:tid 296842] [client 20.197.195.24:13741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/file6.php"] [unique_id "al9NTSn25uliftkV1n4E9QAAAAk"]
[Tue Jul 21 07:43:25.616329 2026] [security2:error] [pid 296703:tid 296900] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/11.php"] [unique_id "al9NTSn25uliftkV1n4E9gAAAEM"]
[Tue Jul 21 07:43:25.891288 2026] [security2:error] [pid 296703:tid 296841] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/v2.php"] [unique_id "al9NTSn25uliftkV1n4E_gAAAAg"]
[Tue Jul 21 07:43:25.891789 2026] [security2:error] [pid 296703:tid 296911] [client 103.86.117.203:56180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NTSn25uliftkV1n4E_wAAAE4"]
[Tue Jul 21 07:43:25.891945 2026] [security2:error] [pid 296703:tid 296911] [client 103.86.117.203:56180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NTSn25uliftkV1n4E_wAAAE4"]
[Tue Jul 21 07:43:25.991557 2026] [security2:error] [pid 296703:tid 296928] [client 20.226.60.151:54280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/aa.php"] [unique_id "al9NTSn25uliftkV1n4FAgAAAF8"]
[Tue Jul 21 07:43:26.094794 2026] [security2:error] [pid 296703:tid 296863] [client 74.249.245.134:17427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/a7.php"] [unique_id "al9NTin25uliftkV1n4FCgAAAB4"]
[Tue Jul 21 07:43:26.097831 2026] [security2:error] [pid 296703:tid 296891] [client 20.63.100.92:2557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9NTin25uliftkV1n4FCwAAADo"]
[Tue Jul 21 07:43:26.167492 2026] [security2:error] [pid 296703:tid 296935] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/panel.php"] [unique_id "al9NTin25uliftkV1n4FDgAAAGY"]
[Tue Jul 21 07:43:26.440462 2026] [security2:error] [pid 296703:tid 296888] [client 117.251.86.144:42270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NTin25uliftkV1n4FOgAAADc"]
[Tue Jul 21 07:43:26.440570 2026] [security2:error] [pid 296703:tid 296888] [client 117.251.86.144:42270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NTin25uliftkV1n4FOgAAADc"]
[Tue Jul 21 07:43:26.484382 2026] [security2:error] [pid 296703:tid 296926] [client 122.164.127.47:57490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NTin25uliftkV1n4FOwAAAF0"]
[Tue Jul 21 07:43:26.484499 2026] [security2:error] [pid 296703:tid 296926] [client 122.164.127.47:57490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NTin25uliftkV1n4FOwAAAF0"]
[Tue Jul 21 07:43:26.510184 2026] [security2:error] [pid 296703:tid 296872] [client 122.186.204.214:59074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NTin25uliftkV1n4FPAAAACc"]
[Tue Jul 21 07:43:26.510290 2026] [security2:error] [pid 296703:tid 296872] [client 122.186.204.214:59074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NTin25uliftkV1n4FPAAAACc"]
[Tue Jul 21 07:43:26.599261 2026] [security2:error] [pid 296703:tid 296940] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/dex.php"] [unique_id "al9NTin25uliftkV1n4FPwAAAGs"]
[Tue Jul 21 07:43:26.649729 2026] [security2:error] [pid 296703:tid 296920] [client 117.247.80.59:31412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTin25uliftkV1n4FQwAAAFc"]
[Tue Jul 21 07:43:26.649919 2026] [security2:error] [pid 296703:tid 296920] [client 117.247.80.59:31412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTin25uliftkV1n4FQwAAAFc"]
[Tue Jul 21 07:43:26.668725 2026] [security2:error] [pid 296703:tid 296849] [client 20.220.225.223:5305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/akismet.php"] [unique_id "al9NTin25uliftkV1n4FRAAAABA"]
[Tue Jul 21 07:43:26.686400 2026] [security2:error] [pid 296703:tid 296743] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NTin25uliftkV1n4FRgAAUCc"]
[Tue Jul 21 07:43:26.686619 2026] [security2:error] [pid 296703:tid 296913] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NTin25uliftkV1n4FRgAAUCc"]
[Tue Jul 21 07:43:26.876926 2026] [security2:error] [pid 296703:tid 296908] [client 178.153.91.96:61446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NTSn25uliftkV1n4E-wAAAEs"]
[Tue Jul 21 07:43:26.877059 2026] [security2:error] [pid 296703:tid 296908] [client 178.153.91.96:61446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NTSn25uliftkV1n4E-wAAAEs"]
[Tue Jul 21 07:43:26.881534 2026] [security2:error] [pid 296703:tid 296939] [client 74.249.245.134:5521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/classsmtps.php"] [unique_id "al9NTin25uliftkV1n4FUwAAAGo"]
[Tue Jul 21 07:43:26.890645 2026] [security2:error] [pid 296703:tid 296944] [client 4.204.201.85:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "denarios.com.br"] [uri "/1.php"] [unique_id "al9NTin25uliftkV1n4FVAAAAG8"]
[Tue Jul 21 07:43:26.890743 2026] [security2:error] [pid 296703:tid 296944] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/1.php"] [unique_id "al9NTin25uliftkV1n4FVAAAAG8"]
[Tue Jul 21 07:43:26.960349 2026] [security2:error] [pid 296703:tid 296863] [client 20.63.100.92:6187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9NTin25uliftkV1n4FWAAAAB4"]
[Tue Jul 21 07:43:26.967562 2026] [autoindex:error] [pid 296703:tid 296917] [client 20.197.195.24:0] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:26.978188 2026] [security2:error] [pid 296703:tid 296921] [client 20.197.195.24:13805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/adminfuns.php"] [unique_id "al9NTin25uliftkV1n4FWQAAAFg"]
[Tue Jul 21 07:43:27.197690 2026] [security2:error] [pid 296703:tid 296888] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/ms.php"] [unique_id "al9NTyn25uliftkV1n4FZAAAADc"]
[Tue Jul 21 07:43:27.364278 2026] [security2:error] [pid 296703:tid 296955] [client 136.144.33.215:48943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NTyn25uliftkV1n4FagAAAHo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:27.376590 2026] [security2:error] [pid 296703:tid 296785] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTyn25uliftkV1n4FawAAUFE"]
[Tue Jul 21 07:43:27.376744 2026] [security2:error] [pid 296703:tid 296913] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTyn25uliftkV1n4FawAAUFE"]
[Tue Jul 21 07:43:27.425810 2026] [security2:error] [pid 296703:tid 296881] [client 74.249.245.134:54368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/rip.php"] [unique_id "al9NTyn25uliftkV1n4FbAAAADA"]
[Tue Jul 21 07:43:27.495412 2026] [security2:error] [pid 296703:tid 296947] [client 202.143.127.214:52720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTyn25uliftkV1n4FbwAAAHI"]
[Tue Jul 21 07:43:27.495519 2026] [security2:error] [pid 296703:tid 296947] [client 202.143.127.214:52720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTyn25uliftkV1n4FbwAAAHI"]
[Tue Jul 21 07:43:27.538447 2026] [autoindex:error] [pid 296703:tid 296834] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:27.590506 2026] [security2:error] [pid 296703:tid 296758] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NTyn25uliftkV1n4FcAAAJzY"]
[Tue Jul 21 07:43:27.590642 2026] [security2:error] [pid 296703:tid 296872] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NTyn25uliftkV1n4FcAAAJzY"]
[Tue Jul 21 07:43:27.690083 2026] [security2:error] [pid 296703:tid 296938] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/memberfuns.php"] [unique_id "al9NTyn25uliftkV1n4FdQAAAGk"]
[Tue Jul 21 07:43:27.824110 2026] [security2:error] [pid 296703:tid 296869] [client 20.226.60.151:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/122.php"] [unique_id "al9NTyn25uliftkV1n4FfAAAACQ"]
[Tue Jul 21 07:43:27.905157 2026] [security2:error] [pid 296703:tid 296871] [client 20.197.195.24:49909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/goods.php"] [unique_id "al9NTyn25uliftkV1n4FfQAAACY"]
[Tue Jul 21 07:43:27.971936 2026] [security2:error] [pid 296703:tid 296943] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/0.php"] [unique_id "al9NTyn25uliftkV1n4FfgAAAG4"]
[Tue Jul 21 07:43:28.187862 2026] [security2:error] [pid 296703:tid 296839] [client 154.192.233.199:58881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NUCn25uliftkV1n4FhQAAAAY"]
[Tue Jul 21 07:43:28.188085 2026] [security2:error] [pid 296703:tid 296839] [client 154.192.233.199:58881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NUCn25uliftkV1n4FhQAAAAY"]
[Tue Jul 21 07:43:28.217706 2026] [security2:error] [pid 296703:tid 296784] [remote 199.189.225.40:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexandrevitor1781543539748.0711679.meusitehostgator.com.br"] [uri "/wp-login.php"] [unique_id "al9NUCn25uliftkV1n4FhwAABVA"]
[Tue Jul 21 07:43:28.283618 2026] [security2:error] [pid 296703:tid 296950] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/BDKR28.php"] [unique_id "al9NUCn25uliftkV1n4FiQAAAHU"]
[Tue Jul 21 07:43:28.347764 2026] [security2:error] [pid 296703:tid 296859] [client 20.63.100.92:2294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/dp.php"] [unique_id "al9NUCn25uliftkV1n4FjAAAABo"]
[Tue Jul 21 07:43:28.407534 2026] [security2:error] [pid 296703:tid 296873] [client 74.249.245.134:5551] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/1.php"] [unique_id "al9NUCn25uliftkV1n4FjwAAACg"]
[Tue Jul 21 07:43:28.407653 2026] [security2:error] [pid 296703:tid 296873] [client 74.249.245.134:5551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/1.php"] [unique_id "al9NUCn25uliftkV1n4FjwAAACg"]
[Tue Jul 21 07:43:28.454731 2026] [security2:error] [pid 296703:tid 296804] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9NUCn25uliftkV1n4FkQAAemQ"]
[Tue Jul 21 07:43:28.677346 2026] [security2:error] [pid 296703:tid 296892] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/green1.php"] [unique_id "al9NUCn25uliftkV1n4FlAAAADs"]
[Tue Jul 21 07:43:28.708431 2026] [security2:error] [pid 296703:tid 296919] [client 117.217.38.194:52572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NUCn25uliftkV1n4FmAAAAFY"]
[Tue Jul 21 07:43:28.708889 2026] [security2:error] [pid 296703:tid 296919] [client 117.217.38.194:52572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NUCn25uliftkV1n4FmAAAAFY"]
[Tue Jul 21 07:43:28.803079 2026] [security2:error] [pid 296703:tid 296815] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9NUCn25uliftkV1n4FmwAACG8"]
[Tue Jul 21 07:43:28.856318 2026] [security2:error] [pid 296703:tid 296928] [client 20.197.195.24:13739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/100.php"] [unique_id "al9NUCn25uliftkV1n4FngAAAF8"]
[Tue Jul 21 07:43:28.977890 2026] [security2:error] [pid 296703:tid 296931] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/nc4.php"] [unique_id "al9NUCn25uliftkV1n4FoAAAAGI"]
[Tue Jul 21 07:43:29.026493 2026] [security2:error] [pid 296703:tid 296884] [client 20.226.60.151:61966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/get.php"] [unique_id "al9NUSn25uliftkV1n4FogAAADM"]
[Tue Jul 21 07:43:29.120429 2026] [security2:error] [pid 296703:tid 296897] [client 194.99.104.35:58014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9NUSn25uliftkV1n4FpwAAAEA"]
[Tue Jul 21 07:43:29.120513 2026] [security2:error] [pid 296703:tid 296897] [client 194.99.104.35:58014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9NUSn25uliftkV1n4FpwAAAEA"]
[Tue Jul 21 07:43:29.141798 2026] [security2:error] [pid 296703:tid 296817] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9NUSn25uliftkV1n4FqAAAbnE"]
[Tue Jul 21 07:43:29.288690 2026] [security2:error] [pid 296703:tid 296923] [client 20.220.225.223:5309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/ace2.php"] [unique_id "al9NUSn25uliftkV1n4FrwAAAFo"]
[Tue Jul 21 07:43:29.303296 2026] [security2:error] [pid 296703:tid 296868] [client 20.197.195.24:13770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/about.php"] [unique_id "al9NUSn25uliftkV1n4FsAAAACM"]
[Tue Jul 21 07:43:29.310329 2026] [security2:error] [pid 296703:tid 296797] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9NUSn25uliftkV1n4FsQAADl0"]
[Tue Jul 21 07:43:29.338556 2026] [security2:error] [pid 296703:tid 296885] [client 20.226.60.151:61982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/as.php"] [unique_id "al9NUSn25uliftkV1n4FsgAAADQ"]
[Tue Jul 21 07:43:29.456421 2026] [security2:error] [pid 296703:tid 296922] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/a1.php"] [unique_id "al9NUSn25uliftkV1n4FtgAAAFk"]
[Tue Jul 21 07:43:29.527203 2026] [security2:error] [pid 296703:tid 296934] [client 74.249.245.134:54367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/chosen.php"] [unique_id "al9NUSn25uliftkV1n4FuQAAAGU"]
[Tue Jul 21 07:43:29.602025 2026] [security2:error] [pid 296703:tid 296781] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9NUSn25uliftkV1n4FuwAAek0"]
[Tue Jul 21 07:43:29.772301 2026] [security2:error] [pid 296703:tid 296707] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9NUSn25uliftkV1n4FxQAADwM"]
[Tue Jul 21 07:43:29.785772 2026] [security2:error] [pid 296703:tid 296727] [remote 124.55.178.99:51676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9NUSn25uliftkV1n4FxgAAaBc"]
[Tue Jul 21 07:43:29.922382 2026] [security2:error] [pid 296703:tid 296854] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/eee.php"] [unique_id "al9NUSn25uliftkV1n4FyQAAABU"]
[Tue Jul 21 07:43:29.964167 2026] [security2:error] [pid 296703:tid 296884] [client 20.226.60.151:54398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ccou.php"] [unique_id "al9NUSn25uliftkV1n4FzgAAADM"]
[Tue Jul 21 07:43:29.985512 2026] [core:error] [pid 296703:tid 296825] [remote 52.167.144.232:64881] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:43:29.985541 2026] [core:error] [pid 296703:tid 296825] [remote 52.167.144.232:64881] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:43:30.032222 2026] [security2:error] [pid 296703:tid 296821] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9NUin25uliftkV1n4F0AAAJHU"]
[Tue Jul 21 07:43:30.140288 2026] [security2:error] [pid 296703:tid 296844] [client 20.197.195.24:49858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/about.php"] [unique_id "al9NUin25uliftkV1n4F0QAAAAs"]
[Tue Jul 21 07:43:30.197090 2026] [security2:error] [pid 296703:tid 296929] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wp-aothait.php"] [unique_id "al9NUin25uliftkV1n4F0gAAAGA"]
[Tue Jul 21 07:43:30.217293 2026] [security2:error] [pid 296703:tid 296719] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9NUin25uliftkV1n4F1AAASg8"]
[Tue Jul 21 07:43:30.247917 2026] [security2:error] [pid 296703:tid 296880] [client 20.226.60.151:54376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/w3lls.php"] [unique_id "al9NUin25uliftkV1n4F1QAAAC8"]
[Tue Jul 21 07:43:30.267026 2026] [security2:error] [pid 296703:tid 296927] [client 59.96.220.140:60701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NUin25uliftkV1n4F1wAAAF4"]
[Tue Jul 21 07:43:30.267145 2026] [security2:error] [pid 296703:tid 296927] [client 59.96.220.140:60701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NUin25uliftkV1n4F1wAAAF4"]
[Tue Jul 21 07:43:30.302478 2026] [security2:error] [pid 296703:tid 296717] [remote 41.186.86.12:21421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "loopfinancas.com"] [uri "/wp-login.php"] [unique_id "al9NUin25uliftkV1n4F2AAAEw0"]
[Tue Jul 21 07:43:30.351563 2026] [security2:error] [pid 296703:tid 296734] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9NUin25uliftkV1n4F3AAATh4"]
[Tue Jul 21 07:43:30.372481 2026] [security2:error] [pid 296703:tid 296950] [client 20.197.195.24:49799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/admin.php"] [unique_id "al9NUin25uliftkV1n4F3gAAAHU"]
[Tue Jul 21 07:43:30.463203 2026] [security2:error] [pid 296703:tid 296934] [client 20.220.225.223:19279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/bscclapb.php"] [unique_id "al9NUin25uliftkV1n4F4gAAAGU"]
[Tue Jul 21 07:43:30.463234 2026] [security2:error] [pid 296703:tid 296833] [client 20.220.225.223:11154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/ms.php"] [unique_id "al9NUin25uliftkV1n4F4QAAAAA"]
[Tue Jul 21 07:43:30.508058 2026] [security2:error] [pid 296703:tid 296905] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/config.json.php"] [unique_id "al9NUin25uliftkV1n4F5AAAAEg"]
[Tue Jul 21 07:43:30.517452 2026] [security2:error] [pid 296703:tid 296955] [client 20.220.225.223:34193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/kq1.php"] [unique_id "al9NUin25uliftkV1n4F5QAAAHo"]
[Tue Jul 21 07:43:30.529691 2026] [security2:error] [pid 296703:tid 296730] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9NUin25uliftkV1n4F5gAACRo"]
[Tue Jul 21 07:43:30.590360 2026] [security2:error] [pid 296703:tid 296874] [client 103.106.20.201:55509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NUin25uliftkV1n4F6AAAACk"]
[Tue Jul 21 07:43:30.590501 2026] [security2:error] [pid 296703:tid 296874] [client 103.106.20.201:55509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NUin25uliftkV1n4F6AAAACk"]
[Tue Jul 21 07:43:30.661267 2026] [security2:error] [pid 296703:tid 296848] [client 20.197.195.24:13726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/admin.php"] [unique_id "al9NUin25uliftkV1n4F6gAAAA8"]
[Tue Jul 21 07:43:30.666549 2026] [security2:error] [pid 296703:tid 296718] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9NUin25uliftkV1n4F6wAAaA4"]
[Tue Jul 21 07:43:30.705560 2026] [security2:error] [pid 296703:tid 296841] [client 20.226.60.151:54310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/test1.php"] [unique_id "al9NUin25uliftkV1n4F7AAAAAg"]
[Tue Jul 21 07:43:30.799151 2026] [security2:error] [pid 296703:tid 296744] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9NUin25uliftkV1n4F8QAAWyg"]
[Tue Jul 21 07:43:30.847151 2026] [security2:error] [pid 296703:tid 296884] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9NUin25uliftkV1n4F9AAAADM"]
[Tue Jul 21 07:43:30.911580 2026] [security2:error] [pid 296703:tid 296897] [client 20.226.60.151:54276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/database.php"] [unique_id "al9NUin25uliftkV1n4F-QAAAEA"]
[Tue Jul 21 07:43:30.948264 2026] [security2:error] [pid 296703:tid 296956] [client 20.197.195.24:49877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/themes.php"] [unique_id "al9NUin25uliftkV1n4F-wAAAHs"]
[Tue Jul 21 07:43:31.035357 2026] [security2:error] [pid 296703:tid 296900] [client 122.162.144.145:33018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NUyn25uliftkV1n4GAAAAAEM"]
[Tue Jul 21 07:43:31.035472 2026] [security2:error] [pid 296703:tid 296900] [client 122.162.144.145:33018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NUyn25uliftkV1n4GAAAAAEM"]
[Tue Jul 21 07:43:31.130431 2026] [security2:error] [pid 296703:tid 296921] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/k2.php"] [unique_id "al9NUyn25uliftkV1n4GAQAAAFg"]
[Tue Jul 21 07:43:31.167436 2026] [security2:error] [pid 296703:tid 296934] [client 74.249.245.134:5558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/css.php"] [unique_id "al9NUyn25uliftkV1n4GAwAAAGU"]
[Tue Jul 21 07:43:31.208199 2026] [security2:error] [pid 296703:tid 296925] [client 20.104.96.117:30437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/v543.php"] [unique_id "al9NUyn25uliftkV1n4GBAAAAFw"]
[Tue Jul 21 07:43:31.254279 2026] [autoindex:error] [pid 296703:tid 296955] [client 20.197.195.24:0] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:31.318547 2026] [security2:error] [pid 296703:tid 296881] [client 139.167.225.182:53185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NUyn25uliftkV1n4GDgAAADA"]
[Tue Jul 21 07:43:31.318653 2026] [security2:error] [pid 296703:tid 296881] [client 139.167.225.182:53185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NUyn25uliftkV1n4GDgAAADA"]
[Tue Jul 21 07:43:31.411422 2026] [security2:error] [pid 296703:tid 296902] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9NUyn25uliftkV1n4GEgAAAEU"]
[Tue Jul 21 07:43:31.516186 2026] [security2:error] [pid 296703:tid 296894] [client 136.144.33.108:52603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NUyn25uliftkV1n4GFwAAAD0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:31.623263 2026] [security2:error] [pid 296703:tid 296871] [client 34.74.242.206:1636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.robertaramos.com.br"] [uri "/robots.txt"] [unique_id "al9NUyn25uliftkV1n4GGgAAACY"]
[Tue Jul 21 07:43:31.623348 2026] [security2:error] [pid 296703:tid 296871] [client 34.74.242.206:1636] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.robertaramos.com.br"] [uri "/robots.txt"] [unique_id "al9NUyn25uliftkV1n4GGgAAACY"]
[Tue Jul 21 07:43:31.660902 2026] [security2:error] [pid 296703:tid 296892] [client 20.226.60.151:54346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/file.php"] [unique_id "al9NUyn25uliftkV1n4GGwAAADs"]
[Tue Jul 21 07:43:31.745735 2026] [security2:error] [pid 296703:tid 296929] [client 20.226.60.151:22393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/eee.php"] [unique_id "al9NUyn25uliftkV1n4GHgAAAGA"]
[Tue Jul 21 07:43:31.773004 2026] [security2:error] [pid 296703:tid 296880] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9NUyn25uliftkV1n4GHwAAAC8"]
[Tue Jul 21 07:43:31.832561 2026] [security2:error] [pid 296703:tid 296951] [client 20.220.225.223:19313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/else1.php"] [unique_id "al9NUyn25uliftkV1n4GIgAAAHY"]
[Tue Jul 21 07:43:31.860637 2026] [security2:error] [pid 296703:tid 296911] [client 34.74.242.206:1654] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.robertaramos.com.br"] [uri "/"] [unique_id "al9NUyn25uliftkV1n4GKQAAAE4"]
[Tue Jul 21 07:43:31.860726 2026] [security2:error] [pid 296703:tid 296911] [client 34.74.242.206:1654] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.robertaramos.com.br"] [uri "/"] [unique_id "al9NUyn25uliftkV1n4GKQAAAE4"]
[Tue Jul 21 07:43:32.047639 2026] [security2:error] [pid 296703:tid 296888] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9NVCn25uliftkV1n4GMwAAADc"]
[Tue Jul 21 07:43:32.210783 2026] [security2:error] [pid 296703:tid 296834] [client 20.226.60.151:60123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/file.php"] [unique_id "al9NVCn25uliftkV1n4GNwAAAAE"]
[Tue Jul 21 07:43:32.314390 2026] [security2:error] [pid 296703:tid 296884] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/for.php"] [unique_id "al9NVCn25uliftkV1n4GOwAAADM"]
[Tue Jul 21 07:43:32.593624 2026] [security2:error] [pid 296703:tid 296711] [remote 202.51.202.242:51256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9NVCn25uliftkV1n4GSgAAWQc"]
[Tue Jul 21 07:43:32.614429 2026] [security2:error] [pid 296703:tid 296947] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/raw.php"] [unique_id "al9NVCn25uliftkV1n4GSwAAAHI"]
[Tue Jul 21 07:43:32.634604 2026] [security2:error] [pid 296703:tid 296852] [client 20.226.60.151:54395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/777.php"] [unique_id "al9NVCn25uliftkV1n4GTAAAABM"]
[Tue Jul 21 07:43:32.645284 2026] [security2:error] [pid 296703:tid 296926] [client 193.36.225.123:32285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NUyn25uliftkV1n4GEwAAAF0"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:32.899692 2026] [security2:error] [pid 296703:tid 296944] [client 173.24.185.52:57881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NVCn25uliftkV1n4GVAAAAG8"]
[Tue Jul 21 07:43:32.899783 2026] [security2:error] [pid 296703:tid 296944] [client 173.24.185.52:57881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NVCn25uliftkV1n4GVAAAAG8"]
[Tue Jul 21 07:43:33.030659 2026] [security2:error] [pid 296703:tid 296939] [client 20.197.195.24:49857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/.well-known/about.php"] [unique_id "al9NVSn25uliftkV1n4GXAAAAGo"]
[Tue Jul 21 07:43:33.114646 2026] [security2:error] [pid 296703:tid 296899] [client 20.226.60.151:61984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ssixta.php"] [unique_id "al9NVSn25uliftkV1n4GYQAAAEI"]
[Tue Jul 21 07:43:33.203032 2026] [security2:error] [pid 296703:tid 296938] [client 122.179.91.63:30711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NVSn25uliftkV1n4GYwAAAGk"]
[Tue Jul 21 07:43:33.203139 2026] [security2:error] [pid 296703:tid 296938] [client 122.179.91.63:30711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NVSn25uliftkV1n4GYwAAAGk"]
[Tue Jul 21 07:43:33.269005 2026] [security2:error] [pid 296703:tid 296783] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVSn25uliftkV1n4GZAAAWU8"]
[Tue Jul 21 07:43:33.269154 2026] [security2:error] [pid 296703:tid 296922] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVSn25uliftkV1n4GZAAAWU8"]
[Tue Jul 21 07:43:33.329733 2026] [security2:error] [pid 296703:tid 296926] [client 20.197.195.24:13815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9NVSn25uliftkV1n4GZwAAAF0"]
[Tue Jul 21 07:43:33.392124 2026] [security2:error] [pid 296703:tid 296780] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVSn25uliftkV1n4GawAADkw"]
[Tue Jul 21 07:43:33.392242 2026] [security2:error] [pid 296703:tid 296847] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVSn25uliftkV1n4GawAADkw"]
[Tue Jul 21 07:43:33.429603 2026] [security2:error] [pid 296703:tid 296838] [client 103.166.103.129:11311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NVSn25uliftkV1n4GbQAAAAU"]
[Tue Jul 21 07:43:33.429695 2026] [security2:error] [pid 296703:tid 296838] [client 103.166.103.129:11311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NVSn25uliftkV1n4GbQAAAAU"]
[Tue Jul 21 07:43:33.490245 2026] [security2:error] [pid 296703:tid 296873] [client 152.59.154.239:56916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVSn25uliftkV1n4GbwAAACg"]
[Tue Jul 21 07:43:33.490590 2026] [security2:error] [pid 296703:tid 296873] [client 152.59.154.239:56916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVSn25uliftkV1n4GbwAAACg"]
[Tue Jul 21 07:43:33.613357 2026] [security2:error] [pid 296703:tid 296909] [client 74.249.245.134:5559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/php.php"] [unique_id "al9NVSn25uliftkV1n4GdgAAAEw"]
[Tue Jul 21 07:43:33.647639 2026] [security2:error] [pid 296703:tid 296949] [client 20.197.195.24:49811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/wefile.php"] [unique_id "al9NVSn25uliftkV1n4GeAAAAHQ"]
[Tue Jul 21 07:43:33.808644 2026] [security2:error] [pid 296703:tid 296902] [client 20.220.225.223:19711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/tkikikoko.php"] [unique_id "al9NVSn25uliftkV1n4GewAAAEU"]
[Tue Jul 21 07:43:33.889368 2026] [security2:error] [pid 296703:tid 296841] [client 20.197.195.24:13725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9NVSn25uliftkV1n4GfAAAAAg"]
[Tue Jul 21 07:43:33.934695 2026] [security2:error] [pid 296703:tid 296955] [client 20.226.60.151:60113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/1c.php"] [unique_id "al9NVSn25uliftkV1n4GgQAAAHo"]
[Tue Jul 21 07:43:33.960383 2026] [security2:error] [pid 296703:tid 296951] [client 216.73.160.188:58045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/wp-login.php"] [unique_id "al9NVSn25uliftkV1n4GgwAAAHY"]
[Tue Jul 21 07:43:34.005715 2026] [security2:error] [pid 296703:tid 296899] [client 20.63.100.92:7694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/old.php"] [unique_id "al9NVin25uliftkV1n4GhQAAAEI"]
[Tue Jul 21 07:43:34.194914 2026] [security2:error] [pid 296703:tid 296952] [client 20.104.96.117:30602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/sixxis.php"] [unique_id "al9NVin25uliftkV1n4GiwAAAHc"]
[Tue Jul 21 07:43:34.230450 2026] [security2:error] [pid 296703:tid 296855] [client 103.29.114.44:62139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVin25uliftkV1n4GhgAAABY"]
[Tue Jul 21 07:43:34.230582 2026] [security2:error] [pid 296703:tid 296855] [client 103.29.114.44:62139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVin25uliftkV1n4GhgAAABY"]
[Tue Jul 21 07:43:34.241631 2026] [autoindex:error] [pid 296703:tid 296913] [client 20.197.195.24:0] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:34.311190 2026] [autoindex:error] [pid 296703:tid 296937] [client 20.197.195.24:13705] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:34.326627 2026] [security2:error] [pid 296703:tid 296926] [client 20.197.195.24:13705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9NVin25uliftkV1n4GkAAAAF0"]
[Tue Jul 21 07:43:34.473571 2026] [security2:error] [pid 296703:tid 296958] [client 37.140.223.191:32275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NVin25uliftkV1n4GlgAAAH0"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:34.628601 2026] [security2:error] [pid 296703:tid 296934] [client 20.197.195.24:13718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/8.php"] [unique_id "al9NVin25uliftkV1n4GnQAAAGU"]
[Tue Jul 21 07:43:34.731413 2026] [security2:error] [pid 296703:tid 296880] [client 103.174.34.15:59032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVin25uliftkV1n4GoAAAAC8"]
[Tue Jul 21 07:43:34.731551 2026] [security2:error] [pid 296703:tid 296880] [client 103.174.34.15:59032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVin25uliftkV1n4GoAAAAC8"]
[Tue Jul 21 07:43:34.783744 2026] [security2:error] [pid 296703:tid 296859] [client 128.127.105.184:44556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9NVin25uliftkV1n4GowAAABo"]
[Tue Jul 21 07:43:34.783913 2026] [security2:error] [pid 296703:tid 296859] [client 128.127.105.184:44556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9NVin25uliftkV1n4GowAAABo"]
[Tue Jul 21 07:43:34.945753 2026] [security2:error] [pid 296703:tid 296915] [client 20.226.60.151:61961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/test2.php"] [unique_id "al9NVin25uliftkV1n4GqAAAAFI"]
[Tue Jul 21 07:43:34.972577 2026] [security2:error] [pid 296703:tid 296921] [client 20.226.60.151:50819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/fffm.php"] [unique_id "al9NVin25uliftkV1n4GqgAAAFg"]
[Tue Jul 21 07:43:35.037480 2026] [security2:error] [pid 296703:tid 296853] [client 20.226.60.151:22971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wp-aothait.php"] [unique_id "al9NVyn25uliftkV1n4GrQAAABQ"]
[Tue Jul 21 07:43:35.151689 2026] [security2:error] [pid 296703:tid 296808] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4GswAATGg"]
[Tue Jul 21 07:43:35.151798 2026] [security2:error] [pid 296703:tid 296909] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4GswAATGg"]
[Tue Jul 21 07:43:35.243108 2026] [security2:error] [pid 296703:tid 296847] [client 106.215.181.8:31009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4GtwAAAA4"]
[Tue Jul 21 07:43:35.243269 2026] [security2:error] [pid 296703:tid 296847] [client 106.215.181.8:31009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4GtwAAAA4"]
[Tue Jul 21 07:43:35.342245 2026] [security2:error] [pid 296703:tid 296888] [client 20.197.195.24:13750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/wp-content/admin.php"] [unique_id "al9NVyn25uliftkV1n4GuAAAADc"]
[Tue Jul 21 07:43:35.441695 2026] [security2:error] [pid 296703:tid 296868] [client 74.249.245.134:54396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/aa.php"] [unique_id "al9NVyn25uliftkV1n4GwgAAACM"]
[Tue Jul 21 07:43:35.523147 2026] [security2:error] [pid 296703:tid 296949] [client 182.8.255.181:17514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4GyAAAAHQ"]
[Tue Jul 21 07:43:35.523318 2026] [security2:error] [pid 296703:tid 296949] [client 182.8.255.181:17514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4GyAAAAHQ"]
[Tue Jul 21 07:43:35.574339 2026] [security2:error] [pid 296703:tid 296904] [client 20.104.96.117:30420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/ip.php"] [unique_id "al9NVyn25uliftkV1n4GzQAAAEc"]
[Tue Jul 21 07:43:35.577450 2026] [security2:error] [pid 296703:tid 296955] [client 178.153.91.96:62112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4GzgAAAHo"]
[Tue Jul 21 07:43:35.577563 2026] [security2:error] [pid 296703:tid 296955] [client 178.153.91.96:62112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4GzgAAAHo"]
[Tue Jul 21 07:43:35.609364 2026] [security2:error] [pid 296703:tid 296874] [client 20.197.195.24:13730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/f6.php"] [unique_id "al9NVyn25uliftkV1n4G0gAAACk"]
[Tue Jul 21 07:43:35.706159 2026] [security2:error] [pid 296703:tid 296921] [client 20.220.225.223:34187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/zzz.php"] [unique_id "al9NVyn25uliftkV1n4G1wAAAFg"]
[Tue Jul 21 07:43:35.720549 2026] [security2:error] [pid 296703:tid 296846] [client 20.220.225.223:19969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9NVyn25uliftkV1n4G2AAAAA0"]
[Tue Jul 21 07:43:35.868955 2026] [security2:error] [pid 296703:tid 296767] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4G3QAAZT8"]
[Tue Jul 21 07:43:35.869113 2026] [security2:error] [pid 296703:tid 296934] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4G3QAAZT8"]
[Tue Jul 21 07:43:35.872784 2026] [security2:error] [pid 296703:tid 296730] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4G3gAAYho"]
[Tue Jul 21 07:43:35.872947 2026] [security2:error] [pid 296703:tid 296931] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4G3gAAYho"]
[Tue Jul 21 07:43:35.924682 2026] [security2:error] [pid 296703:tid 296737] [remote 37.139.53.5:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "37.139.53.5" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9NVyn25uliftkV1n4G3wAAbyE"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 07:43:35.924858 2026] [security2:error] [pid 296703:tid 296944] [client 37.139.53.5:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9NVyn25uliftkV1n4G3wAAbyE"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 07:43:36.094563 2026] [autoindex:error] [pid 296703:tid 296872] [client 3.219.86.171:27103] AH01276: Cannot serve directory /home3/bilili18/lojasafrodite.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:36.122251 2026] [security2:error] [pid 296703:tid 296929] [client 20.226.60.151:54322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/buy.php"] [unique_id "al9NWCn25uliftkV1n4G6wAAAGA"]
[Tue Jul 21 07:43:36.130503 2026] [security2:error] [pid 296703:tid 296770] [remote 37.139.53.5:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "37.139.53.5" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9NWCn25uliftkV1n4G7QAAI0I"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 07:43:36.130637 2026] [security2:error] [pid 296703:tid 296868] [client 37.139.53.5:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9NWCn25uliftkV1n4G7QAAI0I"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 07:43:36.188218 2026] [security2:error] [pid 296703:tid 296940] [client 20.197.195.24:13721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/inputs.php"] [unique_id "al9NWCn25uliftkV1n4G8QAAAGs"]
[Tue Jul 21 07:43:36.273286 2026] [security2:error] [pid 296703:tid 296714] [remote 188.95.113.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9NWCn25uliftkV1n4G9AAAXgo"]
[Tue Jul 21 07:43:36.348212 2026] [security2:error] [pid 296703:tid 296932] [client 103.86.117.203:56718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NWCn25uliftkV1n4G-gAAAGM"]
[Tue Jul 21 07:43:36.348342 2026] [security2:error] [pid 296703:tid 296932] [client 103.86.117.203:56718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NWCn25uliftkV1n4G-gAAAGM"]
[Tue Jul 21 07:43:36.860040 2026] [security2:error] [pid 296703:tid 296908] [client 172.245.102.42:61615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NVyn25uliftkV1n4G1gAAAEs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:36.950497 2026] [security2:error] [pid 296703:tid 296833] [client 122.164.127.47:58058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NWCn25uliftkV1n4HCgAAAAA"]
[Tue Jul 21 07:43:36.952302 2026] [security2:error] [pid 296703:tid 296833] [client 122.164.127.47:58058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NWCn25uliftkV1n4HCgAAAAA"]
[Tue Jul 21 07:43:36.982914 2026] [security2:error] [pid 296703:tid 296950] [client 41.68.90.219:62155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWCn25uliftkV1n4HBwAAAHU"]
[Tue Jul 21 07:43:36.983018 2026] [security2:error] [pid 296703:tid 296950] [client 41.68.90.219:62155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWCn25uliftkV1n4HBwAAAHU"]
[Tue Jul 21 07:43:37.033806 2026] [security2:error] [pid 296703:tid 296868] [client 20.197.195.24:13806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/inputs.php"] [unique_id "al9NWSn25uliftkV1n4HDgAAACM"]
[Tue Jul 21 07:43:37.036967 2026] [security2:error] [pid 296703:tid 296874] [client 117.251.86.144:34918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NWSn25uliftkV1n4HEQAAACk"]
[Tue Jul 21 07:43:37.037099 2026] [security2:error] [pid 296703:tid 296874] [client 117.251.86.144:34918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NWSn25uliftkV1n4HEQAAACk"]
[Tue Jul 21 07:43:37.065629 2026] [security2:error] [pid 296703:tid 296920] [client 20.226.60.151:60097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ssend.php"] [unique_id "al9NWSn25uliftkV1n4HGQAAAFc"]
[Tue Jul 21 07:43:37.156072 2026] [security2:error] [pid 296703:tid 296881] [client 20.220.225.223:34179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/wicked.php"] [unique_id "al9NWSn25uliftkV1n4HHwAAADA"]
[Tue Jul 21 07:43:37.175592 2026] [security2:error] [pid 296703:tid 296846] [client 122.186.204.214:59611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NWSn25uliftkV1n4HIAAAAA0"]
[Tue Jul 21 07:43:37.175726 2026] [security2:error] [pid 296703:tid 296846] [client 122.186.204.214:59611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NWSn25uliftkV1n4HIAAAAA0"]
[Tue Jul 21 07:43:37.187325 2026] [security2:error] [pid 296703:tid 296937] [client 74.249.245.134:54356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/bolt.php"] [unique_id "al9NWSn25uliftkV1n4HIQAAAGg"]
[Tue Jul 21 07:43:37.231546 2026] [security2:error] [pid 296703:tid 296809] [remote 97.74.93.24:36948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compressoresra.com.br"] [uri "/wp-login.php"] [unique_id "al9NWSn25uliftkV1n4HJQAAM2k"]
[Tue Jul 21 07:43:37.260934 2026] [security2:error] [pid 296703:tid 296759] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWSn25uliftkV1n4HJwAAdDc"]
[Tue Jul 21 07:43:37.261062 2026] [security2:error] [pid 296703:tid 296949] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWSn25uliftkV1n4HJwAAdDc"]
[Tue Jul 21 07:43:37.469148 2026] [security2:error] [pid 296703:tid 296903] [client 117.247.80.59:28758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWSn25uliftkV1n4HLwAAAEY"]
[Tue Jul 21 07:43:37.469270 2026] [security2:error] [pid 296703:tid 296903] [client 117.247.80.59:28758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWSn25uliftkV1n4HLwAAAEY"]
[Tue Jul 21 07:43:37.505129 2026] [security2:error] [pid 296703:tid 296919] [client 20.197.195.24:13777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/classwithtostring.php"] [unique_id "al9NWSn25uliftkV1n4HMAAAAFY"]
[Tue Jul 21 07:43:37.962372 2026] [security2:error] [pid 296703:tid 296765] [remote 173.252.82.1:33652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.82.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9NWSn25uliftkV1n4HOwAACT0"]
[Tue Jul 21 07:43:37.975512 2026] [security2:error] [pid 296703:tid 296925] [client 37.140.223.157:59393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NWSn25uliftkV1n4HPgAAAFw"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:38.018909 2026] [security2:error] [pid 296703:tid 296902] [client 20.63.100.92:2534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/ms-new.php"] [unique_id "al9NWin25uliftkV1n4HPwAAAEU"]
[Tue Jul 21 07:43:38.135210 2026] [security2:error] [pid 296703:tid 296866] [client 173.239.214.252:28175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.214.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9NWin25uliftkV1n4HQgAAACE"]
[Tue Jul 21 07:43:38.140175 2026] [security2:error] [pid 296703:tid 296789] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NWin25uliftkV1n4HRAAAWFU"]
[Tue Jul 21 07:43:38.140336 2026] [security2:error] [pid 296703:tid 296921] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NWin25uliftkV1n4HRAAAWFU"]
[Tue Jul 21 07:43:38.203330 2026] [security2:error] [pid 296703:tid 296952] [client 20.197.195.24:13703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9NWin25uliftkV1n4HRwAAAHc"]
[Tue Jul 21 07:43:38.346436 2026] [security2:error] [pid 296703:tid 296869] [client 20.104.96.117:30899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/kq1.php"] [unique_id "al9NWin25uliftkV1n4HTwAAACQ"]
[Tue Jul 21 07:43:38.425833 2026] [security2:error] [pid 296703:tid 296873] [client 202.143.127.214:53145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWin25uliftkV1n4HVAAAACg"]
[Tue Jul 21 07:43:38.425995 2026] [security2:error] [pid 296703:tid 296873] [client 202.143.127.214:53145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWin25uliftkV1n4HVAAAACg"]
[Tue Jul 21 07:43:38.461296 2026] [security2:error] [pid 296703:tid 296879] [client 20.226.60.151:22371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/config.json.php"] [unique_id "al9NWin25uliftkV1n4HVQAAAC4"]
[Tue Jul 21 07:43:38.462927 2026] [security2:error] [pid 296703:tid 296889] [client 185.198.240.204:36991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9NWSn25uliftkV1n4HLgAAADg"]
[Tue Jul 21 07:43:38.548770 2026] [security2:error] [pid 296703:tid 296784] [remote 207.182.27.255:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9NWin25uliftkV1n4HSAAAPVA"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 07:43:38.836845 2026] [security2:error] [pid 296703:tid 296842] [client 20.197.195.24:49810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/wp-blog.php"] [unique_id "al9NWin25uliftkV1n4HYgAAAAk"]
[Tue Jul 21 07:43:38.991053 2026] [security2:error] [pid 296703:tid 296859] [client 20.226.60.151:60141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/item.php"] [unique_id "al9NWin25uliftkV1n4HZAAAABo"]
[Tue Jul 21 07:43:39.077054 2026] [security2:error] [pid 296703:tid 296955] [client 74.249.245.134:5564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/x.php"] [unique_id "al9NWyn25uliftkV1n4HZQAAAHo"]
[Tue Jul 21 07:43:39.190506 2026] [security2:error] [pid 296703:tid 296874] [client 117.217.38.194:53054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWyn25uliftkV1n4HbwAAACk"]
[Tue Jul 21 07:43:39.190613 2026] [security2:error] [pid 296703:tid 296874] [client 117.217.38.194:53054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWyn25uliftkV1n4HbwAAACk"]
[Tue Jul 21 07:43:39.220555 2026] [security2:error] [pid 296703:tid 296894] [client 207.182.27.255:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9NWin25uliftkV1n4HSAAAPVA"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 07:43:39.480765 2026] [security2:error] [pid 296703:tid 296811] [remote 65.111.12.194:19395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.12.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9NWyn25uliftkV1n4HgAAAO2s"]
[Tue Jul 21 07:43:39.902945 2026] [security2:error] [pid 296703:tid 296944] [client 154.192.233.199:59817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWyn25uliftkV1n4HjgAAAG8"]
[Tue Jul 21 07:43:39.903119 2026] [security2:error] [pid 296703:tid 296944] [client 154.192.233.199:59817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWyn25uliftkV1n4HjgAAAG8"]
[Tue Jul 21 07:43:39.940085 2026] [security2:error] [pid 296703:tid 296931] [client 20.104.96.117:30442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9NWyn25uliftkV1n4HjwAAAGI"]
[Tue Jul 21 07:43:39.993927 2026] [security2:error] [pid 296703:tid 296856] [client 20.63.100.92:5386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/track.php"] [unique_id "al9NWyn25uliftkV1n4HkQAAABc"]
[Tue Jul 21 07:43:40.003854 2026] [security2:error] [pid 296703:tid 296924] [client 20.197.192.193:58217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9NXCn25uliftkV1n4HkgAAAFs"]
[Tue Jul 21 07:43:40.044376 2026] [security2:error] [pid 296703:tid 296912] [client 20.197.192.193:56433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9NXCn25uliftkV1n4HnAAAAE8"]
[Tue Jul 21 07:43:40.071605 2026] [security2:error] [pid 296703:tid 296919] [client 20.197.192.193:58198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/dp.php"] [unique_id "al9NXCn25uliftkV1n4HpAAAAFY"]
[Tue Jul 21 07:43:40.092872 2026] [autoindex:error] [pid 296703:tid 296908] [client 20.197.195.24:0] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:40.102619 2026] [security2:error] [pid 296703:tid 296914] [client 20.197.195.24:13776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/wp-content/admin.php"] [unique_id "al9NXCn25uliftkV1n4HqQAAAFE"]
[Tue Jul 21 07:43:40.114664 2026] [security2:error] [pid 296703:tid 296940] [client 74.249.245.134:54355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/jga.php"] [unique_id "al9NXCn25uliftkV1n4HqgAAAGs"]
[Tue Jul 21 07:43:40.118825 2026] [security2:error] [pid 296703:tid 296925] [client 20.197.192.193:58432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/old.php"] [unique_id "al9NXCn25uliftkV1n4HqwAAAFw"]
[Tue Jul 21 07:43:40.165761 2026] [security2:error] [pid 296703:tid 296926] [client 20.197.192.193:58195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/ms-new.php"] [unique_id "al9NXCn25uliftkV1n4HrAAAAF0"]
[Tue Jul 21 07:43:40.232728 2026] [security2:error] [pid 296703:tid 296922] [client 20.197.192.193:58481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/track.php"] [unique_id "al9NXCn25uliftkV1n4HswAAAFk"]
[Tue Jul 21 07:43:40.263313 2026] [security2:error] [pid 296703:tid 296854] [client 20.197.192.193:58452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/2352356666.php"] [unique_id "al9NXCn25uliftkV1n4HtQAAABU"]
[Tue Jul 21 07:43:40.302544 2026] [security2:error] [pid 296703:tid 296889] [client 20.197.192.193:56430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/pn.php"] [unique_id "al9NXCn25uliftkV1n4HuAAAADg"]
[Tue Jul 21 07:43:40.303117 2026] [security2:error] [pid 296703:tid 296943] [client 20.197.195.24:13701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/ms-edit.php"] [unique_id "al9NXCn25uliftkV1n4HuQAAAG4"]
[Tue Jul 21 07:43:40.333599 2026] [security2:error] [pid 296703:tid 296923] [client 20.197.192.193:56438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-wpbak.php"] [unique_id "al9NXCn25uliftkV1n4HuwAAAFo"]
[Tue Jul 21 07:43:40.371613 2026] [security2:error] [pid 296703:tid 296904] [client 20.197.192.193:40886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/dr.php"] [unique_id "al9NXCn25uliftkV1n4HvwAAAEc"]
[Tue Jul 21 07:43:40.399758 2026] [security2:error] [pid 296703:tid 296893] [client 20.197.192.193:58208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/2x.php"] [unique_id "al9NXCn25uliftkV1n4HwAAAADw"]
[Tue Jul 21 07:43:40.429328 2026] [security2:error] [pid 296703:tid 296940] [client 20.197.192.193:58206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/kq1.php"] [unique_id "al9NXCn25uliftkV1n4HwgAAAGs"]
[Tue Jul 21 07:43:40.460469 2026] [security2:error] [pid 296703:tid 296839] [client 20.197.192.193:58186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/zzz.php"] [unique_id "al9NXCn25uliftkV1n4HwwAAAAY"]
[Tue Jul 21 07:43:40.477253 2026] [security2:error] [pid 296703:tid 296956] [client 20.197.192.193:58437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wicked.php"] [unique_id "al9NXCn25uliftkV1n4HxgAAAHs"]
[Tue Jul 21 07:43:40.506847 2026] [security2:error] [pid 296703:tid 296902] [client 20.197.192.193:58183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/edit.php"] [unique_id "al9NXCn25uliftkV1n4HyAAAAEU"]
[Tue Jul 21 07:43:40.530101 2026] [security2:error] [pid 296703:tid 296942] [client 20.197.192.193:56429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/kua.php"] [unique_id "al9NXCn25uliftkV1n4HyQAAAG0"]
[Tue Jul 21 07:43:40.556066 2026] [security2:error] [pid 296703:tid 296879] [client 20.197.192.193:58227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/ez.php"] [unique_id "al9NXCn25uliftkV1n4HygAAAC4"]
[Tue Jul 21 07:43:40.574309 2026] [security2:error] [pid 296703:tid 296858] [client 20.197.192.193:56394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/fz.php"] [unique_id "al9NXCn25uliftkV1n4HywAAABk"]
[Tue Jul 21 07:43:40.593332 2026] [security2:error] [pid 296703:tid 296855] [client 20.197.192.193:58194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/la.php"] [unique_id "al9NXCn25uliftkV1n4HzQAAABY"]
[Tue Jul 21 07:43:40.615601 2026] [security2:error] [pid 296703:tid 296934] [client 20.197.192.193:58219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/nhvoanpl.php"] [unique_id "al9NXCn25uliftkV1n4H0QAAAGU"]
[Tue Jul 21 07:43:40.620925 2026] [security2:error] [pid 296703:tid 296911] [client 136.144.33.106:26281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NXCn25uliftkV1n4H0gAAAE4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:40.655892 2026] [security2:error] [pid 296703:tid 296949] [client 20.197.192.193:58197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/inso.php"] [unique_id "al9NXCn25uliftkV1n4H0wAAAHQ"]
[Tue Jul 21 07:43:40.679469 2026] [security2:error] [pid 296703:tid 296874] [client 20.197.192.193:56420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wpx.php"] [unique_id "al9NXCn25uliftkV1n4H1AAAACk"]
[Tue Jul 21 07:43:40.705314 2026] [security2:error] [pid 296703:tid 296833] [client 20.197.192.193:58233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/berlin.php"] [unique_id "al9NXCn25uliftkV1n4H1QAAAAA"]
[Tue Jul 21 07:43:40.768706 2026] [security2:error] [pid 296703:tid 296937] [client 20.197.195.24:13724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/cgi-bin/index.php"] [unique_id "al9NXCn25uliftkV1n4H3AAAAGg"]
[Tue Jul 21 07:43:40.784355 2026] [security2:error] [pid 296703:tid 296904] [client 20.197.192.193:58479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/billur.php"] [unique_id "al9NXCn25uliftkV1n4H3gAAAEc"]
[Tue Jul 21 07:43:40.811116 2026] [security2:error] [pid 296703:tid 296915] [client 20.104.96.117:30597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/h02ugyh.php"] [unique_id "al9NXCn25uliftkV1n4H4AAAAFI"]
[Tue Jul 21 07:43:40.840250 2026] [security2:error] [pid 296703:tid 296793] [remote 167.160.65.170:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9NWin25uliftkV1n4HVwAAPVk"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 07:43:40.948108 2026] [security2:error] [pid 296703:tid 296944] [client 20.197.192.193:58225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/mimpi.php"] [unique_id "al9NXCn25uliftkV1n4H6QAAAG8"]
[Tue Jul 21 07:43:41.044627 2026] [security2:error] [pid 296703:tid 296924] [client 74.249.245.134:17410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/k.php"] [unique_id "al9NXSn25uliftkV1n4H7wAAAFs"]
[Tue Jul 21 07:43:41.050539 2026] [security2:error] [pid 296703:tid 296856] [client 20.197.192.193:56432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/dp.php"] [unique_id "al9NXSn25uliftkV1n4H8QAAABc"]
[Tue Jul 21 07:43:41.057869 2026] [autoindex:error] [pid 296703:tid 296855] [client 20.197.195.24:0] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:41.095030 2026] [security2:error] [pid 296703:tid 296889] [client 20.197.192.193:49563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/bootstrap.php"] [unique_id "al9NXSn25uliftkV1n4H8gAAADg"]
[Tue Jul 21 07:43:41.096208 2026] [security2:error] [pid 296703:tid 296949] [client 20.197.195.24:13735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/BDKR28WP.php"] [unique_id "al9NXSn25uliftkV1n4H8wAAAHQ"]
[Tue Jul 21 07:43:41.120159 2026] [security2:error] [pid 296703:tid 296833] [client 20.197.192.193:56423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-editor.php"] [unique_id "al9NXSn25uliftkV1n4H9QAAAAA"]
[Tue Jul 21 07:43:41.168136 2026] [proxy:error] [pid 296703:tid 296704] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.168180 2026] [proxy_http:error] [pid 296703:tid 296704] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.168710 2026] [proxy:error] [pid 296703:tid 296704] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.168743 2026] [proxy_http:error] [pid 296703:tid 296704] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.169891 2026] [proxy:error] [pid 296703:tid 296741] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.169939 2026] [proxy_http:error] [pid 296703:tid 296741] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.170470 2026] [proxy:error] [pid 296703:tid 296741] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.170497 2026] [proxy_http:error] [pid 296703:tid 296741] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.191001 2026] [security2:error] [pid 296703:tid 296908] [client 20.197.192.193:56446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/cro.php"] [unique_id "al9NXSn25uliftkV1n4IAAAAAEs"]
[Tue Jul 21 07:43:41.217767 2026] [autoindex:error] [pid 296703:tid 296911] [client 66.249.69.224:51925] AH01276: Cannot serve directory /home1/domusc58/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:41.230754 2026] [security2:error] [pid 296703:tid 296914] [client 20.197.192.193:58200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/cron-tab.php"] [unique_id "al9NXSn25uliftkV1n4IAwAAAFE"]
[Tue Jul 21 07:43:41.232555 2026] [security2:error] [pid 296703:tid 296894] [client 167.160.65.170:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9NWin25uliftkV1n4HVwAAPVk"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 07:43:41.263906 2026] [security2:error] [pid 296703:tid 296880] [client 20.226.60.151:50921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/dfre.php"] [unique_id "al9NXSn25uliftkV1n4IBgAAAC8"]
[Tue Jul 21 07:43:41.284865 2026] [security2:error] [pid 296703:tid 296955] [client 20.197.192.193:49584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/koiy.php"] [unique_id "al9NXSn25uliftkV1n4ICwAAAHo"]
[Tue Jul 21 07:43:41.328247 2026] [security2:error] [pid 296703:tid 296861] [client 20.197.192.193:58441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/hp2.php"] [unique_id "al9NXSn25uliftkV1n4IEAAAABw"]
[Tue Jul 21 07:43:41.331673 2026] [security2:error] [pid 296703:tid 296919] [client 193.36.225.102:25191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NXSn25uliftkV1n4H9gAAAFY"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:41.352490 2026] [security2:error] [pid 296703:tid 296869] [client 20.197.192.193:58488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/hp3.php"] [unique_id "al9NXSn25uliftkV1n4IEwAAACQ"]
[Tue Jul 21 07:43:41.370442 2026] [security2:error] [pid 296703:tid 296923] [client 103.106.20.201:56182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NXSn25uliftkV1n4IFQAAAFo"]
[Tue Jul 21 07:43:41.370610 2026] [security2:error] [pid 296703:tid 296923] [client 103.106.20.201:56182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NXSn25uliftkV1n4IFQAAAFo"]
[Tue Jul 21 07:43:41.378162 2026] [security2:error] [pid 296703:tid 296941] [client 20.197.192.193:58464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/aa1.php"] [unique_id "al9NXSn25uliftkV1n4IFwAAAGw"]
[Tue Jul 21 07:43:41.411099 2026] [security2:error] [pid 296703:tid 296845] [client 20.197.192.193:58467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/acew67.php"] [unique_id "al9NXSn25uliftkV1n4IGgAAAAw"]
[Tue Jul 21 07:43:41.449532 2026] [security2:error] [pid 296703:tid 296868] [client 20.197.192.193:56418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/bscclapb.php"] [unique_id "al9NXSn25uliftkV1n4IHQAAACM"]
[Tue Jul 21 07:43:41.474191 2026] [security2:error] [pid 296703:tid 296914] [client 20.197.192.193:58492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/else1.php"] [unique_id "al9NXSn25uliftkV1n4IHgAAAFE"]
[Tue Jul 21 07:43:41.501790 2026] [security2:error] [pid 296703:tid 296847] [client 20.197.192.193:40861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/tkikikoko.php"] [unique_id "al9NXSn25uliftkV1n4IIAAAAA4"]
[Tue Jul 21 07:43:41.516399 2026] [security2:error] [pid 296703:tid 296866] [client 20.197.192.193:58190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-Blogs.php"] [unique_id "al9NXSn25uliftkV1n4IIQAAACE"]
[Tue Jul 21 07:43:41.530965 2026] [security2:error] [pid 296703:tid 296880] [client 20.197.192.193:49569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-css.php"] [unique_id "al9NXSn25uliftkV1n4IIgAAAC8"]
[Tue Jul 21 07:43:41.531867 2026] [security2:error] [pid 296703:tid 296907] [client 62.102.148.187:36512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9NXSn25uliftkV1n4IIwAAAEo"]
[Tue Jul 21 07:43:41.531929 2026] [security2:error] [pid 296703:tid 296907] [client 62.102.148.187:36512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9NXSn25uliftkV1n4IIwAAAEo"]
[Tue Jul 21 07:43:41.550557 2026] [security2:error] [pid 296703:tid 296878] [client 20.197.192.193:56412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-explorer.php"] [unique_id "al9NXSn25uliftkV1n4IJAAAAC0"]
[Tue Jul 21 07:43:41.555373 2026] [security2:error] [pid 296703:tid 296844] [client 20.63.100.92:1219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/2352356666.php"] [unique_id "al9NXSn25uliftkV1n4IJQAAAAs"]
[Tue Jul 21 07:43:41.573671 2026] [security2:error] [pid 296703:tid 296855] [client 20.197.192.193:58209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/akismet.php"] [unique_id "al9NXSn25uliftkV1n4IJgAAABY"]
[Tue Jul 21 07:43:41.592396 2026] [security2:error] [pid 296703:tid 296867] [client 20.197.192.193:58177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/ace2.php"] [unique_id "al9NXSn25uliftkV1n4IJwAAACI"]
[Tue Jul 21 07:43:41.604996 2026] [security2:error] [pid 296703:tid 296849] [client 20.197.192.193:49586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/ms.php"] [unique_id "al9NXSn25uliftkV1n4IKAAAABA"]
[Tue Jul 21 07:43:41.720950 2026] [proxy:error] [pid 296703:tid 296762] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.721053 2026] [proxy_http:error] [pid 296703:tid 296762] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.722168 2026] [proxy:error] [pid 296703:tid 296762] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.722218 2026] [proxy_http:error] [pid 296703:tid 296762] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.722437 2026] [proxy:error] [pid 296703:tid 296785] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.722497 2026] [proxy_http:error] [pid 296703:tid 296785] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.723113 2026] [proxy:error] [pid 296703:tid 296785] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.723152 2026] [proxy_http:error] [pid 296703:tid 296785] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.785703 2026] [http2:info] [pid 302018:tid 302018] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 07:43:41.859679 2026] [autoindex:error] [pid 302018:tid 302151] [client 20.197.195.24:0] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:41.902426 2026] [proxy:error] [pid 296703:tid 296747] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.902484 2026] [proxy_http:error] [pid 296703:tid 296747] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.903007 2026] [proxy:error] [pid 296703:tid 296747] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.903035 2026] [proxy_http:error] [pid 296703:tid 296747] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.906597 2026] [proxy:error] [pid 296703:tid 296804] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.906637 2026] [proxy_http:error] [pid 296703:tid 296804] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.907145 2026] [proxy:error] [pid 296703:tid 296804] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.907170 2026] [proxy_http:error] [pid 296703:tid 296804] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.951095 2026] [security2:error] [pid 296703:tid 296915] [client 122.162.144.145:14067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NXSn25uliftkV1n4IQQAAAFI"]
[Tue Jul 21 07:43:41.951231 2026] [security2:error] [pid 296703:tid 296915] [client 122.162.144.145:14067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NXSn25uliftkV1n4IQQAAAFI"]
[Tue Jul 21 07:43:41.971595 2026] [security2:error] [pid 296703:tid 296937] [client 20.104.96.117:30869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wp-temp.php"] [unique_id "al9NXSn25uliftkV1n4IRQAAAGg"]
[Tue Jul 21 07:43:41.972367 2026] [security2:error] [pid 296703:tid 296851] [client 139.167.225.182:53836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NXSn25uliftkV1n4IRgAAABI"]
[Tue Jul 21 07:43:41.972447 2026] [security2:error] [pid 296703:tid 296851] [client 139.167.225.182:53836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NXSn25uliftkV1n4IRgAAABI"]
[Tue Jul 21 07:43:41.975971 2026] [security2:error] [pid 296703:tid 296904] [client 74.249.245.134:5565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/vx.php"] [unique_id "al9NXSn25uliftkV1n4IRwAAAEc"]
[Tue Jul 21 07:43:42.093457 2026] [security2:error] [pid 296703:tid 296797] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXin25uliftkV1n4ISgAAZV0"]
[Tue Jul 21 07:43:42.249889 2026] [security2:error] [pid 296703:tid 296750] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXin25uliftkV1n4ISQAAFy4"]
[Tue Jul 21 07:43:42.272887 2026] [security2:error] [pid 296703:tid 296784] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXin25uliftkV1n4IUQAALFA"]
[Tue Jul 21 07:43:42.382903 2026] [autoindex:error] [pid 302018:tid 302157] [client 20.197.195.24:0] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:42.430470 2026] [security2:error] [pid 296703:tid 296904] [client 20.197.195.24:49862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/abcd.php"] [unique_id "al9NXin25uliftkV1n4IWQAAAEc"]
[Tue Jul 21 07:43:42.432937 2026] [security2:error] [pid 296703:tid 296811] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXin25uliftkV1n4IWgAAPWs"]
[Tue Jul 21 07:43:42.443091 2026] [security2:error] [pid 296703:tid 296735] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXin25uliftkV1n4IWwAAXB8"]
[Tue Jul 21 07:43:42.618127 2026] [proxy:error] [pid 296703:tid 296779] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:42.618190 2026] [proxy_http:error] [pid 296703:tid 296779] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:42.618613 2026] [proxy:error] [pid 296703:tid 296779] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:42.618633 2026] [proxy_http:error] [pid 296703:tid 296779] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:42.627161 2026] [security2:error] [pid 302018:tid 302023] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXoAs9lPxxVAErz3iywAAlQI"]
[Tue Jul 21 07:43:42.632664 2026] [security2:error] [pid 302018:tid 302024] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXoAs9lPxxVAErz3izAAAmgM"]
[Tue Jul 21 07:43:42.723348 2026] [security2:error] [pid 296703:tid 296926] [client 20.220.225.223:19699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/wp-css.php"] [unique_id "al9NXin25uliftkV1n4IYgAAAF0"]
[Tue Jul 21 07:43:42.750099 2026] [autoindex:error] [pid 296703:tid 296817] [remote 74.7.242.34:58126] AH01276: Cannot serve directory /home2/jefe0292/robopsf3.agendaclique.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:42.766052 2026] [security2:error] [pid 302018:tid 302173] [client 20.226.60.151:56016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ss.php"] [unique_id "al9NXoAs9lPxxVAErz3izgAAAJw"]
[Tue Jul 21 07:43:42.805824 2026] [proxy:error] [pid 302018:tid 302025] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:42.805865 2026] [proxy_http:error] [pid 302018:tid 302025] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:42.806481 2026] [proxy:error] [pid 302018:tid 302025] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:42.806502 2026] [proxy_http:error] [pid 302018:tid 302025] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:42.810351 2026] [security2:error] [pid 296703:tid 296742] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXin25uliftkV1n4IZQAAKyY"]
[Tue Jul 21 07:43:42.811400 2026] [security2:error] [pid 302018:tid 302026] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXoAs9lPxxVAErz3i0AAAowU"]
[Tue Jul 21 07:43:42.814641 2026] [security2:error] [pid 296703:tid 296838] [client 103.29.114.44:54340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NXin25uliftkV1n4IaQAAAAU"]
[Tue Jul 21 07:43:42.820270 2026] [security2:error] [pid 296703:tid 296838] [client 103.29.114.44:54340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NXin25uliftkV1n4IaQAAAAU"]
[Tue Jul 21 07:43:42.931261 2026] [security2:error] [pid 302018:tid 302178] [client 74.7.175.189:55720] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.robopsf3.agendaclique.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9NXoAs9lPxxVAErz3i1AAAoQc"]
[Tue Jul 21 07:43:42.963745 2026] [security2:error] [pid 296703:tid 296737] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXin25uliftkV1n4IcAAAMSE"]
[Tue Jul 21 07:43:42.993000 2026] [security2:error] [pid 296703:tid 296734] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXin25uliftkV1n4IcQAAbB4"]
[Tue Jul 21 07:43:43.146295 2026] [security2:error] [pid 302018:tid 302030] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NX4As9lPxxVAErz3i2QAAtgk"]
[Tue Jul 21 07:43:43.231136 2026] [security2:error] [pid 296703:tid 296938] [client 128.127.105.184:42070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9NXyn25uliftkV1n4IdAAAAGk"]
[Tue Jul 21 07:43:43.231233 2026] [security2:error] [pid 296703:tid 296938] [client 128.127.105.184:42070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9NXyn25uliftkV1n4IdAAAAGk"]
[Tue Jul 21 07:43:43.235677 2026] [security2:error] [pid 296703:tid 296860] [client 20.197.195.24:13774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/file15.php"] [unique_id "al9NXyn25uliftkV1n4IdQAAABs"]
[Tue Jul 21 07:43:43.379746 2026] [security2:error] [pid 296703:tid 296771] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXyn25uliftkV1n4IfQAANEM"]
[Tue Jul 21 07:43:43.437912 2026] [security2:error] [pid 302018:tid 302200] [client 173.24.185.52:58361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NX4As9lPxxVAErz3i4gAAALc"]
[Tue Jul 21 07:43:43.438086 2026] [security2:error] [pid 302018:tid 302200] [client 173.24.185.52:58361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NX4As9lPxxVAErz3i4gAAALc"]
[Tue Jul 21 07:43:43.474311 2026] [security2:error] [pid 296703:tid 296915] [client 20.104.96.117:30895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9NXyn25uliftkV1n4IgQAAAFI"]
[Tue Jul 21 07:43:43.529519 2026] [security2:error] [pid 302018:tid 302222] [client 20.104.96.117:44096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9NX4As9lPxxVAErz3i5QAAAM0"]
[Tue Jul 21 07:43:43.563065 2026] [security2:error] [pid 296703:tid 296714] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXyn25uliftkV1n4IhQAAPQo"]
[Tue Jul 21 07:43:43.563575 2026] [security2:error] [pid 296703:tid 296925] [client 20.226.60.151:50933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-happy.php"] [unique_id "al9NXyn25uliftkV1n4IhwAAAFw"]
[Tue Jul 21 07:43:43.569048 2026] [security2:error] [pid 296703:tid 296937] [client 34.12.245.104:54327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.245.12.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verbodavidachapeco.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NXyn25uliftkV1n4IhgAAAGg"]
[Tue Jul 21 07:43:43.620095 2026] [security2:error] [pid 302018:tid 302230] [client 74.249.245.134:5531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/ws77.php"] [unique_id "al9NX4As9lPxxVAErz3i6AAAANU"]
[Tue Jul 21 07:43:43.692010 2026] [security2:error] [pid 296703:tid 296897] [client 20.220.225.223:34243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/edit.php"] [unique_id "al9NXyn25uliftkV1n4IiwAAAEA"]
[Tue Jul 21 07:43:43.846657 2026] [security2:error] [pid 296703:tid 296959] [client 59.96.220.140:61236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NXyn25uliftkV1n4IkQAAAH4"]
[Tue Jul 21 07:43:43.846764 2026] [security2:error] [pid 296703:tid 296959] [client 59.96.220.140:61236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NXyn25uliftkV1n4IkQAAAH4"]
[Tue Jul 21 07:43:43.888734 2026] [security2:error] [pid 296703:tid 296881] [client 194.99.104.35:50802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9NXyn25uliftkV1n4ImgAAADA"]
[Tue Jul 21 07:43:43.888825 2026] [security2:error] [pid 296703:tid 296881] [client 194.99.104.35:50802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9NXyn25uliftkV1n4ImgAAADA"]
[Tue Jul 21 07:43:43.894191 2026] [security2:error] [pid 302018:tid 302037] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NX4As9lPxxVAErz3i6gAA3hA"]
[Tue Jul 21 07:43:43.894334 2026] [security2:error] [pid 302018:tid 302239] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NX4As9lPxxVAErz3i6gAA3hA"]
[Tue Jul 21 07:43:43.921171 2026] [security2:error] [pid 302018:tid 302038] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NX4As9lPxxVAErz3i6wAA4BE"]
[Tue Jul 21 07:43:43.921319 2026] [security2:error] [pid 302018:tid 302241] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NX4As9lPxxVAErz3i6wAA4BE"]
[Tue Jul 21 07:43:43.999346 2026] [security2:error] [pid 296703:tid 296853] [client 34.12.245.104:64453] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "verbodavidachapeco.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9NXyn25uliftkV1n4InQAAABQ"]
[Tue Jul 21 07:43:44.138469 2026] [security2:error] [pid 302018:tid 302245] [client 20.226.60.151:22967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9NYIAs9lPxxVAErz3i7QAAAOQ"]
[Tue Jul 21 07:43:44.207553 2026] [security2:error] [pid 296703:tid 296851] [client 103.166.103.129:60778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NYCn25uliftkV1n4IqgAAABI"]
[Tue Jul 21 07:43:44.208345 2026] [security2:error] [pid 296703:tid 296851] [client 103.166.103.129:60778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NYCn25uliftkV1n4IqgAAABI"]
[Tue Jul 21 07:43:44.412663 2026] [security2:error] [pid 296703:tid 296868] [client 20.63.100.92:7967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/pn.php"] [unique_id "al9NYCn25uliftkV1n4IswAAACM"]
[Tue Jul 21 07:43:44.428774 2026] [security2:error] [pid 296703:tid 296890] [client 34.12.245.104:55795] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "verbodavidachapeco.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9NYCn25uliftkV1n4ItAAAADk"]
[Tue Jul 21 07:43:44.863986 2026] [security2:error] [pid 296703:tid 296926] [client 34.12.245.104:64165] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "verbodavidachapeco.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9NYCn25uliftkV1n4IvQAAAF0"]
[Tue Jul 21 07:43:44.885020 2026] [security2:error] [pid 302018:tid 302259] [client 74.249.245.134:5560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/2.php"] [unique_id "al9NYIAs9lPxxVAErz3i9gAAAPI"]
[Tue Jul 21 07:43:44.941689 2026] [security2:error] [pid 302018:tid 302261] [client 20.226.60.151:61981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/hypo.php"] [unique_id "al9NYIAs9lPxxVAErz3i9wAAAPQ"]
[Tue Jul 21 07:43:45.122772 2026] [security2:error] [pid 302018:tid 302268] [client 20.197.195.24:13749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/jp.php"] [unique_id "al9NYYAs9lPxxVAErz3i-AAAAPs"]
[Tue Jul 21 07:43:45.200128 2026] [security2:error] [pid 302018:tid 302044] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NYYAs9lPxxVAErz3i-gAA_hc"]
[Tue Jul 21 07:43:45.269687 2026] [security2:error] [pid 296703:tid 296851] [client 20.226.60.151:50927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/fpr4.php"] [unique_id "al9NYSn25uliftkV1n4IygAAABI"]
[Tue Jul 21 07:43:45.297390 2026] [security2:error] [pid 296703:tid 296947] [client 34.12.245.104:61475] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "verbodavidachapeco.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9NYSn25uliftkV1n4IzAAAAHI"]
[Tue Jul 21 07:43:45.302754 2026] [security2:error] [pid 302018:tid 302233] [client 136.144.33.54:22611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NYYAs9lPxxVAErz3i-wAAANg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:45.376711 2026] [security2:error] [pid 296703:tid 296828] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NYSn25uliftkV1n4I0wAAFXw"]
[Tue Jul 21 07:43:45.404708 2026] [security2:error] [pid 296703:tid 296919] [client 193.36.225.143:36171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NYSn25uliftkV1n4IyAAAAFY"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:45.535571 2026] [security2:error] [pid 296703:tid 296838] [client 103.174.34.15:59516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NYSn25uliftkV1n4I2QAAAAU"]
[Tue Jul 21 07:43:45.535920 2026] [security2:error] [pid 296703:tid 296838] [client 103.174.34.15:59516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NYSn25uliftkV1n4I2QAAAAU"]
[Tue Jul 21 07:43:45.600594 2026] [security2:error] [pid 296703:tid 296780] [remote 104.207.45.89:17005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.45.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9NYSn25uliftkV1n4I1gAAT0w"]
[Tue Jul 21 07:43:45.730172 2026] [security2:error] [pid 296703:tid 296872] [client 106.215.181.8:18543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NYSn25uliftkV1n4I4gAAACc"]
[Tue Jul 21 07:43:45.730276 2026] [security2:error] [pid 296703:tid 296872] [client 106.215.181.8:18543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NYSn25uliftkV1n4I4gAAACc"]
[Tue Jul 21 07:43:45.732035 2026] [security2:error] [pid 302018:tid 302157] [client 34.12.245.104:55834] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "verbodavidachapeco.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9NYYAs9lPxxVAErz3jAgAAAIw"]
[Tue Jul 21 07:43:45.742104 2026] [security2:error] [pid 302018:tid 302159] [client 20.220.225.223:34281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/kua.php"] [unique_id "al9NYYAs9lPxxVAErz3jAwAAAI4"]
[Tue Jul 21 07:43:45.807130 2026] [security2:error] [pid 296703:tid 296747] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NYSn25uliftkV1n4I5AAABis"]
[Tue Jul 21 07:43:45.807262 2026] [security2:error] [pid 296703:tid 296839] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NYSn25uliftkV1n4I5AAABis"]
[Tue Jul 21 07:43:45.977037 2026] [security2:error] [pid 302018:tid 302167] [client 128.127.105.184:46858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9NYYAs9lPxxVAErz3jBQAAAJY"]
[Tue Jul 21 07:43:45.977142 2026] [security2:error] [pid 302018:tid 302167] [client 128.127.105.184:46858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9NYYAs9lPxxVAErz3jBQAAAJY"]
[Tue Jul 21 07:43:45.999707 2026] [security2:error] [pid 302018:tid 302272] [client 182.8.255.181:17335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NYYAs9lPxxVAErz3jBwAAAP8"]
[Tue Jul 21 07:43:45.999851 2026] [security2:error] [pid 302018:tid 302272] [client 182.8.255.181:17335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NYYAs9lPxxVAErz3jBwAAAP8"]
[Tue Jul 21 07:43:46.086628 2026] [security2:error] [pid 296703:tid 296925] [client 20.226.60.151:60138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/users.php"] [unique_id "al9NYin25uliftkV1n4I7wAAAFw"]
[Tue Jul 21 07:43:46.102856 2026] [security2:error] [pid 302018:tid 302151] [client 178.153.91.96:6614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NYoAs9lPxxVAErz3jCQAAAIY"]
[Tue Jul 21 07:43:46.103028 2026] [security2:error] [pid 302018:tid 302151] [client 178.153.91.96:6614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NYoAs9lPxxVAErz3jCQAAAIY"]
[Tue Jul 21 07:43:46.175896 2026] [security2:error] [pid 296703:tid 296940] [client 34.12.245.104:60519] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "verbodavidachapeco.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9NYin25uliftkV1n4I8gAAAGs"]
[Tue Jul 21 07:43:46.177607 2026] [security2:error] [pid 302018:tid 302170] [client 20.197.195.24:13796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/f35.php"] [unique_id "al9NYoAs9lPxxVAErz3jDwAAAJk"]
[Tue Jul 21 07:43:46.365652 2026] [security2:error] [pid 296703:tid 296907] [client 74.249.245.134:17456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/asd.php"] [unique_id "al9NYin25uliftkV1n4I9wAAAEo"]
[Tue Jul 21 07:43:46.467453 2026] [security2:error] [pid 296703:tid 296901] [client 20.226.60.151:22966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/k2.php"] [unique_id "al9NYin25uliftkV1n4I-QAAAEQ"]
[Tue Jul 21 07:43:46.491140 2026] [security2:error] [pid 296703:tid 296911] [client 20.104.96.117:30879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9NYin25uliftkV1n4I-wAAAE4"]
[Tue Jul 21 07:43:46.587298 2026] [security2:error] [pid 302018:tid 302053] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NYoAs9lPxxVAErz3jGwAAqiA"]
[Tue Jul 21 07:43:46.587431 2026] [security2:error] [pid 302018:tid 302187] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NYoAs9lPxxVAErz3jGwAAqiA"]
[Tue Jul 21 07:43:46.615372 2026] [security2:error] [pid 296703:tid 296952] [client 20.197.195.24:13746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/wp-load.php"] [unique_id "al9NYin25uliftkV1n4I_gAAAHc"]
[Tue Jul 21 07:43:46.648526 2026] [security2:error] [pid 302018:tid 302207] [client 34.12.245.104:60056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "verbodavidachapeco.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9NYoAs9lPxxVAErz3jHAAAAL4"]
[Tue Jul 21 07:43:46.654624 2026] [security2:error] [pid 302018:tid 302051] [remote 104.207.48.107:50321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.48.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9NYoAs9lPxxVAErz3jFgAAph4"]
[Tue Jul 21 07:43:46.727020 2026] [security2:error] [pid 302018:tid 302054] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NYoAs9lPxxVAErz3jHQAAsiE"]
[Tue Jul 21 07:43:46.727180 2026] [security2:error] [pid 302018:tid 302195] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NYoAs9lPxxVAErz3jHQAAsiE"]
[Tue Jul 21 07:43:46.833322 2026] [security2:error] [pid 296703:tid 296885] [client 152.59.154.239:48970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NYin25uliftkV1n4JAwAAADQ"]
[Tue Jul 21 07:43:46.833490 2026] [security2:error] [pid 296703:tid 296885] [client 152.59.154.239:48970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NYin25uliftkV1n4JAwAAADQ"]
[Tue Jul 21 07:43:46.834999 2026] [security2:error] [pid 296703:tid 296937] [client 103.86.117.203:57258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NYin25uliftkV1n4JBAAAAGg"]
[Tue Jul 21 07:43:46.835166 2026] [security2:error] [pid 296703:tid 296937] [client 103.86.117.203:57258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NYin25uliftkV1n4JBAAAAGg"]
[Tue Jul 21 07:43:46.898769 2026] [security2:error] [pid 302018:tid 302055] [remote 104.207.58.53:55353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9NYoAs9lPxxVAErz3jHgAAsyI"]
[Tue Jul 21 07:43:47.135889 2026] [security2:error] [pid 302018:tid 302230] [client 20.226.60.151:59488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/file88.php"] [unique_id "al9NY4As9lPxxVAErz3jIQAAANU"]
[Tue Jul 21 07:43:47.181876 2026] [security2:error] [pid 302018:tid 302237] [client 34.12.245.104:59667] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "verbodavidachapeco.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9NY4As9lPxxVAErz3jJAAAANw"]
[Tue Jul 21 07:43:47.217582 2026] [security2:error] [pid 302018:tid 302241] [client 20.226.60.151:54374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/177.php"] [unique_id "al9NY4As9lPxxVAErz3jJwAAAOA"]
[Tue Jul 21 07:43:47.312307 2026] [security2:error] [pid 296703:tid 296926] [client 20.197.195.24:13764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/xyn.php"] [unique_id "al9NYyn25uliftkV1n4JDQAAAF0"]
[Tue Jul 21 07:43:47.389466 2026] [security2:error] [pid 302018:tid 302248] [client 74.249.245.134:54338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/default.php"] [unique_id "al9NY4As9lPxxVAErz3jKwAAAOc"]
[Tue Jul 21 07:43:47.419036 2026] [security2:error] [pid 296703:tid 296854] [client 20.104.96.117:44127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9NYyn25uliftkV1n4JDgAAABU"]
[Tue Jul 21 07:43:47.491007 2026] [security2:error] [pid 302018:tid 302208] [client 122.164.127.47:58627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NY4As9lPxxVAErz3jLAAAAL8"]
[Tue Jul 21 07:43:47.495691 2026] [security2:error] [pid 302018:tid 302208] [client 122.164.127.47:58627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NY4As9lPxxVAErz3jLAAAAL8"]
[Tue Jul 21 07:43:47.789244 2026] [autoindex:error] [pid 302018:tid 302267] [client 20.197.195.24:0] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:47.844414 2026] [security2:error] [pid 302018:tid 302222] [client 117.251.86.144:41530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NY4As9lPxxVAErz3jNQAAAM0"]
[Tue Jul 21 07:43:47.844583 2026] [security2:error] [pid 302018:tid 302222] [client 117.251.86.144:41530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NY4As9lPxxVAErz3jNQAAAM0"]
[Tue Jul 21 07:43:47.889554 2026] [autoindex:error] [pid 302018:tid 302265] [client 20.197.195.24:13714] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:47.891707 2026] [security2:error] [pid 302018:tid 302242] [client 122.186.204.214:60142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NY4As9lPxxVAErz3jNgAAAOE"]
[Tue Jul 21 07:43:47.891841 2026] [security2:error] [pid 302018:tid 302242] [client 122.186.204.214:60142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NY4As9lPxxVAErz3jNgAAAOE"]
[Tue Jul 21 07:43:47.896400 2026] [security2:error] [pid 302018:tid 302277] [client 20.197.195.24:13714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/ccc.php"] [unique_id "al9NY4As9lPxxVAErz3jNwAAAQQ"]
[Tue Jul 21 07:43:48.107745 2026] [security2:error] [pid 296703:tid 296918] [client 20.197.195.24:13704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/w.php"] [unique_id "al9NZCn25uliftkV1n4JHAAAAFU"]
[Tue Jul 21 07:43:48.108461 2026] [security2:error] [pid 296703:tid 296882] [client 34.12.245.104:54760] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "verbodavidachapeco.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9NZCn25uliftkV1n4JHQAAADE"]
[Tue Jul 21 07:43:48.126412 2026] [security2:error] [pid 302018:tid 302252] [client 41.68.90.219:62589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZIAs9lPxxVAErz3jOgAAAOs"]
[Tue Jul 21 07:43:48.127505 2026] [security2:error] [pid 302018:tid 302252] [client 41.68.90.219:62589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZIAs9lPxxVAErz3jOgAAAOs"]
[Tue Jul 21 07:43:48.150289 2026] [security2:error] [pid 302018:tid 302272] [client 20.226.60.151:22364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9NZIAs9lPxxVAErz3jOwAAAP8"]
[Tue Jul 21 07:43:48.204354 2026] [security2:error] [pid 296703:tid 296893] [client 117.247.80.59:20989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZCn25uliftkV1n4JIQAAADw"]
[Tue Jul 21 07:43:48.204499 2026] [security2:error] [pid 296703:tid 296893] [client 117.247.80.59:20989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZCn25uliftkV1n4JIQAAADw"]
[Tue Jul 21 07:43:48.251310 2026] [security2:error] [pid 302018:tid 302057] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZIAs9lPxxVAErz3jPQAAjyQ"]
[Tue Jul 21 07:43:48.251448 2026] [security2:error] [pid 302018:tid 302160] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZIAs9lPxxVAErz3jPQAAjyQ"]
[Tue Jul 21 07:43:48.682366 2026] [security2:error] [pid 296703:tid 296805] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NZCn25uliftkV1n4JMgAAImU"]
[Tue Jul 21 07:43:48.682557 2026] [security2:error] [pid 296703:tid 296867] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NZCn25uliftkV1n4JMgAAImU"]
[Tue Jul 21 07:43:48.698874 2026] [security2:error] [pid 296703:tid 296959] [client 20.226.60.151:59412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/ccc.php"] [unique_id "al9NZCn25uliftkV1n4JNAAAAH4"]
[Tue Jul 21 07:43:48.870195 2026] [security2:error] [pid 302018:tid 302203] [client 20.197.195.24:13754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9NZIAs9lPxxVAErz3jQAAAALo"]
[Tue Jul 21 07:43:48.913915 2026] [security2:error] [pid 296703:tid 296880] [client 34.12.245.104:50854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "verbodavidachapeco.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9NZCn25uliftkV1n4JPwAAAC8"]
[Tue Jul 21 07:43:48.933195 2026] [security2:error] [pid 296703:tid 296937] [client 37.140.223.122:25261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NZCn25uliftkV1n4JQAAAAGg"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:49.177990 2026] [security2:error] [pid 296703:tid 296934] [client 193.36.225.60:61763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NZSn25uliftkV1n4JQgAAAGU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:49.266128 2026] [security2:error] [pid 302018:tid 302061] [remote 65.111.20.205:19507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9NZYAs9lPxxVAErz3jRQAAvCg"]
[Tue Jul 21 07:43:49.294301 2026] [security2:error] [pid 302018:tid 302196] [client 20.226.60.151:22975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9NZYAs9lPxxVAErz3jRwAAALM"]
[Tue Jul 21 07:43:49.433736 2026] [security2:error] [pid 296703:tid 296952] [client 202.143.127.214:53572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZSn25uliftkV1n4JTQAAAHc"]
[Tue Jul 21 07:43:49.434295 2026] [security2:error] [pid 296703:tid 296952] [client 202.143.127.214:53572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZSn25uliftkV1n4JTQAAAHc"]
[Tue Jul 21 07:43:49.617320 2026] [security2:error] [pid 302018:tid 302189] [client 20.63.100.92:1561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9NZYAs9lPxxVAErz3jSQAAAKw"]
[Tue Jul 21 07:43:49.650009 2026] [security2:error] [pid 302018:tid 302204] [client 20.197.195.24:13762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/FWAZ.php"] [unique_id "al9NZYAs9lPxxVAErz3jSwAAALs"]
[Tue Jul 21 07:43:49.678963 2026] [security2:error] [pid 296703:tid 296838] [client 117.217.38.194:53525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZSn25uliftkV1n4JUQAAAAU"]
[Tue Jul 21 07:43:49.679082 2026] [security2:error] [pid 296703:tid 296838] [client 117.217.38.194:53525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZSn25uliftkV1n4JUQAAAAU"]
[Tue Jul 21 07:43:49.790968 2026] [security2:error] [pid 302018:tid 302221] [client 74.249.245.134:5546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/gettest.php"] [unique_id "al9NZYAs9lPxxVAErz3jUQAAAMw"]
[Tue Jul 21 07:43:49.835528 2026] [security2:error] [pid 302018:tid 302249] [client 34.12.245.104:62957] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "verbodavidachapeco.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9NZYAs9lPxxVAErz3jUwAAAOg"]
[Tue Jul 21 07:43:49.915091 2026] [security2:error] [pid 302018:tid 302264] [client 20.197.195.24:13767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/miru1.php"] [unique_id "al9NZYAs9lPxxVAErz3jWAAAAPc"]
[Tue Jul 21 07:43:49.991136 2026] [security2:error] [pid 296703:tid 296848] [client 20.104.96.117:30423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/jj.php"] [unique_id "al9NZSn25uliftkV1n4JWAAAAA8"]
[Tue Jul 21 07:43:50.208072 2026] [security2:error] [pid 302018:tid 302265] [client 20.226.60.151:60112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/config.php"] [unique_id "al9NZoAs9lPxxVAErz3jXAAAAPg"]
[Tue Jul 21 07:43:50.535355 2026] [security2:error] [pid 302018:tid 302258] [client 154.192.233.199:58583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZoAs9lPxxVAErz3jXgAAAPE"]
[Tue Jul 21 07:43:50.535805 2026] [security2:error] [pid 302018:tid 302258] [client 154.192.233.199:58583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZoAs9lPxxVAErz3jXgAAAPE"]
[Tue Jul 21 07:43:50.562992 2026] [security2:error] [pid 296703:tid 296938] [client 20.197.195.24:13769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/aa.php"] [unique_id "al9NZin25uliftkV1n4JbQAAAGk"]
[Tue Jul 21 07:43:50.665895 2026] [security2:error] [pid 296703:tid 296839] [client 20.104.96.117:44229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/media.php"] [unique_id "al9NZin25uliftkV1n4JbwAAAAY"]
[Tue Jul 21 07:43:50.682272 2026] [security2:error] [pid 302018:tid 302156] [client 20.104.96.117:30889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9NZoAs9lPxxVAErz3jXwAAAIs"]
[Tue Jul 21 07:43:50.789499 2026] [security2:error] [pid 302018:tid 302162] [client 20.226.60.151:59518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/777.php"] [unique_id "al9NZoAs9lPxxVAErz3jYwAAAJE"]
[Tue Jul 21 07:43:51.014709 2026] [security2:error] [pid 296703:tid 296954] [client 20.197.195.24:13817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/122.php"] [unique_id "al9NZyn25uliftkV1n4JdwAAAHk"]
[Tue Jul 21 07:43:51.234128 2026] [security2:error] [pid 296703:tid 296866] [client 20.226.60.151:22367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9NZyn25uliftkV1n4JeQAAACE"]
[Tue Jul 21 07:43:51.290119 2026] [security2:error] [pid 302018:tid 302188] [client 20.197.195.24:49871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/get.php"] [unique_id "al9NZ4As9lPxxVAErz3jbgAAAKs"]
[Tue Jul 21 07:43:51.331086 2026] [security2:error] [pid 296703:tid 296890] [client 20.104.96.117:30866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/txets.php"] [unique_id "al9NZyn25uliftkV1n4JegAAADk"]
[Tue Jul 21 07:43:51.661234 2026] [security2:error] [pid 302018:tid 302210] [client 20.226.60.151:54299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/gettest.php"] [unique_id "al9NZ4As9lPxxVAErz3jcAAAAME"]
[Tue Jul 21 07:43:51.724103 2026] [security2:error] [pid 302018:tid 302176] [client 20.220.225.223:34254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/ez.php"] [unique_id "al9NZ4As9lPxxVAErz3jcQAAAJ8"]
[Tue Jul 21 07:43:51.797594 2026] [security2:error] [pid 302018:tid 302184] [client 20.197.195.24:49816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/as.php"] [unique_id "al9NZ4As9lPxxVAErz3jcwAAAKc"]
[Tue Jul 21 07:43:51.813263 2026] [security2:error] [pid 302018:tid 302199] [client 20.104.96.117:30450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/dex.php"] [unique_id "al9NZ4As9lPxxVAErz3jdAAAALY"]
[Tue Jul 21 07:43:51.964880 2026] [security2:error] [pid 296703:tid 296876] [client 193.36.225.143:22429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NZyn25uliftkV1n4JiAAAACs"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:52.209881 2026] [security2:error] [pid 296703:tid 296845] [client 103.106.20.201:56849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NaCn25uliftkV1n4JigAAAAw"]
[Tue Jul 21 07:43:52.210028 2026] [security2:error] [pid 296703:tid 296845] [client 103.106.20.201:56849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NaCn25uliftkV1n4JigAAAAw"]
[Tue Jul 21 07:43:52.228378 2026] [security2:error] [pid 302018:tid 302067] [remote 104.207.52.109:17267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9NZoAs9lPxxVAErz3jXQAA-y4"]
[Tue Jul 21 07:43:52.322848 2026] [security2:error] [pid 302018:tid 302231] [client 20.226.60.151:50886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/for.php"] [unique_id "al9NaIAs9lPxxVAErz3jfAAAANY"]
[Tue Jul 21 07:43:52.371142 2026] [security2:error] [pid 302018:tid 302160] [client 47.128.50.191:11106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gfacil.com.br"] [uri "/robots.txt"] [unique_id "al9NaIAs9lPxxVAErz3jfQAAAI8"]
[Tue Jul 21 07:43:52.407589 2026] [security2:error] [pid 302018:tid 302235] [client 74.249.245.134:54381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/tfm.php"] [unique_id "al9NaIAs9lPxxVAErz3jggAAANo"]
[Tue Jul 21 07:43:52.666780 2026] [security2:error] [pid 302018:tid 302183] [client 139.167.225.182:54479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NaIAs9lPxxVAErz3jhAAAAKY"]
[Tue Jul 21 07:43:52.666912 2026] [security2:error] [pid 302018:tid 302183] [client 139.167.225.182:54479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NaIAs9lPxxVAErz3jhAAAAKY"]
[Tue Jul 21 07:43:52.684801 2026] [security2:error] [pid 302018:tid 302240] [client 20.104.96.117:30406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/xpwer1.php"] [unique_id "al9NaIAs9lPxxVAErz3jhQAAAN8"]
[Tue Jul 21 07:43:52.729708 2026] [security2:error] [pid 302018:tid 302212] [client 122.162.144.145:25266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NaIAs9lPxxVAErz3jiAAAAMM"]
[Tue Jul 21 07:43:52.729802 2026] [security2:error] [pid 302018:tid 302212] [client 122.162.144.145:25266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NaIAs9lPxxVAErz3jiAAAAMM"]
[Tue Jul 21 07:43:52.751677 2026] [security2:error] [pid 302018:tid 302151] [client 59.96.220.140:61730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NaIAs9lPxxVAErz3jiQAAAIY"]
[Tue Jul 21 07:43:52.769495 2026] [security2:error] [pid 302018:tid 302151] [client 59.96.220.140:61730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NaIAs9lPxxVAErz3jiQAAAIY"]
[Tue Jul 21 07:43:52.799086 2026] [security2:error] [pid 302018:tid 302255] [client 20.197.195.24:49795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/ccou.php"] [unique_id "al9NaIAs9lPxxVAErz3jigAAAO4"]
[Tue Jul 21 07:43:52.816313 2026] [security2:error] [pid 302018:tid 302229] [client 20.104.96.117:44129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/images.php"] [unique_id "al9NaIAs9lPxxVAErz3jiwAAANQ"]
[Tue Jul 21 07:43:52.853112 2026] [security2:error] [pid 302018:tid 302261] [client 20.226.60.151:22657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/for.php"] [unique_id "al9NaIAs9lPxxVAErz3jjAAAAPQ"]
[Tue Jul 21 07:43:53.050957 2026] [security2:error] [pid 302018:tid 302274] [client 20.226.60.151:50835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/ssla.php"] [unique_id "al9NaYAs9lPxxVAErz3jkAAAAQE"]
[Tue Jul 21 07:43:53.190917 2026] [security2:error] [pid 302018:tid 302187] [client 136.144.33.102:35951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NaYAs9lPxxVAErz3jkwAAAKo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:53.412072 2026] [security2:error] [pid 302018:tid 302239] [client 103.29.114.44:63164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NaYAs9lPxxVAErz3jlwAAAN4"]
[Tue Jul 21 07:43:53.412189 2026] [security2:error] [pid 302018:tid 302239] [client 103.29.114.44:63164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NaYAs9lPxxVAErz3jlwAAAN4"]
[Tue Jul 21 07:43:53.626644 2026] [security2:error] [pid 302018:tid 302256] [client 122.179.91.63:7999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NaYAs9lPxxVAErz3jmgAAAO8"]
[Tue Jul 21 07:43:53.626841 2026] [security2:error] [pid 302018:tid 302256] [client 122.179.91.63:7999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NaYAs9lPxxVAErz3jmgAAAO8"]
[Tue Jul 21 07:43:54.037900 2026] [security2:error] [pid 302018:tid 302202] [client 20.226.60.151:22962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/raw.php"] [unique_id "al9NaoAs9lPxxVAErz3jpgAAALk"]
[Tue Jul 21 07:43:54.042214 2026] [security2:error] [pid 302018:tid 302169] [client 173.24.185.52:58833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NaoAs9lPxxVAErz3jpwAAAJg"]
[Tue Jul 21 07:43:54.042373 2026] [security2:error] [pid 302018:tid 302169] [client 173.24.185.52:58833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NaoAs9lPxxVAErz3jpwAAAJg"]
[Tue Jul 21 07:43:54.145115 2026] [security2:error] [pid 302018:tid 302177] [client 20.197.195.24:13790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/w3lls.php"] [unique_id "al9NaoAs9lPxxVAErz3jqAAAAKA"]
[Tue Jul 21 07:43:54.168726 2026] [security2:error] [pid 302018:tid 302180] [client 193.36.225.143:48915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NaoAs9lPxxVAErz3jqQAAAKM"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:54.237388 2026] [security2:error] [pid 302018:tid 302215] [client 20.104.96.117:44244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/gecko.php"] [unique_id "al9NaoAs9lPxxVAErz3jqgAAAMY"]
[Tue Jul 21 07:43:54.249259 2026] [security2:error] [pid 296703:tid 296916] [client 20.226.60.151:50881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/zc-131.php"] [unique_id "al9Nain25uliftkV1n4JrgAAAFM"]
[Tue Jul 21 07:43:54.414080 2026] [security2:error] [pid 302018:tid 302086] [remote 132.148.72.88:57622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9NaoAs9lPxxVAErz3jrgAAj0E"]
[Tue Jul 21 07:43:54.437644 2026] [security2:error] [pid 302018:tid 302088] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NaoAs9lPxxVAErz3jsAAA2kM"]
[Tue Jul 21 07:43:54.437798 2026] [security2:error] [pid 302018:tid 302235] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NaoAs9lPxxVAErz3jsAAA2kM"]
[Tue Jul 21 07:43:54.472281 2026] [security2:error] [pid 296703:tid 296727] [remote 45.150.79.142:50588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Nain25uliftkV1n4JsQAAIxc"]
[Tue Jul 21 07:43:54.570312 2026] [security2:error] [pid 302018:tid 302150] [client 20.220.225.223:53454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9NaoAs9lPxxVAErz3jswAAAIU"]
[Tue Jul 21 07:43:54.630025 2026] [security2:error] [pid 302018:tid 302228] [client 20.104.96.117:44276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/82.php"] [unique_id "al9NaoAs9lPxxVAErz3jtQAAANM"]
[Tue Jul 21 07:43:54.653761 2026] [access_compat:error] [pid 302018:tid 302212] [client 162.241.63.68:31450] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:43:54.815861 2026] [security2:error] [pid 302018:tid 302090] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NaoAs9lPxxVAErz3jtwAAhkU"]
[Tue Jul 21 07:43:54.816055 2026] [security2:error] [pid 302018:tid 302151] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NaoAs9lPxxVAErz3jtwAAhkU"]
[Tue Jul 21 07:43:54.830079 2026] [security2:error] [pid 302018:tid 302208] [client 62.102.148.187:50646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9NaoAs9lPxxVAErz3juAAAAL8"]
[Tue Jul 21 07:43:54.830169 2026] [security2:error] [pid 302018:tid 302208] [client 62.102.148.187:50646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9NaoAs9lPxxVAErz3juAAAAL8"]
[Tue Jul 21 07:43:54.944735 2026] [security2:error] [pid 296703:tid 296877] [client 103.166.103.129:61278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Nain25uliftkV1n4JuQAAACw"]
[Tue Jul 21 07:43:54.944884 2026] [security2:error] [pid 296703:tid 296877] [client 103.166.103.129:61278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Nain25uliftkV1n4JuQAAACw"]
[Tue Jul 21 07:43:55.005619 2026] [security2:error] [pid 302018:tid 302262] [client 20.104.96.117:44282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/admin.php"] [unique_id "al9Na4As9lPxxVAErz3juwAAAPU"]
[Tue Jul 21 07:43:55.059122 2026] [security2:error] [pid 302018:tid 302271] [client 20.104.96.117:30598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/flox.php"] [unique_id "al9Na4As9lPxxVAErz3jvQAAAP4"]
[Tue Jul 21 07:43:55.067692 2026] [security2:error] [pid 302018:tid 302222] [client 20.197.195.24:13788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/test1.php"] [unique_id "al9Na4As9lPxxVAErz3jvgAAAM0"]
[Tue Jul 21 07:43:55.182110 2026] [security2:error] [pid 302018:tid 302260] [client 20.220.225.223:53471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Na4As9lPxxVAErz3jvwAAAPM"]
[Tue Jul 21 07:43:55.633686 2026] [security2:error] [pid 302018:tid 302239] [client 20.104.96.117:44144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/adminner.php"] [unique_id "al9Na4As9lPxxVAErz3jyQAAAN4"]
[Tue Jul 21 07:43:55.707253 2026] [security2:error] [pid 296703:tid 296873] [client 62.102.148.187:50650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Nayn25uliftkV1n4JxQAAACg"]
[Tue Jul 21 07:43:55.707342 2026] [security2:error] [pid 296703:tid 296873] [client 62.102.148.187:50650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Nayn25uliftkV1n4JxQAAACg"]
[Tue Jul 21 07:43:55.781802 2026] [security2:error] [pid 296703:tid 296887] [client 20.226.60.151:54357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/min.php"] [unique_id "al9Nayn25uliftkV1n4JyQAAADY"]
[Tue Jul 21 07:43:56.170705 2026] [autoindex:error] [pid 302018:tid 302192] [client 43.157.95.131:46224] AH01276: Cannot serve directory /home2/luisur31/unimundoconsultoria.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:56.204091 2026] [security2:error] [pid 302018:tid 302191] [client 20.226.60.151:54303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/dvjul.php"] [unique_id "al9NbIAs9lPxxVAErz3j0wAAAK4"]
[Tue Jul 21 07:43:56.276257 2026] [security2:error] [pid 302018:tid 302203] [client 20.104.96.117:44243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/admin.php"] [unique_id "al9NbIAs9lPxxVAErz3j1QAAALo"]
[Tue Jul 21 07:43:56.296336 2026] [security2:error] [pid 302018:tid 302199] [client 20.226.60.151:60118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/biufile.php"] [unique_id "al9NbIAs9lPxxVAErz3j1gAAALY"]
[Tue Jul 21 07:43:56.323059 2026] [security2:error] [pid 302018:tid 302104] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NbIAs9lPxxVAErz3j2QAAvlM"]
[Tue Jul 21 07:43:56.323251 2026] [security2:error] [pid 302018:tid 302207] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NbIAs9lPxxVAErz3j2QAAvlM"]
[Tue Jul 21 07:43:56.363559 2026] [security2:error] [pid 302018:tid 302257] [client 103.174.34.15:60002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NbIAs9lPxxVAErz3j2wAAAPA"]
[Tue Jul 21 07:43:56.363713 2026] [security2:error] [pid 302018:tid 302257] [client 103.174.34.15:60002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NbIAs9lPxxVAErz3j2wAAAPA"]
[Tue Jul 21 07:43:56.533919 2026] [security2:error] [pid 302018:tid 302211] [client 20.226.60.151:61957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/av.php"] [unique_id "al9NbIAs9lPxxVAErz3j3QAAAMI"]
[Tue Jul 21 07:43:56.579432 2026] [security2:error] [pid 302018:tid 302167] [client 182.8.255.181:17197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NbIAs9lPxxVAErz3j4QAAAJY"]
[Tue Jul 21 07:43:56.579601 2026] [security2:error] [pid 302018:tid 302167] [client 182.8.255.181:17197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NbIAs9lPxxVAErz3j4QAAAJY"]
[Tue Jul 21 07:43:56.612041 2026] [security2:error] [pid 296703:tid 296906] [client 106.215.181.8:20166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NbCn25uliftkV1n4J2gAAAEk"]
[Tue Jul 21 07:43:56.612136 2026] [security2:error] [pid 296703:tid 296906] [client 106.215.181.8:20166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NbCn25uliftkV1n4J2gAAAEk"]
[Tue Jul 21 07:43:56.676908 2026] [security2:error] [pid 296703:tid 296947] [client 178.153.91.96:63332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NbCn25uliftkV1n4J3AAAAHI"]
[Tue Jul 21 07:43:56.677053 2026] [security2:error] [pid 296703:tid 296947] [client 178.153.91.96:63332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NbCn25uliftkV1n4J3AAAAHI"]
[Tue Jul 21 07:43:56.753593 2026] [security2:error] [pid 302018:tid 302175] [client 20.197.195.24:13772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/database.php"] [unique_id "al9NbIAs9lPxxVAErz3j4wAAAJ4"]
[Tue Jul 21 07:43:56.862368 2026] [security2:error] [pid 302018:tid 302178] [client 20.104.96.117:44126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/k.php"] [unique_id "al9NbIAs9lPxxVAErz3j5AAAAKE"]
[Tue Jul 21 07:43:56.937754 2026] [security2:error] [pid 302018:tid 302230] [client 20.220.225.223:19667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/wp-explorer.php"] [unique_id "al9NbIAs9lPxxVAErz3j5wAAANU"]
[Tue Jul 21 07:43:57.074716 2026] [security2:error] [pid 302018:tid 302251] [client 20.220.225.223:53478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/wander.php"] [unique_id "al9NbYAs9lPxxVAErz3j6gAAAOo"]
[Tue Jul 21 07:43:57.158474 2026] [security2:error] [pid 302018:tid 302229] [client 20.197.195.24:13751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/file.php"] [unique_id "al9NbYAs9lPxxVAErz3j7gAAANQ"]
[Tue Jul 21 07:43:57.197004 2026] [security2:error] [pid 302018:tid 302253] [client 20.104.96.117:30857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/popo.php"] [unique_id "al9NbYAs9lPxxVAErz3j7wAAAOw"]
[Tue Jul 21 07:43:57.245617 2026] [security2:error] [pid 302018:tid 302109] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NbYAs9lPxxVAErz3j8AAAplg"]
[Tue Jul 21 07:43:57.245741 2026] [security2:error] [pid 302018:tid 302183] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NbYAs9lPxxVAErz3j8AAAplg"